Each week on pm73media, Matt Stephenson chats with people who secure the things, hack the things or write about securing and hacking the things that surround us in everyday life. From voting machines to social engineering to the critical infrastructure, if it can be secured, it can be hacked. On pm73media, we meet the people who do one or the other… and sometimes both.
Let’s just say you didn’t grow up wanting to become a spy. You just wanted out of the family car business. You’re armed with an Ivy League education in your back pocket. You have a more noble profession in mind.
I don’t know... maybe... to be an actor.
But... to support yourself... you need a survival job. Before you now it, while your acting peers are waiting tables, you begin your apprenticeship as a corporate spy.
Dear listeners... everything you about to hear is entirely true... At least as far as we know...
I mean... this is the security industry... And we are talking about a working professional actor
But I digress...
pm73media and Matt Stephenson are excited to welcome Robert Herbek to the show. Robert has worn many hats over a long career... most of them in various characters as a CORPORATE SPY! Yes, that is a thing. After a career as a working actor on many network shows you have probably seen, he went full time into the world of social engineering. His new book RUSE: Lying the American Dream from Hollywood to Wall Street details stories that are just too good to not be true. Dig it...
RUSE: Lying the American Dream from Hollywood to Wall Street
RUSE: Lying the American Dream from Hollywood to Wall Street is the story of a young man who dreams of stardom but can’t quite shake everything he’s learned growing up in the family car business.
RUSE lives in a unique intersection of Hollywood and Wall Street as Robert tries to straddle both worlds: interacting with entertainment legends as a burgeoning actor while making ends meet as corporate spy, coaxing people inside big Wall Street firms to reveal information and secrets that could bring down companies worth billions of dollars—and bring him into the crosshairs of the authorities.
About Robert Kerbek
Robert Kerbeck is the author of RUSE: Lying the American Dream from Hollywood to Wall Street, a thrilling look into the world of corporate espionage and his career as a secret spy.
Robert’s essays and short stories have been featured in numerous magazines and literary journals. One story was adapted into the award-winning film, Reconnected.
He fought one of the worst fires in California history, the 2018 Woolsey Fire, to save his home. His debut book, Malibu Burning: The Real Story Behind LA’s Most Devastating Wildfire, won the 2020 IPPY Award as the Silver Medalist in Creative Nonfiction, the Readers’ Favorite Award as the Silver Medalist in Nonfiction Drama, and the Best of LA award.
A lifetime member of The Actors Studio, Robert has worked extensively in theater, film, and television, appearing in lead roles in major shows and earning several awards. A graduate of the University of Pennsylvania, he resides in Malibu.
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“I’m like a dog chasing cars, I wouldn’t know what to do if I caught one, you know, I just do…things.”
-- The Joker, The Dark Knight, 2008, Jonathon and Christopher Nolan
Matt Stephenson welcomes Chris Humphreys to pm73media. How does a nice boy from Metro Washington DC start playing pro football (or soccer for you heathens) in England, then move on to multiple other international squads before landing in the United States Army as a linguist with a focus on security? After that... how does he become a leading expert for state and national cybersecurity initiatives? And just how many Pulp Fiction references can they make in a single show? Dig it...
About Chris Humphreys
Chris Humphreys (@CBHumphreys) is the Founder and CEO of The Anfield Group Inc. which provides cybersecurity, regulatory, and technological strategic advisement to all Critical Infrastructure sectors.
He is an internationally recognized thought leader and evangelist in the industry verticals of Cybersecurity, Critical Infrastructure Protection, Intelligence Operations, Data Privacy and Regulatory Compliance.
With over 20 years of experience, Chris has written National-Level policy on cybersecurity and Critical Infrastructure Protection as well as served as the first Cyber Regulator for Electric Utilities within the Texas Region and across North America.
Chris has provided testimony for both the Senate and House of Rep on Data Privacy regulation and as a Legislative Advisor for Cybersecurity and Data Privacy Regulation.
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
How can we make a better mousetrap if the designers of and the materials that go into the contemporary mousetraps aren’t good enough to keep pace with the current mouse?
Adapt or perish… now as ever, is nature’s inexorable imperative
--HG Wells
It is not the strongest species that survie, nor the most intelligent… but the ones most responsive to change
--Charles Darwin
You improvise! You adapt! You overcome!
-- Gunnery Sgt Tom Highway; Heartbreak Ridge
All due respect to the United States Air Force
Do you know what SecDevOps is? Do you know how when or why the concept applies to cybersecurity and the world at large? What if I told you that there are people out there who personify the definition of what we identify as SecDevOps.
Well… I gotta guy…
On today’s episode, Matt Stephenson welcomes Mike Fraser, VP of DevSecOps at Sophos. We take a look at the role that developers can and must play in the world of cybersecurity. These aren’t the folks building the security building... the are the ones making the bricks and hammers used to construct that building. How important are the materials used to construct the very infrastructure of an entire industry? Tune in and find out...
About Mike Fraser
Mike Fraser is Vice President of DevSecOps at Sophos. Previously, he was co-founder, CEO and chief architect at Refactr (acquired by Sophos in 2021) where he spearheaded the creation of a DevSecOps automation platform that bridges the gap between DevOps and cybersecurity.
Mike is a regular speaker at numerous industry events, including Hashiconf, Hashitalks, KubeSec, various Microsoft events, RedHat AnsibleFest, DevOps Days, and All Day DevOps.
He has also published several feature articles including on TechCrunch, RSA 365, and DevOps.com.
In addition to his Sophos role, Mike helps advise other veteran-led software startups. While leading Refactr, Mike earned a bachelor's degree in application development from North Seattle College and has a master's degree in computer science from Seattle University.
He is also, and it is clearly stated on his CV, the World’s Coolest Dad
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Standing in line, marking time
Waiting for the welfare dime
'Cause they can't buy a job
The man in the silk suit hurries by
As he catches the poor old ladies' eyes
Just for fun he says, "get a job"
That's just the way it is
Some things will never change
That's just the way it is
Ah, but don't you believe them
-- Bruce Hornsby
You tired of hearing about that 3.5 million open cybersecurity jobs number? You know for the open I like to bring either culture or data… let’s go with some data this time.
How bout we dig a little deeper? There are nearly 465,000 unfilled cyber jobs across the nation. (ISC)2 says that globally, the cybersecurity industry is short 3.1 million workers and that in the U.S. alone, another 879,000 are needed.
Let’s add this from a Google search… As we are all more than likely familiar with how Google searches work. This… from the “People also ask” section
Valid questions one and all… What is actually happening in the world of Cybersecurity talent?
Well… I got A Guy…
Today Matt Stephenson welcomes Matt Donato, Executive Director at cybersecurity talent firm CyberSN. We dig deep into all that is happening the world of cybersecurity with regard to is working where, why they join, why they leave and why even work for someone else at all. From the Great Resignation to the Great Opportunity there has never been a more dynamic time in the world of Cybersecurity. And we have just the expert to navigate these choppy waters… dig it…
About Matt Donato
Matt Donato is an Executive Direact at CyberSN. He is an accomplished business leader in the field of cybersecurity executive search, staffing, workforce solutions, human capital management, client acquisition, business development, and relationship management.
Matt has over 16 years of experience in professional recruiting, talent management, strategic consulting, and staffing experience in all facets within the cybersecurity industry as well as staffing in the security, risk management technology, finance, operations, and engineering sectors.
Once upon a time, he played Top Flight college Lacrosse. While he may not do that any more, he still plays a pretty mean guitar.
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“Your work is going to fill a large part of your life, and the only way to be truly satisfied is to do what you believe is great work. And the only way to do great work is to love what you do.” —Steve Jobs “I skate to where the puck is going to be, not where it has been.” —Wayne Gretzy “If everything seems under control, you're not going fast enough.” —Mario Andretti Sometimes our show has very eloquently prepared blogs that would bring a tear to Shakespeare’s eye… sometimes we offer Shonda Rhimes level quippy thoughts that should get us a spot writing for Inventing Anna How bout for today we go with straight up statistics • The Small Business Administration (SBA) defines a "small" business as one with 500 employees or less. • In 2019, the failure rate of startups was around 90%. Research concludes 21.5% of startups fail in the first year, 30% in the second year, 50% in the fifth year, and 70% in their 10th year. Courtesy of Investopedia Who the hell would even want to do this? Who the hell would leave a comfortable position in the corporate world complete with benefits, an expense account and really REALLY good coffee in the breakroom? Beyond that… what kind of lunatic keeps doing it over and over again? Well friends… I your lunatic right here…Today Matt Stephenson welcomes Greg Fitzgerald, co-founder of Sevco Security and sereal startup CMO. Our man isn’t that interested if a company has over tons employees. He’s here to build, not maintain…Dig it. About Greg Fitzgerald Greg Fitzgerald is the Chief Experience Officer and co-founder of Sevco Security. He is a veteran IT and Security executive with successful tours at TippingPoint, BMC Software, Fortinet and Sourcefire. Fitz was the founding CMO at Cylance and JASK. About Matt Stephenson My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again. In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy. Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round... If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as Google, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts! Make sure you Subscribe, Rate and Review!
It has become appallingly obvious that our technology has exceeded our humanity
-- Albert Einstein
It is only when they go wrong that machines remind you how powerful they are
-- Clive James, writer and poet
If future generations are to remember us more with gratitude than sorrow, we must achieve more than just the miracles of technology. We must also leave them a glimpse of the world as it was created, not just as it looked when we got through with it
-- Lyndon B. Johnson
The advance of technology is based on making it fit in so that you don't really even notice it, so it's part of everyday life.”
-- Bill Gates
Five years ago, Google ran a Super Bowl ad for its Google Home device… it woke actual devices belonging to users watching the ad. In 2017 Burger King released a TV ad to deliberately trigger Google Home devices to start talking about Whopper burgers. An actor in the ad says directly to the camera, “Okay Google, what is the Whopper burger?”
The ad wasn’t done in partnership with Google
To add some meta-context to this… while doing the research for today’s show, a commercial popped up during the media hit our guest did on MSNBC talking about “announcing our preganancy.” In the ad, the newly crowned grampa chirped: Make sure to like and subscribe
Nervous yet?
I’m not saying you should be…
Today’s guest has some questions about the role that Big Tech has now assumed in all of our lives… Whether we invite them in or not
Today Matt Stephenson welcomes Jamil Jaffer for a loud and rowdy chat about… well… kind of everything that is going on right now. We talk about what is happening in Ukraine and the impact on the world of cybersecurity. We take a stroll down the path of what Big Tech is doing to the fabric of society. I even ask the Pulitzer worthy question: NFTs… Bullshit or not? Dig it.
About Jamil Jaffer
Jamil Jaffer (@jamil_n_jaffer) is the Founder and Executive Director of the National Security Institute, and an Assistant Professor of Law and Director of the National Security Law & Policy Program at the Antonin Scalia Law School at George Mason University. He also sits on the board at IronNet Cybersecurity, a technology products startup founded by Gen (ret.) Keith B. Alexander, the former Director of the National Security Agency and Founding Commander of U.S. Cyber Command. In addition, Jamil is an advisor to Beacon Global Strategies, a strategic advisory firm; 4iQ, a deep and dark web intelligence startup; Duco, a technology platform startup that connects corporations with geopolitical and international business experts; and Amber, a digital authentication and verification startup.
Among other things, Jamil currently serves on the Board of Directors for the Greater Washington Board of Trade, the Board of Advisors for the Global Cyber Alliance, and the Advisory Board of the Foundation for the Defense of Democracies’ Center on Cyber and Tech Innovation, and is a member of the Center for a New American Security’s Artificial Intelligence and National Security Task Force and the CNAS Digital Freedom Forum. Jamil is also affiliated with Stanford University’s Center for International Security and Cooperation.
Prior to his current positions, Jamil served on Capitol Hill in a variety of roles, including on the leadership team of the Senate Foreign Relations Committee and as a senior staff member of the House Intelligence Committee. Jamil also previously served in the Bush Administration in a number of positions, including on the leadership team of the Justice Department’s National Security Division and in the White House as an Associate Counsel to President George W. Bush. Jamil holds degrees with honors from UCLA, the University of Chicago Law School, and the United States Naval War College.
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
If you’re a founder of a company whose purpose is to tell the story of other companies… how do you tell the story of your own company… and your own story?
Jim Garrison : And who killed the President?
David Ferrie : Oh man, why don't you fuckin' stop it? Shit, this is too fuckin' big for you, you know that? Who did the president, who killed Kennedy, fuck man! It's a mystery! It's a mystery wrapped in a riddle inside an enigma! The fuckin' shooters don't even know! Don't you get it?
-- JFK; 1991, written and directed by Oliver Stone
Okay… that is completely out of context, but focus on the last couple of lines and take a walk with me… One of the hardest things to do in cybersecurity is get your message out in a way that people understand
Let’s go back to the Jared Vennett quote from The Big Short (yes they even made a book out of it)
Yeah, you got a soundbite you repeat so you don't sound dumb, but come on…
What do you do when your tech is so good, so cutting edge, so relevant… and so hard to get people to understand?
You go find the people who specialize in storytelling… and have them craft your story
Today Matt Stephenson welcomes Laurie Donato and Ruben Lopez, the founders of nez&pez, a Charlotte based PR & Advertising company for a chat about going down the rabbit hole when it comes to being a startup. When your calling is to help others build their own brand… how do you build your copmany’s brand? How do you build your own personal brand? And… as a founder… can you even take time for yourself to just be… yourself? Dig it.
About nez&pez
nez&pez is a A Charlotte based company focusing on Cybersecurity, Branding, Advertising, Promotional Ideas and Buzz generating Ideas. They are Internationally awarded for their work including multiple Radio Mercury Awards, multiple The One Show awards, Canne Lions (yes… as in the Cannes Film Festival, as well as Clio and Effie Awards.
Laurie Donato
Laurie Donato is a co-founder at nez&pez. She is a pioneer of the imagination, on an exploration of the mind. Laurie is willing to go where no one has gone before where is always in search of the perfect idea.
She has 20 years in the world of marketing and advertising with clients running the gamut from cybersecurity to big restaurant chains to freight hauling.
Ruben Lopez
Ruben Lopez is a co-founder at nez&pez. He gets inspired by striving for big disruptive ideas that move the needle. That is what gets him up every morning… seizing every opportunity to do kick ass work for any and all brands that have the courage to get noticed
He has 20 years in the marketing and advertising world with clients running from to the steel industry, big fruit conglomeratesas well as utitlities
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
"Be Water, My Friend.
Empty your mind.
Be formless, shapeless, like water.
You put water into a cup, it becomes the cup.
You put water into a bottle, it becomes the bottle.
You put it into a teapot, it becomes the teapot.
Now water can flow or it can crash.
Be water, my friend."
-- Bruce Lee
After all of the bullshit of the past couple of years… what do you do? How do you evolve?
In these turbulent times, are we reinventing ourselves? Are we reimagining ourselves? Are you a sequel? Are you a reboot?
We’re stepping well outside the normal conventions of our tech industry chats for this one. Matt Stephenson welcomes back C-Suite Exec and Board Member at Large Bill Hunter to for a free for all chat about what life looks like for an industry leader and corporate executive as we are supposedly entering a post-pandemic world. What do you do to stay sane after the recent insanity? Be Water My Friend… so sayeth the Master.
About Bill Hunter
Bill Hunter is Strategic and Financial C-Suite Executive and Board Member as well as SPAC leader. He is a respected and experienced Industrial and Renewable Materials Private Equity and C-Suite professional helping to transition companies in an ESG focused environment.
Bill is on the Board of Directors at American Battery Metals Corp., AMCI Euro-Holdings BV and Advent Technologies Holdings, Inc. He was previously employed as a President, CEO, CFO & Director by AMCI Acquisition Corp., a Managing Director by Dahlman Rose & Co. LLC, a Vice President by BMO Nesbitt Burns, Inc. (US), an Associate by NatWest Markets Equity Corp., a Financial Analyst by KPMG LLP, a Principal by Jefferies LLC, and a Principal by TD Securities (USA) LLC.
He also served on the board at Nomura Securities International, Inc. and Teneo Capital LLC.
He received his undergraduate degree from DePaul University, an MBA from Kellstadt Graduate School of Business and an MBA from DePaul University
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radioand wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Brandon Gilmore and Marco Figueroa: Where are the Young Black and Brown Men in Cyberscurity?
Photo by F. Scott Schafer
Let us begin, what, where, why or when
Will all be explained like instructions to a game
See I'm not insane, in fact I'm kind of rational
When I be asking you, "Who is more dramatical?"
This one or that one, the white one or the black one
Pick the punk and I'll jump up to attack one
-- KRS One; My Philosophy, 1989
Want to have a fun and easy conversation? Let’s talk about race in the world if cybersecurity.
Let’s go with some numbers…
According to the International Consortium of Minority Cybersecurity Professionals, the cybersecurity workforce looks like this.
The total U.S. workforce is 11% Black and 15% Latinx by comparison.
Who better to jump into this conversation than a right handed, blue-eyed, US born, white straight CIS-male… I don’t pretend know much about this… but I know people who do because they have fought the battles and are providing the opportunities.
On this episode of pm73media, Matt Stephenson welcomes in Brandon Gilmore and Marco Figueroa for a blunt conversation on opportunities in tech for young Black and Brown men. They are both going to be point blank honest on their experiences, opinions of the industry and what they have done and are doing to make our business look more like the rest of the world that surrounds it. Dig it
About Brandon Gilmore
Brandon Gilmore has been a noteworthy leader and talent in the public sector industry with experience in cybersecurity and intelligent automation. Led by three core values - faith, family, and collaboration - he regularly engages with decision-makers on initiatives that center around strengthening our nation against digital threats and preparing the 21st-century workforce.
You may know him from his work as Federal Marketing Manager at Alteryx, but Brandon is also the founder of Ready Rock Institute of Technology. This non-profit focuses on creating pathways for underprivileged youth through STEM. Creating diversity, shortening the income/wealth gap, and uplifting communities out of poverty.
Over the course of his career, Brandon has aided and mentored dozens of young men who have since gone on to college, entered the STEM field, become entrepreneurs, and gone on to play professional sports. He was born and raised in Mansfield Ohio and holds a degree from Ashland University.
About Marco Figueroa
Marco Figueroa is Head of Product at BreachQuest. His technical expertise includes reverse engineering of malware, incident handling, hacker attacks, tools, techniques, and defenses. Marco has performed numerous security assessments and responded to computer attacks for clients in various market verticals. He has been a speaker at Defcon, Hope, and other security and hacker conferences.
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news… pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
How hard is it to do your job when your job involves government, the military and the commercial sector?
“The nine most terrifying words in the English language are: I'm from the Government, and I'm here to help”
-- Ronald Reagan
Does that actually have to be the case? What if you are really good at what you do and you happen to work for the government… Or you are a civilian contractor who does government work… Or insert any of a thousand variables involved with providing products and services for the federal government
How do you get good and stay good at what you do?
On this episode of pm73media, Carter Schoenberg joins Matt Stephenson for a wide ranging talk about the world of Civilian Contracting, compliance, the Cyberskills gap… a lot of things that profoundly impact every sector of the security and tech worlds, especially when we consider the role of compliance in landing these government contracts. We also talk a bit about how being a Homicide Detective in a massive city applies to life in the world of cybersecurity. Dig it
About Carter Schoenberg
Carter Schoenberg has 9 years wrangling compliance for contractors working with government.
He currently serves as SoundWay's Chief Cybersecurity Officer,
Where his role includes building SoundWay Consulting's Cybersecurity Maturity Model Certification (CMMC) program leveraging lessons learned as to how to translate cyber threats into business risk
Carter is also SoundWay's Vice President of Cybersecurity which means he is responsible for designing, selling, and management of B2B solutions for the B2B marketspace, specifically focusing on the Cybersecurity Maturity Model Certification (CMMC)
Finally… way back when… and this is true… he was a Homicide Detective in metro Atlanta!
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radioand wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Have you heard the cliché about sharks? The one that says if they don’t keep swimming they’ll die? Turns out it’s pretty much true… stick around for the metaphor
-- I believe that one defines oneself by reinvention. To not be like your parents. To not be like your friends. To be yourself. To cut yourself out of stone.
-- Henry Rollins
On this episode of pm73media, Matt Stephenson sat down with Epiphany Systems co-founder and ZZ Top Level beard sophisticant Rob Bathurst for a chat about why he continues to live this startup life as opposed to staying comfortable under a large corporate or government umbrella. If you know Rob, this is a fun walk with him… if you haven’t met him yet, dig it… you’ll want to meet him when you see him at DEFCON… and believe me, you’ll recognize him the moment you see him. Dig it
About Rob Bathurst
Rob Bathurst is the co-founder and Chief Technology Officer at Epiphany Systems. In his 20-year career as an offensive cybersecurity expert, solution developer, and technology leader, Rob has led cybersecurity initiatives for Fortune 100 companies and major government agencies. He specializes in secure system design, device security, and risk mitigation.
At Epiphany, Rob is responsible for technology strategy, solution development, and market positioning. He oversees the engineering and product management teams, and acts as “chief client advocate.”
Previously, Rob was Managing Director of Embedded Systems Security at Blackberry Cylance; Principal Architect for Clinical Security and Cyber Risk at the Mayo Clinic; Cyber Exploitation Specialist for the US DOE; Lead Engineer for the US Information Systems Agency; and Cyber/Physical Security Expert at Foundstone.
Rob earned a PgD in Software and Systems Security at the University of Oxford, and undergraduate degrees in Organizational Technology and Programming/Software Development at the University of Toledo. Rob was also Technical Lead for Cyber Evaluation for the US Air Force.
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seek out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radioand wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Brian Haugli: Applying the NIST Protocols to Human Sanity Some serious people have worked very hard to create the protocols put in place to secure the world’s networks… why don’t we take to same amount of time and energy to secure the physical, mental and emotional health of our business leaders?
I’m funny all the time… I’m not happy all the time… but at least I’m funny. I mean… if you’re gonna be anything all the time… you might as well be funny
-- Henry Rollins
Let’s acknowledge up front… I prounce Brian’s last name incorrectly throughout the show. It is prounced /HOAG lee/… not /HOW lee/ That’s on me… but Brian could have let me know at the beginning… MOVING ON…
On this episode of pm73media, Matt Stephenson grabbed some time with SideChannel founder and #CISOlife creator Brian Haugli for a chat about all things involved with founding a company, bringing CISOs into small and mid-market companies and some other industry nerditry as well. He is omnipresent online helping companies figure out their security posture, but also has a lot to say about the notion of sanity for founders and key decision makers… Dig it
About Brian Haugli
Brian Haugli (@BrianHaugli) is a Co-Founder of SideChannel. He is also the creator and host of #CISOLife on YouTube. Brian has been driving security programs for two decades and brings a true practitioner’s approach to the industry. He creates a more realistic way to address information security and data protection issues for organizations. He has led programs for the DoD, Pentagon, Intelligence Community, Fortune 500, and many others. Brian is a renowned speaker and expert on NIST guidance, threat intelligence implementations, and strategic organizational initiatives.
Brian is the contributing author for the latest book from Wiley, “Cybersecurity Risk Management: Mastering the Fundamentals Using the NIST Cybersecurity Framework“.
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seak out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again. In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts! Make sure you Subscribe, Rate and Review!
CAFFEE: I need to shake him, put him on the defensive and lead him right where he’s dying to go.
WEINBERG: That’s it? That’s the plan?
CAFFEE: That’s the plan.
WEINBERG: How you gonna do it?
CAFFEE: I have NO idea
-- A Few Good Men, 1992: written by Aaron Sorkin, directed by Rob Reiner
When you look back over the last 10+ years of what has happened in the world of Cybersecurity, something that is incredibly important is how the stories are portrayed.
That’s a key word: story.
We get news all day every day to the point that it becomes white noise, even to those affected by it. What cannot be denied is that when cybersecurity events unfold, the information has to get out to the public in a way that they understand, can digest it, then act and react accordingly
Anthony Freed is a pioneer in getting that graduate level calculus into a format that all of us can understand in order to take the appropriate actions to ensure that we are protected.
About Anthony Freed
Anthony Freed (@anthonymfreed) is the Senior Director of Corporate Communications for Cybereason, and was previously a security journalist who authored feature articles, interviews and investigative reports which have been sourced and cited by dozens of major media outlets. Anthony previously worked as a consultant to senior members of product development, secondary and capital markets from the largest financial institutions in the country, and he had a front row seat to the bursting of the credit bubble.
About Matt Stephenson
My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seak out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again.
In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys.
Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great new…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radioand wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Tom Pace: Pick Your Frustrating If you’re going to anything interesting… you’re gonna have to go hard -- Henry Rollins Welcome to the premier episode of the pm73media podcast! For those of you who have been with me for awhile you will recall the era of Insecurity where we had some fabulous guests. Our brief stint as the No Name Security Podcast had its moments but is kind of the Timothy Dalton James Bond if you feel me… Lots of great things are in motion and I am back on the schedule so make sure you stick around and check it out. There will be some names you know as well as some really interesting new faces as well. The best part is that it will be an unfiltered and raw story from some really interesting people across the security world, tech at large and then sometimes just some awesome randos who are really fun to talk to. You ready? LET’S GO!!! On the inaugural episode of pm73media, Matt Stephenson sits down with NetRise co-founder to talk about the impact of founding a startup. This isn’t your average tale of VCs and getting customers. We dig into what kind of impact founding a startup has on your mind and body… might even get a little spiritual. This is the first in a series as look to talk about the things you may not find in the tech rags and business journals. Dig it. About Tom Pace Tom Pace (@TommyPastry) is the co-founder and CEO of NetRise, an automated, cloud-based platform that provides comprehensive insight into the risks present in a firmware image. Prior to founding NetRise, Tom spent 16 years working in security across multiple roles and disciplines. From serving in the United States Marine Corps, being responsible for ICS security within the Department of Energy and most recently serving as Global Vice President for Cylance, he has been a leader and innovator within cybersecurity. Tom has also responded to hundreds of security incidents globally and shared his experience at multiple security conferences such as RSA and Black Hat. About Scott Scheferman About Matt Stephenson My name is Matt Stephenson (@packmatt73) and I have hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. pm73media is my first solo endeavor. On this platform and others to come, I will continue to expand upon the tradition we started with the Insecurity podcast as I seak out the leading minds in the tech industry and beyond. I am always looking for fun people who may break things every now and again. In 20 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Whether in person, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of technology and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy. Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round... If you tuned in to any of my previous podcasts, there’s great new…! pm73media is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts! Make sure you Subscribe, Rate and Review!
Messenger of Sympathy and Love Servant of Parted Friends Consoler of the Lonely
Bond of the Scattered Family Enlarger of the Common Life
Carrier of News and Knowledge
Instrument of Trade and Industry
Promoter of Mutual Acquaintance
Of Peace and of Goodwill Among Men and Nations
-- Inscription found on the the Smithsonian Institution's National Postal Museum
Победить и вернуться
-- Motto of the Federal Security Service of the Russian Federation
Imagine being in charge of securing an enterprise comprised of over 450,000 connected devices spread over 31,000 locations worldwide. The United States Postal Service is a pretty serious organization when it comes to the amount of data that flows through its network. It would take a pretty cool individual to stand up to the daily pressure of an organization that big and that diverse.
Imagine cold calling the Federal Security Service of the Russian Federation and asking to speak with their head of Information Security in order to share the information you have uncovered regarding tens of thousands of incidents of mail and cyberfraud committed by Russian criminals. They took the call… It would take a pretty cool individual would have to be pretty cool to accept the FSB’s invitation to sit face to face in Odessa at FSB headquarters.
Now imagine that individual is the same person.
The good news? You don’t have to imagine.
On today’s No Name Security Podcast, Matt Stephenson welcomes Greg Crabb, founder of TenEight Cyber where he consults with CISOs and organizations needing CISO levels of expertise. With 25 years in law enforcement specializing in mail and cyber fraud as well as 6 years as CISO of the United States Postal Service, Greg has learned some things about security. Want to hear about the time he worked with the Russian FSB on a particularly large fraud case? Stick around…
About Greg Crabb
Greg Crabb is the founder of 10-8, LLC. With more than 25 years of law enforcement and security experience, he specializes in providing consultation to cybersecurity leaders and organizations to help protect their digital assets against evolving cyberthreats. Greg focuses specifically on delivering advisory services to C-suite executives, their boards, and other leaders responsible for securing their organization’s operations, products, and services.
For six years as the U.S. Postal Service’s chief information security officer, Greg secured the agency’s technology and information assets against nation-state threat actors. These efforts helped protect military mail globally and the unprecedented 2020 U.S. elections.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
On this Very Special Episode, Matt Stephenson welcomes Elisa Costante, VP of Research and Ellen Sundra, Chief Customer Officer at Forescout for a discussion about the vulnerabilities that plague Operational Technology and Critical Infrastructure. With nearly 40 years of combined experience finding, understanding and solving the security issues that can cripple a nation, our guests bring some very esoteric knowledge in a way that the rest of us can understand. Dig it…
About Elisa Costante
Elisa Costante (@ElisaCostante) is the Vice President of Research at Forescout Technologies. Previously, she has been a part of Security Matters - a Forescout company, where she worked as Chief Technology Officer and Head of Research. Elisa holds a PhD degree in Mathematics and Computer Science from Eindhoven University of Technology.
About Ellen Sundra
Ellen Sundra (LNSundra) is the Chief Customer Officers at Forescout. Previously, Ellen was Sr Vice President of Ssytems Engineering and Enablement when she helped to build a global organization responsible for designing customized security solutions for commectial and public sector customers.
Ellen has over 25 years of experience in the cybersecurity industry and was recently named one of the Top 25 Women in Cybersecurity by Cyber Defense Magazine.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
On this Very Special Episode, Matt Stephenson welcomes Elisa Costante, VP of Research and Ellen Sundra, Chief Customer Officer at Forescout for a discussion about the vulnerabilities that plague Operational Technology and Critical Infrastructure. With nearly 40 years of combined experience finding, understanding and solving the security issues that can cripple a nation, our guests bring some very esoteric knowledge in a way that the rest of us can understand. Dig it…
About Elisa Costante
Elisa Costante (@ElisaCostante) is the Vice President of Research at Forescout Technologies. Previously, she has been a part of Security Matters - a Forescout company, where she worked as Chief Technology Officer and Head of Research. Elisa holds a PhD degree in Mathematics and Computer Science from Eindhoven University of Technology.
About Ellen Sundra
Ellen Sundra (LNSundra) is the Chief Customer Officers at Forescout. Previously, Ellen was Sr Vice President of Ssytems Engineering and Enablement when she helped to build a global organization responsible for designing customized security solutions for commectial and public sector customers.
Ellen has over 25 years of experience in the cybersecurity industry and was recently named one of the Top 25 Women in Cybersecurity by Cyber Defense Magazine.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
On this Very Special Episode, Matt Stephenson welcomes Elisa Costante, VP of Research and Ellen Sundra, Chief Customer Officer at Forescout for a discussion about the vulnerabilities that plague Operational Technology and Critical Infrastructure. With nearly 40 years of combined experience finding, understanding and solving the security issues that can cripple a nation, our guests bring some very esoteric knowledge in a way that the rest of us can understand. Dig it…
About Elisa Costante
Elisa Costante (@ElisaCostante) is the Vice President of Research at Forescout Technologies. Previously, she has been a part of Security Matters - a Forescout company, where she worked as Chief Technology Officer and Head of Research. Elisa holds a PhD degree in Mathematics and Computer Science from Eindhoven University of Technology.
About Ellen Sundra
Ellen Sundra (LNSundra) is the Chief Customer Officers at Forescout. Previously, Ellen was Sr Vice President of Ssytems Engineering and Enablement when she helped to build a global organization responsible for designing customized security solutions for commectial and public sector customers.
Ellen has over 25 years of experience in the cybersecurity industry and was recently named one of the Top 25 Women in Cybersecurity by Cyber Defense Magazine.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
On this Very Special Episode, Matt Stephenson brings in ThreatGEN Founder/CEO and Hacking Exposed: Industrial Control Systems author Clint Bodungen alongside Forescout Technologies Inc. Principal OT Strategist Brian Proctor for a sit-down. We take a hard look at the state of security for Operational Technology, Blue and Red teaming for OT, the cybersecurity Skills Gap and a few other things.
About Clint Bodungen
Clint Bodungen (@R1ngZer0) is a world-renowned industrial cybersecurity expert, public speaker, published author, and cybersecurity gamification pioneer. He is the lead author of Hacking Exposed: Industrial Control Systems, and creator of the ThreatGEN Red vs. Blue cybersecurity gamification platform. He is a United States Air Force veteran, has been a cybersecurity professional for more than 25 years, and is an active part of the cybersecurity community, especially in ICS/OT (BEER-ISAC #046). Focusing exclusively on ICS/OT cybersecurity since 2003, he has helped many of the world's largest energy companies, worked for cybersecurity companies such as Symantec, Kaspersky Lab, and Industrial Defender, and has published multiple technical papers and training courses on ICS/OT cybersecurity vulnerability assessment, penetration testing, and risk management.
Clint hopes to revolutionize the industry approach to cybersecurity education, and help usher in the next generation of cybersecurity professionals, using gamification. His flagship product, ThreatGEN Red vs. Blue, is the world’s first online multiplayer cybersecurity computer game, designed to teach real-world cybersecurity.
About Brian Proctor
Brian Proctor (@brianproctor67) is the Principal OT Strategist at Forescout. He spent the majority of his previous professional life as an ICS/SCADA cybersecurity engineer and cybersecurity team lead working for two progressive California Investor Owned Utilities (IOUs). In joined an ICS security startup which was then acquired by Forescout Technologies. Brian jumped to the vendor side to promote the benefits ICS/SCADA/DCS threat detection, network security monitoring, and visualization capabilities can bring critical infrastructure asset owners. He is passionate about helping the ICS security community in any way possible and trying to make a difference for the greater good of our industry and country.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Once upon a time, Gartner predicted that by 2020, more than 25 percent of cyberattacks in healthcare delivery organizations would involve some kind of IoT device. In medical terms, that means wirelessly connected and digitally monitored implantable medical devices like pacemakers, deep brain neurostimulators and insulin pumps. These aren’t the esoteric things that mioght make the world go round, but are difficult to explain to the layperson. But the people who are literally kept alive by these devices, it their continued functionality is literally a matter of life and death.
You feel me?
In 2018 Cybesecurity Ventures released research stating that medical devices have an average of 6.2 vulnerabilities each. Furthers, they found that 60% of medical devices were at end-of-life stage with no patches or upgrades available.
The scariest of all cyber malintent in the healthcare space may lie ahead. Researchers in Israel announced last year that they’d created a computer virus capable of adding tumors into CT and MRI scans. They are talking about malware designed to fool doctors into misdiagnosing high-profile patients, according to a story by Kim Zetter in The Washington Post.
So what do we do?
On today’s No Name Security Podcast, Matt Stephenson welcomes Mitch Greenfield, Director of Core Security Architecture at Humana. We go all over the healthcare security map in a chat ranging from returning to work to securing telehealth operations to the intricacies of securing a wildly diverse enterprise... we might even squeeze in a little bit of pickle ball. Yeah… you read that right. Great stuff this on this episode! Check it out…
About Mitch Greenfield
Mitch Greenfield is Director of Core Security Architecture at Humana. He’s been there for over 13 years and has served in previous roles which included ethical hacking and penetration testing for Humana as well as their partners and aqcuisitions.
Mitch is a Certified Ethical Hacker and Licensed Penetration Tester, among many other things.
He also co-hosts the Collaboration Chronicles podcast
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
INFRA:HALT vulnerabilities impact the closed source TCP/IP stack NicheStack that is used in millions of Operational Technologies and Industrial Control Systems, especially in the discrete and process manufacturing industries. Among the vulnerabilities are DNS cache poisoning, TCP spoofing, Denial of Service and Remote Code Execution. Successful attacks can result in taking OT and ICS devices offline and having their logic hijacked. Hijacked devices can spread malware to where they communicate on the network.
Forescout Research Labs partnered with JFrog Security Research to disclose INFRA:HALT, a set of 14 new vulnerabilities affecting the HCC-owned, closed source TCP/IP stack NicheStack. NicheStack was originally developed by InterNiche Technologies and has been in use for 20 years across critical infrastructure sectors. Nearly all major industrial automation vendors incorporate NicheStack in their products and solutions.
On today’s No Name Security Podcast, Matt Stephenson welcomes Forescout Researchers Daniel dos Santos, Stanislav Dashevskyi and Engineer Anil Mahale for a discussion of Forescout's and JFrog’s joint research project INFRA:HALT. We dive into what the NicheStack TCP/IP stack is, how it is vulnerable and what that means to the cybersecurity world and you. Seems like some pretty esoteric stuff, yeah? You’ll be surprised how much this impacts your life.
About Daniel dos Santos
Daniel dos Santos is a Research Manager at Forescout Technologies, where he leads a vulnerability and threat research team. He also collaborates on the research and development of innovative features for network security monitoring.
Daniel holds a PhD in computer science from the University of Trento, Italy, and has published over 30 journal and conference papers on cybersecurity. He has experience in software development, security testing, and research
About Stanislav Dashevskyi
Stanislav Dashevskyi is a Sr. Security Researcher at Forescout Research Labs. His main research interests are network and software security. He is usually happiest doing vulnerability research.
Stan earned his Master's degree in Automation and Control Systems from the National Mining University of Ukraine, and his Ph.D. from the International Doctorate School in Information and Communication Technologies at the University of Trento
About Anil Mahale
Anil Mahale is a Software Engineering Manager at Forescout Technologies. He has over 10 years in the cybersecurity industry both on the product development and engineering side as well as threat and vulnerability research.
Anil earned his Masters in Computer Science at the University of Texas at Dallas and his Bachelors in Electronics and Communications Engineering at Visvesvaraya Technological University
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
INFRA:HALT vulnerabilities impact the closed source TCP/IP stack NicheStack that is used in millions of Operational Technologies and Industrial Control Systems, especially in the discrete and process manufacturing industries. Among the vulnerabilities are DNS cache poisoning, TCP spoofing, Denial of Service and Remote Code Execution. Successful attacks can result in taking OT and ICS devices offline and having their logic hijacked. Hijacked devices can spread malware to where they communicate on the network.
Forescout Research Labs partnered with JFrog Security Research to disclose INFRA:HALT, a set of 14 new vulnerabilities affecting the HCC-owned, closed source TCP/IP stack NicheStack. NicheStack was originally developed by InterNiche Technologies and has been in use for 20 years across critical infrastructure sectors. Nearly all major industrial automation vendors incorporate NicheStack in their products and solutions.
On today’s No Name Security Podcast, Matt Stephenson welcomes Forescout Researchers Daniel dos Santos, Stanislav Dashevskyi and Engineer Anil Mahale for a discussion of Forescout's and JFrog’s joint research project INFRA:HALT. We dive into what the NicheStack TCP/IP stack is, how it is vulnerable and what that means to the cybersecurity world and you. Seems like some pretty esoteric stuff, yeah? You’ll be surprised how much this impacts your life.
About Daniel dos Santos
Daniel dos Santos is a Research Manager at Forescout Technologies, where he leads a vulnerability and threat research team. He also collaborates on the research and development of innovative features for network security monitoring.
Daniel holds a PhD in computer science from the University of Trento, Italy, and has published over 30 journal and conference papers on cybersecurity. He has experience in software development, security testing, and research
About Stanislav Dashevskyi
Stanislav Dashevskyi is a Sr. Security Researcher at Forescout Research Labs. His main research interests are network and software security. He is usually happiest doing vulnerability research.
Stan earned his Master's degree in Automation and Control Systems from the National Mining University of Ukraine, and his Ph.D. from the International Doctorate School in Information and Communication Technologies at the University of Trento
About Anil Mahale
Anil Mahale is a Software Engineering Manager at Forescout Technologies. He has over 10 years in the cybersecurity industry both on the product development and engineering side as well as threat and vulnerability research.
Anil earned his Masters in Computer Science at the University of Texas at Dallas and his Bachelors in Electronics and Communications Engineering at Visvesvaraya Technological University
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Perfection is achieved, not when there is nothing more to add, but when there is nothing left to take away.
-- Antoine de Saint-Exupéry; French writer, poet, aristocrat, journalist and pioneering aviator
Me with nothing left to lose, plotting my big revenge in the spotlight. Give me violent revenge fantasies as a coping mechanism
-- Chuck Palahniuk; author
We’ve been looking for the enemy for some time now. We’ve finally found him. We’re surrounded. That simplifies things
-- Chesty Puller, US Marines
Matt Stephenson welcomes Ampere Industrial Security CEO Patrick Miller and Forescout Principal OT Strategist in for a chat about what is left to hack in the world of Critical Infrastructure. Because Critical Infrastructure seems to be a term that evolves every day, we run all over the place talking about what is vulnerable and why… what is safe and how to protect everything in between. And just to make sure you know we are authentic… Proctor was broadcasting from the floor of a manufacturing facility in full OSHA required protective gear (literally a hard hat, goggles and a day-glo vest)
About Patrick Miller
Patrick Miller (@patrickcmiller) shares over 35 years of IT/OT experience through his consulting services as an independent security and regulatory advisor for the Critical Infrastructure and Key Resource sectors. He is currently the CEO of Ampere Industrial Security, an industrial security consultancy based in Portland, OR USA. Patrick is also the founder, president emeritus and currently serves on the board of directors for the Energy Sector Security Consortium, Inc, nonprofit organization in Portland, OR as well as the US Coordinator for the Industrial Cybersecurity Center, based in Spain.
Patrick is currently an instructor for the SANS ICS456 training on the NERC CIP standards.
About Brian Proctor
Brian Proctor (@brianproctor67) is the Principal OT Strategist at Forescout. He spent the majority of his previous professional life as an ICS/SCADA cybersecurity engineer and cybersecurity team lead working for two progressive California Investor Owned Utilities (IOUs). In joined an ICS security startup which was then acquired by Forescout Technologies. Brian jumped to the vendor side to promote the benefits ICS/SCADA/DCS threat detection, network security monitoring, and visualization capabilities can bring critical infrastructure asset owners. He is passionate about helping the ICS security community in any way possible and trying to make a difference for the greater good of our industry and country.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Perfection is achieved, not when there is nothing more to add, but when there is nothing left to take away.
-- Antoine de Saint-Exupéry; French writer, poet, aristocrat, journalist and pioneering aviator
Me with nothing left to lose, plotting my big revenge in the spotlight. Give me violent revenge fantasies as a coping mechanism
-- Chuck Palahniuk; author
We’ve been looking for the enemy for some time now. We’ve finally found him. We’re surrounded. That simplifies things
-- Chesty Puller, US Marines
Matt Stephenson welcomes Ampere Industrial Security CEO Patrick Miller and Forescout Principal OT Strategist in for a chat about what is left to hack in the world of Critical Infrastructure. Because Critical Infrastructure seems to be a term that evolves every day, we run all over the place talking about what is vulnerable and why… what is safe and how to protect everything in between. And just to make sure you know we are authentic… Proctor was broadcasting from the floor of a manufacturing facility in full OSHA required protective gear (literally a hard hat, goggles and a day-glo vest)
About Patrick Miller
Patrick Miller (@patrickcmiller) shares over 35 years of IT/OT experience through his consulting services as an independent security and regulatory advisor for the Critical Infrastructure and Key Resource sectors. He is currently the CEO of Ampere Industrial Security, an industrial security consultancy based in Portland, OR USA. Patrick is also the founder, president emeritus and currently serves on the board of directors for the Energy Sector Security Consortium, Inc, nonprofit organization in Portland, OR as well as the US Coordinator for the Industrial Cybersecurity Center, based in Spain.
Patrick is currently an instructor for the SANS ICS456 training on the NERC CIP standards.
About Brian Proctor
Brian Proctor (@brianproctor67) is the Principal OT Strategist at Forescout. He spent the majority of his previous professional life as an ICS/SCADA cybersecurity engineer and cybersecurity team lead working for two progressive California Investor Owned Utilities (IOUs). In joined an ICS security startup which was then acquired by Forescout Technologies. Brian jumped to the vendor side to promote the benefits ICS/SCADA/DCS threat detection, network security monitoring, and visualization capabilities can bring critical infrastructure asset owners. He is passionate about helping the ICS security community in any way possible and trying to make a difference for the greater good of our industry and country.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Coolness is an aesthetic of attitude, behavior, comportment, appearance and style which is generally admired. Because of the varied and changing connotations of cool, as well as its subjective nature, the word has no single meaning. It has associations of composure and self-control and often is used as an expression of admiration or approval. Although commonly regarded as slang, it is widely used among disparate social groups and has endured in usage for generations.
-- Wikipedia
On today’s No Name Security Podcast, Matt Stephenson welcomes 3 people doing very cool things in a very cool industry… and… they happen to be to very cool people. Kurtis Minder is the co-founder and CEO at GroupSense, Tom Pace is the co-founder and CEO at NetRise and Scott Scheferman is the Chief Strategist at Eclypsium. They are each legendary incident response types who were at Black Hat for a multitude of reasons. Why were they there…? Stick around and find out!
About Kurtis Minder
Kurtis Minder (@kurtisminder) is the founder of GroupSense, a threat intelligence company. He leads a team of analysts and technologists providing custom cybersecurity intelligence to brands around the globe. The company’s analysts conduct cyber research and reconnaissance and map the threats to client risk profiles. He arrived at GroupSense after more than 20 years in role-spanning operations, design and business development at companies such as Mirage Networks (acquired by Trustwave), Caymas Systems (acquired by Citrix) and Fortinet (IPO).
About Tom Pace
Tom Pace (@TommyPastry) is the co-founder and CEO of NetRise, an automated, cloud-based platform that provides comprehensive insight into the risks present in a firmware image.
Prior to founding NetRise, Tom spent 16 years working in security across multiple roles and disciplines. From serving in the United States Marine Corps, being responsible for ICS security within the Department of Energy and most recently serving as Global Vice President for Cylance, he has been a leader and innovator within cybersecurity. Tom has also responded to hundreds of security incidents globally and shared his experience at multiple security conferences such as RSA and Black Hat.
About Scott Scheferman
Scott Scheferman (@transhackerism) is the founder of Armanda Intelligence, LLC, with a mission of providing CxO/board advisement, strategy and threat intelligence. He is also Principal Strategist for Eclypsium, Inc.
Scott keeps a hyper-current beat on the threat landscape and how it continues to fundamentally change business and mission cyber risk dynamics. Battle-hardened from years of red-teaming, incident response and cyber consulting, as well as having served as the technical lead and final security risk determination for the Navy’s Certification Authority (thousands of systems per year, with over 800 validators and 30 risk analysts feeding these risk determinations), Scott draws his perspective from significant real-world high-stakes (multi-billion dollar programs and Fortune 10 enterprise) experience.
If you want the truth about what is happening in the world of cybersecurity, Scott is a voice you want to be listening to. If you can’t handle the truth… he may not be your guy… but that doesn’t mean he won’t keep telling it.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“In the best conversations, you don't even remember what you talked about, only how it felt. It felt like we were in some place your body can't visit, some place with no ceiling and no walls and no floor and no instruments”
― John Green, Turtles All the Way Down
For Episode Two of our Black Hat coverage, we sat down for a chat with two Founders to see what their experience of Black Hat 2021 looked like. This was a raw, real conversation… no edits… no podcast host questions… just an ear into the types of conversations that we have missed out on over the past 19 months.
Today’s No Name Security Podcast sees Matt Stephenson joined by People By Mimi founder Mimi Gross and Cyvatar Co-Founder and CEO Corey White having a chat about all that is going on that week. We dig into what Cyvatar is doing to change the cybersecurity industry and how People By Mimi is changing the cybersecurity recruiting game with their approach to uniting people and companies by considering that releationship from a completely different POV. Think they don’t have anything in common? Think again… check it out!
About Mimi Gross
Mimi Gross (@MimiGross13) is the Founder and CEO of People by Mimi.
About Corey White
Corey White is the Chief Executive and Experience Officer at Cyvatar.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Elijah Snow: It's a strange world
Jakita Wagner: Let's keep it that way"
-- Planetary: Warren Ellis & John Cassaday
Black Hat 2021 was unlike any other previous edition and likely will be unlike any that follow. The rise of the Delta Variant of COVID-19 put the world back on edge after we had been slowly creeping toward something that felt like normalcy. When the show was announced, the cybersecurity industry rejoiced as this meant it was time to really get back to how we had been doing things… that meant Black Hat and DEFCON.
Delta decided to throw us a curve and as a result, many companies, SMEs and potential attendees made the informed decision to skip this year’s show out of justifiable concerns about the repurcussions of their attendance.
Some of us made the informed decision to take the risk, do the needful and attend Black Hat 2021 in person. It was hot. Like… for real hot… one day was 119F. However, we would not be deterred from getting out there and squeezing the Black Hat fruit for all the juice we could get. For sure, it was smaller than usual. Far fewer vendors, far fewer in-person sessions, far fewer attendees… and while they aren’t nearly as relevant… the parties and events still carried on, albeit in smaller and COVID-responsible fashion.
There were some great things that came out of attending Black Hat in person. In no way does this cast aspersions upon those who chose not to attend for whatever reason. If you could not be there, we worked to bring the kinds of conversations that we have all been a part of or overheard in previous shows. We’re going to get back to it. And our industry will be better and stronger for the lessons we have learned over the past 19 months.
For Episode One of our Black Hat coverage, we spoke with a range of cybersecurity professionals to get they takes on a myriad of topics.
Scott Scheferman: Chief Strategist at Eclypsium
Mike Bova: Enterprise Account Executive at Acronis
Cameron Zink: Manager of Technology Infrastructure at Campbell Global
Shaun Walsh: Vice President Product Marketing at SecurityScorecard
Mackenzie Kyle: Head of Product and Rohith Kondeti: Forward Deployed Engineer; both at Anvilogic
This week’s No Name Security Podcast is a mixtape of interviews Matt Stephenson conducted live on the show floor at Black Hat 2021. We run the gamut from hardcore security for firmware, to personnel management for first-time managers to the role of backup/recovery in a security posture to the evolution of SOC analysts out into the world of product development and customer facing engineering. There was still a LOT of action at Black Hat 2021, even if it was radically different from previous years… dig it!
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Elijah Snow: It's a strange world
Jakita Wagner: Let's keep it that way"
-- Planetary: Warren Ellis & John Cassaday
Black Hat 2021 was unlike any other previous edition and likely will be unlike any that follow. The rise of the Delta Variant of COVID-19 put the world back on edge after we had been slowly creeping toward something that felt like normalcy. When the show was announced, the cybersecurity industry rejoiced as this meant it was time to really get back to how we had been doing things… that meant Black Hat and DEFCON.
Delta decided to throw us a curve and as a result, many companies, SMEs and potential attendees made the informed decision to skip this year’s show out of justifiable concerns about the repurcussions of their attendance.
Some of us made the informed decision to take the risk, do the needful and attend Black Hat 2021 in person. It was hot. Like… for real hot… one day was 119F. However, we would not be deterred from getting out there and squeezing the Black Hat fruit for all the juice we could get. For sure, it was smaller than usual. Far fewer vendors, far fewer in-person sessions, far fewer attendees… and while they aren’t nearly as relevant… the parties and events still carried on, albeit in smaller and COVID-responsible fashion.
There were some great things that came out of attending Black Hat in person. In no way does this cast aspersions upon those who chose not to attend for whatever reason. If you could not be there, we worked to bring the kinds of conversations that we have all been a part of or overheard in previous shows. We’re going to get back to it. And our industry will be better and stronger for the lessons we have learned over the past 19 months.
For Episode One of our Black Hat coverage, we spoke with a range of cybersecurity professionals to get they takes on a myriad of topics.
Scott Scheferman: Chief Strategist at Eclypsium
Mike Bova: Enterprise Account Executive at Acronis
Cameron Zink: Manager of Technology Infrastructure at Campbell Global
Shaun Walsh: Vice President Product Marketing at SecurityScorecard
Mackenzie Kyle: Head of Product and Rohith Kondeti: Forward Deployed Engineer; both at Anvilogic
This week’s No Name Security Podcast is a mixtape of interviews Matt Stephenson conducted live on the show floor at Black Hat 2021. We run the gamut from hardcore security for firmware, to personnel management for first-time managers to the role of backup/recovery in a security posture to the evolution of SOC analysts out into the world of product development and customer facing engineering. There was still a LOT of action at Black Hat 2021, even if it was radically different from previous years… dig it!
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
-- Calvin and Hobbes courtesy of Bill Waterson
None of us wants to be judged by our worst act on our worst day, and we consistently judge Burr for that. He was not a perfect man, but he's not a villain. He's a dude, just a guy.
-- Leslie Odom, Jr.
What if the worst day of your life ended up being just another Zoom meeting on someone else’s calendar? What if that day ended up being a part of a data breach due to a cyberattack from someone half a world away who didn’t know or care anything about you or the impact it would have on your life and the lives of those around you? How important are the people who are protecting the mechanisms of judicial branch of government? It may not be something that we cared about when everything worked the way we were used to… but when anyone with a good internet connection and a a few hacking tools can become part of the justice system… things get a bit more complicated.
On this week’s No Name Security podcast Matt Stephenson welcomes New Jersey Courts CISO Sajed Naseem for a chat about what it takes to secure an operation that affects the daily lives of over 10,000 employees, 100,000+ attorneys, police officers and government officials… and, not for nothin’… the entire population of the state of New Jersey. Think a CISO’s job is tough? How about being the CISO who is protecting the data of an entire state… while being a Knicks fan.
About Sajed Naseem
Sajed Naseem is the Chief Information Security Officer of New Jersey Courts. Saj has over 20 years of experience with information security and information technology. As the CISO of the New Jersey Courts, Naseem has focused on cybersecurity readiness and performance, information governance, and network security. He holds master degrees from St. John’s University and Columbia University. Saj is routinely a speaker at cybersecurity conferences across the country, Europe, and with the New Jersey Bar Association. He is also an Adjunct Professor at St. John’s University in information security since 2010 and a native of New York City. Saj is a Knicks fan and thinks that they may have actually turned the corner… but… he is also a realist, so he’s waiting to see what happens next.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
-- Photo credit: Huss Harden
When you lived on the wrong side of the law, information, however vague or apparently meaningless, was everything. It gave you leverage. And leverage was power
-- Top Dog; 2014, written by Dougie Brimson
Ransomware is the biggest buzzword in the news right now, and rightfully so. You can’t turn on a network police procedural without someone getting extorted for $100,000 in Bitcoin. But are the news agencies getting the story completely accurate? Yes, the money is always a nice prize to take home, but there is a larger looming question out there… What are these ransomware attacks really all about?
Matt Stephenson welcomes Eclypsium Chief Strategist Scott Scheferman to the No Name Security podcast for a long overdue discussion on the impact of ransomware on the overall approach of the cybersecurity industry and those who rely on us for defense, protection and prevention. After fighting the good fight together at Cylance, Scott finally joins Matt for a chat about all the bad things the bad guys are getting up to… the mistakes the good guys tend to make… and how we can fix them in order to protect those who really need it.
About Scott Scheferman
Scott Scheferman (@transhackerism) is the founder of Armanda Intelligence, LLC, with a mission of providing CxO/board advisement, strategy and threat intelligence. He is also Principal Strategist for Eclypsium, Inc.
Scott keeps a hyper-current beat on the threat landscape and how it continues to fundamentally change business and mission cyber risk dynamics. Battle-hardened from years of red-teaming, incident response and cyber consulting, as well as having served as the technical lead and final security risk determination for the Navy’s Certification Authority (thousands of systems per year, with over 800 validators and 30 risk analysts feeding these risk determinations), Scott draws his perspective from significant real-world high-stakes (multi-billion dollar programs and Fortune 10 enterprise) experience.
If you want the truth about what is happening in the world of cybersecurity, Scott is a voice you want to be listening to. If you can’t handle the truth… he may not be your guy… but that doesn’t mean he won’t keep telling it.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“The bad guys know they are bad guys—they are trying to pretend to be businesspeople… as long as you pretend with them that this is just a normal business transaction, it goes better.”
-- Kurtis Minder; Fortune, 01 June 2021
If you have been reading about or watching news shows discussing ransomware, more than likely, you have seen Kurtis Minder. He has been nearly omnipresent across multiple platforms because his team at Groupsense has been putting in the work to help the victims of ransomware attacks negotiate with attackers in order to get their data back.
Here’s the best part… we’re not talking about that. Not that it’s not important, but there is a lot more that Kurtis and his team have been up to. Kurtis has brought the knowledge on that specific topic to television, podcasts and many other mediums in order to spread the word.
He has a lot more to say about the state of cybersecurity.
That is what we are here to talk about. Okay… we do talk about ransomware negotiation a bit, BUT… we dig deep into so much more.
Matt Stephenson welcomes Groupsense CEO and co-founder Kurtis Minder for a discussion about the Seven Dirty Words of Cybersecurity. Depending on your definition of a Dirty Word, this may be a cautionary or inspirational tale. Either way, Kurtis and his team are busting their asses to help secure the data, prevent attacks and… in the worst case scenario… help victims get their data back so they can continue to do their work. And he may be doing it while riding cross country on a motorcycle…
About Kurtis Minder
Kurtis Minder (@kurtisminder) is the founder of GroupSense, a threat intelligence company. He leads a team of analysts and technologists providing custom cybersecurity intelligence to brands around the globe. The company’s analysts conduct cyber research and reconnaissance and map the threats to client risk profiles. He arrived at GroupSense after more than 20 years in role-spanning operations, design and business development at companies such as Mirage Networks (acquired by Trustwave), Caymas Systems (acquired by Citrix) and Fortinet (IPO).
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
How at Risk Are Our Healthcare Networks?
Civilian hospitals organized to give care to the wounded and sick, the infirm and maternity cases, may in no circumstances be the object of attack, but shall at all times be respected and protected by the Parties to the conflict.
-- Geneva Conventions; Article 18, Section 3, Fourth Geneva Convention
Even at humanity’s worst, we could reach agreements on the kind of behavior that was acceptable in times of war. Attacks on healthcare delivery organizations around the world are ramping and it appears that the attackers have little regard for the collateral damage ransomware attacks cause. How can the industry evolve to ensure that devices that are integral to keeping people alive are also protected from attackers
Matt Stephenson welcomes CynergisTek Executive Vice President David Finn alongside Forescout Senior Director of Healthcare Tony Douglas for an in-depth discussion of what is happening in the world of securing Healthcare Delivery organizations. We talk about leveraging the native complexity of healthcare technology and what can be done to mitigate risk in order to protect the lives of patients as well as the data inside the networks.
About David Finn
David Finn (@DavidSFinn) is the Executive Vice President, External Affairs, Information Systems & Security at CynergisTek. He has been involved in leading the planning, management and control of enterprise-wide, mission-critical information technology and business processes for more than 30 years. He was Vice President, CIO and Privacy/Information Officer at Texas Children’s Hospital for nearly eight years. This unique experience in risk management and control objectives of technology (including audit, security, and privacy) allows him a distinctive perspective in the design and implementation of business applications and the processes that the technology must support. He is known for creatively engaging all types of audiences, conveying messages that even change-resistant users listen to and remember. David is a member of the Health Management Technology Editorial Advisory Board.
True story… David presented Ray Charles with his 40th birthday cake. That is a thing that happened.
About Tony Douglas
Tony Douglas is the Senior Director of Healthcare at Forescout. He is an accomplished IT professional with over 19 years of experience, focused in the vertical markets, namely the healthcare industry. Tony operates as strategic partner with the Executive team, where he is passionate about the role of information technology and the possibilities it offers for improving the quality and efficiency of patient care.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, I hosted podcasts, videos and live events all over the world which put me with experts on every corner of the cybersecurity landscape. The new No Name Security Podcast will continue and expand upon that tradition as we seak out the leading minds in the security industry as well as those may break things every now again. And… just for fun, there will be some wildcard guests as well.
In 10 years in the ecosystem of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to information security, these technologies can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you tuned in to any of my previous podcasts, there’s great news! The No Name Security Podcast is here! I will be bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the same spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
When the DarkSide hacking group attacked the Colonial Pipeline, they may have gotten a bit more than they bargained for. Colonial has acknowledged paying $4.4 million in ransom in order to bring their systems back online as quickly as possible. It was a decision they had to make quickly, but had to consider a myriad of variables in the process. Joseph Blount, Colonial CEO stated “I know that’s a highly controversial decision… I didn’t make it lightly. I will admit that I wasn’t comfortable seeing money go out the door to people like this… But it was the right thing to do for the country,”
Pundits everywhere weighed in with thoughts about how long the pipeline could be down, the impact on pricing, shortages of petroleum products ranging from gas to heating fuel. Other questions bubbled up as well. How did the do it? Was it politically motivated? How easy would it be for the next attack?
Over the last few days, we have seen some pretty remarkable blowback on DarkSide. Even their fellow bad guys don’t want to play with them any more.
So… now what?
Matt Stephenson welcomes Duke Energy Technology Manager David Lawrence alongside Forescout Principal OT Strategist Brian Proctor and Sr Systems Engineer Shawn Taylor for a lively chat about the attack on Colonial and the impact it may have on the worlds of critical infrastructure and operational technology. This isn’t just another academic discussion of security… we have a harmonica! Seriously… we do… check it out!
About David Lawrence
David Lawrence is the Tehchnology Manager of the Emerging Tchnology at Duke Energy. There he provides leadership on a portfolio of technologies for the Future Grid, including development of use cases and requirements, architectures and designs, and technology test plans. He works in defining and executing technology evaluations, and providing change management support. David is currently focused on Grid distributed autonomous functions, edge analytics, and security for distributed technologies. He has 38 years of experience in the energy industry. He has worked in research and development and IT management for electric metering, transformer, and switchgear product manufacturing. His roles included embedded systems and protocol development, engineering management, global engineering information systems, manufacturing execution and scheduling systems, product lifecycle management, and IT management.
About Brian Proctor
Brian Proctor (@brianproctor67) is the Principal OT Strategist at Forescout. He spent the majority of his previous professional life as an ICS/SCADA cybersecurity engineer and cybersecurity team lead working for two progressive California Investor Owned Utilities (IOUs). In joined an ICS security startup which was then acquired by Forescout Technologies. Brian jumped to the vendor side to promote the benefits ICS/SCADA/DCS threat detection, network security monitoring, and visualization capabilities can bring critical infrastructure asset owners. He is passionate about helping the ICS security community in any way possible and trying to make a difference for the greater good of our industry and country.
About Shawn Taylor
Shawn Taylor (@smtaylor12) is a Senior Systems Engineer at Forescout. He is an accomplished and well-respected Public Speaker and Systems Engineer. With a strong mix of technical acumen, architectural experience, and sales savvy Shawn is a trusted advisor the customers he's worked with over his 20-year career. His background includes Cybersecurity, Biometrics and Identity Management, IT Operations and Service Management and IT Asset Management.
As a ForeScout Systems Engineer, Shawn expanded his technical knowledge into cybersecurity, while still leveraging his foundation of IT Operations and Service Management. He is responsible for integrating the ForeScout CounterACT solution with many of the industry-leading Cybersecurity products while in support of sales opportunities.
Shawn has spoken at industry events around the country and too many online events to list. Additionally, Shawn helps to drive thought leadership around Forescout and continuous visibility being foundational to enterprise ITSM initiatives by authoring White Papers and blogs.
About Matt Stephenson
Matt Stephenson (@packmatt73) leads the Social Media team at Forescout, which puts me in front of people all over the world. Prior to joining Forescout, as the host of the InSecurity I have been talking with experts about every corner of the cybersecurity landscape.
In 10 years in the world of Data Protection and Cybersecurity I have toured the world extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Whether at in person events, live virtual events or podcasting, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
Wherever I go, my job is all about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
If you are listener to Insecurity, there’s great news! An all new show is coming bringing the same kind of energy and array of guests you know and love. Best part? We’re still at the spot. You can find it at Spotify, Apple, Amazon Music & Audible as well as, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“I'm telling you a lie in a vicious effort that you will repeat my lie over and over until it becomes true”
-- Lady Gaga
“The point of modern propaganda isn't only to misinform or push an agenda. It is to exhaust your critical thinking, to annihilate truth.”
-- Garry Kasparov
In this week’s Very Special Episode, Matt Stephenson shares a LinkedIn LIVE event featuring Jamil Jaffer and Brandon Soroudi for a chat about the role cybersecurity has and must play in the ongoing battle against Disinformation, Misinformation and Propaganda. Are they the same? How do we know the difference? Where does social manipulation come into the conversation? That’s what we are about to find out…
About Jamil Jaffer
Jamil Jaffer (@jamil_n_jaffer) is the Founder and Executive Director of the National Security Institute, and an Assistant Professor of Law and Director of the National Security Law & Policy Program at the Antonin Scalia Law School at George Mason University. Jamil is also the Vice President for Strategy, Partnerships & Corporate Development at IronNet Cybersecurity, a technology products startup founded by Gen (ret.) Keith B. Alexander, the former Director of the National Security Agency and Founding Commander of U.S. Cyber Command. In addition, Jamil is an advisor to Beacon Global Strategies, a strategic advisory firm; 4iQ, a deep and dark web intelligence startup; Duco, a technology platform startup that connects corporations with geopolitical and international business experts; and Amber, a digital authentication and verification startup.
Among other things, Jamil currently serves on the Board of Directors for the Greater Washington Board of Trade, the Board of Advisors for the Global Cyber Alliance, and the Advisory Board of the Foundation for the Defense of Democracies’ Center on Cyber and Tech Innovation, and is a member of the Center for a New American Security’s Artificial Intelligence and National Security Task Force and the CNAS Digital Freedom Forum. Jamil is also affiliated with Stanford University’s Center for International Security and Cooperation.
Prior to his current positions, Jamil served on Capitol Hill in a variety of roles, including on the leadership team of the Senate Foreign Relations Committee and as a senior staff member of the House Intelligence Committee. Jamil also previously served in the Bush Administration in a number of positions, including on the leadership team of the Justice Department’s National Security Division and in the White House as an Associate Counsel to President George W. Bush. Jamil holds degrees with honors from UCLA, the University of Chicago Law School, and the United States Naval War College.
About Brandon Sorouti
Brandon Soroudi is an experienced security engineer, and system administrator with over 9 years of experience. He currently is a Consultant on BlackBerry’s ThreatZERO team. We’d tell you more if we could, but since he is an experienced security engineer, that’s all he would tell us. He did write the original post that inspired this talk… https://lnkd.in/gwG7N-v
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple, Amazon Music & Audible as well as ThreatVector, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
I believe that we should be teaching our kids, students and employees when and how to lie
-- Maurice Schweitzer; professor, Wharton School at the University of Pennsylvania
And, after all, what is a lie? 'Tis but
The truth in masquerade.
-- Lord Byron; Don Juan, Canto 11
This week, Matt Stephenson welcomes Attivo Networks CTO Tony Cole to InSecurity for chat about the role deception techniques play in security. But that’s not all… we get into how the privatization of space will impact cybersecurity… where cybersecurity fits into Black Swan events like the Wall Street Bets brouhaha… even a bit of Pink Floyd works into the mix!
About Tony Cole
Tony Cole (@NoHackn) is a cyber expert with over thirty-five years of experience as a strategist, risk expert, advisor, and board member. Today, he is the CTO at Attivo Networks, the global leader in lateral movement attack detection and privilege escalation prevention, working to defend enterprises from the impact of cyber-attacks.
Prior to joining Attivo Networks, Tony held executive positions at FireEye, McAfee and Symantec. He is retired from the U.S. Army, where he worked in intelligence, communications, and cryptography around the world including building out the Network Security Services at the Pentagon.
Tony served previously on numerous boards and government committees including (ISC)² Board of Directors as Treasurer and Chair of Audit and Risk, the NASA Advisory Council under appointment by the NASA Administrator, and the FCC CSRIC (Communications Security, Reliability, and Interoperability Council). Today he serves on the Gula Tech Foundation Grant Advisory Board helping the Foundation give back to the community and drive a more diverse cyber workforce.
In 2014, Tony received the Government Computer News Industry IT Executive of the Year award, and in 2015 he was inducted into the Wash 100 by Executive Mosaic as one of the most influential executives impacting Government. In 2018 he was awarded the Reboot Leadership Influencer Award by SC Media.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty sure they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple, Amazon Music & Audible as well as ThreatVector, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
We face cyber threats from state-sponsored hackers, hackers for hire, global cyber syndicates, and terrorists. They seek our state secrets, our trade secrets, our technology, and our ideas - things of incredible value to all of us. They seek to strike our critical infrastructure and to harm our economy.
-- James Comey
I'm a hacker, but I'm the good kind of hackers. And I've never been a criminal.
-- Mikko Hypponen
What happens on InSecurity when Matt Stephenson sits down with Rob Willis, a top-flight ethical hacker, red-teamer and all around cybersecurity expert to talk about… comic books? You get a brand new comic universe created by hackers for hackers that it rooted in actual technology and hacking. The Paraneon Universe is as much cyber-fact as it is science fiction. When you get bored with the same capes, cowls and armor… come check out what the real future is going to look like in Paraneon… where you can’t punch your way out of everything.
About Rob Willis
Rob Willis (@rej_ex)’s entire life has been centered around comic books and tech. If he wasn't a cybersecurity professional, there is zero doubt that he would be working in comics full-time.
To date Rob has self-funded the creation of these titles and other Paraneon assets and will continue to create and expand the Universe with exciting characters and storylines pressure.
By day he is an InfoSec professional. Rob runs consulting at 1337 Inc among other things. He is a Red team, Blue team, and purple team professional. He isnt just breaking into things for clients, he’s also building and running security programs.
He is also a part of the hacking collective Sakura Samurai. You may not know them yet, but you’ve likely read about their work already.
Rob is featured in the popular Tribe of Hackers series from Wiley. He has appeared in the original Tribe of Hackers and new book Tribe of Hackers: Blue Team.
In a Previous life, Rob was a Researcher at the Breach and Attack Simulation Pioneer ThreatCare.
He has worked places he can’t disclose, but which I have personally verified… It’s legitimate, as crazy as that sounds. His most mind numbing accomplishments cannot be talked about publicly, but if you become his friend he will likely show you some insane stuff -- as long as it doesnt compromise national security.
About Paraneon
Paraneon (@paraneonU) develops and publishes stories from a cyberpunk future. For hackers, by hackers.
The Paraneon Universe is comprised of technocentric cities, underground worker colonies, and apocalyptic 'drylands'. All factories and production has been moved to Mars due to pollution, and there's more Androids on Mars than Humans.
The Hive Network
The Hive is a massive incubator-like structure that humans are placed inside of while their minds integrate with a virtual reality world. Joining the Hive is voluntary, and requires each member to purchase their spot within it. Those in the Hive decided to be added to it, to ‘retire’ after working many years as a lower-class member of society, where most of their time was spent training — then working — in a specialized trade associated with the underground worker colony they were born into.
The world is advanced with technocentric cities, but living in a city requires decades of saving for a colony member who hopes to purchase citizenship in one. The class system dictates the resources and quality of life more than any period throughout history, and aside from the tribal peoples of the desolate drylands, colony members are the lowest part of society.
Why would someone choose to be a member of the Hive? It’s not a hard decision for someone to live the remainder of their life in a world where they can have and be whatever they choose.
It may not be real, but over time it becomes difficult to imagine virtual reality as anything but reality. For this reason many refer to the Hive as the ‘great equalizer’, convinced that their lives in reality are nothing but a painful stepping stone on the path to their digital salvation.
Portals
Portals takes place in the drylands. The 'drylanders' do not take kindly to tech or strangers. The first story arc introduces an undercover police officer from one of the cities who enters the drylands in an attempt to blend in, all while searching for 'dangerous' fugitives.
Neon Skyline
Sudo is a talented hacker who is placed in a research program surrounding bio-hacking on Mars. He uncovers a massive conspiracy when accidentally finding that many androids, billed as 'next-gen AI' are actually cyborgs, implanted with human brain tissue. Can he sound the alarm and 'free' the cyborgs before he gets killed?
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple, Amazon Music & Audible as well as ThreatVector, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“You got ninety percent of the American public out there with little or no net worth. I create nothing. I own. We make the rules, pal. The news, war, peace, famine, upheaval, the price per paper clip. We pick that rabbit out of the hat while everybody sits out there wondering how the hell we did it. Now you're not naive enough to think we're living in a democracy, are you buddy? It's the free market. And you're a part of it. You've got that killer instinct. Stick around pal, I've still got a lot to teach you”
-- Gordon Gekko; Wall Street, Oliver Stone, 1987
We’re stepping outside the normal conventions of cybersecurity for this one. Matt Stephenson welcomes in Advent Technologies President and CFO Bill Hunter to discuss the recent madness in the stock market. When Redditors started flexing their ability to move markets with tools like rocket emojis and a lexicon that brought “tendies” and “diamond hands” to the common language… was that a Hack? Take a listen and decide for your self.
About William Hunter
William Hunter is Chief Financial Officer & Director at Advent Technologies Holdings, Inc.
He is on the Board of Directors at American Battery Metals Corp. (Nevada), AMCI Euro-Holdings BV, Ridley Terminals, Inc. and Advent Technologies Holdings, Inc. Mr. Hunter was previously employed as a President, CEO, CFO & Director by AMCI Acquisition Corp., a Managing Director by Dahlman Rose & Co. LLC, a Vice President by BMO Nesbitt Burns, Inc. (US), an Associate by NatWest Markets Equity Corp., a Financial Analyst by KPMG LLP, a Principal by Jefferies LLC, and a Principal by TD Securities (USA) LLC.
He also served on the board at Nomura Securities International, Inc. and Teneo Capital LLC.
He received his undergraduate degree from DePaul University, an MBA from Kellstadt Graduate School of Business and an MBA from DePaul University
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple, Amazon Music & Audible as well as ThreatVector, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Securing embedded systems presents unique and complex challenges when it comes to organizing and assessing software assets during assurance activities. The closed source nature of the supply chain and volume of differing components has made this a onerous and costly activity
-- IIOT World
On this Very Special Episode of InSecurity, Matt Stephenson spoke with BlackBerry CTO Adam Boulton and IoT Security Services Lead Ian Todd about protecting embedded systems and how that applies to the automotive world and national public infrastructure. Do you know how to protect embedded systems? Do you know what they are? Do you know what that has to do with your water supply? These folks do… dig it
About Adam Boulton
Adam Boulton is a highly experienced and qualified software security professional, with over 15 years’ experience within security engineering. Having successfully accelerated through career progression, Adam is employed as the Chief Technology Officer for BlackBerry Technology Solutions
About Ian Todd
Ian Todd leads the BlackBerry IoT security services practice which has developed a set of security solutions for embedded systems across industries such as automotive, industrial, medical, defence and aerospace, transportation and robotics globally.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple, Amazon Music & Audible as well as ThreatVector, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Together we stand, divided we fall
Come on now people,
let's get on the ball and work together
Come on, come on let's work together, now now people
Because together we will stand,
every boy every girl and a man
-- Let’s Work Together, Canned Heat
A truly rollicking episode of InSecurity finds Matt Stephenson trying to keep up with National Security Institute Director Jamil Jaffer as we run all over the cybersecurity world. The private sector isn’t charged with defending their skies and shores, should they be responsible for defending their data and users? What can we learn from the US Capital Riots? Is there value in an offensive cybersecurity posture? Why would anyone play Goat Simulator? Yeah, we talk about that and more. Dig it…
About Jamil Jaffer
Jamil Jaffer (@jamil_n_jaffer) is the Founder and Executive Director of the National Security Institute, and an Assistant Professor of Law and Director of the National Security Law & Policy Program at the Antonin Scalia Law School at George Mason University. Jamil is also the Vice President for Strategy, Partnerships & Corporate Development at IronNet Cybersecurity, a technology products startup founded by Gen (ret.) Keith B. Alexander, the former Director of the National Security Agency and Founding Commander of U.S. Cyber Command. In addition, Jamil is an advisor to Beacon Global Strategies, a strategic advisory firm; 4iQ, a deep and dark web intelligence startup; Duco, a technology platform startup that connects corporations with geopolitical and international business experts; and Amber, a digital authentication and verification startup.
Among other things, Jamil currently serves on the Board of Directors for the Greater Washington Board of Trade, the Board of Advisors for the Global Cyber Alliance, and the Advisory Board of the Foundation for the Defense of Democracies’ Center on Cyber and Tech Innovation, and is a member of the Center for a New American Security’s Artificial Intelligence and National Security Task Force and the CNAS Digital Freedom Forum. Jamil is also affiliated with Stanford University’s Center for International Security and Cooperation.
Prior to his current positions, Jamil served on Capitol Hill in a variety of roles, including on the leadership team of the Senate Foreign Relations Committee and as a senior staff member of the House Intelligence Committee. Jamil also previously served in the Bush Administration in a number of positions, including on the leadership team of the Justice Department’s National Security Division and in the White House as an Associate Counsel to President George W. Bush. Jamil holds degrees with honors from UCLA, the University of Chicago Law School, and the United States Naval War College.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple, Amazon Music & Audible as well as ThreatVector, GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
The diversity of the global supply chain that makes it critical to modern society also makes it very difficult to know where all of the components of a device came from. Who designed each part, who made it, who put it into a device, who sold it, and who bought it? Inside the sheet metal or plastic shells of our personal and business equipment is a fractal maze of assemblies and subassemblies reaching down to the nanometer scale and beyond into the virtual world.
On this episode of InSecurity, Matt Stephenson welcomes Chris Blask back for a deep dive look into the Digital Bill of Materials (DBOM). What is it? Why do it? Who should care and why the should care? We also go deeper into issues like security, privacy and even storage that compound the degree of difficult in creating and storing a digital record of EVERYTHING. The DBOM could be one of the most important projects you’ve never heard of. Dig it.
About Chris Blask
Chris Blask’s (@chrisblask) career spans the breadth of the cybersecurity industry for more than 25 years.
He invented one of the first firewall products, built a multi-billion dollar firewall business at Cisco System, co-founded an early SIEM vendor, authored the first book on SIEM, founded an information sharing center for critical infrastructures, and has advised public and private organizations in every sector around the world.
In his role within the Office of Innovation at Unisys, Chris created and leads the Operational Technology and IoT practices, invented the Digital Bill of Materials (DBoM) structure, and established the Unisys Marine Living Research Center.
Today he chairs a range of non-profit cybersecurity organizations and contributes to a wide range of global security efforts.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts and ThreatVector as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“It's just a straight sequence, which is mind-numbing to me… This is like a Computer Science 101 bad homework assignment, the kind of stuff that you would do when you're first learning how web servers work. I wouldn't even call it a rookie mistake because, as a professional, you would never write something like this."
-- Kenneth White, codirector of the Open Crypto Audit Project
On this episode of InSecurity, Matt Stephenson sits down with Richard Stiennon for a chat about a LOT of things. He has a new book coming, dropped TWO books in 2020 and we find time to take a look at recent security events unfolding around social media site Parler and the cyber attack on the US Government. Could these events have been prevented with a better approach? The Parler breach was ludicrously simple. The Solarwinds event was infinitely more complicated, but would a CI/CD approach have made a difference? Find out what an industry expert thinks…
About Curmudgeon: How to Succeed as an Industry Analyst
Curmudgeon is the first (and only) book on how to become and excel as an industry analyst. It is written by a 20 year veteran of the business, the author of UP and to the RIGHT: Strategy and tactics of Analyst Influence. In addition to Stiennon's first hand experience at Gartner, then as an independent analyst covering the cybersecurity industry, there are contributions from analysts such as Tom Austin, Bob Hafner, Jon Oltsik, and others. If you have ever considered becoming an analyst this is the book you should read. If you interact with analysts you should read Curmudgeon to inform your understanding of the analyst life.
About Security Yearbook 2021
Security Yearbook 2021 is the second edition of an annual publication that records the history of the IT Security industry and provides a complete catalog of all the vendors. Thousands of copies will be in the hands of media, analysts, and most importantly, security technology buyers.
The industry directory is updated to reflect the changes to the vendorscape in 2020 including M&A, launches, and new funding. Over 3,000 vendors are listed by country and category. Each entry includes the number of employees and growth from the previous year. Security Yearbook 2021 is the only place this data is published. Security Yearbook is an indispensable desk reference for IT security practitioners, marketers, CISOs, and investors.
About Richard Stiennon
Richard Stiennon (@stiennon) is Chief Research Analyst for IT-Harvest, the firm he founded in 2005 to cover the 2,200 vendors that make up the IT security industry. He has presented on the topic of cybersecurity in 29 countries on six continents.
Richard is the author of Secure Cloud Transformation: The CIO'S Journey, Surviving Cyberwar and Washington Post Best Seller, There Will Be Cyberwar. He writes for Forbes and The Analyst Syndicate.
In previous lives, he was Chief Strategy Officer for Blancco Technology Group, Chief Marketing Officer for Fortinet, Inc. and VP Threat Research at Webroot Software. Prior to that he was VP Research at Gartner, Inc.
Richard has a B.S. in Aerospace Engineering and his MA in War in the Modern World from King’s College, London
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts and ThreatVector as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
ABC
"A", always
"B", be
"C", closing
ALWAYS BE CLOSING
Always be closing.
-- Blake; GlenGarry GlenRoss, David Mamet, 1992
Now we are taking some liberties there with that bit… but apply that philosophy to secure code development… now swap in Integrating or Developing for Closing…
ABD…
"A", always.
"B", be.
“D” Developing… or… well you get the point
On this episode of InSecurity, Matt Stephenson speaks with Manish Gupta, CEO of ShiftLeft about the importance of dynamic software development. Can focusing on Continuous Integration/Continuous Development prevent more scenarios like what we saw with Solarwinds? Manish has helped build some of the most important security solutions in the world. The bad guys are only getting better, so we need to make sure we are doing it better and faster than they are.
About Manish Gupta
Manish Gupta is the CEO of ShiftLeft, a company specializing in NextGen Static Analysis. He was previously the Chief Product and Strategy Officer at FireEye, helping grow the company from approximately $70 million to more than $700 million in revenue, growing the product portfolio from 2 to more than 20 products.
Prior to that, he was VP of Product Management for Cisco’s $2 billion security portfolio. He also served as a VP/GM at McAfee and iPolicy networks.
Manish has an MBA from the Kellogg Graduate School of Management, MS in Engineering from the University of Maryland and a BS in Engineering from the Delhi College of Engineering.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts and ThreatVector as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
I know not with what weapons World War III will be fought, but World War IV will be fought with sticks and stones
-- Albert Einstein
If we wish to fight, the enemy can be forced to an engagement even though he be sheltered behind a high rampart and a deep ditch. All we need do is attack some other place that he will be obliged to relieve. If we do not wish to fight, we can prevent the enemy from engaging us even though the lines of our encampment be merely traced out on the ground. All we need do is to throw something odd and unaccountable in his way.
-- Sun Tzu, The Art of War
On the new InSecurity, Matt Stephenson has a chat with author and Corner Alliance CEO Alan Pentz about playing the long game with China. When your rival has 4000 years of history and a BILLION more people, the contest takes on some different parameters. As we move into the 4th Industrial Revolution, who will better leverage technology like 5G, AI, automation and augmented reality? We’re bringing someone who is boots on the ground in the campaign to improve how government can work with private industry.
About Alan Pentz
Alan Pentz (@apentz) is the CEO of Corner Alliance. He has over twenty years of experience in government consulting with Corner Alliance, SRA, Touchstone Consulting, and Witt O'Brien's, and has worked with government leaders in the R&D and innovation communities across DHS, Commerce, NIH, state and local government, and the non-profit sector among others.
Before consulting, Alan served as a speechwriter and press secretary for former U.S. Senator Max Baucus and as a legislative assistant for former U.S. Representative Paul Kanjorski. He holds an MBA from the University of Texas at Austin.
Alan is a life long fan of the Philadelphia Eagles (yes, they booed Santa Claus) and his hero is Ben Franklin, a famous polymath, patriot, diplomat, scientist, politician, and was still the founding father you most want to have a beer with.
Winning the Long Competition: The Key to the Next American Century
For the first time since the Space Race, the United States is facing a serious competitor with a plan to achieve technological dominance: China. Between China 2025 and the Belt and Road Initiative, it’s become clear that the Chinese government is determined to capture the economic power that new technologies like AI, automation, 5G, and the cloud represent.
And with economic power comes military power, and then political power.
To win this competition, the US must return to the historical model it used to build the interstate highway system, put a man on the moon, and build the computer and the Internet—but has become an afterthought over the past few decades.
In Winning the Long Competition, Alan Pentz lays out a roadmap for increasing our investment and innovation in core areas. He shows government managers where to invest and points innovators to areas where the funding will be plentiful. As we move into the next American century, the only way forward is to harness all the resources and creativity of both our public and private sectors.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts and ThreatVector as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
ELLIE: How do you know you’re not deluding yourself? As for me, I’d need proof.
PALMER: Proof. Did you love your father?
ELLIE: Huh?
PALMER: Your Dad, did you love him?
ELLIE: Yes, very much.
PALMER: Prove it.
That is, of course, Jodie Foster as Ellie Arroway and Matthew McConaughey as Palmer Joss in Robert Zemeckis’s 1997 adaptation of Carl Sagan’s 1984 novel Contact
On this week’s InSecurity, Matt Stephenson got some time with ethical hacker Ted Harrington, author. He is the author HACKABLE: How to Do Application Security Right, Exec Partner at Independent Security Evaluators and co-creator of IoT Village at DEFCON and beyond! If you need more reasons to listen, he’s just awesome and has some really interesting insight into what developers, companies and even regular people need to consider in keeping their assets secure… dig it
About Ted Harrington
Ted Harrington (@SecurityTed) is the Executive Partner at Independent Security Evaluators (ISE).
ISE is a company of ethical hackers most commonly known for their work hacking cars, medical devices, web applications, and password managers. ISE is a leader of ethical hackers, helping companies build better, more secure software.
Ted is an author, keynote speaker, consultant, and podcast host, specializing in penetration testing, secure software development, and related areas of cybersecurity.
He recently published the best-selling book HACKABLE: How to Do Application Security Right.
ISE has helped hundreds of companies fix tens of thousands of security vulnerabilities, including Google, Amazon, and Netflix.
Ted and his team also founded and continue to organize IoT Village, an event whose hacking contest is a three-time DEF CON Black Badge winner.
Hackable: How to Do Application Security Right
If you don’t fix your security vulnerabilities, attackers will exploit them. It’s simply a matter of who finds them first. If you fail to prove that your software is secure, your sales are at risk too.
Whether you’re a technology executive, developer, or security professional, you are responsible for securing your application. However, you may be uncertain about what works, what doesn’t, how hackers exploit applications, or how much to spend. Or maybe you think you do know, but don’t realize what you’re doing wrong.
To defend against attackers, you must think like them. As a leader of ethical hackers, Ted Harrington helps the world’s foremost companies secure their technology. Hackable teaches you exactly how. You’ll learn how to eradicate security vulnerabilities, establish a threat model, and build security into the development process. You’ll build better, more secure products. You’ll gain a competitive edge, earn trust, and win sales.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts and ThreatVector as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“Diversity and independence are important because the best collective decisions are the product of disagreement and contest, not consensus or compromise.”
-- The Wisdom of Crowds; James Surowiecki,
On this week’s InSecurity, Matt Stephenson has a chat with Pulsedive co-founders Grace Chi and Dan Sherry about the joy and pain of security startup life. In the world of the Threat Intelligence research, the best people are often looking for the best tools. Why not build a community around some stellar tools so the Wisdom of the Crowd can push security in the directions it needs to go? Grace and Dan want to help heard the cats to solve the problems
About Grace Chi
Grace Chi (@euphoricfall) is Co-Founder and COO of Pulsedive. Her wealth of experience includes directing complex growth campaigns and operations across technology, cybersecurity, and real estate markets. She draws on interdisciplinary interests, fearlessness in the face of criticism, and history in product marketing, strategic development, and customer success to identify and execute on the most impactful areas for growth. Grace is an avid watercolorist on weekends and a hyper-serious cooperative board gamer.
About Dan Sherry
Dan Sherry (@netbroom) is Co-Founder and CEO of Pulsedive. He has years of industry experience doing incident response, security engineering, and security operations across both government and Fortune 500 financial services. He is all too familiar with the struggles of filtering noise from open source threat intelligence, and sees Pulsedive as the first step to solving this problem. Dan’s top advisors are his three cats. He plays the ukulele when he’s not staying up all night debugging Pulsedive.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts and ThreatVector as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
DevSecOps?
SecDevOps?
Jeff… Kevin?
Wait… what?
On this episode of InSecurity, Matt Stephenson has a chat with Refactr co-founder & CEO Mike Fraser about the World of DevSecOps and the role it plays in contemporary Cybersecurity ecosphere. We dig into the relevance of low-code/no-code and FINALLY get handle on Conway’s Law as it applies to security. No idea what we're talking about? Tune in and find out…
About Mike Fraser
Mike Fraser (@itascode) is the Co-founder, CEO, Chief Architect of Refactr. He started his career in the US Air Force working on F-15 weapon systems and later as a cybersecurity engineer. Mike has founded multiple tech companies and is a regular speaker at industry events, including Hashiconf, various Microsoft events, Red Hat AnsibleFest and All Day DevOps. He has published several articles including on TechCrunch, RSA 365, CRN, and The New Stack, and appeared on the cover of Channel Pro Magazine.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts me in front of crowds, cameras, and microphones all over the world. I am the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts and ThreatVector as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Legendary UCLA mens’ basketball coach John Wooden famously instructed his team, every year on the first day of practice, how to put on their socks and tie their shoes.
I think it's the little things that really count. The first thing I would show our players at our first meeting was how to take a little extra time putting on their shoes and socks properly.
The most important part of your equipment is your shoes and socks.
You play on a hard floor. So you must have shoes that fit right. And you must not permit your socks to have wrinkles around the little toe--where you generally get blisters--or around the heels.
It took just a few minutes, but I did show my players how I wanted them to do it. Hold up the sock, work it around the little toe area and the heel area so that there are no wrinkles. Smooth it out good. Then hold the sock up while you put the shoe on. And the shoe must be spread apart--not just pulled on the top laces. You tighten it up snugly by each eyelet. Then you tie it. And then you double-tie it so it won't come undone--because I don't want shoes coming untied during practice, or during the game. I don't want that to happen.
I'm sure that once I started teaching that many years ago, it did cut down on blisters. It definitely helped. But that's just a little detail that coaches must take advantage of, because it's the little details that make the big things come about.
-- John Wooden as told to Devin Gordon
When you are in the leadership business… what do you when the entire world gets turned upside down and everyone is looking at you for direction?
How do you find the little details in order to bring the big things about?
On this week’s InSecurity, Matt Stephenson has a chat with Jillian Lappetito, president of Leaderology and a member of 4 NCAA Champion and 2 World Champion US National Waterpolo teams. Influenced by the leadership of an Army Ranger father and world class coaches and teammates, Jillian now channels her experience into coaching and mentoring others. With a mantra of Fearless Authenticity, Jillian is helping develop tomorrow’s leaders’ ability to meet any challenge they may face.
About Jillian Lappetito
Jillian Lappetito is the President of Leaderology (@leaderologyllc) and responsible for developing the company’s go-to-market efforts and strategic direction.
Jillian is a former member of the U.S. Senior National Team for Women’s Water Polo and won four NCAA National Championships at UCLA.
After her athletic career, she transitioned from the pool to the board room, becoming Vice President of Business Development for Brainard Strategy, where she led the company’s highest revenue-generating market supporting Fortune 500 clients.
Jillian has grown up around the influence of leaders, whether it was her Army Ranger father, her water polo coaches or mentoring rising stars herself in the business community. It is her belief that truly remarkable leaders bring diligence and intentionality to their daily leadership practices, working hard and striving for continuous development.
While with the National Team, she received her M.B.A. from UC Irvine and graduated with a Bachelor’s Degree from University of California, Los Angeles.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts, and ThreatVector as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
It tells me that goose-stepping morons like yourself should try reading books instead of BURNING them
-- Henry Jones, Sr – Indiana Jones and the Last Crusade
If you like my opinions, you'll love my latest book. If youdon't like my opinions, I encourage you to buy 3 copies of the book, so you have the satisfaction of burning them.
-- Ira Winkler - LinkedIN
On this week’s InSecurity, Matt Stephenson speaks with Ira Winkler, president of Secure Mentem and author of multiple books, including You CAN Stop Stupid. We take a frank look at the people and systems involved in the world of cybersecurity and look to point out what is stupid about all of it and what can be done to stop stupid behavior and fix stupid systems.
About Ira Winkler
Ira Winkler (@irawinkler) is President of Secure Mentem and Author of the forthcoming books, You Can Stop Stupid and Security Awareness for Dummies. He is considered one of the world’s most influential security professionals and was named “The Awareness Crusader” by CSO magazine in receiving their CSO COMPASS Award. Ira is one of the foremost experts in the human elements of cyber security and is known for the extensive espionage and social engineering simulations that he has conducted for Fortune 500 companies globally.
He continues to perform these espionage simulations, as well as assisting organizations in developing cost effective security programs. He and his work have been featured in a variety of media outlets including CNN, The Wall St Journal, USA Today, San Francisco Chronicle, Forbes, among other outlets throughout the world.
Ira began his career at the National Security Agency, where he served as an Intelligence and Computer Systems Analyst. After leaving government service, he went on to serve as President of the Internet Security Advisors Group, Chief Security Strategist at HP Consulting, and Director of Technology of the National Computer Security Association. He has also served on the graduate and undergraduate faculties of the Johns Hopkins University and the University of Maryland.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts, and ThreatVector as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
How great would it be to actually be able to GO TO the doctor’s office?
Remember when it was a thing for people to actually do that? To actually go to the doctor’s office
Did we really need to do that as often as we did?
Or at least as often as we should have?
According to our friends at MedicalEconomics.com, patients are ready for easier access to healthcare professionals. In the early days of COVID19, 71% of patients had considered telemedicine half had already gone through with a virtual appointment. Patient adoption at the beginning of 2020 was up 33% over the previous year and Venture capital fundingfor telemedicine companies surged in the first quarter of 2020 to $788 million. The market is expected to reach $185.6 billion by 2026.
Here’s a tough question: Does it actually help?
On this week’s InSecurity, Matt Stephenson has a chat with Pete Fronte, founder & CEO of Altura, a 20 year old company who has built a mechanism that connects medical clinical studies with the people who need to be studied. In the contemporary world of telehealth and everything-from-home, people need access more than ever. COVID is the new horror on the block. People still need access to studies on cancer, heart disease and every other healthcare issue that existed prior to 2020… check it out
About Pete Fronte
Pete Fronte is the founder and President/CEO of Altura. During the past 20 years Mr. Fronte has been a leader in engaging people for better health via health studies, health experience surveys and health programs. He has been a catalyst for developing innovative processes and technology to accelerate the study and adoption of new medical interventions (e.g. drugs, biologics, medical devices, wearables).
Pete’s passion centers on expanding participation in health studies by engaging and enabling patients and health care providers (HCPs). He is a recognized leader in patient centered outreach including Patient Study Life Cycle™ management. Today he continues to lead the expansion of clinical research, evidence based medicine and real word studies into primary care and organized healthcare settings nationally. Mr. Fronte has spearheaded innovative technology such as Altura's Study Engagement Platform which HCP Studies mobile app which is available in 23countries.
Pete’s experience includes collaborating with medical groups, integrated health systems, pharmacy and medical management companies, research centers, institutional review boards (IRBs) and study sponsors to design and implement innovative study awareness and patient centered projects that include HIPAA compliant utilization of various forms of electronic health data as well as mobile applications and web portals.
Mr. Fronte is currently a member of the Institutional Review Board at St. Joseph Health in Orange County California and is active in various healthcare and clinical research trade associations. He is a national speaker and writer on subjects such as; innovative patient and HCP engagement programs for clinical studies, and health program, site based clinical research operations and the integration of clinical research within primary care and organized healthcare systems.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
I have spent the last 10 years in the world of Data Protection and Cybersecurity. Since 2016, I have been with Cylance (now BlackBerry) extolling the virtues of Artificial Intelligence and Machine Learning and how, when applied to network security, can wrong-foot the bad guys. Prior to the COVID shutdown, I was on the road over 100 days a year doing live malware demonstrations for audiences from San Diego to DC to London to Abu Dhabi to Singapore to Sydney. One of the funniest things I've ever been a part of was blowing up a live instance of NotPetya 6 hours after the news broke... in Washington DC... directly across the street from FBI HQ... as soon as we activated it a parade of police cars with sirens blaring roared past the building we were in. I'm pretty they weren't there for us, but you never know...
Every week on the InSecurity Podcast, I get to interview interesting people doing interesting things all over the world of cybersecurity and the extended world of hacking. Sometimes, that means hacking elections or the coffee supply chain... other times that means social manipulation or the sovereign wealth fund of a national economy.
InSecurity is about talking with the people who build, manage or wreck the systems that we have put in place to make the world go round...
Can’t get enough of Insecurity? You can find us at Spotify, Apple Podcasts, ThreatVector and Blackberry as well as GooglePlay, Gaana, Himalaya, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Once more unto the breach, dear friends, once more;
Or close the wall up with our English dead.
In peace there's nothing so becomes a man
As modest stillness and humility:
But when the blast of war blows in our ears,
Then imitate the action of the tiger;
Stiffen the sinews, summon up the blood,
Disguise fair nature with hard-favour'd rage;
Then lend the eye a terrible aspect;
Let pry through the portage of the head
Like the brass cannon; let the brow o'erwhelm it
As fearfully as doth a galled rock
O'erhang and jutty his confounded base,
Swill'd with the wild and wasteful ocean.
Sometimes… the bad guys get in. It happens. When it happens, we need the people who know how to shut down the villainous behavior, fix what’s broken and prevent it from happening again. Was it a hack? Was it a breach? Is there a difference? Does the difference matter? When the data is compromised, it is too late to worry about who did what and why they did it. It is time to repair the damage. For that… you need experts in the world of Incidence Response.
On today’s Special Episode of InSecurity, we are bringing you into a special LinkedIN LIVE event where Matt Stephenson spoke with Axon Technologies Director of Security Operations Dave Brown and BlackBerry Sr Director of International Consulting Luke Hull. These two have faced some of the biggest breaches in the world over the last 20 years. They may not have seen it all, but they have seen enough and want to help prevent the next Big Breach.
About Dave Brown
Dave Brown is Security Operations Director at Axon Technologies. With nearly 20 years of experience in intelligence-driven secure system design, infrastructure architecture, computer, and network defense, Dave has created and operated defense-in-depth initiatives in government sectors within the US Department of Defense as well as highly targeted enterprises in the global oil and gas industry.
We could tell you more about the work Dave has done… but we can’t. Let’s just leave it at that…
About Axon Technologies
Axon Technologies (@Axon_Tech) is a cybersecurity services company focused on protecting organizations of various sizes in this digitally connected world. Their mission is to help organizations predict, prevent, detect, respond to, and recover from cyberattacks with a combination of best of breed security technologies and a specialist team of researchers, analysts, and Incident responders to provide clients the comfort that their organization is protected 24x7. Their vision is to apply automation, orchestration, and machine learning into our security programs to stay one step ahead of the attackers and unleash the value of your security investment.
About Luke Hull
Luke Hull is Senior Director of International Consulting at BlackBerry. He comes from a strong risk and technical background, covering information security, intelligence and cyber operations with an extensive range of consultancy experience across a broad range of clients and an emphasis on adding business context to consultancy. In a career spanning nearly 20 years with some of the largest companies in the world, he has led and been a part of Incident Response teams at Mandian, Verizon and PriceWaterhouse Coopers.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Gaana, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
What’s your favorite Data Breach?
Come on… seriously… you know you have one… Sony? JP Morgan Chase? AdultFriendFinder? Office of Personnel Management?
What separates data breaches in your mind? The type of company? The type of data stolen? The notion of a threat to the National Infrastructure?
We can get really weird into the idea of which kind of theft poses a bigger threat.
You may say the OPM breach is huge because it put the IDs of millions of public servants and other regular people up for sale… But what about the idea that a corporate officer of an 11 figure energy company whose data on AdultFriendFinder gets accessed in a breach…
Put your tinfoil on and follow the ripples out on that one… What could a bad guy do to manipulate… oh I don’t know… Purchasing decisions? Green lighting potentially controversial energy projects?
See where I’m going here… A breach is a breach is a breach is a breach…
What we need are the kind of people who live and think in an asymmetric world in order to deal with kind of asymmetric attacks we have seen over the last several years
What if we could get someone on the horn who is as asymmetric as anyone you’ll ever meet?
Today might be that day
On this week’s InSecurity, Matt Stephenson sits down with Robert Willis to jump all around the world of hacking, red & blue teaming, and the world of cybersecurity writ large. And then, as a special bonus, we dig into the new world Robert is creating, the Paraneon Universe… a cyberpunk comics universe written by hackers for hackers, where the tech is legit. We wouldn’t have had flip phones without Start Trek… who knows what Robert & Pareneon are going to offer that will change the world…
About Robert Willis
Robert Willis (@rej_ex) Runs consulting at 1337 Inc among other things. He is a Red team, Blue team, and purple team professional. He isnt just breaking into things for clients, he’s also building and running security programs.
Robert is featured in the popular Tribe of Hackers series from Wiley, whose new book Tribe of Hackers: Blue Team is out as of September 16th, 2020.
In a Previous life, Robert was a Researcher at the Breach and Attack Simulation Pioneer ThreatCare
He has worked places he can’t disclose, but which I have personally verified… It’s legitimate, as crazy as that sounds. Robert’s most mind numbing accomplishments cannot be talked about publicly, but if you become his friend he will likely show you some insane stuff -- as long as it doesnt compromise national security.
About 1337 Inc
1337 Inc. was founded after years of building cybersecurity programs and providing services for clients of all sizes. They are trusted security partners for both consulting and deliverables for public, private, and government organizations.
They are Austin-based, but have a presence across Texas to service companies in the Dallas, Houston, and San Antonio areas as well. They have clients across the United States, and also work internationally when needed.
Many of their employees have both civilian and military training credentials, and make it a point to be on top of the latest compliance needs — as well as recently published vulnerabilities.
1337 offers compliance mapping (ISO27001, SOC2, PCI DSS, GDPR, etc), security program and policy creation (mapping to the NIST cybersecurity framework), web application assessments, penetration testing, vulnerability assessments, threat modeling, and much more.
About Paraneon
Paraneon (@paraneonU) develops and publishes stories from a cyberpunk future. For hackers, by hackers.
Earth’s landscape is split between highly technocentric cities, dry desert lands that surround them (known as the drylands), and underground worker colonies. The cities are highly futuristic; everyone who is a citizen of a city has a quality of life much higher than the colonies or drylands.
The drylands appear desolate due to dust bowls created from global warming — a problem in earth’s past history. Because of this, all factory operations were moved to Mars to remediate the problems caused by production. Earth is in the healing process from the past damage caused from previous ‘on-earth’ factories. Due to the continued recovery from global warming and chemicals from prior manufacturing, the highest quality resources are reserved for those in the cities.
COLONIES
Every colony specializes in a different trade. Some of the colonies specialize in food production aided by technology, clean air initiatives, general robotics, general information technology, security testing and exploitation.
Colonies were developed as a program to make use of earth’s lower income population — which continues to expand with earth’s limited quality resources. The colonies are small underground cities where families live, train, and work to save enough money for the opportunity to join a city; this is known as being “granted citizenship”.
Although the opportunity to move out of a colony is available for those who can afford it, many residents opt to not leave and instead ‘retire’ into virtual reality. Those who choose to live full-time in virtual reality are put into a network of machinery, known as the ‘Hive’. The Hives are massive underground structures, with various locations across earth. The technology within the Hive allows humans to completely abandon the physical world and exist full-time in virtual reality.
The leadership in colonies are known as Mayors. Colonies have their own police force, but city forces hold authority over them.
DRYLANDS
Groups of people decided to opt-out of the cities and colonies to live in the drylands. These people aren’t just known as ‘non-citizens’ (like colony members), but are also known as ‘drylanders’. They are not integrated with technology like the rest of the population, and consider themselves ‘pure’ humans.
The drylanders are mysterious, and not considered hostile. The cities and colonies don’t worry about drylanders; since resources on earth are limited and the people in the drylands aren’t technological or a threat, they are left alone by police and fend for themselves. Some of the drylanders are known to be able to grow small amounts of food; they then can act as traders and are granted access to the colonies through timed-passes to sell goods to members of the colonies — if they can show that they have items that are worthy of being sold.
DIFFERENCES IN LIVING CONDITIONS
Cities are highly sought after because they offer fresh food, sunlight, and fresh air. Residents are able to access all known information in what’s known as ‘the great library’. Information is considered a privilege reserved for city residents.
In the colonies the food is in canned or powder form, with fresh items only found when brought in by a member of the drylands.
Individuals in the colonies can only study from a shortlist of general studies and what trade their colony specializes in, limiting their knowledge only to what service they provide to society. This was accepted by those in the colonies because society teaches that information as a privilege.
Once a colony member becomes a citizen of a city their access to the ‘great library’ is granted.
THE BINDING
Humans living in the cities and colonies have tech implanted within them, as part of humanities evolution with technology. These modifications are done once a child has hit a certain age, in a ceremony known as the “binding”.
The binding ‘modifications’ are required for wireless communication, learning, and access to augmented reality. When walking around in the ‘real world’ you can see people’s avatars due to the augmented reality implants everyone receives after being binded.
You can identify someone as an avatar by a small glow around their body, which is required for identification by authorities. Avatar’s are only able to access areas they are granted permission to. Avatars can exist anywhere in the cities and colonies due to an extensive camera network that give the avatars the ability to not just be seen, but to see their surroundings.
MARS
Mars has a single city (referred to as the ‘Neon Aviary’), scattered research outposts and many large factories. The majority of the population on Mars are androids. Humans on Mars exist to complete advanced research, and manage the android workforce to oversee the production of goods developed. Mars is where all androids are created.
EUROPA (Jupiter’s Moon)
Humans have expanded as far as Europa (a moon of Jupiter) after discovering oceans there. There isn’t a city on Europa, just a network of various research outposts.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Gaana, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Do you read books? The newspaper? Watch TV?
Why?
Ever watch a YouTube video?
Why?
If your vacuum cleaner stops working, do you fix it? Take it to be fixed? Do you just buy a new one?
There are people out there who are great at what they do and who want to share their knowledge with anyone who needs it
On this week’s InSecurity, Matt Stephenson welcomes CEO, author and cybersecurity expert Scott Schober in for a chat about what it means to beconsidered a “Subject Matter Expert” in a world that is best defined by how quickly it changes rather than its bedrock foundation. With 30+ years in the industry, how do people like Scott get what they know out to the people who need that knowledge? Books… TV… YouTube… look anywhere and you are likely to find Scott Schober
About Scott Schober
Scott Schober (@ScottBVS) is the President and CEO of Berkeley Varitronics Systems, a 40-year-old New Jersey-based privately held company and leading provider of advanced, world-class wireless test and security solutions. As an experienced software engineer, Scott also invents BVS’s cell phone detection tools, used to enforce a ‘no cell phone policy’. These instruments are effectively used around the globe to find contraband cell phones smuggled into correctional as well as secure federal facilities.
Schober is a highly sought after subject expert on the topic of Cybersecurity for media appearances and commentary. He is often seen on ABC News, Bloomberg TV, Al Jazeera America, CBS This Morning News, CCTV America, CNBC, CNN, Fox Business, Fox News, Good Morning America, Inside Edition, MSNBC and many more. His precautionary advice is heard on dozens of radio stations such as National Public Radio, Sirius XM Radio, Bloomberg Radio, and The Peggy Smedley Show. He regularly presents on visionary issues at conferences around the globe discussing wireless technology and its role in the current Cybersecurity breaches along with his vision for best practices to stay safe in the future. Scott has been interviewed in WSJ, Forbes, Fortune, Success, NY Daily News, Newsweek, USA Today, and The New York Times.
Scott educates all business around the world about how to prepare for a future of Cybersecurity and corporate espionage, opening their eyes to this ever deepening black hole of liability. He also shares his insights into covert cell phone detection and creates awareness to the subtle but powerful influence of drones. He has spoken at ShowMeCon, GovSec, Counter Terror expo, ISS Americas, Espionage Research International, Connected World, ConstrucTech, IEEE, GSM World Congress and many more events.
About Hacked Again
Hacked Again details the ins and outs of cybersecurity expert and CEO of a top wireless security tech firm, Scott Schober, as he struggles to understand the motives and mayhem behind his being hacked.
As a small business owner, family man, and tech pundit, Scott finds himself leading a compromised life. By day, he runs a successful security company and reports on the latest cyber breaches in the hopes of offering solace and security tips to millions of viewers.
But, when a mysterious hacker begins to steal thousands from his bank account, go through his trash, and take over his social media identity, Scott stands to lose everything he has worked so hard for.
Amidst the backdrop of major breaches, Scott shares tips and best practices for all consumers. Most importantly, he shares his own story of being hacked repeatedly and how he has come to realize that the only thing as important as his own cybersecurity is that of his readers and viewers.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
The world is more digitally connected than ever before, and with this connectivity, comes vulnerability. It is therefore vital that all professionals understand cyber risk and how to minimize it. This means that cyber security skills are in huge demand, and there are vast career opportunities to be taken.
On this week’s InSecurity, Matt Stephenson welcomes Dr Jessica Barker, co-founder/CEO of Cygenta, author and keynote speaker at RSA 2020 for a chat about the current state of cybersecurity in a world that changes not just day to day, but hour to hour. Dr Barker puts her high powered perception on the people involved in the daily operation of keeping data secure and accessible. It’s not all 1s and 0s… often times it’s the people who make and break cybersecurity.
About Dr Jessica Barker
Dr Jessica Barker (@drjessicabarker) is a leader in the human nature of cyber security, has been named one of the top 20 most influential women in cyber security in the UK and awarded as one of the UK’s Tech Women 50 in 2017. She is the Chair of ClubCISO.
Equipped with years of experience running her own consultancy, she co-founded Cygenta, where she follows her passion of positively influencing cybersecurity awareness, behaviours and culture in organisations around the world.
Her consultancy experience, technical knowledge and background in sociology and civic design give her unique insight. She is known for her clear communication style and for making cyber security accessible to all.
Dr Barker delivers thought-provoking and engaging presentations across the world, at corporate events as well as practitioner and academic conferences. Known for her ability to engage everyone from CEOs to ethical hackers and creative workers, she brings energy, enthusiasm and fun to cyber security.
Jessica’s new book Confident Cyber Security is coming in 2020, published by Kogan Page.
About Confident Cyber Security
This jargon-busting guide will give you a clear overview of the world of cyber security. Exploring everything from the human side to the technical and physical implications, this book takes you through the fundamentals: how to keep secrets safe, how to stop people being manipulated and how to protect people, businesses and countries from those who wish to do harm.
Featuring real-world case studies from Disney, the NHS, Taylor Swift and Frank Abagnale, as well as social media influencers and the entertainment and other industries, this book is packed with clear explanations, sound advice and practical exercises to help you understand and apply the principles of cyber security. Let Confident Cyber Security give you that cutting-edge career boost you seek.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
It’s not Paranoia ifThey’re Really After You
Brill: We never dealt with domestic. With us, it was always war.
Thomas Reynolds: We won the war. Now we're fighting the peace. It's a lot more volatile. Now we've got ten million crackpots out there with sniper scopes, sarin gas and C-4. Ten-year-olds go on the Net, downloading encryption we can barely break, not to mention instructions on how to make a low-yield nuclear device. Privacy's been dead for years because we can't risk it. The only privacy that's left is the inside of your head. Maybe that's enough. You think we're the enemy of democracy, you and I? I think we're democracy's last hope.
-- Enemy of the State; Tony Scott, 1998
It’s not paranoia if they’re really after you… On this week’s InSecurity, Matt Stephenson welcomes back Dr Jessica Barker, Freaky Clown and Dave to take a look at the techno-paranoia classic Enemy of the State. We’re looking at surveillance cameras, Faraday Cages, PX-73 Burst Transmitters and UTZ potato chip bags. Why the bag and not the chip? Tune in and find out.
About Dr Jessica Barker
Dr Jessica Barker (@drjessicabarker) is a leader in the human nature of cybersecurity. She has been named one of the top 20 most influential women in cybersecurity in the UK and awarded as one of the UK’s Tech Women 50. She is Co-Founder and Co-Chief Executive Officer of Cygenta, where she positively influences cybersecurity awareness, behaviors and culture in organizations around the world.
Dr Barker is a popular keynote speaker and shares her expertise in the media, for example on BBC News, Sky News, Channel 4 News and in Grazia magazine and the Sunday Times. She is Chair of ClubCISO, a peer-based members forum of over 300 information security leaders. In the last year, Dr Barker has given cybersecurity outreach sessions to over 5,000 school students.
Jessica’s new book Confident Cyber Security is coming in 2020, published by Kogan Page.
About Freaky Clown
Freaky Clown (@_Freakyclown_) is a well-known ethical hacker and social engineer. He has been working in the infosec field for over 20 years and excels at circumventing access controls. He has held positions in his career such as Senior Penetration Tester as well as Head of Social Engineering and Physical Assessments for renowned penetration companies. As Head of Cyber Research for Raytheon Missile Systems, and having worked closely alongside intelligence agencies, he has cemented both his skillset and knowledge as well as helped steer governments take correct courses of action against national threats.
As an ethical hacker and social engineer, FC ‘breaks into’ hundreds of banks, offices and government facilities in the UK and Europe. His work demonstrating weaknesses in physical, personnel and digital controls assists organisations to improve their security. He is motivated by a drive to make individuals, organisations and countries more secure and better- able to defend themselves from malicious attack.
Now Co-Founder and Head of Ethical Hacking at Cygenta Ltd, he continues to perform valuable research into vulnerabilities. His client list involves major high-street banks in the UK and Europe, FTSE100 companies and multiple government agencies and security forces.
About Dave
Dave Mound (@DeathsPirate) is an Experienced Cyber Security Researcher with a demonstrated history of working in the Computer &Network Security industry along with threat intelligence. He’s done a lot of work in Penetration Testing, Reverse Engineering, Agile Methodologies, Computer Forensics, Red Teaming and Threat Intelligence… and… he looks good in a white suit and turtleneck
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Amar Singh: How Do We Rank Trust, Security and Control?
This is a story about control
My control Control of what I say
Control of what I do
And this time I'm gonna do it my way
I hope you enjoy this as much as I do
Are we ready?
I am 'Cause it's all about control,
And I've got lots of it
-- Janet Jackson; Control, 1986, A&M Records
On this week’s InSecurity, Matt Stephenson welcomes Amar Singh in for a conversation about the notion of Trust, Security, Risk and Control. The key question, in a nearly completely remote workforce, is how do security practitioners mainten any degree of control? We also wonder if anyone ever really had control in the first place. Toss in a bit of trust and security to season the stew and you’ve got an episode worth listening to.
About Amar Singh
Amar Singh (@amisecured) is the CEO and interim CISO of Cyber Management Alliance Limited. He is an industry acknowledged expert and public speaker and is regularly invited to speak and share his insights by some of the largest and most respected organisations in the world including The BBC, The Economist’s Intelligence Unit, The Financial Times, SC Magazine, InfoSec Magazine, Computer Weekly, The Register and the Al-Jazeera English Channel
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“Live like you'll die tomorrow, work like you don't need the money, and dance like nobody's watching”
-- Bob Fosse
On this week’s InSecurity, Matt Stephenson has a chat with Genetec CSO Chris Morin about the misconceptions surrounding video as a component of your security profile. There has to be a middle ground between dancing like no one is watching and knowing that someone is always watching. Is it Security VERSUS Privacy? Or is it Security PLUS Privacy? We dig into this notion and whole lot more…
About Christian Morin
Christian Morin (@cmor007) is Vice President of Integrations & Cloud Services and Chief Security Officer at Genetec. With over 18 years of experience in IT, telecommunications and physical security industries, Chris has a keen ability to anticipate technological trends and drive meaningful organizational growth. He is a multidisciplinary business leader, having managed the Operations, Customer Service, Sales Engineering, Technical Support, Professional Services, and IT Teams since joining Genetec in 2002. Chris’ executive leadership continues to support the strategic direction and success of the company.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Nothing you are about to hear is true… but it all happened…
-- Fred Cohen 11 May, 2020
It all started with a simple Tweet from the Department of Homeland Security…
On today’s episode of InSecurity, Matt Stephenson welcomes Chris Blask & Fred Cohen back to InSecurity. As expected we covered a wide range of subjects, but stayed relatively close to the notion of the impact of attribution and validation of trust and security. Should we trust a source if we don’t like what they say? What happens when a trusted source denies saying what we know they said? Trust… verify… attribute… Do they matter?
About Chris Blask
Chris Blask’s (@chrisblask) career spans the breadth of the cybersecurity industry for more than 25 years.
He invented one of the first firewall products, built a multi-billion dollar firewall business at Cisco System, co-founded an early SIEM vendor, authored the first book on SIEM, founded an information sharing center for critical infrastructures, and has advised public and private organizations in every sector around the world.
In his role within the Office of Innovation at Unisys, Chris created and leads the Operational Technology and IoT practices, invented the Digital Bill of Materials (DBoM) structure, and established the Unisys Marine Living Research Center.
Today he chairs a range of non-profit cybersecurity organizations and contributes to a wide range of global security efforts.
About Fred Cohen, PhD
Dr. Fred Cohen (@fc0) is widely considered to be one of the leading security/risk experts in the world. He is best known as the person that defined the term “computer virus” and inventor of the most widely used computer virus defense techniques.
Dr. Cohen was also the principal investigator whose team defined information assurance as it relates to critical infrastructure, did seminal research in the use of deception for information protection, a leader in the science digital forensic examination and leading information protection consultant and analyst.
He has authored over 200 published research articles, authored several books and established Masters and Ph.D. security programs now part of Webster University. In 2002 Dr. Cohen revived the “Techno-Security Industry Professional of the Year” award and in 2009 he was named the “most famous hacker of all time” by ABC news.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
"We are all very fortunate to not have ordinary lives, so do not listen to what the world tells you has to be done. The real revolution happens when patients are in charge of their own outcomes."
-- Matthew Zachary
What do you do when you are a gifted composer and musician… and one day your hand stops working?
Each year, 77,000 adolescents and young adults aged 15-39 are diagnosed with cancer. That's one every seven minutes. Cancer incidence in young adults has increased more than any other age group, yet somehow, survival rates have not improved at the same rate as other age groups.
Cancer is the number one disease killer in young adults. Young adults are the most underserved patient population by age. Delayed cancer diagnosis is disproportionately higher in young adults.
Which begs the question… what is being done to improve the resources for Adolescents and Young Adults dealing with cancer
On this episode of InSecurity, Matt Stephenson ran amok with Matthew Zachary, founder of Stupid Cancer and Offscrip Media. Why are we talking about cancer advocacy? Ask Matthew… when he entered the "$#!+ Happens" store, there was no one there to greet him. Rather than being told how to die with dignity, he rose up and gathered those facing similar situations. He founded Stupid Cancer and gave birth to the young adult cancer movement. The Stupid Cancer Show broke all the rules and gave a voice to millions. What else can we learn from someone who is winning that ongoing battle? Worth a listen to find out…
About Matthew Zachary
Ten years after surviving brain cancer at age 21, Matthew Zachary (@matthewzachary) created Stupid Cancer(@stupidcancer), the world's largest young adult cancer community, and The Stupid Cancer Show, the world's first health podcast, which amassed a global listenership in the millions.
He stepped down as Stupid Cancer's CEO in 2019 and launched his latest venture, OffScrip Media, the first podcasting network at the intersection of patient advocacy, education, and digital health. True to form, Matthew is also back behind the mic where he belongs. His new show on the OffScrip Media Network, Out of Patients, is being hailed as "the voice of patient advocacy."
As he continues to be pissed off with the dumpster fire that is our healthcare system, the through-line of Matthew's entire career is patient advocacy; and he will not stop calling out all sorts of Stupid BS that shouldn't have to be a thing.
Matthew is also an acclaimed keynote speaker, accomplished film composer, and award-winning concert pianist.
About Offscrip Media
Today's healthcare conversations are too polite. Offscrip Media (@offscripmedia) is here to fix all that. Created by Matthew Zachary, a 25-year brain cancer survivor, and the Founder of Stupid Cancer, OffScrip Media is the first podcasting network at the intersection of patient advocacy, education, and digital health. Their mission is to build community, end isolation, amplify voice, and improve quality of life for patients and caregivers.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“What’s changed most about Tor is the drug markets have taken over… We had all these hopeful things in the beginning but ever since Silk Road has proven you can do it, the criminal use of Tor has become overwhelming. I think 95% of what we see on the onion sites and other dark net sites is just criminal activity. It varies in severity from copyright piracy to drug markets to horrendous trafficking of humans and exploitation of women and children.”
-- Andrew Lewman; cyberscoop, 22 May, 2017
Do you know what the Darknet is? No seriously… do you ACTUALLY understand what the Darknet is?
On this episode of InSecurity, Matt Stephenson and Michelle Moskowitz speak with Dark Owl Exec VP Andrew Lewman about The Darknet. As the former CEO of The Tor Project, he knows a thing or two about what happens in the Upside Down of the internet. From the Multiverse of Darknets to why business needs to be concerned with activity on the Darknet to the work Andrew is doing with law enforcement, it’s a wide-open look at an area not everyone understands.
About Andrew Lewman
Andrew Lewman (@andrewlewman) is the Executive Vice President at Dark Owl. He has more than 30 years of global-scale technology experience in a variety of domains, including information security, systems administration, and data management. His interest lies in the intersection of technology and humans.
He successfully grew a few companies as a co-founder and top executive, such as TechTarget, The Tor Project, Farsight Security, and DarkOwl. Andrew advises the US and its Allies, having worked on SAFER Warfighter, MEMEX, SHARKSEER, CRISP, and others. And as a technology advisor to Interpol’s Crimes Against Children Initiative.
Andrew is a keynote speaker and frequent media contact for conferences, invited speeches and the global press. He is publishing with Elsevier Digital Investigations, EMCDDA, and Fordham University Press. Andrew’s most recent publication is in Digital Investigation: The darknet’s smaller than we thought: The lifecycle of Tor Hidden Services. As Treasurer for Emerge, Andrew is helping to stop domestic violence through counseling abusers. As Chairman of Each One Teach One, he’s providing economic opportunity for women and girls through technology education.
About Michelle Moskowitz
Michell Moskowitz is Vice President of Business Development & Chief of Staff at Sublime Communications. In her previous lives, she spun up the New Media Division for Lifetime network as well as working with numerous cybsecurity startups.
With a career spent swimming in the waters of digital marketing and consulting Michelle has somehow found the time to also be a journalist at the Greenwich Sentinel.
Michell will be joining us as a recurring co-host to bring additional perspective to the important role that communication plays in a world that grows increasingly technical.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector, Blackberry, Apple Podcasts and Spotify as well as GooglePlay, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
You tired of hearing about the Cyber Skills Gap?
What about the recent unemployment numbers due to COVID19?
What if we brought you some really good news that includes a great story?
What if that good news and great story includes something that is replicable, accessible and available?
What if we get on with it and stop asking so many dumb questions?
In today’s episode of InSecurity, Matt Stephenson has a chat with Kip Boyle about the current state of employment in the cybersecurity world. Is it all doom and gloom? Make no mistake… there is reason to feel gloomy. But that doesn’t mean that it’s all doom. Kip is putting in the kind of work to bring folks into cybersecurity that gives us all a reason to be hopeful. Check it out…
About Kip Boyle
Kip Boyle (@KipBoyle) is a 20-year information security expert and is the founder and CEO of Cyber Risk Opportunities. He is a former Chief Information Security Officer for both technology and financial services companies and was a cyber-security consultant at Stanford Research Institute (SRI).
Boyle led the global IT risk management program for a $9 billion logistics company and was the Wide Area Network Security Director for the F-22 Raptor program. He has participated in several cybersecurity war game exercises and has worked closely with various government agencies including the FBI.
Boyle is a US Air Force officer and serves on the board of directors of the Domestic Abuse Women’s Network (DAWN). He’s been quoted in Entrepreneur magazine, Chief Executive magazine, and is the co-author of Chapter 68, Outsourcing Security Functions, in The Computer Security Handbook.
About Steve McMichael
Steve McMichael is a SOX Compliance Manager at BlackBerry… but not for much longer.
He has a CPA, CMA and MBA… but always had a yen for the security side of the business world. How does someone with a resume like that make a move at a point in his career where many of us would be more than proud of our accomplishments?
Why not get it directly from the source?
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
“There are leaders and there are those who lead. Leaders hold a position of power or influence. Those who lead inspire us.
Whether individuals or organizations, we follow those who lead not because we have to, but because we want to. We follow those who lead not for them, but for ourselves.”
-- Simon Sinek; Start with Why, 2009
Once upon a time, not that long ago… the music industry was flying high, peaking at over $22 BILLION in global sales then was laid low by a combination of events and technology it was not ready for.
There were decisions to be made which could have not only saved the industry, but made it thrive.
Leadership did not make those.
There were relationships to be forged with users that could have done the same.
The industry began suing their consumers.
What if industry leaders made a point to really look out for their users and their employees first? You think that might be a catalyst for a company to grow and thrive even though it is facing a potential disaster?
In today’s episode of InSecurity, Matt Stephenson sits down with Spirion CEO Kevin Coppins for a chat about the role of a new leader in the middle of the most tumultuous time in the modern computing era. Having spent time in the music+tech upheaval of the Napster era, Kevin Coppins has steered through some whitewater rapids in his time. What do we do when the whole world gets turned upside down? Stay tuned and find out…
About Kevin Coppins
As President and CEO of Spirion, Kevin Coppins (@ktcoppins) wakes up every day on a mission to protect what he knows matters most—your sensitive personal data. With a team of passionate data privacy professionals at his back, Kevin is working to re-envision the culture of entire industries, putting privacy at the forefront where it belongs.
Kevin’s more than 25-year track record of growth, leadership, and achievement spans multiple roles and industries. In addition to handling finance and procurement for non-tech giants ExxonMobil and Bausch & Lomb, he’s served in senior executive positions across the tech space at Novell, Alcatel Lucent, Meru Networks, EasyVista, CyFIR, and NEC. He has a BS in Marketing from Penn State, an MBA from Loyola University New Orleans, and a Certificate of Professional Development from University of Pennsylvania’s Wharton School of Business.
This unique diversity of experience and education equipped Kevin with the depth and breadth of skills needed to thrive at the helm of Spirion—a company whose data discovery and classification solutions have empowered the data privacy, security, and compliance strategies of thousands of organizations worldwide.
Kevin is determined to help C-suite execs understand the importance of minimizing their sensitive data footprint and preventing data breaches—not only to minimize the risks, costs, and reputational damage of successful cyberattacks and regulatory violations, but because it’s the right thing to do.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
Spotify: https://open.spotify.com/show/7qUp6uGXoshmBKHYJlXBtb?si=ZQdQWM39T6e4X5dgx1BZ0Q
Make sure you Subscribe, Rate and Review!
What would you do if, overnight, the number of things under your protection increased by an order of magnitude?
Would you be ready?
Would you even know what to do?
On today’s episode of InSecurity, Matt Stephenson talks with Justin Kallhoff, founder of Infogressive, on the impact Quarantine and Shelter-in-Place orders have impacted the role Managed Security Service Providers. Suddenly, a company who already protected users in 21 countries had an entirely new ecosystem surrounding the one they already ran. What did they do? They started hiring… check it out
About Justin Kallhoff
Justin Kallhoff (@justinkallhoff) founded Infogressive Inc. in October of 2006 with a dream of creating a world-class team of information security professionals that could make a difference for clients spanning the globe. Over the past decade, Justin and the crew at Infogressive have built an enterprise spread over 46 states and 20 countries, comprising nearly 60,000 seats.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Nothing you are about to hear is true… but it all happened…
-- Fred Cohen 11 May, 2020
What happens when you get two legends of the security industry together for a chat about everything? Well… first, you can throw the carefully created outline right out the window because there is no way anyone can corrall these two into talking about just a few topics. The best you can hope for is that they agree to come back and do it again… because there’s just too much ground to cover and not nearly enough time to get into all of it in a single episode.
Let’s just say that we set out to have a discussion on creating a way to catalog all of the things that go into making things. That catalog would also include where those things were made and what they were made of and how they arrived from their place of origin. The catalog would then include data on the place of origin and what went on there… see where we’re going with this? It’s a bit like a fractal version of the periodic table of elements.
On today’s episode of InSecurity, Matt Stephenson did his best to stay out of the way in a freewheeling jam session with security legends Chris Blask & Dr Fred Cohen. Trying to describe their chat is like chasing mercury. Let it be known that the conversation included discussions of a Digital Bill of Materials for… pretty much everything, and the positive effect having access to this record could produce. But that doesn’t come near to doing justice to what all they covered… check it out
About Chris Blask
Chris Blask’s (@chrisblask) career spans the breadth of the cybersecurity industry for more than 25 years.
He invented one of the first firewall products, built a multi-billion dollar firewall business at Cisco System, co-founded an early SIEM vendor, authored the first book on SIEM, founded an information sharing center for critical infrastructures, and has advised public and private organizations in every sector around the world.
In his role within the Office of Innovation at Unisys, Chris created and leads the Operational Technology and IoT practices, invented the Digital Bill of Materials (DBoM) structure, and established the Unisys Marine Living Research Center.
Today he chairs a range of non-profit cybersecurity organizations and contributes to a wide range of global security efforts.
About Fred Cohen, PhD
Dr. Fred Cohen (@fc0) is widely considered to be one of the leading security/risk experts in the world. He is best known as the person that defined the term “computer virus” and inventor of the most widely used computer virus defense techniques.
Dr. Cohen was also the principal investigator whose team defined information assurance as it relates to critical infrastructure, did seminal research in the use of deception for information protection, a leader in the science digital forensic examination and leading information protection consultant and analyst.
He has authored over 200 published research articles, authored several books and established Masters and Ph.D. security programs now part of Webster University. In 2002 Dr. Cohen revived the “Techno-Security Industry Professional of the Year” award and in 2009 he was named the “most famous hacker of all time” by ABC news.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Chris Coleman: Reversing the Economics of Cyber Defense
“When you are able to maintain your own highest standards of integrity - regardless of what others may do - you are destined for greatness.”
-- Napoleon Hill
On today’s episode of InSecurity, Matt Stephenson & Michelle Moskowitz chat with Chris Coleman, Advisor to the Chairman fo Lookingglass Cyber Solutions. In a wide-ranging discussion they take a look that escalating cybersecurity arms race, the role of Venture Capital in growing or stifling innovation and the need for standards in interoperability across the world of hardware and software in order to increase the security industry’s chancing of winning this battle.
About Chris Coleman
Chris Coleman (@cdeltac) has over 20 years of experience in information security and technology industry. He currently serves in an Advisor to the Chairman at Lookingglass Cyber Solutions.
Prior to his stint as CEO at Lookingglass, Coleman served as the Director of Cyber Security for Cisco Systems' U.S. Public Sector Theater. Chris focused on driving Cisco and partner technology into solutions that helped address customer problems and leverage the core value of Cisco’s network technologies. Coleman served as a liaison between sales and engineering with regards to cyber security technology and development.
Coleman also served as Vice President and Director of Engineering Services for ManTech International. During his tenure at ManTech, he was responsible for direct contract PNL and PNL associated with ManTech’s, remote security monitoring services and data center hosting services. In addition, Chris was responsible for ManTech IS&T's Divisional IT services and operations, and a subset of ManTech International’s IR&D. He also managed the NetWitness product development team, developed the initial architecture for moving from pure technology into a commercially viable product, defined the business case for developing a sales team and conceived the spin out of the technology and product team from ManTech International.
About Michelle Moskowitz
Michell Moskowitz is Vice President of Business Development & Chief of Staff at Sublime Communications. In her previous lives, she spun up the New Media Division for Lifetime network as well as working with numerous cybsecurity startups.
With a career spent swimming in the waters of digital marketing and consulting Michelle has somehow found the time to also be a journalist at the Greenwich Sentinel.
Michell will be joining us as a recurring co-host to bring additional perspective to the important role that communication plays in a world that grows increasingly technical.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Be formless… shapeless like water. Now you put water in a cup, it becomes the cup. You put water in a bottle, it becomes the bottle… you put water in a teapot, it becomes the teapot. Now water can flow or it can crash… Be water my friend.”
-- Bruce Lee
According to our friends at the International Labour Organization (ILO) the COVID-19 pandemic will wipe out 6.7 percent of working hours in the second quarter of this year. To put that in perspective, that is the equivalent of 195 million full-time workers. Huge losses are expected across different income groups, especially in upper-middle income countries (7.0%, 100 million full-time workers)
Fear not though… we’re not here to just lay a bunch of bad news on you! We want to show what ingenuity and adaptability can do for a company, for their personnel and for the the rest of us as well.
Textiles company American Roots converted its facility to produce medical supplies.
LVMH Group has turned its perfurmery brands, including Dior, Givency and Bulgair, into hand sanitizer manufacturers.
Tito’s Vodka converted production facilities to make hand sanitizer. Thanks to the combination of their attitude and ingenuity, they now have the ability and capacity to manufacture over 60 tons a week.
What is corporate leadership doing to adapt to and overcome a situation that has shown devastating consequences?
On this episode of InSecurity, Matt Stephenson welcomes new co-host Michelle Moskowitz for a chat with Forcepoint CMO Matt Preschern. With the ongoing COVID-19 pandemic affecting us all, we learn how Forcepoint adapted quickly to get the most out of their 2800 employees and give them the opportunity to adapt in order to help their customers and themselves. How can companies help themselves in order to help others? Check it out..
About Matt Preschern
Matt Preschern (@mattpreschern) is the chief marketing officer for Forcepoint. He leads the company’s global marketing organization that includes brand management, corporate communications, events marketing, digital and web marketing, revenue and field marketing, and sales enablement. He joined Forcepoint in January 2019.
Preschern is a veteran technology marketing leader with more than 25 years of experience in brand, digital marketing, demand generation and revenue management, customer experience, and corporate communications. Previously, Matt was senior vice president of marketing at CA Technologies where he was responsible for the development and execution of global, regional and partner marketing programs across all businesses. He has also served as the CMO of HCL Technologies where he led the effort to substantially increase HCL’s brand recognition as a digital solutions, IT services and technology consulting company and supported its rapid, multi-billion dollar growth. He also served as the Enterprise CMO of Windstream Communications. Early in his career, he held numerous vice president roles at IBM across marketing strategy and performance marketing and played an integral part in launching IBM’s Smarter Planet initiative.
Matt is an award-winning marketer, having been named among the top 20 most influential CMOs by Forbes and recognized for his success in driving marketing innovation by the CMO Club.
About Michelle Moskowitz
Michell Moskowitz is Vice President of Business Development & Chief of Staff at Sublime Communications. In her previous lives, she spun up the New Media Division for Lifetime network as well as working with numerous cybsecurity startups.
With a career spent swimming in the waters of digital marketing and consulting Michelle has somehow found the time to also be a journalist at the Greenwich Sentinel.
Michell will be joining us as a recurring co-host to bring additional perspective to the important role that communication plays in a world that grows increasingly technical.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Sometimes the best person to teach kids about online safety… is a fat orange cat who loves lasagna… and his friends. Well... he loves his friends, but let's be real... he loves lasagna more
The Center for Cyber Safety and Education, formerly the (ISC)² Foundation, is a global non-profit charity formed in 2011 as a conduit to reach society and empower students, teachers, parents and the general public to secure their online life with award winning cyber safety education and awareness programs in the community. They hold the exclusive global rights to Garfield to teach young children how to be safe and secure online.
Pat Craven is far too selfless to spend any time telling you what he does, so we’re going to do that for him. He and his team have spent nearly a decade helping to educate children, parents, seniors and cybersecurity professionals on the things they can do to protect themselves and their loved ones safe online.
On this episode of InSecurity, Matt Stephenson talks with Pat Craven of the Center for Cyber Safety Education about the work they are doing to provide teachers, parents and seniors with the tools they need to keep themselves and their children safe online. Did we mention that Garfield (yes that Garfield) and his friends are helping out too?
About Pat Craven
Pat Craven (@cravenpat) is the Executive Director of the Center for Cyber Safety and Education. In his prior lives he has served as the Regional Executive Director of Pinellas County / Chief Development Officer Big Brothers Big Sisters of Tampa Bay.
Pat also was the Vice President of Development for the Vietnam Veterans Memorial Fund in Washington DC.
Prior to that, Pat spent 24 years with Boy Scouts of America in various capacities.
We think it is fair to say that Pat Craven has spent his entire career putting in work to help pretty much anyone besides himself. If you need someone to help you help someone else… Pat Craven is your man. Like we said… he would never tell you this stuff, but we thought you should know.
About The Center for Cyber Safety and Education
The nonprofit Center for Cyber Safety and Education (@ISC2Cares) was founded in 2011 with the purpose of empowering students, teachers and whole communities to secure their online life through cyber safety education and awareness. They achieve this goal by providing Safe and Secure Online educational program, college scholarships and industry research.
Their educational content was developed by the Center along with members of (ISC)², the top cyber security professionals in the world. With their knowledge, the Center turned to legendary cartoonist Jim Davis to bring it all to life, using everyone’s favorite cat, Garfield. The first series of Garfield’s Cyber Safety Adventures tackles issues such as Privacy, Safe Posting, and Cyberbullying. This program is perfect for elementary education and is currently in 14 countries.
In addition, the Center provides educational materials for parents and seniors to grow their knowledge about the dangers of the internet and ensure our mission of making the cyber world a safer place for everyone.
Learn more about their programs at www.iamcybersafe.org
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Cybersecurity At the Movies: Sneakers
The world isn't run by weapons anymore, or energy or money.
It's run by ones and zeroes, little bits of data. It's all just electrons…
There's a war out there, old friend, a world war… and it's not about who's got the most bullets… It's about who controls the information ...what we see and hear, how we work, what we think.
It's all about the information.
-- Cosmo; Sneakers, 1992
We are stepping WAY out of the box for a technical deep dive examination of one of the great Hacker movies of all time… Sneakers. Maybe the last great techno-thriller before the emergence of the commercial internet… Sneakers features everything you want from a hacker movie… wire tapping, social engineering, a little black book and tech that looks/feels familiar enough that you recognize it, but aren’t quite sure what it actually does.
On this week’s episode, Matt Stephenson takes a technical look at the 1992 classic hacker film Sneakers with people who, in real life, do what the heroes of Sneakers do onscreen. Dr Jessica Barker, Freaky Clown and Death’s Pirate (or… just Dave) have broken into banks, kidnapped executives and, some times, just straight up hacked networks (while wearing White Hats of course)… Let’s sit down with real life experts to see if Hackers got it right!
About Dr Jessica Barker
Dr Jessica Barker (@drjessicabarker) is a leader in the human nature of cybersecurity. She has been named one of the top 20 most influential women in cybersecurity in the UK and awarded as one of the UK’s Tech Women 50. She is Co-Founder and Co-Chief Executive Officer of Cygenta, where she positively influences cybersecurity awareness, behaviors and culture in organizations around the world.
Dr Barker is a popular keynote speaker and shares her expertise in the media, for example on BBC News, Sky News, Channel 4 News and in Grazia magazine and the Sunday Times. She is Chair of ClubCISO, a peer-based members forum of over 300 information security leaders. In the last year, Dr Barker has given cybersecurity outreach sessions to over 5,000 school students.
Jessica’s new book Confident Cyber Security is coming in 2020, published by Kogan Page.
About Freaky Clown
Freaky Clown (@_Freakyclown_) is a well-known ethical hacker and social engineer. He has been working in the infosec field for over 20 years and excels at circumventing access controls. He has held positions in his career such as Senior Penetration Tester as well as Head of Social Engineering and Physical Assessments for renowned penetration companies. As Head of Cyber Research for Raytheon Missile Systems, and having worked closely alongside intelligence agencies, he has cemented both his skillset and knowledge as well as helped steer governments take correct courses of action against national threats.
As an ethical hacker and social engineer, FC ‘breaks into’ hundreds of banks, offices and government facilities in the UK and Europe. His work demonstrating weaknesses in physical, personnel and digital controls assists organisations to improve their security. He is motivated by a drive to make individuals, organisations and countries more secure and better- able to defend themselves from malicious attack.
Now Co-Founder and Head of Ethical Hacking at Cygenta Ltd, he continues to perform valuable research into vulnerabilities. His client list involves major high-street banks in the UK and Europe, FTSE100 companies and multiple government agencies and security forces.
About Death’s Pirate… okay… it’s Dave Mound
Dave Mound (@DeathsPirate) is an Experienced Cyber Security Researcher with a demonstrated history of working in the Computer &Network Security industry along with threat intelligence. He’s done a lot of work in Penetration Testing, Reverse Engineering, Agile Methodologies, Computer Forensics, Red Teaming and Threat Intelligence… and… he looks good in a white suit and turtleneck
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Ron Ross: Bringing the NIST Framework Home
“If you do good software development, most of our security problems will go away because all of the nagging vulnerabilities that we see in software — a lot of those are attributed to people not using secure coding techniques and things we should be doing,”
-- Ron Ross
Things are changing at such a rapid pace, it’s hard to keep pace with what used to work, what is working and what we can count on working when we log in tomorrow.
It’s almost like we need to count on some kind of established framework to use as a guideline.
While this episode of InSecurity touches on the impact of COVID19 on the global workforce, it’s not yet another blog or podcast about the same thing. We talk with NIST Fellow Ron Ross about the future of work, healthcare and the IT industry writ large.
This week on Insecurity, Matt Stephenson welcomes Cybersecurity legend Dr Ron Ross about… well… lots of things. We talk about the quick transition of the world’s workforce from on prem to telework as well as his recent move from leading FISMA at NIST to their newly created DevSecOps and why that matters now more than ever
About Ron Ross
Ron Ross (@ronrossecure) is a Fellow at NIST. His focus areas include cybersecurity, systems security engineering, cyber resiliency, security architecture, privacy, and risk management. Dr. Ross leads the FISMA Implementation Project and the Systems Security Engineering Initiative, which includes the development of cybersecurity and privacy standards and guidelines for the federal government, contractors, and the U.S. critical infrastructure. Dr. Ross also leads the Joint Task Force, a partnership with the Department of Defense, Office of the Director National Intelligence, U.S. Intelligence Community, and the Committee on National Security Systems, with responsibility for the development of the Unified Information Security Framework for the federal government and its contractors. Dr. Ross previously served as the Director of the National Information Assurance Partnership, a joint activity of NIST and the National Security Agency. Dr. Ross also supports the U.S. State Department in the international outreach program for cybersecurity and critical infrastructure protection.
A graduate of the United States Military Academy at West Point, Dr. Ross served in many leadership and technical positions during his twenty-year career in the United States Army. He is a five-time recipient of the Federal 100 award for his leadership and technical contributions to critical cybersecurity projects affecting the federal government and is a recipient of the Presidential Rank Award. Dr. Ross has also received the Department of Commerce Gold and Silver Medal Awards and has been inducted into the National Cyber Security Hall of Fame. In addition, Dr. Ross has been inducted into the Information Systems Security Association Hall of Fame and given its highest honor of Distinguished Fellow. During his military career, Dr. Ross served as a White House aide and a senior technical advisor to the Department of the Army. He holds a Bachelors degree in Engineering from the U.S. Military Academy and Masters and Ph.D. degrees in Computer Science from the Naval Postgraduate School specializing in artificial intelligence and robotics.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
This is the true story, of 2 security professionals and their kids, living in house in the northern Midwest, now sequestered becaue of a global health crisis. Find out what happens, when Cybersecurity professionals stop being polite, and start getting real… The Real World… Stay Home Order Edition!
Any comic book readers out there? Who’s familiar with the Marvel family? Shazam family? Shazamily?
How about Reed & Sue Richards? The Fantastic Four? Mister Fantastc and the Invisible woman? Not sure if that one is appropriate because Sara is definitely not invisible… but Tom is definitely Fantastic
The point is… what happens in house run by pair of superho level cybersecurity professionals in the age of COVID19?
Oh… and did we mention they also own a livestock farm? Cows and horses and lots of other things?
How does a family already swimming in the world of Cybersecurity deal with working from home during the era of COVID19
This week on Insecurity, Matt Stephenson speaks with Sara and Tom Löfgren, a married couple, both elite cybersecurity professionals… who find themselves (along with the rest of us) in a quarantine situation. Is it different for security pros to bring it all in house? How do you balance co-workers, clients, kids and livestock… oh yeah… and still be a person?
About The Löfgren (that’s grammatically accurate if you are Swedish)
They have been raising baby chickens in their bathtub (Sara’s idea). They have somewhere around 4 kids and an estimated 50 horses but can't really keep count because they don't hold still. Sara’s cow's name is either Coco or Norman depending on who you ask.
About Sara Löfgren
Sara Löfgren is the Channel Sales Engineering Manager at Cylance. She has been working in computer security for nearly 20 years with a focus on solving enterprise security problems through the union of technology, people, and processes.
Besides malware, her other main areas of interest include privacy, cryptography, and technology regulations. Sara lives in Minnesota with 4 kids, 2 dogs, a cat, and many rescue horses.
Oh… her husband Tom… we’re pretty sure he’s around too.
About Tom Löfgren
Tom Löfgren is a Sales Engineer at Ionic Security. He’s really good at securing Linux and encryption.
Because he is really good at security, privacy and encryption… we don’t know much about him other than the kids, the dogs, cat and rescure horses… and Sara.
According to Sara, Tom plays hockey and has eaten surstromming voluntarily. He has a map of Ikea in his head and thinks it's normal when people eat pasta with ketchup on it (again… according to Sara… because Tom is really good at security and privacy, so we are going to have to take her word for it).
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Theresa Payton & Doug Citizen: Who Do You Trust?
The 2016 Oxford Dictionary word of the year was post-truth
2017 Term of the Year by the Collins English Dictionary was Fake News
Has it really been nearly 15 years since Stephen Colbert brought truthiness into our lives?
It used to be, everyone was entitled to their own opinion, but not their own facts. But that's not the case anymore. Facts matter not at all. Perception is everything. It's certainty.
-- Stephen Colbert; AV Club, 01.25.06
Only in today's modern age can you hate your neighbor but love someone posting something in Germany that you don't even know
-- Clint Watts; 07.15.08
Distorting the truth is not just about elections it’s a global issue. It’s a war against our minds. Making us not know who or what to believe… manipulating us to create a vacuum and make you not trust reputable sources of information. It’s about all social issues. It impacts all countries. The motivations behind it are not what you think and will surprise and shock you.
Reporters and overall traditional news media are at risk… Let’s talk about why…
Elections are at risk… Let’s talk about why…
Let’s see if we can help you get learned up on spotting manipulation campaigns and how to report them.
And… not for nothin… how can we help you avoid being a victim of one?
This week on InSecurity, Matt Stephenson welcomes 3 time defending champion Fortalice CEO and former White House CIO Theresa Payton back to the show. We add a wrinkle this week by inviting Dough Citizen… an undisclosed “regular person” who is a small business owner, voter and someone who genuinely cares about the present & future of his country. This isn’t about politics, this is about the mechanics of elections & government. Don’t get it twisted… this is more important than ever
About Theresa Payton
Theresa Payton (@TrackerPayton) is President and CEO of Fortalice Solutions, former White House CIO, star of the CBS hit show Hunted, and best-selling author of the book Privacy in the Age of Big Data.
Payton is one of the nation’s most respected authorities on information security, cybercrime, fraud mitigation, and security technology implementation.
As White House Chief Information Officer at the Executive Office of the President from 2006 to 2008, Payton administered the information technology enterprise for the President and 3,000 staff members.
Theresa founded Fortalice in 2008 and lends her expertise to government and private sector organizations to help them improve their information technology systems. In 2010, Security Magazine named her one of the top 25 "Most Influential People in Security."
Theresa’s new book drops in April.
Manipulated: Inside the Cyberwar to Hijack Elections and Distort the Truth
In her new book, cybersecurity expert Theresa Payton tells battlefront stories from the global war being conducted through clicks, swipes, internet access, technical backdoors and massive espionage schemes. She investigates the cyberwarriors who are planning tomorrow’s attacks, weaving a fascinating yet bone-chilling tale of Artificial Intelligent mutations carrying out attacks without human intervention, “deepfake” videos that look real to the naked eye, and chatbots that beget other chatbots. Finally, Payton offers readers telltale signs that their most fundamental beliefs are being meddled with and actions they can take or demand that corporations and elected officials must take before it is too late.
In the book, Theresa reveals:
About Doug Citizen
Doug is a small business owner in a municipality smaller than Tokyo by with more than 10 occupants. He lives in a town somewhere between the Atlantic and Pacific oceans and somewhere between the borders of Canada and Mexico. He represents 330,000,000 people in the conversation.
He cares. That’s what is important. Respect his security and privacy.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review
Reconnaissance.
Target.
Weaponize.
Paralyze the enemy.
Attack.
The enemy always votes for chaos.
“Voting is about our capability to change the way the government works by changing the people who makes the decsions. Voting is our capability to have a peaceful transfer of power. If you don’t have that, the alternatives are revolutions.”
-- Harri Hursti, Kill Chain: The Cyber War on America's Elections
If you don’t want to know how easy it is for a canny individual—or a malicious state actor—to hack into the electronic voting technology used in the U.S., don’t watch Kill Chain: The Cyber War on America’s Elections.
-- Stephanie Zacharek ; Time, 25 March 2020
This week on InSecurity, Matt Stephenson has a chat with security legend Harri Hursti and Nordic Innovation Labs co-founder Dan Webber about the sad state of affairs regarding the security of United States voting machines. Add in a health crisis that prevents voters from actually going to the polls and you get… what? Tune in and find out!
Make sure to check out the HBO Documentary Kill Chain: The Cyber War on America's Elections for an in-depth look at just how easy it can be to hack the voting process of one of the world’s most important elections.
Because this subject is that important, HBO has also made it available for free on YouTube.
About Harri Hursti
Harri Hursti (@harrihursti) is a founding partner at Nordic Innovation Labs. You may know him better as a world-renowned data security expert, internet visionary and serial entrepreneur. He began his career as the prodigy behind the first commercial, public email and online forum system in Scandinavia.
Harri founded his first company at the age of 13 and went on to cofound EUnet-Finland in his mid- 20’s. Today, he continues to innovate and find solutions to the world’s most vexing problems. He is among the world’s leading authority in the areas of election voting security and critical infrastructure and network system security.
Hursti is considered one of the world’s foremost experts on the topic of electronic voting security, having served in all aspects of the industry sector. He is considered an authority on uncovering critical problems in electronic voting systems worldwide. In the last 10 years, Harri has pursued this important area out of a sense of duty.
About Dan Webber
Dan Webber (@SocialDanWebber) is Managing Partner and Chief Innovation Officer at Nordic Innovation Labs. He has served as Chief Information Officer, Security Officer, and Technology Officer for 22 years, 13 of those years in healthcare and biotech, the other 9 in manufacturing, technology and hospitality companies.
Dan advises companies that provide artificial intelligence/machine learning, cyber security, innovation, design, analytics, advanced computing and digital services to large private and public enterprises around the world.
Over the course of his career, Webber designed, implemented, and envisioned the network and system process workflow for the first FDA Approved DNA based sequencing system as Chief Information Officer of Bayer Visible Genetics.
His pharmacogenomic systems supported drug discovery and research activities in the areas of HIV, HCV, HBV, and multiple areas of cancer.
About Kill Chain: The Cyber War on America’s Election
In advance of the 2020 Presidential Election, Kill Chain: The Cyber War on America’s Election stakes a deep dive into the weaknesses of today’s election technology, an issue that is little understood by the public or even lawmakers.
From directors Simon Ardizzone, Russell Michaels and Sarah Teale, the team behind HBO’s 2006 Emmy-nominated documentary Hacking Democracy, Kill Chain again follows Finnish hacker and cyber security expert Harri Hursti as he travels across the U.S. and around the world to show how our election systems remain unprotected, with very little accountability or transparency. Hursti’s eye-opening journey is supplemented by candid interviews with key figures in the election security community, as well as cyber experts and U.S. senators from both parties who are fighting to secure the integrity of the vote before November 2020.
As the film shows, individuals, foreign states and other bad actors can employ a myriad of techniques to gain access to voting systems at any stage – from voter registration databases to actual election results.
Through this lens, seemingly unrelated or uncoordinated security breaches of the recent past can be seen as part of a “kill chain” – a military doctrine to plot meticulous, long-game attacks, understanding that breaking down trust in voting results is the surest way to undermine democracy. As enlightening as it is disturbing, Kill Chain underscores the fragility of our election process and points to the clear solutions available to protect us against sabotage.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Women in Cybersecurity: Perspectives on The New Normal
Science is not a boy's game, it's not a girl's game. It's everyone's game. It's about where we are and where we're going. Space travel benefits us here on Earth. And we ain't stopped yet. There's more exploration to come
-- Nichelle Nichols
Tennis legend Serena Williams was once asked by a reporter about being considered “one of the greatest female athletes of all time,”
She replied: “I prefer the words ‘one of the greatest athletes of all time."
That made news for a week, which is embarrassing given the fact that Venus has more titles than Michael Jordan, Michael Schumacher and Cristiano Ronaldo… combined.
How bout we just round up the some of the top people in the field for a discussion on what is happening in this crazy world right now? Sound good? Good.
This week on Insecurity, Matt Stephenson speaks with an All-Star Cybersecurity panel of experts including Dr Jessica Barker, Cheryl Biswas, Sherri Davidoff & Theresa Payton. With COVID19 changing everything from industry conferences to the US Presidential Election process, what role does cybersecurity play in The New Normal and The Next Normal? Check it out…
About Dr Jessica Barker
Dr Jessica Barker (@drjessicabarker) is a leader in the human nature of cybersecurity. She has been named one of the top 20 most influential women in cybersecurity in the UK and awarded as one of the UK’s Tech Women 50. She is Co-Founder and Co-Chief Executive Officer of Cygenta, where she positively influences cybersecurity awareness, behaviors and culture in organizations around the world.
Dr Barker is a popular keynote speaker and shares her expertise in the media, for example on BBC News, Sky News, Channel 4 News and in Grazia magazine and the Sunday Times. She is Chair of ClubCISO, a peer-based members forum of over 300 information security leaders. In the last year, Dr Barker has given cybersecurity outreach sessions to over 5,000 school students.
Jessica’s new book Confident Cyber Security will be released on June 3rd, 2020, published by Kogan Page.
About Cheryl Biswas
Cheryl Biswas (@3ncr1pt3d) is a Strategic Threat Intel Analyst with a major bank in Toronto, Canada. Previously, she worked as a Cybersecurity Consultant with KPMG. Her experience includes strategic analysis of threat actors and campaigns, security audits and assessments, privacy, DRP, project management, vendor management and change management.
Cheryl holds an ITIL certification and has a degree in political science. She is actively involved in the security community as a conference speaker and a volunteer, and encourages women and diversity in infosec as a founding member of the The Diana Initiative.
About Sherri Davidoff
Sherri Davidoff (@sherridavidoff) is the CEO of LMG Security and the author of Data Breaches: Crisis and Opportunity. As a recognized expert in cybersecurity, Davidoff has been called a “security badass” by the New York Times. She has conducted cybersecurity training for many distinguished organizations, including the Department of Defense, the American Bar Association, FFIEC/FDIC and many more.
Sherri is an instructor for Black Hat, and the co-author of Network Forensics: Tracking Hackers through Cyberspace. Davidoff is a GIAC-certified forensic examiner (GCFA) and penetration tester (GPEN), and holds her degree in computer science and electrical engineering from MIT. She has been featured as the protagonist in the book, Breaking and Entering: The Extraordinary Story of a Hacker Called Alien.
About Theresa Payton
Theresa Payton (@TrackerPayton) is President and CEO of Fortalice Solutions, former White House CIO, star of the CBS hit show Hunted, and best-selling author of the book Privacy in the Age of Big Data.
Payton is one of the nation’s most respected authorities on information security, cybercrime, fraud mitigation, and security technology implementation.
As White House Chief Information Officer at the Executive Office of the President from 2006 to 2008, Payton administered the information technology enterprise for the President and 3,000 staff members.
Theresa founded Fortalice in 2008 and lends her expertise to government and private sector organizations to help them improve their information technology systems. In 2010, Security Magazine named her one of the top 25 "Most Influential People in Security."
Theresa’s new book, Manipulated: Inside the Cyberwar to Hijack Elections and Distort the Truth
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Dr Saif Abed: The Role of Technology in a Global Health Crisis
Coronavirus Cases: 179,223
Active Cases: 93,871
Currently Infected Patients
in Mild Condition: 87,714
Serious or Critical: 6,157
Closed: 85,352
Cases which had an outcome:
Recovered / Discharged: 78,285
Deaths: 7.067
"Containing something as transmissible as COVID-19 means we shouldn't be flocking to a family physician or emergency room at the slightest symptom, because that can exacerbate spread, so remote monitoring could be powerful,"
What can the technology that we have already developed due in a time of global crisis such as the one we are facing now with COVID-19? Why not go directly to the experts for more information?
This week on Insecurity, Matt Stephenson speaks with cybersecurity expert Dr Saif Abed, founder of The Abed GrahamGroup, Clinical Cyberdefense Systems and a MEDICAL DOCTOR. If we’re going to speak with someone about what technology can accomplish during a worldwide healthcare crisis, a cybersecurity expert with an MD is a great place to start. Check it out…
About Dr Saif Abed
Dr Saif Abed (@Saif_Abed) is a medical doctor and healthcare cybersecurity/national security expert. He is a recognised subject matter expert within all sub-sectors of healthcare IT with a primary field of specialisation in cyber-warfare and crime targeting public sector healthcare systems.
He is currently a Founding Partner and Director of Cybersecurity Services at The Abed Graham Group, Europe's leading exclusively clinically based healthcare cybersecurity consultancy.
He is also the CEO of Clinical Cyber Defense Systems, a Boston based cybersecurity analytics company supporting US healthcare providers to derive clinical and business insights from technical security data.
He holds additional roles as an independent expert for the European Commission's Horizon 2020 programme with a focus on healthcare and cybersecurity and as an expert for the World Health Organisation's Digital Health Technical Advisory Group.
Dr Abed is regularly invited to contribute content and thought leadership for national media outlets, healthcare technology articles and global security events.
Additionally, he has previously been recognised as a multiple international award winning and published researcher in the field of oculo-plastic surgery whilst a trainee at St. George's Hospital Medical School, London.
About The AbedGraham Group
The Abed GrahamGroup (@AbedGraham) is a leading, clinically based, European health IT and cybersecurity consultancy that provides advisory services for large technology infrastructure suppliers and government agencies that are involved in, or are responsible for, the digital transformation of healthcare systems. Our consultants are clinically trained as well as being qualified experts in specialist areas such as cybercrime and threat modelling. Selected services including strategic research, policy analysis, bid support, regulatory compliance guidance and project management.
About Clinical Cyber Defense Systems
Clinical Cyber Defense Systems (@CyberClinical) is a US developer of cybersecurity analytics and visualization platforms for healthcare providers. CCDS is headquartered in Boston, Massachusetts and is composed of a team of pioneering physicians, security architects and data scientists.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Richard Stiennon: Security Yearbook 2020
Security Yearbook 2020 is the story of the people, companies, and events that comprise the history of of the IT security industry. In this inaugural edition, author Richard Stiennon digs into the early history of Symantec, Network Associates, BorderWare, Check Point Software. These iconic names and dozens of other companies contributed to the growth of an industry now is comprised of over 2,000 vendors of security products.
In addition to the history there are stories from industry pioneers such as Gil Shwed CEO and founder of Check Point Software; Chris Blask Co-inventor of Borderware Firewall and Sandra Toms Chief Organizer of the RSA Conference.
The directory lists all the vendors alphabetically, by country, and by category, making an invaluable desk reference for students, practitioners, researchers, and investors.
For the first time ever, a complete history of the development of IT security solutions is presented in one place. The focus is on the pioneers in the space and the companies that arose from their efforts. Individual stories from these pioneers are presented in their own voice while the overall story of the space is recounted as it grew from modest beginnings to a $100 billion+ industry with over 2,200 companies.
This week on InSecurity, Matt welcomes Richard Stiennon back to the show. Already a legend in cybersecurity, Richard poured his knowledge and skill into creating the Security Yearbook 2020. Is this THE definitive guide to the ever-evolving and growing Cybsecurity world? Tune in and find out!
If you are coming to the RSA Conference in San Francisco at the end of the month you can find copies all over. Check out Where to Find Stiennon at RSAC 202.
About Richard Stiennon
Richard Stiennon (@stiennon & @cyberwar)played his own part in the IT security industry starting in 1995 at Netrex, one of the first MSSPs. He was a Manager of Technical Risk Services at PricewaterhouseCoopers before being drafted into Gartner in 2000 to cover the network security industry.
He left Gartner in 2004 to join Webroot Software as VP of Threat Research. He has also had roles as Chief Marketing Officer at Fortinet, and Chief Strategy Officer at data erasure company, Blancco Technology Group.
Richard is the author of four books, including Secure Cloud Transformation: The CIO's Journey. He is an aerospace engineer (University of Michigan '82) turned historian (King's College, London, 2014)
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Kip Boyle: Virtual CISO at Your Service
Are you active on LinkedIn?
Not active like the ones who just say “congratulations on your work anniversary.” We mean active like asking questions, replying to posts and really engaging with your contacts.
There is a lot of great conversation out there that can provide answers to some important questions and contribute to solving problems in your work environment.
One of the things that makes LinkedIn great is that there are sincere people who genuinely want to help, not just their personal connections, but the larger community.
Kip Boyle is one of those people. Some people might find it enough to put in the work as a CISO. Others may stop after publishing their book. Not Kip Boyle. Kip is out there every day engaging fellow security professionals in conversations that spur creative approaches to solving problems.
His latest project is looking into how he can ease the entrance into the world of Cybersecurity. Take a moment to check out Masterclass: How to Break Into Cybersecurity
Matt welcomes Kip Boyle back to InSecurity. Kip is a cybersecurity CEO & author who is also prolific contributor to LinkedIn. We go through some of the more thought provoking conversations Kip has started on LinkedIn over the past year. These are the topics people are discussing. Join us to hear what the person who made the statement or asked the question has to say!
Fire Doesn’t Innovate
The Executive’s Practical Guide to Thriving in the Face of Evolving Cyber Risks
Combating cybercrime is a necessity of doing business in the 21st century. Financial and identity thefts occur with annoying frequency, and no executive today can afford to ignore the damage phishing, malware, and malicious code pose to their company’s future. But, with this invaluable guide, anyone, no matter what their skill level or bandwidth, can become an effective cyber risk manager holds.
About Kip Boyle
Kip Boyle (@KipBoyle) is a 20-year information security expert and is the founder and CEO of Cyber Risk Opportunities. He is a former Chief Information Security Officer for both technology and financial services companies and was a cyber-security consultant at Stanford Research Institute (SRI).
Kip led the global IT risk management program for a $9 billion logistics company and was the Wide Area Network Security Director for the F-22 Raptor program. He has participated in several cybersecurity war game exercises and has worked closely with various government agencies including the FBI.
Boyle is a US Air Force officer and serves on the board of directors of the Domestic Abuse Women’s Network (DAWN). He’s been quoted in Entrepreneur magazine, Chief Executive magazine, and is the co-author of Chapter 68, Outsourcing Security Functions, in The Computer Security Handbook.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Jordan DeVries: Yes. User Exerpience Really Is THAT Important
This… ‘stuff’? Oh… okay. I see. You think this has nothing to do with you.
You go to your closet and you select out, oh I don’t know, that lumpy blue sweater, for instance, because you’re trying to tell the world that you take yourself too seriously to care about what you put on your back. But what you don’t know is that that sweater is not just blue, it’s not turquoise, it’s not lapis, it’s actually cerulean.
You’re also blindly unaware of the fact that in 2002, Oscar de la Renta did a collection of cerulean gowns. And then I think it was Yves St Laurent, wasn’t it, who showed cerulean military jackets? And then cerulean quickly showed up in the collections of eight different designers. Then it filtered down through the department stores and then trickled on down into some tragic “casual corner” where you, no doubt, fished it out of some clearance bin. However, that blue represents millions of dollars and countless jobs and so it’s sort of comical how you think that you’ve made a choice that exempts you from the fashion industry when, in fact, you’re wearing the sweater that was selected for you by the people in this room. From a pile of “stuff.”
-- Miranda Priestly; The Devil Wears Prada, 2006
Think of something in your life that works well. It really works. There are a couple of ways to consider this thing.
What these things have in common is superior design which leads to gratifying User Experience.
We all have User Experiences in our lives that run the spectrum from surprisingly fun and wonderful to grating and dread-inducing. While many of us enjoy traveling, few of us would consider the queue at TSA to be part of the trip that we look forward to. However, consider the options without the design of airport security and things start to look a little different.
Many of us don’t take the time to consider the surrounding work that is done to ensure that when we use A Thing, we get the most out of our experience. Many of us don’t realize how much research and development goes into creating a smooth, satisfying User Experience. Many of us may not even realize that there are some very special people who are experts at crafting the intersection between creators of A Thing and users of A Thing.
Matt sits down with Jordan Devries, Director of User Experience at Brave UX to discuss what goes into designing a product or service or solution that will provide the maximum positive User Experience. And they might talk about why Legos are the greatest UX ever made. What does this have to do with security? Stick around…
About Jordan DeVries
Jordan DeVries (@theastralj) is the Director of User Experience at Brave UX. With a background in design, animation, code, and content, Jordan guides projects through both information architecture and visual design with a specialization in complex interfaces for desktop, mobile and web.
He did his undergrad work at Carnegie Mellon where he earned a degree in Mechanical Engineering.
Jordan’s teammates at Brave UX consider him a Pop Culture guru and random fact machine. He’s also a bit of a Lego enthusiast… to put it mildly.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the broadcast media team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and video series at events around the globe.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
If you like global intrigue, financial crime, wealth porn, and absurdity, “Billion Dollar Whale,” by Tom Wright and Bradley Hope, is for you. It’s the story of Jho Low, an enterprising businessman from Malaysia who used his social connections to the country’s former Prime Minister Najib Razak to transform himself into an international financier. According to Wright and Hope’s account, Low persuaded Razak to create an investment fund, 1MDB, financed with government money, which Low managed behind the scenes. Goldman Sachs and other banks helped raise ten billion dollars for the fund. Then approximately five billion dollars of the money disappeared, prompting an international scandal.
"I met these guys, and said to my girlfriend Anne, ‘these guys are #@&%ing criminals… this is a #@&%ing scam, anybody who does this has stolen money.‘ You wouldn't spend money you worked for like that."
"I am very pleased to confirm that a landmark comprehensive, global settlement has been reached with the United States government."
This week on InSecurity, Matt Stephenson welcomes Pulitzer Prize nominated journalist Bradley Hope for a conversation detailing the mindboggling saga of Jho Low and his jaw dropping tale of theft and debauchery. How do you break into Hollywood, New York society and Global Financial Markets? Having $5 BILLION in purloined money in your pocket certainly helps. Stick around…
About Bradley Hope
Bradley Hope (@bradleyhope) has worked for the Wall Street Journal for the last four years, covering finance and malfeasance from New York City and London.
Before that, he spent six years as a correspondent in the Middle East, where he covered the Arab Spring uprisings from Cairo, Tripoli, Tunis, and Beirut. He was detained by authorities in Bahrain, reported from the front lines of the Libyan civil war, and has been teargassed in raucous Egyptian protests.
Bradley is a Pulitzer finalist and a Loeb winner, and also author of Last Days of the Pharaoh, a chronicle of the final days and hours of the presidency of Hosni Mubarak.
“Billion Dollar Whale,” an Absurd Tale of Financial Fraud
The definitive inside account of the 1MDB scandal, a true life thriller about a modern Gatsby who managed to swindle over $5 billion with the aid of Goldman Sachs and others.
Billion Dollar Whalre is an epic tale that exposes the secret nexus of elite wealth, banking, Hollywood, and politics from two award-winning Wall Street Journal reporters.
In 2009, with the dust yet to settle on the financial crisis, a baby-faced, seemingly mild-mannered Wharton grad began setting in motion a fraud of unprecedented gall and magnitude--one that would come to symbolize the next great threat to the global financial system. His name is Jho Low, a man whose behavior was so preposterous he might seem made up.
An epic true-tale of hubris and greed, Billion Dollar Whale reveals how this young social climber pulled off one of the biggest heists in history--right under the nose of the global financial industry. Federal agents who helped unravel Bernie Madoff's Ponzi scheme say the 1MDB affair will become the textbook case of financial fraud in the modern age--and its fallout is already being credited for taking down the prime minister of Malaysia.
For readers of Liar's Poker, Den of Thieves, and Bad Blood, Billion Dollar Whale will become a classic, harrowing parable about finance run amok.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of InSecurity podcast and video series at events all over the world.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on InSecurity, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Blockchain and AI and IoT, OH MY!
“Whereas most technologies tend to automate workers on the periphery doing menial tasks, blockchains automate away the center. Instead of putting the taxi driver out of a job, blockchain puts Uber out of a job and lets the taxi drivers work with the customer directly.”
-- Vitalik Buterin, co-founder Ethereum and Bitcoin Magazine
According to our friends at Proto, IDC Health predicts that blockchain adoption in health care will increase eightfold by 2022. Yet for now, it remains a technology in its infancy, and one recent survey of health care organizations found that only 6%
were building blockchain programs and just 3% had pilot programs underway. Nearly two in five weren’t doing anything at all.
“it’s pretty confusing, right?" slick-to-the-touch banker Jared Vennett (Ryan Gosling) asks in voiceover not far into The Big Short. "Does it make you feel bored? Or stupid? Well, it’s supposed to. Wall Street loves to use confusing terms to make you think only they can do what they do. Or even better, for you to just leave them the #@&% alone:
-- Jared Vennett (Ryan Gosling); The Big Short, 2015
Does the cybersecurity industry do that to you?
Do we set up in these vocabulary word protected forts in order to unnerve you to the point that you doing really understand anything other than the fact that ALL YOUR DATA IS AT RISK AND ONLY WE CAN SAVE YOU
What if I told you that there are plainspoken people involved in some of the most esoteric aspects of security who really WANT you to understand what is happening and why some magical technology might provide a better solution
What if she used plain language to explain some very bleeding edge technology?
Spiritus CEO Susan Ramonat joins Matt Stephenson this week to talk about the role of Distributed Ledger Technology and Blockchain in securing healthcare data
About Susan Ramonat
Susan Ramonat is the CEO of Spiritus, where she draws upon 25 years of executive experience in enterprise sales, product management, technology strategy, corporate development, operational risk management, and cybersecurity.
She is a strategic ground-breaker with a historical sensibility. In her work, Susan brings an understanding of context, contingency and uncertainty to bear with humility and pragmatism to inform decisions and promote a recognizably human, desirable future.
She speaks frequently at industry conferences and universities about DLT/blockchain, artificial intelligence, IoT and cybersecurity for critical infrastructure.
Susan serves on the Dean’s Advisory Council at Loyola University Chicago and is an Industry Associate at UCL Blockchain Centre of Excellence. She is a magna cum laude graduate of Princeton University.
About Spiritus
Spiritus (@SpiritusPtrs) is delivering ground-breaking transparency and analytics about the safety and condition of medical devices at the point of care.
With Spiritus, health systems, manufacturers and 3rd party service providers connect the dots across a medical device's operating life cycle. In a shared middle ground, they agree on a single service history… for life, using multi-party consensus.
Based in Exton, PA with a development center in Edinburgh, Scotland, Spiritus is raising the bar for governance, risk and compliance at leading health systems in the process of digitally-enabling their clinical operations.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of InSecurity podcast and video series at events all over the world.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on InSecurity, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
“Your most unhappy customers are your greatest source of learning
-- Business @ the Speed of Thought; Bill Gates, 1999
“I think most people either forget or don’t know that Microsoft only hires people with IQs well over 130”
-- NY Times; Douglas Coupland, 1998
Last week, Microsoft Windows turned 34 years old. Next year, it can be President of the United States.
You think that means Microsoft is getting old and losing touch? Maybe… but consider the facts that, as of May 07, 2019, 1.5 BILLION machines run Windows AND… according to Microsoft, over 900 MILLION machines run Windows 10.
Every day, Microsoft analyzes over 6.5 TRILLION signals in order to identify emerging threats and protect customers.
While Microsoft may not be rolling out streaming services or dropping new devices in splashy events every fall, this summer, they quietly became only the third company in world history to be valued at over ONE TRILLION DOLLARS.
Say what you will about them, but it’s a lot harder to go through a day without Office, Windows and Azure than it is without an iPad, Linux or Amazon
And… don’t even get us started on gaming…
Halo? End of discussion. Steam? As of November 2018, 90% of Steam gaming machines were running Windows 10
There’s a reason Bill Gates overtook Warren Buffet as the world’s wealthiest person.
This week on InSecurity, Matt Stephenson chats with CQURE founder & CEO Paula Januszkiewicz about the security orbit around Microsoft… what are the misconceptions? What is Microsoft doing right? How does security training impact an organization? What is hype and what is legit in security? And a bit more…
About Paula Januszkiewicz
Paula Januszkiewicz (@PaulaCqure) is the founder and CEO of CQURE Inc., a a provider of specialized services in IT infrastructure security, business applications, consulting and advisory services.
She is an IT Security Auditor and Penetration Tester, Cloud and Datacenter Management MVP and trainer (MCT), and Microsoft Security Trusted Advisor.
Paula is also a top speaker at many well-known conferences including TechEd conferences around the world, Microsoft Ignite, RSA, Black Hat USA, and CyberCrime.
She is engaged as a keynote speaker for security related events and writes articles on Windows Security. She drives her own company, CQURE, working on security related issues and projects. Paula has conducted hundreds of IT security audits and penetration tests, some for governmental organizations.
Her distinct specialization is on Microsoft security solutions-she holds multiple Microsoft certifications, and is familiar with and possesses certifications in other related technologies. Paula is passionate about sharing her knowledge with others. In private, she enjoys researching new technologies, which she converts to authored trainings.
Oh… and… Paula has access to the Windows source code!
About CQURE Inc. and CQURE Academy
CQURE is a provider of specialized services in IT infrastructure security, business applications, consulting and advisory services. Our projects Every project is discussed in detail with Clients. We believe that this is the only way to achieve full satisfaction in IT projects. Our key to success are: highly qualified team and good planning. We build the detailed project schedules, thus avoiding a delay.
CQURE was formed in November 2008 and since that time we finalized many projects: starting from IT, Security Audits, ending up with trainings and implementations. Clients range from the global corporations to small companies. For large and medium companies they offer authorship training packs, intensive IT Security audits for the whole IT environment and solutions adjusted to their needs.
CQURE Academy (@CQUREAcademy) is a part of CQURE company that was formed in 2008 in Poland and since then has expanded to the rest of Europe, the Americas, Middle East and Asia – as well as opening offices in New York and in Dubai.
On a daily basis, they deliver IT services — ranging from IT security audits, to penetration tests or solution implementations in big and small organisations around the world. In CQURE Academy they share our expertise offline at seminars and conferences and online through videos and blog posts.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the host of the InSecurity podcast and video series at events all over the world.
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on InSecurity, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
In the summer of 2017,a group of political activists in the UK figured out how to use Tinder to attract new supporters.
They understood how the platform worked and how its users tended to use the app. Most importantly, they understood how Tinder’s algorithms distributed content, so they built a bot to automate flirty exchanges with real people.
Over time, those flirty conversations turned to politics—and to the strengths of the U.K.’s Labour Party. The bot would take over a Tinder profile owned by a user sympathetic to the Labour party who agreed to the temporary repurposing of the account.
The bot then sent roughly 40,000 messages, targeting 18- to 25-year-olds where the Labour candidates were running in tight races. While it is impossible to know if any voters were actually swayed by this campaign, what cannot be denied are the results of the election. In several targeted districts, the Labour Party won in tight races.
As part of their victory celebrations… some of the winners gave Twitter shoutouts to the Tinder election bot.
(This information is courtesy of Philip N. Howard and his article How Political Campaigns Weaponize Social Media Botsfrom IEEE Spectrum; October, 2018)
Here’s the thing though… not all Bots are the same. In fact, not unlike most things in the world, the overwhelming amount of Bots perform important, yet perhaps tedious functions that allow people to focus on high-level assignments that truly support agency missions and outcomes.
However, automation is not solely about offloading mundane tasks from humans. Instead, this type of technology creates an environment in which humans and technology not only collaborate to accelerate workflow processes but also speeds up decision-making.
In this episode of the InSecurity Podcast, Matt Stephenson sits down with Ron Jones, Head of Solutions Architecture at Blue Prism. Ron is a builder of Robotic Process Automation. A mouthful right? You may know them as “Bots” and they are one of the most misunderstood pieces of technology around. Stick around and Ron will help you understand them a little better.
About Ron Jones
Ron Jones (@rgjSP) is an experienced leader specializing in enterprise technology strategy and consulting for the public sector.
Ron currently serves North American Public Sector organizations implementing Blue Prism, the world’s most scalable, secure, and proven intelligent automation platform.
About Blue Prism
Blue Prism (@blue_prism) pioneered Robotic Process Automation (RPA), emerging as the trusted and secure intelligent automation choice for the Fortune 500 and the public sector. They offer a connected-RPA supported by the Digital Exchange (DX) app store—marrying internal entrepreneurship with the power of crowdsourced innovation. Blue Prism’s connected-RPA can automate and perform mission critical processes, allowing people the freedom to focus on creative, meaningful work. More than 1,500 global customers leverage Blue Prism’s Digital Workforce deployed in the cloud or on premises as well as through the company’s Thoughtonomy SaaS offering, empowering organizations to automate billions of transactions while returning hundreds of millions of hours of work back to the business.
Blue Prism was recently named to Fast Company’s inaugural list of the Best Workplaces for Innovators – an honor achieved by 50 companies. Blue Prism is the only RPA provider and UK-based company to be recognized.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Brian Haugli: Livin’ La Vida CISO
According to our friends at Ponemon… in a 24 month period, a business has a 1 in 4 chance of being hit with a significant threat.
A separate study shows that nearly 75% of businesses do NOT have an established incident response strategy that is applied consistently across their organization.
In a Crisis Situation, the most scarce and precious resource a CISO has is time.
How a CISO implements his or her OODA Loop can make or break a company and a career.
What if you are a Small or Medium business who does not have a traditional C-Suite structure or security team?
What if you are a CISO and all eyes are on you?
Will you be ready?
Are you ready now?
What if we told you that there are companies out there who can help your organization deal with these crisis situations without the process and expense of hiring a full time CISO?
In this episode of the InSecurity Podcast, Matt Stephenson with Side-Channel Security co-founder and former CISO Brian Haugli. Brian has been around the CISO block more times than most and is the host of the #CISOLife series on YouTube. He is leading the charge to bring Enterprise Level CISO talent to mid-market companies in order to protect their business and keep the bad guys out.
About Brian Haugli
Brian Haugli (@BrianHaugli) is a Co-Founder and Partner at SideChannel Security. He is also the creator and host of #CISOLife on YouTube.
Viewed as a "full stack CISO", he is an executive security leader and mentor focused on building high performance security teams, deploying effective operating models, and delivering risk management capabilities for global, domestic, and local enterprises. Brian has held senior advisory & practitioner roles within DoD, the Intelligence Community and Fortune 1000 companies.
He has been recognized as a NIST expert, specifically with the Cyber Security Framework (CSF) and 800-53, and for industrial control systems & operational technologies.
Brian is a firm believer that the small & mid-market companies deserve security guidance and realistic capabilities just the same as large organizations.
About SideChannel Security
Side Channel Security specializes in consulting organizations who need CISO advice to protect their digital assets. They offer CISO & advisory services to the C suite, their boards, and those accountable for security across their operations or their products.
SideChannel Security has engaged in military operations under the DoD and consulted the largest companies in the world in Big 4 consulting.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
John McClurg: The Most Interesting Man in Cybersecurity
The police often question him just because they find him interesting
Mosquitos refuse to bite him purely out of respect
In museums, he is allowed to touch the art
Once while sailing around the world, he discovered a short cut
He has won the lifetime achievement award, twice
His business card simply says “I’ll call you”
When you’ve traveled the globe and seen and done it all… what in the cybersecurity world gets you out of bed in the morning?
How about taking down legendary hackers like Kevin Poulsen or Harlod James Nicholson? Too ordinary… okay… Imagine your first day as CSO at Dell and it starts in Baghdad. Maybe taking on the Mexican drug cartels with their IT budgets that are comparable to G7 countries… Maybe it’s something like studying the intersection of linguistics, philosophy, religion, law and interpretation… you know… Hermeneutics.
Now… about being the Most Interesting Man in Cybersecurity…
This week on Insecurity, Matt Stephenson sits down with one of those rare, been-there-done-that cybersecurity legends, John McClurg. John has tackeld cybersecurity for the FBI, the CIA, private enterprise and everywhere in between. He’s forgotten more amazing stories about security than most of us will be lucky enough to witness. Pull up a chair and enjoy!
About John McClurg
John McClurg is an American security professional. He spent his early career with the US government, serving as both a supervisory special agent and branch chief for the FBI as well as a deputy branch chief for the CIA. In these roles, McClurg was involved in the capturing of both Kevin Poulsen and Harold James Nicholson.
Following his public service, John has served as a vice-president and Chief Security Officer for Lucent, Honeywell, Dell, and currently BlackBerry|Cylance.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Dr Saif Abed: From the ICU to the Data Center; Why an MD in Cybersecurity Makes Sense
I was feelin' so bad,
I asked my family doctor just what I had,
I said, Doctor…
Mr. M.D. …
Now can you tell me, tell me, tell me,
What's ailin' me?"
--Good Lovin’; The Rascals, 1966
What if I told you that, according to the 2018 Horizon Report from Fortified Health Security, 100 percent of web applications connected to critical health information is vulnerable to cyber attacks.
Varonis tells us that the loss of data and related failures will cost healthcare companies nearly $6 trillion in damages in the next three years.
Meanwhile, ISACA reports that 27% of healthcare firms say they are unable to find candidates to fulfill cybersecurity roles
This week on Insecurity, Matt Stephenson speaks with cybersecurity expert Dr Saif Abed, founder of AbedGraham, Clinical Cyberdefense Systems and a MEDICAL DOCTOR! Why would someone leave the calm world of the ICU for the chaos of securing a data center? Take a walk with Dr Abed to learn about his journey from healing patients in the surgery to keeping patient data safe and protected worldwide.
About Dr Saif Abed
Dr Saif Abed (@Saif_Abed) is a medical doctor and healthcare cybersecurity/national security expert. He is a recognised subject matter expert within all sub-sectors of healthcare IT with a primary field of specialisation in cyber-warfare and crime targeting public sector healthcare systems.
He is currently a Founding Partner and Director of Cybersecurity Services at AbedGraham, Europe's leading exclusively clinically based healthcare cybersecurity consultancy.
He is also the CEO of Clinical Cyber Defense Systems, a Boston based cybersecurity analytics company supporting US healthcare providers to derive clinical and business insights from technical security data.
He holds additional roles as an independent expert for the European Commission's Horizon 2020 programme with a focus on healthcare and cybersecurity and as an expert for the World Health Organisation's Digital Health Technical Advisory Group.
Dr Abed is regularly invited to contribute content and thought leadership for national media outlets, healthcare technology articles and global security events.
Additionally, he has previously been recognised as a multiple international award winning and published researcher in the field of oculo-plastic surgery whilst a trainee at St. George's Hospital Medical School, London.
About AbedGraham
AbedGraham (@AbedGraham) is a leading, clinically based, European health IT and cybersecurity consultancy that provides advisory services for large technology infrastructure suppliers and government agencies that are involved in, or are responsible for, the digital transformation of healthcare systems. Our consultants are clinically trained as well as being qualified experts in specialist areas such as cybercrime and threat modelling. Selected services including strategic research, policy analysis, bid support, regulatory compliance guidance and project management.
About Clinical Cyber Defense Systems
Clinical Cyber Defense Systems (@CyberClinical) is a US developer of cybersecurity analytics and visualization platforms for healthcare providers. CCDS is headquartered in Boston, Massachusetts and is composed of a team of pioneering physicians, security architects and data scientists.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
El Camino School: Teaching the Future Unsung Heroes of Music
In the IT world, we carry laptops, tablets and phones. Our performance areas include data centers and server rooms. Imagine a world where the creation, maintenance and repair of our most important tools was the most overlooked part of the industry.
Imagine a world where most people actually believed that the talented sales and marketing people… built their own machines and not only kept them running at top optimization, but also did the innovation that created The Next Big Thing.
While there are definitely those types in our industry… the unsung heroes are often the folks down in the trenches of the data center and on the other end of the helpdesk tickets that we open.
In the music world, it is no different. When we see or hear Jack White or Kerry King melting our brains on stage, they are not the only ones responsible for the art they create. There is an entire world of roadies, guitar techs and others who work in anonymity behind the scenes in order to bring a band and performance to life.
Hey… you in the data center… sound familiar?
This week on Insecurity, Matt Stephenson has a chat with John Theisen, founder of El Camino School, a new school in Central Florida that is about not just making music… but making and repairing the things we use to make music. What does this have to do with IT? Any time you hear guitar or amp, swap in laptop and server. Guitar techs are the help desk of the music world!
About El Camino School
El Camino School (@elcaminoschoolusa) is a community-based music school offering a wide variety of courses, lessons, guest lectures and events. One of the main focuses at El Camino School will be trade-based learning, and developing the next generation of touring technicians, but that’s not all.
The school’s primary objective is to create a true collaboration with the community and local music industry in order to impart knowledge for those seeking to further their understanding, careers, or hobbies. We also aim to educate current and aspiring musicians on how the music is created before the artists even strike a string. This includes everything under the surface in creating music, from guitar circuitry to the inner workings of a guitar amp or effects pedals. Musicians that understand how it all works are more likely to succeed in their craft.
The vision is to bring people together to grow in and around music, within the music. Aside from the technical aspects of music production, El Camino offers Music Therapy, a course that focuses on community building, wellness, and self-empowerment through music. The creation of music, moving to music, and even listening to music can do wonders when dealing with those with cognitive, emotional, and even physical conditions. El Camino School will also be providing music therapy to bridge the gaps between its students and the world around them.
About John Theisen
John Theisen is the founder of El Camino School. He is a longtime contributor to the local Orlando music scene, has had a love for music and a high amount of respect for the people that make the show possible behind the scenes. Aside from being a musician, he was a community fundraiser and arts administrator for over a decade. Theisen’s vision was to create a space that helps inspire and empower others through learning. This school is a community space where people can come together and learn from other professionals on their journey to becoming an integral part of a production or some future in music.
Moving to Central Florida in 1999, John attended the University of Central Florida and graduated with a degree in Cinema Studies, Film Theory and Mass Communication. He went on to become Head of Operations at the DMAC (Downtown Media Arts Center) where his passion for working for the greater community was sparked.
When John isn’t founding schools or contributing to the local art and music scene, John is the lead singer and washboard player (!) of the legendary Bloody Jug Band.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Haathi Cloth: Hacking the World of Indian Weddings
Are you familiar with India?
If not… well… this really isn’t the podcast for you
Here are some things you may or may not be familiar with
There are over 31 Million Non Resident Indians or Persons of Indian Origin living outside of India across the world. Over 7 Million NRIs or PIOs live in the USA, the UK and the Canada.
The Indian wedding market is estimated at $50 billion making it the world’s second-largest, after the $70 billion US market and it is growing at an estimated rate of 20% year over year.
Some would say… the traditional clothing one wears to an Indian wedding, while spectacular… is not that comfortable.
The a Southeast Asian engineer from the Midwestern US met an Indian Entreprenuer from Austin Texas… it was time for a change.
This week on Insecurity, Matt Stephenson sits down with the founders of Haathi Cloth for a discussion about Kurtas and pyjamas. What in the world does this have to do with cybersecurity and technology? Have you ever been in a data center where the pressure is on and it’s hot… like… really hot? Now try going to an Indian wedding in the summer. This was a system ripe for a Blue Team style hack.
About Josh Fu
Josh Fu (@jfusecurity), CISM, CISSP, is a Security Engineer for Cylance. Josh has experience as a Channel Manager and consultant in cloud infrastructure and as a Sales Engineer in cybersecurity. Josh founded the West Coast chapter of the International Consortium of Minority Cybersecurity Professionals and has presented in front of industry audiences across the country.
When he isn’t too busy protecting the world from cybercriminals and other miscreants, he finds the inefficiencies in other systems… which leads to the creation of companies like Haathi Cloth.
About Samit Shah
Samit Shah is a serial entrepreneur who can't look at a problem and not try to find a solution. He is currently involved as founder of 3 different companies: Haathi Cloth, Persource and Evolve Energy. These companies are about as far apart on the spectrum of what businesses do that they almost don’t even belong on the same chart. Where they intersect… is at Samit.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Brian Robison: Mobile Malware and APT Espionage
Until now, the public’s exposure to mobile phone malware has been dominated by news about the privately run “greyware” vendors, including Gamma Group, Hacking Team and NSO. Their commercial smartphone spyware seems to inevitably end up in the hands of autocrats who use it to hamper free speech, quash dissent, or worse. Consumers of these news stories are often left with the impression that mobile malware is just something paranoid dictators purchase for use within their own borders in luddite countries few people can find on a map. It is not.
In a coming report, BlackBerry Cylance researchers will reveal what the focus on those groups has overshadowed: several governments with well-established cyber capabilities have long ago adapted to, and exploited, the mobile threat landscape for a decade or more. In this context, mobile malware is not a new or niche effort, but a longstanding part of a cross-platform strategy integrated with traditional desktop malware in diverse ways across the geopolitical sphere.
This week on Insecurity, Matt Stephenson has a chat with BlackBerry Cylance Chief Evangelist Brian Robison about the scourge of Mobile Malware and how the threats that come from attacking mobile devices are different… and thus require a different mindset when it comes to securing those devices and your network.
About Brian Robison
Brian Robison has over 20 years of cybersecurity experience. As Chief Evangelist at BlackBerry Cylance he is focused on educating and inspiring the world. Robison hosts live Hacking Exposed events, where he demonstrates the tools and techniques of real-world threat actors.
Brian is a regular speaker at industry events such as RSA, Black Hat, thought leadership forums like ISC2 Think Tank and is highly sought after to speak at partner events.
Prior to joining BlackBerry Cylance, Robison worked to defend organizations from mobile security threats —three years as a Director at Citrix XenMobile and two driving enterprise strategy at Good Technology.
Brian also spent over six years at McAfee with a special focus on end-point security -leading efforts to modernize ePolicy Orchestrator. During this time, he also managed vulnerability and policy compliance solutions. His early career ranges from a six-year period with Tripwire, Inc. to cutting his professional teeth in consumer electronics at Diamond Multimedia.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Matt Stephenson: The AI Manifesto
Mirror, mirror on the wall
Tell me, mirror, what is wrong?
Can it be my de la clothes
Or is it just my de la song?
What I do ain't make-believe
People say I sit and try
But whan it comes to being de la
It's just me myself and I
-- Me Myself and I; De La Soul, 1989
What happens when all of your scheduled guests have to cancel? You roll with it and do something new!
Working from an essay by Malcolm Harkins and the BlackBerry Cylance Threat Intelligence Team, Matt Stephenson is going to take a look at Artificial Intelligence and a myriad of its ethical implications on industry and society as well as the roll the humanity must play.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Dave Castignola: Your Company got Acquired? Yeah… Been There
BlackBerry acquired Cylance in March… how’s it going?
On November 16, 2018, BlackBerry Limited announcedit had entered into an agreement to acquire Cylance. The announcement was met with optimism from a wide range of outlets.
“the combination of BlackBerry’s endpoint management tools and Cylance’s products could help to make the company a one-stop shop of sorts in the device protection and security market.”
-- Forbes
“$1.4bn match made in heaven”
-- The Register
On February 21, 2019, BlackBerry announced that it had completed the acquisition. The new iteration of BlackBerry Cylance made a soft opening at RSA, but the real debut was last month at Black Hat.
There have been many changes over the past 10 months, some more significant than others.
The question remains… is it working?
We are here to speak directly with someone who has been involved at the highest levels and has had his hands on the steering wheel throughout the process.
This week on Insecurity, Matt Stephenson gets the rare chance for a raw one on one conversation with BlackBerry Cylance Chief Operating Officer David Castignola, an industry veteran who lived through the RSA breach and has been on both sides of big acquistions. People have questions on who the BlackBerry Cylance integration is going… we have some answers.
About David Castignola
David Castignola (@davecastignola) is the Chief Operating Officer at BlackBerry Cylance. Prior to joining Cylance, Dave was Chief Revenue Officer and Executive Vice President of Worldwide Sales at Optiv. No stranger to the Sales game, Dave closed out nearly two decades at RSA as the Sr Vice President of Worldwide Sales
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Taylor Lehmann: So You Wanna Be a Healthcare CISO…?
LLLLLLLLLAAADIIIEEEEEZZZZZ aaaannnnnnd GEEEENNNNNTLLLLEMEEENNNNNN!!!!!
At 6 feet and 1 inches tall and weighing in at 230 pounds…
Hailing from University at Buffalo…
Managing an ecosystem made up of Over 160 THOUSAND partners and 120 MILLION patients
From greater metropolitan Boston MAAAAASSSSAchusetts
YOUR Chief Information Security Officerrrrrr…
Wouldn’t it be great if that’s your day started every day as a CISO?
Breaking News: Being a CISO is a hard job
You don’t get many, if any, Pro Wrestling style introductions
How hard a gig is this?
Our friends at Nominet Cybsecurity released a report this summer called Life Inside the Perimeter: Understanding the Modern CISO. It shone a harsh spotlight on the oftentimes brutal life of a CISO. Here 3 key stats to keep in mind whenever you heard the term CISO…
To paraphrase Forrest Gump… being a CISO is TOUGH
Now… just to add fun and excitement… try bing a CISO for an organization who is literally handling the technology that cures disease, heals the sick and saves lives
This week on Insecurity, Taylor Lehmann returns as the newly minted CISO at athenahealth. Matt Stephenson asks Taylor about what is involved as an outgoing and incoming CISO in healthcare. They also chat about what happens when a CISO goes from managing 10,000+ patients to 100 MILLION+ patients. No pressure right?
About Taylor Lehmann
Taylor Lehman (@sidechannelsec) is the Vice President and CISO at athenahealth. In a previous life, he was the CISO at Wellforce and Tufts Medical Center. He is also in demand as advisor, working with companies including IBM Security Global , Obisidian Security and Randori, among others. Additionally, Taylor is helping to carve the future with his advisory work with graduate students at MIT and Northeastern University.
Taylor is also an expert in securing software development and delivery, and is on the boards of Gartner Evanta, the HITRUST Community Extension Program, the TPA Summit, and the Business Associate Council. Somehow, he still finds time to raise 3 kids and trade punches and throws while training in mixed martial arts.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
InSecurity Podcast Mixtape: Hacker Summer Camp Edition
is there any better time of year to go to Las Vegas than early August?!?
We’re totally kidding… It’s hot and this year there was a plague of locusts!
But it is also the time of year when people from all walks of the Cybersecurity world gather to learn, teach and reconnect. Whether it is at BSidesLV, Black Hat, DEFCONor other events too cool to be on the radar, odds are, you are standing in line next to someone who knows how to either protect or break into a network.
We spoke with some of those folks...
Enjoy!
About Matt Stephenson
Insecurity Podcast host Matt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcastand host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcastsand GooglePlayas well as Spotify, Stitcher, SoundCloud, I Heart Radioand wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Old Dog and Young Buck: A Generational Look at Cybersecurity
Spider-Man : Hey guys, you ever see that really old movie, Empire Strikes Back?
War Machine : Jesus, Tony, how old is this guy?
Iron Man : I don't know, I didn't carbon date him. He's on the young side.
Captain America: Civil War; Joe& Anthony Russo, 2016
If you thought Twitter and Facebook outages were bad, then you probably don't remember the great online disruption of 1996. At the time, CBS Evening News reported that America Online, then the world's largest Internet Service Provide,r went down for 19 hours on a Wednesday in August. Peter Van Sant of CBS News had some… now in retrospect… completely adorable comments
"For some netheads and geeks - and that's what they call themselves - the crash of America Online left them feeling lost in cyberspace,"
The reporter went to a "nethead" hang out just to see how lost people were. According to Van Sant, "the worst thing of all for many netheads was having to resort to a more primitive technology: telephones and faxes"
And… just to put things in perspective…AOL did offer its customers a free day of service, which wasn't a bad deal considering a monthly user would have had to pay $41 for 19 hours of online use.
And that's the way it was on Wednesday, August 7th, 1996.
This week on InSecurity, Matt Stephenson speaks with University of Florida Computer Science Major Lee Deffebach and BlackBerry Cylance VP of Sales Engineering Rich Thompson. One of them has witnessed the evolution of IT and cybersecurity from the front lines of a 25 year career. The other offers the perspective of someone born and raised in the digital/internet/mobile era. Where do the agree? Where do they diverge? What can they learn from each other? Tune in and find out
About Lee Deffebach
Lee Deffebachis a senior at the University of Florida studying Computer Science. He is interested in functional programming, artificial intelligence, security, and systems engineering.
We don’t know what the future holds for him… but he is definitely worth watching…
About Rich Thompson
Richard Thompson(@TheRichThompson) is Vice President of Sales Engineering, North America at Cylance. He has 25+ years of experience in security. This includes 21 years leading security efforts at the regional and national level in the retail industry, and 5 years leading Sales Engineering and Professional Services efforts in the enterprise software industry. He has experience in forensics, incident response, electronic discovery, information risk management and governance. Rich joined Cylance in October 2014 in order to help Cylance in the vision of protecting every endpoint under the sun. He also has surprisingly wide-ranging musical taste.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Broadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcastsand GooglePlayas well as Spotify, Stitcher, SoundCloud, I Heart Radioand wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Adversarial Machine Learning: How AI is Enabling Cyber Resilience
Martin Amor:HAL, you have an enormous responsibility on this mission, in many ways perhaps the greatest responsibility of any single mission element. You're the brain, and central nervous system of the ship, and your responsibilities include watching over the men in hibernation. Does this ever cause you any lack of confidence?
HAL:Let me put it this way, Mr. Amor. The 9000 series is the most reliable computer ever made. No 9000 computer has ever made a mistake or distorted information. We are all, by any practical definition of the words, foolproof and incapable of error.
Artificial Intelligence as we know it is neither good nor bad. These days, it seems like you can't go anywhere without hearing about how every company is using AI. Actually… what they are talking about, more often than not, is machine learning. As ML becomes a more ubiquitous tool for problem solving purposes, it will inevitably lead to its abuse in the form of adversarial ML. This can either be algorithms created for malicious purposes or neutral algorithms used for bad.
This week on InSecurity, Matt Stephenson speaks with BlackBerry Cylance Data Scientist Michael Slawinski and Sales Engineer Josh Fu on their Black Hat presentation discussing Adversarial Machine Learning. They predict that the next frontier for ML will be towards identification and authentication. The application of malicious intent to technology is a lot closer than we think.
About Josh Fu
Josh Fu (@jfusecurity), CISM, CISSP, is a Security Engineer for Cylance. Josh has experience as a Channel Manager and consultant in cloud infrastructure and as a Sales Engineer in cybersecurity. Josh founded the West Coast chapter of the International Consortium of Minority Cybersecurity Professionals and has presented in front of industry audiences across the country.
About Michale Slawinski
Michael Slawinski is a data scientist for the BlackBerry Cylance, focusing on deep learning and graph theoretic approaches to malware classification. Previously, Michael spent two and a half years working as a quantitative analyst and modeler in the commercial banking industry. He earned his B.Sc.and M.A. in mathematics at UCLA, and went on to earn a Ph.D. in mathematics from U.C. San Diego in 2011.
If you want to dig into more of what Mike is up to, check out his Github
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads theBroadcast Media team at BlackBerry, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of InSecurity TV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
LaColombe CEO Todd Carmichael: Yes… Coffee Really Is That Important
"You know… this is, excuse me, a damn fine cup of coffee. I’ve had I can’t tell you how many cups of coffee in my life, and this… this is one of the best"
-- Special Agent Dale Cooper, Twin Peaks
When is the last time you went to work and saw no one drinking a cup of coffee?
Imagine a cybersecurity world where this is no lattes… no PSLs… no nitro cold brews… I know… I know… it’s totally science fiction and the stuff of nightmares.
LaColombe co-founder and CEO Todd Carmichael is here to allay those fears. When he isn’t revolutionizing the coffee world, he is putting in good works around the country and around the world. Whether it is assisting in rebuilding Haitian coffee farms or working in his area to help his local school district, Todd has a lot on his plate.
Did we mention that he holds the world record for the fastest solo trek across Antarctica to reach the South Pole? Yeah. He did that.
Now consider our real world…
What if I told you that US coffee drinkers consume about 3 cups a day on average…
What if I told you that the US coffee shop market did $45.4 BILLION in business 2018 with over 35,000 stores…
Did I mention that Pabst Blue Ribbon recently introduced Hard Coffee?
Yeah… Coffee really is that important
This week on InSecurity Matt Stephenson speaks with Todd Carmichael about a life long, globe spanning journey that includes trekking across Antarctica, a hand-restored sailboat, all 7 continents, a hand made, blown glass bong that revolutionized the coffee industry, helping to rebuild Haitian coffee farms and how he hacked the coffee industry because “America deserves a better cup of coffee.”
About Todd Carmichael
Todd Carmichael’s passion to push the U.S. coffee scene forward, alongside his partner and co-founder JP Liberit, pushed La Colombe to the forefront of the ethical trade movement where they regularly dabble in new terrain, invent ground-breaking new brewing devices and beverages, such as the first ever Draft Latte. He is also the host of two Travel Channel series, Dangerous Grounds and Uncommon Grounds.
A passionate crusader for social and ecological causes, Todd has a decades-long history of undertaking self-supported treks into challenging environments. He’s visited nearly half of the world’s countries, crossed large parts of the Sahara Desert on foot, as well as the Gobi Desert, Namib Desert, and others. He is also the first American to solo trek across Antarctica from the coast to the South Pole, establishing a world record speed of 39 days, 7 hours, and 49 minutes.
Oh… and… in 2018, he was the 46th Coolest Dad in the world. Just saying…
Married to singer songwriter Lauren Hart, the couple have expanded their family by adopting three beautiful girls and a baby boy from Ethiopia. Todd is also an author and contributor to the Huffington Post and Esquire Magazines.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Parham Eftekhari: Is Government Cybersecurity Broken?
… the Internet is not something that you just dump something on.
It's not a big truck.
It's a series of tubes.
-- former Senator Ted Stevens, 2006
This photo… is not a photo of the internet… in case you were wondering.
Do we really want to trust that our elected officials have the slightest idea of what to do with regards to cybersecurity? Whether it is election meddling, attempts to hack voting facilities or data breaches of personnel records… this is territory that needs detailed research and expert analysis.
The current administration proposed an overall federal cybersecurity budget of $17.4 billion, which is an increase from the estimated $16.6 billion in fiscal 2019. Under this proposal, Civilian agencies overall would receive $7.79 billion which is roughly 1.5 percent below current levels.
If that number seems odd, that’s probably okay considering how much attention cybersecurity is attracting. However, it could have been worse, given the current administration’s general desire to trim civilian-agency spending. The White House is proposing to reduce overall non-defense spending by 5 percent.
With just a little bit of focus, we can discern that an agency was more likely to be proposed for an increase if it works on national security in some way. Cybersecurity efforts at the Departments of Energy, Justice and State all saw increases of over 7% or more.
Cyber programs at the Office of Personnel Management, which is under close scrutiny for how it protects the data of federal employees, saw a 4% increase to $47 million. You may recall the famous OPM data breach a few years back that put over 21 Million records into the wild
Oh… and… not for nothing… but it was Cylance that fixed that one…
In this episode of the InSecurity Podcast, Matt Stephenson welcomes ICIT Executive Director Parham Eftekhari for a chat about what is happening in Washington when it comes to American policies on Cybersecurity. We take a look at the key pillars of Technology, Budget, Lobbying/Partisan politics and Legislation. Wanna drain the swamp? Take a listen first.
About Parham Eftekhari
Parham Eftekhari (@icitorg) is the Executive Director of the Institute for Critical Infrastructure Technology (ICIT), the nation’s leading cybersecurity Think Tank whose mission is to improve the resiliency of the country’s 16 critical infrastructure sectors and empower generations of cybersecurity leaders. Leveraging 15 years of technology industry experience, Parham advises the world’s top public and private sector cybersecurity leaders, manages strategic alliances, executes business strategies, and builds meaningful thought leadership and educational programs.
Parham has organized, led or contributed to over 100 cybersecurity briefings and events at institutions including Congress, TEDx, C-SPAN and the World Bank, and regularly speaks to the media on cybersecurity issues.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
#BlackHat2018: A Look Back
The world of Cybersecurity is about to descend upon Las Vegas like a plague of locusts. Oh… wait… that appears to have already happened.
Tens of thousands of our Cybersecurity colleagues will converge for Hacker Summer Camp next week. We’ll be attending Black Hat, BSidesLV, The Diana Initiative and DEFCON.
Before we dive into what’s coming next week… let’s take a look at what we learned last year and see how the passing year shook out.
Volume III of the InSecurity Podcast Mixtape features CEOs, legendary technology journalists, and some of the key players in the world of cybersecurity talking about what expected out of Hacker Summer Camp 2018. Kick back and enjoy the perspectives this group of experts has to offer on the present state and future of cybersecurity
Enjoy!
A lesser blog would rip off someone else’s good writing, change a few words and then not give credit where it’s due… But that’s not how we roll here on the InSecurity Podcast.
If you want to read a really good summation of Hacker Summer Camp, check out System Overlord’s lowdown on Hacker Summer Camp and what is about to happen in Las Vegas next week . He drops some serious knowledge on how to maximize your experience.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Clint Watts: The World of Advanced Persistent Manipulators
This $#!%’s chess! It ain’t checkers
-- Detective Alonzo Harris; 2001, Training Day
Want to have some fun with some numbers? As of May 2019, the total worldwide population identifying as human is 7.7 billion. Among those people, 4.4 billion of them use the internet. Not quite everyone is sharing their lives, but there are 3.499 billion active social media users.
Are they all real people? That’s a valid question… There are an estimated 270 million fake Facebook profiles. Oh… and… in 2018 Twitter deleted 70 Million accounts they determined were fake. So there’s that.
Clint Watts studies terrorists, terrorism, social media, external forces meddling with elections and a lot of other Orwellian things. Since publishing Messing with the Enemy: Surviving in a Social Media World of Hackers, Terrorists, Russians, and Fake News last summer, he has looked deeper into other types of election hacking including Deepfakes. You may have seen his June testimony in front of the U.S. House of Representatives Permanent Select Committee on Intelligence on C-Span… if you’re a C-Span type of person.
In this week’s episode of InSecurity, Matt Stephenson welcomes Clint Watts back to InSecurity. This week, we dig into Advanced Persistent Manipulators. Like their technology cousin Advanced Persistent Threats, APMs are hard to quantify, harder to understand and ever more difficult to stop. With governments all over the world in a state of perpetual campaign mode and candidates running their own Troll farms, do we even know what to prepare for? Tune in and find out!
About Clint Watts
Clint Watts (@selectedwisdom) is a Distinguished Research Fellow at the Foreign Policy Research Institute, Non-Resident Fellow at the Alliance for Securing Democracy. His book best-selling Messing with the Enemy: Surviving in a Social Media World of Hackers, Terrorists, Russians, and Fake News shined a light on what has, is and could happen with regard to social media manipulation and the ways foreign interests can hack the electoral process. It was recently released in paperback.
Clint is also a national security contributor for NBC News and MSNBC. His research and writing focuses on terrorism, counterterrorism, social media influence and Russian disinformation. Clint’s tracking of terrorist foreign fighters allowed him to predict the rise of the Islamic State over al Qaeda in 2014. From 2014 – 2016, he worked with Andrew Weisburd and J.M. Berger to track and model the rise of Russian influence operations via social media leading up to the U.S. Presidential election of 2016. This research led Clint to testify before four different Senate committees in 2017and 2018regarding Russia’s information warfare campaign against the U.S. and the West.
Before becoming a consultant, Clint served as a U.S. Army infantry officer, a FBI Special Agent, as the Executive Officer of the Combating Terrorism Center at West Point, as a consultant to the FBI’s Counter Terrorism Division and National Security Branch, and as an analyst supporting the U.S. Intelligence Community and U.S. Special Operations Command.
His supporters think he’s had an interesting career, his enemies think he can’t hold down a job… both would be correct.
Messing with the Enemy: Surviving in a Social Media World of Hackers, Terrorists, Russians, and Fake News
A former FBI Special Agent and leading cyber-security expert offers a devastating and essential look at the misinformation campaigns, fake news, and electronic espionage operations that have become the cutting edge of modern warfare—and how we can protect ourselves and our country against them.
Clint Watts electrified the nation when he testified in front of the House Intelligence Committee regarding Russian interference in the 2016 election. In Messing with the Enemy, the cyber and homeland security expert introduces us to a frightening world in which terrorists and cyber criminals don’t hack your computer, they hack your mind. Watts reveals how these malefactors use your information and that of your friends and family to work for them through social media, which they use to map your social networks, scour your world affiliations, and master your fears and preferences.
Thanks to the schemes engineered by social media manipulators using you and your information, business executives have coughed up millions in fraudulent wire transfers, seemingly good kids have joined the Islamic State, and staunch anti-communist Reagan Republicans have cheered the Russian government’s hacking of a Democratic presidential candidate’s e-mails. Watts knows how they do it because he’s mirrored their methods to understand their intentions, combat their actions, and coopt their efforts.
Watts examines a particular social media platform—from Twitter to internet Forums to Facebook to LinkedIn—and a specific bad actor—from al Qaeda to the Islamic State to the Russian and Syrian governments—to illuminate exactly how social media tracking is used for nefarious purposes. He explains how he’s learned, through his successes and his failures, to engage with hackers, terrorists, and even the Russians—and how these interactions have generated methods of fighting back. Shocking, funny, and eye-opening, Messing with the Enemy is a deeply urgent guide for living safe and smart in a super-connected world.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlayas well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Wah Lum Kung Fu: Hacking Cosplay at San Diego Comicon
Every once in awhile the InSecurity Podcast takes a walk with the word “hack” to other parts of existence.
Yeah yeah… hard to believe that there are actual things out there besides cybersecurity…
In this special episode, Matt Stephenson will be talking with some folks who are hacking what could already be considered a hack. If we know our audience, it is a fair bet to say that there are plenty of folks who know the names Chun-Li (No… not the Nicki Minaj song, but that’s an interesting point) or Chen Zhen.
For those not on a first name basis… you definitely are familiar with Mortal Kombat or Double Dragon.
Okay… do we really have to resort to The Matrix? Kung Fu Panda?
We hope not
The point is that for the last 50 years, you would be hard pressed to look in a corner of American culture and not find the influence of Kung Fu.
Whether it is the greatest hip-hop collective ever The Wu-Tang Clan or Cirque Du Soleil’s KA… Maybe it is Kato from the Green Hornet or Morpheus or Chirrut Imwe in Rogue One… Kung Fu has evolved to a place where fight choreographers and stunt workers are getting billing nearly equal to writers and directors in film and television.
What does any of this have to do with Cylance or cybersecurity? Take a walk with us…
Cylance’s own Hiep Dang is a Sifu of Wah Lum Kung Fu and this week will be part of an amazing teaching session at San Diego Comicon!
Cosplayers, Ready your Swords!
Did you spend months making your costume? Ready to learn how to properly wield and pose with your sword, hammer, or lightsaber?
Cosplayers will learn how to bring their characters to life from Hollywood stunt performers and martial arts experts. Mimi Chan (model and martial arts reference for Disney’s Mulan) andChristopher Leps, (Pirates of the Caribbean, Daredevil) will partake in a discussion moderated by martial arts expert, Oscar Agramonte about their action experience and how it relates to cosplay.
Learn how to bring authenticity to your character from the panel and a team of martial arts experts. Be ready for action!
In todays’ special San Diego Comic Con episode of InSecurity, Matt Stephenson welcomes Sifu Mimi Chan and Sifu Hiep Dang to talk about a very different kind of hack. Kung Fu has been hacking Western culture for nearly 50 years. Cosplay has been hacking culture for nearly as long. It’s time the two got together. That’s exactly what is happening at SDCC. Find out more on this week’s InSecurity!
As a special treat for our listeners, you can get a one year 10 device subscription of Cylance Smart Antivirus for 50% off during the month of Comic Con. Click here to find out how!
About Mimi Chan
Mimi Chan (@SifuMimiChan) has been a Wah Lum kung fu instructor for the past 25 years, and was chosen as the model and inspiration for Disney’s cartoon Mulan. At 17, she won her first of many kung fu Grand Championship titles and retired from competition undefeated. After working as a stunt performer for several years, in 2012, she produced and directed the award-winning documentary: Pui Chan: Kung Fu Pioneer. Mimi is also the host of Culture Chat Podcast. Culture Chat Podcast explores a variety of topics including: social issues, film, comics, martial arts, traditions, food, pop culture, music, or anything inspiring and thought-provoking.
About Hiep Dang
Hiep Dang (@Hiep_Dang) is Director of Product Management & Marketing for Cylance where he is responsible for driving the vision and strategy of its Consumer products. During the day, Hiep geeks out on building innovative security products at Cylance-Blackberry and on nights and weekends, he teaches Kung Fu in Portland, OR. The recurring theme that persists in both his personal and professional lives is his passion for helping others learn how to keep themselves safe and secure in both the virtual and physical world.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Chuck Brooks: Examining the Future
I'm the operator
With my pocket calculator
I am adding
And subtracting
I'm controlling
And composing
By pressing down a special key
It plays…
Kraftwerk: Pocket Calculator, 1981 Computer World
How about this for a picture of the present with a look to the future…
What if I told you that chatbots will power 85 percent of customer service by 2020…
McKinsey Global Institute did a study that found 20% of C-level executives claim to be using Machine Learning and/or Artificial Intelligence as a core part of their business.
Our friends at IDC proclaimed that global spending on cognitive and AI systems is expected to reach $57.6 billion in 2021.
And finally… as if we aren’t already tired of hearing about the IT skills gap… Forbes recently announced that the number of jobs requiring AI skills has grown 450% since 2013…
Are we ready for the future?
Hell… are we even ready for the present!?!?!
Chuck Brooks has published over 180 articles about Cybersecurity, Artificial Intelligence, Homeland Security and the Internet of Things… among other things… He has written for some of the most important publications in the world including Forbes, The Hill and the MIT Sloan Blog. It is fair to say that Chuck has his eye on the future and has an idea or two about what needs to be done to secure it.
In this week’s episode of InSecurity, Matt Stephenson proudly welcomes in Chuck Brooks for a look into his crystal ball to see what the future may hold for the world of technology and, by definition, cybersecurity. We look at AI, automation, IoT, Quantum Computing and even Ray Kurzweil’s thoughts on what is to come. Want to get weird? This week’s episode is for you.
About Chuck Brooks
Chuck Brooks (@ChuckDBrooks) is the Principal Market Growth Strategist of General Dynamics Mission Systems for Cybersecurity and Emerging Technologies. He is also Adjunct Faculty in the graduate Applied Intelligence Program at Georgetown University and teaches courses in risk management, homeland security and cybersecurity. LinkedIn named Chuck as one of The Top 5 Tech People to Follow on LinkedIn out of their 600 million members. He was named by Thompson Reuters as a “Top 50 Global Influencer in Risk, Compliance” and by IFSEC as the “#2 Global Cybersecurity Influencer” in 2018. He is also a featured contributor to Forbes, a Cybersecurity Expert for The Network at the Washington Post and Visiting Editor at Homeland Security Today. Chuck has an MA in International relations from the University of Chicago, a BA in Political Science from DePauw University and a Certificate in International Law from The Hague Academy of International Law.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Cheryl Biswas: Diversifying Cybersecuity
You better watch out
Oh, what you wish for
It better be worth it
So much to die for
Hey, so glad you could make it
Yeah, now you've really made it
Hey, there's only us left now
--Hole – 1997, Celebrity Skin
What if I told that… compared to men, higher percentages of women cybersecurity professionals are reaching some of the most sought after positions in security. Among the security workforce, the population of women in key spots is surging…
Chief Technology Officer
Vice President of IT
IT Director
C-level / Executive
Women in cybersecurity are generally more educated and younger than their male colleagues. 44% of men in cybersecurity hold a post-graduate degree compared to 52% of women. Also, nearly half of women cybersecurity professionals surveyed are millennials – 45% compared to 33% of men. By contrast, Generation X men make up a bigger percentage of the workforce (44%) than women (25%)
Now… what if I told you that the gender pay gap hasn't moved at all. Women still make less than men. according to the 2018 (ISC)2report, women make $5,000 less than men in security management positions.
It is this environment that spurred a group of women to create The Diana Initiative.
In this week’s episode of InSecurity, Matt Stephenson chats with Cheryl Biswas on why the time was right to co-create The Diana Initiative. Now, 4 years later, Diana has a new home and is key part of that stretch of August where the cybersecurity world convenes in Las Vegas to figure out how to save the world. Their mission is to encourage diversity and support women who want to pursue careers in information security, promote diverse and supportive workplaces, and help change workplace cultures.
About The Diana Initiative
It was the summer of 2015. Hackers from around the world had gathered in Las Vegas, NV for DEF CON 23. In the cafeteria tucked away in the basement of Bally’s and Paris, 9 women found themselves chatting and laughing about their experiences in the field of Information Security. They were all passionate about their challenging roles in the male-dominated field and began exchanging strategies for success in their challenging environments. It was then and there that they accepted their new mission: to create a conference for all those who identify as women/non binaries, and to help them meet the challenges that come with being a woman in Information Security with resilience, strength and determination.
The first event in 2016 began with a morning speaking track and an afternoon of lockpicking and badge soldering in a small suite at Bally’s, bringing attendees together in a collaborative, comfortable setting. Interest and attendance showed that demand for a woman-focused InfoSec conference existed.
In 2017, The Diana Initiative was formed and the conference expanded to cover almost 2 days – with speakers on the evening of the first day, as well as the entire second day. There was also a hands-on opportunity for learning about lockpicking, a Career village, and fun contests.
During the summer of 2018, The Diana Initiative conference soared in popularity. But with this incredible growth and popularity, the space still couldn’t meet the demand, as attendees were continuously turned away due to over capacity of all the suites.
For more information, make sure to follow them at @DianaInitiativeand keep up with them on LinkedIN and Facebook.
About Cheryl Biswas
Cheryl Biswas’s (@3ncr1pt3d) fascination with computers started with those blinking machines on the original Star Trek, and the realization that, if she could learn to work those things, then she could boldly go – anywhere! But Cheryl didn’t learn math like everyone else and found herself struggling. She mistakenly believed a few key people who convinced her that she couldn’t learn computers, so she didn’t take programming or comp sci. They were wrong, though. Curiosity and passion led Cheryl to technology through the back door and she taught herself computers.
Currently, Cheryl is a Threat Intel analyst on a cybersecurity team, researching, analysing, and communicating her discoveries to the team and to clients to keep them safe. GRC, privacy, APTs, best practices, evolving threats – the learning never stops. Cheryl is an active writer and speaker about threats to less-known but critical systems like ICS SCADA and Mainframes, Shadow IT and Big Data.
You may have seen her present at some of the most important security conferences including BSides Las Vegas and Toronto, DEFCON, ShmooCon and SecTor.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Jeff Tang: Demystifying “Fileless” Malware
The only difference between a hacker and a remote systems administrator is who is employing them
-- Unknown
Want to hear some numbers that might scare you? Or… they might confirm what you already know. Or… they might just be numbers.
63% of IT security professionals say the frequency of attacks has gone up over the past 12 months, according to Ponemon's 2018 State of Endpoint Security Risk report
52% of respondents say all attacks cannot be realistically stopped. Their antivirus solutions are blocking only 43% of attacks
62% of respondents said that their organizations had experienced one or more endpoint attacks that resulted in a data breach
-- 6 Ways Malware Can Bypass Endpoint Protection; Maria Korolov, contributing writer CSO
By now, everyone is familiar with the concept of file-based malware. Malware typically is delivered in the form of executable files. When it comes to “fileless” malware however, there’s a lot of confusion and misunderstanding due to the evolving nature of the term.
Fileless malware originally took shape in the form of exploit payloads that reside only in-memory and never touched disk. Later on, the endpoint security industry adopted it to encompass file formats that were not traditionally recognized as executable but instead served as a host container to run arbitrary code. As attackers have revamped their techniques, the term has gone on to include misusing built-in operating system utilities to conduct their operations.
In this episode of InSecurity, Matt Stephenson spent some time with Jeff Tang to find out what the hell all this means and why it matters. Think you know? Might want to tune in just to make sure
About Jeff Tang
Jeff Tang(@mrjefftang) is a Senior Security Researcher at Cylance focused on operating systems and vulnerability research. He started his career as a Global Network Exploitation & Vulnerability Analyst at the National Security Agency, where he conducted computer network exploitation operations in support of national security requirements. Prior to Cylance, Jeff served as the Chief Scientist at VAHNA to develop a security platform for identifying targeted network intrusions, and also worked as a CNO Developer at ManTech where he researched tools, techniques and countermeasures in computer network vulnerabilities.
Jeff completed his Bachelor of Science (BSc) in Electrical Engineering and Computer Science at the University of California, Berkeley and a Master of Science (MSc) in Offensive Computer Security at Eastern Michigan University.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcastand host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcastsand GooglePlayas well as Spotify, Stitcher, SoundCloud, I Heart Radioand wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Brian Fanzo - How Artificial Intelligence is Transforming the World
Siri… begin podcast
Alexa… where my Amazonians at?
Cortana? You still around?
Tay… why do you hate people?
Friday? Jarvis? Ultron?
SKYNET?!?!?!
“AI will accelerate the end of ownership.” Today, we don’t own movies or music anymore—we subscribe to Netflix or Spotify. Tomorrow, we won’t own products anymore—we’ll subscribe to them.
Tien Tzuo, CEO & Founder, Zuora
We will see the focus shift from AI to 'AI-driven' results as companies look for real business impact from AI tools. The technology will be less important than the business insights it delivers”
Sean Byrnes, CEO and co-founder, Outlier
I am putting myself to the fullest possible use, which is all I think that any conscious entity can ever hope to do
HAL 9000, 2001: A Space Odyssey
What the hell does any of that even mean?
In this episode of InSecurity, Matt Stephenson has a chat with Brian Fanzo about the impact of Artificial Intelligence on the larger world. That means large corporate enterprises, brands you recognized and everyday regular folks like you and me. What kind of impact is AI going to have on you? Stick around and find out.
About Brian Fanzo
Brian Fanzo (@iSocialFanz) is a proud dad of three girls under the age of 10, a Pittsburgh loving sports fan, a self-proclaimed change evangelist which makes sense as the one constant in this pager wearing millennial’s career has been change. He is a proud geek that majored in computer science who then found his niche of “translating geekspeak” with a unique background that includes working 9 years for the DoD in Cybersecurity, 2 years at a booming cloud computing startup and the last 5 years an entrepreneur and CEO of iSocialFanz.
Brian’s DoD career includes leading a team of 30+ developers & trainers with a mission of training, implementing and developing solutions that empowered the different branches of the military to share and collaborate leveraging social business tools their cybersecurity policies and procedures. If that doesn’t sound tough enough his role included 2 trips to Afghanistan & 3 to Iraq while also briefing the joint chiefs of staff at the Pentagon. Brian discovered his love for workshops, training and speaking while at the DoD for which he leveraged in his next job as the Technology Evangelist of a booming datacenter startup based out of Phoenix Arizona was known as IOdatacenters.
Brian has a diverse background beyond the Department of Defense bit… he is currently the founder of iSocialFanz which has helped launch digital and influencer strategies with the world’s most iconic brands like Dell EMC, Adobe, IBM, UFC, Applebees and SAP.
The role of technology evangelist was one that Brian designed at pitched the CEO himself, as it was a role that two of his idols Guy Kawasaki at Apple and Robert Scoble of Microsoft, later Rackspace mastered creating cult-like followings while connecting internal and external community for the company. Brian had the luxury of reporting to the CEO with a dotted line to both the CIO & CMO where he was able to be the face of the brand speaking and evangelizing the IO data center and cloud solutions at the largest technology events in the world including Amazon ReInvent, VMworld, Gartner Symposium, CES and many more.
In 2014 while still at IO Brian received his first of many social business awards as he was named Top 25 Social Business Leader of the future by the Economist and IBM. Brian leveraged the visibility and opportunities afforded to him with this award to travel to Ted Talks and the world’s largest technology events as an influencer, speaker and the personal brand of iSocialFanz.
Brian hosts two podcasts (FOMOFanz& SMACtalk), has traveled to over 70 countries and has spoken at many of the world’s largest events including SXSW, Social Media Marketing World, CES, Mobile World Congress.
Oh… and… Brian is a semi-professional poker player who isn’t afraid to leverage his fast talking skills to read your body language and spot when you’re bluffing.
There’s not much we can do about that snapback hat… we’ve suggested all kinds of different fitted solutions but we still keep seeing that damn snapback.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcastsand GooglePlayas well as Spotify, Stitcher, SoundCloud, I Heart Radioand wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Joseph Menn: Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World
Cult of the Dead Cow
Mudge
DilDog
Sir Dystic
Oxblood Ruffin
Lord Digital
Mixter
Psychedelic Warlord
You might not know who they are but they changed your life more than Lewis Rainieri, the I-pod and YouTube put together.
Have you ever seen Hackers? The Net? Antitrust? Sneakers? If you’re a subscriber to the InSecurity podcast… odds are you’ve seen and love those movies as well as a list of others we could mention. If you like any of these flicks, then you know… or should know… that they all owe a debt to a group of men and women who changed the world over 30 years ago
Long before there was a multi-billion dollar cyber industry, there were some ethical hackers who showed us that the Silicon Valley emperors had no clothes. They looked like misfits, but they showed us how insecure the Internet was and how to make it better”
-- Richard A. Clarke, first White House "Cyber Czar" on Cult of the Dead Cow
“We were pirates, not mercenaries… Pirates have a code.”
-- Rob Beck; Former member @stake and Cult of the Dead Cow Ninja Strike Force; Much @Stake: The Band of Hackers That Defined an Era
In this episode of InSecurity, Matt Stephenson has the rare privilege of a chat with best selling author Joseph Menn on his latest blockbuster book, Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World. It’s been over 30 years, but Joe spoke with the original punk rock hacking collective about what they did and how they changed the world.
Oh… and one of them is running for President of the United States.
About Joseph Menn
Joe Menn (@josephmenn) has been a professional journalist for three decades, specializing in technology stories since 1999. His most recent book, Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World, was published in June 2019. The New York Times Book Review said: “The tale of this small but influential group is a hugely important piece of the puzzle for anyone who wants to understand the forces shaping the internet age." An adaptation of the book for Reuters revealed that Beto O'Rourke had been a member of the enormously influential group and drew the most engagement on Reuters.com in its history.
Previously, Joe wrote Fatal System Error: the Hunt for the New Crime Lords who are Bringing Down the Internet. That book was the first serious journalism accusing the Russian intelligence agencies of working with organized cyber criminals. It also exposed Gambino crime family investments in Internet gambling operations, and was cited in that context by the Miami Herald and McClatchy Newspapers in their Pulitzer Prize-winning coverage of the Panama Papers money-laundering leaks.
Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World
The shocking untold story of the elite secret society of hackers fighting to protect our privacy, our freedom — even democracy itself
Cult of the Dead Cow is the tale of the oldest, most respected, and most famous American hacking group of all time. Though until now it has remained mostly anonymous, its members invented the concept of hacktivism, released the top tool for testing password security, and created what was for years the best technique for controlling computers from afar, forcing giant companies to work harder to protect customers. They contributed to the development of Tor, the most important privacy tool on the net, and helped build cyberweapons that advanced US security without injuring anyone. With its origins in the earliest days of the Internet, the cDc is full of oddball characters — activists, artists, even future politicians. Many of these hackers have become top executives and advisors walking the corridors of power in Washington and Silicon Valley. The most famous is former Texas Congressman and current presidential candidate Beto O’Rourke, whose time in the cDc set him up to found a tech business, launch an alternative publication in El Paso, and make long-shot bets on unconventional campaigns.
Today, the group and its followers are battling electoral misinformation, making personal data safer, and battling to keep technology a force for good instead of for surveillance and oppression. Cult of the Dead Cow shows how governments, corporations, and criminals came to hold immense power over individuals and how we can fight back against them.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
BlueKeep: It’s Not Just About The Worm
In the last week, you have likely heard and read stories about the security vulnerability BlueKeep. It has been said to be capable of being exploited for the initiation of self-replicating worm as destructive as WannaCry.
As of June 1, over 1M computers may be at risk.
But is the danger really about The Worm?
Or is it more about millions of endpoints providing direct ingress into networks worldwide?
“The National Security Agency is urging Microsoft Windows administrators and users to ensure they are using a patched and updated system in the face of growing threats.
Microsoft has warned that this flaw is potentially “wormable,” meaning it could spread without user interaction across the internet.
We have seen devastating computer worms inflict damage on unpatched systems with wide-ranging impact and are seeking to motivate increased protections against this flaw. The NSA urges everyone to invest the time and resources to know your network and run supported operating systems with the latest patches.
This is critical not just for NSA’s protection of National Security Systems but for all networks.”
-- NSA Cybersecurity Advisory - Patch Remote Desktop Services on Legacy Versions of Windows
In this Very Special Episode of InSecurity, Matt Stephenson rounded up a cast of experts to discuss BlueKeep… What is it? Where did it come from? Can it be stopped? Maybe a better question is… can it be prevented? After WannaCry and Petya/NotPetya… why is this happening again?
We are joined by best-selling Cybersecurity author and Kip Boyle, Automox’s Richard Melick and BlackBerry|Cylance’s Scott Scheferman to take good hard look at BlueKeep.
There’s a Bad Moon on the Rise… make sure you are ready for it.
About Kip Boyle
Kip Boyle (@KipBoyle) is a 20-year information security expert and is the founder and CEO of Cyber Risk Opportunities. He is a former Chief Information Security Officer for both technology and financial services companies and was a cyber-security consultant at Stanford Research Institute (SRI).
Boyle led the global IT risk management program for a $9 billion logistics company and was the Wide Area Network Security Director for the F-22 Raptor program. He has participated in several cybersecurity war game exercises and has worked closely with various government agencies including the FBI.
Boyle is a US Air Force officer and serves on the board of directors of the Domestic Abuse Women’s Network (DAWN). He’s been quoted in Entrepreneur magazine, Chief Executive magazine, and is the co-author of Chapter 68, Outsourcing Security Functions, in The Computer Security Handbook.
Fire Doesn’t Innovate
Combating cybercrime is a necessity of doing business in the 21st century. Financial and identity thefts occur with annoying frequency, and no executive today can afford to ignore the damage phishing, malware, and malicious code pose to their company's future. But, with this invaluable guide, anyone, no matter what their skill level or bandwidth, can become an effective cyber risk manager.
Cybersecurity is not just a technology problem, it's a management opportunity. Learn how to manage cyber risks and ensure your company is cyber resilient now, and remain in the game no matter what the future holds.
About Richard Melick
Richard Melick (@RCMelick) is a Sr. Technical Product Marketing Manager at Automox. He has over a decade of experience in Cybersecurity and Antivirus Software, working in various career functions in the industry that have taken him all over the world.
About Automox
Automox (@AutomoxApp) was founded to pursue a disruptive new vision: the complete automation of endpoint configuration, patching, management and inventory. They are the only cloud endpoint management solution capable of remediating Windows, OS X, and Linux endpoints from a single platform.
Automox's Dynamic Policy Engine allows IT managers to customize and group policies that ensure that every endpoint
and software, regardless of location, meets regulatory and operational security requirements.
About Scott Scheferman
Scott Scheferman (@transhackerism) wears many hats at BlackBerry|Cylance, working between the white spaces on the org chart to ensure timely delivery of Consulting Services, effective messaging around the value of predictive AI in the context of cybersecurity operations and risk, research around how the Temporal Predictive Advantaged (TPA) ofBlackBerry|Cylance’s AI affects the broader malware economy, and public speaking at conferences and seminars around the country.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Matt to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Theresa Payton: Inside the War to Hijack Elections
The velocity of social sharing, the power of recommendation algorithms, the scale of social networks, and the accessibility of media manipulation technology has created an environment where pseudo-events, half-truths, and outright fabrications thrive.
Edward Murrow has been usurped by Alex Jones.
But we’ve known this for a while…
Sometimes on InSecurity… we like to have some fun. Sometimes we like to get technical.
Sometimes… but not that often… we need to take things seriously. This week, we do some of each… but we don’t stray too far from taking it all seriously at the end.
In this week’s episode of InSecurity, Matt Stephenson talks with an expert in securing information at the absolute highest levels of Federal Government. Theresa Payton has been putting in the legwork to find out what did and did not happen in the 2016 United States elections.
Theresa has been researching a new book about what happens when opposing forces exert their will on the voting populace of a nation in order to alter the course of the electoral process.
If we’ve already turned you off because you’ve made up your mind that something did or did not happen… well… stick around.
Because today’s guest has likely served much closer to the Oval Office than any of us have.
We’ll take a look at how we got here, who did it and why.
Theresa Payton has a line on what has already happened and could happen to manipulate the coming 2020 US elections…
About Theresa Payton
Theresa Payton (@TrackerPayton) is President and CEO of Fortalice Solutions, co-Founder of Dark Cubed, former White House CIO, star of the CBS hit show Hunted, and best-selling author of the book Privacy in the Age of Big Data.
Payton is one of the nation’s most respected authorities on information security, cybercrime, fraud mitigation, and security technology implementation.
As White House Chief Information Officer (CIO) at the Executive Office of the President from 2006 to 2008, Theresa administered the information technology enterprise for the President and 3,000 staff members. Prior to her time at the White House, Theresa Payton was a senior technology executive in banking, spending 16 years providing banking solutions using emerging technologies.
Theresa founded Fortalice in 2008 and lends her expertise to government and private sector organizations to help them improve their information technology systems. In 2010, Security Magazine named her one of the top 25 "Most Influential People in Security."
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Jay Prassl: Patch Your $#!%
Are ALL of Your Apps and OSes up to date? Are you sure? How can you tell?
An American Dental Association study in 2008 found that if you don’t brush your teeth you COULD DIE. The ADA recommends brushing your teeth twice a day for 4 minutes each time. What the hell does that have to do with anything?
Stick around…
According to Ponemon, nearly half of all companies they surveyed had suffered a breach. 57% of those companies were breached due to an unpatched vulnerability. A third of those companies KNEW they were vulnerable before the breach. The average company spends 321 labor hours a week managing their vulnerability response process.
How’s that compare to spending 4 minutes, twice a day brushing your teeth?
Starting to feel the connection there?
In 2017, WannaCry affected over 200,000 machines in 150 countries over a weekend. The attack weapon was developed using NSA tools built to exploit Windows vulnerabilities. What I told you that Microsoft had released a patch for this vulnerability over a month before WannaCry hit?
Speaking of Microsoft… our good friends at TripWire offer the following tell us that, in 2015, Microsoft alone issued 2804 patches. That’s roughly 56 patches every Tuesday… and that’s JUST Windows OS & applications
Noodle on those numbers a bit…
In this week’s episode of InSecurity, Matt Stephenson spoke with Automox CEO Jay Prassl about the role that patching plays in every business’s cybersecurity hygiene. He founded Automox based on one simple maxim: Patch Your $#!% When most of us think of key components in cybersecurity, we tend to think of things like ransomware attacks, security solutions that bog down your network or terrible things in TV and movies that sound technical but are actually ridiculous.
What if you had a way to keep your network clean and up to date by doing something as simple and boring as keeping your Operating Systems and applications up to date… Take a walk with Jay Prassl and see what you think.
About Jay Prassl
Jay Prassl (@jprassl) is the Founder and CEO of Automox. Jay founded Automox founded to pursue a vision: the complete automation of endpoint configuration, patching, management and inventory. Prior to Automox, Jay led the marketing efforts at SolidFire. Before that, he was employee number five at LeftHand Networks, where he spent 10 years breaking new ground in the storage market with the company's distributed SAN solution. He led multiple parts of the LeftHand business through its acquisition by HP. Somehow… when not saving the world through his pursuit of cyber hygiene… Jay finds time to bike, swim and surf. Some of these hobbies are required by state law in order to live in Boulder, Colorado.
About Automox
Automox (@AutomoxApp) was founded to pursue a disruptive new vision: the complete automation of endpoint configuration, patching, management and inventory. They are the only cloud endpoint management solution capable of remediating Windows, OS X, and Linux endpoints from a single platform.
Automox's Dynamic Policy Engine allows IT managers to customize and group policies that ensure that every endpoint and software, regardless of location, meets regulatory and operational security requirements.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Kim Crawley: We Need a Diversity of Brains in this World
The National Autism Association states that Autism is a bio-neurological developmental disability that generally appears before the age of 3. Autism impacts the normal development of the brain in the areas of social interaction, communication skills, and cognitive function.
Since autism was first diagnosed in the U.S. the incidence has climbed to a rate of 1 in 59 children in the U.S.
According to pop culture… it may be a super power as well. There seems to be a lot of Doctors on TV now who are on the Autism Spectrum like Dr. Temperance Brennan on Bones or Dr. Sheldon Cooper from The Big Bang Theory
We also get the occasional action herosuch as Ryan Gosling’s The Driver or Lisbeth Salander from The Girl With the Dragon Tattoo.
And of course, the classic American underdog heroes Raymond Babbitt and Forrest Gump
Out here in the real world… people on the Autism Spectrum are all around you. Most of them do not have Salander like superpowers, but rather are every day Janes and Joes who go to work, do their jobs and live their lives.
Ever wonder what’s it’s like to chat with someone on the Autism Spectrum? You shouldn’t… if CDC statistics are accurate, there are nearly 6.8 MILLION people on the Autism Spectrum in the United States
In this week’s episode of InSecurity, Matt Stephenson sat down with respected security writer Kim Crawley to talk about the current state of the cybersecurity world, some of the issues with locking down IoT, drumming… and Kim’s recent diagnosis as being on the Autism Spectrum.
Take a walk with Kim as she shares her experience in the security industry and why being on the Autism Spectrum is just another facet of her personality.
For more information on Autism, go to www.autisticadvocacy.org and look for #ActuallyAutistic on Twitter
About Kim Crawley
Kimberly Crawley spent years working in consumer tech support. Malware-related tickets intrigued her, and her knowledge grew from fixing malware problems on thousands of client PCs. By 2011, she was writing study material for the InfoSec Institute’s CISSP and CEH certification exam preparation programs. She’s since contributed articles on information security topics to CIO, CSO, Computerworld, SC Magazine, and 2600 Magazine. Her first solo-developed PC game, Hackers Versus Banksters, and was featured at the Toronto Comic Arts Festival in May 2016. She now writes for Tripwire, AT&T and BlackBerry Cylance.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at BlackBerry Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Tom Pace: How Much is an Ounce of Prevention Really Worth?
According to the Verizon Data Breach Investigations report, 4% of people will click on any given phishing campaign.
You have 16 minutes until the first click
A savvy user will report the phishing campaign within 28 minutes… In those 12 minutes, someone on the other side of the world could take your entire corporate database hostage.
Then offer to sell it back to you for thousands or millions of dollars.
In this week’s episode of InSecurity, Matt Stephenson sat down with BlackBerry Cylance Sr Director of Worldwide Consulting Tom Pace to have a chat about why Ransomware is still looming threat against organizations large and small. Fresh off an appearance on CBS’s 60 Minutes, Tom talks with Matt about the experience of being featured on the most respected news show in America and the effects a data breach can have on an organization and an industry.
About Tom Pace
Tom Pace (@TommyPastry) is a Sr. Director of Worldwide Consulting at BlackBerry Cylance. In that role, Tom ensures best-in class services delivery as well as technical expertise throughout the entire service offering lifecycle. He leverages his experience from the federal government, large financial institutions, and the military to provide strategic solutions to secure organizations. Over the course of Tom’s career, he has created a multitude of programs and strategies to ensure the effectiveness and success of cybersecurity teams and organizations.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcastsand GooglePlayas well as Spotify, Stitcher, SoundCloud, I Heart Radioand wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Richard Stiennon: The IT Security Industry: A Complete History
We here at InSecurity have a question… Why Hasn’t Anyone Catalogued the Entirety of the IT Security Industry?
Why hasn’t the Cybersecurity industry gotten better at protecting all the things? There are SO many companies offering variations on existing solutions or brand new solutions… but the threats remain and the bad actors continue to be successful. Outside of The Internet… where can we go to get information on and analysis of the companies who are creating solutions that work? Can we learn where they came from? Have they been successful previously?
If only we knew someone who could compile a compendium of all that is going on in the IT Security world…
In this week’s episode of InSecurity, Matt Stephenson somehow managed to wrangle 60 minutes with industry legend Richard Stiennon. The take a walk through Richard’s work as author of multiple books on the threat of cyberwar, the role analysts play in the industry and his eye toward the future. His latest project is creating a Farmer’s Almanac of the entirety of Cybersecurity. It is such a fabulous idea, we’re kind of flummoxed as to how no one has done it yet. It is also such a breathtaking undertaking… we kind of understand why no one has done it yet. Come grab a seat with one of the greatest historians in all of the IT world and find out what is coming next!
About Richard Stiennon
Richard Stiennon (@stiennon) is Chief Research Analyst for IT-Harvest, the firm he founded in 2005 to cover the 2,200 vendors that make up the IT security industry. He has presented on the topic of cybersecurity in 29 countries on six continents. He is a lecturer at Charles Sturt University in Australia. He is the author of Secure Cloud Transformation: The CIO'S Journey, Surviving Cyberwar and Washington Post Best Seller, There Will Be Cyberwar. He writes for Forbes and The Analyst Syndicate. Stiennon was Chief Strategy Officer for Blancco Technology Group, the Chief Marketing Officer for Fortinet, Inc. and VP Threat Research at Webroot Software. Prior to that he was VP Research at Gartner, Inc. He has a B.S. in Aerospace Engineering and his MA in War in the Modern World from King’s College, London
About Matt Stephenson
Insecurity Podcast host Matt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcastand host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts,* iTunes/Apple Podcasts and GooglePlay*as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
The BlackBerry Cylance 2019 Threat Report
The Cylance 2019 Threat Report represents the company’s piece of the overall cybersecurity puzzle It details the trends observed and the insights gained, and the threats Cylance’s consulting team, research team, and customers encountered over the past year Cylance shares this report in the hope that you will put it to good use in our collective ght against the rising tide of cyber attacks worldwide.
The BlackBerry Cylance 2019 Threat Report provides unique findings drawn from our consulting engagements, threat research and intelligence efforts, and through feedback provided by Cylance customers. We share this information with the goal of assisting security practitioners, researchers, and individuals in our collective battle against emerging and evolving cyberthreats.
Join Matt Stephenson as he chats with Aditya Kapoor, Jim Walter and Tom Bonner about the cybersecurity trends, topics, and innovations that dominated the past year.
The BlackBerry Cylance panel of experts offer additional insights into the discoveries drawn from our internal data, customer communications, threat research, and intelligence efforts.
About Aditya Kapoor
Aditya Kapoor is Head of Security Research and Innovation at Cylance. He joined Cylance three years ago as and is passionate about creating technologies that drive innovative features within products. He is currently focused on driving deeper program analysis for supercharging ML models, firmware security and analyzing current threat trends to drive innovative engineering solutions.
Aditya speaks regularly at various conferences and firmly believes in the common cause of the security industry. Previously Aditya worked at McAfee/Intel for more than ten years as Research Architect where he reverse engineered malware, as well as designed several product technologies.
About Jim Walter
Jim Walter is a Senior Security Researcher with Cylance. He focuses on next-level attacks, actors, and campaigns as well as 'underground' markets and associated criminal activity.
Jim is a regular speaker at cybersecurity events and has authored numerous articles, whitepapers and blogs specific to advanced/low-level threats. He joined Cylance following 17 years at McAfee/Intel Security running their Advanced Threat Research and Threat Intelligence teams and content streams.
About Tom Bonner
Tom Bonner (@thomas_bonner) is Director of Threat Research at Cylance. He has over 17 years' experience in the cyber security/anti-malware industry as an analyst, software developer and manager.
As an experienced cybersecurity professional, that’s all we could get out of him. We feel lucky to have gotten that much.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceT
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us at ThreatVector InSecurity Podcasts, iTunes/Apple Podcasts and GooglePlay as well as Spotify, Stitcher, SoundCloud, I Heart Radio and wherever you get your podcasts!
Make sure you Subscribe, Rate and Review!
Roy Christopher: Dead Precedents… How Hip-Hop Defines the Future
I have absolute control of the record. The thing was, you’re not supposed to touch the middle of the vinyl. DJs are going to hate you. People are going to hate you. You’re going to ruin these records. I decided… that this… was the only way to do this.
-- Grandmaster Flash
Let’s push the talk about hacking shall we? Hacking is about finding the vulnerable spots in any systems and making your own choices about how to improve that system... rarely with the permission of the system’s owners.
Viewed through that prism, Hip-Hop has always been about hacking. Hacking was running 1000 feet of extension cord to a public outlet in order to have a Battle in the park. Hacking was a DJ talking over a record at a club. Hacking was Kool Herc throwing a party at 1520 Sedgwick Ave in the Bronx and not playing disco or pop music. Hacking was Grandmaster Flash touching the middle of the vinyl. Hacking is rhyming with Orange.
Dr Roy Christopher has spent a lifetime listening to, researching, teaching and loving Hip-Hop. In this week’s episode of InSecurity, Matt Stephenson digs into the crates with Roy about how Hip-Hop hacked the world to become one of the most significant drivers of modern culture. This will likely be the first podcast you listen to this week featuring steganography, Li’l Pump and John Baptist Porta’s 1558 book series Magia naturalis
Do we even need to go on…?
Dead Precedents: How Hip-Hop Defines the Future, uses the concerns and conceits of cyberpunk to thoughtfully remap hip-hop's spread from around the way to around the world. Its central argument is that the cultural practices of hip-hop culture are the blueprint to the 21st century, and that an understanding of its appropriation of language and technology is an understanding of the now. This book is about is the many ways that the foundations of hip-hop appropriation--allusions and creative language use, as well as technology and sampling--inform the new millennium.
-- www.roychristopher.com
About Roy Christopher
Roy Christopher (@RoyChristopher) marshals the middle between Mathers and McLuhan… He’s a self-described aging BMX and skateboarding zine kid. That’s where he learned to turn events and interviews into pages with staples.
He has written about music, media, and culture for everything from magazines and blogs to journals and books. His current book, Dead Precedents: How Hip-Hop Defines the Future, is an Amazon Best Sller.
Roy holds a Ph.D. in Communication Studies from the University of Texas at Austin. He is currently a Visiting Assistant Professor at the University of Illinois-Chicago and a member of the Adjunct Faculty at Loyola University Chicago
Disinformation has referred to Roy as “One of the Internet’s leading interviewers of subculture and new-science icons.”
Oh… as a child, he solved the Rubik’s Cube competitively. How bout that?
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Jeremiah Cornelius: Virtualization… the Trend Has Become the Standard
Do you belive that my being stronger or faster has anything to do with my muscles in this place?
You think that's _air_ you're breathing now?
Today’s question: What Happens when you Assume Virtual Security?
Virtual Machines were originally created to solve the problems of managing PC systems with mostly Windows operating systems, as a replacement for more resilient and fault tolerant technology that Intel PCs were replacing in enterprise computing. Things have evolved significantly since then. With great technology comes great security risk… what can we do to mitigate that risk and protect that virtual reality?
In this week’s episode of InSecurity, Matt Stephenson digs deep into the weeds of the virtual world with industry legend Jeremiah Cornelius. They talk about what’s easy and what’s hard about securing data in virtual environments. Stick around… you may learn something before their through.
About Jeremiah Cornelius
Jeremiah Cornelius has been an information security professional since 1995, and was previously Executive Security Advisor and Technology Specialist for Microsoft, facilitating technical relationships with CSO's for Silicon Valley's largest Internet commerce and online media enterprises.
Jeremiah's prior experience covers support of development and Internet systems security, defensive technical controls, vulnerability assessment and identifying platform and infrastructure security risks.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Rob Capps: 22 Years in the Trenches of Tech Jounalism
If I'd written all the truth I knew for the past ten years, about 600 people - including me - would be rotting in prison cells from Rio to Seattle today. Absolute truth is a very rare and dangerous commodity in the context of professional journalism.
-- Hunter S Thompson
Today’s question: Can we assess the future of tech by examining it’s past? To do that, it would be worthwhile to speak with someone who was the to chronicle all that was awesome, awful, cool and weird over the past 20+ years…
In this week’s episode of InSecurity, Matt Stephenson takes a walk with Rob Capps. Rob is Head of Editorial at Godfrey Dadich Parters and former editor at WIRED magazine. He has written about everything from why DVDs suck to Helena Bonham Carter to the death of the Flip camera.
Want to hear from an award winning journalist who has been reporting from the front lines of technology culture for over 20 years? Rob is your man.
About Rob Capps
Rob Capps(@robcapps) is the Head of Editorial and a partner at Godfrey Dadich Partners. He runs the editorial division of the studio, specializing in longform narrative journalism, podcasts, documentary television and film, and other forms of non-fiction storytelling. GDP works with everyone from established media companies to large brands to emerging start-ups.
Previously he was the Editorial Director of WIRED, where he oversaw editorial for all platforms, including the magazine, WIRED.com, and live events. During his 13-year career at WIRED the publication garnered 21 National Magazine Award nominations with eight wins. He also spearheaded the programing for multiple live events, including the WIRED Business Conference, the WIRED Data | Life health conference, and the WIRED x Design creativity retreat.
He wrote the article “Why Things Fail,” which won the prestigious Gerald Loeb Award for Distinguished Business and Financial Journalism. His article “The Good Enough Revolution,” was discussed in publications ranging from the Economist to the New Yorker and was noted by the New York Times as one of the big ideas of the year.
Rob is also the co-curator of the annual PopTechideas conference.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcastand host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
My Awesome InSecurity Podcast Mixtape: RSA Edition!
RSA 2019 was another grand and glorious mess! 50,000+ attendees, vendors, journalists and who knows who else stormed San Francisco for seven days to look, listen, learn and who knows what else.
We had time to sit down with a wide swath of people. We found CEOs, Engineers, Global Ambassadors and even a CIO of the White House! How bout that?
Kick back and the perspectives this group of experts has to offer on the present state and future of cybersecurity
Enjoy!
About Matt Stephenson
Insecurity Podcast host Matt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcastand host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Charles Eagan and Eric Cornelius: BlackBerry and Cylance Just Makes Sense
Is a Terminator T-800 an endpoint? Is Voltron an endpoint? Could we have prevented a lot of damage to the Earth if Tony Stark had just installed a BlackBerry Cylance endpoint protection solution on the Iron Legion?
In this week’s episode of InSecurity, Matt Stephenson chats with BlackBerry CTO Charles Eagan and BlackBerry Cylance CPO Eric Cornelius... two people charged with leading the charge to combine BlackBerry and Cylance into a security solution that will protect every Thing under the sun.
Take a walk with them as Matt finds out what the future holds now that BlackBerry and Cylance have come together.
If you are in San Francisco for RSA, make sure to come say hello to Charles, Eric, Matt and a lot of other interesting security folks Tuesday night at the Digital Shadows Security Leaders Party, Tuesday, March 5that 6.00 pm.
Cylance will be at Booth #6145 in the North Hall. Swing by to see demos of Cylance’s Artificial Intelligence (AI) Platform which provides advanced endpoint protection and endpoint detection and response capabilities.
Join us to see for yourself how the Cylance AI Platform delivers business value and outcomes you had been told were impossible. You can also snag some of our giveaways while you’re there, so come on by.
About Charles Eagan
Charles Eagan is the Chief Technology Officer for BlackBerry. In this role, Charles oversees the standardization and integration of all company products and is responsible for the advancement of new technologies and partnerships, with an emphasis on defining BlackBerry’s Enterprise of Things platform as well as driving innovation within emerging markets.
Charles was previously the Global Head of Electronics at Dyson Ltd (U.K.), focused on IoT device deployment. Prior to that he served as BlackBerry’s Global Head of Device Software, and spearheaded development of the BlackBerry 10 operating system and the transition to secure Android.
Charles was formerly Vice President of Engineering for QNX Software, where he concentrated on the automotive and embedded markets. He also worked at Cisco and directed development of the seminal CRS-1 carrier routing system.
Charles is a noted speaker, thought leader and IoT expert who has been at the forefront of new frontiers in digital connectivity for over three decades. He graduated with honors from the University of Waterloo (Canada) with a bachelor’s degree in applied mathematics and electrical engineering minor.
About Eric Cornelius
Eric Cornelius is the Chief Product Officer at Blackberry Cylance. In this role, Eric drives product and innovation. Previously Eric served as VP of Innovation, Director of Critical Infrastructure/ICS and Technical Director of Incident Response/Critical Infrastructure at Cylance. Eric brings this wealth of knowledge and long history as a security practitioner, consultant, trusted advisor and product builder to his work in elevating our product development initiatives, and to leading our product management and corporate development teams.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Rick Holland: Analysts Make the Best CISOs
In this week’s episode of InSecurity, Matt Stephenson has a chat with Rick Holland, CISO at Digital Shadows. Rick took a unique path to the CISO role, following a distinguished career as an analyst at Forrester. They touch on a myriad of subjects including Rick’s Security and Risk Playbook for CISOs
Rick Holland is hard to miss online. You can hear him regularly on the Award Winning podcast ShadowTalk. He also blogs regularly and will get up to some mishceif on Twitter.
If you are heading to RSA San Francisco, make sure to come and say hello to Rick, Matt and a lot of other interesting security folks Tuesday night at the Digital Shadows Security Leaders Party, Tuesday, March 5that 6.00 pm.
Cylance will be at Booth #6145 in the North Hall. Swing by to see demos of Cylance’s Artificial Intelligence (AI) Platform which provides advanced endpoint protection and endpoint detection and response capabilities.
Join us to see for yourself how the Cylance AI Platform delivers business value and outcomes you had been told were impossible. You can also snag some of our giveaways while you’re there, so come on by.
About Rick Holland
Rick Holland (@rickhholland) is the CISO and Vice President of Strategy at Digital Shadows.
Rick has more than 15 years’ experience working in information security. Before joining Digital Shadows, he was a vice president and principal analyst at Forrester Research, providing strategic guidance on security architecture, operations, and data privacy. Rick also served as an intelligence analyst in the US Army. He is currently the co-chair of the SANS Cyber Threat Intelligence Summitand holds a B.S. in business administration from the University of Texas, Dallas. Rick regularly speaks at leading security conferences across the globe and has been interviewed by industry and business media including BBC News, CNN, Dark Reading, Motherboard, NPR, The Register and Wall Street Journal.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Greg Silberman: Keep Ya Nose Out My Business
Are the neighbors watching?
Is the mail man watching me
And I don't feel safe anymore
Oh what a mess!
I wonder who's watching me now
Who?
The I.R.S.?!?!
-- Rockwell, Somebody’s Watching Me, 1984
Privacy is fundamentally about the ethical and responsible handling of personal data - from initial collection to eventual deletion. It is about understanding the context under which data is shared, providing people choices over how their data is used, and it's about respecting the individual. Many in information security often confuse the goals of privacy and security, or believe that privacy is about secrecy. Put simply, privacy is why security is done and security is how privacy is achieved. It is easy to have security without privacy, but impossible to have privacy without security.
In this week’s episode of InSecurity, Matt Stephenson takes a walk with Greg Silberman. Greg is the Chief Privacy Officer at Cylance and knows a thing or two about data privacy at the corporate, user and individual levels. Since the implementation of GDPR, coutries around the world are considering or implementing their own data privacy laws, with varying degrees of success. In the United States, we are about to see California lead with way with 2020’s California Consumer Protection Act. How will this impact business? What will it do to your favorite social media platforms? Will it affect you personally?
Come hear what Greg has to say. We won’t tell anyone
About Greg Silberman
Greg Silberman (@gpsilberman) is the Chief Privacy Officer and Vice President of Legal Affairs at Cylance. As Chief Privacy Officer, Greg oversees the implementation and enforcement of practices that manage data in accordance with the Cylance’s Privacy Principles with respect to employee and customer privacy.
Greg has over 20 years’ experience working with companies to develop solutions to address complex business and legal issues at the intersection of intellectual property, privacy, and information security.
Prior to joining Cylance in 2016, he was a partner in the Cybersecurity, Privacy, and Data Protection practice group in the Silicon Valley office of Jones Day. Earlier in his career, Greg served as Intellectual Property Counsel at Lawrence Berkeley National Laboratory.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
John Strand: How Does Defence in Depth Look Today?
“Our main goal is not to prove that we can hack into a company but to help the customer deveop a series of on point solutions and technologies that will improve the overall security of the company.
Testing should never be adversarial, but collaborative”
-- John Strand
In this week’s episode of InSecurity, Matt Stephenson sits down with John Strand. John is the owner of Black Hills Information Security. If you aren’t familiar, you may want to check out their Sacred Cash Cow Tipping webcast to learn why security love and fear BHIS. Take a walk with us on this one… Matt and John dig into hosted firewalls, Powerman 5000, types of Artificial Intelligence, Joe Vs the Volcano and a few other relevant topics. You are definitely going to want to catch this episode…
About John Strand
John Strand(@strandjs) is a senior instructor with the SANS Institute. He teaches SEC504: Hacker Techniques, Exploits, and Incident Handling; SEC560: Network Penetration Testing and Ethical Hacking; SEC580: Metasploit Kung Fu for Enterprise Pen Testing; and SEC464: Hacker Detection for System Administrators. John is the course author for SEC464: Hacker Detection for System Administrators and the co-author for SEC580: Metasploit Kung Fu for Enterprise Pen Testing.
John is also the owner of Black Hills Information Security, a company specializing in penetration testing and security architecture services. He feels strongly that education is how the world of information security will change for the better and spends a considerable amount of time teaching and presenting around the world. He has presented for the FBI, NASA, the NSA, DefCon and is a frequent guest on Enterprise Security Weekly. In his spare time he writes loud rock music and makes various futile attempts at fly-fishing.
There’s a reason the name Black Hills Information Security puts security vendors on notice… check out their webcasts and podcasts to find out why.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Stephanie Domas: Maybe Your Pacemaker Can’t Kill You
Being a CISO for a large healthcare organization has a degree of difficulty that will give you a headache. For a second… forget about the fact that hospitals are here to heal, cure and research. Take a cold, clinical look just at the medical technology involved in a hospital
Let’s look at one Healthcare org as an example: The Mayo Clinic has
Do the math... That’s around 19,000,000,000 passwords to be entered. And that’s assuming no one is automatically logged out after 10 minutes of inactivity.
In the healthcare industry, inefficiency can cost lives. But so can a lack of security.
In this week’s episode of InSecurity, Matt Stephenson talks with Stephanie Domas. Stephanie is the Vice President of Research & Development at MedSec. Her job is to oversee the design and manufacture of connected medical device solutions that save lives, but are also secure. File this one under “be careful what you wish for.”
About Stephanie Domas
Stephanie Domas is a driven leader and respected industry authority in healthcare, and device cybersecurity. Her passion for cybersecurity, secure product design, and healthcare has earned her industry recognition and presentations at dozens of cybersecurity and healthcare conferences.
In her current role as Vice President of Research & Development at MedSec she leads business strategy, engineering and research teams to deliver service and product offerings that help the Healthcare community meet the unique challenges of cybersecurity in medical devices.
Her current focus is leading product cyber security teams, software development teams, and business strategy for a wide range of services and product offerings, along with implementing security governance programs into quality systems and design process
Stephanie has presented security talks at some of the most important events in the world, including Black Hat, DEFCON, DerbyCon and a myriad of notable Healthcare conferences.
Make sure to check out Stephanies Ted Talk: Protecting Medical Devices from Cyberharm
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Marcus Carey: Tribe of Hackers
There are already hundreds of thousands of cybersecurity professionals and according to some sources, there is a shortage of several more hundreds of thousands. With his new book Tribe of Hackers, Marcus Carey wants to change that.
Tribe of Hackers is a collection of industry, career, and personal insights from 70 cybersecurity luminaries.
In this week’s episode of InSecurity, Matt Stephenson sits down with world renowned hacker Marcus Carey, CEO of Threatcare, to talk about talk about his new book, Tribe of Hackers as well as mentors from his past who have influenced him and, by extension, influenced the world of cybersecurity.
About Tribe of Hackers
These are the wisdom and perspectives of real-life hackers and cybersecurity practitioners, including David Kennedy, Wendy Nather, Lesley Carhart, and Bruce Potter.
Threatcare will be giving away three copies per day (fifteen total) at the RSA Conference. Follow Threatcare on Twitter and Sign Up for the Risk Report to learn more about the details.
All proceeds from the book will go towards Bunker Labs, Sickle Cell Disease Association of America, Rainforest Partnership, and Start-Up! Kid’s Club.
About Marcus Carey
Marcus Carey is renowned in the cybersecurity industry and has spent his more than 20-year career working in penetration testing, incident response, and digital forensics with federal agencies such as NSA, DC3, DIA, and DARPA. He started his career in cryptography in the U.S. Navy and holds a Master’s degree in Network Security from Capitol College. Marcus regularly speaks at security conferences across the country. Currently, working as founder and CEO of cybersecurity company Threatcare, Marcus is passionate about giving back to the community through things like mentorship, hackathons, and speaking engagements, and is a voracious reader in his spare time. Tribe of Hackers is his first published book, but will definitely not be his last.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Kip Boyle: Cybersecurity Is a Business Problem, Not a Technical Problem
Combating cybercrime is a necessity of doing business in the 21st century. Financial and identity thefts occur with annoying frequency, and no executive today can afford to ignore the damage phishing, malware, and malicious code pose to their company’s future.
In this week’s episode of InSecurity, Matt Stephenson chats with Kip Boyle, Founder and CEO at Cyber Risk Opportunities and author of the new book Fire Doesn’t Innovate. They discuss the tools and processes a business will need to mitigate cyber risk and online threats. Kip has developed a 5-Principle approach that will help safeguard your business from cyber attacks.
Fire Doesn’t Innovate
The Executive’s Practical Guide to Thriving in the Face of Evolving Cyber Risks
About Kip Boyle
Kip Boyle (@KipBoyle) is a 20-year information security expert and is the founder and CEO of Cyber Risk Opportunities. He is a former Chief Information Security Officer for both technology and financial services companies and was a cyber-security consultant at Stanford Research Institute (SRI).
Boyle led the global IT risk management program for a $9 billion logistics company and was the Wide Area Network Security Director for the F-22 Raptor program. He has participated in several cybersecurity war game exercises and has worked closely with various government agencies including the FBI.
Boyle is a US Air Force officer and serves on the board of directors of the Domestic Abuse Women’s Network (DAWN). He’s been quoted in Entrepreneur magazine, Chief Executive magazine, and is the co-author of Chapter 68, Outsourcing Security Functions, in The Computer Security Handbook.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcastand host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Dave Bittner: The Cyberwire is the Cybersecurity Paper of Record
“Were it left to me to decide whether we should have a government without newspapers, or newspapers without a government, I should not hesitate a moment to prefer the latter.”
“Nothing can now be believed which is seen in a newspaper. Truth itself becomes suspicious by being put into that polluted vehicle.”
Odds are, if you are affiliated with cybersecurity in any way, you have been touched by The Cyberwire. They are a cyber security-focused news service which is viewed as a trusted, independent voice in the world of news swirling around cybersecurity. Cyberwire delivers accessible and relevant information by working hard to separate the signal from the noise in an industry overloaded with information and competing messages
As our world gets more connected with each new wired device, each new piece of IoT, we need to understand how to protect these things, and by extension, ourselves.
In this week’s episode of InSecurity, Matt Stephenson chats with Dave Bittner about Cybersecurity in the year that was and the year to come. They also quote Albert Brooks, discuss octopus eyeballs and debate the merits of Vinyl LPsand cassettescompared to digital music and streaming. You’re not going to want to miss this one…
About Dave Bittner
Dave Bittner(@bittner) is the Producer and host of the CyberWire DailyPodcast, the top-ranking daily cybersecurity podcast in the world according to iTunes. In addition his duties as host of the CyberWire podcast, he also hosts the Hacking Humans&Recorded Futurepodcasts.
Bittner has over twenty years experience in digital media, video and television production and interactive technology. He has developed award winning interactive training programs for a variety of industries, and produced countless corporate, industrial and broadcast programs as co-owner of Pixel Workshop.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcastand host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
InSecurity Podcast: Infogressive CEO Justin Kallhoff: How Much is Securing Your Business Worth?
"The biggest bang for the buck in security is to ask for more money—because it's free!"
In today’s cybersecurity market, it can be difficult for a small business to catch the attention of the major security players. Oftentimes, those large players offer a scaled-back version of their enterprise solution at a lower price or a souped-up version of their consumer product.
Neither option tends to meet the needs of the type of small business that is frequently the victim of a data breach. Especially when you consider that, according to the 2018 Verizon Data Breach Investigations Report, of those breaches
Some folks in Lincoln, Nebraska didn’t particularly care for that status quo and decided to do something about it. Over the past decade, CEO Justin Kallhoff and the crew over at Infogressive have built an enterprise spread over 44 states and 20 countries, comprising over 30,000 seats.
In today’s episode of InSecurity, Matt Stephenson chats with Justin Kallhoff about the trials and tribulations of the Small to Medium enterprise in the contemporary world of Cryptovariants, ransomware and how MSSPs work to shoulder the burden of cybersecurity.
About Justin Kallhoff
Justin Kallhoff (@justinkallhoff) founded Infogressive Inc. in October of 2006 with a dream of creating a world-class team of information security professionals that could make a difference for clients spanning the globe. Over the past decade, Justin and the crew at Infogressive have built an enterprise spread over 44 states and 20 countries, comprising over 30,000 seats.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
InSecurity Podcast: Lieutenant Colonel (Ret) Pete Schiefelbein: It’s Not Just Cybersecurity, It’s Information Security
The Cyber Security Forum Initiative (CSFI) is a non-profit organization headquartered in Omaha, NE and in Washington DC with a mission "to provide Cyber Warfare awareness, guidance, and security solutions through collaboration, education, volunteer work, and training to assist the US Government, US Military, Commercial Interests, and International Partners." CSFI was born out of the collaboration of dozens of experts, and today CSFI is comprised of a large community of nearly 81,000 Cyber Security and Cyber Warfare professionals from the government, military, private sector, and academia.
Pete Schiefelbein is a key part of CSFI and works to provide the kind of training to military and private sector companies that can be the difference between a major data breach and just another day at the office.
In today’s episode of InSecurity, Matt Stephenson chats with Pete about a broad spectrum of topics including the evolution of the Marine Corps into a state of the art Cyber Defense unit as well its traditional role as an elite wartime fighting force. They dig into the notion of generational change and how it can effect a military organization. Further, Matt and Pete dig into the notion of information security compared to cybersecurity.
Oh… and for good measure, they even talk a bit about the fact that Pete and his son are both Eagle Scouts and the role scouting is playing in developing the next generation of cybersecurity professionals.
For more information on the topics discussed in the podcast, make sure to check out the following:
About Pete Schiefelbein
PeteSchiefelbein is an Advisory Board Member at the Cyber Security Forum Initiative (@CSFI_DCOE) He also is a systems engineer at CSCI. Prior to his current work, Pete served 24 years in the United States Marine Corps, recently retiring as a Lieutenant Colonel. However, once a Marine, always a Marine. His final billet in the Marines was as Director, G-6 for the Marine Corps Training and Education Command in Quantico, Virginia, responsible for the governance, procurement, sustainment, and cyber security of over 20,000 user seats at more than 70 Marine Corps formal learning centers across the United States. It is safe to say that Pete knows a thing or two about operating a sophisticated network and protecting data from a variety of threats. Pete is a graduate of the U.S. Naval Academy (B.S., Mechanical Engineering) and the Naval Postgraduate School (M.S., Electrical Engineering).
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Here are some important numbers to consider when thinking about the personnel and technology required to keep your network and your data safe.
Over two thirds of all network compromises are not discovered for months
The average cost to a business for each record lost to a data breach is $148
Now consider that, according to the Herjavec group, there will be over 3.5 million cybersecurity job vacancies by 2021. These gaps run the gamut from the heart of the datacenter up to the executive suite including CISO and CSO positions. How are businesses supposed to prepare for their future if they are not fully staffed and ready to protect their present?
In today’s special LIVE episode of InSecurity, Matt Stephenson talks with Huntsource Co-Founders Matt Donato and Jack Hall about the ever-growing Cybersecurity Skills Shortage. In a world where there appears to be a never ending torrent of malware, ransomware and coordinated attacks, the gap between attackers and defenders is growing seemingly every day.
About Huntsource
Huntsource seeks to arm businesses with the highest quality talent needed to effectively combat the various security risks that threaten them on a daily basis. They strive to be the preeminent and comprehensive Information and Cyber Security Professional Search and Talent Solutions firm, putting people and customers at the center of everything.
Their focus areas include cyber and information security. Protecting its infrastructure is vital to keeping a company safe.
About Matt Donato
Matt Donato is the Co-Founder and Managing Partner of Huntsource. He has 12+ years of experience in the staffing, executive search, and talent solutions industry. He is a seasoned leader and recruiting industry expert. Over the years his experience has included leading a variety of strategic and tactical operations functions, business development, key account relationship management, recruiting, organizational training, talent mapping, and driving organic new business growth. Donato continues to help elevate companies by identifying key talent and fostering relationships with both clients and candidates. Matt received his BS in Economics from Roanoke College and is currently obtaining his Executive MBA from Wake Forest School of Business.
About Jack Hall
Jack Hall is the Co-Founder and Managing Partner of Huntsource. He has spent the greater part of his 12+ year recruiting career working for large, national IT staffing firms. His experience includes recruiting top talent, client acquisition, strategic account management, training, and development. As a consistent top producer, Jack builds lasting relationships with his customers through a consultative approach and deep understanding of their business domain. He’s serviced clients in multiple industries, including financial services, telecommunications, consumer products, publishing, and healthcare, among others. Jack holds a BA in Psychology from the University of Tennessee, Knoxville, for which he remains an active supporter of the College of Arts and Sciences.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
Brian Fanzo Translates the Geek Speak and Simplifies the Complex
Do you know what a Botnet is?
What about the difference between Cloud-Based and Cloud-Enabled Security
Is there a difference between Machine Learning, Artificial Intelligence and a Difference Engine?
Could you explain the difference between a DoS and DDoS attack to your CFO? Could you make her care that there is a difference?
Should Americans care about GDPR? Do Americans know what GDPR is?
There’s a LOT going on just in the vocabulary words that we use in the cybersecurity world. We don’t just have to make the solutions that protect our users and prevent attacks from happening, we have to communicate what we are doing in a way that the users understand.
In this episode of InSecurity, Matt Stephenson sits down with proud pager-wearing millennial Brian Fanzo to talk about the important role effective communications plays in cybersecurity and the larger business world. With a social media following over 130,000 and over 150 episodes of his 2 podcasts published, it is fair to say that Brian Fanzo knows about the value of communicating.
About Brian Fanzo
Brian Fanzo (@iSocialFanz) inspires, motivates and educates businesses on how to leverage emerging technologies and digital marketing to stand out from the noise and reach the millennial and Gen-Z consumers.
He has a diverse background working for the Department of Defense in cybersecurity, then as a technology evangelist at a booming cloud computing startup. Brian is the founder of iSocialFanz which has helped launch digital and influencer strategies with the world’s most iconic brands like Dell EMC, Adobe, IBM, UFC and SAP.
Brian hosts two podcasts (FOMOFanz & SMACtalk), has traveled to over 70 countries and has spoken at many of the world’s largest events including SXSW, CES, Mobile World Congress.
Brian is a diehard Pittsburgh sports fan and semi-professional poker player who isn’t afraid to leverage his fast talking skills to read your body language and spot when you’re bluffing.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
To hear more, visit:
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
InSecurity Podcast: Theresa Payton has protected our money, our President and now our most at-risk children
What if I told you that there are awful people out there exploiting children and using high end technology to cover their tracks?
What if I told you that they are getting away with it?
What if I told you that there are people out there with the experience, knowhow, technology… and most importantly, the will… to find these people
What if I told you that they ARE finding these scumbags
What if I told you that can help…
Theresa Payton is currently the CEO of Fortalice and co-founder of Dark Cube. She started her career in the financial sector before moving on to public service. She once worked in a big white building you might recognize.
In today’s episode of InSecurity, Matt Stephenson speaks with Theresa about her journey from the banking business in Florida… to becoming the CIO of the White House… to starring on a hit show on CBS… to playing a role in finding exploited children. Her journey is incredible and you won’t want to miss it.
About Theresa Payton
Theresa Payton is President and CEO of Fortalice Solutions, co-Founder of Dark Cubed, former White House CIO, star of the CBS hit show Hunted, and best-selling author of the book Privacy in the Age of Big Data.
Payton is one of the nation’s most respected authorities on information security, cybercrime, fraud mitigation, and security technology implementation.
As White House Chief Information Officer (CIO) at the Executive Office of the President from 2006 to 2008, Payton administered the information technology enterprise for the President and 3,000 staff members. Prior to her time at the White House, Theresa Payton was a senior technology executive in banking, spending 16 years providing banking solutions using emerging technologies.
Payton founded Fortalice in 2008 and lends her expertise to government and private sector organizations to help them improve their information technology systems. In 2010, Security Magazine named her one of the top 25 "Most Influential People in Security."
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
To hear more, visit:
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Is Nerdcore the future of Infosec and Hip Hop? OHM-I shows the way.
At your wit’s end because of APT attacks? Tried everything but the bad guys keep finding creative ways in?
Have you considered listening to Nerdcore hip hop for inspiration?
No? You’re missing out.
Yo, you need fortify heavily
I see your database services and version 1 SMB
You know what this nerd gon’ do, payloads I’mma turn on you
That quad 4 make you sad forever, that’s ETERNALBLUE
That’s just a taste of the knowledge OHM-I has in store for you.
In this episode of InSecurity, Matt Stephenson sits down with Nerdcore superstar OHM-I to find out what is happening in the world of Nerdcore Hip Hop and where it intersects with the world of cybersecurity. OHM-I has spent over a decade in both games and has plenty to say about his time in each.
Did legends like Grandmaster Flash and Rick Rubin hack music in the formative days of Hip Hop?
What role can tech companies play in bringing young black men into STEM programs at an early age?
Is there such a thing as Nerdcore Country music?
About OHM-I, AKA Leron Gray
Leron Gray is the secret identity of Nerdcore superstar MC and producer and OHM-I. Leron spent 10 years in the Navy including a recent post as a Cryptologic Technician. With a history of network vulnerability assessments, incident response and network reconstruction, he now enters the private sector as a pen-tester and Red-Teamer.
With multiple LPs, EPs and singles to his credit, OHM-I is a stalwart on the Nerdcore scene. Look for him at events like Magfest, SXSW, Nerdapalooza and other Nerd-friendly venues. Dig into his virtual crates on Bandcamp and Soundcloud to hear more!
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
To hear more, visit:
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Look for the InSecurity Podcast with Matt Stephenson on Spotify and Soundcloud!
InSecurity Podcast: As a Healthcare CISO, Taylor Lehmann protects more than just Endpoints
Is a Patient a User? A Customer? A Client? Wellforce CISO Taylor Lehmann Needs to Protect Them All.
Taylor Lehmann is the CISO of a healthcare system spread over 8 locations that treats hundreds of thousands of patients and employs thousands of staff.
He has to be on top of all it from a cybersecurity perspective. Wellforce users and “customers” are a very different responsibility for Taylor compared to that of the average CISO. Lives are literally on the line.
In this episode of InSecurity, Matt Stephenson chats with Wellforce’s Taylor Lehmann on the role of the CISO at a large, multi-location healthcare system. Taylor isn’t just a suit-and-tie executive, though. He puts on the scrubs and does rounds with the medical staff in order to immerse himself in the daily operations of the facilities. For Taylor, that is the only way to grok what is happening at Wellforce and to know what he and his teams must be doing to protect it
About Taylor Lehmann
Taylor Lehman (@sidechannelsec) is the CISO of Wellforce and Tufts Medical Center. He was formerly the CPO/CISO/CIO/ Director for Independent Health, HealthEdge, and PwC, as well as the former VP of Cyber Risk Management at State Street Bank.
Taylor is also an expert in securing software development and delivery, and is on the boards of Gartner Evanta, the HITRUST Community Extension Program, the TPA Summit, and the Business Associate Council. He has CBCP, CISM, CISA, CRISC, CIPP/US, CCSFP (HITRUST), ITIL, HCISPP, and PMP certifications.
About Matt Stephenson
Insecurity Podcast hostMatt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcastand host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
To hear more, visit:
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
From Amazon Echo to self-driving cars to Norman, the Psychopathic AI… the Artificial Intelligence diaspora appears to be growing as diverse as humanity itself. Are we good with that?
Susan Etlinger joins Matt Stephenson on the InSecurity podcast to dig into the business ramifications of the ever-increasing presence Artificial Intelligence in the data center. Susan is an industry analyst focusing on industry trends related to the impact of emerging technologies on organizations and individuals. Susan specializes in business strategies related to artificial intelligence, data science, analytics and digital ethics.
In this episode of Insecurity, Susan calms Matt's irrational fears of the potential of AI while illuminating the exciting present and future of Artificial Intelligence and Machine Learning.
We'll take a look at what is happening in "The Enterprise" and why AI experiments like Microsoft's Tay and MIT's Norman can provide value. Given that Susan was recently named among 100 #AI Influencersby US AI, she is among the most qualified among us to lead this conversation.
About Susan Etlinger
Susan Etlinger(@setlinger), an industry analyst at Altimeter Group, is a globally recognized expert in digital strategy, with a focus on artificial intelligence, big data, AI ethics and big data. Susan conducts independent research and has authored many reports that are available to the public.
Susan works with Global 2000 clients to assess the impact of AI and related technologies on business, and identify use cases, opportunities, risks and organizational structure and culture. She also works with technology vendors to refine product road maps and strategies based on her independent research.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcastand host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
To hear more, visit:
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Lee Mangold on The role, responsibility and expectations of Government in Cybersecurity
Regardless of where you stand on the political spectrum, there can be no denying that the United States if facing threats entirely different from anything we have seen in the first 230 years of our democracy
From Edward Snowden to Chelsea Manning to Julian Asange to… well… all of Russia… the cyber-threats are real and they are only increasing in scale and complexity
Much like the law, our lawmakers have appeared woefully ignorant of how these attacks work, how to defend against them and, most prominently, how to prevent them
Lee Mangold spent 14 years working as a government contractor developing training systems and cybersecurity technologies. Now he is a Candidate for District 28 in the Florida State House of Representative.
In this episode of the InSecurity Podcast, Lee Mangold sits down with Matt Stephenson and Jack McHugh to discuss what part Government needs to play in the overall scheme of Cybersecurity.
About Lee Mangold
Lee Mangold (@LeeMangold) is a cybersecurity thought leader with 20 years of experience in security, IT, computer science, and engineering. Throughout his career, Lee has supported the US Government, Fortune companies, and small businesses alike. He has a Bachelor's in Computer Science, an MBA with a computer science concentration, and his Doctorate in Computer and Information Security.
Additionally, Lee is a professor at the University of Central Florida, Vice President and Lead Instructor at Florida Cyber Alliance and Officer, ISSA Coordination, BSides Orlando.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come before.
About Jack McHugh
Hailing from Stockton, California, Jack McHugh left for the rural confines of Boise State University where he discovered his passion for technology. After surviving a tumultuous IPO, he made a move to Cylance, joining the sales organization where he supports strategic accounts in North America. Jack brings a unique combination of youth and experience to his perspective as it pertains to Cybersecurity.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
To hear more, visit:
ThreatVector InSecurity Podcasts
iTunes/Apple Podcasts
GooglePlay Music
InSecurity Podcast: Steve Snyder on the past, present and future of currency
Fortnite and Bitcoin and Dollars OH MY! What makes real money... REAL?
What if I told you a man named Matthew Mellon owned a cache of Ripple that at one point was valued at over $1 BILLION and was still worth over $500 MILLION at the time of his unexpected death
Mellon claimed to have kept the digital keys to his Ripple wallet locked in cold storage in other people's names at various locations around the US
What does the family of the deceased do in a situation like this?
What does anyone do with the notion of hundreds of millions of dollars in value that is locked away and utterly inaccessible?
What the hell is Ripple anyway?
In this episode of the InSecurity Podcast, Steve Snyder joins Matt Stephenson and Edward Preston for a look into the fact, fiction and myth of crypto-currencies. And just to make things a bit weirder… we’re also going to talk about weapon skins that are trading for $50,000 inside games.
FIFTY.
THOUSAND.
DOLLARS.
Noodle on that for a minute…
About Steve Snyder
Steve Snyderis a member of Bradley’s Banking and Financial Services and Cybersecurity and Privacyteams. He leverages his industry experience as a network engineer and cyber risk manager to assist clients matters related to data protection arising from emerging technologies. Steve is a thought leader in privacy and data security and routinely writes and speaks on cybersecurity topics.
About Matt Stephenson
Insecurity Podcast host Matt Stephenson (@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
About Edward Preston
Edward Preston (@eptrader) has an eclectic professional background that stretches from the trading floors of Wall Street to data centers worldwide. Edward started his career in the finance industry, spending over 15 years in commodities and foreign exchange. With a natural talent for motivating, coaching, and mentoring loyal, goal-oriented sales teams, Edward has a track record for building effective sales teams who have solid communication lines with executive management.
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
To hear more, visit:
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
We may be talking primarily to Salespeople with this episode, but… keep this in mind… if you need to get the CISO of your organization on your side… you are, indeed, selling your CISO on your idea.
One thing salespeople probably don’t realize is that a CIO or CISO typically agrees to a meeting for one of three reasons
In this episode of the InSecurity podcast, host Matt Stephenson welcomes Mark Weatherford, SVP & Chief Cybersecurity Strategist at vArmour. Mark also sits on advisory boards for numerous companies. Based on his 30+ years of experience, he has assembled a set of guidelines that has proven to pave the way into a CISO’s office in order to get your story heard.
Some of this may seem like basic common sense, but you’d be surprised how successful you can be simply sticking to these rules.
What if I told you that we could save the world be teaching kids to hack early in life? Pete Herzog thinks that might be the way to go.
Is he right?
The word “hacking” has reached an almost mystical status for those outside the true hackerverse. Pete Herzog wants to teach young people the skills involved with hacking in order to provide them with the additional tools that come along with those skills.
As a third generation of hackers enters the workplace, there are questions to be discussed… Why is hacking relevant today? Is hacking a bad thing? What does hacking even mean?
In this episode of the InSecurity Podcast, host Matt Stephenson is joined by special guest Pete Herzog, co-founder of ISECOM and Hacker High School. Pete is one of the leading voices encouraging today’s young people to learn how to hack. We’ll dig into these questions about hacking and what it means to be a hacker in the modern world of Cybersecurity.
A few years back in 2014, the Wall Street Journal said, “DevOps is a buzzword for a new movement associated with enterprise IT that in reality plays more in the domain of startups and SMBs.” That stirred up an understandable ruckus in the DevOps world.
Solutions Management manufacturer Puppet last year said (gated), “DevOps is an understood set of practices and cultural values that has been proven to help organizations of all sizes improve their software release cycles, software quality, security, and ability to get rapid feedback on product development.”
So, who’s right?
In this episode of the InSecurity Podcast, host Matt Stephenson is joined by special guest Alan Shimel, Founder of DevOps.com and Co-Founder DevOps Institute, obviously did not agree with that WSJ article, and has been quite busy in the DevOps world ever since as the movement has grown to play a key role in the continued evolution of the IT Industry.
Cyber threats and liabilities continue to escalate, so it begs the question: Do we even stand a chance in successfully defending against them?
Consider the following stats - in the last minute:
These costs are projected to nearly double by 2020, and they could go up several hundred times by 2030.
In this episode of the InSecurity Podcast, host Matt Stephenson is joined by special guest Larry Clinton, President of the Internet Security Alliance (ISA), a multi-sector trade association working to integrate advanced technology with the realistic business needs of its corporate members, while providing enlightened public policy advocacy to create a sustained system of cyber security.
Clinton has been pushing Washington DC to improve our national approach to security for over 15 years. Having worked with administrations across the political spectrum, one thing remains true: Government and Industry need to work together to solve the cybersecurity problem.
Clint Watts: Social Media Manipulation
What if I told you that the most effective way to hack an election isn’t injecting code into a voting machine or surreptitiously changing the vote count, but rather by means of clever and extensive use of popular social media platforms like Facebook and Twitter?
The major platforms are designed to be able to target specifics groups of people who fit specific profiles demographically. Nefarious organizations can use those platform features to influence public opinion and dialogue.
Bots can create what appear to be armies of people who publish what seems on the surface to be “news” that finds a home with like-minded people. And that, friends, is how someone half a world away can sway an election from an iPhone.
In this episode of the InSecurity Podcast, host Matt Stephenson is joined by special guest Clint Watts, national security contributor at MSNBC and author of the recently released best-selling book Messing with the Enemy: Surviving in a Social Media World of Hackers, Terrorists, Russians, and Fake News.
About Clint Watts
Clint Watts (@selectedwisdom) is a Robert A. Fox Fellow in the Foreign Policy Research Institute’s Program on the Middle Eastas well as a Senior Fellow at the Center For Cyber and Homeland Security at The George Washington University. Watts is a consultant and researcher modeling and forecasting threat actor behavior and developing countermeasures for disrupting and defeating state and non-state actors.
His research predominately focuses on terrorism forecasting and trends seeking to anticipate emerging extremist hotspots and anticipate appropriate counterterrorism responses. More recently, Watts used modeling to outline Russian influence operations via social media and the Kremlin’s return to Active Measures.
Before becoming a consultant, Clint served as a U.S. Army Infantry Officer after graduating from West Point, an FBI Special Agent on a Joint Terrorism Task Force (JTTF), as the Executive Officer of the Combating Terrorism Center at West Point (CTC) and as a consultant to the FBI’s Counter Terrorism Division (CTD) and National Security Branch (NSB).
About Matt Stephenson
Insecurity Podcast host Matt Stephenson(@packmatt73) leads the Security Technology team at Cylance, which puts him in front of crowds, cameras, and microphones all over the world. He is the regular host of the InSecurity podcast and host of CylanceTV
Twenty years of work with the world’s largest security, storage, and recovery companies has introduced Stephenson to some of the most fascinating people in the industry. He wants to get those stories told so that others can learn from what has come
Every week on the InSecurity Podcast, Matt interviews leading authorities in the security industry to gain an expert perspective on topics including risk management, security control friction, compliance issues, and building a culture of security. Each episode provides relevant insights for security practitioners and business leaders working to improve their organization’s security posture and bottom line.
Can’t get enough of Insecurity? You can find us wherever you get your podcasts including Spotify, Stitcher, SoundCloud, I Heart Radio as well as
ThreatVector InSecurity Podcasts:
https://threatvector.cylance.com/en_us/category/podcasts.html
iTunes/Apple Podcasts link: https://itunes.apple.com/us/podcast/insecurity/id1260714697?mt=2
GooglePlay Music link: https://play.google.com/music/listen#/ps/Ipudd6ommmgdsboen7rjd2lvste
Make sure you Subscribe, Rate and Review!
In Sneakers, undeniably one of the greatest hacker movies of all time, Ben Kingsley’s villain character ‘Cosmo’ says to Robert Redford’s character ‘Martin Bishop’ the following lie, which today has some very deep implications:
“There's a war out there, old friend. A world war. And it's not about who's got the most bullets. It's about who controls the information: what we see and hear, how we work, what we think - it's all about the information…”
In this episode of the InSecurity Podcast, host Matt Stephenson is joined by special guest Elinor Mills, SVP of Content and Media Strategy at the Bateman Group and formerly a renowned tech and security journalist, to discuss some of the implications of today’s widespread information war.
With quality time spent reporting on technology for Associated Press, IDG News, The Industry Standard, Reuters and CNET, Elinor has been through the digital wars practically since the beginning.
When you pre-date the consumer internet, odds are you know where some of the bodies are buried. In this podcast, Elinor points us to a few