Cyber in Business: Recent Episodes

CTRL Group

Welcome to Cyber in Business, a platform where the best minds in cybersecurity share their insights with businesses. We operate on the belief that only a cyber secure business can outlast. This platform is all about information sharing and helping business leaders make more effective decisions.

Cyber in Business is proudly powered by CTRL Group (ctrlgroup.io)

View Details

Data is without a doubt the most valuable asset that we have, but it's also foundational to cybersecurity. What puts us at risk is the fact that it really likes to hide!

Stephen Cavey is the Co-Founder of Ground Labs, and the perfect person to help us figure out just where some of our unknown data likes to hide. Ground Labs specialise in helping your business uncover the location and content of all that data in your business. Listen to learn more about this essential topic.

Cyber in Business is powered by CTRL Group:
https://ctrlgroup.io/

Learn more about Ground Labs (and definitely check out their Enterprise Recon!):
https://www.groundlabs.com/
https://go.groundlabs.com/enterprise-...

Follow Ground Labs on Twitter:
https://twitter.com/groundlabs

Listen to Cyber in Business on the go!
https://open.spotify.com/show/0U9iyMK...
https://podcasts.apple.com/au/podcast...

Learn more about Cyber in Business:
https://www.cyberinbusiness.com/
https://twitter.com/cyberinbusiness
https://www.linkedin.com/company/cybe...

cyberinbusiness #cybersecurity #cyberinsurance

0:58 What role does data play in the security of a business?
4:15 Can you tell us what Ground Labs do and what value they provide to businesses?
7:45 Where does data hide?
15:08 What do you think is the most common oversight that businesses have that jeopardises their security?
23:52 What kinds of strategies could businesses adopt to better manage their data?
29:25 What are the key points that regulation is targeting with regards to how businesses handle their data?
36:14 What is the best standard for businesses to adhere to?
40:25 What do you foresee in the industry that you are working in?

View Details

Cyber insurance can be a major factor in how your business survives after dealing with a cyber incident. However due to common misunderstandings, cyber insurance is still an area that businesses have yet to take full advantage of.

Chris McLaughlin leads the AON Cyber Solutions Group, working with Michael Parrant who is the Cyber Insurance Practice Leader at AON. Listen to learn more about what cyber insurance actually covers, what the consequences are and how to make it work for you.

Cyber in Business is powered by CTRL Group:

https://ctrlgroup.io/

Learn more about AON’s Cyber Solutions:

https://www.aon.com/cyber-solutions/solutions/cyber-insurance/

Follow AON on Twitter:

https://twitter.com/Aon_plc

Listen to Cyber in Business on the go!

https://open.spotify.com/show/0U9iyMK9s6O2tcxw7Xzqyt

https://podcasts.apple.com/au/podcast/cyber-in-business/id1521208739

Learn more about Cyber in Business:

https://www.cyberinbusiness.com/

https://twitter.com/cyberinbusiness

https://www.linkedin.com/company/cyber-in-business

cyberinbusiness #cybersecurity #cyberinsurance

0:52 What made you move from cybersecurity into cyber insurance? 2:47 What is an example of a hack where the business didn’t have cyber insurance? How did it impact the business?
4:18 Why do you think businesses are choosing not to get cyber insurance?
8:37 What support do businesses get when they purchase cyber insurance from AON? 11:58 What are the mechanics of measuring the amount that you have to pay for cyber insurance?

13:13 How do you really know the risk profile of a business?

17:33 What is the most common oversight businesses make to jeopardise their security?

19:05 Do you have a metaphor you use for your clients to help them understand the importance of cyber insurance?

20:22 How do you encourage small businesses to get cyber insurance?

23:03 What do you foresee for the future of cyber insurance?

View Details

We really underestimate how risk assessments contribute to a mature security posture and its impact on parts of the business such as insurance.

Anthony Stevens,CEO and Co-Founder of 6clicks helps us understand how a SaaS risk and compliance system can help us run our businesses more effectively. Listen to learn more about how you can take advantage of managing your risk and unpack trends around business compliance practices.

Cyber in Business is powered by CTRL Group:

https://ctrlgroup.io/

Learn more about 6clicks:

https://6clicks.io/

Follow 6clicks on Twitter and LinkedIn:

https://twitter.com/6clicksOfficial

https://au.linkedin.com/organization-guest/company/6clicks

Listen to Cyber in Business on the go!

https://open.spotify.com/show/0U9iyMK9s6O2tcxw7Xzqyt

https://podcasts.apple.com/au/podcast/cyber-in-business/id1521208739

Learn more about Cyber in Business:

https://www.cyberinbusiness.com/

https://twitter.com/cyberinbusiness

https://www.linkedin.com/company/cyber-in-business

cyberinbusiness #cybersecurity #riskmanagement

1:16 What made you move into risk assessment and compliance? 2:26 What is a risk assessment in the context of cybersecurity?
3:57 What are the pain points in the industry and the opportunities they present for change and innovation?

5:18 Would this sit alongside the work that consultants would be doing? 6:09 What is an interesting case where the business switched to 6clicks? How did it impact their security posture?
7:44 Walk us through the user experience of your system
9:16 Why is your solution better than competitors?
11:21 What about the predictive analytics and some of the mechanisms behind the software? 13:27 What are some great risk assessment frameworks when applied to cyber hygiene and cyber risk?
14:43 What components of a business do you look at when assessing their cyber risk?
16:06 Are your risk assessments (or broadly all risk assessments) accurate?
7:41 How does risk assessment impact cyber insurance?
19:08 What is the most common oversight businesses have regarding risk compliance that jeopardises their security?
20:06 What do you foresee for the future of assessing and managing cyber risk?

View Details

Schools are responsible for significant amounts of often highly personal information about their students, teachers, and parents. What are the key risks and controls we should be examining to secure data in schools?

Join us as we chat to David Eedle, Co-Founder and CTO of EdSmart. David draws from over 20 years’ experience as a technology leader, investor, entrepreneur and contractor to global Internet and technology businesses. He’s passionate about how technology is embedded and protected in school systems.

Cyber in Business is powered by CTRL Group:

https://ctrlgroup.io/

Learn more about EdSmart:

https://edsmart.com/

Follow EdSmart on Twitter:

https://twitter.com/EdSmartSOS

Listen to Cyber in Business on the go!

https://open.spotify.com/show/0U9iyMK9s6O2tcxw7Xzqyt

https://podcasts.apple.com/au/podcast/cyber-in-business/id1521208739

Learn more about Cyber in Business:

https://www.cyberinbusiness.com/

https://twitter.com/cyberinbusiness

https://www.linkedin.com/company/cyber-in-business

cyberinbusiness #schooldata #cybersecurity

  • 1:47 Tell us a little bit about yourself, what got you into this space?
  • 6:01 Why should schools be concerned with privacy and data protection?
  • 8:43 What kind of data are schools collecting and storing?
  • 14:02 Do you believe schools have the appropriate systems and controls in place to protect their data?
  • 17:43 How would you rate the education sector’s security posture? Where are they exposed?
  • 21:12 Do you think there’s a risk with delegating cybersecurity exclusively to the IT team?
  • 27:25 What risks do you foresee in the future as schools become fully digital?
  • 30:48 What are some emerging technologies that you’re excited about and what are some that you’re worried about?
  • 36:46 Who should be responsible for cybersecurity in a school ecosystem?

View Details

It seems like a very appropriate time in recent history to be talking about crisis, but Grant Chisnall has been supporting people and organisations with managing crisis for years now. As host of the Crisis Talks podcast and founder of Left of Boom, Grant spends his time as a crisis advisor and trainer to empower people to be proactive about crisis management.

Nowadays Grant is increasingly dealing with cyber crisis, so he shares his insight with us from those recent experiences.

Cyber in Business is powered by CTRL Group:

https://ctrlgroup.io/

Learn more about Left of Boom:

https://leftofboom.com.au/

Check out Crisis Talks podcast:

https://crisistalks.podbean.com/

Connect with Grant:

https://au.linkedin.com/in/grant-chisnall

Listen to Cyber in Business on the go!

https://open.spotify.com/show/0U9iyMK9s6O2tcxw7Xzqyt

https://podcasts.apple.com/au/podcast/cyber-in-business/id1521208739

Learn more about Cyber in Business:

https://www.cyberinbusiness.com/

https://twitter.com/cyberinbusiness

https://www.linkedin.com/company/cyber-in-business

cyberinbusiness #cybersecurity

  • 1:25 What are some of the roles in your past that led you to be an expert in risk and crisis management?
  • 4:06 Are there any particular crisis scenarios that shifted your perspective on your work?
  • 7:35 Can you tell us a bit more about the context and nature of the recent major attacks?
  • 11:55 What are the top pieces of advice that you’re giving to companies to manage cybersecurity risk?
  • 14:27 What kind of advice are you giving to business leaders to be more proactive?
  • 17:07 How does an attack actually move through a business network, large or small?
  • 19:08 What’s the biggest challenge you face in consulting organisations on managing their risks?
  • 20:32 Are there any particular hacks that intrigue you?

View Details

We can all agree that no business wants to be insecure, so let’s clarify what makes business information insecure and how to shift the mindset of an entire business to achieve a security-first attitude.

Leading security consultant, Jo Stewart-Rattray, clarifies the relationship between information security and cybersecurity and how it relates to business function. She draws on years of experience in psychology, information security, and leading security teams and non-profit organisations across industries.

We achieved attitudinal shifts with OH&S standards – surely we can do this with cybersecurity!

Cyber in Business is powered by CTRL Group:

https://ctrlgroup.io/

Learn more about Silver Chain Group:

https://www.silverchain.org.au/wa/

Connect with Jo:

https://www.linkedin.com/in/jo-stewart-rattray-cism-cgeit-cisa-crisc-cp-4991a12/

Learn more about Cyber in Business:

https://www.cyberinbusiness.com/

https://twitter.com/cyberinbusiness

https://www.linkedin.com/company/cyber-in-business

https://www.facebook.com/cyberinbusiness/

cyberinbusiness #cybersecurity

  • 1:04 Can you share some of the highlights in your career that underscore the importance of cybersecurity for businesses?
  • 3:24 What are the types of business scenarios you’ve been dealing with recently?
  • 5:30 What is the most common misperception about cybersecurity that you come across?
  • 10:52 What are the challenges you face in getting businesses to achieve a security-first attitude?
  • 14:36 How should businesses be approaching cybersecurity? Where do they start?
  • 19:05 Where do small businesses sit in all this?
  • 20:05 If there’s one thing you wish all businesses, large and small, would be aware of, what would it be?
  • 20:30 What kind of hacks intrigue you the most?
  • 23:52 What does your alter ego wear – blue or red hat?

View Details

Business continuity planning safeguards your organisation for unexpected events that could cripple your capabilities. It doesn’t need to be long or fancy, it just needs to be practical in order to be effective.

The expert in business continuity, Rinske Geerlings, shares her direct and open approach to complex processes involved in business continuity and information security. She also shares how cybersecurity plays a role in safeguarding your business for the unexpected.

Cyber in Business is powered by CTRL Group:
https://ctrlgroup.io/

Learn more about Business As Usual:
https://businessasusual.com.au/
www.linkedin.com/company/businessasusual

Follow Rinske Geerlings:
www.linkedin.com/in/businessasusual

Check out their upcoming events:
https://businessasusual.com.au/meet-business-as-usual

Learn more about Cyber in Business:
https://www.cyberinbusiness.com/
https://twitter.com/cyberinbusiness
https://www.linkedin.com/company/cyber-in-business/
https://www.facebook.com/cyberinbusiness/

cyberinbusiness #cybersecurity #businesscontinuity

  • 1:32 Can you help us understand what business continuity is?
  • 3:42 What are the types of disaster scenarios you’ve been dealing with in your career? What role has cybersecurity played in them?
  • 6:15 What did your involvement with the Australian Financial Industry Standard for Business Continuity entail?
  • 8:18 What are the human elements that we perhaps don’t think about when making business continuity plans?
  • 11:16 What are your observations on how businesses at times jeopardise their security for the purpose of operational benefits?
  • 15:50 In scenarios where staff are evacuated or working remotely, how should organisations plan for returning back to BAU?
  • 18:18 Do you think standards and regulations are going to be impacted by the recent events from the pandemic?
  • 20:21 How are small businesses supposed to do continuity plans when there’s a lot on their plate?
  • 26:08 If there’s one thing you wish all businesses, large and small, would be aware of what would it be?
  • 27:22 Do you have an appetite for any boardgames that you like to play?

View Details

Privacy and data protection are closely interconnected, perhaps so much so that we often think of them as synonymous. Distinguishing between the two is fundamental to understanding what business obligations we have in protecting them and abiding by regulations.

Helping us understand this area is Alison Baker, Partner at Hall & Wilcox and an expert in assisting organisations with responding to data breaches. She outlines what the business obligations are and what you need to be thinking about as you handle confidential information in your business.

Cyber in Business is powered by CTRL Group:
https://ctrlgroup.io/

Learn more about Hall & Wilcox:
https://hallandwilcox.com.au/

Check out their COVID-19 assistance page:
https://hallandwilcox.com.au/practices/turnaround-corporate-renewal/

Office of the Australian Information Commissioner for helpful tips:
https://www.oaic.gov.au/

Learn more about Cyber in Business:
https://www.cyberinbusiness.com/
https://twitter.com/cyberinbusiness
https://www.linkedin.com/company/cyber-in-business/
https://www.facebook.com/cyberinbusiness/

cyberinbusiness #cybersecurity

  • 1:09 Can you explain the difference between privacy and data protection?
  • 2:14 What are the cornerstone laws that are in place for these two disciplines?
  • 3:30 What are the business obligations in Australia for these two disciplines?
  • 5:53 How comprehensive is the Australian privacy and data protection framework?
  • 7:00 Have lawmakers kept up to date with new technological advancements?
  • 8:18 What do you hope to see in the future state of privacy and data protection laws and regulations? Is there room for improvement?
  • 11:03 Do you believe businesses find it challenging to comply with these regulations?
  • 13:06 Can you describe what kind of capabilities businesses need to have in place to adhere to these regulations and laws?
  • 15:14 What are common themes for businesses that are suffering in these scenarios?
  • 18:10 How impactful is a data breach to a business?
  • 19:39 What should businesses be considering for collecting personal and health information of employees to minimise COVID-19 risks?
  • 23:27 Can you talk through privacy considerations for remote working arrangements?
  • 25:43 Can you tell us what your personal view on privacy is? Is it a fundamental human right or should we be looking at it differently?
  • 27:16 Is the COVIDSafe app safe? Can we trust the app to not disclose our information?

View Details

In the business world we often think cybersecurity is just about our technical solutions. The firewall and antivirus software should be enough, right? Not quite.

Bastien Treptel, Co-Founder of CTRL Group, takes us into the hacker mindset to share some of the social engineering techniques his team uses in an ethical breach. He also helps us clarify what social engineering actually entails and shares some insight into how it's changing during a new era of working from home and other COVID-19 consequences.

Learn more about CTRL Group:
https://ctrlgroup.io/
https://www.linkedin.com/company/ctrlgroup/

And check out the Cyber Hacker podcast:
https://ctrlgroup.io/cyber-hacker-podcast/

Cyber in Business is proudly supported by CTRL Group

Learn more about Cyber in Business:
https://www.cyberinbusiness.com/
https://twitter.com/cyberinbusiness
https://www.linkedin.com/company/cyber-in-business/
https://www.facebook.com/cyberinbusiness/

cyberinbusiness #cybersecurity

  • 1:04 How did social engineering originate?
  • 2:05 What outcomes does a social engineering technique drive?
  • 2:32 What are common misconceptions of social engineering?
  • 5:06 Walk us through how your team thinks through planning a social engineering attack?
  • 9:00 Why is it challenging for businesses to understand social engineering attacks?
  • 10:09 What makes an attacker successful at social engineering?
  • 11:56 What do you recommend for businesses to secure themselves and protect against potential social engineering threats?
  • 14:03 What should businesses watch out for as they start increasing their digital activities?
  • 17:52 What is CTRL Group doing to adapt to this environment and deliver (ethical) social engineering attacks?
  • 19:51 What are current trends in attacks?
  • 21:27 What are the implications for social engineering in working from home arrangements?
  • 25:42 Any final thoughts?