News, views and stories from the cyber front line.
Sponsored by Netswitch Technology Management - https://www.netswitch.net/
Stanley Li speaks with veteran security executive Steve Maciejewski (aka “Steve Mack”) to unpack the harsh realities and hopeful opportunities of managing cyber risk in today’s complex digital landscape.
Drawing from decades of experience as a CISO across public and private sectors, Steve explains why traditional compliance checklists and siloed toolsets aren’t enough. Together, they explore the cultural and operational shifts needed to move from reactive security to proactive, risk-informed governance.
“Everyone has reports and dashboards, but most can’t explain
how a breach would truly impact operations,” he said. “You need more
than a SOC report or a compliance checklist. You need a business-driven
risk view.”
Listen to Learn:
Whether you’re leading security for a fast-growing startup or a nonprofit, this conversation will deliver real-world strategies to shift your organization from cyber risk firefighting to sustainable, data-driven cyber risk governance.
Mentioned in this episode:
Podcast Outro Bumper
On the latest episode, hear a discussion about cyber risk management needing to look beyond IT.
The hosts, Stanley Lee and Sean Mahoney, explore the complexities of cybersecurity, emphasizing the importance of understanding cyber risks that extend beyond traditional IT frameworks.
They highlight the critical role of employee awareness and the need for organizations to adapt their security measures in response to evolving threats.
Mentioned in this episode:
Podcast Outro Bumper
In this eye-opening episode of Cybersecurity Chronicles, we tackle a critical challenge facing executives today: the devastating impact of cyberattack downtime. Join Netswitch's VP Sean Mahoney, CFO Bernard Mendoza, and cyber resilience expert Steve Piggott as they move beyond "compliance theatre" to discuss why automated disaster recovery (DR) isn't just a good idea – it's essential for your business's survival and future.
Drawing on real-world examples of crippling ransomware attacks, they break down the immense financial and operational costs of extended downtime, from lost revenue and unexpected expenses to damaged brand reputation and customer churn. Bernard Mendoza shares the stark reality of budgeting for unpredictable recovery costs, while Sean Mahoney recounts a personal survival story highlighting the chaos and expense of manual recovery efforts.
Steve Piggott introduces the power of automated DR, explaining how platforms like Continuity Patrol can drastically reduce recovery times from days or weeks to minutes. Learn how automation frees up valuable IT resources for strategic work and provides the confidence needed for rapid, effective recovery. The discussion also covers how automated DR supports regulatory compliance and instills confidence in investors and boards.
Tune in to understand why investing in automated disaster recovery is a proactive, strategic move that can protect your bottom line, your brand, and your competitive edge in today's volatile cyber landscape.
Mentioned in this episode:
Podcast Outro Bumper
In this episode of Cybersecurity Chronicles, host Sean Mahoney sits down with quantum computing expert John O’Malley to talk about the world of quantum computing.
John worked with the NIST Post Quantum Encryption Standards Committee, after having previously led Change Healthcare's Identity and Access Management (before the breach).
They delve into the current state of quantum technology, its potential applications in various industries, and the challenges that lie ahead. From cybersecurity advancements to the future integration of quantum computing in everyday business operations, this conversation provides a comprehensive overview of how quantum computing is set to revolutionize the tech landscape.
The topic was chosen following the recent NIST release of the long-awaited post-quantum encryption standards.
Key Takeaways:
Mentioned in this episode:
Podcast Outro Bumper
Sean Mahoney of Netswitch is joined by Wil Lassalle, of JLS, Tech to talk about a headline story and share some insights about preventing a similar event from occurring for your SMB.
The guys explore why small businesses are more susceptible to cyberattacks than larger corporations. They talk about the perception among cybercriminals that small businesses have weaker defenses and are easier targets. Additionally, they discuss the potential unfairness of the current system, where large corporations face lighter consequences (like fines) for data breaches despite causing significant financial losses.
Learn WHY:
Sean Mahoney, VP Netswitch, Inc.
Will Lassalle, vCISO JLS, Tech
Learn more about Security And Risk Assessments from Netswitch, Inc.
Mentioned in this episode:
Podcast Outro Bumper
In this episode, Will Lassalle, co-founder of Simplex, a platform designed to assist businesses in complying with cyber regulations in Latin America, discusses the challenges and opportunities surrounding cyber compliance in the region.
We then delve into the evolving cyber regulatory landscape in Latin America, highlighting the region's efforts to catch up with global data privacy laws and cyber regulations.
We emphasize the pressing need for businesses to enhance their cyber hygiene and mitigate the risks associated with breaches and ransomware attacks, particularly for those working with US or European companies that must adhere to their stringent requirements.
Host: Sean Mahoney, VP Netswitch, Inc.
Guest: Will Lassalle, Founder Simplix.io
Mentioned in this episode:
Podcast Outro Bumper
In this episode, we discuss the importance of cyber resilience and business continuity planning for businesses in Latin America. The key points covered include:
We share the secrets of how to invest in cyber resilience to enable innovation, improve efficiency and become a stronger competitive company.
Mentioned in this episode:
Podcast Outro Bumper
In this episode of the Cybersecurity Chronicles, Sean Mahoney with Netswitch, and Tamara Lauterback, Sr. Cybersecurity and GRC Analyst with Guthrie discuss the evolution of cyber risk, focusing on the concept of insider threat.
They explore how seemingly innocent actions can pose significant risks in the digital landscape. The conversation also touches on the role of AI and machine learning in shaping modern threats, the importance of continuous cybersecurity education, and the challenges of maintaining security in a rapidly advancing technological environment.
Mentioned in this episode:
Podcast Outro Bumper
In this episode of the Cyber Security Chronicles, join Sean Mahoney, Stanley Li, CEO and Founder of Netswitch, and special guest Tamara Lauterbach, a senior Cybersecurity & GRC Analyst at Guthrie.
Tamara shares her unique journey from the technical side of cybersecurity to the Governance, Risk Management, and Compliance (GRC) side. She discusses her early career in a Security Operations Center (SOC), where she developed a passion for insider threat analysis. This led her to transition into the GRC field, where she found her skills and experience were highly applicable.
The conversation covers the importance of acceptable use policies, the need for continuous education and awareness in cybersecurity, and the role of GRC in managing cyber risk.
This episode provides valuable insights for anyone interested in the intersection of technical cybersecurity and GRC.
Tune in to learn more about the evolving landscape of cybersecurity and the crucial role of GRC in protecting organizations. Don’t miss out on this enlightening discussion!
Mentioned in this episode:
Podcast Outro Bumper
Sean Mahoney and Will Lassalle catch up on the current state of cybersecurity, recent data breaches, the impact of regulations, and where opportunities for the future seem to be regarding compliance and cyber risk.
Mentioned in this episode:
Podcast Outro Bumper
Proactively Defend Against the Onslaught of Cybercrime by Fortifying Your Defenses with Cyber Risk Assessment and Insurance
The rise of cybercrime poses an increasing challenge for all levels of education. Criminals are constantly adapting their tactics to target faculty, staff, students, and alumni. With the surge in payloadless malware, business email compromise, and various email-based attacks, safeguarding your institution from these threats is now of paramount significance.
Cyber Insurance may be the last line of defense for many organizations, but in education, it may be the first line due to the limited resources of educational institutions.
Listen to Sean Mahoney and Stanley Li talk with Jake Charen, (Risk Architect at Lakeside
Insurance) about the risks in educational organizations, how to cost-effectively mitigate those risks and learn ways to reduce your ever-increasing cyber liability premiums.
Mentioned in this episode:
Podcast Outro Bumper
The various T-Mobile data breaches serve as a stark reminder of the critical importance of supply chain security in today's interconnected business landscape.
While the incident primarily affected a global telecommunications company, the lessons derived from this breach can be invaluable for small and medium-sized enterprises (SMEs) as they strive to become secure supply chain partners.
By understanding and implementing key lessons, SMEs can strengthen their security measures, safeguard sensitive information, and foster trust among their partners and customers.
Will Lassalle and Sean Mahoney share some important insights and offer valuable solutions for executives to look into and see how they may fit into their organizations.
Mentioned in this episode:
Podcast Outro Bumper
There's no escaping cyber risks these days.
But what can you do to mitigate and transfer them?
Listen to this episode for a Founder-to-Founder conversation as they share their perspectives on cyber risk & protecting their small businesses.
You'll learn about different types of cyber risks, how to assess and protect against them, and some tips for preparing for cyber liability insurance to prevent a cyber incident from destroying your business.
Michael McCarron, Founder & CEO of Lakeside Insurance, and Stanley Li, Founder & CEO of Netswitch Technology Management share their perspectives on the topic.
Michael McCarron and Lakeside's talented risk advisors partner with clients, as trusted risk advisors, they look to help:
✔Manage Risk
✔Mitigate Risk
✔Reduce Total Cost of Risk
To drive mutually profitable growth.
Mentioned in this episode:
Podcast Outro Bumper
Data breaches are becoming more and more common, and they are costly—the average cost of a data breach is now $3.86 million. Regulations and compliance will only increase this cost. Businesses need to take steps to protect themselves, and one way to do this is by purchasing cyber liability insurance. Join Hosts Sean Mahoney and Stanley Li and their guest Jake Charen, Senior Rick Architect of Lakeside Insurance to learn: What is cyber liability insurance? Why should executives consider having a cyber liability? Is it worth the investment? After the Travelers and ICS suit, what is the trend in the insurance industry regarding coverage? How you can reduce your risk of a data breach without cyber liability insurance?
www.netswitch.net
Business today faces the great resignation and migration of employees, and that can be a lot of institutional knowledge about your supply chain leaving. The risk from your vendors grows every day and how do you know which ones are cognizant and which ones are unknowing. Pam Hamingson, Director of Compliance with Fortrex joins Sean Mahoney to talk about Third Party Risk Management [TPRM] and the growing level of risk your supply chain brings. The increasing number of regulations expect you to know about your vendors and their security practices. How do you know what data security your vendors do? What should you do to remain in compliance when they are not? When regulations change, how fast can you update GRC? If your vendors are a cyber risk to you, what can you do?
Risk monitoring solutions that are implemented and maintained by regulatory experts and cyber professionals can help you be assured of your compliance and that you have a secure supply chain. Mentioned in this episode: Podcast Outro Bumper
Tara Trantham joins Sean Mahoney of Netswitch to talk about steps regulated and non-regulated businesses should be and can be doing to ensure they are more secure. Learn steps you can take as an SMB to reduce cyber risk and secure your business’s future. Tara Trantham is CEO & Founder of TJ44 Consulting, they are compliance, risk management, and creditors rights services experts and with Tara’s background as an attorney and General Counsel in the Financial Service sector, you have that important perspective as well when it comes to dealing with compliance in a regulated industry. Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Think about your business and everything that goes into defining who and what you are as that business. Your operations, the people you employ, the people and companies you serve. Your products or services. All the fruits of your labor and the reputation you’ve built. Disasters, like ransomware, wildfires, or pandemics often can’t be predicted but will impact your business and affect your employees and customers. Proper planning can ensure your business is back up and running so it lasts. In this episode, https://www.linkedin.com/in/mahoneysean/ (Sean Mahoney) talks with https://www.linkedin.com/in/roberto-rob-zegarra-3482933/ (Rob Zegarra), Instructor at https://drii.org/ (Disaster Recovery Institute), talk about simple and inexpensive steps you can take to lessen the effects of your next unforeseen disaster.
Sean Mahoney & Stanley Li of Netswitch are joined by special guest Dr. Stylianos Kampakis, CEO of Tesseract Academy to discuss what is data science & why it's making the greatest impact for small and mid-size businesses. Plus, the growing influence of blockchain for data ownership and integrity. To learn more about Dr. Kampakis, visit http://tesseract.academy Sponsored by Netswitch Technology Management - netswitch.net
Doug Kreitzberg is the CEO and Founder of Beehive Cyber and is a Certified Information Privacy Professional / Europe and United States. Doug joins Sean Mahoney of Netswitch to discuss the importance of cyber insurance and how it can help a company survive a ransomware attack, how premiums can be reduced, and what you should do BEFORE you get a cyber insurance quote. Sponsored by Netswitch Technology Management - netswitch.net
In this episode, Sean Mahoney and Stanley Li of Netswitch interview Mary Siero, who is a CISSP/CISM as well as an Instructor with the MIS Training Institute. On the call Sean, Stanley and Mary ask the question: 'Now you've started the path to improve your security and lower your risk, how do you measure success and ROI of your cybersecurity solutions?' Sponsored by Netswitch Technology Management - netswitch.net
In this episode, Sean Mahoney and Stanley Li of Netswitch talk with guest expert Fred Doyle, CISSP - CEO & Founder of CubicPrism to discuss why despite the money poured into cybersecurity, we're less secure than ever. Mr. Doyle has been a Senior Security Architect and is regularly being “sold” on the latest and greatest cybersecurity tools with ever-increasing capabilities, but is there a value to them? Sponsored by Netswitch Technology Management - netswitch.net
In this episode, Sean Mahoney and Stanley Li of Netswitch interview Carter Schoenberg, CISSP - Vice President, and Chief Cybersecurity Officer at SoundWay Consulting to discuss why CMMC, although important and a great advancement from where we are today, is not the silver bullet for making a company completely secure and compliant. There are several other aspects to cyber security and compliance that companies of all sizes need to be aware of and consider as part of their overall strategy. PART 2/2 Sponsored by Netswitch Technology Management - netswitch.net
In this episode, Sean Mahoney and Stanley Li of Netswitch interview Carter Schoenberg, CISSP - Vice President, and Chief Cybersecurity Officer at SoundWay Consulting to discuss why CMMC, although important and a great advancement from where we are today, is not the silver bullet for making a company completely secure and compliant. There are several other aspects to cyber security and compliance that companies of all sizes need to be aware of and consider as part of their overall strategy. (PART 1) Sponsored by Netswitch Technology Management - netswitch.net
In this episode, Sean and Stanley discuss the US Senate's latest abysmal cybersecurity report citing "essentially the same failures" as a decade ago and reveals the one easy step to recover from ransomware... Sponsored by Netswitch Technology Management - netswitch.net
In this episode Amira Armond, the Chief Editor of CMMCaudit.org, joins Sean and Stanley to discuss all about CMMC - the Cybersecurity Maturity Model Certification - and its importance for the entire DoD supply chain. Sponsored by Netswitch Technology Management - netswitch.net
CISO Will Lassalle joins Sean Mahoney to discuss the catastrophic implications of the Kaseya ransomware disaster for 1500 SMBs. Sponsored by Netswitch Technology Management - netswitch.net
In this episode CISO Will Lassalle returns with Sean Mahoney to discuss the latest issues, topics and fallout in the world of Cyber Risk, Governance & Compliance... including the mysterious FBI bitcoin recovery 'heist' Sponsored by Netswitch Technology Management - netswitch.net
In this episode CISO Will Lassalle returns alongside Sean and Stanley to discuss the latest issues, topics and fallout in the world of Cyber Risk, Governance & Compliance... PLUS what Cybersecurity has in common with the Death Star... Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Sean Mahoney and Stanley Li from Netswitch discuss the Colonial Pipeline ransomware attack as well as the implications for critical infrastructure and the B2C supply chain.
Ransomware and nation-state attacks are two of the biggest security threats out there, but what do they mean for you? That's exactly what Stanley Li and Sean Mahoney from Netswitch discuss on this latest episode...
In this episode CISO Don Cox returns alongside Sean and Stanley to discuss why AI and machine learning are so important for CyberRisk management, including: -- Why automation is essential for cybersecurity readiness. -- Why being able to fix problems autonomously is critical. -- The lessons Don's learned from his 25-year background into investigating high-tech crimes. -- Why automation is NOT about replacing employees. Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Stanley Li and Sean Mahoney of Netswitch discuss the TWO most important CyberRisk metrics you need to know and measure - MTTD and MTTR. -- What are MTTD and MTTR and why are they so vital? --Why the R in MTTR should be Resolve not Respond --Case Study of the global hotel group with a 91% reduction in MTTD --The #1 cause of all security incidents --The open-source alternatives to expensive proprietary solutions Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Stanley and Sean of Netswitch are joined by SECEON CEO and SIEM automation expert Chandra Pandey to discuss: -- Why is dynamic machine learning & AI automation so important to security? -- How to cope with the dynamic threat model. -- Why CyberRisk governance is driving the monitoring and reaction to security events. -- How effective security automation software can be made affordable for SMBs. -- Why Chandra's thousands of clients have not had ONE incident of ransomware being paid out. Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
On this episode Stanley Li and Sean Mahoney of Netswitch discuss: -- What is a Business Email Compromise (BEC)? -- The bad & ugly, the bad & fortunate and the right way to handle one. -- The Four steps to take if you think you're a victim of BEC -- Why the supply chain is critical -- what is phishing email simulation -- Plus, Stanley's big confession! Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Stanley Li and Sean Mahoney from Netswitch are joined by guest expert Jeff Westeman CSPC. Jeff is President of Black Anvil, LLC and is a specialist in CMMC for DoD Contractors. They discuss: -- How to make the business case for CMMC compliance -- How to get IT tech and compliance controls in alignment -- Why compliance is a cross-organizational issue, not just a technology one -- How to prepare for vendor selection -- Why you should never use your MSP to do your compliance gap analysis Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Stanley Li and Sean Mahoney discuss what the real implications of the Sunburst attack are for small and mid-size businesses, including: -- How do we get management, risk and tech to collaborate? -- How do you monitor cloud infrastructure and work with multiple third parties? -- How do you integrate different toolsets to monitor the cyber kill chain? -- Why its essential to use behavioral tools like SIEMs and where do you start? -- What exactly is a supply chain attack? -- How 'Are you SOC-2 compliant?' has become the new #1 vendor interview question. Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Special guest expert Blake Strozdas from Pcysys joins Stanley Li and Sean Mahoney to share real-life insights and lessons-learned from conducting automated pentests, including: -- Why Gartner says only 3-5% of vulnerabilities are actually exploitable. -- Why automated pentesting tools are needed to help identify vulnerabilities that have the highest priority. -- If a high-risk vulnerability is discovered, how best-of-breed automation tools will take action to nullify risk but not take down your live network. Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Stanley Li and Sean Mahoney join James Watson to discuss the FireEye hacking incident plus what this means for the average small business in the weeks and months ahead, including: -- What exactly was stolen from FireEye and what does it mean for small business owners? -- Why the FBI has very unusually commented on an ongoing case. -- How simulated testing is on the forefront of cybersecurity. -- What are the typical costs of a cyber protection service? Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Sean Mahoney and Stanley Li from Netswitch along with James Watson discuss everything you need to know about cyber insurance, including: -- What does cyber insurance mean -- Why do you need it? -- Why is it different from every other insurance industry? -- What are the 7 different types of cyber insurance? -- How expensive is cyber insurance? Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Stanley Li and Sean Mahoney from Netswitch are joined by James Watson to discuss the return and rise of Ryuk ransomware - one of the most dangerous types of targeted enterprise ransomware: -- What exactly is Ryuk ransomware? -- Which types of organizations are being targeted? -- What is the typical value of a Ryuk ransomware demand? -- What are the simple, low-cost ways organizations can protect themselves from Ryuk? Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Stanley Li and Sean Mahoney from Netswitch discuss the increasing importance of 'RegTech' - where compliance meets technology: -- What exactly is RegTech and SupTech? -- How to bring visibility of both inside a single dashboard. -- How today's world has multiple regulatory compliance standards, not just 1 or 2. -- Why 'managing by spreadsheet' is no longer an option in this complex world. -- A real-world story of the challenges facing one IT Integration architect manager. -- Why communication with auditors can cause more issues than doing the compliance work itself. Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
Sean Mahoney, Stanley Li and James Watson discuss a new case of a construction company that may incur a $1m cost because of a single email deleted by an employee 2 years ago. -- Why Governance Risk and Compliance (GRC) is driving the agenda for security controls, policies and procedures for small and mid-size businesses. -- How automation can be used to manage and mitigate enterprise risk. -- Why managed service providers are evolving to combine support for network administration, security and risk management. Sponsored by Netswitch Technology Management - https://cybersecurity-chronicles.captivate.fm/episode/netswitch.net (netswitch.net)
In this episode, Sean Mahoney, Stanley Li and James Watson discuss the latest US Dept of Treasury advisory on potential sanctions risks for facilitating ransomware payments. Why the OFAC (Office of Foreign Assets Control) is watching. The rumour about why Garmin didn't engage with their ransomware attackers directly. The importance of ESG - Environmental and Social Governance Canadian Internet Registration Authority report says 90% of people will avoid companies that have been breached. The ethical dilemma - should hospitals pay ransomware? The 3 things small and mid size businesses need to have in place to protect themselves from a Ransomware attack. Ransomware used to be a 'last thought' from hackers after breaking into a network. Now its the primary source of 'easy money' for them. The Hiscox report said 350 firms (16%) reported paying ransoms off the back of a malware or ransomware attack. Why the real numbers are much higher. How researchers figured out how to put ransomware on a coffee maker. There is good news.. why tools and open-source resources have never been more cost-effective to protect infrastructure from attackers. The #1 cheapest way to protect yourself from hackers. Sponsored by Netswitch Technology Management - netswitch.net
On this episode Don Cox, former CISO at Mednax, Inc joins Stanley Li and Sean Mahoney of Netswitch to discuss the key differences between a Managed Detection and Response (MDR) Service compared to a Managed Security Service Provider (MSSP). Topics include: - What is MDR and what is an MSSP? - How does the MDR model differ from an MSSP? - Why would I use MDR? - Can MSSPs provide MDR? - What types of organizations typically use MDR? - Can I replace my MSSP with MDR? - Would I ever use MDR and an MSSP? Sponsored by Netswitch Technology Management - https://netswitch.net/ (netswitch.net)
-Why risk management and technology are totally different skill sets. -The #1 problem involving products, vendors, compliance and security. -The 2 top questions CEOs are asking right now about risk. -What Covid-19 means for global security budgets. -Who's becoming the real driver of technology decisions today. -Why risk is a business problem, not an IT one. -Why the roles of CIOs and CFOs are broadening to include risk. -The first question risk managers always ask (hint - its not about tech). Sponsored by Netswitch Technology Management - https://netswitch.net/ (netswitch.net)
In this episode Stanley Li and Sean Mahoney from Netswitch are joined by James Watson to discuss exactly what is Penetration Testing as a Service (PTaaS) and the increasing trend for businesses to move away from once-a-year pen tests to more regular, monthly ones instead. Episode highlights: - 15 years ago, when manual vulnerability scanning and assessments were the only options. - Why manual plus automated testing combined is essential to get the highest quality results from pen tests. - The new CVE 2020 1472 vulnerability Microsoft recently announced that won't be patched until 2021, and what this means for your testing schedule. - Why insecure configurations created by your IT admins could be increasing your risk more than you realise. - How the increasing number of regulatory and certification requirements have changed the testing landscape. - Why companies now have to demonstrate they're consistently pro-active in testing their networks. - Why the increase in remote working has only amplified these issues. - Why penetration testing as a service is much more affordable than annual tests of years gone by. - Which types of companies are particularly increasing their testing frequency. - Why vulnerability assessments alone will not protect you from Ransomware attacks. - What data penetration tests can identify that vulnerability assessments are unable to. - How to effectively manage security risk if you're a small business with a limited budget. - How an international hotel group client has increased their vulnerability assessment frequency from annually to monthly. - Why they jumped at the chance to deploy Penetration Testing as a Service. - How the old way of manual penetration testing could take over a month. - Why the new combination of automation and manual effort can now perform the testing and deliver a report with remediation in just one business week. - Why this means more time can be spent on remediation efforts and less on the testing itself. - Why consistency is the key to effectively managing your cyber risk in an increasingly insecure world. Sponsored by Netswitch Technology Management - https://netswitch.net/ (netswitch.net)
In this episode Sean Mahoney is joined by Stanley Li and Professor Michael Lassiter from Netswitch to discuss some of the most commonly asked questions about penetration tests, which include: How do I know a pen test is effective? How do we set the goals of the pen test? Will you make recommendations to the business? How can we trust your automated tool? Do I need a black box test for PCI-DSS or HIPAA compliance? When you send the post pen test report to us, what are supposed to do with it? How long should it take to do the remediation work? Do we have to remedy the vulns or do you? How do we know the vulns found in the pen test are corrected properly? My vendor (or customer) wants to see the pen test results as part of their supply chain review. Should I share it with them?
Sponsored by Netswitch Technology Management - https://netswitch.net/ (netswitch.net)