Cyber Pro Files: Recent Episodes

securitycurrent

Are you a cyber security pro and want to hear what your peers are doing to safeguard their organizations? Or are you someone who wants to learn how the nation’s top cyber security pros are protecting your data against hackers or just human error?

In these real-world conversations, the nation’s leading Chief Information Security Officers (CISOs) and their security, risk and privacy colleagues, in addition to top thought leaders, share what is top of mind for them. They discuss how their organizations, from the private sector, government and academia, are solving problems in the constantly changing security environment. They explore what is really keeping them up at night.

Prepare to be enlightened, engaged, perhaps challenged and definitely informed while getting to know the pros who are responsible for it all.

View Details

Congratulations to Secureworks for their win in the #CISOChoiceAwards in the #SecurityAnalytics Category. In this interview, leading analyst Richard Stiennon talks with Ed Martin, Director of Product Management for #Secureworks, about their security analytics product, Secureworks Taegis, a cloud-native XDR solution that offers broad visibility into complex attacks by tracking threats across an entire ecosystem.

View Details

Congratulations to Zero Networks for their recognition in the 2021 #CISOChoiceAwards. In this interview, leading analyst Richard Stiennon talks with Benny Lakunishok, Co-Founder and CEO of #ZeroNetworks, to discuss their Access Orchestrator which was recognized in the #NetworkSecurity Technology Category. Zero Networks’ #AccessOrchestrator uses #microsegmentation to protect all servers and devices within a network with agentless and automated self-service.

View Details

Congratulations to Lynx Technology Partners for their win in the 2021 #CISOChoiceAwards for their Governance, Risk and Compliance offering. In this interview, leading analyst, Richard Stiennon talks with Franklin Donahoe, CEO of Lynx Technology Partners, about their #GRC solutions including Lynx 360 Security which enables proactive security through integration, visibility and communication. If you are a #CISO and would like access to more value-added content, request a complimentary membership to #CISOsConnect today: https://CISOsConnect.com

View Details

Congratulations to deepwatch for their win in the 2021 CISO Choice Awards for their MSSP offering. In this interview, leading analyst, Richard Stiennon talks with Tim West, Field CTO for deepwatch, about their Managed Detection and Response which is embraced by the CISOs for its differentiated approach to secure their organizations with an “always-on” security team to combat ongoing threats. Stay tuned for more interviews from the CISO Choice Awards and for more value-added content, request complimentary access to CISOs Connect today: https://CISOsConnect.com

View Details

Congratulations to Salt Security for their win in the 2021 CISO Choice Awards in the Application Security category. In this interview, leading analyst Richard Stiennon talks with Roey Eliyahu, CEO of Salt Security, about Salt’s API Protection Platform which is lauded by the CISOs for helping to protect organizations and their assets in an increasingly digitized information world. Stay tuned for more interviews from the CISO Choice Awards and for more value-added content, request complimentary access to CISOs Connect today: https://CISOsConnect.com

View Details

Congratulations to the Telos Corporation for their recognition in the 2021 CISO Choice Awards for their Cloud Security Solution. In this interview, leading analyst Richard Stiennon talks with Tom Badders, a Senior Product Manager for the Telos Corporation, about the Telos Ghost solution which is a virtual-based obfuscation network that works to ensure a totally secure online cloud environment. Stay tuned for more interviews from the CISO Choice Awards and for more value-added content, request complimentary access to CISOs Connect today: https://CISOsConnect.com

View Details

Congratulations to Stacklet for their recognition in the 2021 CISO Choice Awards for their Governance, Risk and Compliance Technology. In this interview, leading analyst Richard Stiennon talks with Travis Stanfield, CEO and Co-Founder of Stacklet, about the Stacklet Platform which is founded on the idea of cloud governance as code. Stay tuned for more interviews from the CISO Choice Awards and for more value-added content, request complimentary access to CISOs Connect today: https://CISOsConnect.com

View Details

Congratulations to RackTop Systems for their recognition in the 2021 CISO Choice Awards. In this interview, leading analyst Richard Stiennon talks with Jonathan Halstuch, CTO and Co-Founder of RackTop Systems, to discuss their BrickStor SP solution which was recognized in the Data Security category. BrickStor SP helps to protect data from malicious actors and potential ransomware attacks through integrated UEBA and SOAR technologies. Stay tuned for more interviews from the CISO Choice Awards and for more value-added professional development and technology content, request complimentary access to CISOs Connect today: https://CISOsConnect.com

View Details

Congratulations to Black Kite for their win in the 2021 CISO Choice Awards for their Risk Management solution. In this interview, leading analyst Richard Stiennon talks with Paul Paget, CEO of Black Kite, about Black Kite’s Cyber Rating System solution, which was lauded by the CISOs for helping organizations protect themselves against continuous threats from third parties. Stay tuned for more interviews from the CISO Choice Awards and for more value-added content, request complimentary access to CISOs Connect today: https://CISOsConnect.com

View Details

Congratulations to Axonius for their recognition in the 2021 CISO Choice Awards in the Partner in Success category. In this interview, leading analyst Richard Stiennon talks with Chris Cochran, Creative Director and Cybersecurity Advocate for Axonius, about their differentiated approach to working with the CISOs to ensure speedy alert triage and incident response. Stay tuned for more interviews from the CISO Choice Awards and for more value-added content, request complimentary access to CISOs Connect today: https://CISOsConnect.com

View Details

Congratulations to Armorblox for their win in the 2021 CISO Choice Visionary Award for their Email Protection solution. In this interview, leading analyst Richard Stiennon talks with Brian Johnson, CSO of Armorblox, about their vision and their differentiated email solutions which helps to protect companies against threat actors trying to infiltrate through phishing and other targeted attacks. Stay tuned for more interviews from the CISO Choice Awards and for more value-added content, request complimentary access to CISOs Connect today: https://CISOsConnect.com

View Details

CISO Choice Awards Judge Richard Stiennon talks about the value of the recognition as the CISO judges base their decisions on real-world experience. The CISO Choice Awards 2021 is made possible with the support of YL Ventures, W2 Communications, PLDT and Smart Communications, Inc.

View Details

Submit now: https://securitycurrent.com/ciso-choice-awards-2021

Closing date for applications is midnight (US time) on 15 September 2021. The CISO Choice Awards 2021 Board of Judges includes the following CISOs: Cherokee Nation Businesses CISO Nikk Gilbert Delta Dental CISO Fred Kwong, Ph.D. Dollar Tree Stores VP & CISO Kevin McKenzie Florida Crystals VP, IT Strategy & CISO Christine Vanderpool Invitae CISO Dave Ruedger Markel Corporation CISO & Privacy Officer Patricia Titus Nexteer Automotive CISO Arun DeSouza OneMain Financial CISO Tunde Oni-Daniel Group CISO PLDT Group & Smart Communications Angel Redoble Ricoh USA, Inc. CSO David Levine RWJBarnabas Health CISO Hussein Syed William Blair CISO Ralston Simmons, CISM Also, on the Board of Judges is well-known author and analyst Richard Stiennon who wrote the Security Yearbook 2021, which includes a directory of 2,615 companies. The CISO Choice Awards 2021 is made possible with the support of PLDT, Smart Communications, Inc., YL Ventures and W2 Communications.

View Details

Watch CISOs Connect's CISOs Top 100 CISOs (C100) 2021 Esteemed CISO Board of Judges congratulate the winners of the first of its kind CISO recognition honoring the top 100 CISOs across the United States. Winners will be announced on July 7th with a formal ceremony. The C100 recognition is made possible with the support of ePLDT, BlackKite, YLVentures, Orca and rThreat.

View Details

CISOs Connect's CISOs Top 100 CISOs (C100) 2021 Distinguished CISO Board of Judges talk about the First of Its Kind CISO-selected CISO Recognition honoring the top 100 CISOs across the United States.

Call for entries! Nominate your CISO here: https://bit.ly/3f74qDv 

There is no registration or nomination fee. The application deadline is April 30th, 2021.

Recognizing the CISOs with support from ePLDT, Black Kite, YL Ventures, Orca and rThreat.

View Details

Global financial services CISO and Security Current's CISO Choice Awards Board of Judges CISO Matt Hollcraft speaks with the winner of the best Security Startup, Cyral founder and CEO Manav Mital. A data cloud security company, Cyral also was selected by the 12 CISO board as the best Data Security Company. The two leading security experts discuss the cloud, where things stand today and where they are heading in 2021. They also talk about Cyral's cloud-native solution and the importance of being able to observe, control and protect cloud data without impacting performance. Watch to learn more.

View Details

WATCH: Legal Expert Mark Rasch and Industry Analyst Richard Stiennon discuss suspected Russian hackers' use of SolarWinds to break into US Government Agencies including DHS, the Treasury and Commerce Departments. https://lnkd.in/gjA8KnK #cybersecurity #security #cyber #datasecurity #infosec #dataprotection #cybercrime #cyberattack #legal #solarwinds #russianhackers #DHS #treasury #commerce

View Details

The winners of the CISO Choice Awards 2020 are:

VISIONARY VENDOR: ORCA SECURITY PREMIER SECURITY VENDOR: PROOFPOINT STARTUP SECURITY COMPANY: CYRAL COVID-19 PIVOT: ATTACKIQ PARTNER IN SUCCESS: SECURITYSCORECARD NETWORK SECURITY: ZERO NETWORKS ENDPOINT SECURITY: MALWAREBYTES DATA SECURITY: CYRAL IDENTITY AND ACCESS MANAGEMENT (IAM): SEMPERIS GOVERNANCE RISK & COMPLIANCE (GRC): AXONIUS FRAUD PREVENTION: ALLURE SECURITY THREAT INTELLIGENCE: ANOMALI EMAIL SECURITY: ABNORMAL SECURITY SECURITY ANALYTICS: HUNTERS IOT SECURITY: PHOSPHORUS CYBERSECURITY APPLICATION SECURITY: STACKHAWK CLOUD SECURITY SOLUTION: SONRAI SECURITY MANAGED SECURITY SERVICE PROVIDER (MSSPS): DEEPWATCH RISK MANAGEMENT: NORMSHIELD SIEM SOLUTION: DEVO VULNERABILITY MANAGEMENT: KENNA SECURITY SECURITY OPERATIONS: HUNTERS SECURITY EDUCATION/TRAINING: CLOUD RANGE CYBER

Thanks to our leading Board of Judges and Sponsor YL Ventures! Canadian National Railway CISO Vaughn L. Hazen Dollar Tree Stores CISO Kevin McKenzie Ellie Mae SVP & CISO Selim Aissi Florida Crystals VP, IT Strategy & CISO Christine Vanderpool Hellman & Friedman CISO Matt Hollcraft LMC, a Lennar Corp VP, Information Security Margarita Rivera, Markel Corporation CISO & Privacy Officer Patricia Titus NFL CISO Tomas Maldonado OneMain Financial CISO Tunde Oni-Daniel Premise Health CISO Joey Johnson RWJBarnabas Health CISO Hussein Syed William Blair CISO Ralston Simmons, and IT-Harvest Analyst Richard Stiennon

View Details

Richard Stiennon, leading author and analyst, speaks with Mark Rasch, well-known attorney, on the charges against Joe Sullivan, former Uber CSO. With more than 30 years of experience in cybersecurity and data privacy – including within the U.S. Department of Justice, where he created the DOJ Computer Crime Unit and Cyber-Forensics practice, Mark discusses the implications and what it could mean for CSOs and CISOs.

View Details

To submit visit https://securitycurrent.com/ciso-choice-awards

Sponsored by YL Ventures https://www.ylventures.com/

View Details

Tomás Maldonado, CISO of the National Football League (NFL), speaks with Ian Keller, CSO of SBV Bank, which operates across Africa and is the only company in South Africa to partner with the South African Reserve Bank to collect banknotes and coins.

The two leading security executives talk about their everyday experiences and the commonalities in terms of what they face from business and technical perspectives. They also discuss the convergence of physical and information security.

In particular, Ian discusses attacks on their over 700 armored vehicles and how it impacts not only physical security but information security. He also touches on the decline in use of cash and how that impacts the business.

Security Current’s host Tomás also discusses today’s technology trends in security with Ian and how there has been a shift to focus on the endpoint which with a remote workforce is outside of a CISOs direct control.

View Details

Special thanks for making this video on TPRM to CISOs Mike Davis, Bob Turner, Marcos Marrero, Joey Johnson, David Levine, Al Ghous and Marc Crudgington, MBA, and to our corporate sponsor NormShield CyberSecurity for their continued support of the CISO community. #TPRM #ThirdPartyRiskManagement #CISO #ResearchReport #RiskManagement #thirdpartyrisk #KnowledgeSharing #PeerToPeer #RFI #BuyersGuide #Security #SecurityProfessionals

View Details

Dan Bowden, VP and CISO Sentara Healthcare, speaks with *David Cass, VP of Cyber & IT Risk at the Federal Reserve Bank of New York, about the not-for-profit health system’s journey post COVID-19. The two leaders talk about how each industry - and within healthcare itself - have encountered different issues when ramping up. They discuss security, cloud capabilities, training and more. They also touch on personnel and the importance of taking care of employees while acknowledging the commitment and impressive work Sentara’s team, which serves Virginia and North Carolina, has performed. Listen to learn about the successes and some of the unique challenges Dan has encountered and how he has met them.

*Any opinions David expresses are his own and do not represent the Federal Reserve Bank of New York or the Federal Reserve System

View Details

Having conducted a major influenza pandemic exercise in Q4 of last year assuming all employees were sent home, Ellie Mae SVP & CISO Selim Aissi was able to quickly and effectively respond to COVID-19. In this podcast, Selim speaks with *David Cass, VP of Cyber & IT Risk at the Federal Reserve Bank of New York. Selim talks about technology and the importance of endpoint security as the perimeter becomes unknown. He also discusses attack trends he is seeing since COVID-19 hit, noting an increase in phishing using COVID as bait. And he talks about the importance of ensuring the well-being of employees and the need to communicate regularly. Listen now to hear Selim’s invaluable insights.

*Any opinions David expresses are his own and do not represent the Federal Reserve Bank of New York or the Federal Reserve System

View Details

Host and moderator Joey Johnson, CISO of Premise Health, will be joined by leading healthcare CISOs Hussein Syed of RWJBarnabas Health and Anahi Santiago of ChristianaCare as they discuss the unique challenges they face as they support frontline and remote medical workers as well as the myriad of other personnel and people. As you’ll hear from Joey in this preview, he will talk about how they are facilitating and securing a diverse workforce as well as patients, what they have learned and where they see things heading. Sponsored by Forescout --- for every registrant, Forescout will donate 10 meals to Feed America.

View Details

Jake Margolis, CISO Metropolitan Water District of Southern California – the largest distributor of treated drinking water in the United States, has leveraged tried and true foundational technologies in response to COVID-19 while moving forward with their tech procurement plans. In this conversation with *David Cass, VP of Cyber & IT Risk at the Federal Reserve Bank of New York, the two leaders discuss the impact the pandemic has had on organizations from a technology, security and personnel perspective. They talk about how today’s changes with the shift to working remotely may impact hiring and the way a business operates in the future. Listen to learn some of the innovative and creative ways Jake has met the challenge facing all CISOs.

*Any opinions David expresses are his own and do not represent the Federal Reserve Bank of New York or the Federal Reserve System

View Details

Fannie Mae CISO Christopher Porter speaks with David Cass, VP of Cyber & IT Risk at the Federal Reserve Bank of New York. The two industry leaders discuss today’s challenging times and the importance of people. They talk about staying connected with and taking care of staff. Chris provides additional insights into his new normal and where he sees things heading.

*Any opinions David expresses are his own opinions and don't represent the Federal Reserve Bank of New York or the Federal Reserve System.

View Details

Global CSO of TikTok Roland Cloutier speaks with David Cass, VP of Cyber & IT Risk at the Federal Reserve Bank of New York (*any opinions David expresses are his own opinions and don't represent the Federal Reserve Bank of New York or the Federal Reserve System). A seasoned executive, Roland provides guidance on being successful when starting a new role. The two industry leaders also discuss the new normal and what things may look like on the other side. They talk business resiliency and CISO TikToks.

View Details

Dr. Pablo Molina, AVP and CISO at Drexel University speaks with David Cass, VP of Cyber & IT Risk at the Federal Reserve Bank of New York (any opinions David expresses are his own and do not represent the Federal Reserve Bank of New York or the Federal Reserve System).

Dr. Molina discusses how the university transitioned faculty, staff and students among others to a work remotely and distance learning and the challenges the leading university has encountered. Additionally, he addresses Zoom bombing incidents, increased phishing attempts with bad actors trying to leverage COVID-19 and the need for the university to maintain an open network from a research and  academic freedom point of view.

View Details

Host and moderator David Cass, VP of Cyber & IT Risk at the Federal Reserve Bank of New York* talks about what to expect when his CISO peers Frank Aiello of Maximus, David Levine of RICOH USA, Colin Anderson of Levi Strauss and Tessian CEO Tim Sadler join him to discuss the people and processes in place due to the pandemic and what to expect moving forward.

* The opinions David expresses are his own and do not represent the Federal Reserve Bank of NY or the Federal Reserve System

View Details

CISO Colin Anderson of Levi Strauss speaks with David Cass, VP of Cyber & IT Risk at the Federal Reserve Bank of New York (*any opinions he expresses are his own opinions and don't represent the Federal Reserve Bank of New York or the Federal Reserve System). Colin discusses how Levi Strauss is putting people first and using the current crisis to move the business forward. The two seasoned security professionals also discuss challenges that have arisen due to COVID-19.

View Details

What impact has the COVID-19 pandemic had on the security of organizations that have now by and large had to quickly migrate to a remote workforce? David Cass, VP of Cyber & IT Risk at the Federal Reserve Bank of New York (*any opinions he expresses are his own opinions and don’t represent the Federal Reserve Bank of NY or the Federal Reserve System) speaks with David Levine, VP and CISO of RICOH USA, Inc. The experts discuss how the move impacts RICOH and what it has meant in terms of security. Prepare to be enlightened, engaged, and definitely informed on the new normal.

View Details

The business of information security is tough: the bad guys only need to get it right once, while the good guys have to get it right all the time. One hundred percent protection of all endpoints is not possible, and eventually, there will be an infection. The question is, how do you react as quickly as you can to detect the most important infections before they wreak havoc in your system?

In this Bitdefender-sponsored podcast, IBM Cloud and SaaS Operations Global CISO David Cass talks to Harish Agastya, VP of Enterprise Solutions at Bitdefender, about the challenges in Endpoint Detection and Response (EDR). They explore how EDR is one of many layers of protection and how it works best when it relies on the intelligence of prior layers.  

Harish emphasizes how the reduction of noise generated by these often-disparate solutions is crucial and how such solutions need to be available to all players in the market – not just to big organizations with deep pockets.

View Details

Enterprise networks grow more complex by the day. With hundreds to thousands of firewall rules, devices and routers across on-premise and hybrid cloud environments, it is difficult to have visibility into the security policy change process.

This complexity, combined with the increasing rate of change, leads to vulnerability in the network. In addition, business owners need to have applications provisioned quickly but have little consideration as to the security implications of their requests.

In this Tufin sponsored podcast, David Cass, the Global Partner, Cloud Security and FSS CISO at IBM, discusses with Sagi Bar-Zvi, Tufin’s Solution Architect for the Americas, the benefits to CISOs of automating security policy orchestration. The two talk about how it delivers agility while verifying change requests – sometimes hundreds per day – will not cause a security breach once made.

View Details

Mastercard is a technology company in the global payments industry which operates the world’s fastest payments processing network, connecting consumers, financial institutions, merchants, governments and businesses in more than 210 countries and territories. Mastercard’s products and solutions make everyday commerce activities – such as shopping, traveling, running a business and managing finances – easier, more efficient and secure for everyone. 

As Mastercard’s Executive Vice President and CISO, Ron Green is responsible for upholding that mission. In this podcast, Green, a security visionary responsible for both cyber and physical security, speaks with David Cass, Global Partner, Cloud Security and FSS CISO at IBM, about what Mastercard is doing to ensure the promise of security not only today but in the future. Green talks about new technologies and processes, what keeps him up at night, and he provides recommendations to his peers. 

View Details

The endpoint is becoming the new edge of the business. As the doorway to your data, with more and more breaches getting in via the endpoint, it is turning into one of the weakest links for today’s business. It is critical that businesses can detect new, and real threats at the endpoint, and respond to those threats in near real-time.

However, with masses of data being generated and processed, being able to scale and respond effectively is getting harder. As you’ll hear in this SentinelOne sponsored podcast with CEO & Co-founder Tomer Weingarten and Maxim Integrated Chief Cyber Risk Officer Matt Hollcraft, automation and machine learning are key components in being successful in protecting against today’s malware.

View Details

CISOs are increasingly looking to User Behavior Analytics (UBA) as a key security tool to help combat threats by identifying anomalous behavior.

According to the report, CISOs Investigate: UBA, authored by more than a dozen CISOs, by quickly providing actionable intelligence, UBA enables them to potentially reduce loss to their organizations by identifying and thwarting attacks earlier.

Feris Rifai, CEO of Bay Dynamics, a provider of analytics and UBA solutions, says CISOs are realizing that to effectively protect their organization they need to add a UBA component to their security arsenal.

In this sponsored podcast, Rifai and David Cass, the Global Partner, Cloud Security and FSS CISO at IBM, discuss what UBA offers and how it is helping organizations across industries.

View Details

Enterprises are increasingly adopting cloud strategies. Despite this, adoption has been impacted in some cases due to cybersecurity concerns.   In this podcast, David Cass, the Global Partner, Cloud Security and FSS CISO at IBM reviews the state of cloud adoption and security with Mike Schuricht, Senior Director of Product Management at Bitglass, a cloud access security broker.   The two experts discuss how cloud is taking off and that despite security being a key concern of CISOs, with the right protections and solutions in place, cloud can be highly secure.    In this Bitglass sponsored podcast, the two touch on critical control areas and what CISOs should take into account when adopting and maintaining a cloud strategy.

View Details

Premise Health is a leader in onsite health and wellness programs providing some 600 large employer sponsored employee clinics. With a highly distributed and regulated environment, Johnson is responsible for all cybersecurity and information technology, compliance, audit and vendor risk management. Johnson was just named the winner of the prestigious Information Security Executive® of the Year Award in the Southeast. In this podcast, Johnson speaks with David Cass, IBM Cloud & SaaS Global CISO, about Premise Health’s unique business model and how he uses proactive security and risk management to meet challenging security, compliance and audit demands.

View Details

The volume of threats and attacks most security teams face daily can leave them overworked and fatigued, operating in what DocuSign CISO Vanessa Pegueros has identified as level one trauma – a sort of cyber PTSD that can put organizations at risk. In this podcast, Pegueros talks with David Cass, IBM Cloud & SaaS Global CISO, about her four-part series in Security Current that explores the human element of incident response and how CISOs can identify and resolve trauma in the organization. They also discuss the Board’s role in incident response and why being quick to fire after a breach may not always be the most effective approach. Read the series: Read Part OneRead Part TwoRead Part ThreeRead Part Four

View Details

The CISO increasingly has a seat in the boardroom, as the role is becoming more of the rule than the exception in enterprises.

During RSA Conference 2017, Marci McCarthy, President & CEO of T.E.N., sat down with David Cass, Global CISO IBM Cloud & SaaS, to discuss the continuing evolution of the information security industry and specifically the role of the executive.

McCarthy founded the prestigious ISE® Awards Program, which has helped elevate the role of security executives, who are recognized by their peers for their contributions and specific security projects. In this podcast, McCarthy provides insights into the profession and talks about the shortage of security personnel, the startup ecosystem and where the industry is headed.

View Details

The city of San Diego is a $4 billion business and it doesn’t shut down. As you’ll hear in this discussion between Gary Hayslip, the city’s CISO, and David Cass, Global CISO IBM Cloud and SaaS, San Diego is a smart city which is continuously rolling out new technologies to facilitate 'the business' while bolstering its security.

In this podcast, recorded during the RSA Conference, Hayslip talks about joining the city as its first CISO some three years ago and how he established a five-year-plan which leveraged established frameworks like the National Institute of Standards and Technology (NIST) to increase the security of the city and its 24 networks and 40 departments. The two also discuss ‘cloud first’ initiatives, resilient networks and the role of the CISO, which Hayslip provides practical guidance on with his book “A CISO Desk Reference Guide: A Practical Guide for CISOs.”

View Details

There has been an exponential adoption of Internet of Things (IoT) with experts predicting billions of IoT devices coming into use. And with the strategy more often than not being go to market and secure it later, enterprises are increasingly exposed to a variety of attacks.

As you’ll hear in this podcast with David Cass, Global CISO IBM Cloud and SaaS, and Len Rosenberg, ForeScout’s Commercial CTO and VP of Systems Engineering, the IoT is here to stay and security needs to be by design and not an afterthought. They also discuss what CISOs can do today to mitigate their exposure and what they should demand from IoT manufacturers.

View Details

With RSA around the corner and more security vendors than you can count, if you are a new CISO at the conference what should your game plan be? As you’ll hear in this podcast, the sheer number of interesting technologies at RSA can potentially overwhelm new CISOs.

David Cass, Global CISO IBM Cloud and SaaS, and Dr. Anton Chuvakin, research VP at Gartner’s Technical Professionals (GTP) Security and Risk Management Strategies team and a speaker at the RSA conference leading sessions on threat intelligence, discuss how RSA is a great place to talk to the vendors and their top product executives and see solutions up close. They also stress that people and process gaps and not a “particular box” are what needs to be addressed first.

Chuvakin first addresses today’s malware, box fatigue, and critical challenges and ways to think about threat vectors in 2017.

View Details

Tokenization is helping render data theft obsolete. Jason Witty, US Bancorp EVP and CISO, is in the midst of completing a multi-year tokenization integration project, for which his team won the recent ISE North America Project of the Year Award in the Financial Services category.

He discussed the many benefits of tokenization with David Cass, Global CISO IBM Cloud & SaaS, including fraud prevention and the reduction of risk and the attack surface. They discuss how it is a complex process, which is “simple” to implement but difficult to adopt. Witty also touches on the many unintended business benefits.

View Details

What specific things should companies look at when it comes to security monitoring in 2017? As you’ll hear in this podcast, a lot of the security problems facing organizations from the late 1990s and early 2000s have yet to be solved. David Cass, Global CISO IBM Cloud and SaaS, and Dr. Anton Chuvakin, research VP at Gartner’s Technical Professionals (GTP) Security and Risk Management Strategies team, discuss how security executives are still operationally challenged.

Chuvakin discusses how the technology landscape is changing but a lot of the challenges with the people themselves actually haven’t changed and the “old problems” haven’t been solved. In this podcast, he talks to Cass about the essential things organizations should be looking at, including newer technology like User Behavior Analytics (UBA) as well as Data Loss Prevention (DLP) solutions.

View Details

As you’ll hear in part two of the conversation between David Cass, Global CISO IBM Cloud and SaaS, and Chris Roberts, Acalvio Chief Security Architect, threat detection technology is allowing enterprises to identify intruders quickly. In this sponsored podcast you’ll hear how this burgeoning field of cybersecurity is helping enterprises protect their perimeters and internal infrastructure while shortening the time to discovery. ​

View Details

Ensuring continuous compliance while reducing complexity is essential to bolstering security for many organizations, in particular, those that process credit card data.

In this Tufin-sponsored podcast, IBM’s David Cass talks with Monext’s Laurent Klefstad, Leader for Systems, Network and Telecom, about automated security policy orchestration and how it allows the French company to save time and money by reducing the complexity of its networks and firewalls. Klefstad explains how Monext’s implementation of the Tufin solution provided Monext continuous compliance and the ability to reduce its firewall rules, of which there were about 3,000, by upwards of 20 percent. He also talks ROI, staffing implications and business enablement.

View Details

It’s becoming an old adage: it isn’t a matter of if an attacker will infiltrate your network but when.” With that being the case and with research showing that attackers often reside on an enterprise’s network for many months doing reconnaissance and exfiltrating data before being identified, what are and can enterprises do? The use of autonomous threat deception technologies to identify an intruder once inside the network is being adopted by enterprises seeking preventive and proactive to technologies. As you’ll hear in this conversation with David Cass, Global CISO IBM Cloud and SaaS CISO, and Chris Roberts, Acalvio Chief Security Architect there has been a significant evolution in threat detection technology to allow enterprises to identify intruders quickly. In this sponsored podcast you’ll hear how a new dynamic and smart approach to traditional honeypots is helping enterprises by allowing them to immediately detect lateral movement, shortening the time to discovery.

View Details

In this interview Matt Hollcraft, Maxim Integrated CISO, discusses common threat vectors – what is old and what is new – with Dan Schiappa, SVP & GM, Sophos Enduser Security Group. They talk about ransomware, the mobile workforce, Internet of things and hacking as a business. In this sponsored podcast, you’ll also hear about approaches that enterprises can take to reduce threats, which are increasingly sophisticated and continuous.

View Details

In this conversation with Security Current podcast host David Cass, Global CISO IBM Cloud & SaaS, David Mahon, CenturyLink CSO, talks about the evolution of the CISO role.

A seasoned security executive, with experience reporting to boards-of-directors, Mahon also provides guidance on how to present to a board. He also gives recommendations to current and aspiring CISOs on how to advance their careers.

View Details

The use of user behavior analytics (UBA) is at the forefront of technologies that CISOs are seeking for their security toolkits to help them identify that needle-in-a-haystack.

In this podcast sponsored by Exabeam, IBM’s David Cass talks with ADP’s V.Jay LaRosa about how UBA provides always on threat hunting to detect and thwart cyber attacks. LaRosa discusses ADP’s selection and implementation of the UBA solution and how his team uses it to quickly and effectively identify potential anomalous behavior. He also talks ROI, staffing and why he wishes he had started sooner.

View Details

In this conversation, CISO David Cass and CTO Reuven Harrison, discuss the journey to the cloud. They talk about increasing enterprise cloud adoption and hybrid environments. They also discuss the associated demand for automation of network security policy implementation across these hybrid cloud infrastructures.

In this sponsored podcast, you’ll hear how it is important to maintain business agility while securing applications in these increasingly diverse and complex networks.

You’ll also learn how automation and orchestration help ensure visibility and control across heterogeneous networks.

View Details

In this conversation, MIAX Options CSO John Masserini discusses the threat detection and response space with AlienVault President and CEO Barmak Meftah.

An early adopter of threat intelligence, Masserini notes its challenges and asks Meftah what AlienVault is seeing in the market and how threat intelligence is being integrated into companies’ security organizations.

Meftah talks about the need to efficiently aggregate information while noting that it is more important to synthesize the information to ensure it is easily consumable and actionable.

He describes AlienVault’s crowdsourcing approach and how it is helping SMBs centralize and simplify their threat detection and response. They were speaking in this sponsored podcast at the Black Hat Conference in Las Vegas earlier this month.

View Details

In the series brought to you by Security Current and Intersections IT Security ONE2ONE Summit and you will hear CISOs discuss today’s most critical issues in IT Security.

This episode features David Cass, IBM Cloud & SaaS Global CISO, and David Rooker, Actian Corporation CISO, who discuss the most prevalent attack vectors today, from email to ransomware with the Internet of Things (IoT) increasingly becoming a high security issue.

In this podcast you’ll hear about how the IoT brings great benefits while exponentially expanding the opportunity landscape for bad actors. You’ll also hear what Rooker is doing to enable business processes while bolstering security. They also touch on the need for qualified security personnel and how to find the right candidates.

View Details

In part three of the conversation David Cass, IBM cloud & SaaS global CISO and John Weinschenk, Spirent Communications general manager enterprise and network application discuss the potential hacking of medical devices and automated cars.

In this Spirent-sponsored podcast, Weinschenk explains how they worked with a surgeon to hack a medical device. He also talks about a second hack they conducted on an autonomous car that allowed them to take control of the systems and vehicle itself.

They discuss what needs to be done to secure these Internet of Things (IoT) devices and how manufacturers need to start thinking about how these systems can be exploited.

View Details

In this conversation with  Security Current podcast host David Cass, Global CISO IBM Cloud & SaaS, David Mahon, CenturyLink Chief Security Officer, discusses what he sees as two of today’s critical security issues and how to tackle them.

Mahon points to phishing and ransomware as the most prevalent types of attacks he is seeing in the industry. The two executives talk about the importance of security awareness training and Mahon provides tactical approaches to reduce the likelihood of a successful breach. They also discuss metrics, ROI and best practices for reporting to the board.

View Details

In the series brought to you by Security Current and Intersections IT Security ONE2ONE Summit you will hear CISOs discuss today’s most critical issues in IT Security.

This episode features David Cass, IBM Cloud & SaaS Global CISO, and William Okula, Executive Officer Police Technology Bureau at the Suffolk County Police Department who, discuss the most prevalent types of attack in the public sector.

In this podcast you’ll hear in particular about phishing and malware. They also discuss challenges facing security departments in the public sector, staffing and security best practices.

View Details

This episode features David Cass, IBM Cloud & SaaS CISO, and Richard Seiersen, GE Healthcare’s General Manager Cybersecurity and Privacy who discuss the different types of attack vectors in healthcare, which as you’ll hear is “As Security as it Gets.”

In this podcast you’ll hear about implantable medical devices or wearables, and the Industrial Internet of Healthcare Things. They also touch on Seiersen’s upcoming book “How to Measure Anything in Cybersecurity Risk,” which explores decision science and in particular quantitative approaches to decision making.

View Details

In the series brought to you by Intersections IT Security ONE2ONE Summit and Security Current you will hear CISOs discuss today’s most critical issues in IT Security.

This episode features David Cass, IBM Cloud & SaaS CISO, and Jonathon Neel, University of Virginia School of Medicine CISO, who discuss threat sharing with other CISOs, compliance, wearables and how to keep up with technology.

In this podcast you’ll also hear about FISMA and how it may impact the way universities operate in the future. David and Jonathon also touch on the Internet of Things (IoT) and how that impacts application development in the healthcare setting.

View Details

In part two of the conversation David Cass, IBM cloud & SaaS global CISO and John Weinschenk, Spirent Communications general manager enterprise and network application security, discuss managing risk.

In this Spirent sponsored podcast they talk about the need for continuous monitoring and testing to optimize spend to reduce risk. They also touch on the ability to respond quickly to a breach by ensuring strong remediation plans are in place, and discuss the need to diversify technology solutions.

View Details

CISOs can never reduce risk to zero. As technology development increases at a lightning speed with the Internet of Things (IoT) bringing more Internet-enabled devices daily and the cloud becoming more pervasive, what can and should be done? 

CISO David Cass, IBM Cloud and SaaS, speaks with John Weinschenk, , general manager enterprise and network application security of Spirent Communications, about some of the biggest threats facing enterprises as a result of these trends. 

Listen to this sponsored podcast as David and John, discuss ransomware, including hacker help desks, and the Internet of Things, including the potential for your refrigerator to attack you. They talk about some of the top things enterprises need to do from patching systems to testing to awareness to bolster their defenses.

View Details

Welcome to the Intersections IT Security One2One Summit podcast series presented in conjunction with Security Current.

In the series you will hear CISOs discuss today’s most critical issues in IT Security.

This episode features David Cass, IBM Cloud & SaaS CISO, and James Beeson, GE Capital Americas' CISO, who discuss how the nature of attacks has fundamentally changed and are becoming more destructive, for example with ransomware, which impacts corporations and individuals.

In this podcast you’ll also hear about organized crime and the traditional bad actors and how it is much easier to recruit because of the economics of it. David and James discuss how cybercrime has become so ‘mainstream’ that support is even offered on malware that easily purchased online. They also talk about what they think needs to be done to help combat today’s increasing attacks.

View Details

Welcome to the Intersections IT Security ONE2ONE Summit podcast series presented in conjunction with Security Current. In the series you will hear CISOs discuss today’s most critical issues in IT Security.

The first episode features David Cass, IBM Cloud & SaaS CISO, and David Hahn, Hearst Corporation CISO, who discuss today’s biggest security and associated business problems facing media corporations and how they are leading to billions of dollars in lost revenue.

In this podcast you’ll hear about malvertising, how it works, the absence of regulations and government intervention, and the Sony breach and its implications.

View Details

In today’s digital age, there are more connected devices than ever before. A look at the history of the digital universe shows that, like the real universe, it is expanding. From a single device meeting our needs—starting with the PC, then moving to laptops and phones—we seem poised on the brink of a technological “big bang” resulting in an ever-more-diffuse array of gadgets, monitors, appliances, and communications all working in tandem to enhance our personal and professional lives. And with the convergence of technologies more data is being generated than ever.

The question arises as to how then will we secure our networks and data?

As you’ll hear in this interview with David Cass, IBM Cloud & SaaS CISO, who speaks with Dr. J.R. Reagan, Deloitte Touche Tohmatsu Limited CISO, the way enterprises approach security likely may require new ways of thinking. They discuss how security has transformed from managing things to managing data in order to protect the enterprise. Dr. Reagan also provides 3 key takeaways for security executives in today’s digital age.

View Details

Cloud security continues to be a key consideration for CISOs with them weighing in on the pros and cons of whether or not to migrate to the cloud and, if so, best practices for migrating. A recent report issued by the Cloud Security Alliance (CSA), a member-driven organization chartered with promoting the use of best practices, touches on the key concerns facing adoption today. In this podcast recorded at the RSA 2016 Conference with Security Current's Vic Wheatman, CSA Chief Technology Officer Daniele Catteddu discusses the current and future state of the cloud and the enterprise.

View Details

Skyport Systems mission is to deliver a simple and effective secure-computing platform for enterprise applications.

As we hear from Skyport Systems Corporate Vice President Doug Gourlay, Skyport Systems SkySecure is a turnkey platform to run and manage application workloads that are the highest priority for the business to protect. It fully integrates hardware, software, and service components to simplify the assembly, deployment, and operational effort needed to manage secure servers.

In this sponsored podcast, Gourlay speaks with Security Current’s Vic Wheatman.

View Details

Tempered Networks enables enterprises to ‘cloak’ their networks, communications and endpoints so they are undetectable and tamper-proof, protected from cyber threats and human misuse/errors.

As we hear from Tempered Networks VP Security Architecture and Services Marc Kaplan, the company addresses a TCP/IP vulnerability by replacing IP addresses with cryptographic identities using built-in PKI encryption, managed through centralized policy and trust orchestration using a simple user interface

In this sponsored podcast, Kaplan speaks with Security Current’s Vic Wheatman.

View Details

Spikes Security Isla Malware Isolation System assumes all web content is bad and isolates everything on an appliance in the DMZ, protecting web users inside the network.

As we hear from Spikes Security Chief Marketing Officer Franklyn Jones, web content is fully rendered and completely transformed in the DMZ, then delivered in a malware-free format to secure endpoints inside the corporate network.

In this sponsored podcast, Jones speaks with Security Current’s Vic Wheatman.

View Details

Pwnie Express provides full threat detection of every wireless and wired devices in and around an organization’s workplace.

As we hear from Pwnie Express CEO Paul Paget, the company is the only one that detects rogue, misconfigured, and unauthorized devices across wired and wireless spectrums. He explains that by automating wireless and wired device detection, Pwnie Express continuously detects the devices on around the network that are open pathways for attackers.

In this sponsored podcast, Paget speaks with Security Current’s Vic Wheatman.

View Details

Interset is a user behavior analytics (UBA) solution, which leverages machine learning, big data, and risk forensics to provide an intelligent, accurate detection solution for insider and targeted attacks.

As we hear from Interset’s Vice President of Marketing Bill Munroe, the company’s patented analytics process aggregates data classes (endpoint, directory, SIEM, IP repository), and associates collected events to users, machines, applications and files – then applies risk scores to each.

In this sponsored podcast, Munroe discusses real-world use cases with Security Current’s Vic Wheatman.

View Details

GuardiCore provides a real-time breach detection and response solution that leverages threat deception and process-level visibility to quickly detect and respond to advanced threats inside data centers and clouds.

As we hear from GuardiCore Vice President of Marketing Dave Burton, this allows GuardiCore customers to know immediately when their data center has been breached and respond in a fraction of the time of traditional security technologies. In this sponsored podcast, Burton speaks with Security Current’s Vic Wheatman.

View Details

ProtectWise offers a Cloud Network DVR, which records everything on the network.

As we hear from ProtectWise Co-founder and Chief Technology Officer (CTO) Gene Stevens, the technology provides long-term retention of full fidelity network data, automated smart retrospection, advanced visualization and the ease of an on-demand service deployment model. In this sponsored podcast, Stevens speaks with Security Current’s Vic Wheatman.

View Details

Exabeam is a user behavior analytics (UBA) solution, which leverages existing log data to quickly detect advanced attacks, prioritize incidents and accelerate responses.

UBA solutions, as we hear in this podcast with Exabeam Chief Marketing Officer Rick Caccia, are dynamic and do not rely on static correlation rules but rather use machine learning to automatically understand normal user behavior and raise the alarm when users begin to do multiple things that are out of the norm.

In this sponsored podcast, Caccia speaks with Security Current’s Vic Wheatman.

View Details

Morgan Wright is an internationally recognized cybersecurity, cyberterrorism and identity theft expert. 

He's testified in front of congress, advised the U.S. State Department and served in law enforcement.  In this conversation with Security Current's Vic Wheatman, Morgan speaks about ISIS-inspired cyber terrorism, ransomware, and social engineering as a tool for enabling spear phishing to steal credentials and corrupt business systems.

Training, policy and philosophy are critical, even before security technologies are implemented.  As you'll hear from Wright: "Think before you click the link." 

View Details

With vast amounts of personal information and Internet-enabled medical equipment, health care faces unique security requirements. Some are a result of regulatory mandates such as HIPAA while others are because of the critical clinical equipment found in hospitals and doctors offices.  

Gaining visibility into the variety of platforms present while positioning for future needs becomes a challenge.  Technologies such as Network Access Control (NAC) can provide a needed overview into the security environment.  In this podcast with Security Current’s Vic Wheatman, Barnabas Healthcare’s CISO Hussein Syed and Dominic Hart, the healthcare system’s manager of information security architecture discuss their approach to this complex environment.

View Details

Encryption is fundamental to business today. But encryption also allows evildoers to plan nefarious criminal or terrorist acts.  Law enforcement, intelligence agencies and political interests have proposed "back doors" to enable them to do their jobs.  Shades of the cryptographic device, The Clipper Chip and the Skipjack algorithm!  Look it up!

CISO's need to work with stakeholders to find the right balance between their responsibilities in protecting sensitive data and cooperation with law enforcement and Homeland Security.  We discuss these and other issues in this conversation between Security Current's Vic Wheatman and Greg Schaffer, FirstBank VP and Information Security Officer. 

View Details

In the push to launch mission critical applications, insecure software often makes it into production. Sometimes hackers find the gaps and exploit vulnerabilities. Now new approaches are leading to continuous vulnerability testing - by ‘hackers.’

Based on crowdsourcing and by offering bug bounties, Secure Systems Development Life Cycle (SDLC) principles are being enhanced and developers' mindsets are being changed.

Code quality improvements resulted and efficiency improved. In this conversation, SANS Institute Director of Emerging Security Trends John Pescatore tells Security Current's Vic Wheatman what some CISOs and application developers have found by moving in this direction.

View Details

Each year is a new opportunity to use what we've learned in the past in order to address the future and anticipate what the bad actors may do next to breach our information security.

Here, the head of information security at Delta Dental of New Jersey addresses what we can expect as we enter 2016, discusses the role of cyber insurance, warns about how old source code can be exploited and highlights how Identity and Access Management and Managed Security Service Providers can help plan the future state of our Information Security.

Listen to Delta Dental of New Jersey's Roota Almeida in conversation with Security Current's Vic Wheatman.

View Details

The overall cost of cyber crime in 2015 to the world economy as a whole was estimated at a conservative $575 billion, according to research. Breaches are growing in number and sophistication.

According to Jason Witty, Executive Vice President and CISO at U.S. Bancorp, there are five major sources of information security threats and they are continuing to evolve dramatically.

He identified five high-level classifications which include: insider threats, organized crime, hactivists, terrorists, and nation states.

But as Witty tells Security Current’s Vic Wheatman there is a light at the end of the tunnel. Using security frameworks and taking advantage of new legislation that supports threat information sharing among organizations are some of the most viable approaches to combating the increasingly sophisticated and emerging threats.  Hear about these topics, as well as the growth in business email compromise, in this conversation.

View Details

Things happen. Staffers click links they shouldn't. Interlopers enter the workplace, gain access to a vacant desk, log in and steal corporate secrets. 

Technology helps, but end user security awareness training puts people on the front line of defense.  Employees need to recognize that the threats are real. Executives need to see that there is a real return on security training investment, partly due to preventing lost productivity, and that business risks can be significantly reduced. 

In this sponsored podcast, Security Current's Vic Wheatman speaks with Amy Baker, Vice President of Marketing of Wombat Security Technologies, a premier provider of security awareness training.

View Details

In a world of three letter acronyms comes yet another -- a new specification from the Cloud Security Alliance. SDP or Software Defined Perimeter.

SDP approaches are meant to create a secure micro segment between the user and a host. But how are SDPs different from other perimeter security approaches based on firewall appliances or virtual firewalls?

Can SDPs eliminate the need for firewalls? Can they save money? Who provides the technology and what are the advantages? Security Current's Vic Wheatman speaks with Gartner Research Director Lawrence Pingree about this emerging technology.

View Details

With the plethora of information security products and services on the market, how can CISOs prioritize what they truly need? And how can they differentiate from what may be a short-term fad brought to market by earnest but oftentimes aggressive solution providers or a long-term solution? 

The answer lies in stepping back and carefully examining your organization's overall security program from a predict, prevent, detect, protect and respond context to help plan priorities. 

Gartner surveys CISOs bi-annually to determine security buying trends and top of mind concerns.  In this podcast, Security Current's Vic Wheatman speaks with Gartner Research Director Perry Carpenter about the current state of CISO thinking in this area. 

View Details

In both the public and private sectors employees are by and large the weakest links when it comes to information security breaches.

Training needs to be more than simply a checkbox on a compliance list. Optimal approaches combine training and technology to ensure employees are security aware.

As you'll hear from Gartner Research Director Perry Carpenter in this conversation with Security Current's Vic Wheatman, training is not a one-time endeavor but needs to be multifaceted and continuous. 

View Details

The European Union's (EU) highest court recently found that the "Safe Harbor" provisions allowing data transfers from EU countries to United States' data centers are invalid.

Triggering this finding was a lawsuit motivated, in part, by spy agency access to citizen data in violation of privacy initiatives. Despite this ruling, transatlantic data flows can continue -- assuming other safeguards are in place.

Security Current's Vic Wheatman speaks with Lawrence Dietz, General Counsel for California-based TAL Global to make sense out of this and what it means to CISOs. Dietz is a nationally recognized expert in the areas of cybersecurity, cyber warfare, information security and intellectual property.

View Details

What is the optimal structure within an enterprise in terms of CISO reporting? Should a CISO report to the CIO? Or possibly to the CFO? In some cases, as you'll hear in part two of Vic Wheatman's interview with CISO Brian Lozada, CISO can stand for Chief Information Scapegoat Officer. Avoiding blame for security incidents requires relationships to ensure that both business and technical concerns are properly addressed. 

View Details

Information security in hedge funds is new and many hedge funds don't know what cybersecurity is or what is at risk. And there are unique security issues specifically related to hedge funds. 

With a high risk/reward mentality, and with high-worth individuals involved, regardless of the technologies implemented, the potential security problems may best addressed presently through ongoing security awareness and education, according to an expert in the space. 

Brian Lozada, Director and CISO of Abacus Group, LLC, a solutions provider servicing the segment, speaks with Security Vic Wheatman about the state of hedge funds and how they are a 'rich' target for cyber attackers. 

View Details

How can CISOs differentiate among "me too" information security startups? What is the role of incubators and are they useful in helping new security companies get started? And how is the NSA considered one of the best "graduate schools" in cybersecurity?

Security Current's Vic Wheatman explores this and other topics with Allegis Capital's Founder and Managing Director Robert Ackerman in part three of our investor series. 

View Details

One of the primary exit strategies for security startups is to be acquired. Sometimes that's a good thing, other times, not so much.

Hear about some of the issues associated with acquisitions and where startups added value to a security platform or suite of a larger solution provider.

And get the inside scoop on what Allegis Capital's Founder and Managing Director Robert Ackerman sees as some of the most creative, innovative, and cutting edge information security ideas of today.

In part two of a three-part series, Ackerman discusses exits and technologies he is watching.

View Details

At the second Security Current Security Shark Tank competition held during Black Hat in Las Vegas, six up and coming cybersecurity providers came face-to-face with some 20 Chief Information Security Officers (CISOs).

The startups were: Dtex Systems, Infocyte, Cymmetria, Datex Inc, Wombat Security and Syncurity.

After each startup's interaction with the Security Sharks, Security Current's Vic Wheatman spoke with the speaker for a quick hit podcast. 

Hear the results.

View Details

The level of venture capital financing has hit new heights with increasing investments in information security. Some venture capitalists (VCs) specialize in finding and funding startups in security, which is a unique segment within technology. 

What does this mean for security startups? And how does an investor's perspective impact Chief Information Security Officers? 

In part one of a three-part series, Security Current's Vic Wheatman speaks with Robert Ackerman, founder and managing director of Allegis Capital about the current state of VC funding and the burgeoning security field. 

View Details

How effective are Security Analytics tools and how do you compare their operational effectiveness?

After spending months researching this subject, Gartner's Dr. Anton Chuvakin says the long and short is that they just don't know how well the tools work as there isn't much data on the operational effectiveness of security analytics.

He points out that for analytics tools, many of the vendors have just 5-10 customers that have some data but it isn't enough. He tells Security Current's Vic Wheatman that a lot of stuff is very anecdotal and we only hear the success stories. So, he says it is hard to say, which type of a tool, model and statistics are working well. Listen to hear what you should do.

View Details

It no longer is will an intruder will gain access to your network, it is just a matter of when they will gain access.

Cybersecurity company Datex, Inc. says employees will make mistakes, user credentials will be compromised, data theft will happen and compliance mandates will not be met.

Its DataStealth service addresses these and other issues by inspecting network traffic, extracting sensitive information and substituting spurious data for the original information, transforming that information into secure and usable fragments to allow applications to securely do their jobs.

In this sponsored podcast with Security Current's Vic Wheatman, Ross Morley of Datex, Inc. describes how the service works, its benefits and provides real-world use cases.

View Details

SIEM stands for Security Information and Event Management.

SIEM is continuing to grow in usage but where does it stand in terms of cloud deployments and what is its cloud-based market share?

Gartner's Dr. Anton Chuvakin challenges the idea that one can compute market share for "Cloud SIEM" products because they actually don't quite exist, yet.

While he acknowledges that there are some "almost" SaaS (Software as a Service) SIEM products and services, true cloud-based SIEM solutions are not available.

In conversation with Security Current's Vic Wheatman, Dr. Chuvakin provides a taxonomy for SIEM and describes for the definitional differences.

View Details

Massive database breaches have resulted in millions of user identification and authentication profiles being compromised. Identifying unauthorized attempts to access systems or accounts is a basic requirement for financial institutions, etailers, retailers, healthcare provides and other enterprises.

Knowing the difference between employee and attacker behavior is key to avoiding security alert fatigue and using scarce resources to parse the good from the bad access attempts.

Further, collecting information about rogue takeovers for forensics purposes is a a good idea. Security Current's Vic Wheatman speaks on these issues and others with Mark Seward, Vice President of Marketing for Exabeam in this sponsored podcast.

View Details

With experts citing employees being compromised by attackers as a primary cause of security breaches, many enterprises are seeking new training methods.

Spun out of Carnegie Mellon University, Wombat Security takes what it says is a different approach that applies learning science principles. Gone are traditional classrooms and videos, replaced by an interactive more engaging approach based on research on how people best learn new things.

In this sponsored podcast, Security Current's Vic Wheatman speaks with Joe Ferrara, President and CEO of Wombat Security about how his company's training programs are improving the security posture of today's enterprises. 

View Details

For organizations to achieve maximum privacy and security the two need to go hand-in-hand but unfortunately they are often siloed within organizations. So how are organizations evolving to incorporate privacy, risk and compliance to address information security requirements? 

Finding the balance between holding what may be sensitive information about individuals and partners among others with regulations and laws protecting that information has become critical. Security Current's Vic Wheatman speaks with internationally-acclaimed, Professor Daniel Solove of the George Washington Law School, and CEO and Founder of training company TeachPrivacy about these issues and a groundbreaking conference being held in October 2015 that bridges the silos between privacy and security.

View Details

Many security policies are aspirations, doomed to fail because they are unrealistic. Not only can they be unachievable, but may in fact encourage people to disregard policies because, after all, "we can't really do that." 

Further, enterprises may not be able to collect on cyber insurance policy payouts because they didn't meet their own, internal standards. These and other issues surrounding information security policies are discussed in this conversation between Security Current's Vic Wheatman and Gartner's Dr. Anton Chuvakin.

View Details

Most "new" security technologies use functions and features developed years ago. Network Forensics applies machine learning, automating detection functions via machine-based analytics to decode and visualize relevant metadata.

Accordingly, Network Forensics represents an evolutionary trend in security. Who is providing these tools and capabilities? Gartner Research Director Lawrence Pingree answers the questions in this interview with Security Current's Vic Wheatman.

View Details

In this interview with an information security officer who prefers to remain anonymous we discuss the definitions of security intelligence, what it takes to be a CISO and the toughest part about heading up security at an enterprise. 

He also discusses how network complexity grows as new systems are built on top of existing infrastructure leading to potential problems. The interview conducted by Security Current's Vic Wheatman was recorded at the RSA Conference.

View Details

As the news of breaches across multiple sectors continues the role of the Chief Information Security Officer (CISO) has never been more important.

The CISO is not only responsible for protecting the organization they are tasked with enabling the business. And with the CISO speaking in both business and technical languages, they are quickly gaining visibility with the Board of Directors that needs to understand, and to provide resources for, enterprise security.

In this podcast, Daniel Conroy, the CISO of Synchrony Financial, a leading financial institution, speaks with Security Current's Vic Wheatman about the CISO role, the definition of security intelligence, and what keeps him up at night.

View Details

It isn't a matter of if your organization will be infected with malware but rather a matter of when. Based on that premise, Seculert designed a cloud service to quickly and automatically identify the machines connected to bad actors on the Internet. By knowing which equipment if compromised, desktop support staff can quickly replace or wipe the offending machine.

In this sponsored podcast, Security Current's Vic Wheatman speaks with Richard Greene, Seculert's President of Field Operations about the compensating controls the company provides, and why unsubscribing from spam may not be such a good idea.

View Details

Healthcare providers have some of the most complicated environments with a multitude of systems, users and regulatory mandates. And often, according Barnabas Health CISO Hussein Syed, this leads to one of the biggest challenges, which is a misunderstood environment. 

There concerns over Personally Identifiable Information (PII), as well as maintaining compliance with Payment Card Industry (PCI) mandates as healthcare providers generally take credit cards. 

Further, because of the growing Internet of Medical Things with various equipment now networked, data leakage becomes a greater concern. And compounding this is are third party providers, from doctors to billing companies, working with healthcare providers, making security even more difficult. 

As you'll hear from Hussein Syed as he speaks with Security Current's Vic Wheatman while at RSA it is a balancing act to provide access while ensuring security. They speak about these and other issues.

View Details

RSA Conference 2015 was bigger than ever with hundreds of startups promoting their wares. One segment that caught the attention of CISOs was what is being dubbed as next generation endpoint security.

As you'll hear, new approaches to endpoint security may allow enterprises to turn off legacy anti-virus, anti-worm and other traditional protections. And what does security intelligence means to a CISO?

Security Current's Vic Wheatman speaks with Patricia Titus about these and other issues including the toughest part of being a CISO.

View Details

A surprising number of organizations are expecting a cyber attack. Despite this it is getting harder to fill cyber security jobs.

ISACA, an independent, nonprofit global association that develops and promotes the adoption of globally accepted practices for information systems, in collaboration with the RSA Conference published a survey titled: The State of Cyber Security: Implications for 2015.

The survey found that while boards of directors are now including cyber security on their agendas security still isn't where it should be. The survey also revealed that despite organization's anticipating attacks there is a lack of sufficiently trained talent available to fill security positions.

According to Eddie Schwartz, who chairs ISACA's Cyber Security Task Force, only about 25 percent of applicants had the requisite skills to fill open security positions. Schwartz told Security Current's Vic Wheatman about the survey, and security certifications ISACA is rolling out to meet the growing need for skilled cyber security professionals.

The study based on the survey is available here

View Details

Is there room for yet another endpoint protection product in a market crowded with alternatives?

SentinelOne says there is and that they are reinventing endpoint protection with an aim to replace antivirus within the enterprise. In this sponsored podcast SentinelOne explains its approach to protecting against advanced persistent threats (APTs) and zero-day attacks while also providing forensics. Tomer Weingarten, co-founder and CEO of SentinelOne, explains to Security Current's Vic Wheatman just how the startup combines behavior detection with cloud intelligence and whitelisting to block, detect and predict attacks.

View Details

The percentage of the IT budget allocated to security is increasing. In fact, it is growing at a faster rate than the overall IT budget. But what about staffing? Security departments have too many consoles to manage, and have too many false positives to consider. In this podcast recorded on one of the shuttle buses at RSA, Security Current's Vic Wheatman speaks with Greg Young, Vice President and Research Director for Gartner, who offers specific advice for both CISOs and the vendors who sell to them, about these trends.

View Details

Some 2.5 billion emails containing malware were sent in 2014. Malware URLs are on the rise. Phishing URLs are on the rise. And according to CYREN's 2015 Cyber Threats Yearbook it doesn't appear that attackers will be letting up any time soon.

The CYREN report, which analyzed 5 trillion Internet transactions, found that while high-profile breaches like Home Depot and Sony made headlines, attackers have set their sights on enterprises of all sizes and notoriety. No organization is immune. It also found that BYOD, consumer grade products, are creating new vulnerabilities in the enterprise. 

Knowing the threat sources and how armies of botnet machines are being spawned to spread malware is key to building effective defensive strategies. 

In this sponsored podcast, Security Current's Vic Wheatman speaks with Lior Kohavi, CYREN's Chief Technology Officer. They discuss the reports findings and how cloud-based security solutions are being use to predict and subsequently mitigate against attacks.

View Details

More than 90 percent of enterprise security problems are reportedly caused by malicious email. The number of corporate spear phishing attacks is growing. It isn’t a matter of if an employee will click on a malicious email, voicemail, or efax etc. but a matter of when.

Blocking, detecting and responding to phishing, spear phishing and other email-based attacks is now a fundamental enterprise security requirement. And looming large on the horizon are attacks launched via social media. In fact, according to security vendor Proofpoint, last year 1 out of every 5 large enterprise brands on Twitter with an apparent account did not actually belong to the brand.

In this sponsored podcast Security Current’s Vic Wheatman speaks with Kevin Epstein, Vice President of Advanced Security and Governance with Proofpoint about combatting today’s advanced targeted attacks.

View Details

2015 has been dubbed the year of the security start-up and competition has never been greater. How do Chief Information Security Officers (CISOs) who are responsible for the security of their enterprises identify cutting edge technologies?  And how do the start-ups rise above the tide? 

Security Current is launching its inaugural Security Shark Tank during the upcoming RSA Conference. The Security Shark Tank offers CISOs the opportunity to hear from today's cutting edge security start-ups and allows the start-ups to swim with the sharks . 

One sponsor of the upcoming Security Shark Tank is Tempered Networks. Led by Jeff Hussey, Tempered Networks co-founder and CEO, the Seattle-based company aims to address a fundamental security vulnerability in TCP/IP to ensure secure connectivity for business critical information and infrastructure. A serial entrepreneur with a focus on security, Hussey previously founded F5.

In this sponsored podcast with Security Current's Vic Wheatman, Hussey discusses how his company's approach differs from other solutions, such as firewalls and encrypted links, and why the Security Sharks should select Tempered Networks to secure their environments.

For more on the Security Shark Tank visit www.securitysharktank.com

View Details

How big a market is Security Analytics? If you ask our guest, Gartner Research VP Dr. Anton Chuvakin you'll hear that there actually is no specific or defined market called Security Analytics. He says that while there are technology providers offering products or services so labeled they all do somewhat different things in different ways. 

There are vendors who look at packets, others that look at logs or roles and those that look at malware among other things and they all carry a label of analytics but according to Dr. Chuvakin the fact that all of the vendors do different things indicates that there is no market that you can just go to and buy a security analytics product. 

Organizations need to self define what they want to analyze and then assemble the required pieces and perhaps integrate with a Security Information and Event Management (SIEM) system, which is in some cases is essential for aspects of security analytics to work.

In any case, the buy versus build discussion becomes much more than binary. Dr. Chuvakin explores this largely undefined territory with Security Current's Vic Wheatman.

View Details

Five-time CISO Jeff Klaben, who is currently at a Silicon Valley think tank and also is an adjunct professor, says there is a shortage of skilled security professionals, especially at the management level, to combat an increasingly complex enterprise attack surface.

Klaben was exploring the connection between cyber security education, threat intelligence and incident response. He told Security Current's Vic Wheatman that the aim was to create actionable intelligence but the question remained, "how do we prepare folks to leverage these tools and capabilities?"

He said education and particularly mentoring within an organization would be integral to a successful security program and encouraged CISOs to mentor up and coming security professionals within. Klaben also called on CISOs to work with security start-up vendors to, at the very minimum, provide them feedback so as to ensure they are developing cutting edge technologies. 

He was speaking at the Security Innovation Network's (SINET) Conference at the Computer History Museum in Mountain View California.

View Details

Imagine a future when cars are no longer controlled by the driver.

With automatically controlled cars coming "just around the corner" and with more automation features being introduced there are concerns that vehicles might be vulnerable to security attacks.

But advancements in connectivity and automation need to keep pace with market needs. Automation may be able to make a dent in the 33 thousand annual road fatalities.

So what should be the relative roles of government and industry? Should the automobile companies collaborate on security and are they doing it already?

Security Current's Vic Wheatman spoke with Dr. Peter Sweatman, Director of the University of Michigan's Transportation Research Institute, about the self-driving car. The podcast was recorded at SINET, the Security Innovation Network's recent conference in Mountain View, California.

View Details

Monitoring new cloud environments for adequate security is challenging, particularly when trying to determine which approach might be best.

Most Managed Security Service Providers (MSSPs), while "out there" in someone else's data center, are not operating from the cloud and are not necessarily the right choice for monitoring the security of cloud instances.

Organizations have a responsibility to manage the relationship when MSSPs are used or money could be wasted.

Emerging between the enterprise and the cloud are Cloud Access Security Brokers or CASBs. These topics are explored in this discussion between Security Current's Vic Wheatman and Gartner Research Vice President Dr. Anton Chuvakin.

View Details

Scanning a network, devices or applications for security vulnerabilities may not tell the whole story or even tell the true story. IP addresses and host names are a moving target, constantly changing. This leads to frustration and potentially remediation of the wrong assets while broken assets may remain unevaluated and vulnerable. And the problem is worse as organizations use cloud environments. In this sponsored podcast, Security Current's Vic Wheatman speaks with security expert Tom Desot, CIO of Digital Defense Inc., who talks about the problem and offers ways to mitigate.

View Details

Some research suggests that 97 percent of organizations are already compromised, according to former Gartner analyst Eric Ouellet. And according to Ouellet the hackers are smarter and more persistent than ever, often having a better understanding of an organization's particular computing environment better than its owners.

Recorded on the streets of San Francisco with Security Current's Vic Wheatman, Ouellet who is currently VP of Strategy for Bay Dynamics says that hackers will find a way to get inside an organization's network even if it takes a long time. There is only so much you can do to protect your environment, Ouellet adds and points to credit card companies use of anomalous behaviors as where the industry needs to head to mitigate attacks. 

View Details

The recent US Presidential Directive along with White House statements on cybersecurity have brought new energy to law enforcement approaches against cybercrime. 

Sharing threat data within the public and private partnership is becoming increasingly important as work continues to mitigate security breaches.

In this podcast, Security Current's Vic Wheatman speaks with FBI Assistant Special Agent in Charge for San Francisco's Cyber Division Malcomb Palmore about the evolution of cyber threats, cyber terrorism, industrial espionage and the FBI's focus.

View Details

You wouldn't think that innovation and city government go hand in hand but in The City of San Diego that is precisely the case. 

In this conversation with Vic Wheatman, the city's CISO Gary Hayslip discusses how the City of San Diego embraces cutting edge technology, working with early stage security startups.

With 41 departments and 400 applications under his purview, Hayslip discussed how by its very nature and data it retains the city is under constant threat.

He discusses how he is dealing with legacy systems that are "duct taped" to newer applications in an environment that is increasingly using cloud services to cope with its security requirements. 

And he relays the top three security issues that keep him up at night.

View Details

There's a desire to "get back" at infrastructure attackers through offensive deception techniques. Products are just emerging designed to lead the bad guys into worthless, time-wasting activities to minimize the damage they can cause. But there are risks to existing business processes and partner relationships, suggesting a cautionary approach.

Security Current's Vic Wheatman speaks with Lawrence Pingree, Research Director at Gartner, Inc. about this new class of tools for cyberspace defense.

View Details

The aviation industry is a pillar of critical infrastructure and the industry is very complicated. It has cargo, passenger, military and leisure components with an overlay of complex communications systems. Networks connect all of the information yet airlines and their networks are independent. There are potential vulnerabilities that can be exploited by people intending to do harm. 

What agencies are responsible for securing air travel? Security Current's Vic Wheatman speaks with attorney Lawrence Dietz, General Counsel and Managing Director of Information Security at TAL Corporation talks about who is responsible for aviation security from a cyber perspective.

View Details

LabMD processes medical specimens. One day, a security services company emailed them advising that its patented searching software, which looks for problems caused by peer-to-peer applications, found a file with sensitive information.

The security company offered its services at $475 an hour in what was interpreted as a shakedown. LabMD refused to play and refused to pay, choosing to mitigate the problem themselves. 

The security company turned over its finding to the Federal Trade Commission (FTC) leading to a multi-year, resource-draining battle by LabMD to try prove that they did nothing wrong. 

Security Current's Vic Wheatman spoke with LabMD's CEO Mike Daugherty, author of The Devil Inside the Beltway: The Shocking Expose of the US Government's Surveillance and Overreach into Cybersecurity, Medicine and Small Business. Daugherty talks about taking on a government bureaucracy over matters of principle. 

Also, read Security Current's Richard Stiennon's review of Daugherty's book.

View Details

With Bring Your Own Device (BYOD) increasing in the workplace, the question arises of employer and employee rights governing the use of these employee-owned tablets, laptops, smartphones and other personal devices. What are the rights when these devices are used for work-related activities?

How do you balance productivity and the protection of corporate intellectual property? How does labor law factor into the discussion? securitycurrent's Vic Wheatman speaks with Lawrence Dietz, JD, General Counsel and Managing Director of Information Security at TAL Global Corporation on these issues. 

View Details

There is a shortage of operational security professionals, with approximately 100,000 open positions seeking technically qualified people. Supporting education in STEM, sourcing ex-military and promoting people from the ranks of general information technology are some of the ways the market is working to fill the gap.

securitycurrent's Vic Wheatman speaks with John Pescatore, securitycurrent's Ask Mr. Security Answer Person and the SANS Institute Director of Emerging Security Trends about the pressing nature of the problem. 

View Details

It takes a village to build a secure world. Privacy and security are intertwined. But approaches in America are subtly different than approaches taken in Europe. Americans often approach security from an infrastructure perspective while Europeans focus on privacy. 

Do terrorists win if you don't buy a firewall? What is the role of Fear, Uncertainty and Doubt (FUD)? securitycurrent's Vic Wheatman speaks with Johannes Lintzen of Germany-based Utimaco about the different ways information security has evolved around the world. 

View Details

With the increase in APIs, and in particular usage with REST-based architecture, developers need to rethink how they secure them. So what should CISOs know about securely developing new mobile, Internet of Things (IoT) or cloud-based applications?

There are multiple security components to consider including new authentication mechanisms, link protection and hardening systems against vulnerabilities.

securitycurrent's Vic Wheatman speaks with Roberto Medrano, Executive Vice President for SOA Software, about this emerging space. 

View Details

As the Internet of Things (IoT) evolves security is often an afterthought. One of the greatest challenges facing IoT project teams is ensuring the communications links are secure.

securitycurrent's Vic Wheatman speaks with PubNub CEO Todd Greene on the challenges of securing the IoT. Greene outlines use cases where enterprises as diverse as Coca Cola, Nike, McDonalds and Dodge are using secure data communications for a variety of IoT applications.The podcast was recorded at the Internet of Things Expo produced by Sys-Con Events in Santa Clara, California.

View Details

Whatever happened to public key infrastructure (PKI)? Despite rumors of its demise, PKI is not dead! However, it has essentially disappeared into the applications, processes and products it is now protecting.

The current iteration of PKI is being used to protect devices on the IoT. securitycurrent's Vic Wheatman speaks with Johannes Lintzen, a security expert at Utimaco Inc., about the evolution of PKI in a world where IP is everything. This podcast was recorded at the Internet of Things Expo produced by Sys-Con Events held in November in Santa Clara, California. 

View Details

How does a CISO approach the special security and privacy issues involved in a medical setting as the Internet of Things moves forward? Jeff Misrahi, CISO of AdvantageCare Physicians, a multi-specialty physician practice delivering comprehensive, community-based care throughout the New York metropolitan area, discusses this topic with securitycurrent's Vic Wheatman.

Misrahi also describes best practices on transmitting data,  wireless devices, how security should ideally be approached in a distributed enterprise and where he fits in the organizational structure.

View Details

Who should the CISO report to in the organization? How can CISOs who are at competing organizations share information security without tension? And what is the relationship between risk, compliance and information security? 

In part two of our interview with Steve Katz, recognized as the first CISO, Vic Wheatman discusses these and other issues. 

View Details

Steve Katz, credited with being the first Chief Information Security Officer (CISO), sets the record straight on that honorific. He talks about what it was like being the first CISO, jesting that he slept like a baby, getting up every two hours and crying.

In the first of a two part interview, Katz tells securitycurrent's Vic Wheatman how he sees the role of CISO, suggests a new title for it and proposes a process whereby business units would be required - in writing - to accept responsibility should they take risks that the CISO advises against. Katz now advises Deloitte in security and privacy and heads up Security Risk Solutions LLC.

View Details

Embedded systems, the Internet of Things and security. What do these three things have in common?Once in use industrial, medical, avionics and other systems typically don't get upgraded, but they need to operate in a safe and trusted manner. But in the world of the Internet of Things where new, creative offerings are quickly hitting the market, security often is just an afterthought. 

securitycurrent's Vic Wheatman speaks with Senior Technical Marketing Engineer Roman Romaniuk of Wind River, a provider a of secure operating systems that are also in use on the planet Mars as you'll in hear in this podcast. The podcast was conducted at the Gigaom Structure Connect conference in San Francisco.

View Details

The drumbeat of breaches -- Home Depot, Target, Jimmy John's and the list goes one -- continues almost daily. Why is this the case? It doesn't appear to be a lack of security investment or governance.

As you'll hear from one former Gartner analyst who has 'gone over to the dark side,' a key problem is that individual security functions largely exist in isolated silos. Eric Ouellet, who is now VP of Strategy at Bay Dynamics, says this approach leads to data overload for security analysts causing fatigue and subsequently inadequate responses to attacks.

Ouellet tells securitycurrent's Vic Wheatman that traditional approaches have flaws and generally lack the correlation of threat information from one silo to the rest, which would support holistic responses.

View Details

Threat Intelligence is more than just a list of bad actors' IP addresses. The best sources of it tend to come from the more mature and 'enlightened' providers who employ a substantial number of security analysts who can evaluate the nature of the threats.

In fact, some are able to drill down not only to specific groups of threat actors or countries that may be after an organization but to the specific people who may be out to get them as well. But how do most organizations use this information and what kind of threat intelligence would help you the most? securitycurrent's Vic Wheatman discusses these topics with Gartner Research Vice President Dr. Anton Chuvakin.

View Details

Data Loss Prevention (DLP) solutions help keep private data private. Using various rules based on certain policies, sensitive information can be prevented from being exfiltrated. But CISOs are walking a fine line. They must be careful not to inhibit user and business processes lest there be dire business consequences.

securitycurrent's Vic Wheatman speaks with ex-Gartner analyst Eric Ouellet, who is now Vice President of Strategy at Bay Dynamics, about how DLP actually works and where it can be used.

View Details

It is often law enforcement that finds evidence of a security breach first. Being able to respond effectively to breaches can reflect on an organization's reputation. There is always malware running somewhere. Some enterprises have Security Response Teams, but many do not. If it is a one-man shop should they be a 'doer' or a 'coordinator?' If it is a large team, how should it be structured? What is the role of third parties and can open source tools be used? 

securitycurrent's Vic Wheatman speaks with Gartner Research Vice President Dr. Anton Chuvakin on this business critical issue.

View Details

Malware in its various forms has been around since the start of the computing age, but one platform remains more susceptible to evil code than others with more than 1 million new unique virus  signatures discovered each and every day, according to F-Secure.

Also according to F-Secure's Threat Strategist David Perry, it is "primarily a Windows world attribute." However, the concerns are shifting with the proliferation of mobile. And just as the Internet offers little native security, it also does not respect privacy.

In this entertaining and humorous exchanged recorded at Black Hat, securitycurrent's Vic Wheatman and David Perry discuss these and other issues.

View Details

Honeypots, used to detect cyber attacks, have been around information security for a long time.

The non-profit Honeynet Project is dedicated to investigating the latest attacks and working to improve the utility of honeypots in today's changing network environment.

In this podcast Vic Wheatman speaks with Gartner VP of Research Dr. Anton Chuvakin about this sticky issue. They look at the benefits of Low-interaction honeypots, which simulate only the services frequently requested by attackers, versus High-interaction honeypots that imitate the activities of the production systems that host a variety of services, and, therefore, an attacker may be allowed a lot of services to waste time.

View Details

Why should a commercial entity consider a defense contractor for security projects?Answering the question is Edward Hammersla, President of Raytheon's Trusted Computer Solutions, Inc.

Mr. Hammersla provides perspective on the role of trusted operating systems, the ways of protecting data in a highly sensitive bring your own device (BYOD) environment and the appeal of using the term "cyber" in describing today's approaches to information security. Mr. Hammersla was speaking with securitycurrent's Vic Wheatman.     

View Details

Black Hat Series

There are a multitude of threat data sources used by Intrusion Prevention Systems (IPS) and anti-malware products to strengthen enterprise protections. Differentiating in this competitive almost commodity service market is a matter of numbers.

securitycurrent's Vic Wheatman speaks with Jeff Harrell, Sr. Director of Product Marketing for Norse, a threat intelligence company that offers an appliance it says is designed to detect and defend against attacks from "darknets" as well as other Internet-based attacks. They talk about this saturated market and Harrell discusses the x-ray machine that was used to verify the validity of stolen credit cards.

View Details

YALE NEW HAVEN HEALTH SYSTEM CASE STUDY

With an increase in cyber attacks across industries, and in particular healthcare with medical-related identity theft accounting for 43 percent of all identity thefts reported in the United States last year according to the Identity Theft Resource Center, managing risk has never been more pressing for organizations.

With risk growing daily and the consequences -- both in terms of data loss, patient and employee confidence and potential fines -- looming large, one healthcare organization that takes cyber security seriously is Yale New Haven Health System.

Steve Bartolotta, who heads the health system's information security and risk management program talks about the challenges facing organizations today across verticals and what measures he recommends taking. 

In this podcast with securitycurrent's Vic Wheatman, Bartolotta talks about the actual tools he uses to support Yale New Haven's risk management system and what he has gained. 

View Details

BLACK HAT SERIES 2014

Hackers continue to go after the easiest target -- the branch or remote office be it a gas station, retail store, bank branch, local health clinic or the like.

Armed with the knowledge that organizations are increasingly distributed and most organizations' budgets are allocated to headquarters, a branch or remote office often provides an easy access point for attackers.

Vic Wheatman speaks at Black Hat with Dave Porcello, CTO and founder of Pwnie Express about what kinds of attack the organization should actually be concerned about.

Is it the advanced persistent threat or is it that unknown rogue access point? As you'll hear from Porcello, your organization may have unbelievable security 99 percent of the time but it's that one computer, or air conditioning duct, that often opens the door.

View Details

BLACK HAT SERIES

Purpose-built, specialized malware dubbed "Backoff" is being found in point-of-sales (POS) systems. At the discovery, the malware, which is gathering magnetic strip information, keyed data and more, had low to zero percent anti-virus detection rates. That meant that fully updated anti-virus engines on fully patched computers could not identify malware as malicious, according to the National Cybersecurity and Communications Integration Center (NCCIC), US Secret Service (USSS), Financial Sector Information and Sharing and Analysis Center (FS-ISAC), and Trustwave SpiderLabs.

Meanwhile, exploit kits enabling ransomware are holding data hostage. These business models for criminals are proving to be very lucrative. securitycurrent's Vic Wheatman speaks with Karl Sigler, Manager SpiderLabs Threat Intelligence at Trustwave, on "Backoff" and the latest findings from Trustwave's Global Security Report.

View Details

BLACK HAT SERIES 2014

IBM's Security Systems X-Force recommends that a shift takes place from focusing on protecting the perimeter to  securing applications.

The X-Force publishes a Threat Quarterly Report that analyzes security breaches and methods used by the bad guys. Based on over one million data points, the report found that Java, SQL injections, cross-site scripting and authentication problems remain challenges for developers and recommends they adopt Secure Lifecycle Development to reduce system vulnerabilities.

At Black Hat in Las Vegas, securitycurrent's Vic Wheatman spoke with Michael Hamelin, the Lead X-Force Security Architect on today's most prevalent forms of attack and what should be done.

View Details

A recent movie shows what happens when a private video goes "up into the cloud" for everyone to see. 

The movie is called "Sex Tape." A memorable refrain from one of the characters in the movie is "Nobody Understands the Cloud."

securitycurrent's Vic Wheatman speaks with cloud expert JD Sherry of Trend Micro about the controls and protective services organizations should implement to protect their cloud-based applications.

Sherry, Trend Micro's VP of Technology and Solutions, notes that by 2014 some 51 percent of workloads will be processed in the cloud, pointing out that organizations are seeing the benefits of the adoption of these huge cloud-based services.

The also examine the importance of security and privacy and note real-world instances of just what can happen in a cloud ecosystem. 

View Details

An upcoming movie shows what happens when a private video goes "up into the cloud" for everyone to see. 

The movie is called "Sex Tape." A memorable refrain from one of the characters is "Nobody Understands the Cloud."

securitycurrent's Vic Wheatman speaks with cloud expert JD Sherry of Trend Micro about the responsibilities of the cloud service provider and the controls and protective services organizations should implement to protect their cloud-based applications.

Sherry, Trend Micro's VP of Technology and Solutions, notes that by 2014 some 51 percent of workloads will be processed in the cloud, pointing out that organizations are see the benefits of the adoption of these huge cloud-based services.

And they examine the importance of security and privacy and note real-world instances of just what can happen in a cloud ecosystem. 

View Details

Security analysts and experts often talk about big data security analytics as a burgeoning space. But is that the really the case?

What is reality behind big data analytics for security? Is it mainstream? Does a security analytics market even exist? 

securitycurrent's Aimee Rhodes speaks with Gartner Research Vice President Anton Chuvakin who researched big data security analytics to find out what it is good for, where it is heading, who is using it, who isn't using it and who should be using it. 

View Details

Many consumer-facing e-commerce implementations depend on 1960s technology to identify and authenticate customers. SecureKey is bringing authentication down to the device and chip level in order to combat fraud. It also is working to share digital IDs across an Identity Federation.

securitycurrent's Vic Wheatman speak with SecureKey's CEO Charles Walton who talks about these timely issues.

View Details

What are intelligence security controls? Intelligence sharing domains? Shared response infrastructure? Are they just information security buzz words or do they have actionable meaning?

securitycurrent's Vic Wheatman speaks with Gartner Research Director Lawrence Pingree about these concepts and their usefulness as part of an information security program. 

View Details

From email to texting and other forms of social media, the need for protected communications underscores the requirement to continue encrypted messaging development. 

Despite legacy and current solutions on this matter, academic and private research continues in an effort to apply encryption to solving new business problems in numerous contexts. 

securitycurrent's Vic Wheatman speaks with Voltage's Chief Technology Officer Terrence Spies about the continuing evolution of secure messaging. 

View Details

Does the Payment Card Industry Data Security Standard (PCI DSS), now in its 3rd version, actually increase safeguards required to be taken by enterprises to ensure customer data?

According to the PCI Security Standards Council, PCI DSS is a comprehensive standard "intended to help organizations proactively protect customer account data."

But with the continuous news of breaches, is it successful? Is being compliant for an audit, essentially a snapshot in time, enough or has the latest version succeeded in bolstering security over the long haul?

securitycurrent's Aimee Rhodes speaks with Gartner Research Vice President Anton Chuvakin, who has spoken with the Standards Council, on the changes in the latest version, how the standard has made real progress in fostering security and what to look forward to in the future with mobile processing.

View Details

What are use cases for security tools for protecting information in the cloud?

What organizational changes can trigger an enterprise to adopt additional cloud-based protection?

We are increasingly seeing a growth in cloud security providers offering tools to protect information and retain control of data.

securitycurrent's Vic Wheatman speaks with CipherCloud's Chief Trust Officer Bob West about what we can expect to see in the growing field of cloud security.

View Details

The Security Innovation Network (SINET) this week held its annual IT Security Entrepreneurs Forum in Silicon Valley. 

There, connections were made among early stage security companies, investors, lawyers, regulators, educators and others.

securitycurrent's Vic Wheatman spoke with SINET Chairman and Founder Robert Rodriguez who talks about the goals of the conference and gives its flavor also looks at the role emerging companies take in combatting proliferating security threats.

View Details

How valuable is data visualization in spotting patterns on attacks on individuals, institutions or locations? 

Understanding what is going on in this realm can help organizations protect themselves against organized cyber criminals, rogue intelligence agencies (or not so rogue possibly), and malevolent nation states. securitycurrent's Vic Wheatman speaks with Mike Horn, Co-founder and CEO of NetCitadel, a security incident response vendor about this and other issues.

View Details

The Ability to See All the Things: Vulnerability Assessment and Pentesting.

What security vulnerabilities are you not seeing in your remote facilities or branch offices? Are you the next Target?

Dubbed a hack-in-the-box, Pwnie Express leverages the same open source tools used by hackers to provide enterprises visibility and the ability to assess vulnerabilities across their networks, both wired and wireless. 

Victor Wheatman speaks with Pwnie Express CEO Paul Paget on the importance of consistent vulnerability assessment and penetration testing across the enterprise. 

View Details

What is tokenization? How does tokenization compare to encryption and format preserving encryption?

Are there performance issues regarding its use?

Is it standardized so one solution can exchange tokens with a different implementation?

Vic Wheatman talks to Voltage CTO Terrence Spies who urges enterprises to look at their infrastructures, take inventories of what pieces of data they are storing and what could be breached, and then catalogue them as they are the potential candidates for tokenization.

View Details

Security and the Internet of (Every)Thing.

How are data and communications going to be protected as CPUs and Near Field Communication chips become less expensive and are embedded in to the Internet of (Every)Thing?

What are some of the leading edge indicators and social trends that will drive the need?

securitycurrent's Vic Wheatman speaks with Mocana CEO James Isaacs and John Aisien, Senior Vice President Marketing and Corporate Development while at the RSA security conference.

View Details

Security and the Internet of Things.

How are data and communictions going to be protected as CPUs and Near Field Communications chips become less expensive and are imbedded in to the Internet of (Every) Thing? 

What are some of the leading edge indicators and social trends that will drive the need?securitycurrent's Vic Wheatman speaks with James Isaacs, CEO of Mocana, and John Aisien, Senior Vice President Marketing and Corporate Development at the RSA security conference.

View Details

Threat Intelligence -- What is it? Who provides it? What should you do with it? securitycurrent's Vic Wheatman speaks at the RSA conference with Pete Lindstrom of Spire Security on this central topic in information security. 

View Details

A soon to be released survey conducted by cloud security automation provider Hytrust found that consumers believe corporations don't really care about protecting consumer data. Yet companies are increasingly moving to the cloud, causing a concentration of risk. securitycurrent's Vic Wheatman speaks with Hytrust's Co-founder and President Eric Chiu about improving trust and what comes after cloud.

View Details

Security from the top? What does a c-level executive at an organization need to know about information security given today's security trends? Join trend Micro's JD Sherry, VP of Technology and Solutions, and Rik Ferguson, VP of Security Research as they discuss third party risk, PCI compliance, cyber insurance and the Dark Web with securitycurrent's Vic Wheatman.

View Details

Victor Wheatman speaks with leading security analysts David Monahan, Research Director for the Security and Risk Management Group at Enterprise Management Associates, and Edward S. Ferrara, Principal Analyst serving security and risk professionals with Forerster Research.  They discuss the state of security in the banking industry after attending Symantec's 2014 CyberWar Games. They commented on the actual games, which included some 40 of Symantec's best and brightest who attacked a mock bank both logically and physically. Hear what they learned.

View Details

Analyst and securitycurrent's senior editor Victor Wheatman speaks with Gartner security and privacy analyst Lawrence Pingree on the calls by some security experts to boycott the RSA 2014 conference over the reported NSA revelations. 

It began with a Reuters story from Joe Menn: Exclusive: "Secret contract tied NSA and security industry pioneer." The report disclosed that RSA, the crypto pioneer and security products vendor, had allegedly accepted a secret $10 million payment from the NSA in order to incorporate a backdoor in to their BSafe crypto suite. 

Hear their take.