CYBER24 is a weekly podcast with one simple goal: to help business leaders and policy makers understand the often-intimidating subjects of cybersecurity and data privacy. Each week, our panel of rotating experts discusses the top cybersecurity issues and stories in the news. We decode the cybersecurity jargon to help you understand the complexities of cybersecurity and to help you ask the right questions of your IT and cybersecurity teams.
In this episode of the CYBER24 podcast, presented by VLCM, we discuss application security with Laura Bell Main, the founder and CEO of SafeStack. We discuss incentivizing security in software design and her belief that secure software is more than just the code developers write.
Panelists
Laura Bell Main, CEO of Safestack
In this episode of the CYBER24 podcast, we sit down with Patrick Hynds and Duane Laflotte from Pulsar Security to discuss cybersecurity and their podcast "Security This Week." As experienced cybersecurity professionals and educators, they share their insights on teaching cybersecurity to their audience and what businesses can do to protect themselves against cyber threats. Tune in to learn from their expertise and experience.
Panelists
Patrick Hynds, CEO
Duane Laflotte, CTO
In this episode of the CYBER24 podcast, presented by VLCM, we talk about cybersecurity education with Laurie Salvail, the executive director of CYBER.org. She’s working to improve cybersecurity literacy and expand K-12 cybersecurity education to help student stay safe online and prepare them for cybersecurity careers.
Panelists
Laurie Salvail, Executive Director of CYBER.org
Our guest this episode is Eric Olden who is the Co-founder and CEO of Strata Identity. He is a widely respected thought leader in identity management. He is also the visionary behind Symplified’s strategy to secure the cloud. We discuss the identity landscape, identity orchestration and identity fabric.
In this episode of the CYBER24 podcast, presented by VLCM, we look at security tools your organization may have but not utilize - or under utilize. We talk with Andre Keartland of Netsurit about the Microsoft security stack and how using it right can help you get the most from limited security personnel.
In this episode of CYBER24, presented by VLCM, we discuss the growing compliance risks stemming from business communications with Garth Landers of Theta Lake. He discusses key findings from the company’s 2022 Modern Communications Compliance and Security Report, why firms from all sectors should be prepared for regulatory scrutiny of their ability to capture, monitor, retain and retrieve all relevant communications, and how businesses can prepare now to future-proof their collaboration tool usage.
Panelists
Garth Landers, Software Executive at Theta Lake
In this episode of CYBER24, presented by VLCM, we visit with Sangeeta Krishnan, who is a senior analytics leader with Bayer and the author of “Thriving in a Data World.” We discuss the challenges of establishing a data-driven culture, the most difficult thing she sees about working in the data world and data industry buzzwords - including her favorite one she says no one actually understands.
Amazon book link
https://www.amazon.com/Thriving-Data-World-Leaders-Managers/dp/1637424167](https://www.amazon.com/Thriving-Data-World-Leaders-Managers/dp/1637424167
Follow her
https://www.linkedin.com/in/sangeeta-krishnan/
https://sangeetakrishnan.com/](https://sangeetakrishnan.com/
Panelists
Sangeeta Krishnan, North American Analytics Lead at Bayer
In this episode of the CYBER24 podcast, presented by VLCM, we talk with Bron Gondwana, the CEO of Fastmail. He’s a former programmer who shares his perspective on open standards. We talk about what that means for email, why businesses should adopt open standards and the biggest isues facing data privacy today.
In this episode of the CYBER24 podcast, presented by VLCM, we take a deep dive on one of the hottest phishing trends, HTML malware. Karl Sigler of Touchware SpiderLabs shares his perspective on HTML smuggling, social engineering and how this type of attack will evolve in the coming years.
In this episode of the CYBER24 podcast, presented by VLCM, we talk with Tyer Moffitt, senior security analyst at OpenText Secuirty. They’ve released their 2022 Nastiest Malware Report and we discuss the top threats facing small businesses and average Joes. We also dive into what Tyler is seeing as the most intersting new tactics the hacker groups are using.
In this episode of the CYBER24 podcast, presented by VLCM, we sit down with Jon Murchison, founder and CEO of Blackpoint Cyber. Jon is a fromer NSA computer operations expert and we cover everything from how he recruits the best cyber talent in a high-demand market to how the ongoing war in Ukraine has impacted the types of cyber attacks his team is fighting.
In this week’s episode of CYBER24, presented by VLCM, we discuss digital extortion with Michael Orozco of MorganFranklin Cybersecurity. He gives his insight on why are cybercriminals stealing personal and business information for future use and digital extortion and how they target differnet types of people, sectors or organizations. We also cover what should organizations do once they have been attacked or information is compromised and what steps can people or organizations take to mitigate these risks in the future.
In this week’s episode of CYBER24, we sit down with Dr. Danny Rittman to discuss Overlooked Security Vulnerabilities. Dr. Rittman is an R&D expert and CTO of GBT Technologies. We discuss everyIn this week’s episode of CYBER24, we sit down with Dr. Danny Rittman to discuss Overlooked Security Vulnerabilities. Dr. Rittman is an R&D expert and CTO of GBT Technologies. We discuss everything from a new type of chip he’s working on that will greatly increase storage capacity. We also talk about radio cybersecurity and authentication methods, inlcuidng how machine learning plays into cybersecurity. thing from a new type of chip he’s working on that will greatly increase storage capacity. We also talk about radio cybersecurity and authentication methods, inlcuidng how machine learning plays into cybersecurity.
Businesses spend significant time building their digital defenses - and with good reason. But there’s a type of attack many overlook and it’s a combination of a physical and digital attack. Wr discuss phygital attacks with Will Plummer, chief security officer of RaySecure.
Cybersecurity has been a male-dominated field and that’s a problem - especially when there’s incredible demand for talent right now. In today’s episode, we discuss women in cybersecurity, mentoring and more with Lynne Doherty of Sumo Logic.
Guest
Lynne Doherty
Linkedin
Twitter
Sumo Logic
In this episode, we discuss Cyber Risks in the Remote-Work World with Tyler Moffitt of OpenText Security. We ask him if remote work is making this risky cyber behavior worse and look at the recent Uber breach to learn what organizations should do to ensure employees are prepared these days.
Panelists
Tyler Moffitt, Senior Security Analyst
In this episode of CYBER24, presented by VLCM, we discuss Safety for Payment Platforms with Josh Shaul, CEO of Allure Security and author of Practical Oracle Security. We cover how online payment platforms can protect themselves from brand impersonation and spoofing, how AI can prevent account takeover attacks, brand Protection tactics every business should consider, and how retail brands can leverage technology to get ahead of the curve to protect their brand reputation.
Hiring tech talent can be a real challenge for any organization. In this week’s episode of CYBER24, presented by VLCM, we discuss the Cultural Needs of Tech Businesses with Helen Horstmann-Allen, the COO of Fastmail. The pod covers changes she’s seen in the process of recruiting talent for an international tech business in the post-COVID era to competing with tech giants for talent and advice she has for small to mid sized tech companies looking to land talent in 2023.
In this episode, we sit down with Stephen Semmelroth, the VP of cyber at Avant Communications. Stephen was in the Army for 6+ years, and he served in Afghanistan and the Army's Cyber Corps, where he led a red team and a threat intelligence team defending US assets across an entire continent. He also co-wrote the training doctrine that defines how cyber units defend the US. Stephen broke his back while on a mission in Afghanistan, which left him paralyzed, and he had to relearn how to walk. After retiring from the Army, he founded Rainier Cyber, a cybersecurity recruiter that matches Cyber Vets with tech jobs across the county, which was acquired by StrataCore in 2020.
Panelists
Stephan Semmelroth, VP Cyber at StrataCore
The pandemic had a ripple effect on the supply chain but there’s also a software supply chain - and a disruption there can be big trouble for your business. In this episode of CYBER24, presented by VLCM, we chat with Anirban Banjeree CEO and Co-founder of Riscosity, a company dedicated to providing businesses with a working Software Supply Chain Security Platform––granting them greater visibility, control, and security.
We all rely on email and have accepted its benefits and drawbacks. But email can be much better than what most of us experience.
In this episode, Rik Signes, CTO of Fastmail, helps us understand how we can better protect ourselves on the web––specifically as we use email. Fastmail is an email provider that guarantees total privacy over your information, offering better privacy with email aliases and custom addresses. They offer protection from tracking, data leaks, and spammers by providing alternative addresses that keep your main address private.
In this week’s episode, we sit down with Eli Schwartz to discuss the power of search engine optimization. Schwartz is an SEO expert and consultant with more than a decade of experience working for leading B2B and B2C companies. His ability to demystify and navigate the SEO process has generated billions of dollars in revenue for some of the internet's top websites, including such clients as Shutterstock, WordPress, Blue Nile, Quora, and Zendesk.
As head of SurveyMonkey's SEO team, Schwartz oversaw the company's global operations, helped launch the first Asia-Pacific office, and grew the company's organic search from just one percent of revenue to a key driver of global revenue.
His work has been featured by TechCrunch, Entrepreneur.com, and Y Combinator, and he has given talks at business schools and keynote conferences around the world. His new book is Product-Led SEO: The Why Behind Building Your Organic Growth Strategy
Learn more at elischwartz.co
In this week’s episode, we discuss how organizations can foster a “security culture” with Perry Carpenter, who currently serves as chief evangelist and strategy officer for KnowBe4 the world’s most popular security awareness and simulated phishing platform.
A recognized thought leader on security awareness and the human factors of security, he’s provided security consulting and advisory services for the world’s best-known brands. His previous book, Transformational Security Awareness: What Neuroscientists, Storytellers, and Marketers Can Teach Us About Driving Secure Behaviorsquickly gained a reputationas the go-toguide for security awareness professionalsworldwide, and, in 2021, he was inducted into the Cybersecurity Canon Hall of Fame.
He’s the creator and host of the popular 8th Layer Insights podcast and co-author of the new book The Security Culture Playbook: An Executive Guide to Reducing Risk and Developing Your Human Defense Layer .
What should you do with old devices? We discusses e-waste disposal and hardware security with John Shegerian, best-selling author and co-founder of ERI, the largest recycler of e-waste in the United States.
You can find more information about ERI here.
Shegerian's book, The Insecurity of Everything: How Hardware Data Security is Becoming the Most Important Topic in the World, is available here.
In this week’s episode, we discuss how businesses and users can “think like hackers” with Ted Harrington, author of Hackable: How to do Application Security Right and renowned “ethical hacker.”
In today’s discussion, Horacio Zambrano, Chief Marketing Officer at Secret Double Octopus, tells us about the future of “passwordless,” and the future of user security and authentication.
Want to learn more? You can check out today’s featured guest at DoubleOctopus.com.
Seniors are reluctant to adopt to new tech and when they do they can be easy targets for hackers. In this episode of CYBER24, we sit down with cyber security expert and best-selling author Scott Schober to discuss how seniors can stay safe online.
DNS Security has remained stagnant for 30 years; in this episode, we sits down with John Todd, the general manager of Quad9—a company specializing in DNS security—to talk about the future of the protocol.
In this episode, we are joined by Daniel Schuyler, a cybersecurity expert, to discuss cyber warfare in the Russia-Ukraine conflict.
In this episode, we sit down with Dr. Sameer Patil, professor of computer science at the University of Utah. Widely published (and cited), Dr. Patil is an authority on cybersecurity and privacy. In this episode, he helps businesses and organizations to know how they can counter cybersecurity threats.
For most people, artificial intelligence is what companies use to serve us ads and learn more about us. But AI is supposed to be helpful to humans and make life better. In this episode of CYBER24, we sit down with Trung Tran, the founder and CEO of Amplio.ai. He has an interesting perspective on artificial intelligence and his company is working on a way to put it to good use for the employees first and from that help the company avoid burning people out.
Webcheck Security asked its key engineers and practitioners about cyber trends to watch out for in 2022. We get the inside scoop in this episode of CYBER24.
Guest Expert:
Greg Johnson, Webcheck Security
You hear the stories of data breaches and snippets of associated costs, but you may not be privy to ALL the costs of that cyber incident. What are the factors involved in data breach incidents and how can you prepare and assign a dollar value BEFORE something bad happens?
Panelists
Greg Johnson, CEO, Webcheck Security
In this episode of CYBER24, presented by VLCM, we look at how tech is impacting the spy game, the spillover impacts on regular citizens from international cyber attacks and another round of congressional rumblings on antitrust tech bills.
Guest Expert:
Dan Schuyler from Nice CXone
There's rarely any good news for anyone hit with ransomware but in this episode of CYBER24, presented by VLCM, we look at how contacting law enforcement quickly can help you recover money paid to cybercriminals and how the authorities acted to put three hackers behind bars.
Panelists
Dan Schuyler, Nice CXone
There's no such thing as a cybersecurity silver bullet, but a virtual private network might be the closest thing. As incidents of cybercrime and ransomware continue to increase, more and more businesses are utilizing VPNs to solve problems before they happen.
The feds try to slow cybercrime by randomly seizing more funds collected by hackers. That comes as Congress looks to punish businesses that don't report cyber incidents. We take a closer look on this episode of the CYBER24 podcast, presented by VLCM.
Cybercrime is growing exponentially and private businesses, individuals and government can't seem to slow the growing threat. Now one tech giant is putting some serious cash into the fight and looking to upgrade government systems in the process. Will it make a difference? We discuss on this episode of the CYBER24 podcast, presented by VLCM.
Japan calls out bad cyber actors, the DOJ ditches carrots for sticks, ransomware isn't going anywhere and Twitch source code gets stolen. We cover it all on this week's episode of CYBER24, presented by VLCM.
This was a week Facebook won't soon forget and for all the wrong reasons.
First, a whistleblower made allegations on 60 Minutes Sunday and before Congress later in the week that the social media giant incentivizes angry posts that cause division. And Monday Facebook, along with Instagram and Whatsapp were down for nearly six hours.
But Facebook says the problem wasn't the result of an outside bad actor breaking through its security, but rather a self-inflicted wound. In this episode of CYBER24, presented by VLCM, we look into the issue and the fallout with Mike Hussey, the former CIO for the state of Utah.
In 2021, every business is an online business and that means you deal with risk. How strategically you manage that risk is critically important when there are cyber criminals who would love nothing more than to take you down for the money or just for the fun of it. In this episode of CYBER24, presented by VLCM, we discuss strategic risk management with Dr. Paul Godfrey, business professor, strategic risk management, and co-author of *Strategic Risk Management, New Tools for Competitive Advantage in an Uncertain Age.
Immediate response to being hit by hackers can send your head spinning and force you to overlook some important steps to take before the problem gets worse. In this episode of the CYBER24 podcast, presented by VLCM, we look at five steps you don't want to overlook when hit with ransomware. Plus, we look at the industries most frequently targeted by hackers.
Guest ExpertMike Hussey, Utah Division of Technology Services
The recent data breach at T-Mobile exposed the personal data of 54 million people - not all of them customers of the nation's second-largest mobile carrier. Hackers didn't hit the company with ransomware but they are shopping for buyers for as much as $270,000 worth of bitcoin. As much as anything, the breach has raised serious questions about how much data businesses collect and keep, whether they need it or not, and whether or not it's worth the risk.
Guest Expert
Mike Hussey, Utah Division of Technology Services
Whenever you buy or sell something online you can bet there are cyber criminals who would love to hack that transaction. But just what are the risks related to eCommerce and what should your business do about them? We discuss it on this episode of the CYBER24 podcast, presented by VLCM.
Guest Expert
Mike Potter, CEO and Founder of Rewind
It's not just the frequency of cyber attacks that are on the rise, the cost of each of those attacks is up sharply and expected to surpass $10 billion worldwide within five years. In this episode of CYBER24, presented by VLCM, we discuss cyber-attack costs in dollars and more with Rewind CEO Mike Potter.
Guest Expert
Mike Potter, CEO and Founder of Rewind
Over the past several weeks, we've noted the sharp increase in the amount of money hackers are demanding in ransomware cases. Businesses seem to be taking note and they're upping the ante by shelling out big bucks for cyber talent.
Guest Expert
Mike Hussey, Utah Department of Technology Services
Legislators looking to fight back against cyber criminals consider prohibiting state and local law enforcement from paying ransom to hackers. They say making it known they won't negotiate will, ultimately, make them less of a target. But are they right? We discuss it in this episode of the CYBER24 podcast, presented by VLCM.
Guest Expert
Mike Hussey, Utah Division of Technology Services
In order to adequately protect your business, you need to know what kind of threats you face. In this episode of the CYBER24 podcast, presented by VLCM, we look at the importance of risk assessment as well as a military cybersecurity exercise being hosted right here in Utah.
Guest Expert:
Dan Schuyler, NICE
When your business is hit by hackers demanding a ransom to unlock your systems, you quickly realize you are in a desperate position. But, in addition to the immediate problem, you have a decision to make: do you pay the ransom and get back online or do you stand on principle? Lots of factors come into play but a new one has emerged recently, the potential tax advantages of paying up. We look at why mixed incentives are frustrating law enforcement and cybercrime victims in this episode of the CYBER24 podcast, presented by VLCM.
Guest ExpertDan Schuyler, NIC
As the COVID-19 pandemic winds down, there are still concerns about people who do not get the vaccine and the potential they have to spread illness. One proposed way to get the vaccinated public back to normal life is by using a vaccine passport. The idea is simple: prove you've been vaccinated and you can travel, shop and recreate without any concerns. But for governments, healthcare providers and businesses, adding new, sensitive data comes with privacy and cybersecurity concerns. In this episode, we discuss the potential benefits and drawbacks of vaccine passports.
Guest Expert
Rob Shavell, CEO and Co-founder of Abine/DeleteMe
For years, cybercriminals have operated in a sweet spot. They have targeted businesses with the resources to pay the ransom but not the kind that has hurt the public at large. Over the past few months that seems to be changing. The Colonial pipeline attack sent gas prices skyrocketing and had people filling plastic bags with gasoline. The hack of JBS Meat caused food prices to increase. It begs the question: are hackers expanding their scope of the attack and will it finally put cybersecurity front and center for the general public?
Guest Expert:Greg Johnson, Webcheck
Ransomware had been a growing issue for businesses for the past several years, growing exponentially in the past two years, particularly as the world made an abrupt shift to remote work during the pandemic.
As attacks become more prolific, more businesses countered by improving mothering security, most notably by having back-ups to allow them to get back online quickly.
But in a game of chess, every move triggers a counterattack and hackers have responded. It’s called a double-extortion scheme that is an elevated version of ransomware designed to ensure the hackers maintain leverage over their victims, whether they have a backup or not.
Panelists
Mike Hussey, Utah Department of Technology Services
A mind-boggling ransom payment paid by one of the largest me producers in the world after getting hacked. Plus we’ll talk about what the FBI’s recommendation is to businesses that have been hacked and why it wants to be involved whether you pay the ransom or not.
Guest Expert:
Anthony Booyse, Sophos
Just weeks after the U.S. faced spikes in gas prices from the cyberattack on a critical energy pipeline, the world's largest meat supplier has also been targeted by Russian hackers. Meanwhile, Chinese hackers breached the New York subway system in April and the U.S. Energy Secretary says foreign adversaries are capable of shutting down the energy grid. In this episode of CYBER24, presented by VLCM, we discuss federal policies, private sector responses and debate when, if ever, a tipping point is coming in our collective response to cyber warfare.
Guest Expert:
Matt Sorensen, Silicon Valley Bank
The Irish Health Department was hit with ransomware by a group known as Conti. Despite an initial demand for payment, the hackers changed tactics and provided the victims with a decryption key, allowing officials to work toward restoring normal service while still threatening to release data in order to collect funds. In this episode of the CYBER24 podcast, presented by VLCM, Marty Carpenter and Mike Hussey look at the hack and the FBI's warning that the same group has already hit more than a dozen US health systems.
Thinking you won't get hit by malware attacks and phishing schemes leaves you at the mercy of hackers who could take businesses for hundreds of millions of dollars every year. We look at the threat and the steps you can take to protect yourself and your business.
Guest
Dan Schuyler, VLCM
A significant piece of U.S. energy infrastructure is hit by hackers and the ripple effect will impact all American's at the gas pump... but is this the wake-up call that will really make a difference?
Until these past few days, you had likely never heard of the Colonial Pipeline. It's a 5,500-mile system that moves 100 million gallons of fuel each day from Texas to New Jersey. (That's roughly 45% of the fuel consumed in that region.) The AP reported that this was a cyber extortion attempt by a group called DarkSide.
We discuss how the attack happened, the ripple effects in the economy and whether or not this will finally make businesses take the threat seriously.
GuestMike Hussey, Utah Dept. of Technology Services
According to one study, data breaches exposed 36 billion records in the first half of 2020. And another study indicates 86% of breaches were financially motivated. Cybersecurity is an issue making its way to the forefront nationally and in the private sector. In this episode of the CYBER24 podcast, presented by VLCM, former head of the Utah Dept. of Technology Services Mike Hussey and Utah Chief Information Security Officer Phil Bates look at what the US is doing, what role states play, and how the private sector is included and, sometimes, left on its own.
Panelists
Hackers threaten all kinds of businesses and the various ways they can cause you problems are growing more numerous and sophisticated. In this episode of the CYBER24 podcast, presented by VLCM, we look at the most common types of cyberattacks and the simple steps you can take to protect yourself.
It is easy to forget just how much technology has changed over the last quarter-century. For much of the workforce, it's impossible to remember life without the internet and those of us who remember life with our "crackberries" are starting to feel ancient.
This evolution has made it easier to do business but it comes with a lot of challenges for your IT department, especially when it comes to security.
A DIY approach may still be possible, but it comes with real risk.
Our expert panel talks about your best approach to cybersecurity and what you need to know before you decide to go it alone.
Panelists
In this episode take a look at how the Chinese hack of Microsoft could be trouble for your business after Microsoft discovered a vulnerability that allowed hackers to access Exchange servers going as far back as ten years.
Even if you don't follow cyber attacks closely, by now you've likely heard about the Solarwinds attack. We take a closer look next. This is the CYBER24 podcast, presented by VLCM.
Panelists
This past week the hosting service we use for this podcast was hit with a Distributed Denial of Service attack and it has us asking questions about what a similar attack would mean for your busines
Panelists
If you are still working at the office you are definitely in the minority. We look at the biggest challenges that come with working at home for businesses and employees
Panelists
North Korean hackers use a sophisticated version of social engineering to dupe cybersecurity researchers and CISA warns against letting your cyber heart get broken this Valentine's Day.
Panelists
When it comes to a company's cybersecurity efforts, a strong partnership between the C-suite and the IT department is a must. But there's also a natural tension. We look at the best ways IT teams and executives can work together for the benefit of the organization.
It probably didn't take until you had finished building your incident response plan to realize you may need some outside help. We look at the benefits of hiring a managed security service, next, on the CYBER24 podcast, presented by VLCM.
Panelists
Dan Schuyler, VLCM
Anthony Booyse, Sophos
Paul Whittier, Adlumin
Hackers know your business is only as secure as your weakest link and they'll try anything to trick your employees into giving away a password. Training your employees to be on the lookout for social engineering efforts and making sure they understand their role in protecting your business is a critical part of your security strategy. In this episode of CYBER24, presented by VLCM, we discuss how you can take simple steps to beat the hackers at their own game.
Panelists
Dan Schuyler, VLCM
Anthony Booyse, Sophos
Paul Whittier, Adlumin
The year 2020 brought a lot of change to the word but it didn't stop ransomware. Now a new Ransomeware as a Service is growing in popularity among hackers. Egregor has publicly claimed over 150 victims since September and the FBI is warning business about this new "Swiss Army Knife" tool that finds your weakest security link and attacks it.
We also discuss the physical security issue at the U.S. Capitol and how it left a big mess to clean up for congressional IT security teams.
Panelists
Dan Schuyler, VLCM
You have worked for years or decades to build your business reputation. Customers have come to trust you for the quality of your service and all that takes a significant hit when a hacker penetrates your defenses and compromises the security of customer data. The good news is, if you handle the situation right and communicate effectively, you can actually emerge with a stronger relationship with your customers and your community. In this episode of the CYBER24 podcast, presented by VLCM, we discuss the keys to crisis communication and the key decisions you can make today to be better prepared should a breach occur.
A hacker gets into your network and your tech team springs into action. What do they need to be trained and equipped to do when every second counts? We discuss response actions you need to have ready with our panel of cybersecurity experts.
Guest Experts
A hacker breaches your system and causes any number of problems. Figuring out how they got in and what you can do to prevent it is a key part of your response.
As Sophos security experts put it: "The more data that is collected – from the endpoints and beyond – the more context is available during investigation. Having broader visibility will allow your team to not only determine what the attackers targeted but how they gained entry into the environment and if they still have the ability to access it again."
Special Guest
Scott Pugmire, FBI Cyber Task Force
Not everyone in your organization should have access to the same parts of your network or to all your data. It only makes sense that the marketing team and the human resources team have distinct roles and each doesn't need access to the same data and systems in order to do what they need to do. Establishing proper access controls is fundamental to your day-to-day operations and to your cybersecurity. Businesses that fail to track, control, and keep access levels up to date run the risk of opening gaping vulnerabilities in their security. In this episode of the CYBER24 podcast, presented by VLCM, we discuss the importance of proper access controls and how it is an essential part of your incident response plan.
Panelists
Businesses that fall victim to cybercrime often use the term, "blindsided." Not seeing an attack coming is one thing and responding to one without maximum visibility compounds your problems. What do you need to make sure you can see what a hacker is doing so you can stop it? We discuss that in this episode of the CYBER24 podcast, presented by VLCM.
Guest Expert
Richard Rieben, Secuvant
Ransomware incidents rose sharply in 2019 and that trend only continued in 2020 as the COVID-19 pandemic had businesses shifting to remote work and cybercriminals found more vulnerabilities they could exploit. The right cyber insurance policy could make all the difference if your business is hit by hackers.
With ransomware attacks on the rise more businesses are protecting themselves with cyber insurance policies. These polices can cover the cost of digital forensics, regulatory compliance and even ransom demanded by hackers. So, does your business need a cyber insurance policy? And what exactly should you know as you make decisions about the kind of coverage you need?
We talk with insurance executive Jonathan Stutz of Moreton and Company to give you everything you need to know about cyber insurance.
Ransomware incidents rose sharply in 2019 and that trend only continued in 2020 as the COVID-19 pandemic had businesses shifting to remote work and cybercriminals found more vulnerabilities they could exploit. The right cyber insurance policy could make all the difference if your business is hit by hackers.
With ransomware attacks on the rise more businesses are protecting themselves with cyber insurance policies. These polices can cover the cost of digital forensics, regulatory compliance and even ransom demanded by hackers. So, does your business need a cyber insurance policy? And what exactly should you know as you make decisions about the kind of coverage you need?
We talk with insurance executive Jonathan Stutz of Moreton and Company to give you everything you need to know about cyber insurance.
Bringing your key stakeholders together for regular tabletop exercises could make a significant difference in your response to a cybersecurity incident. When time is money and the clock is ticking you don't want to review a dusty plan and hope you have the ability to put it into action. Holding regular tabletop exercises will not only help your team prepare for the worst, it will help you identify gaps in your current plan. In this episode of CYBER24, presented by VLCM, we continue our discussion with our panel of experts who share discuss the top four incident response scenarios you use to test your ability to respond.
Panelists
Having an incident response plan is one thing; being able to execute that plan when a crisis hits is a whole different ballgame. Holding regular tabletop exercises will not only help your team prepare for the worst, it will help you identify gaps in your current plan. In this episode of CYBER24, presented by VLCM, we talk with a panel of experts who share their perspective on what makes for an effective tabletop exercise. This is part one of a two-part discussion.
Panelists
The worst time to make decisions is in the heat of the moment. When your business is hit with a cyberattack, you need a strategy in place to respond to the threat while getting your team back up and working as quickly as possible.
In this episode of the CYBER24 podcast, presented by VLCM, we discuss the first two steps many businesses take when creating an incident response plan: determining key stakeholders and identifying critical assets. Time is money and that is especially true when a hacker has knocked your business offline. Over the next few weeks, we'll walk through the main points you should include as you prepare for the worst.
PanelistsMarty Carpenter, 24NINEDan Schuyler, VLCM
Anthony Booyse, Sophos
Paul Whittier, Checkpoint
Cybersecurity can mean different things to different businesses but it should never be ignored. A recent Forbes article makes the case that businesses should focus not only on cybersecurity (keeping hackers from committing a crime at your expense) but also on cyber resilience (keeping your business alive and getting back to full throttle after a cybercrime is committed). When a hacker is successful, your team is suddenly pulled from what they do best to deal with data recovery, regulators and upset customers. So, you should ask yourself what are we doing to prevent a hacker from causing us trouble and what are we going to do if a hacker is successful.
Panelists
Dan Schuyler, VLCM
Anthony Booyse, Sophos
Cybercriminals have ramped up their ransomware attacks and you may be surprised by the four ways they gain access to your system. In this episode of CYBER24, presented by VLCM, we break down how the hackers get past your defenses and look at alarming trends with ransomware attacks
Ransomware has become a serious issue for businesses across the United States with a 147 percent jump in attacks over the last two years. Businesses have adapted by adding cyber insurance policies to cover them - meaning helping them pay a ransom and get back to work. With the problem growing so fast, the Treasury Department is making a significant change, now threatening to fine companies that pay the ransom. It leaves businesses in a no-win situation, either paying a ransom and facing a government sanction or losing their data altogether.
In this episode of CYBER24, presented by VLCM, we talk with our panel of experts about the U.S. government's new approach, how it will impact business and why it makes it more important than ever to avoid falling victim to ransomware.
The fractional information security officer (FISO) - also known in some circles as a virtual or vCISO - has grown in popularity in recent years. In this episode of CYBER24, presented by VLCM, we look at why small and medium-sized businesses should consider this option to boost their security efforts without breaking the bank.
Guest Expert
Greg Johnson, CEO of Webcheck
Whether they will admit it or not, most people have really bad password habits. They use passwords that are too simple, too easy to guess and they use them for too many accounts. A 2019 study showed nearly seven out of ten people share passwords with colleagues and more than half reuse the same passwords for personal and work accounts. The bottom line: your employees don't have a good system or strategy to manage the hundreds of passwords we all need and that is putting your organization at risk. Utilizing a password manager can solve all those issues and greatly enhance your security. In this episode of the CYBER24 podcast, presented by VLCM, we take a look at the benefits of a password manager and how to choose the right one for your situation.
Panelists
In mid-March of this year, with the COVID-19 pandemic taking hold across the state, Utah Governor Gary Herbert closed state buildings and, in the process, moved many of the 24,000 state employees to remote work. Over the following days and weeks, attacks on the state network became more targeted and doubled to three billion per day. In today's episode, we talk with the men in charge of making sure the technology was in place and secure for it to happen and discuss the difference between a temporary transition to remote work and one that is permanent.
Guest
Mike Hussey, Executive Director, Utah Department of Technology Services
Phil Bates, Chief Information Security Officer, Utah Department of Technology Services
In this episode of the CYBER24 podcast, presented by VLCM, we continue our discussion of the importance of offsite storage with the CIO of Perpetual Storage. We discuss the difference between replication and backup, as well as the best way to use cloud and offsite storage to protect your business.
PanelistsJR Maycock, Perpetual Storage
Dan Schuyler, VLCM
By now you know just how important it is to back up your organization's data. Doing so can be the difference between your business surviving a data breach and a hacker closing your doors forever. Where and how you back up that data are also key risk management decisions. In this episode of the CYBER24 podcast, presented by VLCM, we discuss the benefits of offsite storage with the CIO of local business that specializes in protecting your data in a unique manner and location.
PanelistsJR Maycock, Perpetual Storage
Dan Schuyler, VLCM
Web applications occupy a large space within the IT infrastructure of a business. They simply just don’t touch a front end or a back end; today’s web apps impact just about every corner of it. They have also become complex, which has made them a prime target for sophisticated cyberattacks. As a result, web apps must be tested from the inside and out in terms of security before they can be deployed and launched to the public for business transactions to occur. In this episode of the CYBER24 podcast, presented by VLCM, we speak with the author of a new book looking at how your business can keep its app secure.
The more deeply we dive into cybersecurity as an issue for you and your organization, the clearer it becomes that problems stem from a lackluster commitment to the basics. In this episode of the CBYER24 podcast, presented by VLCM, we look at two-factor authentication and how it can frustrate efforts to hack your data.
Panelists
Anthony Booyse, Sophos
The more deeply we dive into cybersecurity as an issue for you and your organization, the clearer it becomes that problems stem from a lackluster commitment to the basics. In this episode of the CBYER24 podcast, presented by VLCM, we look at two-factor authentication and how it can frustrate efforts to hack your data.
PanelistsAnthony Booyse, Sophos
In just the past few weeks, a 17-year vulnerability on Microsoft servers was discovered and it was given the highest security risk rating possible. SIGRed is an attack on DNS and, though Microsoft has distributed a patch, the danger is real for businesses that fail to implement it. So, what danger does SIGRred pose to your business and how is it a potential preview of a global cyber pandemic? We discuss on this edition of the CYBER24 podcast.
PanelistsPaul Whittier, Checkpoint
Don Ainslie, Secuvant
Richard Rieben, Secuvant
Many business leaders would be shocked at how vulnerable their data and network can be when they fail to properly manage access to their wired and WIFI networks. In this episode of the CYBER24 podcast, presented by VLCM, we take a closer look at how Aruba Cleapass allows you to safely connect business and personal devices to your network in compliance with your security policies.
PanelistDan Schuyler, VLCM
The internet has grown remarkably fast over the past decade as technology has reached into every part of our lives and your business. On this episode of the CYBER24 podcast, presented by VLCM, we look at a new project the US government is working on - developing the "national quantum internet." It's mind-blowing stuff and we look at what it could mean for the future of the web. We also discuss Rite Aide allegedly using facial recognition on unsuspecting customers and a ransomware hack at Garmin.
PanelistsDan Schuyler, VLCM
When you think about cybersecurity, you probably picture a hacker in a dark room. But there are physical threats to your cybersecurity that are just as critical to your overall defenses. From physical barriers to video surveillance, we look at what you may be missing when it comes to protecting your business.
PanelistsDan Schuyler, VLCM
Paul James, VLCM
Apple recently held its annual WorldWide Developers Conference - this year with no in-person audience. The WWDC is where Apple rolls out updates to software, saving the new iPhone and other hardware announcements for later in the year. Apple iOS 14 comes with its most notable feature changes in many years and, with the tech giant touting its focus on security, there are some pretty cool features aimed to give you more control over your data and your device. We got some hands-on experience to give you a look at what to expect when the update rolls out to all users later this year. PanelistsDan Schuyler, VLCM
Building a culture of cybersecurity in your business doesn’t just happen. And when it doesn’t happen, trouble is just a few clicks away. So how do you keep your IT team connected to senior leadership and even to your governing board?
Cybersecurity is an effort that requires more than just the talents of a dedicated IT staff. To be effective in protecting your data and your networks - in keeping your business safe from hackers and cybercriminals - you have to develop a culture of cybersecurity. From the most entry-level employee all the way up to the CEO, everyone has to be committed to success when engaged in a battle where the opponent only has to be right (or lucky) once.
More and more, cybersecurity is becoming a priority for board members. Where they used to trust the CEO, who trusted the IT guy… that’s not the case as much anymore.
Panel:
Anthony Booyse, Sophos
One of the world’s largest and most influential social media platforms had a breach of some of its most high-profile users. In this episode of the CYBER24 podcast, presented by VLCM, we look at the hack of verified Twitter accounts and discuss foreign attempts to steal COVID-19 vaccine research from the U.S. and our allies.
Panelists
Dan Schuyler, VLCM
Anthony Booyse, Sophos
Protecting your business from cyber criminals means you have to think like a hacker. In this episode of CYBER24, presented by VLCM, we connect with Webcheck Security CEO Greg Johnson and Webcheck Security VP of Engineering Curt Jeppson, to get some insight on how hackers go about trying to break into your system and steal your data and your money.
PanelistsGreg Johnson, Webcheck Security CEO
Curt Jeppson, Webcheck Security VP of Engineering
For many businesses, their most valuable asset may be their web domain. If customers can’t find you on the web, you may as well not exist. But a new study shows a shocking number of businesses don’t take basic steps to protect their domains. Plus, we look at the new normal of online meetings. Love them or hate them, are they here to stay or will we ever get back to business as usual?
Panelists
Dan Schulyer, VLCM
Anthony Booye, Sophos
In this episode of the CYBER24 podcast, presented by VLCM, we discuss why many businesses are willing to risk a cybersecurity incident rather than invest in security training and technology. We also look into a recent phishing incident at a Utah hospital system.
Panelists:
Dan Schyuler, VLCM
Anthony Booye, Sophos
In this episode of the CYBER24 podcast, presented by VLCM, we continue our look cyber frameworks and certifications. We take a deep dive into the popular SOC 2. We learn more about SOC 2, to whom it applies, why some organizations need it, and how they get it.
In this episode of the CYBER24 podcast, presented by VLCM, we take a closer look nation-state hackers trying to get access to COVID vaccine research in the U.S. Because the work is being done at universities and private companies, the federal government can’t provide the level of security many say we need.
PanelistsAnthony Booyse, SOPHOS
Dan Schuyler, VLCM
In this episode of the CYBER24 podcast, presented by VLCM, we take a closer look at effective cyber frameworks and maturity assessments. Our discussion covers the top reasons frameworks are important and what frameworks apply to which businesses.
Panelists
Greg Johnson, CEO Webcheck
Mike Hussey, Executive Director, Utah Dept. of Technology Services
You likely know that cybercriminals will never waste an opportunity to get access to your personal for company financial data. And disruptions to our everyday routines make it easier to slip one past us. But you might be surprised at just how much of a spike in pandemic-related cybercrime attacks there have been. One report shows an increase of 30,000 percent. In this episode of the CYBER24 podcast, presented by VLCM, we discuss the factors at play to make you and your organization more vulnerable when your routine is interrupted.
Panelists
Matt Sorensen, Formidify
Dan Schuyler, VLCM
Phillip Kemp, VLCM
After a remarkable scramble, generally speaking, by businesses across the country to transition to a remote workforce, smart businesses are looking at what they can accomplish while workers are out of the office. Think of it as a state that takes advantage of fewer cars on the road to get some big road construction projects done. On this episode of the CYBER24 podcast, presented by VLCM, we ask our experts what your business should be up to while the office is empty. To quote Uncle Rico from Napoleon Dynamite, “You might as well do somethin’ while you’re doing nothin’.”
When society’s regular routine is thrown out off-kilter, cybercriminals get right to work. Whether they are stealing your video conferencing credentials to interrupt a meeting, using those credentials to access other accounts or launching websites to phish your employees, you need your defenses up now more than ever. In this episode of CYBER24, presented by VLCM, we discuss the various attack vectors hackers are utilizing to cause you financial pain.
Some of us are old enough to remember the Cola Wars between Coke and Pepsi. The pandemic, work-from-home version of that is a Video Conference War. Zoom has become so widely adopted that it has become a verb but Google has now banned its use on company computers, citing security concerns.
In this episode of the CYBER24 podcast, presented by VLCM, we take a look at the efforts by Zoom competitors to push back against the new big kid on the block. We also discuss warnings from the Department of Justice for those who are trying to hack into video conferencing platforms.
Panelists
Dan Schuyler, VLCM
Anthony Booyse, Sophos
Paul Whittier, Sophos
Links
Google bans its employees from using Zoom over security concerns - The Verge
Federal, state and local law enforcement warn against teleconferencing hacking - DOJ
With remote work, these cyber threats are on the rise - Technical.ly
Over the past few weeks, businesses have had to shift the way they work. As COVID-19 has forced offices to shift to remote work, many companies are just now starting to understand the security risks related to their online meetings. In this week’s episode of CYBER24, presented by VLCM, we take a look at the various platforms available, how Zoom jumped out to a quick leed and what you should be thinking about to keep meetings secure.
Panel:
Dan Schuyler, VLCM
Matt Sorensen, Formidify
Ransomware is a growing problem for American businesses — particularly small and medium-sized businesses. In just the first nine months of 2019, there were nearly 152 million ransomware attacks. They are getting more sophisticated. Most efforts to thwart hackers rely on better training and better identifying malware. But there are larger forces at play that no single business or coalition of businesses can adequately address. In this episode of CYBERR24, presented by VLCM, we are joined by Matt Sorensen of Formidify as we take a look at three elements driving the rapid growth of ransomware.
Element #1: Socio-economic conditions for STEM Educated Citizens of Eastern European Countries
Element #2: Mainstream Development of the Cryptocurrency Ecosystem
Element #3: Mass Availability of cheap Malware and Free Hacking Tools
Over the past couple of weeks, a large portion of the workforce has faced a quick transition from office life to working remotely. Some organizations were well prepared to make that change, many employees had already been working remotely, but some faced significant challenges.
In this episode of CYBER24, presented by VLCM, we connect remotely with Dan Schuyler to get his expert insight on what business leaders should consider to keep their employees productive and their data and systems secure.
Over the past week, national leaders have asked businesses to allow employees to work from home and Utah added a big earthquake to the mix.
For leaders in the Utah Dept. of Technology Services, this meant putting plans into action to allow workers to connect while away from the office. In this episode of CYBER24, presented by VLCM, we sit down (uh, make that, connect remotely) with Mike Hussey, the state’s CIO and Phil Bates, the state’s CISO, to discuss the challenges of transitioning to an online workforce and the security measures that had to be in place.
Plus, we talk about online scams and how quickly hackers swoop in to take advantage of a disruption in our normal routines.
For all the talk about the importance of cybersecurity, despite an increase in the number of businesses and other organizations being targeted by hackers, for all the new regulations aimed at protecting consumers while forcing businesses to take data protection seriously, there are still far too many businesses that hesitate to put proper protections in place. Many fail to properly train their employees on security basics and it is still far too common for the C-suite to make cybersecurity the IT guy’s problem.
In this episode of CYBER24, presented by VLCM, we sit down with Matt Sorensen of Formidify to take a closer look at the common excuses businesses give for not taking the issue seriously and ways the security industry may not be speaking the language of its most important potential customers.
Detecting increasingly sophisticated malware attacks requires complex defenses. Security companies are using more and more advanced types of machine and deep learning to blacklist malware and prevent it from ever getting to your employees or your computer systems. We take a closer look at how they do it and how your business can benefit from smarter defenses on this week’s episode of the CYBER24 podcast, presented by VLCM.
Anthony Booyse
Paul Whittier
In this week’s episode of the CYBER24 podcast, presented by VLCM, we discuss how a leading security company educates your employees to help them keep your data safe online. We also discuss the sophisticated technology they use to keep malicious links from getting to your employees in the first place.
Anthony Booyse, Sophos
Paul Whittier, Sophos
The state of Utah is exploring the possibility of using blockchain technology to make voting more secure and more convenient. In this episode of CYBERR24, presented by VLCM, we sit down with Utah’s top technology official to learn more about the technology that might make voting from your phone a possibility, how they will accommodate non-tech voters and how tests of the tech have gone so far.
Panel
Anthony Booyse, Sophos
Mike Hussey, Utah Dept. of Technology Services
We know internet users love to click on links, often with too little regard for how trustworthy the source may be. And that can have bad results for everyone. Some experts say we need to do more than just try and train users to be smarter about their web security practices. In this episode of CYBER24, presented by VLCM, we sit down with Anthony Booyse of Sophos to learn more about his company’s approach to preventing malicious links from causing you problems.
We also look at Google’s recent announcement that it wants to phase out third-party cookies. What will this mean for how businesses serve ads to potential customers online? We break it down.
The internet of things (IoT) has been steadily creeping into our lives. From smart appliances to smart light bulbs, there are more and more devices that make our lives more convenient. But these devices operate on our personal and business networks. Any vulnerability on any one of those devices is a potential security risk for you, your family or your business.
In this episode of CYBER24 presented by VLCM, our expert panel takes a deep dive into IoT, the security vulnerabilities it presents and what network segregation can do to keep you secure.
Panelists
Anthony Booyse, Sophos
Paul Whittier, Sophos
Dan Schuyler, VLCM
Many considered 2019 to be the year of ransomware as the number of incidents shot up significantly. High profile targets — big cities like Atlanta and Baltimore — were targets. So were softer targets like school districts right before school resumed in the fall. So were small towns and smaller businesses with less sophisticated defenses.
But as businesses get better at having backup, they become less likely to pay. So the bad guys have evolved their attacks.
A new trend shows more hackers not only hitting targets with ransomware, but they have begun to steal the data and release small amounts of it to turn up the heat on victims and make sure they pay.
On this episode of CYBER24, we look at this new trend and discuss whether it will become the new norm.
We also take a look at a cyber attack on the head of Amazon and discuss how CEOs are becoming potential targets for cybercriminals.
If you are in business in the year 2020, you almost certainly collect, stores and use data. At the beginning of 2020, new regulations went into place that likely pertain to your day-to-day operations. In this episode of the CYBER24 podcast, presented by VLCM, we discuss the differences between privacy and security; new regulations like the California Consumer Privacy Act (CCPA) or internationally, the General Data Protection Regulation (GDPR); and a new approach to getting and staying compliant, developed by a company right here in Utah.
On this episode of CYBER24, we sit down with Greg Johnson, CEO of Webcheck, a company that specializes in penetration testing. We discuss the difference between penetration tests and vulnerability scans, what you can learn from each and how to determine the frequency with which you should perform these types of tests.
The U.S. takes military action against Iran and suddenly cybersecurity advocates don’t seem like they’re crying wolf.
Experts and advocates have been saying for years that the time has come for the U.S. in both the private and public sectors to take their cybersecurity measures seriously and, suddenly, at the beginning of 2020, everyone seemed to begin to understand why.
So, what does the potential of a cyberattack from Iran mean to your business? What about your state or local government? We dig in on that question on this episode of CYBER24, presented by VLCM.
We also look back at 2019, which is now being called “the year of ransomware.” A new report puts a hefty price tag on U.S. businesses that found themselves locked out of critical systems last year. We discuss why it’s a trend that will only accelerate this year.
Utah is home to a tech boom of its own with top-names tech companies finding the Silicon Slopes a great place to do business and military and defense companies growing around Hill Air Force Base in Davis County. For policymakers, finding ways to encourage more Utah students to explore careers in those fields has been an ongoing challenge. This month, the Beehive State made two big announcements to show it is ready to do everything it can to ensure a steady pipeline of talent for decades to come.
First, Gov. Gary Herbert announced he was including $10.2 million in his budget proposal to ensure every Utah student from K-12 has access to computer science education. That money is in addition to the private sector money pledged by the heads of some of Utah’s top tech companies - a total of $4 million to this point.
That announcement came just a few days after the state had announced it would actively participate in the Girls Go CyberStart initiative, a program to encourage high school girls to explore their interest in and aptitude for careers in cybersecurity.
Registration for Girls Go CyberStart opened this week, with online gaming commencing on January 13, 2020. Additional details and pre-registration can be found at www.girlsgocyberstart.org.
Teacher information and student practice programs are available by clicking here. To see the types of challenges the students will face in the games, click here.
On this week’s episode of CYBER24 presented by VLCM, we talk with the head of the Utah Dept. of Technology Services and the state’s chief information security officer about why these efforts are so important to the state and why finding talent to fill these jobs can be difficult.
It’s a safe bet that over the past few weeks you have made an online purchase or two. You add your items to the cart and then check out. But just how secure is that shopping cart? Thousands of online vendors use a similar type of base-code for that shopping cart and hackers were recently able to access the systems at Macy’s, add a few small lines of code to the shopping cart and for a week they had access to data from every customer.
On this week’s episode of CYBER24, presented by VLCM, we dive into what happened with Macy’s,learn more about the Megacart attack and how it is a concern for every website with a shopping cart.
Also, hundreds of millions of people may have had their text messages exposed online. If that’s not a headline that will catch your attention, I’m not sure what will. You may have become accustomed to data breaches or email compromise but text messages have become a primary source for information. We send a lot. We read a lot. And we generally trust that those texts are private.
Cybercrime isn’t a uniquely American phenomenon. Recent high-profile attacks on Pemex, Mexico’s state-owned oil monopoly was hit with ransomware demanding $5 million comes just months after a similar attack on Norwegian aluminum producer Norsk Hydro. The former was offered a discount by hackers if they paid right away (which they did not) while the later refused to pay at all and has spent a reported $71 million to clean up the mess.
On this week’s episode of CYBER24, we discuss these high-profile foreign attacks and outline some of the steps you can take to protect your business.
Black Friday, Small Business Saturday and Cyber Monday are all coming up this week. Besides needing to carefully develop a strategy to handle all the cardboard boxes about to hit your doorstep, it is also the right time to take some important steps to protect yourself from cybercriminals looking to make their holiday season brighter at your expense.
With the biggest online shopping days of the year starting this week, today’s CYBER24 podcast topic is online shopping and the steps you can take to protect yourself.
Our expert panel includes:
A recent study shows that businesses that have a cybersecurity policy in place - and are willing to talk about it - are more valuable to investors.
Having policies in place for protecting your business against cybercriminals and to protect the data you collect is critical, but so is having an incident response plan including a communication plan. That much has become a more commonly accepted position. But calibrating just how much you should say publicly can be tricky. Businesses have to balance their interests between sharing with customers and potential investors that they value a culture of cybersecurity without drawing unwanted attention from hackers looking for a challenge.
In this week’s episode of CYBER24, we discuss the pros and cons of talking about your commitment to cybersecurity with our expert panel (Mike Hussey, executive director of the Utah Dept. of Technology Services; Phil Bates, Utah Chief Information Security Officer; and Dan Schuyler, VLCM Cybersecurity Solutions Architect). Plus, we look at the recent adventures of the President’s top cybersecurity advisor and what you should know before you take your devices in for repair.
Over the past 10 or 15 years, something really remarkable has happened: the face of business has transformed.
I’m not talking about the way business is done, though technology has had an impact there. I’m talking about the way most people interact with companies everyday. Two decades ago, some businesses had some kind of a website but today, many if not all customers interact with a business primarily through its website.
We buy clothes, household supplies and even groceries online. Just recently, Amazon began to offer grocery delivery within two hours, as a matter of fact. The idea (dream?) of never having to leave the house is becoming very real.
With so much of a business’ success depending on its website, you can bet the good guys aren't the only ones who have noticed.
Website security is the topic for today’s episode of CYBER24.
Poor cybersecurity leads to breaches and breaches cost your business time and money. But buying the right technology to keep the hackers at bay can only be so helpful if you don’t take the time to craft the right cybersecurity strategy.
On this week’s pod, we look at a study showing two out of every five businesses have lost money thanks to lackluster cybersecurity practices and we talk you through the questions you should ask to ensure you have the right plan in place.
We also look at one of the easiest and least expensive things you can do to improve your cybersecurity without breaking the bank.
PanelistDan Schuyler, VLCM
As data breaches and other cybersecurity incidents continue to grab headlines, it’s worth wondering whether or not the American public is growing numb to the news.
Marriott says up to 500 million people may have been affected by a security vulnerability that may have been exploited for four years. Facebook fell victim to a sophisticated hack that exposed 50 million people. The numbers are staggering – and those are just the ones that rise to the attention of the mainstream media.
But those flashy headlines rarely come with advice for those impacted. Other than the Equifax breach, can you recall the last time the news included steps potential victims should take to find out if they had been one of the millions of people who were impacted? Have you taken any steps to look into any of the recently reported breaches yourself?
Maybe it’s just because the impact is so often delayed. Your personal data is breached somewhere; bad guys may or may not have it; if they have it they may or may not use it; if they use it you may or may not find out about it.
There’s a general feeling of helplessness and hopelessness.
In this week’s episode of CYBER24, we take a look at why that may be. We also conclude our discussion with our panel of experts as we ask them what advice they would have for anyone considering a career in cybersecurity.
The post Episode 39 – Hacks at Facebook, Marriott raise eyebrows appeared first on Cyber24.
The world of cybersecurity faces some significant challenges over the next several years. In this week’s episode of CYBER24, we bring you the second part of a two-part series from the panel discussion we led at a recent cybersecurity summit hosted by VLCM.
Our panel of experts includes:
Matt Sorensen, Secuvant CISO
Kevin Howard, Secuvant Chief Security Architect
Trent Bond, Pluralsight CISO
Dan Schuyler, VLCM Cybersecurity Systems Architect
In this episode, we discuss the impact Artificial Intelligence (AI) could have on the cybersecurity world and if it will help the good guys or the bad guys be more effective. We also discuss the challenges associated with the Internet of Things (Iot)
If you missed part one of our discussion, you can find it in Episode 37, wherein we focus on whether businesses are getting better at cybersecurity or if, despite their efforts, the cybercriminals are evolving so fast that businesses are falling behind. We also ask the panel what they think the impact of cybersecurity regulation at the state and federal level would have on businesses and consumers.
The post Episode 38: Cybersecurity Expert Panel – Part II appeared first on Cyber24.
One of those unwritten rules of cybersecurity is that you don’t brag about how good your security is. It’s more than just bad karma, it’s the type of chest thumping that can awaken the sleeping hacker giants looking for a challenge. But last week, Jack Ma, the founder and former executive chairman of Alibaba (if […]
The post Episode 58: Never lost one cent appeared first on Cyber24.
When the legendary Green Bay Packers football coach, Vince Lombardi, opened training camp each season, he started with the basics. “Gentlemen, this is a football.” Even with a squad full of professional football players, Lombardi knew the importance of focusing on the fundamentals. As October is National Cybersecurity Awareness month, there’s no better time than […]
The post Episode 57: Focus on the fundamentals of cybersecurity appeared first on Cyber24.
Another week, another big hack. It may come as no surprise that millions of people play video games on their phones. Whether they are attacking pigs with chickens, rolling some old school Nintendo games or playing electronic versions of classic board games, video games are big business. And now more than 200 million people who […]
The post Episode 56: If you played Words with Friends, you’ve been hacked appeared first on Cyber24.
Cyber warfare is at the heart of a potential U.S. response to incidents in the Middle East, according to published reports. While attacks and responses to attacks have traditionally been held on the battlefield, that battlefield is increasingly moving to the cyber world. In this week’s podcast we discuss how the U.S. uses cyber attacks, […]
The post Episode 55: Cyber attacks as part of military responses appeared first on Cyber24.
One thing you should never underestimate? The astounding creativity of cybercriminals. As security services and our overall cybersecurity posture continue to improve, the bad guys need to come up with more and more innovative ways to get access to the data they want. In this week’s episode of CYBER24, we take a look at a […]
The post Episode 54: Shocking hacker creativity and how your mood impacts your security appeared first on Cyber24.
Sometimes you read something and just can’t believe it. Sometimes the numbers involved in cyber breaches are just overwhelming. And then there’s this one. The entire country of Ecuador got hacked. Not it’s biggest bank. Not its largest company. Nope. A database that had staggering amounts of data on, essentially, everyone in the entire country. […]
The post Episode 53: An entire country gets hacked appeared first on Cyber24.
Cybercriminals have found small cities and towns to be easy targets for ransomware. In fact, 45 percent of attacks on municipalities have been aimed at cities with populations under 50,000 and a quarter of all attacks on those smaller than 10,000 residents. One reason these smaller towns make great targets is that they hold important […]
The post Episode 52: How state government is helping Utah cities protect themselves from hackers appeared first on Cyber24.
One topic has dominated our podcast the past few weeks, and for good reason. Ransomware attacks have more than doubled this year and the majority of them have been targeted at state and local government. According to a study by Barracuda Networks, 55 ransomware attacks targeted state and local governments from January to July of […]
The post Episode 51: Ransomware attacks double, cities frequent, soft targets appeared first on Cyber24.
As the federal and state governments have worked to enhance their cybersecurity infrastructure, cyber criminals have now seemingly set their sights on a new and, evidently, far more vulnerable target: cities and towns. Texas learned this the hard way earlier this month when more than 20 smaller local government entities were targeted in what authorities […]
The post Episode 49: Ransomware breakout in Texas appeared first on Cyber24.
Last month, Utah Lt. Gov. Spencer Cox announced a pilot program testing the benefits of state employees teleworking showed increased productivity, reduced carbon output by eliminating the commute to an office and allows for more efficient use of state office space. But with more employees working from home – many handling sensitive data – the […]
The post Episode 48: Protecting data when employees work remotely appeared first on Cyber24.
Across the country, parents are busy with back-to-school shopping while kids are squeezing every minute of rest and relaxation they can out of the final weeks of summer vacation. As schools prepare to welcome students back, many are becoming targets of hackers. In this week’s episode of CYBER24, our panel of cybersecurity experts discusses the […]
The post Episode 47: Cyber hacks on schools lead to a state of emergency appeared first on Cyber24.
Sometimes the numbers are so big you can’t ignore them. And when two business giants are involved it gets even harder to miss. The latest headline-grabbing cyber breach involves Capitol One, a former employee of Amazon Web Services (AWS) and a breach impacting 106 million people. On this week’s episode of CYBER24, our panel of […]
The post Episode 46: What (or who)’s in your wallet? appeared first on Cyber24.
If there’s one thing we’ve learned through two seasons of the CYBER24 podcast (besides you need to do better managing your passwords) it’s that the bad guys are always going to be a step ahead of the good guys. It’s the nature of playing defense. Just when you stop the current attack, they are already […]
The post Episode 45: Trends to watch in cybersecurity this year appeared first on Cyber24.
In late January, the director of the Cybersecurity and Infrastructure Security Agency (CISA) issued agency’s first Emergency Directive, outlining current and potential risks posed to Federal agencies. The attack was a combination of simplicity over sophistication and outside-the-box thinking and it is the kind of attack that could put businesses and local governments at risk. […]
The post Episode 44: CISA’s first emergency directive appeared first on Cyber24.
As we sat down to record this week’s pod, the federal government had been shut down for 26 days with no end in sight. While the battle over a board wall continues in the nation’s capital, we at CYBER24 wanted to take a look at how a shutdown impacts our nation’s cybersecurity. We welcome back […]
The post Episode 43: How is the Federal Government Shutdown Impacting Cybersecurity? appeared first on Cyber24.
In this week’s episode of CYBER24, we head back to campus to discuss the cybersecurity challenges faced by universities. We sit down with Bret Ellis, vice president of information technology at Weber State University. From protecting student data, to ensuring professors can teach and grade their students, to the stuff you might not consider – […]
The post Episode 42: Protecting Data on Campus appeared first on Cyber24.
In this week’s episode, we look into the game causing relationship stress and carpal tunnel syndrome across the globe. Fortnite is the biggest thing in video games right now and, despite the fact that it is free to play, hackers have been breaking into accounts, taking control and selling them to other players. We’ll take […]
The post Episode 41: Fortnite hackers – Battle Royale appeared first on Cyber24.
The world of cybersecurity faces some significant challenges over the next several years. In this week’s episode of CYBER24, we bring you a panel discussion we led at a recent cybersecurity summit hosted by VLCM. Our panel of experts includes: Matt Sorensen, Secuvant CISO Kevin Howard, Secuvant Chief Security Architect Trent Bond, Pluralsight CISO Dan […]
The post Episode 37: Cybersecurity Expert Panel – Part I appeared first on Cyber24.
It can be amazing to think back to a quaint time when the internet didn’t touch every part of your life. Just ten years ago, for example, I recall setting up the very first Facebook, Twitter, Linkedin and YouTube accounts where I worked. It has been a decade of rapid innovation and changes to our […]
The post Episode 36: Federal Regulation of Consumer Data appeared first on Cyber24.
In our last episode, I talked about some new tech at our house and the chain reaction of resetting computers, reinstalling operating systems, updating passwords and other security measures. We outlined the top ten things you need to do before connecting a new computer to the internet. One thing we did not discuss is that […]
The post Episode 35: Keys to safely dispose of old technology appeared first on Cyber24.
Sometimes it comes in waves. This has been a season of new tech at my house including a new laptop for me. My old one passed down to my daughter. I found out my son’s PC was somehow mining bitcoin. Good heavens. As I’ve been setting up and resetting computers over the past several days, […]
The post Episode 34: Ten steps you should take before connecting a new computer to the internet appeared first on Cyber24.
When a top-ranked U.S. security official says our digital lives are in danger like never before, you should probably believe her. That’s a direct quote from the Secretary of Homeland Security Kirstjen Nielsen. In this week’s episode of CYBER24, we take a look at some of the top cybersecurity stories you likely missed, unless you […]
The post Episode 33: Cybersecurity top concern for US appeared first on Cyber24.
Some of you may remember the short-lived NBC game show in which a British woman berated contestants who underperformed (or who did just fine) by staring them down and declaring in a stern voice, “you are the weakest link. Goodbye.” No doubt cybersecurity experts, IT professionals and many supervisors have wanted to express the same […]
The post Episode 32: The importance of Security Awareness Training appeared first on Cyber24.
By the time you are listening to this podcast the 2018 Election will be just a few weeks away and voters in Utah will have ballots in-hand ready to be filled out and mailed back. Casting a ballot for the candidate of your choice is among the most American things we do… and increasingly it […]
The post Episode 31: Protecting Utah elections from hackers appeared first on Cyber24.
As much as business leaders and elected officials may wish it were so, the unfortunate truth is there is no such thing as a silver bullet when it comes to cybersecurity. Instead, protecting the data and systems that make running your company possible takes an expertly crafted plan and constant vigilance. On this week’s episode […]
The post Episode 30: There is no cybersecurity silver bullet appeared first on Cyber24.
For most students in Utah, the excitement (or dread) of going back to school has come and gone and they have settled into the routine of classes, homework and tests. But today’s students face an additional challenge… one that their Oregon Trail playing parents didn’t have to consider at all – and that’s cybersecurity. Our […]
The post Episode 29: What Teenagers Need to Know about Cybersecurity appeared first on Cyber24.
In this week’s episode of CYBER24, we take a look at how business is working with government – be it law enforcement or even the military – to play an important role in cybersecurity. In our first segment, we break down a report from earlier this month, written by Evan Carson at CNET, looking in […]
The post Episode 28: Biz and Gov’t a cybersecurity dynamic duo? appeared first on Cyber24.
Every time you hear about another data breach with exposing personal information on thousands of people you may wonder if your name is on that list now floating around the dark web. Heck, you may even assume you were part of the breach. But how do you find out just how often you may have […]
The post Episode 27: Have you been victimized by a breach? appeared first on Cyber24.
As cyber crime continues to become a bigger concern for businesses and policymakers, some are now suggesting the best defense may actually be a good offense – or at the very least slightly more aggressive one. In this week’s episode of the award-winning CYBER24 podcast, we kick off our second season breaking down a recent […]
The post Episode 26: Is it time to hack back? appeared first on Cyber24.
Cybercrime is ever-evolving and the effort to keep up with hackers presents multiple challenges. Do policymakers fully appreciate what’s at stake? Can they implement the right policies, procedures and technologies before the threat switches tactics? And will the public support spending sufficient resources on cybersecurity before something catastrophic forces it to the forefront of their […]
The post Episode 25: Inside look at the Internet Security Threat Report appeared first on Cyber24.
If it seems like cybersecurity stories have started to pop up in the news more frequently, you’re not crazy. Although, headlines about cyber breaches, hacks and ransomware are still pushed off the front page by political gossip and other scandals, there is no doubt cybercrime is a topic of growing importance to business, elected officials […]
The post Episode 24: Ransomware Cripples Atlanta appeared first on Cyber24.
When you are starting a small business, there is plenty to worry about. How do you make your product amazing? How are you going to make sure your potential customers know about what you have to offer? How do you hire the right people? With so much going on, it is easy to see why […]
The post Episode 23: Critical Security Controls: First steps for business cybersecurity appeared first on Cyber24.
Utah government agencies have to fend off hundreds of millions of attacks every single day – and the Dept. of Technology Services (DTS) does a great job protecting the massive amounts of public data. Having blazed a trail for the rest of the nation in the way it investigates and prosecutes cyber crime by establishing […]
The post Episode 22: Utah planning Cybercenter to help state, private sector combat cybercrime appeared first on Cyber24.
Through the first 20 episodes of the CYBER24 podcast, we have examined the issues surrounding cybersecurity and how to protect your business or your family. While the issues we have discussed have all been important and have, hopefully, provided some helpful and actionable advice, it can be a little impersonal. It can make it easy […]
The post Episode 21: Tragic impacts of cybercrime appeared first on Cyber24.
When you go to the doctor and fill out those forms on the clipboard, well all of that data eventually ends up in digital form. You may not really appreciate just how much health-related data you have in various doctors’ offices, pharmacies, with your insurance company, but hackers find it very valuable. In fact, health-related […]
The post Episode 20: Price tag to protect your health data growing as hackers target your medical records appeared first on Cyber24.
The internet is widely considered to be a place where you can find, well, access to all human knowledge – good and bad. In reality, what most of us think of as the World Wide Web, accounts for only about four percent of what the internet really is. You have probably heard of the other […]
The post Episode 19: Dangers of the Dark Web appeared first on Cyber24.
Once upon a time, detectives in long trench coats would step inside the police tape, look at the scene of a crime and find just the clue they were looking for… at least that’s how it worked on television crime shows. Today, turn on any one of the CSI programs (or any other show of […]
The post Episode 18: Digital Forensics appeared first on Cyber24.
All across the country, millions of American workers are starting to do their taxes. With so many people receiving various tax forms in the mail from their employer and using other sensitive information, this is a time of high opportunity for cybercriminals. In this week’s episode of the CYBER24 podcast, we sit down with Vince […]
The post Episode 17: Tips to thwart tax fraud and looking out for skimmers appeared first on Cyber24.
When you have a business trip that takes you out of the country, there are a lot of things you don’t want to forget. You need your passport, you need your toiletries, you need the right clothes… and you really need to think about protecting your sensitive data. Like it or not, once you leave […]
The post Protecting your data during international travel appeared first on Cyber24.
When news of a cyber breach breaks, consumers across the country start worrying about whether or not their personal data was exposed and how that could negatively impact their credit. Protecting against damage to your finances is a serious concern and not an altogether uncomplicated process. This week on CYBER24, we sit down with Utah […]
The post Episode 15 – Protecting your credit after a cyber breach appeared first on Cyber24.
In this episode: Issues facing businesses – Ransomware, employee negligence, malicious employee revenge, business email compromise. What constitutes a “breach,” as well as Utah’s Protection of Personal Information Act. Creating an Information Security Plan – Being proactive about assessing your company’s assets, risks and management. Creating policies to address them. Breach response – What does […]
The post Episode 14: Cyber attacks may have big legal ramifications for unprepared businesses appeared first on Cyber24.
Cybersecurity issues receive more and more attention as states come to a better understanding of just how much a target they are for hackers. The more data you have, the bigger of a target you are. But many states were slow to adopt robust security measures and many are still behind the curve. During his […]
The post Episode 13: Virginia Gov. McAuliffe leads states efforts to meet the threat of cyber attacks appeared first on Cyber24.
In part 2 of our panel discussion with four leading cybersecurity experts, we discuss how someone can hire someone to launch a cyber attack on your business that could shut you down. We also discuss where a business should executive should start to address cyber security when there is so many options. Our thanks to […]
The post Episode 12: VLCM Panel Discussion Part 2 appeared first on Cyber24.
It may seem odd to talk about some of the hottest trends in cybercrime and cybersecurity. After all these aren’t fashion trends shown off on the catwalks displayed by supermodels. But new types of attacks keep coming as cyber criminals and hackers work to stay a step ahead of investigators and security providers work to […]
The post Episode 11: VLCM panel discussion Part 1 appeared first on Cyber24.
By now you likely understand a data breach is a matter of “when” not “if” for your organization. Hopefully you are working to build a culture of cybersecurity within your business and tightening up your security measures themselves. But when something does eventually happen, how do you avoid complicating the situation, legally speaking? This week […]
The post Episode 10: Victim of a data breach? Don’t become an accomplice to the crime appeared first on Cyber24.
There was a time when you only had a password for a handful of accounts like you email and your computer login. Those days are long gone. Today, you likely have a password for everything from your Netflix account to your online shopping account to the app you use to order pizza. When you consider […]
The post Episode 9: Creating unbreakable passwords appeared first on Cyber24.
In this week’s episode of CYBER24, we take a look at some interesting polling information that shows exactly who Americans trust and distrust with their data. But does it make a difference in how we actually behave? We also take a deep dive into the world of cyber insurance with a local expert. Trust no […]
The post Episode 8: Cyber insurance gaining popularity as hacks increase appeared first on Cyber24.
In this week's episode of CYBER24, the man in charge of protecting state data and devices talks about the security measures in place that helped the Dept. of Technology Services move quickly to close a vulnerability discovered by a Utah man. We also talk about the value of having cybersecurity expertise with your legal counsel when responding to a cyber incident.
The post Episode 7: State cyber team closes vulnerability found by Utah man appeared first on Cyber24.
Do you remember back when you had your first email account and you received an unsolicited email from someone claiming to be a Nigerian prince? It seems like most of America had a similar offer and, sadly, more than a few fell for it. It was one of the earliest phishing schemes.
Well, #spoileralert, the person who sent those email wasn’t royalty and his fortune was based solely on the money his victims sent him. But, did you know the Nigerian prince - at least one of them - was brought to justice by Utah law enforcement?
The post Episode 6: Investigating cybercrime and nabbing the Nigerian prince scammer appeared first on Cyber24.
“I used to think that elections just happen but I can assure you they do not,” says Lt. Gov. Spencer Cox, who is designated by the Utah Constitution as the chief elections officer. “It’s a one-time-a-year thing for everyone else, but for my office it is twenty-four-seven, 365 days a year.”
The post Episode 5: Keeping Utah elections secure appeared first on Cyber24.
How many emails do you get a day? Studies show the average American received nearly 100 emails each day and many would say that’s a slow morning at the office. Add to that number each ding for texts, tweets and direct messages, and it’s easy to see why not every message gets your full attention.
The post Episode 4: Business Email Compromise – Wolf in sheep’s clothing appeared first on Cyber24.
North Korea tests US cyber vulnerabilities Authentication, encryption and the padlock on your browser (9:40) Implementation of guidelines to protect US critical infrastructure (22:40) Hackers attacking hospitals, cars and pacemakers – sometimes for profit (30:48) In the third episode of CYBER24, we sit down get a look at the security risks of IoT – or […]
The post Episode 3 – Internet of Things appeared first on Cyber24.
First, a note of thanks. The premiere episode of CYBER24 debuted to rave reviews and proved there is a desire among business leaders and policy makers to better understand cybersecurity issues. Admittedly, we gave you your money’s worth in episode one. So this week we keep it nice and tight: 35 minutes with a breakdown […]
The post Episode 2-Cybersecurity in the Workplace is Everyone’s Business appeared first on Cyber24.
In the premiere episode of CYBER24, we discussed some of the top cybersecurity threats of 2017 with Matt Sorensen, chief information security officer (CISO) with Secuvant, and Sgt. Jeff Plank, a member of the state Cyber Task Force. First, it’s important to know who the bad guys are and what they are after. “With the […]
The post Episode 1-Simple Steps to Online Safety appeared first on Cyber24.