Discover the unique, inspiring, and often amusing stories behind what it takes to lead cybersecurity efforts in an organization. The Security Stories podcast features interviews with a diverse range of guests, each sharing their leadership experiences for the benefit of others in the cybersecurity industry. Discover more at https://www.cisco.com/c/en/us/products/security/securitystories.html
In this podcast episode, Taz and Raj explore the strategies and tactics that successful businesses can use to drive innovation from within. With real-world examples of companies that have successfully implemented innovative solutions and examine the challenges that these companies faced in the process.
We’ll delve into current tech trends and predictions for 2024, including but not limited to the rise of artificial intelligence, the growing complexity of security in a multi-cloud world, and the increasing convergence of networking and security. We’ll discuss how these trends shape the world of innovation and examine the implications for businesses looking to drive innovation from within.
On today's episode, Hazel is back to chat to Jeremy Maxwell, CISO of Veradigm. Veradigm is a healthcare IT company providing electronic health record systems and other solutions to a variety of medical organizations. These organizations range from small physician practices all the way up to some of the world’s largest insurance and pharmaceutical companies.
Serving roughly 10,000 customers in a highly regulated industry, security is critical for Veradigm’s success. Much is at stake when it comes to the confidentiality, integrity, and availability of patient information.
In this chat, Jeremy talks about his personal journey into cybersecurity and his various roles leading up to his current position as CISO. He talks in detail about incident readiness, and how his team is structured to deal with security incidents. Jeremy has been partnered with Cisco Talos Incident Response for over 6 years now, and we’ve helped the organization put various response plans and scenarios together (and test them rigorously).
Jeremy also describes a specific attack attempt that occurred at Veradigm, in which an attacker tried to gain access using spear phishing. This is a fascinating insight into the mentality of dealing with a high stakes, high pressure situation, and how the team came together to oust the attacker before anything was taken.
Cybersecurity attacks continue to rise and become more pervasive and sophisticated. Depending on the size of an organization, there may be millions or even billions of data points and signals that need to be analyzed. AI has emerged as the top defense against threats because it can "keep up with the bad guys", combing through data and providing organizations with predictive analytics to pinpoint malicious activities, calculate risk, and surface threats before they can be exploited. These solutions need the right architecture and engineering to ensure human needs are translated into understandable and trustworthy information. Hear from Shaila Shankar, SVP of SBG Engineering talk about how AI is shaping Cybersecurity and how we are engineering for the future.
Listen to Taz dig into Cisco's Social Responsibility initiatives with Brian Tippens, Chief Social Impact Officer. In this episode, we explore the downstream impact of technology and the role that Cisco plays in creating a better world. We discuss the importance of social impact for Cisco and the responsibility they have to prioritize it in their operations and innovations. Taz and Brian delve into the challenges and opportunities for Cisco to create a positive impact, and the ways in which they can work towards a better future.
Aside from being entertained by friendly banter between the two, listen to Chief Information Security Officer of the NFL, Tomas Maldanado and Taz take on the most common myths about cybersecurity and unpack the realities behind these bloated assumptions.
Taz explores the importance of using simple language in the cybersecurity space and the critical role that departments outside of cybersecurity and engineering with Tom Gillis. Everyday we are shown that communications and marketing play in shaping messaging that reaches the market.
They discuss the essential role of translators in the cybersecurity industry and how they serve as a bridge between technical experts and non-technical stakeholders. Listen in to learn how simplifying cybersecurity language, collaborating across departments, and utilizing translators can improve your organization's cybersecurity efforts and keep you and your data safe.
Technology has transformed our world in ways we couldn't have imagined just a few decades ago. But as we continue to rely on technology to connect, learn, and innovate, we must also consider the impact it has on our society. Taz and guest TK Keanini explore the intersection of digital sociology, responsible tech, ethics, and cybersecurity and how they shape the way we live, work, and interact with one another. From examining the social and ethical implications of new technological developments to discussing how we can create a more equitable, just, and sustainable digital future, this podcast will inspire you to think critically about the role technology plays in our lives and how we can use it to create a better world.
As Artificial Intelligence (AI) continues to advance and become more prevalent in various industries, the importance of ensuring responsible AI practices has become increasingly apparent. One crucial aspect of responsible AI is cybersecurity.Article mentioned at 23:26: https://futurism.com/delphi-ai-ethics-racist
Background topics/articles and notes:
· AI language models are becoming more advanced and efficient.
· Switch Transformer could help make AI language processing more accessible to researchers and developers.
· Improved language models could lead to more accurate and efficient natural language processing in a variety of applications.
· Tech giants like Microsoft are investing heavily in AI to improve their products and services.
· AI is increasingly being used to develop enterprise solutions that can help businesses become more efficient and effective.
· The acquisition of Cognitivescale could help Microsoft compete with other cloud providers like Amazon and Google.
· AI is being used to develop more accurate and efficient diagnostic tools for medical conditions.
· The use of AI in healthcare could help improve patient outcomes and reduce costs.
· This new AI system could provide a non-invasive and accurate way to detect heart failure.
In this episode, Taz interviews Alex Wolf. Alex is a business & tech thought-leader, investor and author; recognized as Fast Company’s Top 100 Most Creative People In Business. Alex’s effort to make big companies think critically about technology has been recognized by Apple, Snapchat, Stanford University, Fordham University, NYU and more. Her thought-leadership has been profiled in Forbes, Inc. Entrepreneur and in AfroTech as “The Woman Silicon Valley Is Too Afraid To Call A Genius”. She sold a multi-million dollar internet company she built from scratch before the age of 25. Wolf now speaks and writes to an audience of over 34,000+ entrepreneurs & investors who trust her opinion on the future of business & acquisitions.
In this episode, Taz and Alex chat about Alex's path into the M&A space, what it's like to be an investor and how security plays a valuable role in her work and industry. Enjoy!
Links from discussion:
Trigger warning - {child abuse} content filtration is a sensitive topic that covers some of the harsh realities of our world that folks on trust and security teams have to deal with on a daily basis.
In this episode, Taz speaks with Yasmin Abdi, CEO and Founder of NoHack and Security engineering manager at Snap. They cover a wide range of topics from Yasmin's career trajectory, her experience on a content filtration team and her transition into entrepreneurship as a new founder.
Yasmin Abdi is an experienced technical advisor on security, privacy, and data protection. She has over 5 years of experience as a software engineer and has built and managed in-house software and security solutions at Snap, Meta, and Google. Yasmin was also a founding member of Meemo, an AI-powered social finance app, which was recently acquired by Coinbase. The technologies she has built are currently being used by 100+ million daily active users worldwide.
Ms. Abdi has several years of experience leading organizations, providing thought leadership, and assisting private sector clients in the areas of software engineering, security infrastructure and best practices, IT solutions, and corporate strategy consulting. Given her unrelenting entrepreneurial spirit and keen interest for information security, Yasmin founded noHack, a government contracting company focused on cyber security services and solutions. As the CEO of noHack, Ms. Abdi takes a hands-on approach to delivering high-impact solutions. Her goal is to protect her clients by providing an extra layer of all-around protection.
Outside of tech, Ms. Abdi’s passion is to help bridge the gap between minority students and tech companies. Yasmin has mentored and helped over 50 students land jobs within tech.
Ms. Abdi also holds a Bachelor of Science in Computer Science with a focus in cyber security engineering from the University of Maryland.
Here’s Yasmin, hope you enjoy.
Links:
In today’s episode you’ll hear from Joe Toscano. Joe is an award winning designer, published author, and international keynote speaker who left his role consulting for Google because he felt the industry was misusing data and that the issues needed to be addressed through innovation rather than strict regulation. Since leaving, Joe has written a book, called Automating Humanity, and has started DataGrade, both focused on increasing technology literacy and purpose-driven innovation. You may have seen Joe featured in The Social Dilemma or his TEDx Talk, “Want to work for Google? You already do,”.
Joe and Taz have been running in the same data ethics advocacy circles for some time but officially met in 2021 during their joint keynote speech alongside Brittany Kaiser at Eurpol’s annual EDEN conference.
In our chat, you’ll hear about Joe’s origin story – mathmetician, turned psychology buff turned data scientist. Through his changing career one factor remained strong – data ethics. We cover his journey into data ethics advocacy, what he’s doing with his new start up DataGrade and most importantly – you’ll learn what resilience means to him. Here’s Joe – hope you enjoy.
In this episode, Taz interviews Jason Button, Information Security Director who manages our Mergers & Acquisitions Cybersecurity efforts. This conversation is full of compassion, leadership insights, and brilliant gems that anyone can apply in their lives. In addition to chatting about imposter syndrome and Jason's career journey, you'll hear details about the M&A process and how to successfully go about it, no matter the size of your organization.
Jason came to Cisco through the Duo acquisition, and the work that he and his team have been doing is quite interesting as they are now working with Corporate Development to assess the security threats of companies we’re looking to acquire.
More from Jason:
I’m interviewing Lena Olympio. Lena hosted a fantastic conversation about Women in Leadership. You all know how important that is to us here at Cisco and on this podcast so I wanted to share it with all of you.
Lena interviewed 3 incredible leaders here at Cisco Dana, Alex and Allison (a part of our Partners Organization) - they were rightfully recognized as this year’s Women of the Channel among many other incredible humans.
I was inspired by their story and inevitably became more curious about Lena's. In this episode you can expect to hear more about Lena, her career journey and how her interview with Dana, Alex and Allison truly inspired her. You’ll also hear about the different paths non-technical people can take to get into a technical role – especially women. And lastly, the biggest take away from this conversation ... you don’t have to be in a position of quote "leadership" to. lead.
I’ve included their full conversation at 32 minutes and 30 seconds at the end of my interview with Lena. I hope you are inspired and can take this energy with you into the holiday season!
More on Lena:Lena Olympio is currently a Technical Solutions Architect at Cisco. She joined Cisco in November 2012 as contractor, auditing customer service phone calls and cases, and worked her way into a Global Process Manager role in March of 2015 to drive process improvement within the Cisco Commerce Workspace (CCW) customer service teams.
With Cisco’s latest focus on security, Lena is excited to be working in an area that is helping drive the company’s priorities. She is perpetually learning and sharing her knowledge with others to help them achieve their personal and professional goals.
More on the Women of the Channel 2022:https://unifiedguru.com/record-38-cisco-leaders-make-crns-2022-women-of-the-channel-list/
Alexandra Della Sera
https://www.linkedin.com/in/alexandra-della-sera/?dtid=oblgzzz000659
https://www.crn.com/rankings-and-lists/wotc2022-details.htm?w=299
Dana Miller
https://www.linkedin.com/in/dana-coop-miller/?dtid=oblgzzz000659
https://www.crn.com/rankings-and-lists/wotc2022-details.htm?w=822
Alison Stahl
https://www.linkedin.com/in/alisonstahl/?dtid=oblgzzz000659
https://www.crn.com/rankings-and-lists/wotc2022-details.htm?w=1153
National Cybersecurity Awareness Month continues and in honor of it we interview global and industry recognized thought leader, Confidence Staveley.
To name a few of her incredible accomplishments, Confidence has been recognized as Cybersecurity Woman of the Year in 2021 and 2022, she is a part of the U.S. State Department’s International Visitors Leadership Program. Not to mention she has single handedly changed the future of so many young girls as it relates to their access to technology, education and security awareness.
To learn more about Confidence, you can find her on all social media platforms:
Linkedin, Twitter, Instagram
To learn more about her organization, Cybersafe Foundation and to donate to their incredible cause you can visit: https://cybersafefoundation.org/donate/
Additional resources:
CISA Security Resources
Cisco Secure's Cyberecurity Awareness Month Page
If you’re inclined to share this episode with your community, please tag us!
@Ciscosecure @techwithtaz @hazeburton
Happy National Cyber Security Awareness Month! Today's guest is Cathy Pedrayes: Author, television host and bilingual social media influencer, Cathy Pedrayes is best known as TikTok's 'Mom Friend.'
She developed the reputation after sharing safety content that ranges from items she keeps in her first aid kit to how to maintain your security and privacy online.
With millions of followers on TikTok, Cathy is on a mission to help her audience see themselves in cyber.Our chat covers Cathy's unique way in the security industry, her origin industry and insights into her book, The Mom Friend Guide to Everyday Safety and Security.This episode is a reminder that no matter where you are, what you do - you are entitled to feel safe online and better yet, you can get involved!
We can't thank you enough for your continued support, especially during this glorious month of National Cybersecurity Awareness!
If you are inclined to share this episode with your friends, please tag us and use the hashtags below:
On today's show our guest is one of our very own - Ashlee Benge, Strategic Intelligence Lead on the Cisco Talos team.
After a very informative presentation at Blackhat on "Opsec in a Post-Roe World' we wanted to dive deeper with her to learn about the impact and implications on the security industry, practitioners and the world at large.
The episode covers a vast range of discussion, with the fundamental hope to inspire people to take charge of their privacy and develop agency around big decisions made by regulators.
Join us for a raw, rich and very real conversation.
Oh, and some exciting news underway for the podcast!
To read more about this topic, take a look at Ashlee's in depth article: Our current world, health care apps and your personal data
Today's episode features a recording from a live event that we hosted on 24 August, aka Independence Day for Ukraine.
Six months since Russia's invasion of Ukraine, Dmytro Korzhevin, a senior threat intelligence researcher, JJ Cummings, Talos' national intelligence principal, and Ashlee Benge, a strategic intelligence lead, provided insights into their past few months of work in the region.
The discussion primarily focused on the resiliency of Ukrainians, who have worked tirelessly over the years to transform their cybersecurity capabilities. Ukrainian infrastructure has largely stayed operational and, in most cases, exceeded expectations. It seems to have baffled most pundits, but for those that have spent years working in Ukraine, it’s no surprise about the levels of dedication and commitment to protecting their critical infrastructure from those that would do it harm.
The team also covered how groundwork laid years ago is paying dividends now during the war, as well as an update on the types of cyber threats we’re observing, including the deployment of the GoMet backdoor.
You can watch the video version of this event on the Talos blog which is also where you can access relevant resources and articles.
Security Stories faces off, once again, against the Beers with Talos crew, to see if we can regain some dignity after our close defeat in the first game of "Would I lie to you?"
This second round contains stories of betrayal, donkeys, embarrassing situations, and antics so dangerous, Hazel feels compelled to issue a "Don't try this at home kids" warning at the start.
Speaking of Hazel, where is she, and why does she suddenly have a much deeper, more Americanized voice?
This episode also contains a preview of what we've got going on at Black Hat. Be sure to stop by booth 1932 to see lightening talks, and chat with our crew of experts. More details can be found at https://www.cisco.com/c/en/us/products/security/black-hat-usa.html
We hope to see you there!
Martin Lee, who leads Strategic Planning and Communications for Cisco Talos in EMEA, joins Hazel for a quick chat about the current status of hiring in cybersecurity.
We discuss the industry needs are in terms of bringing more threat analysts in, what is getting in the way of hiring, and the potential solutions that we as an industry should consider.
We also talk about the skills need to be nurtured within the security workforce, and how we can improve knowledge transfer.
For more stories on the various paths people have taken to join the cybersecurity industry, take a look at our ebook: Diversity in cybersecurity: A mosaic of career opportunities
Today’s episode, recorded live at RSA 2022, features a great conversation with Tomás Maldonado, NFL Chief Information Security Officer, and Brad Garnett, Director of Cisco Talos Incident Response. The dialogue is led by none other than the brilliant Tazin Khan.
Taz talks to Tomás about his early life and career (“I didn’t want to be another statistic”) and how he approaches new opportunities. He talks about how he communicates his vision for a cybersecurity strategy, as well as how he ‘blends the tracks’ between a technical and managerial style of leadership.
Tomás then goes into details about how he builds steering committees across the NFL so that people have a voting stake in technology and security decisions. Together with Brad, they discuss how Cisco and the NFL worked together to secure the most recent Super Bowl (“This sounds like a movie script”), and how they created a playbook based on learned threat intelligence, to proactively secure future major events.
For more details about the work Cisco has been doing to help secure the NFL, visit this blog https://blogs.cisco.com/security/nfl-teams-up-with-cisco-to-secure-super-bowl-lvi
All rise, all rise, for the inaugural episode of Infosec Court, brought to you live from RSA Conference.
Judge Wendy Nather presides, and three infosec experts (Helen Patton, Dave Lewis and Dennis Fisher) all have a ‘hot take’ that they want to be more widely accepted in the infosec industry.
Their task as plaintiffs is to try to persuade Judge Wendy and a jury of their peers that their hot take deserves to become infosec canon.
Come for the chance to hear Wendy in her element. Stay for the outrageous objections ("What even is Non Zero Trust?) and the unexpected turn of events when Wendy introduces an Amicus Curiae, handed to her shortly before proceedings began...
For our 50th episode, we invited our friends from Cisco Talos to join us for an authentic, truthful conversation about mental health and burnout.
Amy Henderson, Ashlee Benge, Matt Olney, and Mitch Neff, joined Hazel and Taz to share some experiences. We start by talking about the work that Talos has been doing in Ukraine and the mental health effects of that work. That also includes that weird, disconnected feeling that can develop when we're doing as much as we can to help, but we also go home to a warm and comfortable bed, i.e not in a war zone.
This takes us to conversations about other global events, and how hard it can be to prioritize self care when everything feels...a lot....
We also share our own practices and techniques that have helped us manage our mental health, and how we can give ourselves permission to be kind to ourselves.
Further resources:
Creating safe spaces in cybersecurity ebook
Ryan K. Louie’s presentation at RSA: The mental health impact of cyberattacks
Black Hat community: A place to engage with Black Hat attendees on topics specific to the InfoSec community, including health and well-being.
Cisco Gateway: A global online community where Cisco customers share their professional and personal challenges and stories.
CALM (Campaign Against Living Miserably):Leading a movement against suicide.
Today's episode features a chat between Hazel and three security leaders - Accidental CISO (yes, the anonymity intrigues us too!), Liz Waddell, Incident Response Practice Lead for Cisco Talos, and Christos Syngelakis, CISO and Data Privacy Officer at Motor Oil Group.
They talk about their experiences of building security resilience – so we got into the key elements of an Incident Response plan, how to achieve company wide buy in, the best ways to go about training your people and trying to avoid burnout, how to use threat intelligence and all the things that go into running a SOC, what to do in the case of a Zero Day attack, how to build a security design program...and so much more.
For more stories on how to build security resilience, check out our new ebook here.
This episode was originally recorded as a live Cisco Chat event. You can watch the original video here
Today we're going full steam into the metaverse and Web 3.0. Joining us to discuss his research on this topic is Jaeson Schultz, Technical Leader for Cisco Talos Security Intelligence & Research Group.
Taz and Hazel have a great conversation with Jason about the evolution of the metaverse, as well as the security implications, such as rising numbers of scams going after people’s cryptowallets, and the ethical concerns that are potentially popping up.
For more on this topic, have a read of Jason's in depth research on the metaverse and Web 3.0 here.
Jason has over 20 years specialising in thwarting abuse of security protocols like SMTP, HTTP/S, and DNS. He's a former manager of the SpamCop DNSBL which has been taking the fight to the spammers for over a decade.
He's also assisted in design and development of the Cisco IronPort Anti-Spam content scanner and he’s also developed some of the architecture & content detection for Cisco’s Web Security Appliance, Cloud Web Security, and Next Generation Firewall products.
Most recently as Technical Leader for Talos, he conducts security research, speaks at conferences, and authors blogs and whitepaper publications.
Today's guest is Shannon Lietz, VP of Vulnerability Labs at Adobe. Shannon joined Hazel to talk about how she first got into offensive security and the lessons she’s learned along the way, as well as the kind of work she and her team undertake at Adobe to test defenses.
We also talk about measurement, and how security was never set up to be measured properly, which is something Shannon is trying to change. She also has some thoughts on risk management and tackling that in a different way.
And at one of the most poignant parts of the interview, Shannon talks about the moment she decided to change her leadership style.
If you're interested in the book Shannon mentioned, "Humanocracy" here's a link to the website www.humanocracy.com
Finally, if you're free at 10am PT on April 26th, be sure to join Hazel plus special guests Accidental CISO, Liz Waddell and Christos Syngelakis, to discuss stories of how to build security resilience. Sign up to be reminded here - CiscoChat Live: Detect, Respond, Recover
Today we welcome two guests to the Security Stories pod. Firstly Martin Lee from Talos drops by to give us an update on wiper malware, and how it’s been playing a part in cyber attacks on Ukrainian organizations and infrastructure.
We talk about the history of wiper malware, where it’s cropped up before, it’s role in the kill chain and possible threat actor motivations, as well as what organizations can be doing to prevent this type of attack.
Secondly, we welcome Jerry Gamblin, Director of Security Research at Kenna Security to join us for an in depth chat about his career. Jerry’s story is a really interesting one, from starting out on the IT helpdesk, to working on security networks at the Misouri House of Representatives, and onto his role at Kenna where he has built several tools to help people understand the different types of vulnerabilities and how to mitigate them.
We discuss Jerry’s approach – how he inspires his team to think differently, and how personally he’s driven a sense of thinking outside of the job description. We also discuss how organizations can deal with the ever growing list of new vulnerabilities, and how you can prirotise them.
Head here for Kenna's Prioritization to Prediction report
Head here for Jerry's vulnerability analysis and graphing CVE.ICU
A short bonus episode for your feeds today, as Hazel got the opportunity to sit down with Cisco Talos' Head of Outreach, Nick Biasini, and chat all things hybrid work.
Nick recently published the research, "Time to secure hybrid work for 2022, not 2002" and in this episode, we explore some of the malicious activities from state-sponsored actors and criminal organizations, which have made being a defender an increasingly difficult task in recent months.
Join Hazel for a threat alert event for guidance on current cyberattacks and insight into internet activity in Ukraine. This event was originally broadcast live, featuring members of the Cisco Talos threat intelligence team, and Cisco ThousandEyes.
Both teams are actively monitoring the digital landscape and openly sharing essential findings to contribute to the safety of our customers globally.
Speakers:
JJ Cummings, Principal, Threat Intelligence & Interdiction, Cisco Talos
Amy Henderson - Leader, Strategic Planning and Communications, Cisco Talos
Angelique Medina, Head of Internet Intelligence, Cisco ThousandEyes
For the latest information on Talos' research into the current situation in Ukraine, check here for continual updates: cs.co/TalosUA
In today's Security Stories episode we meet Goher Mohammad, Head of Infosec at L & Q Group, one of the UK’s largest charitable housing associations which houses over a quarter of a million people.
Goher’s is a story of resilience, geeking out over technology, and the challenges and rewards of building a brand new security team from scratch. We also talk about the power of community and how Goher is bringing together fellow non-profit security professionals.
Before that, Taz and Ben are back to join Hazel in the pod booth for a really interesting discussion on data privacy - more specifically online tracking, and some recent developments made there. You can also check out Cisco's new Data Privacy Report: Privacy becomes mission critical.
Please note that this episode was recorded before the events in Ukraine. For analysis on what Cisco Talos is observing, which includes a variety of cyber attacks targeting Ukraine, including disinformation, defacements, DDoS, and wiper malware please check out the Talos threat advisory blog.
Cisco stands guard with our customers in Ukraine. You can read here about Talos’ efforts to-date in information gathering, threat hunting and the assigning of dedicated Cisco engineers to Ukrainian organizations seeking to secure their operations, and how we have taken the extraordinary step of directly operating security products 24/7 for critical customers in Ukraine while over 500 employees at Cisco have joined them to assist in collecting open-source intelligence.
Since there’s been a lot of discussion and debate about Extended Detection and Response (XDR) at the moment, we thought we would bring on two experts to talk about it.
Enric Cuixeres is a Cisco Secure customer who has implemented an XDR strategy within his organization Leng D'Or. Our other expert is former US army CID special agent and computer forensic examiner Jessica Bair. Jessica is the Director of Technical Alliances at Cisco, who has been helping many of our customers with their XDR strategies.
We discuss the practical implications of implementing XDR, as told by people who have been there and done it – and also what benefits will it really bring, including how it can help overburdened security staff.
For more on this topic, take a look at our ebook "Extended Detection and Response for Dummies."
Learn more about the Cisco Gateway community as mentioned in the episode.
Before that, Lindsey O’Donnell Welch, executive editor of Decipher, is back with us for the second week in a row. Lindsey discusses the just-announced Cyber Safety Review Board and its role in assessing “significant cybersecurity events”. For more information about this check out Decipher's report.
And finally, you can view the on-demand broadcast "Defending Against Critical Threats" in which six experts from across Cisco Secure came together to analyze what's been happening in the realms of ransomware, supply chain attacks, vulnerabilities, log4J, Emotet and the rise in Mac OS malware.
Today's guest is Jane Frankland, owner and CEO of Knewstart, and founder of the IN Security movement. Jane has been in the cybersecurity industry for 24 years and is an award winning entrepreneur and best selling author of "IN Security: How a failure to attract and retain more women in cybersecurity is making is all less safe’. She was also named as the third most influential person in cybersecurity in the UK.
We discuss Jane's start in cybersecurity and her entrepreneurial career, including how she built a seven-figure business within two years. She has held senior executive roles and been actively involved in OWASP, CREST and Cyber Essentials. We discuss her activism around attracting and retaining women in the industry, and why we need more right brain thinkers.
Plus, Jane talks about her latest venture, "The Source", a platform for women in cybersecurity and businesses who value them. Find out more.
Before that, for our opening topic we are delighted to welcome Decipher's Executive Editor Lindsey O-Donnell Welch, and Editor-in-Chief Dennis Fisher to discuss what we know about the cybersecurity situation currently in Ukraine (note we recorded this on 20th January and it's a very fluid situation).
Decipher is an independent editorial website covering security news, exploring the impact of the latest risks and providing informative and educational material for readers intent on understanding how security affects our world.
Episode timings:
0.00 - 13.46: Opening topic with Decipher
13.47 - 69.24: Interview with Jane Frankland
69.25 - 70.16: Closing thoughts
Today's guest is the brilliant Jarell Oshodi, currently Deputy Chief Privacy Officer for the Centre for Disease Prevention and Control. So she’s had an interesting few years....
Hazel and fellow data privacy advocate Tazin both interview Jarell, in what turned out to be a really fun chat. Jarell has spent 12 years honing her expertise in data compliance and privacy at various federal agencies, including the Department of Justice, and her current role at the CDC.
Jarell has such an interesting story as to how she’s got where she is, and how her life experiences have affected her whole approach, which she shares with us.
We talk about the issues around data privacy today and what she’s witnessed in her work, and we also talk about the importance of giving people a voice when they may not feel like they have one.
And, just as we were about to end the interview, we stayed on another 10 minutes to chat about a really celebratory moment for Jarell – stay tuned to find out what that was.
Links mentioned in this episode:
Cisco Networking Academy: https://www.netacad.com/courses/cybersecurity
Afro Tech: https://www.experience.afrotech.com
Today's guest is Gary Hibberd, AKA "The Professor of Communicating Cyber" for the Cyberfort Group. Gary has worked in cybersecurity for over 35 years, spending much of that time in highly regulated industries.
We get into some areas that we’ve not covered all that much on the podcast before, such as the impact of branding and marketing on cybersecurity, and how organizations might be missing a trick if they’re not talking to their marketing teams about how they’re keeping their customers’ data safe.
We also talk about the work that Gary does for his charity, Gamers Beat Cancer.
Plus, if you haven't seen it already, he shared his experiences for our recent e-book on mental health and burnout.
The wonderful Tazin Khan is also back, and she opens the show with a thoughtful discussion on how experts aren’t always the best teachers, and how we can best create community and representatives that can help our mission as an industry.
On today's show our guest is Brad Arkin, Cisco’s Chief Security and Trust Officer.
Before joining Cisco (the very same day Cisco issued a work-from-home mandate in March 2020!), Brad was Adobe’s first Chief Security Officer. He grew the security function from just a few employees, to over 600 globally.
Early in Brad’s career, he co-founded the Software Security Group at Cigital and led the Application Security practice for AtStake. He was a pioneer in software security, helping code writers in commercial settings adopt a “built-in security” approach throughout the development process rather than treating security as an afterthought.
Since joining Cisco, he has led the company’s rapid global Zero Trust architecture deployment to over 100,000 users across 120,000 devices in just five months. He is focused on evolving the Cisco Secure Development Lifecycle and security governance models to help accelerate Cisco’s transition to software and services.
Also on today's show, we invite Mitch Neff from the Beers with Talos podcast to join us, to see if we can settle the score from our 'Would I lie to you?' episode which ended in a heart breaking tie.
As Ben tells his security career story, can Mitch win the title for his team? Or will he lose it all? Will anyone's dignity remain intact?
Plus, Ben has been visiting the database vaults and has some excellent research on the top threats encountered by Cisco Secure Firewall, and the Secure IPS component and Snort rules used to control and inspect the traffic on the network.
To see Ben's research in full, visit https://blogs.cisco.com/security/threat-trends-firewall
We’re delighted to be joined today by members of the Cisco Talos Threat Detection & Response Group, a group we haven’t chatted to on the podcast before, but hopefully this goes some way to making up for that error.
Joining Hazel for a brilliant discussion, are Christopher Marshall (far better known as Marshall), Director of Talos threat detection and response, Diana Brown, Security Research Engineer, Doaa Osman, Security Analyst, and Lilith Wyatt, Security Research Engineer.
The Threat Detection and Response team are Cisco customers' first responders. They're hunting for the hardest-to-find threats, and for one team, they come into work every day and try and do something that's never been done before.
We have a chat about the team's day to roles, and how they each got into the security industry. Each path is fascinating, and unique.
We also learn about the supportive culture within Talos, and how each team member is given the freedom and encouragement to do their best work.
This conversation is for anyone who wants to get into the threat detection and response aspect of the security industry, or who may have kids or mentees who would like to do so.
To see current Talos job openings, visit https://talosintelligence.com/careers
Welcome to a very special edition of Security Stories, as we go head to head with the Beers with Talos podcast team.
Using a live game show format based on the British show 'Would I lie to you?' we present "facts" about significant moments in our security careers—but can the teams work out who is telling the truth, and who is bluffing?
This episode features Mitch Neff, Joel Esler and Matt Olney on the BWT team. Joining Hazel on the Security Stories team are Dennis Fisher of Decipher, and Pam Lindemoen, CISO Advisor for Cisco Secure.
To learn if we can sort fact from fiction, don't miss this special edition: "Would I lie to you? Security Stories versus Beers with Talos."
To learn more about Talos careers, head to https://talosintelligence.com/careers
Today's guest is Dr Kelley Misata. Having survived years of cyber stalking, Dr Kelley completed a PhD in information security, where she did her dissertation on the cybersecurity preparedness of nonprofits working with victims of violence.
She later set up her own non profit company, Sightline Security.
This is her story.
In the pod booth, we're excited to be joined by a brand new cohost! Tazin Khan, whom you might remember joined us as a guest in episode 25, joins Ben and Hazel to talk about the findings of a new Cisco consumer data privacy study.
We each then relate it to our own experiences of taking action to protect our personal data.
For more information about Sightline and to get involved with the community, visit https://sightlinesecurity.org
For the Cisco consumer data privacy report, head to https://www.cisco.com/c/dam/en_us/about/doing_business/trust-center/docs/cisco-cybersecurity-series-2021-cps.pdf
Episode time stamps:
00.00 - 5.15: Intro and getting to know Taz
5.16 - 30.23: Interview with Dr Kelley Misata part 1
30.24 - 50.28: Discussions on new consumer data privacy findings
50.29 - 68.05: Interview with Dr Kelley Misata part 2
68.06 - 72.12: Closing thoughts and outro
Today we're delighted to be joined by Pam Lindemoen, Advisory CISO at Cisco Secure and former Deputy CISO at Anthem Inc.
In this thoughtful interview, learn about Pam's passion for championing women in IT, her approach to learning from mistakes and failure, as well as her top tips to ensure that security and risk can be understood across the entire business.
Pam has gained a well deserved reputation as a bold and strategic thinker, and being an exceptional leader - she shares many of her lessons learned from 25 years in the IT industry in this chat.
Before that, host Hazel shares a tribute to Mick Jenkins MBE, the first ever guest on Security Stories, who recently passed away. She shares her memories of first meeting him, the impact he had, and continues to have, on her work, and she remembers some of his most inspiring stories.
"Never let fear get in the way of your dreams." Mick Jenkins, MBE
For the full Mick interview, listen to episode 1 of the podcast at https://securitystories.buzzsprout.com/926089/2985046-1-from-the-battlefield-to-the-boardroom-with-mick-jenkins-mbe
To learn more about our CISO connections community, visit https://www.cisco.com/c/en/us/products/security/ciso-connection.html
Today's guest is Stuart Coulson, director at Hidden Text Ltd, where he uses the skill sets and knowledge borne of many years in the security industry to help others.
It's probably fair to say that Stuart's journey in cybersecurity hasn't been the most traditional He’s been in sales, recruitment, engineering, working on UK government cybersecurity contracts, to being a deputy CISO. He is now the cybersecurity director of an online gaming company, in addition to managing Hidden Text.
In addition to discussing Stuart's career path in cybersecurity, we chat about managing social media as an infosec professional, and how to deal with imposter syndrome (it's an interesting take - stay with it!). We also discuss how improv comedy relates to cybersecurity, and Stuart has some great advice for anyone who wants to get into mentoring.
In the studio, Ben and Hazel discuss the rise of proxyware abuse, and why organizations and individuals need to be aware of this growing threat. This is based on some excellent research conducted by our Talos team, which you can read more about on this blog.
Also take a look at our brand new ebook, "Creating safe spaces in cybersecurity". This focusses on the topic of mental health and cybersecurity burnout. We’ve captured the stories of 20 people (both leaders and practitioners) from across the cybersecurity industry, and hope that by sharing their experiences, we’ll inspire anyone who is struggling to know they are not alone.
Finally, check out a few of Stuart's Hidden Text articles which we found particularly interesting:
Imposter syndrome does not exist
Dear infosec hiring managers
Episode time stamps:
0.00 - 18.28: Intro and discussing the rise of proxyware abuse
18:29 - 68.45: Interview with Stuart Coulson
68.46 - 79.18: Closing thoughts and outro
It's a warm welcome today to our guest Ian Thornton-Trump, CISO at Cyjax Limited, also known as @phat_hobbit on Twitter.
Ian talks about his career journey, from joining the Military Intelligence Branch of the Canadian Forces, to managing IT projects at the Canadian Museum of Human Rights, to being a CISO.
He also shares his top lessons learned from 30 years in the cybersecurity industry, from his paper '8 Leadership Principles' (or, as Ian refers to it "8 of my biggest mistakes").
In the studio, Geraldo, currently studying Film and Television at college, disucsses how cybersecurity is represented in the media. We discuss Mr Robot, Silicon Valley, The Matrix, and how Hollywood has led some accurate (and very inaccurate) portrayals of the industry.
In Threat Corner, Ben takes us through the storied history of the REVil ransomware family, and how the attackers operate under a ransomware-as-a-service model. Follow along at https://blogs.cisco.com/security/threat-protection-the-revil-ransomware
Episode time stamps:
03:20 - 25:23: Cybersecurity in the media
25:24 - 40:53: Ian Thornton Trump interview, Part 1
40:54 - 50:54: Threat Corner: REVil ransomware family
50:55 - 65:47: Ian Thornton Trump interview, Part 2
65:48: Closing thoughts and outro
Jenny Radcliffe, AKA 'The People Hacker' joins us as our guest today. Jenny is a world renowned Social Engineer, hired to bypass security systems through a mixture of psychology, con-artistry, cunning and guile.
We learn about incidents in Jenny's childhood which led her to become a 'burglar for hire', including getting locked in the lion’s enclosure at the zoo! She has spent a lifetime talking her way into secure locations, protecting clients from scammers, and leading educational simulated criminal attacks on organisations of all sizes in order to help secure money, data and information from those with genuine malicious intent.
We also talk about how Jenny copes mentally with being in some of these situations, and how she works with organizations and helping them with their security culture.
There’s a great deal of advice here too about how to protect yourself and your friends and your families from social engineering attacks.
Jenny's podcast is available at https://humanfactorsecurity.co.uk/podcast-2/
Before that, it's Sana's last episode with us for a while (sob!) but she goes out on a high by telling the story of three military terms that have shaped the cybersecurity narrative in the last couple of decades. If you are like a movie buff, or geek out on military terminologies, or simply say ‘Roger that’ in response to everything, then you'll love this segment.
If that wasn't enough, we also have Nirav Shah join us in the pod booth. Nirav is new to Cisco, having joined us directly from Solar Winds. He was working then when the massive breach that was heard around the world happened. We hear the inside story, and learn how this was a catalyst in the threat landscape. Learn more in Nirav's blog here.
Episode time stamps:
0:00 - 15:31 - Intro topic with Sana - Three military terms that have shaped the cybersecurity narrative
15:32 - 42:29 - Interview with Jenny Radcliffe, Part 1
42:50 - 55:26 - Nirav Shah on the Solar Winds breach
55:38 - 73:24 - Interview with Jenny Radcliffe, Part 2
73:25 - 83:30 - Closing thoughts and outro
Our guest today is Stuart Peck, director of cybersecurity strategy for Zero Day Lab. Stuart talks to Hazel about his various career roles within threat intelligence, social engineering and incident response. We also talk about how he went from a non technical background to a technical one, and overcoming imposter syndrome in the process.
Stuart then talks about how preparing your mentality for a data breach is an incredibly important part of your plan, and how you can do that. We also talk about the Many Hats Club community that Stuart set up, providing a network for infosec professionals as well as raising incredible funds for vulnerable children's charities. You can see more details about this at https://themanyhats.club
Plus, there’s some great advice in this interview for anyone who might be on the verge of burnout, or needs any tips on how to manage stress, as Stuart talks about his experience in these areas.
In the studio, we have a new cohost joining the ranks for a few epsiodes - Geraldo De La Cruz who is interning with us this summer and has his own podcast. We get to know him a little.
Plus, we tell the story of one of the most notorious data breaches of all time – the Enigma code. It's striking how many of the tactics used still tie in to current thinking when it comes to protecting one’s data.
Time stamps:
0.00 Intro and getting to know Geraldo
10:16 The story of breaking the Enigma code
24:19: Stuart Peck interview
72:40: Closing thoughts and outro
The past week has been a lot for people in the security industry. Last Friday in the US, people were just about to clock off for what would hopefully be a relaxing Fourth of July long weekend. Only for cybercriminals to have other plans.
This episode contains the audio from a recent live stream, where Hazel sat down with Cisco Talos’ US Outreach Team lead Nick Biasini. We talked about the unfolding events surrounding the REvil ransomware campaign and Kaseya VSA supply chain attack.
Nick broke down the complicated scenario, and talked about how the two attacks worked together. We also spoke about the impact for organizations around the world, as well as what we’re seeing with ransomware on a general level at the moment.
The audio includes questions that we received during the live stream from our audience, and Nick's answers.
To stay up to date on this attack, please take a look at the Talos response post which is being continually updated.
Joining today's episode are not one, but two distinguished guests. First of all, we have Dug Song, Cisco's Chief Security Strategy Officer. Dug is the founder of Duo Security which was acquired by Cisco in 2018, and he is one of the industry’s most passionate and outspoken voices about building inclusive cultures.
We're also joined by Gene Hall, Vice President of Security Marketing at Cisco. Gene is a veteran of Cisco for over 20 years and is someone who is a great advocate for nurturing the next generation, and driving down barriers across the security industry.
Both Gene and Dug meet up with Hazel to discuss how they both got into the security industry and what issues they're passionate about. We also chat about how Duo was born, and the values that Dug led with which have stood the test of time.
We discuss the greatest security challenges that our customers are going through and how Cisco Secure is helping them through those.
We also talk about what we can all do as a collective industry to build more inclusive cultures, and address the security skills shortage. Plus, we learn how Dug got his motto of ‘Dig and be Dug in return’.
To learn more about Cisco's recruitment drive and to check out current openings, head to https://www.linkedin.com/company/cisco/jobs/
Today's guest is Tanya Janca (@shehackspurple), founder and CEO of We Hack Purple, an online learning academy, community and weekly podcast that revolves around teaching everyone to create secure software. She’s also the best selling author of 'Alice and Bob Learn Application Security'.
We chat about Tanya's career journey and the various hats she's collected (there are many!) - as well as being a founder and CEO, she’s been a pentester, a CISO, an AppSec Engineer, and software developer. She’s worked in startups to public service, including being the CISO for the Canadian elections when Justin Trudeau was elected, to working in tech giants.
Tanya has a really interesting perspective on many issues in cybersecurity, as you'll see in this chat. From why application security needs to be given more of a spotlight, to the issue of representation, working closely with devs, and seeking a fundamental change in the way we educate people in the industry.
Before that, Ben leads our intro topic. He discusses the influence his father had on him and his security career, which prompts Hazel and Sana to look back at their own lives and talk about their greatest influencers.
Plus, we discuss the new proposal from Talos and the Cyber Threat Alliance to truly tackle the global ransomware threat. If you can, please take a few minutes to read Neil Jenkins and Matt Olney's op ed piece on this, which is available on the Talos blog.
Time stamps:
01:46 - 15:33 Intro topic - Influencing figures, led by Ben
15:34 - 32:51 Tanya Janca interview, part 1
32:52 - 38:49 Ransomware recommendations discussion
38:50 - 60:00 Tanya Janca interview, part 2
60:01 - 66:56 Closing thoughts and outro
Our guest today is Al Huger, Vice President of Cisco’s security platform and response. Al is a well known figure in the vulnerability space, and has developed several patents for cloud managed threat products which hunt down malware. He is also a three time veteran of building security companies, and successfully selling them to large organizations, including Cisco.
In this interview there is a huge amount of useful advice for anyone who is thinking of selling a company, or perhaps building your own security company is an ambition of yours. We also explore the hottest security trends, taking a particular look at the future of end user security and SASE.
And we lift the lid on Al’s creative process, as he talks about how he comes up with new ideas. We also talk about culture, the power of his team, and Al’s advice for security leaders heading into the next 6 months.
In the studio, Sana leads our intro topic by recapping the best of RSAC 2021. And in Threat Corner, Ben and Hazel have a discussion on a new threat actor category posed by Talos: the privateers, whereby Hazel finally learns the difference between privateers and pirates.
Resources mentioned in the episode:
Cisco Secure Insights Summit with Al Huger: https://www.linkedin.com/video/live/urn:li:ugcPost:6806262317710491648/
Talos blog post on the proposal for a new category of threat actor: https://blog.talosintelligence.com/2021/05/privateer-groups.html
Time stamps:
02:10: Intro topic by Sana - RSAC 2021 highlights
11:06: Interview with Al Huger, part 1
23:27: Threat corner: The new potential threat actor category - the privateers
28:39: Interview with Al Huger, part 2
48:49: Final thoughts and outro
On today’s show our guest is Helen Patton, CISO Advisor for Cisco Duo. Previously, Helen was an Executive Director at JP Morgan Chase, and CISO for Ohio State University.
Helen talks candidly about these two wildly different experiences—as well as how to know when it's time to leave a company, resilience in the age of Covid and killer hornets, and how the CISO role is likely to develop over the next three years.
In the virtual studio, we chat about the new executive order signed by President Biden aimed at improving the United States’ cybersecurity, and Ben runs down his latest threat research on supply chain attacks.
More resources:
Helen's RSA talk: https://www.rsaconference.com/Library/presentation/USA/2021/a-year-of-living-dangerously-resilience-after-covid-killer-hornets
Helen's blog response to the new Executive Order on cybersecurity issued by President Biden: https://duo.com/blog/cybersecurity-executive-order-observations
Ben's supply chain attacks blog: https://blogs.cisco.com/security/threat-explainer-supply-chain-attacks
Time stamps:
0.00 - 14.54 Intro and recapping President Biden's executive order on improving the nation's cybersecurity
14.55 Interview with Helen Patton part 1
35.49 Supply chain attacks
46.02 Interview with Helen Patton part 2
01.01 Closing thoughts and outro
Today's episode is a little different from our usual format. In conjunction with Mental Health Awareness month, we welcome three leaders from Cisco Talos to join Hazel, Ben and Sana for a discussion on mental health, stress and burnout - specifically in the security and threat intelligence industry, although there are things that we discuss that could be relevant beyond that.
Joining us are Matt Watchinski, Vice President of Talos who has been a guest before when we talked about the power of diverse teams. We also have Matt Olney, Talos’ Head of Threat Intelligence and Interdiction who our listeners will know from our episodes on election security. And we have Mitch Neff, who leads Talos' communication strategy and hosts the Beers with Talos podcast.
Together, we share our own experiences about dealing with stress and burnout, both during the pandemic and beyond. We share these experiences from an individual level, and also our experience managing people within teams, and also helping managers who are managers too.
Of course, there are many areas within mental health and people's experiences in threat hunting that we don't cover, so please don't consider this a full resource on the topic.
We hope that by sharing our experiences, we’re helping to destablise any stigmas that are out there when it comes to talking about these topics, and if you or anyone close to you is struggling at the moment, we hope this inspires you to talk to someone.
Some further resources:
Adjusting to extraordinary times ebook https://www.cisco.com/c/en/us/products/security/extraordinary-times-ebook.html
Creating safe spaces, with Chloe Messdaghi
https://www.buzzsprout.com/926089/6457849-20-creating-safe-spaces-and-the-troubling-nature-of-attribution-in-threat-research-with-chloe-messdaghi-and-warren-mercer
We welcome back Talos guests Nick Biasini and Edmund Brumaghin discuss their latest research on the rising cases of collaboration app abuse, and how cyber criminals have come up with new ways of using them as an entry point into organizations. They also share lots of advice on how people can protect themselves from this increasing trend. You can read more about their research on the Talos blog.
In the studio, Ben shares the origin stories behind some cyber threats—and how they got their unusual names. For more on this, check out Ben's twitter thread.
You can also check out more information about the Ryuk ransomware in this run down by Talos
Plus, Sana chats about the evolution of threats over the past year, how people can protect their home environments, and how the industry is fighting back.
Episode time stamps:
02:14 - The origin stories of prominent malware
14:23 - Interview with Nick and Edmund on collaboration app abuse
33:33 - Threats in the home environment, and how the industry is fighting back
43:58 - Closing thoughts
We're delighted to have Tazin Khan as our guest this week. Tazin is a data privacy advocate and founder of the Cyber Collective, a community-centered organization that seeks to help people understand the ways data and privacy impact them, and empower them to learn more about their data privacy rights. Cyber Collective is the first and only women of color-owned data ethics, privacy, and cybersecurity research organization.
In what Hazel describes as one of the most moving interviews she's ever conducted, Tazin isn’t afraid to tap into the power of her vulnerability, and talk about incidents that greatly affected her and shaped who she is today. From growing up as a Bengali immigrant, making a life for herself and her family in New York, finding her cybersecurity "sweet spot" and taking a stance on key issues, it's a fascinating story.
In the studio, Sana leads our intro topic. She takes us through a journey of discovery with some 2021 security trends, as decided by over 1650 security experts. This includes how companies are working on their rapid response capabilities, and what are the top causes of burnout. Access the full data here cisco.com/c/m/en_us/products/security/securex/polls-ebook.html
And finally Ben brings you the latest threat intelligence research, with some fascinating insights into the top threat categories certain industries face, and the threats that they’re more likely to encounter. Read the full blog at blogs.cisco.com/security/threat-trends-dns-security-part-2
Episode time stamps:
01:35: Sana discusses 2021 security trends
11:30: Interview with Tazin Khan part 1
38:07: Industry specific threat trends with Ben
45:21: Interview with Tazin Khan part 2
64:08: Closing thoughts
After a bit of a break, Security Stories is back! And we're back with a brand new lineup. Joining Hazel and Ben in the virtual pod booth is Sana Yousuf, a Cisco security marketing leader and storyteller, responsible for a diverse set of threat-focused products and solutions that bring our security platform to life. She is a diversity and inclusion evangelist and author of research reports.
In this episode, we'll get to know Sana, as well as kick off a brand new opening feature. For each episode we’re going choose a topic that’s on our mind, and lead a discussion on it. There are no rules! This week it's Hazel's turn, and she leads a discussion on influential women in cybersecurity history, whose work may have gone under the radar. For more on this topic, check out this Time Magazine article: time.com/4974299/hacker-history-code-girls/
Also check out our brand new ebook, "Lifting each other up: A celebration of women in cybersecurity and their advocates" cisco.com/go/boostincybersecurity
Our guest this week is Dr Christine Izuakor (@Stineology). Christine is the founder of Cyber Pop up which helps small businesses with their cybersecurity needs and strategies. She’s had a really varied career, going from the corporate world to start up land, becoming an author, CEO and hacker along the way, and she is someone very motivated by injustice. In this interview we hear about her life, why some people told her not to pursue a career in cybersecurity, and we chat about the opportunity divide and how we can make the field more accessible to more people.
Plus, we reveal the latest threat trends in DNS Security to help inform you on where to dedicate resources or training. For more of those great looking charts Ben talks about, head to https://blogs.cisco.com/security/threat-trends-dns-security-part-1
Episode time stamps:
02:40 Getting to know Sana
07:50 Influential women in cybersecurity history
19:12 Interview with Dr Christine Izuakor part 1
46:05 Threat trends: What DNS Security told us about the past year
59:38 Interview with Dr Christine Izuakor part 2
76:18 Outro
We're joined today by Wade Baker, co-founder of Cyentia Institute (@wadebaker) and Wolfgang Goerlich (@jwgoerlich), Advisory CISO at Cisco, for a fun discussion on security outcomes.
Wade and Wolf dissect the results from Cisco's 2021 Security Outcomes Study, which seeks to answer the ultimate question, "What actually works in cybersecurity?" using random sampling and statistical analysis.
Together, we discuss how can we efficiently and effectively manage our cybersecurity risk, how is it that even the largest companies with the biggest security budgets still struggle to achieve certain outcomes, and with all the various options out there for achieving a successful cybersecurity program, which ones should practitioners focus on? New technology? More training? Better incident response procedures? Listen to find out!
The full report can be downloaded for free from www.cisco.com/go/securityoutcomes
On today's show we welcome two guests onto the pod. First up is Esmond Kane, CISO of Steward Health care. Esmond spoke to Hazel and told her what it was like (and still is like) to be on the front lines of the pandemic, and how security is playing a part in helping the fight back against COVID-19.
Esmond also gets pretty deep in describing what the role of a security leader is today, and we also learn how Sherlock Holmes and Dr Watson help him to find the best talent.
Our second guest is Edmund Brumaghin, threat researcher for Cisco Talos. He joins Hazel and Ben live to discuss his research into Big Game Hunting (the security kind) and the evolution of ransomware over the past 12 months.
Plus, Ben and Hazel take a quick dive into the main topics from our latest threat report, out today. For the full picture, download the magazine "Defending against critical threats: A 12 month roundup"
For our final episode of 2020, we're joined by two very special guests. First up is Fareedah Shaheed, CEO and founder of security consulting company Sekuva. As a serial entrepreneur, Fareedah has just embarked on a brand new path, which she reveals during our chat.
Fareedah has also just been named on Forbes’ 30 under 30 list, which identifies those who are making waves in technology. She has such a fascinating story, from growing up in Saudi Arabia to building her own businesses, to her explorations in how the human mind works, and developing her own identity.
Secondly, Ben and Hazel are joined by Ben Munroe, Senior Director for Security Product Marketing at Cisco, for our Review of the Year. The three of us each count down our top 3 security moments, and reveal why we chose them.
In an incredibly testing year, we've found some moments to celebrate, some moments to be proud of, some moments to reflect on, and some moments we originally overlooked.
Thank you so much for listening to Security Stories this year. We'll be back in January with more amazing guests, more stories, and some exciting new plans. We wish all our listeners a great festive season, and look forward to connecting with you again in 2021.
Episode time stamps:
0:00 Intro
07:48: Interview with Fareedah Shaheed
47:22: Review of the Year with Ben Munroe
01:39:12: Outro
In today's episode we're delighted to welcome Chloé Messdaghi, an infosec advocate and activist who is working to create a safe space for underrepresented groups within the industry.
Chloé is the CEO and founder of We are Hackerz, as well as the cofounder of Hacking is not a crime, Women of Security and The Hacker Book Club, and she is also VP of Strategy at Point3 Security.
We chat about the growing issue of burnout and how people can spot the signs within themselves and others. Chloé also reveals how she comes up with her ideas, and how she is seeking to address certain issues in the cybersecurity industry such as women and underrepresented groups being trolled online. Plus, we discuss the fight for the truth in a growing age of misinformation.
Our second guest is Warren Mercer, a threat researcher from Cisco Talos who helped to discover the Olympic Destroyer attack in 2018. Warren is in the studio with Ben and Hazel to discuss the research he’s being doing on the evolution of Remote Access Trojans, and one of the newest players, Poetrat.
We also discuss his starring role in the new multi part documentary by Tomorrow Unlocked, called 'Who hacked the 2018 Winter games’. That then brings us onto the topic of why attribution is so difficult in the threat landscape, and what some of the consequences are of misattribution.
Our guest today is one of the security industry's most prolific video bloggers, Javvad Malik. Javvad has a signature fresh and light hearted take on security, and during this interview he talks about how he found his own voice. He also has plenty of advice for our audience on how to put a great presentation together to keep your audience engaged.
In addition, Javvad's story on how he got into the security industry, and the people who helped him along the way, is well worth a listen to. Plus, we discuss the "Zombieland" rules for Security, and find out what kind of movie Javvad would make if he was put in charge of such a thing.
Also in this episode, we bid a fond farewell to Noureen who is moving on to an incredibly exciting new adventure. Before she goes however, she has some wonderful words of inspiration and wisdom for our listeners.
And finally Ben has some brand new threat research for us. He's here to tell us all about Remote Desktop Protocols. We examine the ways in which RDP has been a target of bad actors over the years, covering unauthorized logins, man-in-the-middle attacks, and vulnerabilities, including the ‘wormable’ BlueKeep exploit. You can learn more about this research at https://blogs.cisco.com/security/rdp-and-the-remote-desktop
Episode time stamps:
0.00 - 14.16: Intro and saying goodbye to Noureen
14.17 - 54.50: Interview with Javvad Malik
54.51 - 67.54: Threat of the month (RDP attacks) with Ben
67.55 - 69.09: Closing words
"Computers make excellent and efficient servants, but I have no wish to serve under them."
That Star Trek Spock quote is relevant in more ways than one today, because in this episode we meet Gabriel Gumbs, Chief Innovation Officer at Spirion, a company which specialises in data and security privacy. Gabe's role is to lead the charge on where data security is going next, which includes the evolution of what Gabe lovingly refers to as the 'SPOC' (aka the security and privacy operations centre).
We also chat about Gabe's career trajectory, from when he was hacking portable devices at school. We also touch on how he’s been able to overcome personal fears of speaking in public.
After that, we welcome Nigel Houghton from Talos and Wolf Goerlich, one of our advisory CISOs for Duo Security at Cisco, to talk about the impact COVID-19 has had and potentially will have on security operations.
We also learn how Talos was able to transform itself into a entirely remote workforce, and the technical and non technical challenges that arose from that. And Wolf talks about how organizations can modernise their security defences and take the path to passwordless.
To learn more about this, do have a read of Wolf's paper 'Passwordless: The Future of Authenthication'
You can also check out Gabe's other podcast, 'Privacy Please' https://www.buzzsprout.com/622234
On today's episode we’re heading into the murky waters of online manipulation campaigns, and particularly how they’re used to try and influence political elections.
To do that, we welcome back Theresa Payton, the first female CIO of the White House and author of 'Manipulated: Inside the Cyberwar to Hijack Elections and Distort the Truth'. We also welcome for the first time, Nick Biasini. Nick is a threat researcher within Cisco Talos and recently published a paper called ‘The Building Blocks of political disinformation campaigns’, which is part of Talos’ hands on research into election security.
We chat about some of the things that shocked Theresa when she was doing her research into manipulation tactics, as well as the amplification methods that are being used to spread certain lies online. Plus, we talk about what can be done to curb these campaigns with only a few weeks to go until the United States general election.
This is a really fascinating discussion, and whilst it highlighted the huge challenges that we’re facing at the moment, Nick and Theresa shared a lot of great information on how we can overcome them.
Also in this episode, Ben Nahorney shares his latest research on current threat trends. This time we rank the Indicators of Compromise that organizations have encountered grouped by particular topics, including ransomware, credential stealing, and looking at the top operating system IoCs.
Link to Manipulated: Inside the Cyberwar to Hijack Elections and Distort the Truth'
Link to ‘The Building Blocks of political disinformation campaigns’
On today's episode, Hazel and Noureen are joined by Leticia Gammill, Cisco’s Channel leader for Canada and Latin America, and Matt Watchinski, Vice President of Cisco Talos.
Together, we share our first hand experiences and stories on the impact of diversity in cybersecurity. There are some brilliant insights here about where companies can find diverse talent, beyond the usual recruitment channels.
We also discuss how organizations can build a culture of mentoring and support, so that members of diverse teams can feel appropriately valued, and retainment levels are strong.
Also in this episode, Hazel chats to Cisco’s new CISO, Mike Hanley. Mike became our CISO in June, after 5 years in Duo where he was part of Duo Labs and then became Vice President of Security, and built and nurtured the team around him.
From the importance of hiring a multitalented diverse team, to building a culture of appreciation, openness and fun, Mike’s interview is a fascinating listen for anyone leading a team today.
We hope you enjoy this episode, and are inspired by both of these discussions as much as we were when we recorded them.
Episode timestamps:
0.00 Intro
02:27 Discussion on diversity in cybersecurity
46:49 Mike Hanley interview
1h 26: Closing remarks
For more on this subject, do check out our new eBook, "Diversity in cybersecurity: A mosaic of career possibilities". It contains over 20 interviews with cybersecurity professionals from around the world.
We asked them how they all got their starts in the industry, and what they would tell their younger selves if given the chance. You can read that ebook by visiting cisco.com/go/securitycareersebook
In the first of four special episodes being released during the month of October, today's episode is all about cybersecurity careers.
Hazel, Ben and Noureen are joined by guests Mitch Neff and Corien Vermaak, for a discussion on how we all got our starts in the cybersecurity industry. As it turns out, none of us took a conventional path! We also talk about the people and the mentors that helped us along the way, including some practical advice for anyone who wants to be a mentor, or gain a mentor.
We passionately tackle the topic of job descriptions and why they might be contributing to the so called "cybersecurity skills gap". We also talk about what hiring managers can do to make sure they're not putting the right people off with their words.
Before that, Hazel meets Curtis Simpson, Chief Information Security Officer at Armis to discover his story. A self taught cybersecurity geek, Curtis spent 20 years at Sysco, building a decentralized network.
He talks about how he turned around perceptions on cybersecurity being a cost centre, and focussed on how cybersecurity could contribute to business outcomes. He also touches on just how difficult a decision it was to leave after 20 years, but how he knew it was the right thing.
We also talk about his organisation's reaction to COVID-19, and Curtis' take on the current threat landscape, particularly around securing IoT devices.
We hope this episode proves that that there is no singular footpath into cybersecurity. And that’s no bad thing.
Time stamps:
0.00 Intro
3.46 Interview with Curtis Simpson
47.26 Discussion on careers in cybersecurity
1.42.00 Close
Here are some more resources as mentioned in our careers discussion:
Noureen's cybersecurity mentoring hub: https://cybersecmentorship.org
Noureen's mentor and mentee group on LinkedIn: https://www.linkedin.com/groups/8673525/
Cisco NetAcademy courses: https://www.netacad.com/courses/cybersecurity
Blue Team Village Discord of which Talos are a sponsor: https://discord.com/invite/blueteamvillage
Also check out our just published eBook: Diversity in Cybersecurity: A Mosaic of Career Possibilities
Today we chat to Chris Leach, senior CISO Advisor at Cisco. From his background as an accountant (which he hated!) to venturing into cybersecurity ("I had to learn to speak in bits and bytes, after only speaking in 1s and 0s"), he has a fascinating story to share.
Chris also has some brilliant insights into how to be a great leader and role model for your team, and he has some really poignant thoughts on resiliency, bouncing back, and dealing with the fear of failure.
Also in today's episode, Ben shares the highlights of his just-published research on threat landscape trends. The idea behind this work is to shed light on areas where you can quickly have an impact defending your assets, especially if you're dealing with limited security resources. You can read more about this in Ben's blog post.
And finally our 'On this Day' feature takes us back to the movies! In honor of the 25th anniversary of the film Hackers, the team sits down to talk about what that movie got right, and perhaps, not so right, with some surprising reveals.
We also discuss what our own movies on cybersecurity would look like, if we were each in charge of screenwriting. Personally, we hope Noureen's idea does genuinely get greenlit!
In October, we're doubling our production schedule to release episodes on topics that mean a lot to us, including careers and diversity in cybersecurity, and how to protect your loved ones from disinformation campaigns (or "fake news) online. It would be brilliant if you could subscribe to your podcast feed of choice so that you don't miss any of these exciting episodes.
We almost called this episode "Robocop 4: The future of security law enforcement", but we actually hope that movie happens so we didn't want to jinx it...
But security law is our prime directive today, as on this episode we have an interview with Tanya Forsheit, partner at Frankfurt Kurnit Klein & Selz and co-chair of the firm's privacy & data security group. Tanya is considered one of the world's leading data privacy and security counselors and litigators.
During our chat, we talk about why the United States needs a privacy law at the federal level, similar to what the European Union has done with GDPR. We also talk about what the future holds for data privacy in the next 12-24 months, within the context of COVID-19 and an increasing amount of IoT devices.
Tanya is also highly experienced in data breach incidents, and is often involved in data rescue operations for her clients. So she has some great views on response planning and business continuity.
Before that, Noureen brings us some fascinating stories from her recent mentor and mentee workshop sessions, including how people who were made redundant back in March at the start of lockdown have been able to find new jobs in the cybersecurity industry. We also have a chat about careers and job descriptions, and why perhaps more thought needs to go into some of those descriptions in order to attract more people who are passionate about the industry.
For our "Emerging Threats" section Ben has been doing some very in depth research into the ransomware variant "WastedLocker". He talks about the nuances of this attack and how the bad actors spread across the network to further compromise additional systems until all the key systems are under their control. You can read more in his blog here.
And finally for "On this Day" our time travel machine takes us back to 2003, and the story of the Blaster worm. For Ben, this was a trial by fire as he had just started work in a threat intelligence company and this was his first project. Hear him relive some not so fond memories!
In a break from our usual format, today I wanted to bring you highlights of some of my favorite interviews with security leaders so far.
There's a definite theme to the clips I've chosen - it's all about what we can do to help each other. There are ideas here about some of the things that we can do to make sure the cybersecurity industry becomes more accessible in the future, in terms of attracting talent from more places. And there are important discussions on the role of an ally; those who can give up their privilege in order to give others a boost.
In the intro I mention a competition that we're running to give away free copies of Theresa Payton's book 'Manipulated: Inside the Cyber War to hijack elections and distort the truth'. Listen to the question, and send in your answers as a direct message to us on either of the below social networks, by the closing date of 31st August for a chance to win a free copy. Terms and conditions apply.
Link to Cisco Secure on Facebook
Link to Cisco Secure on Twitter
Election security is right up there as one of the most important discussions of our lifetime. To quote fictional president Dr Josiah Bartlet, "Decisions are made by those who show up" and so protecting people's right to show up and be heard, is fundamental. That's what this episode is all about.
We have Matt Olney, Director of Talos Threat intelligence and Interdiction joining us today, to talk about his paper, ‘What to expect when you’re electing’. After the Washington Post first reported in the summer of 2016 on how adversaries had breached servers for one of America’s two major national political parties, Talos initiated what would become a long-running and hands on investigation into election security issues. This included watching one state plan an election in real-time.
We were able to talk to Matt for about an hour (and we could have talked to him for far longer) and it truly is a fascinating story with many lessons learned, and it’s an important reflection on where America stands now on election security leading into the General Election in only 3 months time.
Also joining us for the discussion, is Steve Caimi from the Cisco US public sector cybersecurity marketing team. Steve has over 20 years experience in cybersecurity and has an in depth knowledge of industry best practices including the NIST Cybersecurity Framework, the NIST Risk Management Framework, and the MITRE ATTACK framework. During the interview Steve provides many recommendations for security practitioners in the context of election security.
Back in the virtual studio, Ben, Noureen and Hazel discuss their own personal experiences of voting in elections from their different corners of the world.
This is just the start of our election coverage in the run up to November, but in the meantime, here are some resources you may find useful:
We're joined this week by Quentyn Taylor, CISO for Canon Europe. Odds are that you might have had your hands on a Canon camera or printer at one point in your life, and if you’ve ever had a security related query about their products in Europe, it’s Quentyn’s team who you would have spoken to. That's because as well as protecting Canon, the cybersecurity team are also customer centric, which is a really interesting story.
Quentyn also talks to Hazel about missing those "in person" meetings and how he's trying to overcome the virtual hurdle. Plus we discuss the skills and qualities that he looks for in his team members, and why firing the CISO immediately after a data breach is rarely the best course of action. We then end our interview as all interviews should: with a spot of cybersecurity cocktail making.
Check out Quentyn's Security Insights video series here: https://www.youtube.com/results?search_query=security+insights
In the non studio studio, Ben and Noureen fill us in on the last couple of weeks of hacker news, including what Cozy Bear have allegedly been up to.
And for 'On this Day' we take the DeLorean back to 2016, to explore the story behind the Mirai botnet. We discuss the chaos that was caused when certain networked devices running Linux were turned into remotely controlled bots that were then used in large-scale network attacks.
Don't miss our next episode, which is an election special! We'll be welcoming several special guests, to help us discuss where America stands with election security heading into November's general election.
In this episode we chat to Andy Ellis, who, on the very day we interviewed him, was celebrating his 20th anniversary as the Chief Security Officer for Akamai. We cover many topics - from taking down the "booth babe" culture at RSA, to fighting for more representation and diversity on cyber panels, to how he eliminated the password at his organization and built a Zero Trust network, before that became a thing.
Andy also shares one of the most interesting Star Wars theories we've ever heard, and has a fascinating take on heroes vs villains, and how the two overlap depending on who's telling the story. He then talks about why he hires librarians and journalists in his security team, and also, exactly how hard it is to train lizards. (The last two topics aren't related, btw!)
You can read Akamai's "State of the Internet" report here: https://www.akamai.com/uk/en/resources/our-thinking/state-of-the-internet-report/
In the studio, Hazel and Ben are joined (virtually) again by Noureen Njoroge. Following the interview with Andy, Noureen talks incredibly passionately about her advocacy roles for women and minorities in cybersecurity, and some of the mentoring work that she does. For anyone who wants to know more about what they can do to give more opportunities for others - don't miss this section.
For our 'Emerging Threats' feature, we cover Ripple20: a set of 19 critical vulnerabilities impacting a TCP/IP software stack, used by wide variety of vendors and installed on millions of systems: enterprise network, consumer devices, but also IIoT. More details can be read about this in our blog: https://blogs.cisco.com/security/ripple20-critical-vulnerabilities-might-be-putting-your-iot-ot-devices-at-risk
And finally we have our 'On this Day' feature, which is when we jump into the DeLorean and head back in time to explore a significant security event. This time we’re travelling back to 2001 to talk about Sircam, which was a notable worm that spread by email. The series of unfortunate events often started with a couple of lines of text that began ‘I send you this file in order to have your advice’.
If you'd like to know more about the advocacy roles for women and minorites that Noureen is involved in, as well as access a wealth of cybersecurity resources, you can check them out at https://cybersecmentorship.org
This episode of Security Stories is a little different from usual, but for good reason! With the help of some very special guests, we take a comprehensive look back at the Not Petya cyber attack, the Sandworm hackers, and the context behind this act of cyber warfare.
First to join us is Noureen Njoroge, a senior cybersecurity engineer and threat intelligence analyst at Cisco. Noureen is a passionate advocate for women and minorities in the IT industry, and is the founder of Cisco's global mentoring program, as well as the president of North Carolina Women in Cybersecurity (WiCyS) Affiliate chapter. We learn about Noureen's passion for mentoring, as well as her thoughts on the threat landscape.
Then we're joined by Andy Greenberg, senior cybersecurity investigative journalist for Wired Magazine, and author of the book "Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers". The book tells the true story of the desperate hunt to identify and track an elite team of Russian agents who are bent on digital sabotage. It starts out as a detective story but it soon turns into a disaster story as the truth starts to come to the fore.
Andy also talks to Hazel about how he spent time in Russia and Ukraine, gathering sources, and learning about this new emergence and type of cyber criminal. And he has a fascinating take on how the hacker culture has evolved in recent years.
Finally, we're joined by senior threat analysts from the Cisco Talos team, including Craig Williams, Matt Olny and Mitch Neff. We chat to them about what happened on the day of the attack (June 27th 2017), the process the investigative team used to find out what was really happening, and what impact the attack has left on the threat landscape and the world at large.
This really is a fascinating episode with some incredible guests, who each share their insights, experience and advice for the benefit of the wider cybersecurity community.
In this episode we meet Marene Allison, Vice President and Chief Information Security Officer at Johnson & Johnson. We talk about her life journey, from graduating from West Point Military Academy in the first class to include women, to then becoming a special agent in the FBI in undercover drug and counterterrorism operations, to how she’s built a diverse cybersecurity team and program at J & J. It's one of Hazel's favourite interviews to record yet. Stand by for the Hollywood script she's writing off the back of it!
For our Threat of the Month, Ben reveals some interesting stats about remote working, and he talks about how cyber criminals' patterns have shifted to pandemic related activities across spam and malicious domains. You can find more details about this at Cisco.com/go/threatofthemonth
And finally for our 'On this Day' feature the DeLorean takes us back to 2004, where we discuss the Cabir worm, said to be the first ever worm to infect mobile phones.
On today's show we have a brilliant interview with a famous, altruistic Irishman who wears cool glasses and has a nice variety of white hats.
Nope, it's not Bono, but are lucky enough to have Brian Honan as our guest on this episode. We cover a wide variety of topics including the genesis of the Irish Emergency Response Team, his thoughts on why companies get such a bad hounding when they suffer a data breach, running a company and managing a team, and why the cybersecurity industry needs more accountability.
And finally for our "On This Day" feature, which is when Ben and I jump in the Delorean and visit a significant cybersecurity event in the pasto, we go all romantic, sort of. Because this month is the 20 year anniversary of a certain worm called "I love you" or the "Love Bug", or indeed the "Love letter for you" - a cyber attack which ended up infecting over 10 million personal Windows computers. Discover the unique story behind this attack, and the additional part of the story from only a few days ago.
In this episode we meet Masha Sedova, co-founder of Elevate Security, a company which uses data and behavioral analytics to help organizations build a strong security culture. Masha was recently announced as finalist for the 2020 Innovation Sandbox Award at RSA, which tells you something about how unique and interesting her solution is.
We also chat about certain challenges that she faced setting her company up, and also what it's like to be a female entrepreneur setting up a business in the cybersecurity industry...let's just say Hazel nearly fell off her chair when Masha told her what happened during one particular investor meeting!
Also in this episode, Ben talks about the resurgence of digital extortion scams, what they tend to include, and what to do about them.
And finally for our "On this Day" feature we’re only going back 3 years this time, but it’s a biggie. It’s been three years WannaCry, so we revisit the timeline of the attack, how it all unfolded, and the significance the WannaCry attack still has today.
Links to further resources mentioned in the episode:
Digital extortion scams: https://blogs.cisco.com/security/your-money-or-your-life-digital-extortion-scams
Talos ransomware discussion: https://blog.talosintelligence.com/2019/07/ransomware-extortion-roundtable-government-payments.html
Registration for Cisco Live June 2-3 https://www.ciscolive.com
Meet Mark Weatherford, who has one of the most impressive cybersecurity CVs we’ve ever seen! Learn how he created the U.S Navy’s first ever Red Team, and how he was hired by Arnold Schwarzenegger to help "change the way California did technology".
Mark also talks about how he worked with many different groups to get laws passed to formerly establish a security program for the first time in several US states…And we talk about how Batman fits into all of this….
Also in this episode, Ben and Hazel celebrate the anniversary of Snort becoming open source in our 'On this day" feature. It's a fascinating story that starts with a rainy day/weekends project that entered into the Hall of Fame as one of the best pieces of open source software of all time.
And finally in our "Emerging threats" segment, Ben talks about a previously unknown type of Remote Access Trojans, recently discovered by Cisco Talos, which we're calling "PoetRAT." We talk about the unique features of this RAT, its impact, and what organizations can do to protect themselves.
In the latest episode of Cisco's Security Stories, we have the incredible fortune to speak to Theresa Payton, who was named one of the top 25 Most Influential People in Security by Security Magazine and is one of the most respected authorities on security and intelligence operations.
Theresa was the first female CIO of The White House, taking up the post in George W Bush’s second term. We chat about what life was really like working in the White House. She also starred in CBS’ ‘Hunted’ TV series which gives ordinary citizens to chance to try and evade police capture , running the intelligence operations side.
Theresa is also very passionate about protecting people’s right to privacy, and has co-authored two books focused on helping others learn how to protect their privacy online. Her third book is called ‘Manipulated: Inside the cyberwar to hijack elections and distort the truth’ which is coming out on 22nd April, and we talk in quite a bit of detail about the topic of hijacking elections, and what people can do to protect their voting rights.
Also in this episode, our ‘On this day’ feature takes us back to 1993 to discuss the announcement of the ‘Clipper chip’, which was designed to enhance the security of communications devices. It’s a really interesting story that addresses people’s right to privacy and the balance with survelliance, so stay tuned for that.
And Ben chats to us about 'credential dumping', an increasingly popular technique whereby an attacker scours a compromised computer for credentials in order to move laterally and/or carry out further attacks. To learn more, visit https://blogs.cisco.com/security/stealing-passwords-with-credential-dumping
Wendy Nather, Head of Advisory CISOs at Cisco Duo, joins us for the latest episode of Security Stories. Wendy discusses how we can involve users in our security practices, rather than blaming them when they fall foul of the rules. And she comes up with a unique idea for shaking up the security industry.
Also in this episode, Ben has some handy tips for remote workers and how we can all play our part to ensure the security and privacy of our data. More details about how Cisco is supporting companies with an expansion of our free security offerings is available here https://blogs.cisco.com/security/cisco-expands-free-security-offerings-to-help-with-rise-in-remote-workers
We also chat about how cyber criminals might be taking advantage of the current situation - more details are available on the Talos blog https://blog.talosintelligence.com/2020/03/covid-19-pandemic-threats.html
And finally our 'On this Day' feature, where we look back into the cybersecurity archives, takes us on a journey of the Conficker worm, and how April Fools Day 2009 was shaping up to be a key day in cybersecurity history before things took a surprising turn.
Welcome to the first episode of our new fortnightly podcast, Security Stories. A podcast by the Cisco Security team, we use storytelling to talk about the past, present and future of cybersecurity.
On this episode, our special guest is Mick Jenkins MBE, CISO for Brunel University London, former army officer and soldier, and author of several spy novels including The Kompromat Kill. Mick talks about his life, career, and how he has led some incredibly innovative changes at his organization to turn its cybersecurity approach around.
In the pod booth, hosts Hazel and Ben chat about Cisco's latest 'Threat of the Month', Industrial IoT attacks, and why they're on the rise. Plus discover why March 16th 1971 was a momentous day for cybersecurity in our 'On This Day' feature.