Protecting People: Recent Episodes

Proofpoint

Today’s cyber attacks target people, not technology. Protecting People is a podcast focused on the human side of cybersecurity. Each episode, you’ll learn how today’s threats really work, who’s being targeted by them, and what you can do to safeguard your people, data and systems.Get real-world insight and learn about the latest trends in social engineering, malware, threat protection, cloud security and more. Protecting People is cybersecurity for the rest of us.

View Details

Five Minute Forecast for the week of January 30th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
* International law enforcement takes down Hive ransomware * U.S. officials issue warning about remote monitoring attacks * A breach at JD Sports exposes data for 10 million customers

And threat researcher Greg Lesnewich joins us to discuss North Korean state-sponsored threat actor TA444.

View Details

Five Minute Forecast for the week of January 23rd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
* Microsoft blocks another route used by Excel attackers * Ransomware profits are falling as victims refuse to pay * Mailchimp employee falls prey to social engineering

And threat research manager Daniel Blackford joins us to discuss a new campaign using clever salary-related lures. Check out the Threat Insight Twitter: @threatinsight

View Details

Five Minute Forecast for the week of January 16th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
* Europol calls time on a chain of pig butchering call centers * Norton Password Manager accounts targeted in credential stuffing attack * LockBit affiliate takes aim at the U.K.’s Royal Mail delivery service

And senior threat researcher Joshua Miller shares up-to-the-minute details on a campaign by advanced persistent threat actor, TA450.

View Details

Five Minute Forecast for the week of January 9th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
* LastPass breach is the gift that keeps on giving—but all its delivering is bad news for users * Phished credentials unlock Slack’s GitHub code repositories * LockBit ransomware says sorry for attack on SickKids hospital in Toronto

And senior threat intelligence analyst Crista Giering shares her headlines and highlights from the 2022 threat landscape.

View Details

Five Minute Forecast for the week of December 19th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Malware botnet taken down by Google last year back from the dead
  • Another botnet targets Minecraft servers
  • And an attacker infiltrates an FBI-run cybersecurity information-sharing program

View Details

Five Minute Forecast for the week of December 12th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Patients moved after ransomware attack at a Paris hospital
Looking for a last-minute gift? How about a stolen email address for $2?
Microsoft says the holidays could deliver a new wave of Russian cyber attacks 

And email threat researcher Timothy Kromphardt shares his highlights from another busy year of cyber threats.

View Details

2022 continued long-standing cybersecurity risks — aligning with our expectations — alongside new harrowing threats. What does that mean for the new year, and what can we do to best prepare for new tricks in 2023?
In this episode, Ryan Kalember, EVP of Cybersecurity Strategy at Proofpoint, joins us to shine a light on best practices for risk prevention, unpack present and potential threats, and more.
Join us as we discuss:
Potential pain points in cybersecurity for 2023
How security leaders should prepare for multiple challenges
Top concerns for security leaders

Register for our Power Series: https://go.proofpoint.com/powerseries#tab3

View Details

Five Minute Forecast for the week of December 5th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Car app bugs could let attackers steal vehicles with just an email address
LastPass confirms its second data breach in just four months
And malware-as-a-service makes starting a life of cyber crime even easier

View Details

Five Minute Forecast for the week of November 28th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Massive data breach at Twitter exposes millions of phone numbers
U.S. authorities seize pig butchering sites
Pro-Russia “hacktivists” take down the European Parliament website

And senior reverse engineer Pim Trouerbach shares the latest developments with Emotet.

View Details

Despite existing security solutions, organizations are continuing to see their user’s information compromised—whether it be business email compromise, ransomware attacks, phishing, or supply chain threats. The ways attackers are targeting people has evolved, but there's one constant in the ever-changing threat landscape; people are still the primary target.
Over the last year, Proofpoint has released several innovations for our overall threat protection platform. In this episode of Protecting People, we invited Neil Hammet, Technical Director at Proofpoint, to join the show to help us understand what these recent innovations mean for our customers. Neil dives deeper into the machine learning technology that is used on the back end to ultimately deliver these capabilities and help our customers.
Join us as we discuss:
Three different types of threats the extortion micro-classifier identifies
The new Inline+API deployment and the philosophical shifts that came with that transition
Proofpoint’s new PX bundle and who the ideal customer for that bundle would be

Check out these resources mentioned:
https://www.proofpoint.com/us/solutions/bundles
https://www.proofpoint.com/us/learn-more/email-rapid-risk-assessment
https://www.proofpoint.com/us/blog/email-and-cloud-threats/inline-api-new-era-email-security
https://www.proofpoint.com/us/blog/email-and-cloud-threats/behavioral-analysis-and-aiml-threat-detection-going-behind-scenes
https://it-harvest.com/shop/security-yearbook-2022/

For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.

View Details

Five Minute Forecast for the week of November 14th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Empty wallets see fingers pointed at FTX insiders
Europol arrests a high-profile member of LockBit
The FBI closes down multiple reshipping domains

And senior threat research engineer Adam McNeil discusses seasonal mobile threats.

View Details

Five Minute Forecast for the week of November 7th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.  
“Hackers for hire” target critics of World Cup host Qatar  
Twitter turmoil inspires a phishing expedition  
And Emotet returns with some old tricks  

And senior threat research engineer Adam McNeil explains the conversational techniques being used by job fraudsters.

View Details

Five Minute Forecast for the week of October 31st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Former-U.K. Prime Minister Liz Truss targeted by Russian attackers
Credit card thieves enjoy a two-year spree on See Tickets
Hinge targets scammers with profile verification

And email threat researcher Timothy Kromphardt breaks down all the details on romance scams.

View Details

Five Minute Forecast for the week of October 24th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
US authorities warn of a new ransomware campaign targeting healthcare
Attackers use hundreds of mis-spelled domains to distribute malware
And a research update on a new kind of conversational social engineering threat

And email threat researcher Timothy Kromphardt explains the connection between pig butchering and cryptocurrency fraud.

View Details

Five Minute Forecast for the week of October 17th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
CISA launches open-source tool for Red Teams
Developer error leaves Toyota customer data exposed
And keyless entry car thieves face being locked up

And threat research manager Daniel Blackford reflects on themes and insights from the recent Virus Bulletin 2022 conference.

View Details

Five Minute Forecast for the week of October 10th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Pro-Russia attackers ground several U.S. airport websites
1.2 million credit cards given away in dark web marketing promotion
Crypto thieves strike it big after a breach at Binance 

And senior threat intelligence analyst Selena Larson shares key insights from a comprehensive review of pandemic-related social engineering.

View Details

How prepared are organizations to deal with a cyberattack? What's the board's relationship with their CISOs? 
To find out the answers, Lucia Milica, Global Resident CISO at Proofpoint, joins us to discuss the Cybersecurity: 2022 Boards Perspective Report, where 600 board members from around the world were surveyed to share the boards-eye view of the threat landscape. 
Resources:
CISO Hub:
https://www.proofpoint.com/us/ciso-hub 
Cybersecurity: 2022 Boards Perspective Report: https://www.proofpoint.com/us/resources/white-papers/board-perspective-report 
Voice of the CISO episode: https://podcasts.apple.com/us/podcast/voice-of-the-ciso-insights-from-1-400-cisos-around-the-globe/id1492463146?i=1000561867551  
For more episodes like this one, follow Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.

View Details

Five Minute Forecast for the week of October 3rd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Exchange Servers at risk from two major zero-day vulnerabilities
Ransomware gang publishes data stolen in school system attack
Fake CISO profiles flood LinkedIn

We’re joined by former Gartner analyst Jonathan Care, who explains what cybersecurity awareness months means for security professionals.

View Details

Five Minute Forecast for the week of September 26th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
London police arrest teen who may be connected to Uber, Rockstar attacks
A highly advanced cyber-spying group found in telecom and university systems
And malicious OAuth cloud apps turn Microsoft Exchange servers into spam networks 

We’re joined by former Gartner analyst Jonathan Care, who explains how to identify and protect against insider and external threats.

View Details

In preparation for Cybersecurity Awareness Month in October, we invited Lisa Plaggemier, Executive Director at the National Cybersecurity Alliance, to join the show to discuss how to drive behavior change, and how to positively impact your cybersecurity culture.
Join us as we discuss:
What it means to “See Yourself in Cyber” and staying safe online
How behavioral science plays a role in driving a positive security culture
How to measure success of good security culture program

Check out these resources mentioned:
https://staysafeonline.org/
https://www.proofpoint.com/us/cybersecurity-awareness-hub

For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.

View Details

Five Minute Forecast for the week of September 19th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Attackers breach Uber’s internal systems
Thieves make off with Grant Theft Auto VI code
And a new phishing campaign uses the Queen’s death to steal credentials

And senior threat researcher Joshua Miller discusses multi-persona impersonation—a new technique employed by Iran-aligned attacker, TA453.

View Details

Five Minute Forecast for the week of September 12th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Ransomware attacks on schools set to rise
North Korean attackers set their sights on the energy sector
Former Conti members teach a new dog some nasty tricks

And Proofpoint VP Threat Research and Detection Sherrod DeGrippo on the threats that keep security leaders up at night.

View Details

Five Minute Forecast for the week of September 5th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Ransomware locks up a Los Angeles school district
Attackers score big on a security fumble by the 49ers
Researchers find malware embedded in space telescope images

And threat research engineer Michael Raggi talks cyber espionage on the South China Sea.

View Details

September 2022 is the fourth annual National Insider Threat Awareness Month. This month is dedicated to emphasizing the importance of safeguarding our nation and organization by detecting, deterring, and mitigating insider threats.
In honor of National Insider Threat Awareness Month, we invited Jonathan Care, Cybersecurity Expert and Former Gartner Analyst, to join us to help bring awareness to this crucial topic and dive deeper into insider risks and threats within organizations.
Join us as we discuss:
The difference between insider threat and insider risk in organizations
Some of the common behavior patterns that indicate there might be insider threat or risk going on with employees
The value of implementing an Insider Threat program within an organization

Resources:
https://cybersecurityforward.it.wisc.edu/wp-content/uploads/sites/1326/2020/02/Building-Incident-Response-Scenarios-for-Insider-Threats-Brian-Reed.pdf
www.proofpoint.com/us/resources/threat-reports/cost-of-insider-threats
www.proofpoint.com/us/reduce-insider-risk/insider-threat-management-hub

For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.

View Details

Since 2003, the United States has recognized the month of October as Cybersecurity Awareness Month. In preparation for October, Dr. Bob Hausmann, Assessment and Learning Architect at Proofpoint, joins the show to discuss how to build a strong security culture, and why it's essential to do so.
Join us as we discuss:
3 aspects that define organizational cultures and the key elements of building out a strong security culture
The impact of having a good security culture
Why training alone isn’t sufficient for building a great security culture
How to reinforce a security culture within an organization

Check out these resources we mentioned:
https://www.proofpoint.com/us/cybersecurity-awareness-hub
https://www.amazon.com/Cognitive-Science-Educators-suggestions-evidence-based/dp/1912906716

For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.

View Details

Five Minute Forecast for the week of August 29th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Quantum computing is nearly here and quantum-enabled cyber criminals won’t be far behind
The attacker behind SolarWinds casts a “MagicWeb”
Lockbit bites back after last week’s distributed denial of service attack

And threat research manager Daniel Blackford joins us to discuss seasonality in the cyber crime landscape.

View Details

Five Minute Forecast for the week of August 22nd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Apple releases urgent security patch with millions of devices at risk
Lockbit points the finger, saying one of its ransomware victims is trying to retaliate
Why a Grammy-winning music video could be bad for your hard drive’s health

And threat researcher Joe Wise joins us to discuss TA558’s attacks against the travel industry.

View Details

Five Minute Forecast for the week of August 15th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
U.S. authorities turn up the heat on Conti with a $10 million reward
Call center nightmares continue as telephone-oriented attacks surge by over 600%
Signal messaging accounts caught up in last week’s smishing attack on Twilio

And senior threat research engineer Adam McNeil joins us to explain the similarities and differences between email and SMS phishing.

View Details

Five Minute Forecast for the week of August 8th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
U.S. and Australian cybersecurity agencies reveal last year’s most prolific malware
Cloud software giant Twilio hit with a sophisticated SMS phishing attack
Security flaws could allow attackers to send fake messages through the Emergency Alert System

And senior threat intelligence analyst Selena Larson joins us to discuss a new malware campaign targeting cryptocurrency and decentralized finance.

View Details

In this episode of Protecting People, Host Lucia Milica, Global Resident CISO at Proofpoint, speaks with Patrick Gaul, Executive Director of the National Technology Security Coalition, as they discuss the 2022 NTSC 5th Annual National CISO Policy Conference. This event hosts CISOs and technology security executives from all over the United States to come together and discuss today's top issues impacting cybersecurity policy and legislation. Lucia and Patrick share their key learnings and updates from their time in Washington DC, as well as some of the latest industry development security professionals need to know about.
Join us as we discuss:
Three of the biggest takeaways from the conference for CISOs and security leaders
The latest developments in Congress regarding the proposed American Data Privacy and Protection Act
The shortage of cyber professionals and the challenges of cyber workforce development  

Check out these resources we mentioned:
https://www.proofpoint.com/us/ciso-hub  

For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.

View Details

Five Minute Forecast for the week of August 1st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
The FCC says SMS phishing attacks are on the rise and targeting U.S. consumers
A new phishing-as-a-service platform targets big name banks
New data shows a second quarter decline in average ransomware payments

And senior threat intelligence analyst Selena Larson joins us to discuss how Microsoft’s macro blocking policy is affecting the threat landscape.

View Details

Five Minute Forecast for the week of July 25th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
The FBI warns investors to be on the lookout for fake crypto appsDetails of over five million Twitter users for sale after data breach
Microsoft moves ahead with its plan to auto-block macros

Joining us to discuss threat actor attribution and state-sponsored activity in the Middle East is senior threat researcher Joshua Miller.

View Details

Five Minute Forecast for the week of July 18. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Media outlets face increasingly advanced espionage attempts
H0lyGh0st ransomware group linked to North Korea—but maybe not its government
CIA insider convicted in massive data leak

Joining us to discuss media-focused APT attacks is Proofpoint Threat Researcher Crista Giering.

View Details

Five Minute Forecast for the week of July 11th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
U.S. healthcare organizations targeted with state-sponsored ransomware
Deepfakes of American workers used to apply for remote tech jobs
Personal data of 1 billion Chinese citizens for sale on the dark web

Joining us to discuss a day in the life of a threat hunter is senior threat detection engineer Tony Robinson.

View Details

John Checco, Resident CISO at Proofpoint joins the show this episode to discuss The Art of Storytelling. CISOs are often presenting technical or complex ideas at the board-level. Trying to do so in a simple yet compelling way can prove challenging, and that is where mastering the ancient art of storytelling can play a critical role in cybersecurity.
Join us as we discuss:
Six basic concepts of storytelling for business
The importance of data relevance and context when presenting
Strategies for the improvisational moments of storytelling
The biggest mistakes CISOs and security leaders make when presenting to a board

Check out these resources we mentioned:
https://www.proofpoint.com/us/ciso-hub

For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.

View Details

Five Minute Forecast for the week of June 27th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
FTC advises LGBTQ+ dating app users to beware of cyber extortion
Lockbit ransomware gets into the bug bounty game
UK delivery services Yodel is hit by cyber attack

Joining us is Selena Larson from the Proofpoint Threat Research team, to discuss the latest news on social engineering strategies.

View Details

Five Minute Forecast for the week of June 20th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Law enforcement arrest thousands in global social engineering stings
Icefall vulnerabilities put thousands of critical systems around the world at risk
Blackcat takes ransomware victim shaming to a new level

Joining us is Proofpoint VP of Threat Research and Detection, Sherrod DeGrippo, who shares her thoughts on this year’s Human Factor report.

View Details

Most of the time, security slip-ups happen because of careless, accidental behavior. Through educating people and focusing on changing behaviors, those cyber risks can be mitigated. That’s the idea behind the importance of people-centric cybersecurity. 
Today we hear from Jeffrey Wheatman, Cyber Risk Evangelist at Black Kite, about implementing people-centric cybersecurity and assessing your organization’s risk appetite. 
Join us as we discuss:
Why people-centric cybersecurity matters
Evaluating risk quantification in the cybersecurity industry
The importance of determining your organization’s risk appetite
Risk appetite versus risk tolerance 

Check out this resource we mentioned:
Voice of the CISO Report: https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report  
https://blackkite.com/  

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of June 13th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Unpatched router vulnerabilities are being exploited by state-sponsored attackers
Ukrainian security authorities warn of active Follina campaigns
Details of a massive Facebook phishing campaign revealed

Joining us is senior threat researcher Jared Peck, for a discussion about cryptocurrency and cyber crime. 
Link to the blog post mentioned: https://www.proofpoint.com/us/blog/threat-insight/how-cyber-criminals-target-cryptocurrency

View Details

Five Minute Forecast for the week of June 6th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
A cyber attack causes chaos in one of Italy’s largest cities
Has FluBot delivered its last message? European law enforcement thinks so.
Apple blocks over 1.6 million malicious and untrustworthy apps from iPhones

Joining us is senior threat researcher Daniel Blackford, to discuss highlights from this year’s Human Factor report.
Human Factor Report: https://www.proofpoint.com/us/resources/threat-reports/human-factor

View Details

Proofpoint’s biggest release of the year is here: the 2022 Human Factor Report. To ensure you don’t miss a thing, Protecting People has your on-the-go breakdown of the report straight from the source,
Sherrod DeGrippo, Vice President of Threat Research and Detection at Proofpoint, joins the show to talk about some of the key findings and topics from the Proofpoint 2022 Human Factor Report and how to best protect yourself and your organization in this new threat landscape.
Join us as we discuss:
The three key areas of user risk
How to identify vulnerable users within organizations
The increase of malicious URLs in 2022
How remote work is impacting organization’s security risks
The influence of Russia’s invasion of Ukraine on the threat landscape 

For more episodes like this one, follow Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Resource:
2022 Human Factor Report: https://www.proofpoint.com/us/resources/threat-reports/human-factor

View Details

Five Minute Forecast for the week of May 30th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
A New York man gets four years for his part in stealing more than four million credit cards
Ransomware causes serious disruption to one of India’s largest airlines
CLoP ransomware makes a return after four months of silence

Joining us is senior threat researcher Andrew Northern, to discuss the etymology and characteristics of the newly discovered Nerbian RAT.

View Details

Five Minute Forecast for the week of May 23rd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Conti ransomware calls time on direct attacks, but remains highly influential
Half a million Chicago students have their personal information stolen in a security breach
U.S. authorities recover $15m from ad fraud operators

Joining us is Proofpoint’s Cheryl Tang, for a review of customer insights at our recent Protect and Wisdom events.

View Details

What attacks keep CISOs up at night? Are your employees prepared for those attacks? Is remote work putting you at risk?
To find out the answers, Lucia Milica, Global Resident CISO at Proofpoint, joins us to discuss this year's Voice of the CISO Report, where 1,400 CISOs from around the world were interviewed to share their experiences of the past 12 months and offer their insights for the years ahead.
Listen in to our conversation with Lucia about:
Why CISOs aren't more worried
Is threat modeling really helping?
Which threats are softening up
What security concern rocketed to the top of charts

For more episodes like this one, follow Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Resources:
CISO Hub:
https://www.proofpoint.com/us/ciso-hub
2022 Voice of the CISO Report: https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report

View Details

Five Minute Forecast for the week of May 16th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Managed service providers could let attackers scale supply chain attacks
GCHQ says that Russian attackers continue to target Ukraine supporters
Firmware bugs affect over 200 models of HP computers

Joining us is Proofpoint cybersecurity evangelist, Brian Reed, for a preview of our Voice of the CISO report, launching this week.

View Details

Five Minute Forecast for the week of May 9th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Security experts warn of a major vulnerability for F5 Networks’ BIG-IP products
  • The U.S. Chamber of Commerce to oppose SEC-proposed rules for cyber incident disclosure.
  • And Costa Rica declares a national emergency amid a wave of ransomware attacks

Joining us is senior threat researchers Daniel Blackford to discuss the return of the REvil gang.

View Details

Two conferences, four main tracks, numerous speakers, a cybersecurity ecosystem and community — plus the snazzy jackets. You won’t want to miss the all-virtual events Protect 2022 and Wisdom 2022 from Proofpoint.

Hear our conversation with Tim Choi, Vice President Product Marketing at Proofpoint:

  • Why “versus” is the event theme this year
  • What to expect in the four different tracks
  • Who the keynote speakers are (hint: Magic Johnson!)
  • Puns, community, and the jackets we all love

More information about Tim and today’s topics:

  • Protect 2022: https://www.proofpoint.com/us/events/protect
  • Wisdom 2022: https://www.proofpoint.com/us/events/wisdom

For more episodes like this one, follow Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.

View Details

Five Minute Forecast for the week of May 2nd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • REvil returns in what appears to be fallout from the Russia-Ukraine conflict
  • A phishing scheme steals more than $20 million from the Department of Defense
  • Onyx ransomware destroys data instead of locking it away

Joining us is senior threat researcher Daniel Blackford, for an update on the Emotet malware.

View Details

Five Minute Forecast for the week of April 25th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Five Eyes tells members to watch out for Russia-aligned cyber attacks
  • Black Cat ransomware pounces on sixty victims in just four months
  • T-Mobile gets hits by Lapsus$ but emerges relatively unscathed

Joining us is email fraud researcher Timothy Kromphardt, to discuss the latest IC3 Internet Crime Report.

View Details

Five Minute Forecast for the week of April 18th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • US authorities warn of a dangerous new malware targeting industrial control systems
  • The FBI blames North Korean attackers for a record-breaking crypto theft
  • Microsoft hits back against a notorious banking Trojan

Joining us is senior threat researcher Daniel Blackford, to discuss this tax season’s social engineering tactics.

View Details

Five Minute Forecast for the week of April 11th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Russian organizations no longer immune from cyber attacks
  • Cash App notifies over eight million customers of a data breach
  • VMware warns of several critical vulnerabilities in its products

Joining us is senior threat researcher Andrew Northern, for a discussion about the recent spate of data theft attacks by Lapsus$. 

View Details

Tax season is fast upon us in the United States. Here’s the rundown of tax-related phishing trends to make you more wary and alert.

Hear our conversation with John Checco, Resident CISO at Proofpoint:

  • Tax-themed phishing trends old and new
  • What’s real and what’s not about IRS messaging
  • Top preventative measures to enact today

More information about John and today’s topics:

  • LinkedIn Profile: https://www.linkedin.com/in/checco/
  • Company Website: https://www.proofpoint.com/us

For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.

And keep up with the latest tales from the threat research trenches by subscribing to DISCARDED in Apple Podcasts, Spotify, or wherever you get podcasts. Thanks for listening!

  • https://podcasts.apple.com/us/podcast/discarded-tales-from-the-threat-research-trenches/id1612506550

View Details

Five Minute Forecast for the week of April 4th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • More Lapsus$ leaks as two teenagers are charged with cyber crimes in the UK
  • The FBI warns of a phishing campaign targeting US election officials
  • Another contender emerges for biggest ever cryptocurrency theft

Joining us is email threat researcher Timothy Kromphardt, to discuss a wave of employment fraud attacks targeting students at U.S. universities.

View Details

Five Minute Forecast for the week of March 28th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • U.S. authorities say Russian cybersecurity firm poses a risk to national security
  • Lapsus$ suspects arrested after unprecedented data theft spree
  • More than 600 critical infrastructure orgs hit by ransomware in 2021

Joining us is senior threat researcher, Andrew Northern, to discuss a new malware campaign that uses some highly advanced techniques.

View Details

Everyone gets phishing emails. Not everyone falls for them. In this episode, we discuss the eighth annual State of the Phish report and learn how vulnerable users are to today’s so-called New Normal.

What should you know and how should you respond?

Today we hear from Gretel Egan, Sr. Security Awareness Training Strategist at Proofpoint and primary author of the annual State of the Phish report, about the outlook for phishing in 2022.

Join us as we discuss:

  • What “phishing” and “vulnerability” mean in the report
  • The effect that remote work has had on cyberattackers
  • Different types of phishing and how they’re deployed
  • Surprising findings in data and reporting
  • Awareness and preparedness

Check out this resource we mentioned:

  • 2022 State of the Phish Report - Stats, Trends & More | Proofpoint US

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of March 21st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Data thieves add Microsoft to their growing list of tech victims
  • Office updates are mistakenly flagged as ransomware
  • German government warns against using Russian antivirus software

Joining us is senior threat researcher, Andrew Northern, to discuss a recently leaked trove of documents relating to the Conti ransomware gang.

View Details

Five Minute Forecast for the week of March 14th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Big tech data theft spree continues with attack on gave developer Ubisoft
  • Chinese government-sponsored attackers target U.S. Gmail accounts
  • Authorities extradite an REvil affiliate implicated in Kaseya ransomware attack

Joining us is threat research engineer, Adam McNeil, to discuss a new wave of mobile malware attacks in Europe.

View Details

In this episode, Ken Spencer Brown, Senior Manager, Marketing Strategy and Content at Proofpoint, helps us navigate the new possibilities and challenges posed by artificial intelligence and machine learning in cybersecurity. We'll uncover how it's being used, where it's going, and why we should take notice.

Join us as we discuss:

  • The differences between AI, machine learning, and deep learning
  • How machines actually "learn"
  • Ways ML can help threat detection… and threat actors
  • Who wins in the AI vs. human face-off

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or search for Protecting People in your favorite podcast player.

Music by Eric Matyas at www.soundimage.org

View Details

Five Minute Forecast for the week of March 7th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Attackers leak Nvidia secrets after the chip giant refuses to negotiate
  • Researchers get a closer look at the inner workings of Conti, including source code

Joining us is Proofpoint Director of Threat Research and Intelligence, Wes Drone, for a look at the cybersecurity implications of the Russian invasion of Ukraine.

View Details

Five Minute Forecast for the week of February 28th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • War in Ukraine spills over into the cyber security arena
  • Toyota pauses car production after supply chain cyber attack
  • And Conti pulls the plug on Trickbot a week after taking over

Joining us is Proofpoint cyber security evangelist, Brian Reed, to talk about the growing role of CISA in setting security standards for U.S. organizations and businesses.

View Details

Five Minute Forecast for the week of February 21st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Meet the new boss, not quite the same as the old boss, as cyber criminals invade virtual meetings
  • Conti ransomware group launches a Trickbot takeover
  • Digital art collectors fall prey to a coordinated phishing attack

Joining us is threat researcher Joe Wise to discuss TA2541, a cyber attacker with a fondness for the aerospace industry.

View Details

Five Minute Forecast for the week of February 14th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Romance is in the air—with scams that cost U.S. citizens over half a billion dollars
  • Microsoft makes a move against Office macro malware delivery
  • The Department of Justice seizes billions in stolen Bitcoin

Joining us is email fraud researcher, Timothy Kromphardt, to discuss new developments in the world of commodity phish kits.

View Details

Five Minute Forecast for the week of February 7th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Intuit warns customers of a new tax season phishing campaign
  • Sugar ransomware targets consumers—but just wants a taste
  • Yet another crypto platform suffers big losses in a cyber attack

Joining us is security researcher, Assaf Friedman, to discuss a new cloud campaign using malicious OAuth apps to target high-profile executives.

View Details

Ransomware attacks are becoming both more targeted and more damaging. Is your organization prepared?

In this episode, host Itir Clark interviews Neko Papez, Manager, Product Marketing at Proofpoint, about the newest trends in ransomware — and the best strategies for prevention.

Join us as we discuss:

  • Human-operated ransomware and its dangerous effectiveness
  • Illustrations of how damaging ransomware can truly be
  • The big-game-hunting mentality shift of ransomware threat actors
  • Phishing emails: the origin of most ransomware

Check out these resources we mentioned during the podcast:

  • 2021 Verizon DBIR report: https://enterprise.verizon.com/content/verizonenterprise/us/en/index/resources/reports/2021-dbir-executive-brief.pdf
  • Treasury Department report: https://www.wsj.com/articles/suspected-ransomware-payments-for-first-half-of-2021-total-590-million-11634308503
  • Ransomware Hub: https://www.proofpoint.com/us/ransomware-hub

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of January 31st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • The U.K. echoes U.S. warnings over destructive cyber attacks
  • A prominent banking Trojan gains some new defensive tricks
  • U.S. consumers lose over $700 million to social media fraud

Joining us is founder and chairman of the Ponemon Institute, Larry Ponemon, to discuss the growing cost of insider threats.

View Details

Five Minute Forecast for the week of January 24th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • CISA tells U.S. organizations to prepare for possible data-wiping attacks
  • Law enforcement links new ransomware to The Trick banking Trojan
  • The Red Cross urges cyber attackers to do the right thing

Joining us to kick off Data Privacy Week is Proofpoint Cybersecurity Evangelist, Brian Reed.

View Details

Five Minute Forecast for the week of January 17th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Russian authorities arrest 14 in REvil crackdown
  • World’s largest marketplace for stolen credit cards closes its doors
  • CISA warns government agencies of vintage threats

Joining us is Proofpoint’s Fabiola Fernandez to talk about the launch of this year’s Phishing Awareness Kit.

View Details

You can buy a phish kit online for 10 bucks. But beware, since it’ll probably come back to bite you in ways you might not expect.

In this episode, hosts Selena Larson and Crista Giering chat with Jared Peck, Senior Threat Researcher at Proofpoint, about the pros and cons of phish kits — and why there’s no honor among thieves.

Join us as we discuss:

  • What a phish kit is and how it works
  • Ways a phish kit relates to MFA tokens and other authorizations
  • Monetization, credentials for initial access, and the attack chain
  • How organizations and people can defend against phishing attacks

Resource mentioned:

  • Have Money for a Latte? Then You Too Can Buy a Phish Kit | Proofpoint US

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of January 10th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • FBI warns that USB drives sent through the mail probably aren’t belated holiday gifts
  • It’s a crime, but is it art? Thieves steal $2 million of NFTs
  • Famous authors phished for unpublished manuscripts

Joining us is Proofpoint Cybersecurity Evangelist, Brian Reed, for a look ahead at 2022.

View Details

Five Minute Forecast for the week of December 20th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Threat actors exploit Log4Shell with a variety of attacks
  • Anubis banking trojan targets almost 400 Android finance apps
  • Thieves make off with another big cryptocurrency score

Joining us is Proofpoint Threat Researcher Selena Larson to discuss a spate of recent campaigns targeting customers of German financial institutions.

View Details

If you asked for M&M’s and received Skittles, you might pop a few in your mouth, but it won’t take long to realize something’s off.

This is exactly what’s happening with RTF files: Instead of the intended attachment, unaware companies are delivering these files and realizing later that they were actually malicious.

On this episode of Protecting People, hosts Selena Larson and Crista Giering chat with Michael Raggi, Senior Threat Research Engineer at Proofpoint, about RTF files, template injection, and campaigns using the technique in an effort to make sure customers aren’t being surprised with “Skittles.”

Join us as we discuss:

  • The importance of template injection
  • Campaigns using the technique
  • Widespread adoption of the RTF injection
  • Mitigating and monitoring the technique

Resource mentioned:

  • https://www.proofpoint.com/us/blog/threat-insight/injection-new-black-novel-rtf-template-inject-technique-poised-widespread
  • https://www.youtube.com/watch?v=bqyOtkibGro&feature=youtu.be
  • https://twitter.com/sansforensics/status/1470901574717382663

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of December 13th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Log4Shell puts the security industry on high alert
  • Wifi and Bluetooth flaws could leave millions of devices vulnerable
  • Emotet gives the gift of Cobalt Strike this holiday season

Joining us is Proofpoint Threat Researcher Eric Koeppen to discuss a series of holiday-themed campaigns launched by threat actor TA575.

View Details

Five Minute Forecast for the week of December 6th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Hundreds of thousands of patient records stolen from Planned Parenthood
  • Thieves make off with a $200 million haul in the latest crypto heist
  • Labor activists communicate with service industry workers through hacked point-of-sale printers

Joining us is Proofpoint Senior Threat Intelligence Analyst, Selena Larson, for an update on pandemic-themed cyber attacks.

View Details

Five Minute Forecast for the week of November 29th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Interpol arrests almost 1000 suspects in cyber crime operation
  • A hardware bug could let attackers listen in on Android phone calls
  • The Huawei AppGallery delivers malware to nine million phones

Joining us is Proofpoint Senior Threat Research Engineer, Michael Raggi, for a look at a dangerous new phishing technique.

View Details

Have you ever been bitten by a TOAD? No, we're not talking about the marsh-dwelling amphibian. We're discussing telephone oriented attack deliveries (TOADs) in which scammers use real phone numbers to gain access to information and accounts.

TOADS represent an atypical — but very poisonous — online threat especially to men in the 20-50 age range. Featuring believable fake invoices and U.S.-based phone numbers, these scammers can hop off with hundreds or thousands of your dollars.

On this episode of Protecting People, hosts Selena Larson and Crista Giering chat with Tim Kromphardt, Email Threat Researcher at Proofpoint, about TOADS, how to avoid them, bait them, or report them.

Join us as we discuss:

  • The two kinds of TOAD threats
  • How investigators locate and shut down TOAD scammers
  • What the scambaiting community does
  • Where and how to report a TOAD attack

Resources mentioned:

  • Caught Beneath the Landline: A 411 on Telephone Oriented Attack Delivery

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of November 22nd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Emotet back from the dead almost a year after shutdown
  • Six million routers left at risk in the U.K.
  • GoDaddy breach exposes data of 1.2 million customers

Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, for an update on North Korea-aligned threat activity.

View Details

What does Data Loss Prevention look like in an increasingly remote world? Is the entire concept of DLP flawed? And at the end of the day, whose responsibility is DLP?

DLP is a complex and complicated topic that is crucial for any business to fully understand. After all, you’re protecting your most valuable assets, your intellectual property.

On this episode of Protecting People, host Brian Reed sits down for a conversation with Cosmo Romero, Sr. Sales Engineer at Proofpoint, for a conversation all about DLP, incident response, and more.

Join us as we discuss:

  • What a modern information protection offering actually looks like
  • Why DLP is a business issue, not a technology issue
  • How to transition away from a legacy DLP mindset
  • Why DLP as an acronym and concept may not make much sense in 2021

Resources mentioned during the interview:

  • Gartner - It's Time to Redefine Data Loss Prevention

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

View Details

A Five Minute Forecast for the week of November 15th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Fake security emails sent from the FBI’s own server
  • A massive breach at Robinhood affects 7 million accounts
  • An Iranian group seeks stolen data on the dark web

Joining us is Daniel Blackford, Proofpoint Senior Threat Researcher, for a preview of our new Fall/Winter threat update.

View Details

It’s the holiday season!

While that might conjure up images of family gatherings and gift-giving, internet scams are, unfortunately, all too common during this season as well.

In this Expert Insights episode, host Sara Pan interviews Brian Reed, Cybersecurity Strategist at Proofpoint, about how you can protect yourself when the cyber Grinch comes knocking.

Join us as we discuss:

  • Suspicious gift card offers and shipping confirmations
  • Phishing and smishing involving coupon codes and discounts
  • The consequences of falling for holiday scams
  • How to combat brand spoofing and lookalike domains

Check out these resources we mention during the podcast:

  • Cybersecurity Awareness Center

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of November 8th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Foreign attackers breach targets in defense, energy and other key sectors
  • A $10m bounty for anyone who can shine a light on DarkSide ransomware
  • And President Biden orders government agencies to clean house

Joining us is Brian Reed, Proofpoint Director, Cyber Security Strategy, to discuss the ramifications of the Biden Administration’s latest directive.

View Details

Five Minute Forecast for the week of November 1st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Israeli businesses hit by attacks from state-sponsored cyber criminals
  • German police set their sights on an REvil kingpin
  • HelloKitty ransomware sharpens its claws

Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, to talk about a new threat actor impersonating government departments in the Philippines.

View Details

APT stands for advanced persistent threat and refers to threat actors who are acting in the interests of other political states.

In other words, espionage.

In this episode of our #ThreatDigest series, hosts Selena Larson and Crista Giering, Senior Threat Intelligence Analysts at Proofpoint, interview Joshua Miller, Senior Threat Researcher at Proofpoint, about the advanced persistent threat landscape in Iran.

Join us as we discuss:

  • Determining whether malware is motivated for finances or for espionage
  • How Iranian threat actors have shifted their strategy since COVID
  • What we can infer about Iranian government priorities from threat actors
  • Why Iranian threat actors are taking more risks
  • Where to start in tracking APTs in the world of cyber threat intelligence

Check out the resources we mentioned during the podcast:

  • Operation SpoofedScholars: A Conversation with TA453
  • BadBlood: TA453 Targets US and Israeli Medical Research Personnel
  • I Knew You Were Trouble: TA456 Targets Defense Contractor
  • Media Coverage Doesn't Deter Actor From Threatening Democratic Voters
  • DHS blames Iran for threatening emails sent to Democratic voters
  • A Cyber Threat Intelligence Self-Study Plan: Part 1
  • STAR Webcast: Dissecting BadBlood: an Iranian APT Campaign
  • Better Than Binary - Elevating State-Sponsored Attribution via Spectrum of State Responsibility

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of October 25th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Russia launches new cyber attacks in defiance of U.S. sanctions
  • A cyber criminal gang recruits unwitting security professionals to carry out attacks
  • Evil Corp launches a new strain of ransomware

Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, to talk about a legitimate “red team” security tool being used by cyber criminals.

View Details

Five Minute Forecast for the week of October 18th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • 90% of Americans are concerned about the threat of cyber attacks
  • The U.S. Treasury identifies over $5 billion in ransomware payments
  • Google reports a huge increase in attacks by state-sponsored groups

Joining us is Crista Giering, Proofpoint Senior Threat Intelligence Analyst, to talk about the return of a major cyber crime group.

View Details

Five Minute Forecast for the week of October 11th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Gaming site Twitch is hit by a massive breach
  • New legislation proposes strict timelines for ransomware reporting
  • Microsoft closes the door on a popular malware vector

Joining us is Daniel Blackford, Proofpoint Senior Threat Researcher, to talk about Excel, macros and malware.

View Details

How is an insider threat incident response like a murder investigation?

You start with motive, then leverage investigative tools and knowledge of people to unearth a trail of mistakes. (Yes, it’s actually quite exciting!)

In this episode, series host Sai Chavali speaks with fellow Protecting People host Brian Reed, Cybersecurity Evangelist at Proofpoint, about insider threat cases and what makes a successful incident response.

Join us as we discuss:

  • The three buckets of insider threats
  • Specific insider threat cases every investigator should study
  • Asking “who, what, why, and when” to protect against insider threats
  • How incident response can be like a murder investigation

Check out these resources we mentioned:

  • Report mentioned at [5:47]

2020 Cost of Insider Threats: Global Report

  • Proofpoint blog post mentioned at [8:19]

The Top 10 Biggest and Boldest Insider Threat Incidents, 2020-2021

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of October 4th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast. 

  • The U.K. makes plans to strike back against future cyber attacks
  • President Biden rallies international support in the fight against ransomware
  • Six thousand Coinbase customers fall victim to an account recovery vulnerability

Joining us is Selena Larson, Proofpoint Senior Threat Analyst, to talk about a series of campaigns by prolific threat actor, TA544. 

View Details

Five Minute Forecast for the week of September 27th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast. 

  • No honor among thieves as REvil is caught stealing by its own affiliates
  • America’s food supply under attack from Ransomware
  • New mobile malware emerges in North America

Joining us is Adam McNeil, Senior Threat Researcher at Cloudmark to discuss a new mobile malware emerging in the U.S. and Canada.

View Details

Gone are the days of 2016 when we saw 12 million ransomware attachments randomly blasted out per day. It’s 2021 now, when threat actors selectively deploy ransomware against high value targets across the victim organization’s entire network in order to secure initial access.

Why is initial access so often overlooked in protecting against the multiplicity of ransomware threats?

In the inaugural episode of our Threat Digest series, series hosts Selena Larson and Crista Giering, Senior Threat Intelligence Analysts at Proofpoint, interview Daniel Blackford, Senior Threat Researcher at Proofpoint, about initial access and what can happen afterwards.

Join us as we discuss:

  • The evolution of ecrime in the past five years
  • Initial access, dwell time, and the prevalence of Cobalt Strike activity
  • What white glove ransomware treatment is like
  • Tips for protecting your org against multiple malign actors at various stages of an attack

Check out the report we mentioned during the podcast:

-The First Step: Initial Access Leads to Ransomware

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of September 20th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast. 

  • The government blitz on cyber crime takes aim at Bitcoin
  • Grief ahead for victims of one ransomware gang
  • The FBI counts the cost of romance scams

Joining us is Proofpoint Senior Threat Researcher, Daniel Blackford, to discuss the relationship between ransomware and cryptocurrency. 

View Details

Guess how many organizations found they had an insider threat incident at least once — 69%.

Of the remaining 31%, it’s most likely the case that they simply don’t have the capability to identify insider threats, not that they were incident-free.

In this episode, series host Sai Chavali speaks with Proofpoint’s Deborah Watson, Resident CISO, and Jeremy Wittkop, Senior Director, Technology Services, PCMS, about jumpstarting a successful insider threat program.

Join us as we discuss:

  • What insider threats are and where they can come from
  • How to monitor for the unknown
  • Why insider threat training needs to be frequent and reinforced
  • How to build and measure your insider threat program

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of September 13th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast. 

  • Cyber criminals infiltrate the UN
  • Vacation’s over as REvil returns
  • And Yandex is battered by a history-making attack

Joining us is Proofpoint Threat Analyst, Davide Canali, to discuss a cryptocurrency spin on one of the oldest attacks in the books. 

View Details

Five Minute Forecast for the week of September 6th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast. 

• Billions of devices at risk from Bluetooth bugs 

• Ransomware source code leaked online 

• Funny business on Banksy’s website – but for once the artist isn’t to blame 

Joining us is Sherrod DeGrippo, Proofpoint’s Vice President, Threat Research and Detection, to discuss the perennial threat of business email compromise. 

View Details

Five Minute Forecast for the week of August 30th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Tech’s biggest hitters join the fight against cyber attacks
  • Samsung reveals a secret ‘kill switch’ hidden in its televisions
  • Attackers are still profiting from fear and doubt over the pandemic

Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, to discuss how cyber criminals are continuing to use the pandemic in their attacks.

View Details

Five Minute Forecast for the week of August 23rd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Anonymous sources confirm a potentially serious breach at the State Department
  • Data theft puts telecom giants in the spotlight
  • A ransomware gang seeks insider help

Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, to talk the insider threat of ransomware.

View Details

Remote desktop protocol, email vector, and VPN — the three most common methods of ransomware attack. However, virtually 100% of all attacks still rely on human vulnerability, not software vulnerability…

Making security awareness training one of your most valuable shields against ransomware.

In this Expert Insights episode, we interview Neko Papez, Manager, Product Marketing at Proofpoint, about changes in the ransomware threat landscape and how Proofpoint can help.

In this episode we discuss:

  • Why ransomware is such a common attack type

  • The importance of ransomware education

  • How to help users become aware and on guard

Check out these resources we mentioned during the podcast:

  • Proofpoint’s ransomware kit

  • A ransomware webinar

  • The Threat Insight blog

To hear more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, or your preferred podcast platform.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of August 16th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Most Americans think the government can’t keep them safe from cyber attacks
  • DarkSide still tapping Colonial Pipeline months after their initial breach
  • A cryptocurrency thief steals a record haul before giving it all back

Joining us is Ryan Kalember, Proofpoint’s EVP, Cybersecurity Strategy, to discuss the latest developments in the ongoing ransomware crisis.

View Details

What is it that we didn’t know that we should have known?

Many incident response plans miss this crucial question, but it’s absolutely foundational to learning how you can prevent the incident from happening again.

In this episode, we talk with Matt Stamper, CISO at EVOTEK, about the most important elements of an incident response plan and why security awareness has the largest return from a threat mitigation perspective.

What we talked about:

  • Getting started with incident response

  • Untangling conflicting priorities in the process

  • Widening the circle of concern with regard to insider threats

  • Investing in security awareness

Check out these resources we mentioned during the podcast:

  • TheHLayer.com

  • CISO Desk Reference Guide: A Practical Guide for CISOs (Vol. 1)

  • CISO Desk Reference Guide: A Practical Guide for CISOs (Vol. 2)

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for P rotecting People in your favorite podcast player.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

Five Minute Forecast for the week of August 9th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • CISA announces a new public-private task force featuring some of the biggest names in tech
  • The Conti ransomware gang’s playbook leaks online
  • And millions of home internet routers potentially at risk

Joining us is Brian Reed, Proofpoint’s cyber security evangelist, to talk about how enterprise-scale businesses are responding to the current wave of cyber attacks.

View Details

Five Minute Forecast for the week of August 2nd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Don’t ban ransomware payments, the FBI warns congress
  • A new ransomware gang rises from the ashes of REvil and DarkSide
  • And Iranian cyber attackers play the long game

Joining us is Sherrod DeGrippo, Proofpoint’s Senior Director of Threat Research and Detection, to explain why some threat actors spend so long developing relationships with their victims.

View Details

Five Minute Forecast for the week of July 26th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • China denies involvement in cyber crime and points the finger at the United States
  • Kaseya unlocks ransomed systems after getting its hands on an R-Evil decryption key
  • More printer woes for Windows users as yet another vulnerability is discovered

Joining us is Ryan Kalember, Proofpoint’s Executive Vice President of Cyber Security Strategy, to discuss how cyber security has become a part of the global political conversation.

View Details

Fraudsters who perpetrate BEC and various other types of email scams are a serious and continuous threat to businesses today. In 2019, there were 26.2 billion dollars in reported losses from these kinds of malicious malware attacks.

For part two of our Expert Insights into Business Email Compromise (BEC) and email fraud protection, host Sherrod DeGrippo leads a lively discourse with Robert Holmes, Sr. Director of Threat Research and Detection, and Sam Scholten, CISSP, and Staff Email Fraud Researcher, both of Proofpoint — a company at the forefront of using AI and machine learning for radical, comprehensive threat protection.

Here's a sneak peek:

  • The small but crucial differences between DDoS extortion and a BEC attack.

  • The next generation of how Proofpoint is stopping these threats with deep analysis of every email for metadata signs of intrusion.

  • Fascinating samples of previous attacks and highly creative threat actors who leveraged social cues to launch an attack.

  • Successful scams take advantage of human nature and the fundamental vulnerability of individuals.

To hear more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, or your preferred podcast platform.

View Details

Five Minute Forecast for the week of July 19th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • Human rights activists around the world are targeted with military-grade spyware
  • Yet more trouble at Solar Winds, as a new zero day vulnerability lets in attackers
  • A high-profile ransomware group goes dark, but are they really gone or just on vacation?

Joining us is Sherrod DeGrippo, Proofpoint’s Senior Director of Threat Research and Detection, to explain what’s really happening when cyber criminal groups go on hiatus.

View Details

Five Minute Forecast for the week of July 12th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • A patch is released for Microsoft’s Printer bug, but the nightmare isn’t over for everyone
  • Attackers send out fake security updates for the recent Kaseya supply chain breach
  • And a ransomware gang’s gotta catch ‘em all as they demand rare Pokemon cards as payment

Joining us is Proofpoint Cybersecurity Evangelist, Brian Reed, to discuss Solar Winds, Kaseya, and the growing threat of software supply chain compromise.

View Details

Business Email Compromise, or BEC, is a type of scam that utilizes social engineering to trick companies into paying fraudulent invoices or giving up sensitive information that can be used for a future attack.

Malware, phishing, BEC, and thread hijacking. The “baddies,” as one of today’s guests charmingly anoints them, utilize these deep, complicated attacks because the rewards are so very great - in 2019, stats from the Internet Crime Complaint Center showed losses over $1.7 billion.

Join host Sherrod DeGrippo for part one of this in-depth discussion, as she talks through various current threats and how companies can defend against them with email fraud defense experts Robert Holmes, Sr. Director of Threat Research and Detection, and Sam Scholten, CISSP Staff Email Fraud Research, of Proofpoint.

Here's a sneak peek:

  • Learn the signs of suspicious emails

  • Threat actors are putting a high amount of energy into today’s scams

  • BEC is a global problem

  • Stricter financial controls can help your company along with EFD

To hear more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, or your preferred podcast platform.

View Details

Five Minute Forecast for the week of July 5th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • No letup in sight from the recent wave of cyber attacks
  • Solar Winds still blowing as notorious attacker strikes again
  • And cracked versions of popular video games provide a crypto-mining bounty

Joining us is Proofpoint Threat Researcher Selena Larson with a primer on how cyber criminals are using a legitimate security testing tool called Cobalt Strike to make their attacks even more effective.

View Details

Proofpoint has concluded 3 of their 2021 conferences: Wisdom, Protect, & Protect EMEA with great success; highlighting their guest speakers and information protection—the show takes a behind-the-scenes look at the action.

Tim Choi, Vice President Product Marketing at Proofpoint, joins the show to discuss the Proofpoint conferences.

What we talked about:

  • The Structure of the Protect, Protect EMEA, & Wisdom Conferences

  • Discussing the Conference Panel Participants

  • COVID-19 and the Information Protection Transformation

  • Security Awareness Training within an Organization

Check out these resources we mentioned during the podcast:

  • Protect Conference 2021 - Day 1 Recap

  • Protect Conference 2021 - Day 2 Recap

  • Wisdom Recap

To hear more interviews like this one, subscribe to the Protecting People Podcast on Apple Podcasts, Spotify, or your preferred podcast platform.

View Details

Five Minute Forecast for the week of June 28. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.

  • The NSA opens its doors to the cyber security research community
  • San Francisco’s water supply is threatened by a digital breach
  • And copyright activists block access to piracy sites with an unusual piece of malware

Joining us is Proofpoint Threat Researcher Selena Larson, to explain why cyber criminals are now operating fake movie streaming sites and support call centers.

View Details

Five Minute Forecast for the week of June 21. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast

  • Presidents Biden and Putin butt heads over cyber security strategy
  • US businesses pay big money to ransomware gangs, but the FBI is clawing some of it back
  • And attackers hide in plain sight on Steam – a popular gaming platform

Joining us is Proofpoint Threat Researcher Daniel Blackford, giving the lowdown on the steganography techniques attackers are using to place malware on the Steam platform.

View Details

About 85% of threats involve some sort of human interaction, and about 50% of organizations have experienced a successful phishing attack.

So, attacks are overwhelmingly focused on people.

In a recent Expert Insights episode of Protecting People, we spoke with Brett Shaw, Senior Product Marketing Manager at Proofpoint, about some of the latest trends in the threat landscape — and how to protect people from them.

What we talked about:

  • Email is the easiest way to prey on vulnerabilities

  • Reducing risk means developing a multi-layered approach to security

  • A system is only as good as the data that feeds it, but…

  • Human action can overset any system with just one click

Check out these resources we mentioned during the podcast:

  • The State of the Phish 2021

  • The Verizon DBIR report [referenced at 3:28]

  • Email Fraud and Security Awareness Kit [referenced at 4:57-5:46]

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

Let’s talk about the adversarial relationship between end users and vendors.Things could improve in both directions.

In this episode, we interview Dan Holden, VP of Cyber Security at BigCommerce, about anger, angst, and ‘forgivability’ in the vendor/end user relationship.

What we talked about:

  • It’s more about fit than about vendor or product

  • The advantages of building a vendor relationship with a startup

  • The CISO’s role in understanding the vendor landscape

  • 3 questions for the CISO to ask to set vendor priorities

You’re invited to Protect 2021 on June 8-9.

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

Dan Holden, VP of Cybersecurity at BigCommerce takes a threat centric angle when discussing information security. He emphasizes the importance of awareness around the extent of cybercrime capability.

What we talked about:

  • Different ways to handle information security

  • Changes in the threat landscape

  • External aspects of cybercrime capability

  • Framework vs. Strategy

Check out these resources we mentioned during the podcast:

  • Proofpoint Protect 2021

For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.

Listening on a desktop & can’t see the links? Just search for Protecting People n your favorite podcast player.

View Details

The new world has changed our concerns about how information is accessed and handled. Remote work has accelerated the insider threat, insider risk, and DLP concern. The need for information protection is at an all-new high.

In this episode in our Inside Line on Information Protection series, host Brian Reed chatted with Tim Choi, Vice President Product Marketing at Proofpoint, about information protection and the upcoming Protect 2021 conference.

What we talked about:

  • New information protection situations Tim has seen

  • Why Protect 2021 is focused on customers

  • Where to register for Protect 2021

Check out this resources we mentioned during the podcast:

  • You’re invited to attend Proofpoint Protect 2021

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

We’ve been joined by Gretel Egan, Senior Security Awareness Training Strategist at Proofpoint, to discuss this year’s State of the Phish (SOTP) Report, where we get an in depth look at user awareness, vulnerability and resilience.

This episode covers:

  • A breakdown of what goes into the SOTP report and where the data is sourced from

  • The broadness of the term ‘phishing’ and what it includes or means, in the context of the data

  • The application of phishing techniques across different media

  • How the COVID-19 pandemic gave attackers the opportunity of a lifetime

  • How to measure informational security preparedness and awareness within your organization

  • The resilience ratio, and how automated reporting can improve this figure for your organization

Below is the link to access this year’s State of the Phish Report:

  • The 2021 SOTP Report

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

When everyone is feeling overwhelmed by taxes and afraid of doing something wrong, that’s when the phishing, smishing, and website impersonation reaches its height.

How can we reassure and train our employees about tax-related scams?

In this episode of our Expert Insights series, we interview Susan Mackowiak, Senior Director, Program Content at Proofpoint, about resources to avoid being a victim of a tax scam.

What we talked about:

  • What scammers are trying to accomplish

  • How the IRS contacts you and how to contact the IRS

  • An overview of the contents of Proofpoint’s Tax Awareness Kit

Check out these resources we mentioned during the podcast:

  • Tax Season Awareness Kit

  • 7th Annual Report for the State of the Phish

  • The IRS’s phishing reporting site

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

If you’re asking which information protection platform to choose, that’s not deep enough. It’s intellectually lazy.

Too often, we make technology decisions instead of programmatic decisions.

In a recent episode in our Inside Line on Information Protection series, we chatted with cybersecurity executive Jeremy Wittkop about reimagining DLP as a method for protecting people first.

We also talked about:

  • Why technology solutions don’t help CSOs discuss data protection
  • Multilingual services, behavioral analytics, and resource distribution
  • IT budgets and security budgets are not the same
  • Genuinely measuring and analyzing risk

Resources we mentioned during the podcast:

  • Activate Your Brain by Scott G. Halford
  • How to Measure Anything in Cybersecurity Risk by Hubbard and Seiersen

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

When we’re looking ahead at 2021 in information governance and regulatory changes, what will define the cybersecurity industry?

In this second of two episodes featuring regulatory changes in our Expert Insights series, John Pepe, Resident Chief Compliance Officer and Regulatory Counsel at Proofpoint, and Sonali Bhavsar, technology executive, forecast governance in 2021.

What we talked about:

  • The importance of voice as a data footprint

  • What to supervise for remote workers

  • The challenge of creating a use case with archiving, supervision, and behavior analytics all as separate products

  • Expectations on the regulatory side, plus new technologies

  • Machine learning for entity mapping

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

In addition to focusing on malicious actors trying to gain access to your networks and your systems, are you just as focused on making sure that the people who already have access are doing what they’re supposed to be doing?

Insider Threat detection is one of the most underutilized, but overlooked aspects of any cybersecurity organization.

On this episode of The Inside Line on Information Protection, we talk with Larry Ponemon about:

  • Why every company regardless of size, should be running Insider Threat programs

  • The astronomical cost of Insider Threat investigations

  • Why good people making silly mistakes may be more damaging that bad actors doing bad things

  • The easiest way into a Fortune 50 company (it’s probably not what you think)

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

Introducing our new series: Inside Line on Information Protection.

In this show, we’ll welcome expert guests with diverse backgrounds in information protection to discuss topics like insider threat, information governance, and cloud security.

In this inaugural episode, host Brian Reed is joined by Catherine Hwang, Director of Product Marketing for Information Protection Products at Proofpoint.

What we talked about:

  • The topics that will be covered in the series

  • Why legacy DLP solutions aren’t solving customer challenges

  • Wanting to solve more than one problem at a time with DLP budgets

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

Governance, AI, analytics, and regulation — 2020 sure changed a lot.

Good data hygiene looks totally different now, as does so much in the regulatory financial services realm.

In this first of two episodes featuring regulatory changes in our Expert Insights series, John Pepe, Resident Chief Compliance Officer and Regulatory Counsel at Proofpoint, and Sonali Bhavsar, Technology Executive, discuss what’s changed in governance 2020.

What we talked about:

  • How communication data has exponentially shifted

  • Regulatory and legal changes surrounding data

  • Best practice guidance for insider threats

  • What CFTC guidance means for technology best practices

  • AI, machine learning, and transaction surveillance/transaction supervision

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.

View Details

People spend over 3.5 hours on their mobile phone every day, and 50% of that time is spent on social media.

If you think your employees aren’t representing your company on social media platforms, you’re just plain wrong.

In this episode, we interview Amanda Anderson, Product Marketing Manager, Compliance at Proofpoint, about understanding security risks on social media from a people-centric perspective.

What we talked about:

  • How social media is integral to modern business

  • Trends and types of social media-related risks

  • How technical and administrative controls play a role in social media compliance and security

Resources we mentioned during the podcast:

  • Proofpoint & Hootsuite’s webinar: How to Design an Adaptable, Flexible and Compliant Social Selling Program

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Data doesn’t lose itself.

A person loses the data.

What, exactly, do we mean when we talk about people-centric security?

In our latest People Variable episode of Protecting People, Brian Reed, Cybersecurity Evangelist at Proofpoint and former Gartner analyst, talks to us about data loss prevention.

What we talked about:

  • 3 reasons you would ever start a DLP project

  • How to talk to your CISO about data loss

  • Communication is everything in security awareness training

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Cloud account takeover activity has skyrocketed in 2020. When the security perimeter of your org is your people, how they access the cloud matters.

In this episode of our People Variable series, we spoke with Itir Clarke, Sr. Product Marketing Manager at Proofpoint, about risks people pose in the cloud.

What we talked about:

  • One in six people use the same 1-2 passwords

  • Why cloud security is of growing importance for awareness programs

  • Two easy steps to address account compromise

Check out this resource we mentioned during the podcast:

  • Getting Started with CASB

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

It’s the most wonderful time of the year. If you’re a hacker, that is.

Holiday season is always the time of the year when we see cyber attacks go through the roof. Why?

Because people are stressed out, they’re in a hurry, and they aren’t always paying close enough attention to things as they should.

After all, when Amazon emails you and tells you your package is going to arrive late, you take action, right?

Susan Mackowiak stopped by the Protecting People podcast recently and had a couple of thoughts to keep you and your loved ones safe this holiday season. We talked all about:

  • How hackers utilize fear to get what they want

  • Why you should do your shopping on a computer instead of your phone

  • Why you should be wary of ads on social media, even if they appear to be from brands you trust

  • Why people are the weakest link in the security chain

Find additional content, like our 2020 Holiday Security Awareness Training Kit and Best Practices Guide, and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Cybercriminals may be nefarious, but they are also people.

And people have habits.

If you want to stop one, it helps if you learn them.

In our latest episode, we’re speaking with Wes Drone, Sr. Manager, Threat Intelligence, at Proofpoint and a former FBI Agent, about what a typical day looks like for the people stopping threat actors by thinking like them.

We discuss:

  • Wes’ transition from the FBI to threat intelligence

  • The habits of threat actors

  • How Wes tracks individual threat actors

Find additional content, like our Insider Risk Threat Assessment and Guide to Building a Security Awareness Program that Works, and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Nobody wants to view employees as insider threats. Yet in the last 2 years, there have been about 40% more insider threat incidents - almost 1 in 3 breaches involves insider threats.

In this first episode of our People Variable miniseries, we interview Sai Chavali, Sr. Product Marketing Manager at Proofpoint, about insider threats.

What we talked about:

  • The 3 types of people-centric insider threats

  • Providing targeted security awareness about insider threats

  • How insider threats are changing the security landscape

Find additional content, like our Insider Risk Threat Assessment and Guide to Building a Security Awareness Program that Works, and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Would you pay the ransom?

There are 4,000+ ransomware attacks per day with $3.5Bn lost in just 2019.

Looks like the answer is Yes.

In our 6th episode to understand the mind of cybercriminals, your Protecting People hosts learn all about ransomware from Christopher Budd, Principal at Christopher Budd Security, and Ryan Kalember, EVP, Cybersecurity Strategy at Proofpoint.

What we talked about:

  • What ransomware is & why people pay

  • How to pay your ransomware attacker

  • Professionalism among cybercriminals! Some have stopped attacking the healthcare industry during COVID-19

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

The word malware comes from “malicious” + “software” — and it’s as bad as it sounds.

To get inside the minds of cyber criminals, we asked 2 security experts to teach us about malware.

In this episode, we interviewed Christopher Budd, Principal at Christopher Budd Security, and Sherrod DeGrippo, Sr. Director, Threat Research and Detection at Proofpoint, about how to get and avoid malware.

What we talked about:

  • What malware is & how to get it

  • Different types of malware like rats & banking Trojans

  • COVID-themed lures vs. classic lures for malware

  • Whether it’s better business sense to buy or build your own malware

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

We recently put this question to three security awareness experts:

Where do you start with a company-wide training program?

In this #TacklingUserBehavior episode, we interview Eddie Whittingham, founder of the recently-acquired The Defence Works, Kurt Wescoe, Former CMU Faculty and Chief Architect at Proofpoint Security Awareness Training, and Robert Shields, Sr. Product Marketing Manager at Proofpoint.

What we talked about:

  • The need to have specific goals instead of doing “everything”

  • Donuts as an excellent motivator

  • Incorporating personal examples into training

  • Focusing on your organization's unique risks and user landscape to tailor education

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Not all cybercriminals are evil. Some send phishing emails to their coworkers for their own good.

We’re talking about simulated phishing emails for education.

In this episode, we interview Jason Riegner, Jr Front End Developer at Proofpoint, about the Microsoft TEAMS phish he designed, which most of us fell for.

What we talked about:

  • How to identify a phishing email

  • What to do & especially what not to do when you get one

  • The nuanced design of phishing emails, from intricate to innocuous

  • We had a contest! Who wins our respect?

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

BEC, or Business Email Compromise, is when an attacker disguises themselves to look like a trusted person.

But EAC, or Email Account Compromise, is when an attacker actually compromises an email account. They can start sending emails as, well, you.

In this episode, we hear from past guests Rob Holmes, Sherrod DeGrippo, & Mike Bailey about how to access and compromise a legitimate mailbox.

What we talked about:

  • BEC & EAC attacks caused more than $26 billion in losses since 2016

  • Why a real estate agency is a great target for a new cybercriminals

  • How to leverage people skills to make believable demands for money

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Wouldn’t it be great if security training were so exciting that employees started begging for the next episode? Security training should feel like watching your favorite sketch comedies.

In this episode, we interview Eddie Whittingham, Founder of The Defense Works and former police officer and lawyer, about his inspiration for humorous, interactive security training.

What we talked about:

  • Finally, the end of traditional security training

  • How interactive comedy affects user behaviors

  • The process of creating training episodes with comedy writers

  • Eddie’s goal to push the boundaries of what security training means

Check out these resources we mentioned during the podcast:

The Defense Works’ YouTube channel gives you a taste of their training

Their blog is pretty funny, too

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Security is like having a foolproof safe. Privacy is like telling everyone the combination.

When it comes to the complex security and privacy landscape, where do you even start with awareness training?

In this episode of the #TacklingUserBehavior series, we interview Daniel Solove, Founder of TeachPrivacy and John Marshall Harlan Research Professor of Law at the George Washington University Law School.

What we talked about:

  • The overlap between privacy and security

  • The “hub and spokes” approach to training employees in security

  • The qualities of effective privacy training

  • Enforcement in the age of COVID-19

Check out this resource we mentioned during the podcast:

  • Daniel has a Privacy + Security blog

  • Register for our August 18th webinar: https://www.proofpoint.com/us/webinars?id=416919

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

80% of what you need to be a cybercriminal is Internet access.

The other 20% is mostly social engineering. Effective cybercriminals understand how people think.

In this episode, we interview Robert Holmes, VP and General Manager, Email Fraud Defense at Proofpoint, about the easy process for business email compromise (BEC) attacks.

What we talked about:

  • Smaller companies are more likely to be victimized than larger companies

  • Cybercriminals pretend to be a trusted persona (like your CEO)

  • Super easy but insidious tech tips that people fall for all the time

  • Phishing, vishing & smishing: What are they?

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Users still clicking phishing emails? Reusing passwords?

Don't worry - you're not alone.

In this inaugural episode of our new #TacklingUserBehavior series, we interview Kurt Wescoe, VP of Engineering at Proofpoint and former Carnegie Mellon University faculty, about how to achieve successful user behavior change.

What we talked about:

  • The importance of user buy-in and engaging security awareness programs

  • Contextualizing education for users might mean incident-by-incident training

  • How to be adaptable in setting achievable goals

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Your workers are 100% remote now… using their personal devices and personal accounts for work. Cybercriminals will capitalize on their shock and fear to cause as much data loss as possible.

In this #ExpertInsights episode, I interview Tim Choi, VP of Product Marketing at Proofpoint, about how to protect your people from cybercrimes… remotely.

What we talked about:

  • Examples of shock-based phishing (some are quite clever)

  • What employees can do to protect themselves

  • What employers can do to protect employees & data

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Do you think you have what it takes to be a cybercriminal? It’s not a profile you might expect: high in people skills… low in tech.

In this episode, we interview Adenike Cosgrove, Director of International Product Marketing at Proofpoint, about skills that cybercriminals need.

What we talked about:

  • Ideal places to live for cybercrime

  • People skills, not tech skills

  • Who criminals research — VAPs (very attacked people)

  • Examples of successful cyber crimes

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or on our website.

View Details

Regulatory change can inspire downright terror in many of us. When that happens, the best thing to do is search for insights from experts.

In this episode, the first in our #ExpertInsights series, we interview Guy Levitt, CEO at TeleMessage, and Nigel Cannings, CTO at Intelligent Voice, about the myriad challenges of recording voice calls.

What we talked about:

  • Everything can be retrieved in WhatsApp

  • Why regulations are so apparently conflicting and definitely confusing

  • Predictions about the future of regulation

  • California will come after you if you are in breach of two-party consent

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or on our website.

View Details

Privilege is an entity's degree of power within an org.

Think technical access, like a DevOp manager’s ability to manipulate sensitive files and systems.

Or a finance team member’s authority to issue wire transfers on behalf of the org.

We are rounding out our series on risk by interviewing Roie Cohen Duwek, Director of Security Research at Proofpoint, about privilege-based attacks.

What we talked about:

  • Why EAC attacks are so insidious and effective

  • Privilege abuse and cloud-based attacks

  • Ways that legitimate accounts get compromised

  • What CISOs should do to protect their employees

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or on our website.

View Details

If you could send an email as anyone, who would it be? You might pick an executive assistant, the agent of your favorite band, or a payroll employee.

Jumping from persona to persona is the game that hackers are playing now.

In this episode, we interview Sherrod DeGrippo, Sr. Director of Threat Research and Detection at Proofpoint, about the psychology of today’s hackers.

What we talked about:

  • The psychology of threat agents and how they bounce across personas in an organization

  • Analyzing attacks from a people-centric viewpoint

  • The pattern and process of attacks, start to finish

  • Tools and technology to reduce vulnerabilities

Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.

View Details

Just 61% of survey respondents knew what the definition of phishing was — and that was from a multiple-choice list.

This response is a huge indication of the language gap between InfoSec and users, which speaks to the urgent need for security awareness training.

In this episode, we interview Gretel Egan, Security Awareness and Training Strategist at Proofpoint, about the extent of vulnerabilities.

What we talked about:

  • What effective security awareness training looks like

  • The 2020 State of the Phish Report’s robust data

  • How employees are putting their organizations at risk

  • Pain points for companies (55% had a successful attack)

Check out this resource mentioned during the podcast:

  • The 2020 State of the Phish Report

Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.

View Details

Why would you do something hard when you could do something easy? That’s exactly what attackers are thinking.

99% of attacks rely on duping a human to run malicious code.

In this episode, we interview Ryan Kalember, EVP of Cybersecurity Strategy at Proofpoint, about why today’s attacks are about people, not infrastructure.

What we talked about:

  • Social engineering is at the heart of over 99% of cyberattacks

  • 26 billion cyberattacks are only a tiny fraction

  • Industry focuses on technology while attackers focus on people

Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.

View Details

There are only two types of companies in the world today: companies that are compromised and companies that don’t know they’re compromised. Which one is yours?

In this episode of Protecting People, we interview Prasanna Ramakrishnan, Global Head of Infosecurity Risk at Signify, about the fact that we are all living in a continuously compromised state.

What we talk about:

  • Smart devices in your home can be hacked

  • People are the weakest link in the security chain

  • The 2 types of companies out there

  • Awareness training and other effective security controls

Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.

View Details

The biggest cybersecurity challenges are the wicked problems, the unsolvable, people-based problems.

A lot of security is getting into the “wicked problem” space at this point.

On this episode, we interview Adrian Ludwig, CISO at Atlassian, about how he protects people against people-based risks:

What we talked about:

-Challenges in communicating risk effectively to people

-Creating layered systems to protect against training failures

-Finding hidden expectations in your workplace and among consumers

-Where cybersecurity is headed in 2020

Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.

View Details

85% of execs identified that most cybersecurity breaches are a result of human vulnerabilities. Not because of technology. Because of people.

Listen in to hear 2 ways that companies are responding to protect themselves from people-based threats.

On this episode, we interview Robert Powell, Editorial Director Americas and Thought Leadership at The Economist Intelligence Unit:

What we talked about:

-The most surprising statistics from Robert’s latest report

-Who is most likely to be targeted at a company

-How companies are protecting themselves from people-based threats

-What it means to practice good digital hygiene

Check out the report we mentioned during the podcast:

Cyber Insecurity: Managing Threats from Within

Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.

View Details

Today’s cyber criminals target regular people. Chief financial officers. Fifth grade teachers. Your grandmother. (You get the picture.) 

It’s sometimes hard to find the human perspective behind these attacks and the strategies we use to fight back. 

This is why we’re incredibly proud to launch our new podcast, Protecting People: Cybersecurity for the Rest of Us. 

What you’ll hear: 

  • Industry leaders on today’s top cybersecurity threats 

  • Security challenges for email fraud & phishing 

  • Best practices for email encryption & email archiving 

Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.