Cymulate Cybersecurity Podcast: Recent Episodes

Cymulate

Cymulate Cybersecurity Podcast. Covering cybersecurity best practices.

View Details

Most cybersecurity professionals still do not understand the fundamentals of securing programming and application cybersecurity. Beyond principals like shift left are well understood there are all sorts of other key things that these professionals can discuss with programmers to make enterprises considerably more secure. Join Dave Klein, Director and Cyber Evangelist for Cymulate, and Tanya Janca of SheHacksPurple as they discuss:

  • Programming hygiene and best practices
  • Cloud-specific caveats
  • Playbook must-dos
  • What shift-left really means
  • Incorporation of threat exposure management

Tanya Janca is the author of Alice and Bob Learn Application Security. She is also the founder and CEO of We Hack Purple, an online learning academy, community, and weekly podcast that revolves around teaching everyone to create secure software. Tanya has been coding and working in IT for over twenty years, won numerous awards, and has been everywhere from startups to public service to tech giants (Microsoft, Adobe, & Nokia). She has worn many hats; startup founder, pen-tester, CISO, AppSec Engineer, and software developer. She is an award-winning public speaker, active blogger & streamer and has delivered hundreds of talks and training on 6 continents. She values diversity, inclusion, and kindness, which shines through in her countless initiatives.

View Details

In the past, on this broadcast, we have gone in-depth learning how to understand the best ways to test, validate and optimize first-party and third-party security controls in everything from email and host to email and critical enterprise systems. In this broadcast, we focus on cloud security essentials. Cloud is similar yet very different from past environments.

Come join Dave Klein and his guest Yoni Leitersdorf to learn:

•The challenges we face in rapidly provisioned cloud environments.

•How cloud security is different.

•The key fundamentals required to protect cloud environments.

•Why continuous testing is essential 

Yoni Leitersdorf, is the US CTO for Cymulate. Coding since age six, his enthusiasm for automation and security has strongly influenced his career. Before Cymulate, he served as CEO and founder of the company Indeni, was in product management at Check Point, and was part of a world-renowned IDF 8200 unit, where he managed a team of programmers and won the esteemed Israeli Security Prize given by the president. 

View Details

Asia has never experienced more business-impacting cybersecurity threats than the current time. The Cyber-Essentials Mark Certification for Enterprises being established by Singapore goes a long way to shore up cybersecurity, reduce risk and ensure business continuity and resilience. Join Dave Klein and Dr. Magda Chelly as they discuss.

Come join the discussion to learn:
•Where to start?
•How to implement it?
•What are the benefits?
•Importance of making it a continuous journey?
•Why is testing critical to success?

About Magda Chelly:
Dr. Magda Chelly is an award-winning global cybersecurity leader. IFSEC Global has listed her as one of the top 20 most influential cybersecurity personalities globally, in 2017 and 2021. After years of experience as an Information Security Officer in several multinational organizations, she is a co-founder of a cybersecurity start-up.

View Details

With threats changing constantly, new and existing vulnerabilities stacking up, and dynamic nature of enterprises adding new misconfigurations and security gaps daily we are at a crossroads. Dr. Chase Cunningham and Dave Klein Discuss. 

Come join the broadcast to learn:

  • Why is it important to truly understand both technical and business impact when looking at outcomes?
  • What is the relation to segmentation, access and privileges, and cloud controls?
  • What is the importance of both continuous security validation and breach feasibility testing?
  • How does this help minimize threat exposure and validate Zero Trust?

Dr. Chase Cunningham is a retired Navy Chief Cryptologist with more than 20 years of experience in Cyber Forensic and Analytic Operations and forensic analysis. He gained his operations experience by being "on pos" doing cyber forensics, analytics, and offensive and defensive cyber operations while functioning in highly technical and operationally demanding work centers within the NSA, CIA, FBI, and other government agencies. As a Principal Analyst at Forrester, Dr. Cunningham spearheaded their Zero Trust initiatives. He currently works as Ericom’s Chief Strategy Officer.

View Details

With business continuity taking center stage in cybersecurity effectiveness, being proactive is a must. Join Chuck Brooks and Dave Klein as they discuss.

Come listen to learn:

  • What are business continuity and resilience?
  • What are the critical factors to run a successful and proactive cybersecurity program?
  • What is the role of good incident response plans?
  • What kind of collaboration is required from technical operations and C-Suite?
  • How do you truly build resilience?
  • What is the role of continuous simulation testing?

View Details

Take your cyber resilience from superficial to thorough. Have your testing merely protect against the latest IoCs is helpful, but with just a little effort you can easily inoculate your enterprise for a longer duration and against threats in a deeper fashion. Join Dave Klein, Director, Cyber Evangelist and his guest Dan Lisichkin, Threat Hunter and Threat Intelligence Researcher as they discuss best practices to easily incorporate better threat testing and purple teaming and walk-through testing against Threat Actor UNC2596 and the Cuba Ransomware.

Join this broadcast to learn how to:

  • More effectively do purple teaming
  • Utilize Pyramid of Pain to understand what kind of changes you can truly disrupt attackers
  • Easily test and optimize your enterprises defenses against threats in a deeper fashion with broader impact and duration.

Dan Lisichkin is a Threat Hunter and Threat Intelligence Researcher for Cymulate.

View Details

Email continues to be the number one attack vector used by hackers to gain footholds during breaches.

Shoring up defenses takes some good understanding of both email security gateways, server and client side defenses, reconnaissance and end user training. 

  • Shore up email external attack surface from discovering poor server side hygiene and finding stolen enterprise accounts.
  • Email server side hardening, upkeep and cloud migration best practices
  • Email security gateway optimization
  • EDR and Operating System side optimization
  • Phishing awareness campaigns to educate enterprise users against threats

George Nazarey is a Youngstown State University Graduate with over 15 years of cybersecurity experience including ten years of US federal customer work. He has worked on some of the largest email security deployments in the world. Today he is a Crowdstrike Regional Sales Engineer.

View Details

he number of vulnerabilities is 600% larger than was discovered merely a decade prior. 

Time to exploit is often hours.

Join the conversation to learn how Attack Based Vulnerability Assessment can be used to:

  1. Effectively find existing vulnerabilities within your environment.

  2. Test your environment to measure your own enterprises’ risk profile.

  3. Find mitigating first and third party controls to quickly and effectively reduce this risk. 

About Magda Chelly:

Dr. Magda Chelly is an award-winning global cybersecurity leader. IFSEC Global has listed her as one of one of the top 20 most influential cybersecurity personalities globally, in 2017 and 2021. After years of experience as Information Security Officer in several multinational organizations, she is a co-founder of a cybersecurity start-up.

View Details

In looking at the top attacks the last few years, attackers take full advantage of users with excessive privileges and those who run without multi-factor authentication. To make matters worse, cyber insurance is beginning to come with waivers for those who work from home or cannot validate a device is truly authenticated correctly to the correct user. Come join Cymulate’s Dave Klein, Director, Cyber Evangelist and TypingDNA’s Tim Savage, VP as they discuss.

Join to learn about:
•Importance of Least Privileges and MFA.
•Importance of truly identifying/authenticating users behind a login.
•Critical techniques to protect executive, high target and administrative accounts.
•Insurance and compliance standards driving adoption.
•Offensive testing’s role in identifying gaps.

Tim Savage, VP for TypingDNA is a serial cybersecurity entrepreneur and expert. Currently, endpoint authentication & MFA has his full current attention. He and his team are evangelizing the doctrine of authenticating the user to a higher level of security than just a password.  Ensuring that the least privileges provided are not shared with anyone else. Either foolishly or maliciously. Raising the bar of compliance and overall cybersecurity.

View Details

It used to be when we spoke of hackers living off the land, we were simply discussing how attackers would stealing victim’s compute and storage to assist them in their attack. Today, living off the land includes rapidly taking over critical enterprise infrastructure and applications leading to very difficult to remediate losses. Stopping this has become paramount. Come join me and IGNITE Cyber’s Chuck Sirois as they discuss.

Join to learn about:

  • How hackers infiltrate enterprise critical assets like Active Directory, Exchange, DNS, and other services to expand and accelerate attacks.
  • How offensive testing techniques can be used to find where your enterprise is susceptible and provide valuable insight in remediation.

Top takeaways to harden these critical services.

Chuck Sirois is a veteran cybersecurity vCISO, expert, writer, and speaker. Currently on the board of startup IGNITE Cyber.

View Details

As a business executive, understanding how cyber risks can lead to financial losses and more importantly how to reduce risk to an acceptable level is critical. 

Today we are going to discuss:

·       How Cybersecurity risk is real risk?

·       How everyone is a target?

·       How business driving risk reduction is key for success of cybersecurity programs.

·       As an executive to know what questions to ask, what to measure and how to mitigate these risks.

·       A non-technical understanding of how Extended Security Posture Management with offensive testing is used to 1. visualize, explain, and reduce risk. 2. Ensures optimized value for your cybersecurity spend.

Dr. Magda Chelly is an award-winning global cybersecurity leader. IFSEC Global has listed her as one of the top 20 most influential cybersecurity personalities globally. 

After years of experience as Information Security Officer in several multinational organizations, she co-founded a cybersecurity start-up. 

View Details

Never have applications, most web based, been more critical for success of every business. Yet when looking at enterprises' ability to shore up security here, it has become the weakest link.

In Verizon’s 2021 Data Breach Investigations Report, Web Applications were accounted for 89% of credential abuse and over 56% of asset compromises.

Today we will be learning:

· Ways to secure applications and to build application security programs.

· Bringing in offensive testing, extended security posture management and CI/CD pipeline routines to shore up security within applications.

· How to develop your people into an effective team and break down silos between security, development, and business.

Tanya Janca: also known as @SheHacksPurple

Best-selling author of ‘Alice and Bob Learn Application Security.’

Founder of We Hack Purple, an online learning academy, community and podcast that revolves around teaching everyone to create secure software.

Tanya has been coding and working in IT for over twenty years, won countless awards, and has been everywhere from startups to public service to tech giants (Microsoft, Adobe, & Nokia).

Startup founder, Pen Tester, CISO, AppSec Engineer, and software developer.

She is an award-winning public speaker, active blogger & streamer and has delivered hundreds of talks and trainings on 6 continents. She values diversity, inclusion, and kindness, which shines through in her countless initiatives.

View Details

Zero Trust has become the framework of choice to reduce risk and ensure optimized cybersecurity. Join Dave Klein, Director and Cyber Evangelist for Cymulate and his guest Chuck Brooks as they discuss. 

Join this talk to learn: 

  • How to make Zero Trust truly actionable and continuous.
  • How to optimize risk reduction and outcomes.
  • The role of offensive testing and purple teaming in Zero Trust.

View Details

Podcast 1 

Cymulate Cybersecurity Video/Podcast 
Essential Purple Teaming Management 
Wednesday, February 9th, 2022 
Guest: Tracy Z. Maleeff  

Target audience: Leadership and Technical 

To mitigate and reduce cybersecurity risks it is essential that everyone within an enterprise becomes involved. Purple teaming has become the natural evolution of goal-oriented cybersecurity risk management. Come join our podcast to learn: 

  • Problems with legacy methods
  • Benefits of Purple Teaming and Offensive Testing
  • Explaining the importance to management in terms they understand.
  • How to maximize success and inclusion of other teams?
  • What is scenario based purple teaming?
  • How to come up with test scenarios?
  • How to look at outcomes, make changes and test again?