The Confident Defense Podcast: Recent Episodes

Conor Sherman

The Science of Security. The Art of Human Relationships. These are Conversations with the Best in Cybersecurity.

View Details

Maxime is the co-founder of LimaCharlie, on-demand primitives for security engineering. Before this, Maxime worked at Google, Google X and CrowdStrike. Maxime had his start in cyber security by working for Canadian Intelligence doing Counter CNE development and operations.LimaCharlie.io is a platform for cloud-native cybersecurity tools & infrastructure.

View Details

Terry is the Founder and CEO of PhishCloud Inc. He is an ethical hacker with over twenty years of experience in the cybersecurity industry and has served in a broad range of technical, analytical, and leadership roles. Terry is a serial entrepreneur with a passion for IT and OT security and solving complex challenges. He holds a BS in Information Technology from Capella University and several cybersecurity certifications.

View Details

Nick Sullivan is Head of Research at Cloudflare, a leading Internet security, performance, and reliability company. Nick leads research efforts in the fields of security and privacy, cryptography, Internet measurement, and emerging networking paradigms. Prior to working at Cloudflare, he developed encryption technology for Apple’s Internet Services division, co-wrote Symantec’s Internet Security Threat Report, and completed degrees in both Computer Science and Pure Mathematics. ✅ Follow Nick Sullivan’s or Twitter @grittygrease ✅ Follow The Cloudflare Research team https://research.cloudflare.com/

View Details

Mackenzie Jackson is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code. GitGuardian has been monitoring every single commit pushed to public GitHub since July 2017

View Details

Chris Castaldo is the Chief Information Security Officer at Crossbeam, the world's first and most powerful partner ecosystem platform. Chris is also the author of the best selling book Start-Up Secure: Baking Cybersecurity into your Company from Founding to Exit and is a visiting fellow at the National Security Institute at George Mason University's Antonin Scalia Law School.

View Details

Joining us today is Andy Shoemaker an expert in DDoS attacks and the founder of NimbusDDOS. His company helps enterprises, governments, and cloud-native companies prepare for DDoS attacks by performing risk assessments and launching controlled real-world attacks against their infrastructure.

View Details

Brian Vallelunga the CEO of Doppler, A central source of truth for developers to manage secrets across projects, environments, teammates, devices, and clouds. Doppler is backed by Sequoia, Google, Kleiner Perkins, and has the attention of amazing angel investors like the CEO of Github, CTO of OpenAI, and Peter Thiel. Brian was recently listed in Forbes 30 under 30 and is tackling one of the most pressing security risks in the market today - MITRE CWE-798 or use of hard-coded credentials.

View Details

Guest Intro----------------Our guest today is Richard Moore Author of Cyber Intelligence-Driven Risk (CI-DR®) former CISO for New York Life Insurance Company, Managing Director Alvarez & Marsal is an active Board Advisor and now serves as the CEO of CyberSix Socials-------- Site: https://www.cybersix.com/ LinkedIn: https://www.linkedin.com/in/richardmoorecybersix/Topics Reviewed------------------------ Cyber Threat Intelligence * 2012 The Year of the DDoS Lessons from Military Threat Intelligence * Unpacking the “cyber black box” Re-framing Vulnerability Management * Threat Intelligence - The Value of Data Sharing Supply Chain SecurityReference---------------- https://www.fsisac.com/ https://www.unifiedcompliance.com/ https://www.ffiec.gov/ https://sharedassessments.org/sig/ https://security.googleblog.com/2021/06/introducing-slsa-end-to-end-framework.html https://www.ssae-16.com/ https://www.acq.osd.mil/cmmc/ https://portswigger.net/daily-swig/axa-ransomware-attack-comes-just-days-after-insurer-pulled-coverage-for-cyber-attack-class-in-france* https://www.nist.gov/

View Details

Rick Deacon is a Serial Entrepreneur and security leader. He is the co-founder of Interlock formerly Apozy, also cofounded RADwood and RAD for Sale. Over 12 years in cybersecurity, he has been influential in helping shape the conversation around the role of blockchain in our security community through presentations at Defcon, SANS, and companies he has founded.

View Details

Guest Profile---------------------Our Guest today is Mohit Tiwari, Professor of the University of Texas at Austin and the Co-Founder and CEO of Symmetry Systems. A company on a mission to amplify Security Engineers by building products that discover, surface, and help engineers and leaders proactively protect their most valuable assets, data. Socials-----------------LinkedIn: https://www.linkedin.com/in/mohit-tiwari8/Site: https://www.symmetry-systems.com/Topics Reviewed ------------------------- Journey from Professor to CEO How do you provide insights without taking a copy of the data? * Making You Own Category Evolution of Data Security Evidence Based Security Teams Data Security - Policy as Code Risk of Dark Data

View Details

Guest Profile-----------------Our guest today is Paul Katzoff, the CEO of WhiteCanyon, WhiteCanyon Software provides the WipeDrive platform for erasing any IT asset or data-bearing device.Paul Katzoff is the CEO of WhiteCanyon Software. They are located in Salt Lake City, Utah, and their source code has never left the USA or been outsourced to 3rd parties.Socials----------------- Site: https://www.whitecanyon.com/ LinkedIn: https://www.linkedin.com/in/paulkatzoff/ Twitter: https://twitter.com/PaulKatzoffTopics Reviewed: * Closing the Gap on Data Security Complete Data Security Lifecycle Maintaining Data Security with Cloud Providers Risk of Harddrive Resale with Customer Data Secure Data deletion for home users WipeDrive Prime tool - Tracking Data Deletion * Ransomware Defense * Route to CEO* Future of Data Security

View Details

AJ Yawn is Co-Founder and CEO at ByteChek and a Founding Board Member of the National Association of Black Compliance and Risk Management Professionals (NABCRM). AJ has earned 6 AWS certifications including the AWS Solutions Architect-Professional and AWS Security-Specialty. Prior to ByteChek, AJ spent over a decade in the cybersecurity industry both in the US Army and as a consultant. He is a regular speaker at SANS Cloud Security curriculum events such as BIPOC in Cloud Forum and CloudSecNext Summit, and can be found teaching SEC557: Continuous Automation for Enterprise and Cloud Compliance at the SANS Institute. Socials------------LinkedIn: /in/ajyawn Twitter: @ajyawnTopics Reviewed: ------------------------- Military Service Impact on Fixing Compliance * Instructor at SANS How should companies select their auditors? * "Risk vs Audit" vs. "Risk of Audit" Fixing Auditor and Security Relationship Future of Automating Security Compliance* Embracing Innovation

View Details

Chen Arie is the chief architect and co-founder of Enso security. As co-founded Enso he has built the first application security posture management (ASPM) platform enabling security teams to scale and gain control over application security Favorite Quotes:-------------------------“It’s challenging to build applications is really challenging to build security and it’s really really challenging to build secure applications.” “When using it safely is the easiest option, then developers will use it because they are focused on delivering functions.” Reference:-----------------Enso Security raises $6M for its application security posture management platformhttps://techcrunch.com/2020/10/28/enso-security-raises-6m-for-its-application-security-management-platform/

View Details

Introduction-----------------Bob Fabien Zinga is senior-level cybersecurity and technology, risk executive who was a Senior Information Warfare Officer in the US Navy, currently serves on the Forbes Technology Council, and is the Director of Security at Directly Conversation Topics -------------------------------- A community of Innovation, Forbes Technology Council- Diversity in Leadership - They should reflect the company and counties we protect- SolarWinds Breach- How to Change Security Behavior - How to Start a Career in Security- Embracing Paradigm shifts - e.g. The Internet is our Network.- Retool for working with AIInsights in this Interview-----------------------------------"The Internet is our Network. Principles don't change but how you apply them does.”Favorite Quotes-------------------------"My superpower is my unshakeable determination to succeed.”“If you can't fly then run, if you can't run then walk, if you can't walk then crawl, but whatever you do you have to keep moving.” - Martin Luther King Jr.Reference----------------15 Digital Payment Upgrades That Would Improve The Customer Experiencehttps://www.forbes.com/sites/forbestechcouncil/2021/01/22/15-digital-payment-upgrades-that-would-improve-the-customer-experience/The Enterprise Data And AI Journey To The Cloud: Three Fundamental Milestoneshttps://www.forbes.com/sites/forbestechcouncil/2021/01/21/the-enterprise-data-and-ai-journey-to-the-cloud-three-fundamental-milestones/?sh=5ad184e079e3https://profiles.forbes.com/members/tech/profile/Bob-Fabien-Zinga-Head-Director-Information-Security-Information-Warfare-Commander-Directly-Inc-U-S-N/fcf91616-0afb-4518-94aa-93103b562d3c

View Details

Introduction------------------Grant Wernick, an inventor and serial entrepreneur who has built three Natural Language Processing companies, part of the team that built AngleList, laid the foundation of Kauffman Labs from the Kauffman Foundation, and is the co-founder & CEO of Fletch.ai an NLP powered platform is that highlight risk and insights into the cloud and SaaS environments. Socials---------- LinkedIn: https://www.linkedin.com/in/grantwernick/ Twitter: https://twitter.com/grantwernick Blog: https://fletch.ai/resources/ Site: https://fletch.ai/ Insights in this Interview-----------------------------------A simple “human-centric” user experience can break down technical barriers and with it cultural divides. Technology should adapt to humans not the other way around. NLP is the most effective way to interface with technology in a human-centric way.Topics Reviewed-------------------------- Career Journey * The Power of Natural Language Processing (NLP) The Story of Fletch* The future of knowledge and threat intelligence sharing Favorite Quotes------------------------"Fletch is the center of your data universe”“The promise of data has not delivered.” Reference---------------Weotta Goes Deep To Challenge Google On Local Searcheshttps://www.forbes.com/sites/parmyolson/2014/06/10/weotta-goes-deep-to-challenge-google-on-local-searches/?sh=668d8334b6cdWe Need More Transparency in Cybersecurityhttps://www.darkreading.com/vulnerabilities---threats/we-need-more-transparency-in-cybersecurity/a/d-id/1333780?A Look Back and a Leap Forward: 2020 Predictionshttps://medium.com/@grant.wernick/a-look-back-and-a-leap-forward-2020-predictions-b716c34695f9Salesforce is buying data visualization company Tableau for $15.7B in all-stock dealhttps://techcrunch.com/2019/06/10/salesforce-is-buying-data-visualization-company-tableau-for-15-7b-in-all-stock-deal/?guccounter=1Google to Buy Data Analytics Company Despite New Antitrust Scrutinyhttps://www.nytimes.com/2019/06/06/technology/google-data-analytics-looker-acquisition.html

View Details

Jasson Casey is the CTO of Beyond Identity, an Identity Management platform that is focused on killing the password. Humans and passwords are fundamentally incompatible and this is why 81% of hacking-related breaches use either stolen or weak passwords according to Verizon Data breach report. Jasson Casey - LinkedIn: https://www.linkedin.com/in/jassoncasey/Jasson Casey - Twitter: https://twitter.com/jassoncasey

View Details

Sean D. Mack is a visionary and innovative technology leader with a history of driving global business strategy and transformation. He has an extensive background in leading DevOps, infrastructure, enterprise applications, security, and desktop services in the educational technology and the publishing industry. Sean ran engineering at Etsy, he was the CEO for xOps, a DevOps consulting company, and now serves as dual CIO & CISO at Wiley.Conversation Highlights - Leading With Innovation- DevSecOps- Compliance Automation- Scalable Business First Security Architecture

View Details

Caroline is the Chief Strategy Officer at Cobalt, a pentest as a service company where she oversees security, people, and community. She began her career in InfoSec fifteen years ago, leading security teams at eBay and Zynga. Caroline also hosts the Humans of InfoSec podcast and teaches cybersecurity courses on LinkedIn Learning. She is the author of popular textbook, Security Metrics: A Beginner's Guide.Follow on LinkedIn: https://www.linkedin.com/in/carolinewmwong/Follow on Twitter: https://twitter.com/CarolineWMWongConnect over Email: caroline@cobalt.ioInsights in this InterviewTop security issues are misconfigurations, leverage machines, and humans in the right ways for an effective application security programThe discipline of Application Security (#AppSec) has a mature model for measuring maturity that is the BSIMMTopics Reviewed: * Her path into security, from dance to engineering to IT to security * Published a textbook on Security Metrics with McGraw-Hill. AppSec and her work with BSIMM Framework Improving AppSec Culture * Her thoughts on OWASP Top 10 Insights from dataset from 2,500+ Penetration Tests How to hire better in CybersecurityFavorite Quotes:“Find the common group, appsec and engineers have different priorities” Reference: Caroline Wong’s Wikipedia Page: https://en.wikipedia.org/wiki/Caroline_Wong Humans of InfoSec Podcast: https://podcasts.apple.com/us/podcast/humans-of-infosec/id1353458440 Security Metrics, A Beginner's Guide by Caroline Wong: https://www.amazon.com/dp/0071744002/ref=cm_sw_r_tw_dp_x_KbJLFbTD1FYY8 BSIMM - Observable Model of Application Security - http://bsimm.com/COBALT The State of Pentesting: 2020 - https://resource.cobalt.io/the-state-of-pentesting-2020

View Details

Ron and Chris are the co-hosts of Hacker Valley Studio. A podcast where they explore the human element of cybersecurity programs and technology. It's humanity meets technology meets the hacker's mindset.

View Details

Upa Campbell has over 20 years of experience in cybersecurity leading across marketing, product management and engineering. She has served as a key executive at four Cloud Native Security Companies, RedLock, Palerra, and Zscaler and is now serving as Chief Strategy and Marketing Officer at Accurics.

View Details

Yaniv Bar-Dayan is a member of the Forbes Technology Council, VC Insider, and the Co-Founder & CEO of Vulcan Cyber a vulnerability remediation platform. SocialsLinkedIn: https://www.linkedin.com/in/ybd/Twitter: https://twitter.com/ybardayanBlog: https://vulcan.io/blog/Site: https://vulcan.io/

View Details

Dr. Rebecca Wynn, a CISO, author, keynote speaker, consultant. She has more than 16 major industry and federal certifications in information security and risk management. She has contributed to the security community more than 70 professional articles and presentations ranging from cybersecurity to cyberethics to risk mitigation and recently featured in AI Magazine for her work in cybersecurity in the Artificial Intelligence field. SocialsLinkedIn: https://www.linkedin.com/in/rebeccawynncissp/

View Details

Corey built his career with 25 years of hands-on leadership and in both proactive security and Incident Response, he served as the SVP of Worldwide Consulting and Chief Experience Officer at Cylance. Corey co-founded Cyvatar where he serves as the CEO. Craig has served in an executive security role at multiple international companies such as CDK Global, Fujitsu, and others he sits on venture capital advisory boards and is co-founder and Chief Product & Strategy Officer for Cyvatar. Cyvatar is changing how security consulting is done. By focusing on remediation, not just detection. Head over to Cyvatar.AI and complete the 5min posture check to see where you need to prioritize your remediation efforts today and grab the eBook on why consulting is failing Cyber Checkup: https://clarity.cyvatar.ai/cybercheckup?source=confident-defense-podcastDownload eBook: SocialsSite - Cyvatar: https://cyvatar.ai/Twitter - Cyvatar: https://twitter.com/cyvatarLinkedin - Corey White: https://www.linkedin.com/in/coreydwhite/LinkedIn - Craig Goodwin: https://www.linkedin.com/in/craiggoodwin/Youtube - Unf*cking Cybersecurity: https://www.youtube.com/channel/UCu9QAWsnGSh2W-GX-g0vuDg

View Details

Ricky Tan, a West Point graduate, a US Army soldier who served as a cyber operations officer and is now the host of CyberSpacial a media channel aiming to make cybersecurity accessible for everyone by interviewing world-class practitioners and experts.

View Details

Margo Hohsfield is a Senior cybersecurity Recruiter Consultant at Stott and May, she is the founder of Growing Women in Technology (GroWiT); and Co-Founder and Director of Development at CyberDEI a non-profit organization centered around building a more diverse and inclusive cybersecurity community.

View Details

Amit Kanfer, CEO of build.security, on a mission to simplify how access controls are built and enforced inside high consequence software. Build.Security is an Authorization (AuthZ) platform that empowers engineers to build security software fast. Head over to Build.Security to schedule a demo and check out the webinars to explore AuthZ and how it can be solved at scale with Open Policy Agent (OPA).

View Details

VP of Security of Klaviyo, the premier marketing automation platform for any business that sells online. Brian is a security executive with over a decade of experience building and running high-performance teams and is a trusted voice on cyber security councils for multiple VC firms.

View Details

Michael Piacente, Cofounder and Managing Partner of Hitch Partners, a firm that specializes in CISO and Security leadership retained search projects, host of the podcast The Hitch Cast, trusted advisor to industry-leading CISOs, cited as an expert in WSJ.

View Details

Jake King. Jake is the Co-Founder and CEO and CMD (Command) a Linux and cloud security company. Jake is a frequent speaker on the topic of Linux Security at BSides, MITRE, and other conferences, as well as an active member of the Vancouver cybersecurity community. An Australian native, Jake studied cyber forensics and information security management before relocating to Vancouver, Canada in 2013.

View Details

E.J. Hilbert is the founder of KCE Cyber Consulting. EJ has over 2 decades of experience in the Cyber Security field. E.J. spent 8 years as a Special Agent for the FBI where he was the lead case agent for numerous cyber-crime, white-collar, and counterterrorism investigations. E.J. has been cited as an expert in Cyber and Counterterrorism by Rolling Stone Magazine, the Washington Post, Wired Magazine, the Financial Times, the Wall Street Journal, CNN, the NY Times, CNBC, the BBC, MSNBC, The History Channel and The Science Channel.Follow on LinkedIn: https://www.linkedin.com/in/ejhilbert/Follow on Twitter: https://twitter.com/ejhilbertFollow on Medium: https://medium.com/@ejhilbertConnect Online: https://kcecyber.com/Insights in this InterviewThere are six types of hacking financial crime, espionage, disruption, activism, manipulation, and regulation. Manipulation is when you start believing something and you don’t know why you believe it. Topics Reviewed: Security at MySpaceFBI Agent - Take Down of Carder PlanetFBI Agent - Infiltration of Al QaedaPrivacy - GDPR and how Privacy is Driving Security Security - Mandatory Breach NotificationSecurity - Cloud SecurityFavorite Quotes:“You can always tell the pioneers by the arrows in their back. I now wear my arrow scars with pride.”“We are [prone] to being manipulated because we listen to only what we want to hear.”Reference:Rogue Agent - https://medium.com/@ejhilbert/rogue-agent-34421d816279DoubleCross by Kevin Poulsen - https://www.wired.com/2016/05/maksym-igor-popov-fbi/Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground - https://www.amazon.com/Kingpin-Hacker-Billion-Dollar-Cybercrime-Underground-dp-0307588688/dp/0307588688/

View Details

Introduction: Stephen Semmelroth is both a West Point and Ranger School graduate, served in Afghanistan, led both a red team and a threat intelligence team while in the Army's Cyber Corps, founded and sold a Veteran-focused cyber recruiting company, and now leads both StrataCore's external recruiting division and their client security procurement discipline. Stephen is the VP of Cyber at Statacore that is an International focused organization that is headquartered in Seattle.Follow on LinkedIn: https://www.linkedin.com/in/stephencsemmelroth/Follow on Twitter: https://twitter.com/diodepackConnect over Email: stephen@stratacore.comInsights in this InterviewThat helicopter pilots are the best at threat modelingIf you are transitioning into security, leverage your “unfair advantage” and demonstrate that you are capable by competing in CFT or other competitive events. Topics Reviewed: Journey to cybersecurity from farm to electrical engineer to cybersecurityCode FellowsHow Security Practitioners can level up their gamePrivileged Access Management Systems “PAM”Effective Incident Response Planning from executives to engineers Threat Modeling and why helicopter pilots are the best at itOSINT as adversarial “Due Diligence” Favorite Quotes:“To be an endurance athlete you have to endure”“For a security product to be considered it must solve at least two problems and be designed to be effective in the hands of the most junior person on the team”Reference:Code Fellows: https://www.codefellows.org/Linux Privileged Access Management “PAM”: https://cmd.com/General Resume Guidance “ATS”: https://www.stratacore.com/rainier-cyber-resume

View Details

Robert (Bob) Vail, Citrine’s Director of Security, is a Certified Information Systems Security Professional (CISSP) with over 20 years of experience in the financial services, software, and cybersecurity industries. Started his journey as a helicopter pilot, worked with Security4Charities, and is now sought out as a thought leader in the security industry. Connect with Bob on LinkedIn - https://www.linkedin.com/in/bobvail/Insights in this Interview Why the FAIR Methodology is so powerful and how to use it The difference between being negligent, ignorant, and being effective in detecting attacks How to define and use Intrusion vs Breach when defending your companyTopics Reviewed: * History from Helicopter Pilot to CTO to CISO Involvement with Security4Charities Leading during “enforced work from home” #WFH #COVID19 How the “shared responsibility” model impacts newer companies Defining and exploring “Intrusion vs Breach” Insights into effective User Training “Go out of band” * Communicating effectively with executives using the FAIR methodologyFavorite Quotes:“In security there are few right answers but lots of strong thinking”“The moat [defending the castle] was made unless the day they invented the helicopter”“The job of the computer is to reply “yes” the job of security controls is to prevent the questions from being asked.”Reference: Security4Charities - https://www.linkedin.com/company/security4charities FAIR - https://fair.org* FAIR - https://www.risklens.com/why-risklens/built-on-the-fair-standard/

View Details

Taz is the founder of the Cyber Collective an organization focused on protecting the voice of content creators and influencers. Email: hello@cybercollective.orgTwitter: @TechWithTazInstagram: @TechWithTaz

View Details

Hiring and keeping security talent in a marketplace where there is a negative unemployment rate, and over 3 million roles going unfilled every year is a top challenge for security leaders. In this episode Stuart Mitchell the Head of Security Recruitment for Stott and May explore the challenges and solutions to building a top tier security team. We review how bias, expectations, compensation, and commitment to development are hurting our teams and how to fix it.Stuart Mitchell - Head of Security Recruitment - North Americahttps://www.linkedin.com/in/stuart-mitchell-08230a40/

View Details

Security products are how most practitioners protect their organizations, but most security startups are unable to breakthrough and be heard slowin down innovation in the security market. Security startups are at the heart of security innovation and sales is how startups grow and thrive! Amy Looper owns a growth company, Relativity Consulting, that specializes in helping security product and services find thier voice and build a repeatable sales and marketing function. "Best way to sell something: don't sell anything. Earn the awareness, respect and trust of those who might buy." - Rand FishkinAmy Looper ContactEmail: amy@relativityconsultingllc.comLinkedIn: https://www.linkedin.com/in/amylooper1/

View Details

The attacker seems to always have the upper-hand, the only way to defend against them is to think, plan and act like them. Penetration testing and Red team exercise are how the good guys act like the bag guys so security leaders can more effectively protect their organizations. Brian and Brad dive into the adventure and divulge the details of what is like to break into a bank, get caught in a police raid, and more!Brian Tant - CTO https://www.linkedin.com/in/briantant/Brad Herring - VP of Business Developmenthttps://www.linkedin.com/in/infosecbrad/

View Details

Security for startups, if you deploy code you need an AppSec program. In a long form conversation James Chiappetta the VP of Security at CLEAR talks us through the importance of AppSec and why it is needed to maintain trust with customers, integrity in the service, and how to get started.Linkedin: https://www.linkedin.com/in/jameschip/

View Details

CyberSecureIPS is the global leader in unified cyber-physical protection. They are a an organization with the singular mission of defending critical infrastructure from physical attacks. From nation-state actors to government led cyber espionage the physical layer is the most important layer when defending critical infrastructure, Scott and Steve unpack the challenges and what it takes to defend effectively at scale.Scott Rye - CEOhttps://www.linkedin.com/in/scott-rye-74bbb95/Steve Sohn - CTOhttps://www.linkedin.com/in/stevesohn/