AttackIQ’s podcast series, Think Bad, Do Good, brings together security researchers, informed defenders, and intelligence practitioners for discussions about how security teams can build a strong threat-informed defense strategy. Listen in for lively discussions on emerging strategic concepts, threats and emulation plans, optimizing your cybersecurity investments, and cybersecurity events in the news.
About AttackIQ: Adversaries across the globe, from nation-states to criminal organizations, hold our businesses, democracy, and society at risk through cyberspace. Our mission at AttackIQ is to help solve that problem and make the world safe for compute.
As the leading independent vendor of breach and attack simulation solutions, we built the industry’s first Security Optimization Platform for continuous security control validation and improving security program effectiveness and efficiency. We are trusted by leading organizations worldwide to identify security improvements and verify that cyberdefenses work as expected, aligned with the MITRE ATT&CK framework.
We’re strongly committed to giving back to the cybersecurity community through our free, award-winning AttackIQ Academy, open Preactive Security Exchange, and partnership with MITRE Engenuity Center for Threat-Informed Defense, and we’re proud to be consecutively named a Fortune Great Place to Work, as well as a participant in the Respect in Security pledge.
Guest: Renée DiResta, Research Manager, Stanford Internet Observatory
Renée di Resta is a pioneer in the study of disinformation, and through her research at the Stanford Internet Observatory and regular contributions to The Atlantic Monthly she has made her voice heard on the harms of amplified propaganda and the role it has in shaping public opinion.
How do false narratives spread? “You have human nature, which has not really changed very much in many ways over time, either. A lot of the kind of psychological motivators have been consistent. What do people need, what do they want, what are they looking for?” Renée investigates the intersection of platform algorithms with user behavior and factional crowd dynamics to get to the root of the problem. “What really does change is the communication technology. And when we’re talking about propaganda, which really is referring to messaging, we’re talking about ways in which entities who are trying to achieve a particular objective, use communication to send messages to the public.”
In this installment of Think Bad, Do Good, Renée and Jonathan examine the role of “filter bubbles” in the dissemination of false narratives and individual agendas, the creation of polarization in public opinion, blurred lines between fact and bias, and the growth and spread of extremism. “Another thing that we see a lot in our work is looking at what makes things go viral,” Renée says. “People make crazy claims on the internet all the time but what starts to happen is that you’ll see incentivized influencers with very large followings who will pick up that claim, but they do it in a really interesting way.”
Tune in to learn more.
Renée’s most recent articles: It’s Not Misinformation. It’s Amplified Propaganda: https://www.theatlantic.com/ideas/archive/2021/10/disinformation-propaganda-amplification-ampliganda/620334/ The Ukraine Crisis Briefly Put America’s Culture War in Perspective: https://www.theatlantic.com/ideas/archive/2022/03/russia-ukraine-war-stopped-internet-culture-war/627122/ Elon Musk Is Fighting for Attention, Not Free Speech: https://www.theatlantic.com/ideas/archive/2022/04/elon-musk-buy-twitter-free-speech/629571/ The Digital Maginot Line: https://www.ribbonfarm.com/2018/11/28/the-digital-maginot-line/
Click here to read the transcript: https://www.attackiq.com/podcasts/confronting-the-disinformation-age/#transcript
Guest: Josephine Wolff, The Fletcher School of Law and Diplomacy
For anyone interested in understanding cybersecurity insurance, Josephine Wolff is the premier global expert on the issue. And cyberinsurance is a tricky market. “We’re all relying on the same infrastructure or the same fairly small set of infrastructure for our computer systems,” Josephine says in this episode of Think Bad, Do Good. Other types of insurers can diversify their risk portfolio and assume that all policy holders are not going to be hit by the same fire, the same flood, or the same car accident all at once. But due to the scope of cybersecurity risk, cyberinsurers lack that luxury.
How does it play out? “The ideal would be your insurer comes in, they assess your security posture, and then they price your premium based on how good your security is. And I think what a lot of companies feel now is like, they come in, they do this endless questionnaire, and then they’re just going to price your premium based on how big your company is anyway.” The impact is significant. “It plays into this larger dynamic of sort of caution on the part of the insurers, saying, ‘We don’t really feel we know how to defend against these types of incidents, so we would rather not be on the hook to be covering more and more and larger and larger of them.’” That issues rests at the core of the current public debate.
Author of Cyberinsurance Policy and professor at The Fletcher School, Josephine Wolff examines the development of cyberinsurance, compares it to other sectors, and details how the complexity of cybersecurity insurance can lead to legal disputes between insurers and policyholders. “Who ends up paying? What are all the various complicated legal and liability issues here? And what can we say about who gets held responsible and who doesn’t?” Tune in to learn more about the path ahead.
Key links to Josephine’s work: Link to her new book, available from MIT Press: Cyinsurance Policy: Rethinking Risk in an Age of Ransomware, Computer Fraud, Data Breaches, and Cyberattacks: https://mitpress.mit.edu/9780262544184/cyberinsurance-policy/ Her recent article in the Financial Times: “Insurers must rethink handling of cyberattacks on states.”: https://www.ft.com/content/aa147054-ec14-4a75-a183-bee345319948 Her recent article in Slate (no paywall), “A Brief History of Cyberinsurance.”: https://slate.com/technology/2022/08/cyberinsurance-history-regulation.html
Click here to read the transcript: https://www.attackiq.com/podcasts/the-state-of-the-cyberinsurance-market-today/#transcript
Guest: Marcus Bartram, General Partner at Telstra Ventures
Telstra Ventures’ Marcus Bartram understands the growing pains inherent in building a business. Working at high-growth companies early in his career helped him build wisdom and resilience and foster a sense of empathy towards entrepreneurs. As a venture capitalist, Marcus understands how to use capital as a tool for building a business, and he and his team have led successful investments in companies like CrowdStrike, Auth0, Corvus Insurance, Elastica, and vArmour, among many others.
In this episode, Marcus joins Jonathan to discuss the ins-and-outs of evaluating potential investment opportunities, the company profiles that attract venture capitalists, and the excitement that comes with building partnerships. “Who’s the team?” Marcus asks. “Do you believe in the vision they’re trying to paint? Do you trust them to want to give them literally millions of dollars of money? And do you think they can execute on the vision?”
Marcus recounts stories of navigating the turbulent dotcom boom of the late-1990s, reflects on the role it played in his career, and shares his views on the future of cybersecurity and technology. “For my sins, I really like the cybersecurity market, which is a huge, vibrant market with lots of opportunity,” he remarks. “What’s their unique view on that, and why are they different to the other thousands of cybersecurity startups that are in the market today? Are they solving a big problem, or are they solving for a feature in cybersecurity?”
Click here to read the transcript: https://www.attackiq.com/podcasts/how-to-build-and-scale-a-successful-cybersecurity-company/#transcript
Rob Hornbuckle, Chief Information Security Officer, Allegiant Airways.
Years before he became Chief Information Security Officer (CISO) at Allegiant Airways, Rob Hornbuckle studied acting and worked as a bartender – lessons that served him well as a four-time CISO. He understands business, he understands technology, but above all he understands human behavior.
“Something is eventually going to happen at any organization you potentially could work for,” says Rob. “If you work there long enough, something will eventually happen. What’s going to determine your success and your longevity long-term as a CISO is how you react to it, how you handle it, how well everyone trusts that you’ve both done the best you can, and that you’ve had the best interest of the organization in mind.”
Accountability matters a lot. “One of the most executive things you can ever do is stand up and take accountability when it’s your fault,” he says. “You will garner significantly more respect if you stand up and take accountability when it’s your fault than if you try to slough it off or if you act dodgy. It’s almost human nature to want to shy away, to want to not get in trouble, to want to try to curl up and defend yourself in some way. But the most executive thing that you can possibly ever do is stand up and take accountability when you were at fault either fully or even partially.”
In one of the most illuminating podcasts yet, Rob sits down with Jonathan to outline his vision for leadership development and success in security.
Click here to read the transcript: https://attackiq.com/podcasts/not-your-normal-ciso-lessons-in-security-leadership-from-bartending-to-the-boardroom/#transcript
Juliette Kayyem wants you to fail safer when disaster inevitably strikes. A former assistant secretary of homeland security, Harvard professor, and contributor to The Atlantic Monthly, she is the author of the new book, The Devil Never Sleeps: Learning to Live in an Age of Disasters. In this episode, Juliette talks with host Jonathan Reiber about how we can get ahead of disasters and bounce back when the inevitable “boom” finally comes.
Click here to read the transcript: https://attackiq.com/podcasts/preparing-for-disaster-and-achieving-cybersecurity-readiness/#transcript
The confusion between fortune, chance, and luck speaks to the fact that most people aren’t fully aware of how much control they have over their own fate. If you look closely though, you will see lots of ways to increase your luck. The key is understanding that luck is rarely a lightning strike— isolated and dramatic — but a wind that blows constantly. Join Dr. Tina Seelig from Stanford University, with Toby Shapshak, editor-in-chief and publisher of Stuff, in an insightful conversation around how to catch the winds of luck in your profession and daily life.
Speakers: Dr. Tina Seelig Toby Shapshak - Stuff
How are leading companies and organizations adopting a threat-informed defense? Join Chris Kissel, Research Director, International Data Corporation (IDC)'s Security & Trust Products Group, Russ Nolan, Security Engineer, Stripe and Stephan Chenette, Co-Founder and CTO, AttackIQ.
Speakers: Chris Kisse, International Data Corporation (IDC)'s Security & Trust Products Group Stephan Chenette, AttackIQ Russ Nolen, Stripe
MITRE’s Jonathan Broadbent and Dr. Christina Liaghati discuss AI Threats & Vulnerabilities, real-world observations, demonstrations from ML red teams and security groups, and the state of the possible from academic research and MITRE ATLAS, the Adversarial Threat Landscape for AI Systems, a collaboratively developed knowledge base of adversary tactics, techniques (MITRE ATLAS™ Introduction - YouTube). They walk through how threats and vulnerabilities have and can continue to impact AI systems, showing real-world examples and talked about MITRE’s growing mechanism for collaboration with ongoing opportunities for industry leaders to shape the future of AI Assurance. If you are interested in driving action as part of the ATLAS Consortium or you would like to learn more about the ATLAS framework, email Jonathan at jbroadbent@mitre.org and Christina at cliaghati@mitre.org and the full MITRE ATLAS team at atlas@mitre.org.
As the security industry has matured over the last decade, businesses now invest in the most advanced security technologies to stop attacks, from endpoint detection to next generation firewalls to micro-segmentation. The problem is that companies overemphasize technology procurement at the expense of team performance. Only 15 percent of the risks we face in cyberspace are related to technology; the other 85 percent is due to human performance. It’s time for managers to tilt the focus away from technology procurement and towards training for operational readiness. In this session, join Timothy Rohrbaugh, Chief Information Security Officer of JetBlue Airways, and Jonathan Reiber, Senior Director for Cybersecurity Strategy and Policy at AttackIQ and former Chief Strategy Officer for Cyber Policy in the Office of the Secretary of Defense, in conversation with Maggie Miller, Cybersecurity Journalist at Politico, about the importance of continuous testing in achieving optimal team performance.
Speakers: Timothy Rohrbaugh, JetBlue Airways Maggie Mille, Politico Jonathan Reiber, AttackIQ
Time Out: Thinking About AI. This session will discuss the future of artificial intelligence and how we engage with data. "Time Out" is not just time away from our normal discourse, but time further out, as the security of artificial intelligence will be an issue of the future. We turned to cybersecurity long after we developed the systems of cyberspace; we must not fall similarly behind on AI, particularly since AI systems may be harder to protect than our networks. They are not deterministic, they are more opaque than the software of cyberspace, and data, not code, is what directs the machine. There are significant analogies between machine learning, bureaucracies, and markets for us to divine as we think about the future of AI security. There is a vulnerability to data poisoning across all three areas, and each ignores externalities and "common sense" behavior that is not already pre-programmed within it. Machine learning will be subject to regulation just as bureaucracies and markets themselves became regulated. Come and listen to two of the world’s leading theorists of artificial intelligence, technology, and security to think deeply about the future of AI, building on Richard Danzig's recent paper, "Machines, Markets and Bureaucracies as Artificial Intelligences."
The Hon. Dr. Richard J. Danzig is a Senior Fellow at the Johns Hopkins Applied Physics Laboratory, a Trustee of the RAND Corporation, a Director of the Center for a New American Security, and a Director of Saffron Hill Ventures (a European investment firm). Dr. Melanie Mitchell is the Davis Professor at the Santa Fe Institute. Her current research focuses on conceptual abstraction, analogy-making, and visual recognition in artificial intelligence systems.
Speakers: Dr. Richard J. Danzig Dr. Melanie Mitchell, Sante Fe Institute Joe Uchill, SC Media
The creation of the MITRE ATT&CK framework has helped security teams focus on specific adversaries to enhance their defense effectiveness. Since the launch of the Center for Threat-Informed Defense in 2020, the Center has built out a library of adversary emulations, beginning with APT29 and FIN6. What is the benefit of thinking about a specific adversary in this way? Join leaders from a premier global technology company in a discussion about their prospective use of adversary emulations to improve cybersecurity operations.
Speakers: Cory Sutliff, AttackIQ Douglas Hurd, Cisco
Attacks on the healthcare sector have increased exponentially under the coronavirus pandemic, from ransomware attacks on strained hospitals to intellectual property theft of vaccine data from research institutions. What is the evolving threat landscape for the healthcare sector, particularly for medical devices, and how can security teams use known threat behaviors to improve their cybersecurity posture? In this session, join Ingrid Skoog, Assistant Director of Research & Development, Center for Threat-Informed Defense; Dr. Suzanne Schwartz, Director, Office of Strategic Partnerships and Technology Innovation, Center for Devices & Radiological Health, US FDA; Margie Zuk, Sr. Principal Cybersecurity Engineer, MITRE; and Jose Barajas, Technical Director, AttackIQ for an in-depth discussion for how to improve cybersecurity for medical devices and the healthcare and public health sectors.
Speakers: Ingrid Skoog, Center for Threat-Informed Defense Suzanne Schwartz, FDA Margie Zuk, MITRE Corporation Jose Barajas, AttackIQ
Are you capturing the right logs? Are your logs complete? Would you be able to detect the next Solorigate attack? These questions may keep you awake at night. But using DeTT&CT and the MITRE ATT&CK Framework can help you understand where you need to shore up your logging. Let me show you how!
In this session, we'll discuss why the ATT&CK Framework is important for threat detection. Then we'll dig into how you can use DeTTECT to identify the areas of your environment where your logging may not be comprehensive enough to catch the threats in ATT&CK. It's a fun exercise and very visual. Best of all, I'll walk you through the steps you'll need to perform to set this up on your own.
Speaker: David Branscome, Microsoft
What will cybersecurity leaders Gabriel Lawrence of Toyota and Uma Mahesh Reddy of Prime Healthcare Services have to say about staying on top of threats and how to find your blind spots? Join this session to hear their thoughts on strategies for agility in the face of new threats, and if you can ever truly say "we’re secure."
Speakers: Uma Mahesh Reddy, Prime Healthcare Services Gabe Lawrence, Toyota Julie O’Brien, AttackIQ
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
Nation-state and cybercriminal adversaries are investing substantially in cyberoffensive capabilities in order to accomplish their objectives. Year over year, we continue to see a massive escalation in both frequency and severity of attacks. While organizations are spending more than ever before in the modern history of defensive cyberoperations, the unfortunate success of adversaries is measured in the trillions of dollars lost. Some argue we are involved in a kind of low-intensity, asymmetric warfare. For every dollar a cyberadversay spends we have to spend $100 on defense. It is clear we must shift our strategy, as governments and as capitalist markets, if we wish to maintain our strategic advantages. In the digital era, every organization can be considered a technology company. Whether you provide electricity, banking, public transportation or government services, you are increasingly dependent upon the internet and network connectively to make money, save lives, and provide services to citizens. If all organizations are technology companies, that means all companies need to prioritize cybersecurity as a strategic imperative to ensure they are connected, digitized, and defended.
In this fireside chat, Lt. Gen. Lori Reynolds (ret'd), US Marine Corps, former Commander of U.S. Marine Corps Cyberspace Command, and Carl Wright, Chief Commercial Officer of AttackIQ and former Chief Information Security Officer of the U.S. Marine Corps., will discuss strategic questions that organizations need to ask and answer as part of a proactive plan to stop cyberadversaries from disrupting operations. You will also learn about how Cyber Command and the NSA are sharing intelligence, as well as how to access this intelligence.
Speakers: Lt. General Loretta (Lori) Reynolds, United States Marine Corps (Ret.) Carl Wright, AttackIQ
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
There has been a lot of buzz around Extended Detection and Response (XDR) as an evolution of Endpoint Detection and Response (EDR), however definitions of what comprises an effective XDR solution vary depending on who you ask. The dramatic changes to IT infrastructure as organizations accelerate their migration to the Cloud while still relying on traditional on-premises security architecture has increased telemetry volumes and the complexity of correlating threat intelligence across disparate environments to make accurate detections early in the attack sequence. In this session we will discuss the evolution of security from the endpoint to across the entire IT ecosystem, from legacy antivirus to EDR, and now from EDR to XDR. We will show how detection use cases and workflows that previously required complex syntax queries and manually configured SIEM and SOAR solutions can be automated and streamlined with XDR for rapid detection, investigation and predictive response actions that move intervention further to the left in the attack sequence.
Speakers: Ken Westin, Cybereason Mark Bagle, AttackIQ
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
Since MITRE ATT&CK was first published in 2015, it has led to a transformation in how security teams think about and approach threats and cybersecurity effectiveness. Now ATT&CK is being amplified by cutting-edge research from the Center for Threat-Informed Defense, a non-profit, privately funded research and development organization operated by MITRE Engenuity with over 13 major projects behind it. How is ATT&CK and the practice of threat-informed defense changing the world? Join Neal Bridges, creator of the Cyber Insecurity livestream channel on Twitch and Chief Cyber Security and Content Officer at INE, Jonathan Baker, Director of Research and Development, Center for Threat-Informed Defense, MITRE Enguiniety, and Cat Self, Lead Adversary Emulation Engineer, MITRE for a conversation about ATT&CK and the future of threat-informed defense.
Speakers: Neal Bridges, Query.AI Jonathan Baker, MITRE Engenuity Cat Self, MITRE Corporation
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
Information technology is creating a more connected world, and our dependence on technology for all aspects of our lives continues to increase. However, the advanced technology and sophisticated logistics networks that support this connectivity are facing unprecedented attacks, which risk undermining the trust on which growth, prosperity, and international relations rest. Complicating matters further, the complexity, sophistication and potential impact of attacks also have increased substantially over time. This session will focus on taking a holistic approach to protecting supply chains and delivering products, solutions and services that customers can trust. John will clearly define the modern supply chain (both physical and digital), provide examples of past attacks, current threats and how security governance, risk management and preventative threat assessment are critical to safeguarding the performance and integrity of global supply chains. The session will further examine a posture of "defense-in-depth" and "defense-in-breadth" that involves multiple layers of preventative measures and controls to mitigate threats that could be introduced into global critical infrastructure supply chains.
Speaker: John Boyle. Dell
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
Threat hunting is one of the most popular techniques used by security analysts for all kinds of investigations. It is both science and, to some degree, inspiration. However in the last years the security industry has developed new tools and techniques that can dramatically improve the effectiveness and efficiency of our threat hunting. In particular, similarity and automatic Yara generation are key when dealing with large amounts of data. In this talk we learn what's new in the process of threat hunting and showcase how to leverage new techniques available for analysts to step research up to the next level.
Speaker: Vicente Diaz, Google
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
Despite spending billions of dollars adopting best-in-class cyberdefense technologies and hiring top-tier personnel, organizations continue to suffer security breaches. How can organizations achieve a strong return on their cybersecurity investments, particularly through the use of purple teaming and a threat-informed defense? Join two innovative CISOs that are answering this question. Martin Petersen, Chief Information Security Officer at ISS World Services A/S and Allan Alford, Chief Information Security Officer and Chief Technology Officer at TrustMAPP.
Speakers: Martin Petersen, ISS A/S Allan Alford, TrustMAPP
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
Public cloud providers have built native security controls into their cloud offerings so customers can easily defend their data in the cloud, but organizations still need a means to test and optimize their cloud security effectiveness. Join leaders from major cybersecurity providers in a discussion about trends in threat-informed defense in cloud security operations.
Speakers: Victor Monga, VMware Chad Skipper, VMware
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
How do you build an evidence-based cybersecurity program? To learn how to improve your cybersecurity performance, come listen to leading cybersecurity strategists discuss how to measure program success, what data is important to collect, and other aspects of using evidence-based cybersecurity management to achieve better business outcomes. Vicente Aceituno Canal, Chief Information Security Officer of Lottoland, and Christopher Frenz, Information Security Officer and AVP of IT Security at Mount Sinai South Nassau.
Speakers: Vicente Aceituno Canal, Lottoland Christopher Frenz, Mount Sinai South Nassau Keith Wilson. AttackIQ
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
What are the key challenges in cybersecurity and cyberspace operations today, and how can the U.S. government best respond? Listen to two of the United States’ most important thinkers and leaders in cybersecurity and technology, Jen Easterly, Director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in conversation with Dr. Richard Danzig, Senior Fellow at Johns Hopkins Applied Research Laboratory and former U.S. Secretary of the Navy.
Speakers: Jen Easterly, Director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
Dr. Richard J. Danzig, Senior Fellow at the Johns Hopkins Applied Physics Laboratory, a Trustee of the RAND Corporation, and former U.S. Secretary of the Navy
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
In an increasingly complex world, security teams struggle over how best to improve their program performance. Even after decades of investment in the best technologies and teams, intruders keep breaking past and having an impact. Why? Just like a World Cup soccer team, security teams need to train and prepare for their opponents. Today, they don’t do so enough. There is a path for elevating cybersecurity performance, however, and it begins by focusing on what we know. Practically, we know adversaries use the same time-honored tactics, techniques, and procedures, over and over, to achieve their strategic objectives. That’s why the MITRE ATT&CK framework is so useful as a period table of known behaviors. It is why we believe in a purple team defensive construct. And it is why we gather at the Purple Hats Conference: to prepare for the challenges we face, to share lessons derived from wisdom and experience, and to make the world a safer place. Join AttackIQ CEO Brett Galloway in exploring these and other issues in his opening address.
Speaker: Brett Galloway, AttackIQ
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
Welcome to the 2nd annual, award-winning virtual Purple Hats Conference — the industry destination for cybersecurity practitioners to collaborate, share ideas, and learn how to evolve from a reactive to proactive threat-informed defense! Founded by AttackIQ, Purple Hats provides free access to globally recognized experts, technical content, and innovative techniques for improving your security posture and building a stronger, more collaborative team.
AttackIQ Purple Hats: www.purplehats.org/ AttackIQ Academy: academy.attackiq.com/ AttackIQ: attackiq.com/
Guest: Christopher Frenz, Information Security Officer and AVP of IT Security at Mount Sinai South Nassau
In this episode, Christopher and Jonathan discuss the zero trust security model and look at how to achieve an evidence-based security program by adopting a threat-informed defense in the hospital sector. Hospitals and healthcare organizations are under siege in cyberspace following an increase in ransomware attacks and the broader pressures of the coronavirus pandemic. After decades of work in cybersecurity, Christopher understands how continuous testing and the MITRE ATT&CK framework can help organizations get ahead. “A lot of the metrics used today are not fine grained enough,” he says. “Looking at MITRE ATT&CK, the different tactics and techniques that can be used against us provides an effective way to identify what we need to be protecting, and what we need to be detecting. We use this as a basis for testing and evaluating the security that is in place within our organizations.” He takes a scientific approach to security by measuring the efficacy of the controls through real-time testing and uses data to improve his organization’s overall security posture.
Tune in and listen to one of the cybersecurity industry’s leading advocates of a threat-informed defense. For more on this subject, check out Christopher’s recent article in Healthcare IT News:https://www.healthcareitnews.com/blog/achieving-evidence-based-security-threat-informed-defense
Guest: Ken Towne, Adversary Emulation Engineer, and Adam Moore, Head of Adversary Research and Development, AttackIQ
In the face of Russian aggression and with the risk of potential cyberattacks increasing, it’s time to make sure that your cyberdefense shields work. Join Ken Towne, Adversary Emulation Engineer, and Adam Moore, Head of Adversary Research and Development, as they talk with host Jonathan Reiber about threat behaviors that are being observed at this moment, how organizations can improve their cybersecurity readiness, and steps teams can take to validate their defenses against Russia-based attackers using a new attack graph in the AttackIQ Security Optimization Platform.
Guest: Uma Mahesh Reddy, CISO, Prime Healthcare Services.
In this episode, Uma and Jonathan discuss the practice of a threat-informed defense and how organizations can use real-time performance data to optimize their security program performance and make the most of their security investments.
AttackIQ Vanguard has been instrumental in supporting Uma’s team with their cybersecurity readiness. Vanguard helps Prime Healthcare identify configuration errors, find security gaps, and enhance the team’s performance through continuous security control validation.
“Having cybersecurity controls (technology, people, process and procedures) in place will not alone protect your organization from breaches and attacks. Proactively measuring the effectiveness of your controls on a regular basis and fine-tuning them to keep up with the ever-changing threat landscape is imperative,” said Uma Mahesh Reddy.
When Jonathan asked Uma what AttackIQ’s slogan “we’ve got your six” means to him when it comes to cybersecurity programs, he explained with confidence, “You’re not only watching our back, you’re watching the other two sides too. We are focusing on the business, and how do we keep it running securely by having all these controls in place, but you are helping us to make sure that we are heading in the right direction towards our goal.”
Guest: Ted Harrington, Author of Amazon’s best seller Hackable
In episode 10 of Think Bad, Do Good, Jonathan speaks with Ted Harrington, best-selling author of the book Hackable: How to Do Application Security Right, about the way attackers think, readiness and resilience, and how to live a purposeful career in leadership and public service.
About Hackable: How to Do Application Security Right
If you don’t fix your security vulnerabilities, attackers will exploit them. It’s simply a matter of who finds them first. If you fail to prove that your software is secure, your sales are at risk too.
Whether you’re a technology executive, developer, or security professional, you are responsible for securing your application. However, you may be uncertain about what works, what doesn’t, how hackers exploit applications, or how much to spend. Or maybe you think you do know, but don’t realize what you’re doing wrong.
To defend against attackers, you must think like them. As a leader of ethical hackers, Ted Harrington helps the world’s foremost companies secure their technology. Hackable teaches you exactly how. You’ll learn how to eradicate security vulnerabilities, establish a threat model, and build security into the development process. You’ll build better, more secure products. You’ll gain a competitive edge, earn trust, and win sales.
Guest: Jose Barajas, Director of Global Sales Engineering, AttackIQ
In episode 8 of Think Bad, Do Good, Jose Barajas and Jonathan Reiber discuss MITRE Engenuity’s Center for Threat-Informed Defense and AttackIQ’s emulation plan for menuPass. This plan will enable defenders to replicate tactics and techniques used by menuPass, a cyber threat actor that has been active since 2006 and whose goals are aligned with the People’s Republic of China’s Five Year plan. Members of the group have, according to MITRE ATT&CK, worked in association with the Chinese Ministry of State Security’s (MSS).
What has been their impact? menuPass is responsible for global intellectual property theft in at least 12 countries. The group has targeted companies within the healthcare, defense, aerospace, and government sectors, with emphasis since 2014 on Japanese victims. As MITRE ATT&CK describes the group’s behavior, “menuPass leveraged its unauthorized access to these managed service providers’ networks to pivot into subscriber networks and steal information from organizations in banking and finance, telecommunications, healthcare, manufacturing, consulting, biotechnology, automotive, and energy.”
In this podcast, you will see and hear about how AttackIQ incorporates MITRE Engenuity’s Center for Threat-Informed Defense’s emulation plan into the Security Optimization Platform to automate the tactics, techniques and procedures used by menuPass. This allows AttackIQ customers to run the emulation plan against their existing and planned security controls to validate their effectiveness and improve their performance against the group. The Security Optimization Platform then provides detailed gap analysis and remediation reports.
Guest: Pete Luban, Head of Information Security and IT Risk at Dimensional Fund Advisors
Chief information security officers and security leaders all over the globe struggle with complexity. Complex socio-political risk; complex risk management organizations; and complex technologies. In Episode 8 of Think Bad, Do Good, we talk with one of the world’s leading cybersecurity operators not just about how you can decrease complexity and strengthen your security program, but how you can become a more effective leader for your organization.
Pete Luban knows the issues well. He is the head of the cybersecurity program for Dimensional Fund Advisors (DFA), an investment management service that operates with over $550 billion in assets under management. Headquartered in Austin, Texas, the 38-year-old company has over 1,700 employees and, in the words of Peter Luban, is “run by a group of computational geniuses.” As a global distributed firm with significant financial assets, it faces similarly significant cyberthreats to its assets and personnel.
For managing these risks, Pete calls the MITRE ATT&CK framework the “mother brain” for security effectiveness. Why? Since he started using ATT&CK, he has seen a fundamental increase in effectiveness in protecting his company, but also in how he communicates to his board. ATT&CK and AttackIQ give him a single tool to see threats and threat behaviors. “That is a giant value add use case that follows the life cycle of information or misinformation from beginning to end and gives me a tool by which to validate, no pun intended, that what we do is worth what the company spends on it, right? That’s a simple use case that is insanely valuable.”
Listen to this episode to learn more about what keeps Pete up at night, what Pete would like to see more broadly adopted in his community to increase communication and effectiveness, and how COVID has transformed cybersecurity for companies everywhere.
Guest: Kumar Chandramoulie, Vice President, Cyberdefense, Data, and Threat Management at AmerisourceBergen
Kumar Chandramoulie is no stranger to challenge. As Vice President, Cyberdefense, Data, and Threat Management at AmerisourceBergen, Chandramoulie is responsible for planning his firm’s approach to cybersecurity risk management across its global operations. This is a vital mission: AmerisourceBergen provides pharmaceutical products, value-driving services, and business solutions that improve access to care. Global manufacturers depend on AmerisourceBergen for services that drive commercial success for their products. Tens of thousands of healthcare providers, veterinary practices, and livestock producers trust AmerisourceBergen as their partner in the pharmaceutical supply chain. Data underpins the entire process, and Kumar is responsible for securing the firm’s networks across multiple borders, businesses, and platforms.
He uses MITRE ATT&CK and AttackIQ to achieve operational effectiveness and help his team do the best job they can. In this episode, Jonathan and Kumar discuss his approach to cybersecurity and how MITRE ATT&CK and AttackIQ help him secure AmerisourceBergen’s data. They talk about Kumar’s process of building a cybersecurity system, why MITRE ATT&CK is so useful for AmerisourceBergen’s security effectiveness, and how performance data helps AmerisourceBergen leadership understand their cybersecurity.
For more about how AmerisourceBergen uses MITRE ATT&CK and AttackIQ, you can dive into this case study here: https://attackiq.com/wp-content/uploads/2020/10/cs-amerisourcebergen.pdf
Guest: Julia Voo, Cyber Fellow at the Belfer Center, Harvard University
Julia Voo once auditioned for a part in Harry Potter because she wanted to go to Hogwarts. But it was much cooler to be a British foreign service officer in Beijing after Brexit covering China’s approach to cybersecurity policy and artificial intelligence from a trade perspective. Now, she’s crushing it on China and cyber policy at Harvard’s Belfer Center, where she serves as a Fellow, and has just led a global team in a comprehensive review of global cyber powers.
In this episode, Jonathan talks with Julia about how an innocuous one-off conversation kicked off the National Cyber Power Index (NCPI), the nature of cyber power in international relations, and the future of U.S.-China relations. Jonathan’s son also makes a brief cameo.
So who are the top ten most “cyber powerful” countries? And why is the Netherlands number 6? The National Cyber Power Index provides an overall measurement of a country’s aptitude as a cyber power – far more than just offensive and defensive capabilities. It gives a new look at international cyberpower, who wields it the most, and how it can best be leveraged in foreign affairs. Learn more and tune in for more.
Guests: Maria Barsallo Lynch, Siobhan Gorman, and Robby Mook of Harvard’s Belfer Center for Science and International Affairs.
Mis/Disinformation and the 2020 Presidential Election.
In this episode of Think Bad Do Good, join cybersecurity and public affairs experts Robby Mook, Siobhan Gorman, and Maria Barsallo Lynch of Harvard’s Defending Digital Democracy project as they discuss the coming presidential election and how state and local government officials and American citizens can take steps to assure its integrity.
Over the last four years these individuals have played significant leadership roles in the United States in helping the states learn about and prepare for cyberspace operations and disinformation operations alike, and last week the Harvard team released The Election Influence Operations Playbook, Part 1, to help election officials manage the threat of disinformation operations to the election.
Defending Digital Democracy was founded in the aftermath of the 2016 election by a group of bipartisan policy, technology, and political leaders to help defend the country’s democratic processes in cyberspace. Since then the Harvard team has produced over half a dozen playbooks and landmark research projects and engaged state, local, and federal government organizations as they address cybersecurity risks to the U.S. democratic process. For more information about the team and its research: https://attackiq.com/podcasts/the-belfer-centers-defending-digital-democracy-project/#description – and give the podcast a listen!
Guest: Jose Barajas, Director, Global Sales Engineering at AttackIQ
Join Jonathan Reiber and Jose Barajas for Episode 4 of “Think Bad, Do Good” diving into the first adversary emulation plan developed at the Center for Threat Informed Defense. The target of this plan is none other than cybercrime group FIN6.
FIN6’s operations have been recorded since 2015. Their modus operandi includes stealing payment card data and then selling it on underground marketplaces. FIN6 is notorious for aggressively targeting and compromising point of sale (PoS) systems in the hospitality and retail sectors. As of last year, their operations have extended to compromising E-Commerce merchants, via placing malware on checkout pages. And like many active threat actors today they are evolving to utilize more advanced methods. But with this emulation plan developed at the Center for Informed Defense (or CTID), organizations within these at-risk industries can begin mounting effective threat-informed preemptive measures against FIN6.
This emulation plan also represents a historic event: the first project that the CTID has released. This organization consists of representatives from the world’s leading cybersecurity companies researching threats (like those posed by FIN6) and developing the tools to counter them.
But how can cybersecurity teams actually take advantage of this new emulation plan for FIN6 and knowledge? Jose and Jonathan explain the process and benefits an emulation plan tailored to a specific threat actor provides. The goal: to help align your defenses with the latest of CTID research built upon MITRE ATT&CK.
Guest: Ben Opel, Director for Customer Success, AttackIQ
Join Jonathan Reiber and Ben Opel for a discussion of threat-informed defense lessons learned from their time serving in the Department of Defense in episode 3 of Think Bad, Do Good. Reiber and Opel reflect on lessons from their two separate but related career trajectories in the Defense Department, Reiber writing the DoD's cyber defense strategies and working in the Office of the Secretary of Defense from the creation of U.S. Cyber Command, Opel joining the U.S. Marine Corps and serving as a cyberspace operator, and defending key terrain and running purple team operations, after graduating from the United States Naval Academy. Both reflect on the current state of operations today from the perspectives of their past experiences.
Jonathan Reiber is Senior Director for Cybersecurity Strategy and Policy at AttackIQ. In this position, he focuses on strategic communications, thought leadership, and content development for the firm. During President Barack Obama’s administration, he served as Chief Strategy Officer for Cyber Policy and Speechwriter in the Office of the U.S. Secretary of Defense. His writing has appeared and been highlighted by Foreign Policy, Lawfare, The Atlantic Monthly, DefenseOne, The San Jose Mercury News, and Literary Hub, among others. An affiliate at UC Berkeley's Center for Long-Term Cybersecurity, he is the author of two book-length Berkeley monographs, A Public, Private War, and Asian Cybersecurity Futures. He is a graduate of Middlebury College and The Fletcher School of Law and Diplomacy. You can follow him on Twitter at @jonathanreiber
Ben Opel is a Director for Customer Success at AttackIQ, where he advises customers on cybersecurity capabilities and operations, and also serves as a Purple Team instructor at AttackIQ Academy. A former officer in the U.S. Marine Corps, he led, trained, and integrated Marines in defensive cyberspace operations in support of U.S. national security objectives. He is a graduate of the U.S. Naval Academy.
Guests: Adam Isles, Principal, Chertoff Group; Kurt Alaybeyoglu, Senior Associate, Chertoff Group
Less fear, uncertainty, and doubt. How can you optimize your cybersecurity investments to achieve maximum effectiveness? Listen to two of the world’s leading practitioners of cybersecurity and hear about their experiences managing major incidents from the top of DHS and operating in the U.S. Air Force’s cyber warfare wing on episode two of the AttackIQ Think Bad, Do Good podcast.
Welcome to the first episode of AttackIQ's Think Bad, Do Good. In this episode we discuss APT29, threat informed defense, and how to take on a "purple" team approach. With Jose Barajas, Technical Director at AttackIQ, Ben Opel, AttackIQ Academy Purple Team Instructor, and Jonathan Reiber, Senior Director for Cybersecurity Strategy and Policy at AttackIQ.
*Note: this is an imperfect pilot episode for the series, and we'll sort out our audio and video recording methods for the next episode.
What do an Emmy-winning Simpsons writer and TED Talk speaker have to do with the practice of cybersecurity? They may not be certified in Purple Teaming, but they've both had to deal with pressure-cooker environments, challenge perceptions, and deliver innovative solutions time after time. Join this fun and witty session with Carolyn Omine and Toby Shapshak to learn the answers to questions like: Where does real innovation come from? How do you foster creativity in your team? What's it like to write for the Simpons Dog, Santa's Little Helper? You'll leave with a smile on your face and inspiration to challenge the status quo!
Speakers: Carolyn Omine - The Simpsons Toby Shapshak - Stuff
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/
For years in cybersecurity, security teams lacked clarity about adversary tactics, techniques, and procedures and as a result, defenders stumbled in the dark as they tried in vain to defend their data. The result resembled swiss cheese: everyone from the financial sector to the U.S. military to healthcare companies were pummeled by cybercriminals and nation-states alike. In 2015, this changed with the publication of the MITRE ATT&CK framework. ATT&CK is a periodic table of adversary behaviors and threat intelligence; it gives defenders all over the world a single repository to drive-up security effectiveness by focusing on known threats. Now the ATT&CK team is training the world on how to make the framework operational. In this session, please join Chriss Knisley, General Manager of MITRE ATT&CK Defender™(MAD), and Steve Luke, Director of Content for MITRE ATT&CK Defender, as they talk about the evolution of MITRE ATT&CK and MITRE ATT&CK Defender's – “MAD” – certification. Produced by MITRE’s own ATT&CK experts, MAD certified defenders learn directly from the masters to apply ATT&CK across disciplines for threat-informed defense operations.
Speakers: Chriss Knisley - MITRE ATT&CK Defender Steve Luke - MITRE ATT&CK Defender Jonathan Reiber - AttackIQ
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/
As medical devices become more digitally interconnected and interoperable, they can improve the care patients receive and create efficiencies in the health care system. However, medical devices, like computer systems, can be vulnerable to security breaches, potentially impacting the safety and effectiveness of the device. What is the role of the US FDA in cybersecurity? Hear from one of the US FDA's leading experts, Dr. Suzanne Schwartz, Director, Office of Strategic Partnerships & Technology Innovation, Center for Devices & Radiological Health. She'll share how the US FDA is working to protect public health by fostering collaboration, preparing for cyber intrusions, reducing medical device vulnerabilities, mitigating potential impacts on patients, and enabling timely restoration of devices and systems.
Speakers: Suzanne Schwartz - FDA Carl Wright - AttackIQ
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/
FIN6, a financially-motivated cybercrime group possibly of Russian origin, has been linked to attacks against point-of-sale systems in retail and hospitality sectors since at least 2015. The group is known to have used FrameworkPOS and GratefulPOS malware, deployed Ryuk and LockerGaga ransomware, and also linked to various Magecart campaigns. Learn how to use MITRE ATT&CK techniques with the FIN6 emulation plan to know what will happen if your organization gets hit by this cybercrime group. Join AttackIQ cyber experts Jose Barajas and Mark Bagley to learn how your team can leverage breach and attack simulation to test the group’s activities in production, at scale. They will also touch on other groups, such as APT29, to understand your risks by looking at the results of what happened after running an emulation plan.
Speakers: Mark Bagley - AttackIQ Jose Barajas - AttackIQ
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/
Since the publication of MITRE ATT&CK, MITRE Engenuity has been at the global forefront in fostering the practice of “threat-informed defense.” Since the founding of MITRE Engenuity’s Center for Threat-Informed Defense two years ago, the Center has brought industry leaders together to learn from each other and publish transformative research, including a comprehensive adversary emulation library for the public, mapping the MITRE ATT&CK framework to the NIST 800-53 family of security controls, and the new “Sightings” database that invites contributions from across the cybersecurity community. Join Richard Struse, Center Director, Jon Baker, Center Director of Research and Development, and Jonathan Reiber, AttackIQ Senior Director for Cybersecurity Strategy and Policy, for a conversation about the evolution of ATT&CK, how to put it to use, and the future of threat-informed defense research and operations.
Speakers: Jonathan Baker - MITRE Engenuity Richard Struse - MITRE Engenuity Jonathan Reiber - AttackIQ
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/
How do you operationalize the concept of “cyber excellence” in your organization and move your program from being reactive to proactive and preventative? It takes an evolution of your technology stack, organizational structure, and processes. Join Marlys Rodgers, CISO of CSAA Insurance Group, with leaders in her cybersecurity team to learn how to move from a defensive to offensive cybersecurity program. They’ll share best practices for validating controls, leveraging the MITRE ATT&CK framework, assessing control maturity, discovering potential gaps, and working with the audit team. You will walk away with actionable steps and insights to begin your journey to a threat informed defense.
Speakers: Brian Kindred - CSAA Insurance Group Michael McCurrey - CSAA Insurance Group Randa Moore - CSAA Insurance Group Marlys Rodgers - CSAA Insurance Group
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/
Since the field of cybersecurity began, teams have struggled to measure a clear return on cyberdefense investment. After years of focus on advanced technology procurement and workforce development, today there’s a shift occurring in cybersecurity practice away from “speeds and feeds” and towards outcomes-based management and security program effectiveness. In this session Allan Alford, CISO/CTO of TrustMAPP and host of the Cyber Ranch podcast, will lead a discussion with Gabe Lawrence, GM of Cybsercurity Protection at Toyota, and Ben Opel, a former U.S. Marine who led the development of the Marine Corps cyberspace operational doctrine, on what it takes to successfully build and adopt a threat-informed defense strategy through purple team operations and automated testing.
Speakers: Allan Alford - TrustMAPP Gabe Lawerence - Toyota Ben Opel - AttackIQ
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/
Against a backdrop of increasing cybersecurity risk — particularly ransomware and concurrent data exfiltration — CISOs in healthcare and public health (HPH) organizations are investing hundreds of billions of dollars in cybersecurity. Much of this is going to security controls that protect critical clinical and administrative systems, data, and networks. Learn how Ron Mehring, the CISO of Texas Health Resources, is uniting risk and threat management as part of his strategy to look at security through the lens of adaptive risk. You'll learn how to automate and more cleanly orchestrate processes with security stack technologies, as well as how tto manage end-to-end risk across disparate environments, all the way from consumer side.
Speaker Ron Mehring - Texas Health Resources
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/
The definition of resilient is “being able to withstand or recover quickly from difficult conditions.” In cybersecurity, resilience is “the ability to prepare, prevent, respond and successfully recover to the intended secure state during a crisis or after a security breach.” Learn how Clayton Chandler, the CISO of Credit Suisse, thinks about operational resilience and strategies to assess gaps and drive enhancements to the overall security posture of the bank. He’ll be interviewed by Neal Bridges, a former NSA hacker, who is a cybersecurity influencer, streamer, and expert. In addition to operational resiliency, they will also discuss the role of breach and attack simulation as a foundational technology to help cybersecurity teams think differently and be more agile in handling new risks and attackers.
Speakers Clayton Chandler - Credit Suisse Neal Bridges - INE Training
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/
Faced with mounting attacks, tighter regulations, and greater budget scrutiny, cybersecurity teams have increasingly found themselves in strategic boardroom conversations. Yet, despite years of "blank check' investments in security controls, adversaries keep coming. What questions should business leaders to be asking about emerging cybersecurity trends? Which technologies, processes, and strategies will best protect the organization? How can you help guide investments that are based on optimizing business outcomes, not technology for technology's sake? AttackIQ CEO Brett Galloway will share his vision for 2021 and beyond in his opening keynote.
Speaker: Brett Galloway - AttackIQ
AttackIQ Purple Hats: https://www.purplehats.org/ AttackIQ Academy: https://academy.attackiq.com/ AttackIQ: https://attackiq.com/