Sophos Lounge: Recent Episodes

Sophos APJ

Computer and Network Security.

View Details

Increasing collaboration between red and blue teams is a vital step in improving cybersecurity. Join this session to hear from a member of the team responsible for keeping Sophos safe from cyberthreats. Michelle will share how the red team vs. blue team mindset has evolved, how to get ‘purple’ teaming conversations started, and why, her team find thinking like an attacker makes them better defenders.

View Details

No one suggests that compulsory motor insurance is a bad idea because it encourages people to drive with less care. But when it comes to cyber insurance, sceptics aren't so sure: some people insist that cyber insurance is a major driver behind ransomware attacks, by encouraging lax habits in companies that assume "the insurance will cover it" and emboldening the crooks to demand ever-higher payments. Paul Ducklin talks to Dr Jason Nurse to find out how you can turn cyber insurance to everyone's advantage by using it as a driver to improve your cybersecurity posture.

View Details

The well-documented cyberattacks on Kaseya and SolarWinds continue to highlight just how unprepared many organizations are when it comes to defending against supply chain attacks. In this session, Paul and Chet discuss the critical steps organizations need to take to minimize the risk to their supply chain.

View Details

Malware isn’t going anywhere. Get under the enemy’s skin with fascinating insights from SophosLabs’ director of threat research. Fraser deep dives into how threats work, shares fresh discoveries from the Sophos Labs team and explores the latest malware trends. Watch this session to get the latest threat updates and to know what you’re up against.

View Details

This week, our hosts Wana Tun and Aaron Bugal are discussing the importance of using network data for understanding an attack and how to utilize this data to look for indicators of compromise. They discuss how by combining network operations teams and security operations teams, we can have a better protection and detection capability within an organization.

View Details

Our hosts Hywel Morgan chats with Andrew Brandt discuss the impacts of Covid-19 on the cybersecurity industry one year on. As the workforce shifted the techniques and targets of attackers also shifted. In recognition of this changing threat landscape and increase in criminals leveraging on Covid-19 to insight attacks - IT professionals around the world banded to together to share live threat intelligence.

View Details

Our hosts Ben Verschaeren and Aaron Bugal discuss some recent data attacks against multinational companies, in one attack 10 Terabytes of data was exfiltrated out from the cloud undetected. They discuss how understanding your baseline is key this will help you detect anomalies and therefore help to prevent nefarious attacks.

View Details

Our hosts Aaron Bugal and Hywel Morgan discuss the State of Ransomware 2020 report. They discuss, the ransomware problem touching on how; there are fewer headlines than in 2017 but the problem is still very much real, most attacks result in data being encrypted, and how paying ransom doubles the total incident remediation costs. They conclude with some possible solutions to the ransomware problem.

View Details

Our hosts Aaron Bugal and Wana Tun discuss the vulnerabilities within IOT devices in the healthcare industry. Often with these devices cybersecurity is an afterthought and they can therefore be vulnerable to attacks. We have seen examples of this depicted in TV shows and movies, but now we are starting to see real life incidents, is life imitating art?

View Details

The recent ACSC report released on Friday 19th June highlighted that there has been a wave of sophisticated cyber attacks against the NSW government. Our hosts Ben and Aaron discuss whether it's something to be alarmed about or is it just bringing to the public eye an average day in cyber-security. Also discussed, are the learning's from these attacks and what are the simple and safe things to thwart against such attacks.

View Details

There has been a lot of Supply Chain companies being attacked of late. For example Toll Group has been attacked by ransomware twice - what is the motivation? Are supply chains deliberately being attacked or is it opportunistic? As consumers what should we do?

View Details

Ever wondered how cybersecurity companies manage their own defenses? Join this podcast to hear from the people responsible for keeping Sophos safe from cyberthreats. Craig and Luke will share their team’s approach, the main challenges they face, and how they deal with common issues. You’ll get a host of best practices and insider info you can apply to your own organization.

Speakers: Paul Ducklin, Craig Jones, Director of Information Security and Luke Groves, Senior Penetration Tester, Sophos Cybersecurity Team

View Details

Get under the enemy’s skin with fascinating insights from SophosLabs’ director of threat research. Fraser will deep dive into how threats work, sharing fresh discoveries from the Sophos Labs team and exploring the latest malware trends. Join this session to get the latest threat updates and to know what you’re up against.

Speakers: Paul Ducklin and Fraser Howard, Director of Threat Research, SophosLabs

View Details

Privacy is a top concern for many people, fueled by revelations of covert smartphone surveillance and – yet more – data breaches. Join James as he explores how to balance keeping data secure while stopping criminals from hiding in the shadows. Plus, with home/remote working soaring due to the coronavirus, we’ll explore how the network perimeter is expanding and what this means for security.

Speakers: Paul Ducklin, James Burchell, Senior Security Advisor, Sophos

View Details

Hackers often spend weeks exploring your network before deploying their payload. Spot them before they strike and you’ll save your organization huge amounts of pain and cost. Join this session to get top tips on how to spot an intruder on your network from a threat hunting expert. Chet will explain how sophisticated, multi-stage attacks work, the tell-tale signs you’ve got an intruder on your network, and what to do if you spot something suspicious.

Speakers: Paul Ducklin and Chet Wisniewski, Principal Research Scientist, Sophos