Today’s cyber attacks target people, not technology. Protecting People is a podcast focused on the human side of cybersecurity. Each episode, you’ll learn how today’s threats really work, who’s being targeted by them, and what you can do to safeguard your people, data and systems.Get real-world insight and learn about the latest trends in social engineering, malware, threat protection, cloud security and more. Protecting People is cybersecurity for the rest of us.
Five Minute Forecast for the week of January 30th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
* International law enforcement takes down Hive ransomware
* U.S. officials issue warning about remote monitoring attacks
* A breach at JD Sports exposes data for 10 million customers
And threat researcher Greg Lesnewich joins us to discuss North Korean state-sponsored threat actor TA444.
Five Minute Forecast for the week of January 23rd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
* Microsoft blocks another route used by Excel attackers
* Ransomware profits are falling as victims refuse to pay
* Mailchimp employee falls prey to social engineering
And threat research manager Daniel Blackford joins us to discuss a new campaign using clever salary-related lures. Check out the Threat Insight Twitter: @threatinsight
Five Minute Forecast for the week of January 16th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
* Europol calls time on a chain of pig butchering call centers
* Norton Password Manager accounts targeted in credential stuffing attack
* LockBit affiliate takes aim at the U.K.’s Royal Mail delivery service
And senior threat researcher Joshua Miller shares up-to-the-minute details on a campaign by advanced persistent threat actor, TA450.
Five Minute Forecast for the week of January 9th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
* LastPass breach is the gift that keeps on giving—but all its delivering is bad news for users
* Phished credentials unlock Slack’s GitHub code repositories
* LockBit ransomware says sorry for attack on SickKids hospital in Toronto
And senior threat intelligence analyst Crista Giering shares her headlines and highlights from the 2022 threat landscape.
Five Minute Forecast for the week of December 19th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Five Minute Forecast for the week of December 12th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Patients moved after ransomware attack at a Paris hospital
Looking for a last-minute gift? How about a stolen email address for $2?
Microsoft says the holidays could deliver a new wave of Russian cyber attacks
And email threat researcher Timothy Kromphardt shares his highlights from another busy year of cyber threats.
2022 continued long-standing cybersecurity risks — aligning with our expectations — alongside new harrowing threats. What does that mean for the new year, and what can we do to best prepare for new tricks in 2023?
In this episode, Ryan Kalember, EVP of Cybersecurity Strategy at Proofpoint, joins us to shine a light on best practices for risk prevention, unpack present and potential threats, and more.
Join us as we discuss:
Potential pain points in cybersecurity for 2023
How security leaders should prepare for multiple challenges
Top concerns for security leaders
Register for our Power Series: https://go.proofpoint.com/powerseries#tab3
Five Minute Forecast for the week of December 5th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Car app bugs could let attackers steal vehicles with just an email address
LastPass confirms its second data breach in just four months
And malware-as-a-service makes starting a life of cyber crime even easier
Five Minute Forecast for the week of November 28th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Massive data breach at Twitter exposes millions of phone numbers
U.S. authorities seize pig butchering sites
Pro-Russia “hacktivists” take down the European Parliament website
And senior reverse engineer Pim Trouerbach shares the latest developments with Emotet.
Despite existing security solutions, organizations are continuing to see their user’s information compromised—whether it be business email compromise, ransomware attacks, phishing, or supply chain threats. The ways attackers are targeting people has evolved, but there's one constant in the ever-changing threat landscape; people are still the primary target.
Over the last year, Proofpoint has released several innovations for our overall threat protection platform. In this episode of Protecting People, we invited Neil Hammet, Technical Director at Proofpoint, to join the show to help us understand what these recent innovations mean for our customers. Neil dives deeper into the machine learning technology that is used on the back end to ultimately deliver these capabilities and help our customers.
Join us as we discuss:
Three different types of threats the extortion micro-classifier identifies
The new Inline+API deployment and the philosophical shifts that came with that transition
Proofpoint’s new PX bundle and who the ideal customer for that bundle would be
Check out these resources mentioned:
https://www.proofpoint.com/us/solutions/bundles
https://www.proofpoint.com/us/learn-more/email-rapid-risk-assessment
https://www.proofpoint.com/us/blog/email-and-cloud-threats/inline-api-new-era-email-security
https://www.proofpoint.com/us/blog/email-and-cloud-threats/behavioral-analysis-and-aiml-threat-detection-going-behind-scenes
https://it-harvest.com/shop/security-yearbook-2022/
For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Five Minute Forecast for the week of November 14th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Empty wallets see fingers pointed at FTX insiders
Europol arrests a high-profile member of LockBit
The FBI closes down multiple reshipping domains
And senior threat research engineer Adam McNeil discusses seasonal mobile threats.
Five Minute Forecast for the week of November 7th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
“Hackers for hire” target critics of World Cup host Qatar
Twitter turmoil inspires a phishing expedition
And Emotet returns with some old tricks
And senior threat research engineer Adam McNeil explains the conversational techniques being used by job fraudsters.
Five Minute Forecast for the week of October 31st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Former-U.K. Prime Minister Liz Truss targeted by Russian attackers
Credit card thieves enjoy a two-year spree on See Tickets
Hinge targets scammers with profile verification
And email threat researcher Timothy Kromphardt breaks down all the details on romance scams.
Five Minute Forecast for the week of October 24th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
US authorities warn of a new ransomware campaign targeting healthcare
Attackers use hundreds of mis-spelled domains to distribute malware
And a research update on a new kind of conversational social engineering threat
And email threat researcher Timothy Kromphardt explains the connection between pig butchering and cryptocurrency fraud.
Five Minute Forecast for the week of October 17th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
CISA launches open-source tool for Red Teams
Developer error leaves Toyota customer data exposed
And keyless entry car thieves face being locked up
And threat research manager Daniel Blackford reflects on themes and insights from the recent Virus Bulletin 2022 conference.
Five Minute Forecast for the week of October 10th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Pro-Russia attackers ground several U.S. airport websites
1.2 million credit cards given away in dark web marketing promotion
Crypto thieves strike it big after a breach at Binance
And senior threat intelligence analyst Selena Larson shares key insights from a comprehensive review of pandemic-related social engineering.
How prepared are organizations to deal with a cyberattack? What's the board's relationship with their CISOs?
To find out the answers, Lucia Milica, Global Resident CISO at Proofpoint, joins us to discuss the Cybersecurity: 2022 Boards Perspective Report, where 600 board members from around the world were surveyed to share the boards-eye view of the threat landscape.
Resources:
CISO Hub:
https://www.proofpoint.com/us/ciso-hub
Cybersecurity: 2022 Boards Perspective Report: https://www.proofpoint.com/us/resources/white-papers/board-perspective-report
Voice of the CISO episode: https://podcasts.apple.com/us/podcast/voice-of-the-ciso-insights-from-1-400-cisos-around-the-globe/id1492463146?i=1000561867551
For more episodes like this one, follow Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Five Minute Forecast for the week of October 3rd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Exchange Servers at risk from two major zero-day vulnerabilities
Ransomware gang publishes data stolen in school system attack
Fake CISO profiles flood LinkedIn
We’re joined by former Gartner analyst Jonathan Care, who explains what cybersecurity awareness months means for security professionals.
Five Minute Forecast for the week of September 26th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
London police arrest teen who may be connected to Uber, Rockstar attacks
A highly advanced cyber-spying group found in telecom and university systems
And malicious OAuth cloud apps turn Microsoft Exchange servers into spam networks
We’re joined by former Gartner analyst Jonathan Care, who explains how to identify and protect against insider and external threats.
In preparation for Cybersecurity Awareness Month in October, we invited Lisa Plaggemier, Executive Director at the National Cybersecurity Alliance, to join the show to discuss how to drive behavior change, and how to positively impact your cybersecurity culture.
Join us as we discuss:
What it means to “See Yourself in Cyber” and staying safe online
How behavioral science plays a role in driving a positive security culture
How to measure success of good security culture program
Check out these resources mentioned:
https://staysafeonline.org/
https://www.proofpoint.com/us/cybersecurity-awareness-hub
For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Five Minute Forecast for the week of September 19th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Attackers breach Uber’s internal systems
Thieves make off with Grant Theft Auto VI code
And a new phishing campaign uses the Queen’s death to steal credentials
And senior threat researcher Joshua Miller discusses multi-persona impersonation—a new technique employed by Iran-aligned attacker, TA453.
Five Minute Forecast for the week of September 12th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Ransomware attacks on schools set to rise
North Korean attackers set their sights on the energy sector
Former Conti members teach a new dog some nasty tricks
And Proofpoint VP Threat Research and Detection Sherrod DeGrippo on the threats that keep security leaders up at night.
Five Minute Forecast for the week of September 5th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Ransomware locks up a Los Angeles school district
Attackers score big on a security fumble by the 49ers
Researchers find malware embedded in space telescope images
And threat research engineer Michael Raggi talks cyber espionage on the South China Sea.
September 2022 is the fourth annual National Insider Threat Awareness Month. This month is dedicated to emphasizing the importance of safeguarding our nation and organization by detecting, deterring, and mitigating insider threats.
In honor of National Insider Threat Awareness Month, we invited Jonathan Care, Cybersecurity Expert and Former Gartner Analyst, to join us to help bring awareness to this crucial topic and dive deeper into insider risks and threats within organizations.
Join us as we discuss:
The difference between insider threat and insider risk in organizations
Some of the common behavior patterns that indicate there might be insider threat or risk going on with employees
The value of implementing an Insider Threat program within an organization
Resources:
https://cybersecurityforward.it.wisc.edu/wp-content/uploads/sites/1326/2020/02/Building-Incident-Response-Scenarios-for-Insider-Threats-Brian-Reed.pdf
www.proofpoint.com/us/resources/threat-reports/cost-of-insider-threats
www.proofpoint.com/us/reduce-insider-risk/insider-threat-management-hub
For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Since 2003, the United States has recognized the month of October as Cybersecurity Awareness Month. In preparation for October, Dr. Bob Hausmann, Assessment and Learning Architect at Proofpoint, joins the show to discuss how to build a strong security culture, and why it's essential to do so.
Join us as we discuss:
3 aspects that define organizational cultures and the key elements of building out a strong security culture
The impact of having a good security culture
Why training alone isn’t sufficient for building a great security culture
How to reinforce a security culture within an organization
Check out these resources we mentioned:
https://www.proofpoint.com/us/cybersecurity-awareness-hub
https://www.amazon.com/Cognitive-Science-Educators-suggestions-evidence-based/dp/1912906716
For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Five Minute Forecast for the week of August 29th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Quantum computing is nearly here and quantum-enabled cyber criminals won’t be far behind
The attacker behind SolarWinds casts a “MagicWeb”
Lockbit bites back after last week’s distributed denial of service attack
And threat research manager Daniel Blackford joins us to discuss seasonality in the cyber crime landscape.
Five Minute Forecast for the week of August 22nd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Apple releases urgent security patch with millions of devices at risk
Lockbit points the finger, saying one of its ransomware victims is trying to retaliate
Why a Grammy-winning music video could be bad for your hard drive’s health
And threat researcher Joe Wise joins us to discuss TA558’s attacks against the travel industry.
Five Minute Forecast for the week of August 15th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
U.S. authorities turn up the heat on Conti with a $10 million reward
Call center nightmares continue as telephone-oriented attacks surge by over 600%
Signal messaging accounts caught up in last week’s smishing attack on Twilio
And senior threat research engineer Adam McNeil joins us to explain the similarities and differences between email and SMS phishing.
Five Minute Forecast for the week of August 8th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
U.S. and Australian cybersecurity agencies reveal last year’s most prolific malware
Cloud software giant Twilio hit with a sophisticated SMS phishing attack
Security flaws could allow attackers to send fake messages through the Emergency Alert System
And senior threat intelligence analyst Selena Larson joins us to discuss a new malware campaign targeting cryptocurrency and decentralized finance.
In this episode of Protecting People, Host Lucia Milica, Global Resident CISO at Proofpoint, speaks with Patrick Gaul, Executive Director of the National Technology Security Coalition, as they discuss the 2022 NTSC 5th Annual National CISO Policy Conference. This event hosts CISOs and technology security executives from all over the United States to come together and discuss today's top issues impacting cybersecurity policy and legislation. Lucia and Patrick share their key learnings and updates from their time in Washington DC, as well as some of the latest industry development security professionals need to know about.
Join us as we discuss:
Three of the biggest takeaways from the conference for CISOs and security leaders
The latest developments in Congress regarding the proposed American Data Privacy and Protection Act
The shortage of cyber professionals and the challenges of cyber workforce development
Check out these resources we mentioned:
https://www.proofpoint.com/us/ciso-hub
For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Five Minute Forecast for the week of August 1st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
The FCC says SMS phishing attacks are on the rise and targeting U.S. consumers
A new phishing-as-a-service platform targets big name banks
New data shows a second quarter decline in average ransomware payments
And senior threat intelligence analyst Selena Larson joins us to discuss how Microsoft’s macro blocking policy is affecting the threat landscape.
Five Minute Forecast for the week of July 25th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
The FBI warns investors to be on the lookout for fake crypto appsDetails of over five million Twitter users for sale after data breach
Microsoft moves ahead with its plan to auto-block macros
Joining us to discuss threat actor attribution and state-sponsored activity in the Middle East is senior threat researcher Joshua Miller.
Five Minute Forecast for the week of July 18. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Media outlets face increasingly advanced espionage attempts
H0lyGh0st ransomware group linked to North Korea—but maybe not its government
CIA insider convicted in massive data leak
Joining us to discuss media-focused APT attacks is Proofpoint Threat Researcher Crista Giering.
Five Minute Forecast for the week of July 11th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
U.S. healthcare organizations targeted with state-sponsored ransomware
Deepfakes of American workers used to apply for remote tech jobs
Personal data of 1 billion Chinese citizens for sale on the dark web
Joining us to discuss a day in the life of a threat hunter is senior threat detection engineer Tony Robinson.
John Checco, Resident CISO at Proofpoint joins the show this episode to discuss The Art of Storytelling. CISOs are often presenting technical or complex ideas at the board-level. Trying to do so in a simple yet compelling way can prove challenging, and that is where mastering the ancient art of storytelling can play a critical role in cybersecurity.
Join us as we discuss:
Six basic concepts of storytelling for business
The importance of data relevance and context when presenting
Strategies for the improvisational moments of storytelling
The biggest mistakes CISOs and security leaders make when presenting to a board
Check out these resources we mentioned:
https://www.proofpoint.com/us/ciso-hub
For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Five Minute Forecast for the week of June 27th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
FTC advises LGBTQ+ dating app users to beware of cyber extortion
Lockbit ransomware gets into the bug bounty game
UK delivery services Yodel is hit by cyber attack
Joining us is Selena Larson from the Proofpoint Threat Research team, to discuss the latest news on social engineering strategies.
Five Minute Forecast for the week of June 20th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Law enforcement arrest thousands in global social engineering stings
Icefall vulnerabilities put thousands of critical systems around the world at risk
Blackcat takes ransomware victim shaming to a new level
Joining us is Proofpoint VP of Threat Research and Detection, Sherrod DeGrippo, who shares her thoughts on this year’s Human Factor report.
Most of the time, security slip-ups happen because of careless, accidental behavior. Through educating people and focusing on changing behaviors, those cyber risks can be mitigated. That’s the idea behind the importance of people-centric cybersecurity.
Today we hear from Jeffrey Wheatman, Cyber Risk Evangelist at Black Kite, about implementing people-centric cybersecurity and assessing your organization’s risk appetite.
Join us as we discuss:
Why people-centric cybersecurity matters
Evaluating risk quantification in the cybersecurity industry
The importance of determining your organization’s risk appetite
Risk appetite versus risk tolerance
Check out this resource we mentioned:
Voice of the CISO Report: https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report
https://blackkite.com/
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of June 13th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Unpatched router vulnerabilities are being exploited by state-sponsored attackers
Ukrainian security authorities warn of active Follina campaigns
Details of a massive Facebook phishing campaign revealed
Joining us is senior threat researcher Jared Peck, for a discussion about cryptocurrency and cyber crime.
Link to the blog post mentioned: https://www.proofpoint.com/us/blog/threat-insight/how-cyber-criminals-target-cryptocurrency
Five Minute Forecast for the week of June 6th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
A cyber attack causes chaos in one of Italy’s largest cities
Has FluBot delivered its last message? European law enforcement thinks so.
Apple blocks over 1.6 million malicious and untrustworthy apps from iPhones
Joining us is senior threat researcher Daniel Blackford, to discuss highlights from this year’s Human Factor report.
Human Factor Report: https://www.proofpoint.com/us/resources/threat-reports/human-factor
Proofpoint’s biggest release of the year is here: the 2022 Human Factor Report. To ensure you don’t miss a thing, Protecting People has your on-the-go breakdown of the report straight from the source,
Sherrod DeGrippo, Vice President of Threat Research and Detection at Proofpoint, joins the show to talk about some of the key findings and topics from the Proofpoint 2022 Human Factor Report and how to best protect yourself and your organization in this new threat landscape.
Join us as we discuss:
The three key areas of user risk
How to identify vulnerable users within organizations
The increase of malicious URLs in 2022
How remote work is impacting organization’s security risks
The influence of Russia’s invasion of Ukraine on the threat landscape
For more episodes like this one, follow Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Resource:
2022 Human Factor Report: https://www.proofpoint.com/us/resources/threat-reports/human-factor
Five Minute Forecast for the week of May 30th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
A New York man gets four years for his part in stealing more than four million credit cards
Ransomware causes serious disruption to one of India’s largest airlines
CLoP ransomware makes a return after four months of silence
Joining us is senior threat researcher Andrew Northern, to discuss the etymology and characteristics of the newly discovered Nerbian RAT.
Five Minute Forecast for the week of May 23rd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Conti ransomware calls time on direct attacks, but remains highly influential
Half a million Chicago students have their personal information stolen in a security breach
U.S. authorities recover $15m from ad fraud operators
Joining us is Proofpoint’s Cheryl Tang, for a review of customer insights at our recent Protect and Wisdom events.
What attacks keep CISOs up at night? Are your employees prepared for those attacks? Is remote work putting you at risk?
To find out the answers, Lucia Milica, Global Resident CISO at Proofpoint, joins us to discuss this year's Voice of the CISO Report, where 1,400 CISOs from around the world were interviewed to share their experiences of the past 12 months and offer their insights for the years ahead.
Listen in to our conversation with Lucia about:
Why CISOs aren't more worried
Is threat modeling really helping?
Which threats are softening up
What security concern rocketed to the top of charts
For more episodes like this one, follow Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Resources:
CISO Hub:
https://www.proofpoint.com/us/ciso-hub
2022 Voice of the CISO Report: https://www.proofpoint.com/us/resources/white-papers/voice-of-the-ciso-report
Five Minute Forecast for the week of May 16th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Managed service providers could let attackers scale supply chain attacks
GCHQ says that Russian attackers continue to target Ukraine supporters
Firmware bugs affect over 200 models of HP computers
Joining us is Proofpoint cybersecurity evangelist, Brian Reed, for a preview of our Voice of the CISO report, launching this week.
Five Minute Forecast for the week of May 9th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is senior threat researchers Daniel Blackford to discuss the return of the REvil gang.
Two conferences, four main tracks, numerous speakers, a cybersecurity ecosystem and community — plus the snazzy jackets. You won’t want to miss the all-virtual events Protect 2022 and Wisdom 2022 from Proofpoint.
Hear our conversation with Tim Choi, Vice President Product Marketing at Proofpoint:
More information about Tim and today’s topics:
For more episodes like this one, follow Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
Five Minute Forecast for the week of May 2nd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is senior threat researcher Daniel Blackford, for an update on the Emotet malware.
Five Minute Forecast for the week of April 25th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is email fraud researcher Timothy Kromphardt, to discuss the latest IC3 Internet Crime Report.
Five Minute Forecast for the week of April 18th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is senior threat researcher Daniel Blackford, to discuss this tax season’s social engineering tactics.
Five Minute Forecast for the week of April 11th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is senior threat researcher Andrew Northern, for a discussion about the recent spate of data theft attacks by Lapsus$.
Tax season is fast upon us in the United States. Here’s the rundown of tax-related phishing trends to make you more wary and alert.
Hear our conversation with John Checco, Resident CISO at Proofpoint:
More information about John and today’s topics:
For more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, the Proofpoint website, or anywhere you get podcasts.
And keep up with the latest tales from the threat research trenches by subscribing to DISCARDED in Apple Podcasts, Spotify, or wherever you get podcasts. Thanks for listening!
Five Minute Forecast for the week of April 4th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is email threat researcher Timothy Kromphardt, to discuss a wave of employment fraud attacks targeting students at U.S. universities.
Five Minute Forecast for the week of March 28th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is senior threat researcher, Andrew Northern, to discuss a new malware campaign that uses some highly advanced techniques.
Everyone gets phishing emails. Not everyone falls for them. In this episode, we discuss the eighth annual State of the Phish report and learn how vulnerable users are to today’s so-called New Normal.
What should you know and how should you respond?
Today we hear from Gretel Egan, Sr. Security Awareness Training Strategist at Proofpoint and primary author of the annual State of the Phish report, about the outlook for phishing in 2022.
Join us as we discuss:
Check out this resource we mentioned:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of March 21st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is senior threat researcher, Andrew Northern, to discuss a recently leaked trove of documents relating to the Conti ransomware gang.
Five Minute Forecast for the week of March 14th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is threat research engineer, Adam McNeil, to discuss a new wave of mobile malware attacks in Europe.
In this episode, Ken Spencer Brown, Senior Manager, Marketing Strategy and Content at Proofpoint, helps us navigate the new possibilities and challenges posed by artificial intelligence and machine learning in cybersecurity. We'll uncover how it's being used, where it's going, and why we should take notice.
Join us as we discuss:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or search for Protecting People in your favorite podcast player.
Music by Eric Matyas at www.soundimage.org
Five Minute Forecast for the week of March 7th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Director of Threat Research and Intelligence, Wes Drone, for a look at the cybersecurity implications of the Russian invasion of Ukraine.
Five Minute Forecast for the week of February 28th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint cyber security evangelist, Brian Reed, to talk about the growing role of CISA in setting security standards for U.S. organizations and businesses.
Five Minute Forecast for the week of February 21st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is threat researcher Joe Wise to discuss TA2541, a cyber attacker with a fondness for the aerospace industry.
Five Minute Forecast for the week of February 14th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is email fraud researcher, Timothy Kromphardt, to discuss new developments in the world of commodity phish kits.
Five Minute Forecast for the week of February 7th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is security researcher, Assaf Friedman, to discuss a new cloud campaign using malicious OAuth apps to target high-profile executives.
Ransomware attacks are becoming both more targeted and more damaging. Is your organization prepared?
In this episode, host Itir Clark interviews Neko Papez, Manager, Product Marketing at Proofpoint, about the newest trends in ransomware — and the best strategies for prevention.
Join us as we discuss:
Check out these resources we mentioned during the podcast:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of January 31st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is founder and chairman of the Ponemon Institute, Larry Ponemon, to discuss the growing cost of insider threats.
Five Minute Forecast for the week of January 24th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us to kick off Data Privacy Week is Proofpoint Cybersecurity Evangelist, Brian Reed.
Five Minute Forecast for the week of January 17th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint’s Fabiola Fernandez to talk about the launch of this year’s Phishing Awareness Kit.
You can buy a phish kit online for 10 bucks. But beware, since it’ll probably come back to bite you in ways you might not expect.
In this episode, hosts Selena Larson and Crista Giering chat with Jared Peck, Senior Threat Researcher at Proofpoint, about the pros and cons of phish kits — and why there’s no honor among thieves.
Join us as we discuss:
Resource mentioned:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of January 10th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Cybersecurity Evangelist, Brian Reed, for a look ahead at 2022.
Five Minute Forecast for the week of December 20th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Threat Researcher Selena Larson to discuss a spate of recent campaigns targeting customers of German financial institutions.
If you asked for M&M’s and received Skittles, you might pop a few in your mouth, but it won’t take long to realize something’s off.
This is exactly what’s happening with RTF files: Instead of the intended attachment, unaware companies are delivering these files and realizing later that they were actually malicious.
On this episode of Protecting People, hosts Selena Larson and Crista Giering chat with Michael Raggi, Senior Threat Research Engineer at Proofpoint, about RTF files, template injection, and campaigns using the technique in an effort to make sure customers aren’t being surprised with “Skittles.”
Join us as we discuss:
Resource mentioned:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of December 13th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Threat Researcher Eric Koeppen to discuss a series of holiday-themed campaigns launched by threat actor TA575.
Five Minute Forecast for the week of December 6th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Senior Threat Intelligence Analyst, Selena Larson, for an update on pandemic-themed cyber attacks.
Five Minute Forecast for the week of November 29th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Senior Threat Research Engineer, Michael Raggi, for a look at a dangerous new phishing technique.
Have you ever been bitten by a TOAD? No, we're not talking about the marsh-dwelling amphibian. We're discussing telephone oriented attack deliveries (TOADs) in which scammers use real phone numbers to gain access to information and accounts.
TOADS represent an atypical — but very poisonous — online threat especially to men in the 20-50 age range. Featuring believable fake invoices and U.S.-based phone numbers, these scammers can hop off with hundreds or thousands of your dollars.
On this episode of Protecting People, hosts Selena Larson and Crista Giering chat with Tim Kromphardt, Email Threat Researcher at Proofpoint, about TOADS, how to avoid them, bait them, or report them.
Join us as we discuss:
Resources mentioned:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of November 22nd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, for an update on North Korea-aligned threat activity.
What does Data Loss Prevention look like in an increasingly remote world? Is the entire concept of DLP flawed? And at the end of the day, whose responsibility is DLP?
DLP is a complex and complicated topic that is crucial for any business to fully understand. After all, you’re protecting your most valuable assets, your intellectual property.
On this episode of Protecting People, host Brian Reed sits down for a conversation with Cosmo Romero, Sr. Sales Engineer at Proofpoint, for a conversation all about DLP, incident response, and more.
Join us as we discuss:
Resources mentioned during the interview:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
A Five Minute Forecast for the week of November 15th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Daniel Blackford, Proofpoint Senior Threat Researcher, for a preview of our new Fall/Winter threat update.
It’s the holiday season!
While that might conjure up images of family gatherings and gift-giving, internet scams are, unfortunately, all too common during this season as well.
In this Expert Insights episode, host Sara Pan interviews Brian Reed, Cybersecurity Strategist at Proofpoint, about how you can protect yourself when the cyber Grinch comes knocking.
Join us as we discuss:
Check out these resources we mention during the podcast:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of November 8th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Brian Reed, Proofpoint Director, Cyber Security Strategy, to discuss the ramifications of the Biden Administration’s latest directive.
Five Minute Forecast for the week of November 1st. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, to talk about a new threat actor impersonating government departments in the Philippines.
APT stands for advanced persistent threat and refers to threat actors who are acting in the interests of other political states.
In other words, espionage.
In this episode of our #ThreatDigest series, hosts Selena Larson and Crista Giering, Senior Threat Intelligence Analysts at Proofpoint, interview Joshua Miller, Senior Threat Researcher at Proofpoint, about the advanced persistent threat landscape in Iran.
Join us as we discuss:
Check out the resources we mentioned during the podcast:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of October 25th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, to talk about a legitimate “red team” security tool being used by cyber criminals.
Five Minute Forecast for the week of October 18th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Crista Giering, Proofpoint Senior Threat Intelligence Analyst, to talk about the return of a major cyber crime group.
Five Minute Forecast for the week of October 11th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Daniel Blackford, Proofpoint Senior Threat Researcher, to talk about Excel, macros and malware.
How is an insider threat incident response like a murder investigation?
You start with motive, then leverage investigative tools and knowledge of people to unearth a trail of mistakes. (Yes, it’s actually quite exciting!)
In this episode, series host Sai Chavali speaks with fellow Protecting People host Brian Reed, Cybersecurity Evangelist at Proofpoint, about insider threat cases and what makes a successful incident response.
Join us as we discuss:
Check out these resources we mentioned:
2020 Cost of Insider Threats: Global Report
The Top 10 Biggest and Boldest Insider Threat Incidents, 2020-2021
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of October 4th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Selena Larson, Proofpoint Senior Threat Analyst, to talk about a series of campaigns by prolific threat actor, TA544.
Five Minute Forecast for the week of September 27th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Adam McNeil, Senior Threat Researcher at Cloudmark to discuss a new mobile malware emerging in the U.S. and Canada.
Gone are the days of 2016 when we saw 12 million ransomware attachments randomly blasted out per day. It’s 2021 now, when threat actors selectively deploy ransomware against high value targets across the victim organization’s entire network in order to secure initial access.
Why is initial access so often overlooked in protecting against the multiplicity of ransomware threats?
In the inaugural episode of our Threat Digest series, series hosts Selena Larson and Crista Giering, Senior Threat Intelligence Analysts at Proofpoint, interview Daniel Blackford, Senior Threat Researcher at Proofpoint, about initial access and what can happen afterwards.
Join us as we discuss:
Check out the report we mentioned during the podcast:
-The First Step: Initial Access Leads to Ransomware
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of September 20th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Senior Threat Researcher, Daniel Blackford, to discuss the relationship between ransomware and cryptocurrency.
Guess how many organizations found they had an insider threat incident at least once — 69%.
Of the remaining 31%, it’s most likely the case that they simply don’t have the capability to identify insider threats, not that they were incident-free.
In this episode, series host Sai Chavali speaks with Proofpoint’s Deborah Watson, Resident CISO, and Jeremy Wittkop, Senior Director, Technology Services, PCMS, about jumpstarting a successful insider threat program.
Join us as we discuss:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of September 13th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Threat Analyst, Davide Canali, to discuss a cryptocurrency spin on one of the oldest attacks in the books.
Five Minute Forecast for the week of September 6th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
• Billions of devices at risk from Bluetooth bugs
• Ransomware source code leaked online
• Funny business on Banksy’s website – but for once the artist isn’t to blame
Joining us is Sherrod DeGrippo, Proofpoint’s Vice President, Threat Research and Detection, to discuss the perennial threat of business email compromise.
Five Minute Forecast for the week of August 30th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, to discuss how cyber criminals are continuing to use the pandemic in their attacks.
Five Minute Forecast for the week of August 23rd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Selena Larson, Proofpoint Senior Threat Intelligence Analyst, to talk the insider threat of ransomware.
Remote desktop protocol, email vector, and VPN — the three most common methods of ransomware attack. However, virtually 100% of all attacks still rely on human vulnerability, not software vulnerability…
Making security awareness training one of your most valuable shields against ransomware.
In this Expert Insights episode, we interview Neko Papez, Manager, Product Marketing at Proofpoint, about changes in the ransomware threat landscape and how Proofpoint can help.
In this episode we discuss:
Why ransomware is such a common attack type
The importance of ransomware education
How to help users become aware and on guard
Check out these resources we mentioned during the podcast:
Proofpoint’s ransomware kit
A ransomware webinar
The Threat Insight blog
To hear more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, or your preferred podcast platform.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of August 16th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Ryan Kalember, Proofpoint’s EVP, Cybersecurity Strategy, to discuss the latest developments in the ongoing ransomware crisis.
What is it that we didn’t know that we should have known?
Many incident response plans miss this crucial question, but it’s absolutely foundational to learning how you can prevent the incident from happening again.
In this episode, we talk with Matt Stamper, CISO at EVOTEK, about the most important elements of an incident response plan and why security awareness has the largest return from a threat mitigation perspective.
What we talked about:
Getting started with incident response
Untangling conflicting priorities in the process
Widening the circle of concern with regard to insider threats
Investing in security awareness
Check out these resources we mentioned during the podcast:
TheHLayer.com
CISO Desk Reference Guide: A Practical Guide for CISOs (Vol. 1)
CISO Desk Reference Guide: A Practical Guide for CISOs (Vol. 2)
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for P rotecting People in your favorite podcast player.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
Five Minute Forecast for the week of August 9th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Brian Reed, Proofpoint’s cyber security evangelist, to talk about how enterprise-scale businesses are responding to the current wave of cyber attacks.
Five Minute Forecast for the week of August 2nd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Sherrod DeGrippo, Proofpoint’s Senior Director of Threat Research and Detection, to explain why some threat actors spend so long developing relationships with their victims.
Five Minute Forecast for the week of July 26th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Ryan Kalember, Proofpoint’s Executive Vice President of Cyber Security Strategy, to discuss how cyber security has become a part of the global political conversation.
Fraudsters who perpetrate BEC and various other types of email scams are a serious and continuous threat to businesses today. In 2019, there were 26.2 billion dollars in reported losses from these kinds of malicious malware attacks.
For part two of our Expert Insights into Business Email Compromise (BEC) and email fraud protection, host Sherrod DeGrippo leads a lively discourse with Robert Holmes, Sr. Director of Threat Research and Detection, and Sam Scholten, CISSP, and Staff Email Fraud Researcher, both of Proofpoint — a company at the forefront of using AI and machine learning for radical, comprehensive threat protection.
Here's a sneak peek:
The small but crucial differences between DDoS extortion and a BEC attack.
The next generation of how Proofpoint is stopping these threats with deep analysis of every email for metadata signs of intrusion.
Fascinating samples of previous attacks and highly creative threat actors who leveraged social cues to launch an attack.
Successful scams take advantage of human nature and the fundamental vulnerability of individuals.
To hear more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, or your preferred podcast platform.
Five Minute Forecast for the week of July 19th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Sherrod DeGrippo, Proofpoint’s Senior Director of Threat Research and Detection, to explain what’s really happening when cyber criminal groups go on hiatus.
Five Minute Forecast for the week of July 12th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Cybersecurity Evangelist, Brian Reed, to discuss Solar Winds, Kaseya, and the growing threat of software supply chain compromise.
Business Email Compromise, or BEC, is a type of scam that utilizes social engineering to trick companies into paying fraudulent invoices or giving up sensitive information that can be used for a future attack.
Malware, phishing, BEC, and thread hijacking. The “baddies,” as one of today’s guests charmingly anoints them, utilize these deep, complicated attacks because the rewards are so very great - in 2019, stats from the Internet Crime Complaint Center showed losses over $1.7 billion.
Join host Sherrod DeGrippo for part one of this in-depth discussion, as she talks through various current threats and how companies can defend against them with email fraud defense experts Robert Holmes, Sr. Director of Threat Research and Detection, and Sam Scholten, CISSP Staff Email Fraud Research, of Proofpoint.
Here's a sneak peek:
Learn the signs of suspicious emails
Threat actors are putting a high amount of energy into today’s scams
BEC is a global problem
Stricter financial controls can help your company along with EFD
To hear more episodes like this one, subscribe to Protecting People on Apple Podcasts, Spotify, or your preferred podcast platform.
Five Minute Forecast for the week of July 5th. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Threat Researcher Selena Larson with a primer on how cyber criminals are using a legitimate security testing tool called Cobalt Strike to make their attacks even more effective.
Proofpoint has concluded 3 of their 2021 conferences: Wisdom, Protect, & Protect EMEA with great success; highlighting their guest speakers and information protection—the show takes a behind-the-scenes look at the action.
Tim Choi, Vice President Product Marketing at Proofpoint, joins the show to discuss the Proofpoint conferences.
What we talked about:
The Structure of the Protect, Protect EMEA, & Wisdom Conferences
Discussing the Conference Panel Participants
COVID-19 and the Information Protection Transformation
Security Awareness Training within an Organization
Check out these resources we mentioned during the podcast:
Protect Conference 2021 - Day 1 Recap
Protect Conference 2021 - Day 2 Recap
Wisdom Recap
To hear more interviews like this one, subscribe to the Protecting People Podcast on Apple Podcasts, Spotify, or your preferred podcast platform.
Five Minute Forecast for the week of June 28. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
Joining us is Proofpoint Threat Researcher Selena Larson, to explain why cyber criminals are now operating fake movie streaming sites and support call centers.
Five Minute Forecast for the week of June 21. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast
Joining us is Proofpoint Threat Researcher Daniel Blackford, giving the lowdown on the steganography techniques attackers are using to place malware on the Steam platform.
About 85% of threats involve some sort of human interaction, and about 50% of organizations have experienced a successful phishing attack.
So, attacks are overwhelmingly focused on people.
In a recent Expert Insights episode of Protecting People, we spoke with Brett Shaw, Senior Product Marketing Manager at Proofpoint, about some of the latest trends in the threat landscape — and how to protect people from them.
What we talked about:
Email is the easiest way to prey on vulnerabilities
Reducing risk means developing a multi-layered approach to security
A system is only as good as the data that feeds it, but…
Human action can overset any system with just one click
Check out these resources we mentioned during the podcast:
The State of the Phish 2021
The Verizon DBIR report [referenced at 3:28]
Email Fraud and Security Awareness Kit [referenced at 4:57-5:46]
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
Let’s talk about the adversarial relationship between end users and vendors.Things could improve in both directions.
In this episode, we interview Dan Holden, VP of Cyber Security at BigCommerce, about anger, angst, and ‘forgivability’ in the vendor/end user relationship.
What we talked about:
It’s more about fit than about vendor or product
The advantages of building a vendor relationship with a startup
The CISO’s role in understanding the vendor landscape
3 questions for the CISO to ask to set vendor priorities
You’re invited to Protect 2021 on June 8-9.
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
Dan Holden, VP of Cybersecurity at BigCommerce takes a threat centric angle when discussing information security. He emphasizes the importance of awareness around the extent of cybercrime capability.
What we talked about:
Different ways to handle information security
Changes in the threat landscape
External aspects of cybercrime capability
Framework vs. Strategy
Check out these resources we mentioned during the podcast:
For more episodes like this one, subscribe to us on Apple Podcasts, Spotify, and the Proofpoint website, or just search for Protecting People in your favorite podcast player.
Listening on a desktop & can’t see the links? Just search for Protecting People n your favorite podcast player.
The new world has changed our concerns about how information is accessed and handled. Remote work has accelerated the insider threat, insider risk, and DLP concern. The need for information protection is at an all-new high.
In this episode in our Inside Line on Information Protection series, host Brian Reed chatted with Tim Choi, Vice President Product Marketing at Proofpoint, about information protection and the upcoming Protect 2021 conference.
What we talked about:
New information protection situations Tim has seen
Why Protect 2021 is focused on customers
Where to register for Protect 2021
Check out this resources we mentioned during the podcast:
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
We’ve been joined by Gretel Egan, Senior Security Awareness Training Strategist at Proofpoint, to discuss this year’s State of the Phish (SOTP) Report, where we get an in depth look at user awareness, vulnerability and resilience.
This episode covers:
A breakdown of what goes into the SOTP report and where the data is sourced from
The broadness of the term ‘phishing’ and what it includes or means, in the context of the data
The application of phishing techniques across different media
How the COVID-19 pandemic gave attackers the opportunity of a lifetime
How to measure informational security preparedness and awareness within your organization
The resilience ratio, and how automated reporting can improve this figure for your organization
Below is the link to access this year’s State of the Phish Report:
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
When everyone is feeling overwhelmed by taxes and afraid of doing something wrong, that’s when the phishing, smishing, and website impersonation reaches its height.
How can we reassure and train our employees about tax-related scams?
In this episode of our Expert Insights series, we interview Susan Mackowiak, Senior Director, Program Content at Proofpoint, about resources to avoid being a victim of a tax scam.
What we talked about:
What scammers are trying to accomplish
How the IRS contacts you and how to contact the IRS
An overview of the contents of Proofpoint’s Tax Awareness Kit
Check out these resources we mentioned during the podcast:
Tax Season Awareness Kit
7th Annual Report for the State of the Phish
The IRS’s phishing reporting site
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
If you’re asking which information protection platform to choose, that’s not deep enough. It’s intellectually lazy.
Too often, we make technology decisions instead of programmatic decisions.
In a recent episode in our Inside Line on Information Protection series, we chatted with cybersecurity executive Jeremy Wittkop about reimagining DLP as a method for protecting people first.
We also talked about:
Resources we mentioned during the podcast:
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
When we’re looking ahead at 2021 in information governance and regulatory changes, what will define the cybersecurity industry?
In this second of two episodes featuring regulatory changes in our Expert Insights series, John Pepe, Resident Chief Compliance Officer and Regulatory Counsel at Proofpoint, and Sonali Bhavsar, technology executive, forecast governance in 2021.
What we talked about:
The importance of voice as a data footprint
What to supervise for remote workers
The challenge of creating a use case with archiving, supervision, and behavior analytics all as separate products
Expectations on the regulatory side, plus new technologies
Machine learning for entity mapping
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
In addition to focusing on malicious actors trying to gain access to your networks and your systems, are you just as focused on making sure that the people who already have access are doing what they’re supposed to be doing?
Insider Threat detection is one of the most underutilized, but overlooked aspects of any cybersecurity organization.
On this episode of The Inside Line on Information Protection, we talk with Larry Ponemon about:
Why every company regardless of size, should be running Insider Threat programs
The astronomical cost of Insider Threat investigations
Why good people making silly mistakes may be more damaging that bad actors doing bad things
The easiest way into a Fortune 50 company (it’s probably not what you think)
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
Introducing our new series: Inside Line on Information Protection.
In this show, we’ll welcome expert guests with diverse backgrounds in information protection to discuss topics like insider threat, information governance, and cloud security.
In this inaugural episode, host Brian Reed is joined by Catherine Hwang, Director of Product Marketing for Information Protection Products at Proofpoint.
What we talked about:
The topics that will be covered in the series
Why legacy DLP solutions aren’t solving customer challenges
Wanting to solve more than one problem at a time with DLP budgets
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
Governance, AI, analytics, and regulation — 2020 sure changed a lot.
Good data hygiene looks totally different now, as does so much in the regulatory financial services realm.
In this first of two episodes featuring regulatory changes in our Expert Insights series, John Pepe, Resident Chief Compliance Officer and Regulatory Counsel at Proofpoint, and Sonali Bhavsar, Technology Executive, discuss what’s changed in governance 2020.
What we talked about:
How communication data has exponentially shifted
Regulatory and legal changes surrounding data
Best practice guidance for insider threats
What CFTC guidance means for technology best practices
AI, machine learning, and transaction surveillance/transaction supervision
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Listening on a desktop & can’t see the links? Just search for Protecting People in your favorite podcast player.
People spend over 3.5 hours on their mobile phone every day, and 50% of that time is spent on social media.
If you think your employees aren’t representing your company on social media platforms, you’re just plain wrong.
In this episode, we interview Amanda Anderson, Product Marketing Manager, Compliance at Proofpoint, about understanding security risks on social media from a people-centric perspective.
What we talked about:
How social media is integral to modern business
Trends and types of social media-related risks
How technical and administrative controls play a role in social media compliance and security
Resources we mentioned during the podcast:
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Data doesn’t lose itself.
A person loses the data.
What, exactly, do we mean when we talk about people-centric security?
In our latest People Variable episode of Protecting People, Brian Reed, Cybersecurity Evangelist at Proofpoint and former Gartner analyst, talks to us about data loss prevention.
What we talked about:
3 reasons you would ever start a DLP project
How to talk to your CISO about data loss
Communication is everything in security awareness training
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Cloud account takeover activity has skyrocketed in 2020. When the security perimeter of your org is your people, how they access the cloud matters.
In this episode of our People Variable series, we spoke with Itir Clarke, Sr. Product Marketing Manager at Proofpoint, about risks people pose in the cloud.
What we talked about:
One in six people use the same 1-2 passwords
Why cloud security is of growing importance for awareness programs
Two easy steps to address account compromise
Check out this resource we mentioned during the podcast:
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
It’s the most wonderful time of the year. If you’re a hacker, that is.
Holiday season is always the time of the year when we see cyber attacks go through the roof. Why?
Because people are stressed out, they’re in a hurry, and they aren’t always paying close enough attention to things as they should.
After all, when Amazon emails you and tells you your package is going to arrive late, you take action, right?
Susan Mackowiak stopped by the Protecting People podcast recently and had a couple of thoughts to keep you and your loved ones safe this holiday season. We talked all about:
How hackers utilize fear to get what they want
Why you should do your shopping on a computer instead of your phone
Why you should be wary of ads on social media, even if they appear to be from brands you trust
Why people are the weakest link in the security chain
Find additional content, like our 2020 Holiday Security Awareness Training Kit and Best Practices Guide, and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Cybercriminals may be nefarious, but they are also people.
And people have habits.
If you want to stop one, it helps if you learn them.
In our latest episode, we’re speaking with Wes Drone, Sr. Manager, Threat Intelligence, at Proofpoint and a former FBI Agent, about what a typical day looks like for the people stopping threat actors by thinking like them.
We discuss:
Wes’ transition from the FBI to threat intelligence
The habits of threat actors
How Wes tracks individual threat actors
Find additional content, like our Insider Risk Threat Assessment and Guide to Building a Security Awareness Program that Works, and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Nobody wants to view employees as insider threats. Yet in the last 2 years, there have been about 40% more insider threat incidents - almost 1 in 3 breaches involves insider threats.
In this first episode of our People Variable miniseries, we interview Sai Chavali, Sr. Product Marketing Manager at Proofpoint, about insider threats.
What we talked about:
The 3 types of people-centric insider threats
Providing targeted security awareness about insider threats
How insider threats are changing the security landscape
Find additional content, like our Insider Risk Threat Assessment and Guide to Building a Security Awareness Program that Works, and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Would you pay the ransom?
There are 4,000+ ransomware attacks per day with $3.5Bn lost in just 2019.
Looks like the answer is Yes.
In our 6th episode to understand the mind of cybercriminals, your Protecting People hosts learn all about ransomware from Christopher Budd, Principal at Christopher Budd Security, and Ryan Kalember, EVP, Cybersecurity Strategy at Proofpoint.
What we talked about:
What ransomware is & why people pay
How to pay your ransomware attacker
Professionalism among cybercriminals! Some have stopped attacking the healthcare industry during COVID-19
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
The word malware comes from “malicious” + “software” — and it’s as bad as it sounds.
To get inside the minds of cyber criminals, we asked 2 security experts to teach us about malware.
In this episode, we interviewed Christopher Budd, Principal at Christopher Budd Security, and Sherrod DeGrippo, Sr. Director, Threat Research and Detection at Proofpoint, about how to get and avoid malware.
What we talked about:
What malware is & how to get it
Different types of malware like rats & banking Trojans
COVID-themed lures vs. classic lures for malware
Whether it’s better business sense to buy or build your own malware
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
We recently put this question to three security awareness experts:
Where do you start with a company-wide training program?
In this #TacklingUserBehavior episode, we interview Eddie Whittingham, founder of the recently-acquired The Defence Works, Kurt Wescoe, Former CMU Faculty and Chief Architect at Proofpoint Security Awareness Training, and Robert Shields, Sr. Product Marketing Manager at Proofpoint.
What we talked about:
The need to have specific goals instead of doing “everything”
Donuts as an excellent motivator
Incorporating personal examples into training
Focusing on your organization's unique risks and user landscape to tailor education
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Not all cybercriminals are evil. Some send phishing emails to their coworkers for their own good.
We’re talking about simulated phishing emails for education.
In this episode, we interview Jason Riegner, Jr Front End Developer at Proofpoint, about the Microsoft TEAMS phish he designed, which most of us fell for.
What we talked about:
How to identify a phishing email
What to do & especially what not to do when you get one
The nuanced design of phishing emails, from intricate to innocuous
We had a contest! Who wins our respect?
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
BEC, or Business Email Compromise, is when an attacker disguises themselves to look like a trusted person.
But EAC, or Email Account Compromise, is when an attacker actually compromises an email account. They can start sending emails as, well, you.
In this episode, we hear from past guests Rob Holmes, Sherrod DeGrippo, & Mike Bailey about how to access and compromise a legitimate mailbox.
What we talked about:
BEC & EAC attacks caused more than $26 billion in losses since 2016
Why a real estate agency is a great target for a new cybercriminals
How to leverage people skills to make believable demands for money
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Wouldn’t it be great if security training were so exciting that employees started begging for the next episode? Security training should feel like watching your favorite sketch comedies.
In this episode, we interview Eddie Whittingham, Founder of The Defense Works and former police officer and lawyer, about his inspiration for humorous, interactive security training.
What we talked about:
Finally, the end of traditional security training
How interactive comedy affects user behaviors
The process of creating training episodes with comedy writers
Eddie’s goal to push the boundaries of what security training means
Check out these resources we mentioned during the podcast:
The Defense Works’ YouTube channel gives you a taste of their training
Their blog is pretty funny, too
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Security is like having a foolproof safe. Privacy is like telling everyone the combination.
When it comes to the complex security and privacy landscape, where do you even start with awareness training?
In this episode of the #TacklingUserBehavior series, we interview Daniel Solove, Founder of TeachPrivacy and John Marshall Harlan Research Professor of Law at the George Washington University Law School.
What we talked about:
The overlap between privacy and security
The “hub and spokes” approach to training employees in security
The qualities of effective privacy training
Enforcement in the age of COVID-19
Check out this resource we mentioned during the podcast:
Daniel has a Privacy + Security blog
Register for our August 18th webinar: https://www.proofpoint.com/us/webinars?id=416919
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
80% of what you need to be a cybercriminal is Internet access.
The other 20% is mostly social engineering. Effective cybercriminals understand how people think.
In this episode, we interview Robert Holmes, VP and General Manager, Email Fraud Defense at Proofpoint, about the easy process for business email compromise (BEC) attacks.
What we talked about:
Smaller companies are more likely to be victimized than larger companies
Cybercriminals pretend to be a trusted persona (like your CEO)
Super easy but insidious tech tips that people fall for all the time
Phishing, vishing & smishing: What are they?
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Users still clicking phishing emails? Reusing passwords?
Don't worry - you're not alone.
In this inaugural episode of our new #TacklingUserBehavior series, we interview Kurt Wescoe, VP of Engineering at Proofpoint and former Carnegie Mellon University faculty, about how to achieve successful user behavior change.
What we talked about:
The importance of user buy-in and engaging security awareness programs
Contextualizing education for users might mean incident-by-incident training
How to be adaptable in setting achievable goals
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Your workers are 100% remote now… using their personal devices and personal accounts for work. Cybercriminals will capitalize on their shock and fear to cause as much data loss as possible.
In this #ExpertInsights episode, I interview Tim Choi, VP of Product Marketing at Proofpoint, about how to protect your people from cybercrimes… remotely.
What we talked about:
Examples of shock-based phishing (some are quite clever)
What employees can do to protect themselves
What employers can do to protect employees & data
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Do you think you have what it takes to be a cybercriminal? It’s not a profile you might expect: high in people skills… low in tech.
In this episode, we interview Adenike Cosgrove, Director of International Product Marketing at Proofpoint, about skills that cybercriminals need.
What we talked about:
Ideal places to live for cybercrime
People skills, not tech skills
Who criminals research — VAPs (very attacked people)
Examples of successful cyber crimes
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or on our website.
Regulatory change can inspire downright terror in many of us. When that happens, the best thing to do is search for insights from experts.
In this episode, the first in our #ExpertInsights series, we interview Guy Levitt, CEO at TeleMessage, and Nigel Cannings, CTO at Intelligent Voice, about the myriad challenges of recording voice calls.
What we talked about:
Everything can be retrieved in WhatsApp
Why regulations are so apparently conflicting and definitely confusing
Predictions about the future of regulation
California will come after you if you are in breach of two-party consent
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or on our website.
Privilege is an entity's degree of power within an org.
Think technical access, like a DevOp manager’s ability to manipulate sensitive files and systems.
Or a finance team member’s authority to issue wire transfers on behalf of the org.
We are rounding out our series on risk by interviewing Roie Cohen Duwek, Director of Security Research at Proofpoint, about privilege-based attacks.
What we talked about:
Why EAC attacks are so insidious and effective
Privilege abuse and cloud-based attacks
Ways that legitimate accounts get compromised
What CISOs should do to protect their employees
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or on our website.
If you could send an email as anyone, who would it be? You might pick an executive assistant, the agent of your favorite band, or a payroll employee.
Jumping from persona to persona is the game that hackers are playing now.
In this episode, we interview Sherrod DeGrippo, Sr. Director of Threat Research and Detection at Proofpoint, about the psychology of today’s hackers.
What we talked about:
The psychology of threat agents and how they bounce across personas in an organization
Analyzing attacks from a people-centric viewpoint
The pattern and process of attacks, start to finish
Tools and technology to reduce vulnerabilities
Find additional content and subscribe to Protecting People on Apple Podcasts, Spotify, or our website.
Just 61% of survey respondents knew what the definition of phishing was — and that was from a multiple-choice list.
This response is a huge indication of the language gap between InfoSec and users, which speaks to the urgent need for security awareness training.
In this episode, we interview Gretel Egan, Security Awareness and Training Strategist at Proofpoint, about the extent of vulnerabilities.
What we talked about:
What effective security awareness training looks like
The 2020 State of the Phish Report’s robust data
How employees are putting their organizations at risk
Pain points for companies (55% had a successful attack)
Check out this resource mentioned during the podcast:
Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.
Why would you do something hard when you could do something easy? That’s exactly what attackers are thinking.
99% of attacks rely on duping a human to run malicious code.
In this episode, we interview Ryan Kalember, EVP of Cybersecurity Strategy at Proofpoint, about why today’s attacks are about people, not infrastructure.
What we talked about:
Social engineering is at the heart of over 99% of cyberattacks
26 billion cyberattacks are only a tiny fraction
Industry focuses on technology while attackers focus on people
Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.
There are only two types of companies in the world today: companies that are compromised and companies that don’t know they’re compromised. Which one is yours?
In this episode of Protecting People, we interview Prasanna Ramakrishnan, Global Head of Infosecurity Risk at Signify, about the fact that we are all living in a continuously compromised state.
What we talk about:
Smart devices in your home can be hacked
People are the weakest link in the security chain
The 2 types of companies out there
Awareness training and other effective security controls
Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.
The biggest cybersecurity challenges are the wicked problems, the unsolvable, people-based problems.
A lot of security is getting into the “wicked problem” space at this point.
On this episode, we interview Adrian Ludwig, CISO at Atlassian, about how he protects people against people-based risks:
What we talked about:
-Challenges in communicating risk effectively to people
-Creating layered systems to protect against training failures
-Finding hidden expectations in your workplace and among consumers
-Where cybersecurity is headed in 2020
Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.
85% of execs identified that most cybersecurity breaches are a result of human vulnerabilities. Not because of technology. Because of people.
Listen in to hear 2 ways that companies are responding to protect themselves from people-based threats.
On this episode, we interview Robert Powell, Editorial Director Americas and Thought Leadership at The Economist Intelligence Unit:
What we talked about:
-The most surprising statistics from Robert’s latest report
-Who is most likely to be targeted at a company
-How companies are protecting themselves from people-based threats
-What it means to practice good digital hygiene
Check out the report we mentioned during the podcast:
Cyber Insecurity: Managing Threats from Within
Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.
Today’s cyber criminals target regular people. Chief financial officers. Fifth grade teachers. Your grandmother. (You get the picture.)
It’s sometimes hard to find the human perspective behind these attacks and the strategies we use to fight back.
This is why we’re incredibly proud to launch our new podcast, Protecting People: Cybersecurity for the Rest of Us.
What you’ll hear:
Industry leaders on today’s top cybersecurity threats
Security challenges for email fraud & phishing
Best practices for email encryption & email archiving
Subscribe to Protecting People at Apple Podcasts, Spotify, or our website.