JU focus is on Information and Cyber Security with discussions on related topics. e.g. News, regulations, threats, education, advisory, interviews and so on focusing on Africa. This is a platform to connect Security Professionals, Managers, Executives and enthusiasts for knowledge sharing and advisory
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series, we will be discussing the roles of CISO vs BISO, who wins? Is it really a competition?
1.W hat is the difference between a CISO and a BISO
2. Is it time for a dedicated BISO?
3. CISO Vs BISO
4. BISO Responsibilities
5. BISO Role in the Security Function
6. BISO Soft Skills
7. Is the BISO role still necessary?
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series, we will be discussing Achieving Data Residency in Africa
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will be discussing the Best Way to Organize and run a GRC Programme.
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we talk about passwords, are they going away soon?
Removing passwords is a solid goal as they are fraught with vulnerability issues – reuse, common construction patterns and the almighty leaked password problem.
Reasons why most organizations are not ready to abandon on-premises Active Directory and move towards a cloud-only model.
Reason 1: Hybrid directory will continue to dominate
Reason 2: Passwordless methods still rely on passwords in the background
Reason 3: Cybersecurity risks associated with passwordless
Do not neglect password security
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we have a discussion on Blockchain and Identity Management with a Software development and engineering manager with over 15 years of experience and one of the pioneers in identity management in Nigeria. His areas of interest spans different sectors.
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Deep Fake: New Cyber Security Warfare?
Deepfakes (a portmanteau of "deep learning" and "fake"[1]) are synthetic media[2] in which a person in an existing image or video is replaced with someone else's likeness. While the act of faking content is not new, deepfakes leverage powerful techniques from machine learning and artificial intelligence to manipulate or generate visual and audio content with a high potential to deceive.
We look at
1. Hyper-Connectivity Provides Opportunity
2. Deepfakes Present a Major Security Threat
3. Audience Manipulation
4. Role of Security Leaders
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
#Deepfake #warfare #cybersecurity, #cloudsecurity, #informationsecurity, #attack , #CISO
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Prioritizing Patching in Cybersecurity
Just an overview that FortiGuard Labs has found that very few vulnerabilities see widespread exploitation in the wild. Among all exploits logged by their sensors over the last two years, only 5% were detected by more than 10% of organizations. Three out of four exploits didn’t reach one in 1,000 firms.
What to do lets go through this
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
#patching #cybersecurity, #cloudsecurity, #informationsecurity, #attack , #CISO
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about CISO & Deep Dark Web
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
#Darkweb #cybersecurity, #cloudsecurity, #informationsecurity, #web, #CISO
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Active Directory Security
Develop the Strategy and Projects as a Team
Keep Your Strategy Flexible
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
#enterprise security #Activedirectory #cybersecurity, #cloudsecurity, #informationsecurity, #NIST, #CISO
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we wrap-up 2021 and look at some highlights and what to expect for 2022.
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about User friendly Security
We look at the current Security Myth
If the interface is easy to use, it’s less secure.
If it’s secure, it’s more difficult to use.
and some steps to take in ensuring user friendly security
1. Involve a UX designer
2. Get Stakeholders Involved in UX Security Early
3. Design Methods for Security Solutions
4. Build for Trust: End to End Encryption
5. Authentication
6. Enhance User Privacy and Data Privacy
7. Remove Unnecessary Security Obstacles
8. Secure Against Social Engineering
.
In Conclusion,
Consider and respect users when designing, implementing and operating any security solution or programs. Remember the WEAKEST LINK!
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about antidotes to ransomware
Agenda
1. What is Ransomware
2. Antidotes to ransomware such as
A. Enterprise Protection
B. Minimize the Impact
C.SEGMENTATION & ISOLATION
D. Understand how Ransomware works (Breaking the Cyber Kill Chain)
E. RESPONSE
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Zero trust architecture design principles and how we view each principles by the United Kingdom's National Cyber Security Center.
To know more you cango to https://www.ncsc.gov.uk/collection/zero-trust-architecture
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about a national cyber security policy and strategy with a pioneer and advocate for cyber security in Nigeria. He is no other than Olusegun Olugbile , the DG/CEO Araba Technologies Ltd (an emerging technology solution provider),
Executive Chairman of Data Analytics Privacy Technology Ltd - Owner of NDPR365-SaaS Brand, President, Global Network for Cybersolution Ltd/gte - Driver of Africa Digital Alliance (afrida),
Member, Board of Directors, International Centre for Emerging Technology-FUT Minna
Member, National Cybercrime Advisory Council, Presidency (2015 till date)
Member, National Committee on the Review and Development Cybersecurity Policy Strategy. 2014 & 2020
Former Member United Nation Internet Governance Multistakeholders Advisory Group to UN Secretary General.
Member/Fellow on Digital Economy, Abuja Chambers of Commerce & Industry, and International Chambers of Commerce Nigeria Chapter.
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
SHOW LESS
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about Cloud Access Security Broker (CASB)
Gartner defines the cloud access security broker market as products and services that address security gaps in an organization’s use of cloud services. Especially designed to protect and control access to data that’s stored in someone else’s systems, CASBs deliver differentiated, cloud-specific capabilities that generally aren’t available as features in traditional security products.
We will focus on the follwoing
1. The Core functionalities of CASB
2. CASB Vendors
3. Integration to CASB
4. Advanced CASB features
5. What to avoid when selecting CASB
Remember to SUBSCRIBE, SHARE , LIKE and COMMENT
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about OWASP TOP 10 Draft review 2021 focusing on the following
Listen, Like, Subscribe and Share
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we are honored to have our guest speaker, Foster Kplomdo, discuss NIST Cyber Security Framework.
As an experienced technology and security professional, He has worked in leadership roles across multiple technology disciplines in several multinational companies, as an instructor with some of the reputable academic institutions in the country and as a consultant to several businesses.
With over 17 years of progressive experience in the technology industry, a knack for research and drive for process optimization and knowledge sharing, Foster knows how to concretely define problems, prescribe solutions and execute them towards helping businesses and professionals maximize their potentials.
Hope you enjoy the session like we did.
Remember to SUBSCRIBE, LIKE and SHARE
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about August security news and HOT TOPIC -How to prepare for Security Audit in your organisation
Top Cybersecurity News in August are
1. An Inside Look at Soliciting Employees to Deploy DemonWare
https://abnormalsecurity.com/blog/nigerian-ransomware-soliciting-employees-demonware/
Google and Microsoft said they are pledging to invest a total of $30 billion in cybersecurity advancements over the next 5 years.
https://thehackernews.com/2021/08/microsoft-google-to-invest-30-billion.html
Telecom giant T-Mobile recently suffered yet another data breach.
https://thehackernews.com/2020/03/hackers-compromise-t-mobile-employees.html
There are mainly 11 Key steps when preparing for a security audit
Step 1: Scope and Gap Analysis - Audit Standard Selection (ISO, PCIDSS, GDPR, IT Audit or Statutory Audit) and interfaces
Step 2:Create an IT Asset Inventory
Step 3: Risk Assessment
Framework for Risk Assessment - NIST 800:53 or Specific policy requirement. Template and Procedure
Step 4: Close Gaps
Step 5: Review findings from Previous Audits
Step 6: Review and Create IT Policies and Procedures - (Operating Standard) as well as
create a List of Controls and Safeguards
Step 7: Perform a Self-assessment
Step 8: Schedule Tests or Deliverables
Step 9: Ask Your Auditor for a Document/Procedure Checklist
Step 10: Be Prepared for Anything
NOTE: ENSURE TO TALK ABOUT THE RESULTS AND AGREE ON THE REPORT BEFORE BEING PRESENTED IN THE CLOSING MEETING TO MANAGEMENT
SUBSCRIBE, LISTEN and SHARE
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about the BEST Cyber Security Framework for your organisation. We will talk about
SUBSCRIBE, LISTEN and SHARE
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about some security news , events and HOT TOPIC
July 2021 Patch Tuesday: Greatest Number of Updates for Ongoing Zero-Day Vulnerabilities Year-to-Date
https://www.crowdstrike.com/blog/patch-tuesday-analysis-july-2021/
LinkedIn breach reportedly exposes data of 92% of users, including inferred salaries
https://9to5mac.com/2021/06/29/linkedin-breach/
China Sets Up New Worrying Vulnerability Disclosure Rules
https://www.bitdefender.com/blog/hotforsecurity/china-sets-up-new-worrying-vulnerability-disclosure-rules
Kaseya obtains decryption key for vicitims of massive Ransomware Attack
https://www.cyberscoop.com/kaseya-ransomware-russia-revil/
HOT TOPIC - API SECURITY
https://owasp.org/www-project-api-security/
https://github.com/OWASP/API-Security/raw/master/2019/en/dist/owasp-api-security-top-10.pdf
SUBSCRIBE,LISTEN and SHARE
This is all about driving, measuring and management of Security culture in an organization. Our guest Richard Uhunmwagho is a seasoned cybersecurity & data privacy leader with years of experience across various sectors, leveraging my knowledge and expertise across diverse geographical regions, sectors, and regulated industries.
Professional focal points include Information Security/IT Risk management, IT Governance (GRC), Regulatory Compliance Assurance, Data Privacy and Protection, Business continuity & Operational Resiliency, Internal Audit, Security Awareness & Training and successfully managing enterprise risk management programs - end-to-end.
He has helped organizations set up and run effective security awareness programs with the intended objectives in changing human behaviours and habits in dealing with cyber threats.
Enjoy the session like we did and do not forget to LIKE , SUBSCRIBE, LISTEN and SHARE
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about some security news , events hot topics such as the
New Chrome 0-Day Bug Under Active Attacks – Update Your Browser ASAP!
https://thehackernews.com/2021/06/new-chrome-0-day-bug-under-active.html
Vulnerabilities Expose Fortinet Firewalls to Remote Attacks
https://www.securityweek.com/vulnerabilities-expose-fortinet-firewalls-remote-attacks
Fastly's global outage: Here's what went wrong
https://www.zdnet.com/article/fastlys-global-outage-heres-what-went-wrong/
Attackers are hunting for this critical VMware vCentre flaw
https://www.zdnet.com/article/patch-now-attackers-are-hunting-for-this-critical-vmware-vcentre-flaw/
Largest password data breach in history has been leaked online
https://techxplore.com/news/2021-06-largest-password-breach-history-leaked.html
Hackers Steal Wealth of Data from Game Giant EA
https://www.vice.com/en/article/wx5xpx/hackers-steal-data-electronic-arts-ea-fifa-source-code
Exclusive: NATO Classified Cloud Platform Compromised
https://ddosecrets.substack.com/p/exclusive-nato-classified-cloud-platform
9.Al Jazeera repels cyber-attacks that sought to disrupt media network
https://portswigger.net/daily-swig/al-jazeera-repels-cyber-attacks-that-sought-to-disrupt-media-network
UPDATES and POLICIES
12. DOJ recovers pipeline ransom, signals more aggressive approach to cybercrime
https://blog.malwarebytes.com/malwarebytes-news/2021/06/doj-recovers-pipeline-ransom-signals-more-aggressive-approach-to-cybercrime/
GOOGLES GOOD DEEDS
Google Expands Open Source Vulnerabilities Database
https://github.com/google/osv
https://osv.dev/list
Google open-sources tools to bring fully homomorphic encryption into the mainstream
https://github.com/google/fully-homomorphic-encryption
Thanks for listening and do not forget to SUBSCRIBE, LISTEN, SHARE and LIKE
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk to a special guest on Business Security Architecture
He is Oluwaseyi Ojo. An alumnus of John F. Kennedy School of Government, Executive Education Program of the prestigious Harvard University. A seasoned Business Security Architect with passion and focus on Governance, Quality, Risk and Compliance and deep competencies in Cybersecurity Management, Business Security Architecture, Enterprise Architecture, Enterprise Risk Management, IT Governance, Project Management, Business Continuity Management, Cyber Threat Intelligence, Network Security, Cloud Security, Digital/Cloud Forensics, Solution Architecture, Information Security and Assurance.
Thanks for Listening and do not forget to SUBSCRIBE, LISTEN and SHARE
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about some security events, news , hot topics such as the
-Cisco HyperFlex web interface has critical flaw
-Nagios IT monitoring vulnerabilities
-Canada Post reveals supplier data breach
- Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices
-FBI issues warning about Fortinet vulnerabilities after APT group hacks local gov’t office
-Over 40 Apps With More Than 100 Million Installs Found Leaking AWS Keys
-Experts warn of a new Android banking trojan stealing users' credentials
-CISA used new subpoena power to contact US companies vulnerable to hacking
-UK funds new African cybercrime office
-Top 10 Services that should not be exposed to the Internet directly
-FBI to share compromised passwords with Have I Been Pwned
-WARNING!!!
Nobelium (The Hackers known for Solarwinds hack) launched this week’s attacks by gaining access to the Constant Contact account of USAID.
Thanks for watching and do not forget to SUBSCRIBE, LISTEN, SHARE and LIKE
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk to a special guest on adapting Security Operations to the new realities - DevSecOps.
She is a certified InfoSec&GRC professional with an MSc in Computer Security and Audit and an MBA in HRM. She is currently working for one of the biggest UK retailers.
She is one of the early certified CISSP in Nigeria. Her name is Aijay Okani
Thanks for watching and do not forget to SUBSCRIBE, LISTEN and SHARE
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about some security events, news , hot topics such as the
-Security Researcher Dan Kaminsky is dead
-F5 Big-IP Vulnerable to Security-Bypass Bug
-NSA: Top 5 vulnerabilities actively abused by Russian govt hackers
- Checklist for Offboarding Remote Employees
-REvil ransomware gang claims it stole top-secret tech designs
-Hundreds of customer networks hacked in Codecov supply-chain attack
-Password manager Passwordstate hacked to deploy malware on customer systems
-Tiki app aims to hand ownership of personal data back to the individual
Thanks for watching and do not forget to SUBSCRIBE, LISTEN, SHARE and LIKE
Welcome to another edition of Just Unsecure series on information and cyber security matters as it relates to Africa. In this series we will talk about some security events such as the
-FBI, CISA warn Fortinet FortiOS vulnerabilities are being actively exploited
-NSA Discovers New Vulnerabilities Affecting Microsoft Exchange Servers
-Four in 10 South African ransomware victims pay the criminals
-Security pro seizes expired DR Congo top-level domain, takes over 50% of DNS traffic
-Major BEC Phishing Ring Cracked Open with 3 Arrests
-CISA releases tool to review Microsoft 365 post-compromise activity
Thanks for watching and do not forget to follow us on Twitter, LinkedIn, Spotify, Google and Apple podcast.
Hello and welcome to our Podcast on Information and Cyber Security , This episode we will talk about the following
The other company is located in Europe. What should I do and who should I report to?
Thanks for listening