The Virtual CISO Moment: Recent Episodes

Greg Schaffer

The Virtual CISO Moment with Greg Schaffer dives into the stories of information security, information technology, and risk management pros; what drives them and what makes them successful while helping small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no catchy music, no complex graphics, and no script - just honest discussion of SMB information security risk issues. Quick strike and wrap up audio-only episodes drop Mondays and Fridays; Throwback Thursday episodes are repeats. @VirtualCISO1 on Twitter. #cybersecurity #infosec #security Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Matthew Quammen's journey in cyber security dates to dial-up internet and AOL accounts. He has seen first hand the disastrous effects of Data Loss. His father was a blue-collar business owner who lost a significant portion of the value of his life's work due to a Data Loss Event. He is passionate about working with the right partners to help companies from falling victim to the same outcomes.

View Details

Since the very first days of the Internet, Warner Moore has been part of tech. His love for technology and for building things, for easily and effectively sharing information, and for communicating with people across the world are why he is dedicated to helping companies improve their tech. As the founder of Gamma Force, a large part of what he does is provide innovative strategies for augmenting tech and cybersecurity capabilities. Additionally, working with the tech community in Columbus, OH led him to create Tech Community Coalition (TCC), a non-profit organization whose mission is to enable the tech startup community through education and mentorship.

View Details

Mark Burnette is the Chief Growth officer for LBMC and the author of Risky Business: Cybersecurity Leadership the Right Way. Driving growth (increased revenue) has been an important part of his career. During his 30+ years in the professional world, he has helped start and build service lines for three major professional service firms, led a boutique consulting firm as President, and co-founded, built, and sold a software company, among other career experiences. W discuss lie after the CISO, how we all are sales persons in some way, his book, and much more. Viewers and listeners can obtain a free copy of his book by visiting https://www.lbmc.com/blog/risky-business-cybersecurity/

View Details

Shane Simmons is the Senior Director IT Security, Global Lending Services LLC. As a seasoned IT executive with over a decade of experience, he specializes in driving cybersecurity and information technology strategies that transform organizations. His expertise as both a Chief Information Officer (CIO) and Chief Information Security Officer (CISO) uniquely positions him to lead comprehensive digital transformation efforts while ensuring robust cybersecurity frameworks that protect critical assets and drive business outcomes.

View Details

Pius Emmanuel Papka is a Malware Engineer (Internship) with the Army War College, Abuja, Federal Capital Territory, Nigeria. We discuss his reasons for entering the cybersecurity field, serving his country, and his desired career growth path. He also provided some tips to me about Football (Soccer to Americans). Finally, he provides the answer to the question: if Americans receive scam emails from a Nigerian prince promising much money, do Nigerians receive the same from an American prince?

View Details

Matthew Harvey an information security professional with both deep and wide experience in the field of computers and networking. He has been in the computer business full-time since 1997, and has done a little bit of everything. He has expertise in everything from intrusion detection and malware analysis to Cisco LAN and WAN internetworking configuration, as well as database and web development, design, configuration, and troubleshooting.

View Details

Praj Prayag-Debis the founder of Cyberpink Advisors, offering information security consulting services to small and midsized businesses. She is an influential tech-savvy Cybersecurity and Technology risk executive and a strategic leader with a demonstrated track record of building successful Cybersecurity and Governance, Risk, and Compliance (GRC) programs from the ground up. She has 15+ years of experience in diverse and complex environments, including Big4, Top tier financial services (Bank of America, Morgan Stanley, Macquarie Bank) and Fortune 50 (Comcast).

View Details

With more than 25 years of IT and Security experience, it is safe to say that information security is Matthew Webster's passion. Whether it is giving presentations to various members of the IT and Security community, providing direction to various organizations, or formerly leading as a CISO, helping companies transform their practice one company at a time is what he loves doing. His extensive experience building an array of programs includes all the major disciplines of information security. This has helped him to build holistic programs and provide clients with a fast keen insights to help them facilitate their journey to better security programs.

View Details

Mike Burns is the Security Manager at Amberjack Global. He has been working within IT and security since the mid 90's. During his time he have been fortunate to work for both really niche small local firms no one will know, to working with the biggest names in Banking, Aero, Manufacturing and Defence, and managed operational security for one of UK HMG's largest outsourced services. Join us as we cover security from the perspectives of both sides of the pond!

View Details

Jeffrey Wheatman is SVP, Cyber Risk Strategist for Black Kite, an innovative company redefining third-party risk management around the globe. Previously, he was a Vice President in Gartner’s Cybersecurity and Risk Management Group, where he honed his understanding of cybersecurity through detailed research and analysis while building relationships with strategic business leaders in the field. He has also served as a DEF CON Speaker Goon for many years, beginning in 2007.

View Details

Mishaal Khan is vCISO and Cybersecurity Practice Lead at Mindsight and is the co-author of The Phantom CISO. With a deep understanding of the bits & bytes to the business processes, he uses his experience and skillset as an Ethical Hacker, OSINT enthusiast and Social Engineer to help customers secure their organization and solve real-world challenges. He's spoke at premier conferences like Black Hat, DEF CON, Wild West Hacking Fest, TEDx, and SANS.

View Details

Anthony Scarola is not only our first repeat guest, he is the author of FITLSDOG - The Financial Information Technology Leader's Strategy Development and Operations Guide. This is an excellent, thorough resource for IT and information security pros, and not only in the financial sector. Find out why FITLSDOG should be a part of your library!

View Details

Nick Lorizio is Co-Founder and CEO of Astute, a cutting-edge online platform that connects skilled IT professionals with businesses and individuals in need of IT support and cybersecurity solutions. Embarking from Boston's historic vibrancy, refined by the intellectual rigor of New York, and embracing the ethos of freedom in New Hampshire, his journey symbolizes a relentless pursuit of excellence and innovation. With a mantra inspired by the resilience of the past and an eye towards the limitless potential of the future, he invites collaboration with visionaries and pioneers eager to explore the frontiers of technology and innovation.

View Details

Brent Gallo is the founder of Hire a Cyber Pro. Hire A Cyber Pro specializes in cybersecurity consulting services, helping organizations large and small by providing cybersecurity professional services such cybersecurity risk and compliance assessments and security solutions. Hire A Cyber Pro also conducts penetration tests, develops cybersecurity programs and policies, and provides managed cybersecurity and IT and cybersecurity hiring and recruiting services.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Jason Firch is the CEO and co-founder at PurpleSec. PurpleSec's approach to the way cyber security services are delivered is different. Unlike other companies, PupleSec automate and combine the vulnerability management and penetration testing processes into an enterprise solution that is cost-efficient frees time from repetitive tasks, and enables your team to do more focused work on high-caliber tasks. But he didn't start out in cybersecurity. Learn how a chance encounter with a book led to a different career direction.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Dr. Mike Brass is the Vice President Information Security, Data Privacy and Business Systems (CISO) at Ubisense. He is also the creator of the Udemy course Governance, Risk, and Compliance (GRC) (see https://www.udemy.com/course/governance-risk-and-compliance-grc/). He is the author of the upcoming book Governance, Risk and Compliance: Demystifying the Risk and Data Privacy Landscape, a book-length version of the Udemy GRC-Data Privacy course. In addition to GRC we cover a lot of topics, including elements that archaeology and information security share.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

With over 25 years of experience in IT and cybersecurity, Chuck Anderson is a passionate and versatile consultant who strives to deliver innovative and effective solutions for my clients. His core competencies include process improvement, technology research, software development, and database management. He has a bachelor's degree in cybersecurity and information assurance, and a MBA at Western Governors University. His mission is to help organizations enhance their security posture, mitigate risks, and optimize their performance.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Peter H. Gregory is a security leader, former Virtual CISO, and long-time strategic security advisor to CISO's, CSO's, CIO's, boardrooms, and other security, risk, and business executives. He is a security and risk senior director with experience in SaaS, retail, telecommunications, consulting, advertising, non-profit, legalized gaming, manufacturing, healthcare, and local government.

Additionally, he is a published author of over fifty books on information security, with editions in four languages. Interviews and articles in magazines and newspapers.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Sam Glynn is the founder of Code In Motion, an independent consultancy firm that provides IT security advice and independent assurance to help SMEs prove they are taking reasonable steps to manage IT and cyber security risk. He ensures my clients are on the fast-track to align or certify to ISO27001.

He is also the founder of MySecurityGuide.com, an online service to help self-employed professionals and small teams who do not want to be cyber experts, or cyber victims.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Andrew Wilder helps businesses, boards, and startups understand and address Cybersecurity Risk. He has broad range of Cybersecurity, Risk Management, Audit, Merger & Acquisition, Organizational Design, and International experience cultivated over more than two decades across several industries. He is a retained Chief Security Officer, an adjunct professor in cybersecurity, and is an advisor for many cybersecurity startups.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Challenges and Opportunities in Small and Midsized Business Information Security - a special episode, recorded at BSides Nashville May 11, 2024.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Darren Ritch has been in the IT Industry for 34 years, with AT&T about 20 and work in the CSO office. He also volunteers as a CISO for the past several years for a non profit and have helped them with HIPAA compliance, and recently earned the Certified Business Coach designation from Mindvalley.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Curt Vincent is cyber security maverick and entrepreneur. Founder and leader of the 400 person Morgan Stanley Cyber Security Division for 15 years, Senior Vice President and COO for both the Global Networking and Applications Operations Command Center at Bank of America, VP of a Dev/Ops team at Goldman Sachs and a founder of 5 startup companies. Curt is also a retired U.S. Army Lieutenant Colonel where he played cyber cat and mouse with nation states as the Operations Officer of the Army's Global Network Operations and Security Center.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Frank Platt joined me on The Virtual CISO Moment in 2022. I share that episode as a remembrance and tribute to the great person he was. We will miss you, Frank.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Chris Kimpland is a cybersecurity leader with a passion for helping organizations advance their security posture and succeed in today's threat landscape. He has extensive Governance Risk and Compliance experience across multiple frameworks, standards, and regulations such as DFARS, HIPAA, PCI, and NCUA. In this episode we cover a variety of topics including information security risk management and a great upcoming initiative to combat online predators.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

John Christly is a cybersecurity evangelist, military veteran, former CIO/CISO/CTO, author, and instructor. Currently the Director of IT Security at Summit 7, he is a passionate IT and cybersecurity professional with decades of experience. He has served in key roles such as CIO, CISO, and CTO, helping organizations of all sizes to build resilient IT systems, fortify their security systems, and grow security related practice offerings. He also owned and operated a successful Florida based MSP/MSSP for over 13 years.

Additionally, he is the author of the new book The Basics of Cybersecurity (available at https://www.amazon.com/Basics-Cybersecurity-John-Christly-ebook/dp/B0CZXQQTGR/) and the creator and instructor of the Udemy course How to become a CISO (see https://www.udemy.com/course/cybersecurity-leadership-how-to-become-a-ciso/).

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Joshua Copeland is a seasoned cybersecurity professional and educator with 25 years of experience, with a focus on holistic cloud and on-prem security approaches and specific expertise in building and operating security stacks, SOC operations, and cybersecurity governance, risk, and compliance (GRC) processes. Additionally, he served 20 years in the US Air Force. Also, since 2021 he has been the purveyor of #unpopularopinions as the "Unpopular Opinion Guy" SM or "UOG" on LinkedIn, covering topics like hiring, mentoring, and cybersecurity.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Troy Bowman is an Information Security Analyst for Costco Wholesale, specializing in application security. He is also a Navy veteran and has some excellent advice on those looking to enter cyber from military service. He also relays one of the most unique way I have heard to decompress with stress!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Evan Francen is the CEO of FRSecure and SecurityStudio. His mantra of focusing on the mission is inspiring, and his mission is to, simply put, fix problems. He is the founder of the CISSP Mentor Program and the Certified vCISO (CvCISO) training. Additionally, he authored The Information Security Industry is Broken (June 2018). The industry may be broken, but we can fix it; that's just one of the topics we discuss.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Darius Davis is a cybersecurity professional with over 15 years of information technology experience. He's worked in a wide-range of areas from tech support, system administration, to networking and security engineering. In this episode, he provides four excellent points of wisdom for those looking to enter and advance in their cybersecurity career. A hint: you have to crawl before you walk. He also is a great example of serving the infosec community, holding board positions in not one but two local professional security organization chapters.
Darius can be reached on LinkedIn at https://lnkd.in/emg3VYhf and X at @cyberninjapod.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Richea Perry is a seasoned GRC and Cybersecurity Professional with an unwavering passion for securing today's digital environments. Throughout his journey, he has been at the forefront of shaping resilient network infrastructures, robust Governance, Risk Management, and Compliance strategies that are not just benchmarks, but catalysts for business growth. We discuss AI risks for SMBs, GRC (of course), and his career path from IT (networking) to cybersecurity. He is also the host of the CyberJA podcast - and I finally learned what the JA means! Hint - I definitely overthought it.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Stanley Charles is the Founder of the Charles Technology Group and Senior Manager, Information Security and Compliance at Pixel United. I realized early in the discussion that we have similar career paths, from aircraft maintenance in the United States Air Force, to an early career in networking as a network engineer, to eventually land in the information security and cybersecurity space. We cover a lot of ground in this episode, including advising SMBs on how to get the most out of their relationship with their MSP/MSSP.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Nick Mullen is the Founder and Principal Consultant at Sanguine Security Solutions and is also a Cybersecurity Program Mentor at Kennesaw State University. He is a technology leader dedicated to enabling teams and facilitating achievement, and his expertise is in program/project management, information security, IT governance, and compliance in the financial services sector. In this special midweek episode, we talk security plus Star Trek - a great combination!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Robert Hill is a visionary leader with over three decades of expertise in the cybersecurity industry. As the founder and CEO of Cyturus Technologies, Inc, a leading Compliance and Risk Management solution provider, Robert has played an instrumental role in shaping the landscape of cybersecurity and helping organizations, navigate the complex challenges of a digital era.

Prior to founding Cyturus, Robert held positions within various consulting firms, where he honed his skills by collaborating closely with Fortune 500 companies to develop cybersecurity strategies. His hands-on experience in identifying deficiencies, mitigating risks, and implementing robust compliance frameworks has proven instrumental in fostering a culture of security awareness among clients.We cover a wide range of topics in this episode, including the limitations of traditional once-a-year assessments in organizations, where senior leadership makes decisions based on outdated data.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Nick Oles is an author, cybersecurity professional, and veteran. We cover many topics including his book How to Catch a Phish (available at https://lnkd.in/e35B8YHz) and career paths, including this preview where he reviews his beginnings in IT in college. I often say that working at a university is a great place to get foundational IT experience, and he is a great example.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Jonathan Mandell calls Chicago home and has worked across various tech roles, from Enterprise AE to Business Development. He was part of the founding team of Tiz, which later became Provi, a SaaS company reshaping the alcohol industry. He has worked in third party risk management (TPRM) for the past 5 years, and recently founded Teepee, a cybersecurity firm delivering solutions in the area of TPRM. Join us as we discuss the challenges and benefits for SMBs in ensuring effective third party risk management.

For more information, check out Teepee at https://teepeesafe.com/.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Matthew Meadows is an experienced Information Technology Security Specialist with a demonstrated history of working in the medical practice industry, and is currently an Information Security Engineer with Premier, Inc. Join us as he discusses a new approach to information security training for healthcare professionals. Learn more about the CyberSecurity Center of Excellence's Healthcare Track at https://cvcc.edu/CSCE/CyberSecurity-in-Healthcare.cfm.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Chris Foulon, Founder and Principal Cybersecurity Strategist of CPF-Coaching, is a seasoned vCISO, IT, and Security leader with over 17 years of progressive experience. He is also the co-host Breaking into Cybersecurity with Renee Smalls where they interviewed individuals who have transitioned into the cybersecurity industry within the past 5 years.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Daniel Moses is SDR for Cyble, which provides capabilities for customers to manage cyber risks with AI powered actionable threat intelligence, and are specialists in gathering intelligence across the Deepweb, Darkweb and the Surface Web. Join us as he discusses his journey, including that cybersecurity has taught him that you need to be able to pivot and keep pressing forward.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Bruno Aburto is the cofounder of and vCISO at Aburto Kinney Consulting LLC. He is responsible for providing comprehensive cybersecurity and IT support to executives and their organizations, working =tirelessly to safeguard all digital assets and sensitive information, ensuring that clients are protected against potential threats and vulnerabilities. He provides augmented cyber expertise that enables clients to identify and mitigate risks while supporting business operations and enhancing overall security posture.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Jay is a 17 year veteran of Information Technology who has been helping organizations of different industry verticals all over the United States. He also has 12 years experience in sales and recently stepped into leadership as well. In his spare time, Jay is extremely passionate about health, fitness, and nutrition.

As a bonus, see what I recommend for office fitness equipment to get in those workouts when going to a gym isn't feasible!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Brian Smith is a 20-year veteran and entrepreneur in multimedia, cybersecurity, and technologies alike. He is Co-Founder and CTO at Spyderbat, an automated runtime security platform. Spyderbat stops attacks and automates root cause analysis on cloud-native environments by proactively recording Cloud system and container activities into a living 'Google Map'. With Spyderbat, DevOps and Platform teams stop attacks, prevent misconfigurations, and get a full understanding of what happened, how to clean up, and how to prevent it in the future.

In 2000, together with Marc Willebeek-LeMair, Brian founded TippingPoint Technologies (acquired by 3Com), and in 2009 he founded Click Security (acquired by Alert Logic). Prior to TippingPoint, Brian received his Ph.D. in Computer Science from the University of California at Berkeley in 1994 and was the Xerox Professor of Computer Science at Cornell University until 1998. He now holds 13 patents and is a fellow of the Alfred P. Sloan Foundation.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Mike Pedrick is the VP, Cybersecurity Consulting for Nuspire. He believes that all businesses are at risk - hackers, crackers, nation states and bad actors - but small- and medium-sized businesses have to defend themselves against the same threats as the major corporations with fewer resources at their disposal. Who helps small business leaders navigate the murky waters of risk management, governance, compliance, privacy, and guerilla marketing campaigns? He does. Join us for an engaging conversation focused on SMB information security risk.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Ty Ward is a published author (https://a.co/d/ipWJj2G) and seasoned cybersecurity professional with over 15 years of experience in the field. Ty is a former U.S. Air Force and also a former U.S. Intelligence Agency member. He has responded to hundreds of real-world data breaches and cyber-attacks, performed hundreds of penetration tests against organizations, and has served as a chief information security officer for a multitude of companies both nationally and internationally. He holds multiple university degrees and a long list of professional certifications, including the CISSP, GCIH, and others. Ty is also the Founder of the NightLight Foundation (https://www.nightlight-foundation.org/), an anti-child exploitation and trafficking not-for-profit organization.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

With 25 years of experience working in the networking, telecommunications, and information security space, Scott McCrady is currently serving as the CEO of SolCyber Managed Security Services. Scott has worked with large companies and start-ups, among them IBM and EDS, where he held Security Engineer and Team Leader positions (US and London).

Join us in a where we discuss a unique approach to providing MSSP services. I also learned a new term, "talent stacking". Listen or watch to learn what that means!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Sabine VanderLinden is a seasoned executive with a proven track record of creating long-term sustainable impact for growth ventures and corporates. She specializes in designing, industrializing, and democratizing category-driven digital ecosystems that help de-risk corporate venturing for incumbent players. Sabine co-founded Alchemy Crew three years ago, a venture-first R&D lab that accelerates the commercialization of tech ventures by working with global Fortune 500 companies, venture capital funds, private equity funds, universities, and acceleration programs.Join us as we take on startups, insurance, entrepreneurship, taking risks, cybersecurity, and a bunch of other topics!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

James Fair is the Senior VP of Technical Operations at Executech, a leading IT outsourcing company committed to cutting costs for businesses in various industries. With expertise spanning over 35 years in IT, 30 years in Leadership, and a dozen years in the interpersonal workspace, James is a seasoned professional with a deep understanding of business strategy, cybersecurity, information technology (IT), and management.

James's remarkable journey from an entry-level technician to Senior Vice President has equipped him with an extensive knowledge base in all facets of IT. He leverages his passion for IT and cybersecurity, coupled with his dedication to leadership development, to teach and mentor other IT professionals and leaders.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Thomas Ballin, Cofounder of Cytix, is an experienced security expert with leadership, management, and operational experience in cyber security. He has spent the past ten years as a security champion building innovative products, services, and teams to meet the needs of customers. In this episode we discuss SMB pen test challenges, scaling security programs, and Cytix's innovate approach to identifying how to effectively manage a vulnerability discovery program (hint: it's not put in a subnet and mask and click "run").

He is also cohost of the Real Cybertalk podcast, a new podcast premiering January 2, 2024. Check it out!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

We're back with a new season of great conversations on The Virtual CISO Moment, beginning with our first episode of the year coming January 2, 2024. Hope you can join us!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

We end 2023 with a very special guest! Keith Price is the CSO for National Highways. Has worked in tech since 1991, beginning as a Mainframe Operator in the United States Air Force - so of course I had to wear my Air Force cap for this discussion! If you've never come across Keith's LinkedIn posts I'd be surprised, as he is always providing excellent and helpful content. He assists students, military veterans, and professionals wanting a change in their profession in cybersecurity. Most importantly, he loves what he does!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Evgeniy Kharam is the founder of EK Cyber and Media Consulting providing consulting and advisory services in both the cyber and media domains, catering to vendors and MSSPs. He also is the founder of the Cyber Inspiration Podcast and cofounder of the Security Architecture Podcast, where they interview vendors in cybersecurity about their design and architecture. We talk about the need for SMBs to enhance awareness and the struggles for access to talent and other security issues for all businesses. Plus he's working on a book on the importance of soft skills in technical sales, to help communicate more effectively.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Daniel Waters is a cyber and technology strategist, startup advisor, business builder, and cybersecurity subject matter expert. We discuss how some issues affect large and small businesses alike, but startups often have more significant challenges in just trying to stay in business. We also tackle cyber burnout and how change from the leadership level can help.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Paul Valente is the CEO and co-founder of VISO Trust and former CISO of Restoration Hardware, Lending Club and ASAPP.

He holds several industry designations, including Certified Information Systems Security Professional (CISSP), Certified Information Systems Manager (CISM) and ISO 27001 Lead Implementer.

Listen to learn how VISO Trust, leveraging AI, can help with an issue all CISOs and vCISOs deal with - Third Party Risk Management.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Marc Crudgington is the CEO, vCIO/vCISO of CyberFore Systems, has many years at the CISO level, and is a United States Air Force Veteran. He is also the author of two books, including "The Cyber War Is Here, US and Global Infrastructure Under Attack A CISO's Perspective". Join us as he discusses his career path and what led him to author two cybersecurity books.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Transitioning from one career to cyber can be challenging but also brings opportunities. Kyron Joseph is a newly converted Cyber Security Professional with 5+ years of experience in Social Media /Marketing account management, content creation, data protection and client communication and pursuing the GRC path. He's learned a very important aspect of information security that many don't, even after decades in the field, and that puts him ahead of others in the GRC space. Listen to find out what that is.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Esteban Ribičić is the Founder and Project Leader at eramba. Serving thousands of companies around the world, eramba is a popular open Governance, Risk and Compliance (GRC) application. Listen to hear the story of eramba, how it was developed to solve real problems with simplicity, and how eramba's core values center on service.

www.eramba.org

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Grant Elliott is the CEO and Chairman of Ostendio. He is an entrepreneurial leader with over 20 years experience in a variety of Operations, Customer Service and Product Development roles mostly in an Executive capacity. He has a proven track record of successfully leading organizations that require significant growth, development or change, having led business units in large, medium and start-up enterprises.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Dave Hatter is an accomplished, enthusiastic, award-winning technology professional and servant leader with more than 30 years’ experience as a cybersecurity consultant, software engineer, project manager, and instructor. He also has more than 25 years' experience as a local government official, most recently the last nearly nine years as Mayor of Fort Wright, Kentucky.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

TJ Bettles is the founder and CEO of WhiteHat CyberSecurity Solutions, a Vancouver based network of ethical hackers and security experts offering penetration testing as a service. He is also a strength athlete that has dedicated 12+ years to strength training, coaching and to a much lesser degree, competition.

Additionally, he is the host of a new podcast focused on bullying in the workplace, Bully Proof. The first episode of Bully Proof, a discussion with Jennifer Fraser, author of The Bullied Brain, drops Monday, November 13, 2023. You won't want to miss it!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Matt Winkeler is a analytical security and privacy leader. He created a security and privacy program compliant with SOC 2, GDPR, and CCPA in less than a year. He has provided leadership as organization expanded from US to Europe, India, Australia, and beyond.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Simon Janin is the CEO of X80. He is a Technology Entrepreneur with strong expertise in Security, Computer Science and Software as a Service. He is a prior member of the Swiss Military Intelligence CNO unit, founded three companies, and made contributions to the fields of secure protocols, financial infrastructure and cyber security.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Tim Golden am the founder of Compliancerisk.io, a company that focuses on empowering the compliance function within your #MSP by streamlining your compliance operations. He is a seasoned professional in the governance risk and compliance space, with over 20 years of experience helping organizations tackle their business problems with the help of people, process, policy, and technology. He is an expert in compliance, risk management, governance policy management, and cybersecurity, and provides training, consulting, and technical assistance and governance programs to Managed Service Providers (MSPs)

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Empathy is his superpower, cyber security is his professional passion. Learn about Iboro Philip's rather unique journey and how a simple scam propelled him to a career in cybersecurity.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From March 29, 2023 - Greg van der Gaast is an international speaker on Why Security Fails, IT Quality, Leadership, and Strategy. He also is a former hacker, FBI & DoD operative, author, advisor, CISO, and people and culture enthusiast. Listen to hear his fascinating story and what is a major threat for SMB information security that most don't consider. He can be reached at https://gregvandergaast.com/.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Andrea Toponi is the CEO and founder of Cyberangels. With over 18 years of experience in project management, risk management, and IT consulting, he has always been passionate about using technology to solve complex problems and create value for customers. As a CEO and founder of Cyberangels, he helps small and medium-sized businesses (SMBs) secure their digital assets and protect their reputation from cyber attacks.

https://cyberangels.it

https://cyberangels.io (coming soon)

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Bill Butler is an experienced Vice President Of Engineering with a demonstrated history of working in the hospital and health care and security compliance industry. He is the Founder and VP Engineering of PolicyCo (policyco.io), a platform that lets you tie Regulations, Policies, Procedures, Control Testing and Remediation together in a single platform, along with a host of other features like version control, reporting, sharing, attestations, and a public API.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Perry Ausbrooks is a passionate Veteran Success Specialist & IT Systems Analyst at Intellectual Point, where he combines his commitment to helping fellow veterans with his growing expertise in cybersecurity. With certifications in Security+, C|EH, and Splunk, he provide training and mentorship to veterans transitioning into IT and cybersecurity careers.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

For our 100th discussion episode, Jeremy Snyder, founder and CEO of FireTail joins us. FireTail is a different, effective approach to API security. He looks for interesting challenges in the cloud, cybersecurity, data and robotics domain spaces, with the potential to have a positive impact. He tends towards entrepreneurial environments where people are highly motivated and moving at a fast pace, and where he can contribute more to the company's success.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

"Cybersecurity Cowboy" Chris Rule joins us to discuss cybersecurity concerns in education. He has been a School District level Technology Director since 1999 and worked directly or consulted with numerous school districts in Wyoming and Colorado. Aside from being a CoSN certified Education Technology Leader (CETL), a Certified vCISO, and a former Microsoft Certified System Engineer (MCSE), he is an experienced technology infrastructure expert and carries a wide array of technology skills.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From March 21, 2023 - Michael Lines is CISO for Open Technology Solutions, an expert in developing and leading information security and risk programs for organizations ranging from global enterprises to SaaS startup, and is authoring a book titled Heuristic Risk Management, dealing with why most risk management efforts are ineffective and what to do about it.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

With over 10 years of experience in cybersecurity, REST APIs, operations, and leadership, Terence Bennet the CEO and General Manager of DreamFactory Software. He oversees the daily operations, product development, customer success, and business strategy of DreamFactory, which is used by Fortune 500 companies, large tech companies, and government agencies. He served in the U.S. Navy as a Naval Intelligence Officer and Surface Warfare Officer during Operation Iraqi Freedom.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

A new direction...--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From March 14, 2023 - Carlota Sage is the Founder and Community CISO for Pocket CISO, thrives in that squishy area where business and technology meet human nature, and builds the relationships that get security, technology, business processes and people working together better, and has a background that includes information architecture, enterprise infrastructure, information security, and knowledge management. Among other things we discuss the vCISO space and the importance of brake lines!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Cyrus McCoy is a quality-driven Information Systems Engineering professional with ten plus years of cybersecurity experience in addition to being an Army veteran. He is an accomplished IT project manager (PMP Certified) with a proven ability to develop and implement strategies supporting business and financial objectives.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

AP Style Book Brach https://www.infosecurity-magazine.com/news/ap-stylebook-breach-hit-hundreds/

Microsoft Teams Phishing Attack https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-attack-pushes-darkgate-malware/

Cisco Zero Day Exploited https://arstechnica.com/security/2023/09/ransomware-crooks-exploit-unpatched-0-day-in-cisco-security-appliances/

78% of Healthcare Organizations Suffered Cyberattack https://www.hipaajournal.com/78-of-healthcare-organizations-suffered-a-cyberattack-in-the-past-year/

North Korea Cyberattacks https://www.scmagazine.com/brief/north-korea-ramps-up-intelligence-gathering-cyberattacks Cybersecurity Burnout Blog Post https://www.cybersecuritythoughts.com/blog/dealing-with-burnout-and-information-overload


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Sorry about the late publish, I had PM instead of AM configured! :)

LastPass Vaults Possibly Cracked https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/

Topgolf Calloway Brands Breached https://cybernews.com/security/topgolf-callaway-brands-hacked-million-golfers-exposed/

Virtual CISO and Information Security Risk Management Services https://vcisoservices.com

Company Culture of Cybersecurity Starts at the Top https://www.securitymagazine.com/articles/99573-embracing-a-company-culture-of-cybersecurity-starts-at-the-top

Microsoft Support for TLS 1.0, 1.1 Ends https://www.theregister.com/2023/09/04/tls_windows_deprecation/

Hackers Target IT Help Desks https://www.bleepingcomputer.com/news/security/okta-hackers-target-it-help-desks-to-gain-super-admin-disable-mfa/ Android Zero Day Alert https://thehackernews.com/2023/09/zero-day-alert-latest-android-patch.html


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From March 7, 2023 - Dave Sobel is the host of the Business of Tech podcast (https://www.businessof.tech/), a leading IT services focused news and analysis podcast and YouTube show, and owner of MSP Radio. He is regarded as a leading expert in the delivery of technology services, with broad experience in both technology and business. He owned and operated an IT Solution Provider and MSP for over a decade, both acquiring other organizations and eventually being acquired. Dave holds a bachelor's degree in Computer Science from the College of William and Mary. He is a dynamic voice within the IT community, a former member and facilitator for Heartland Technology Groups and passionate about collaborating with clients and peers on utilizing technology to advance organizations.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Dr. Fredrick Scholl is the Cybersecurity Program Director, Quinnipiac University. He is a cybersecurity thought leader and innovator, passionate about enabling success for people and businesses. He has a unique combination of skills and experience in academia, business and technology. His accomplishments range from the server room to the board room.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Chinese iMessaging Smishing https://thehackernews.com/2023/09/chinese-speaking-cybercriminals-launch.html

UK Military Hit By LockBit https://www.infosecurity-magazine.com/news/sensitive-data-uk-army-potentially/

Virtual CISO and Infosec Risk Management Services https://vcisoservices.com

Ransomware Attacks Go Beyond Data https://www.helpnetsecurity.com/2023/09/04/ransomware-preparedness-strategies/

University of Sydney Data Breach https://www.bleepingcomputer.com/news/security/university-of-sydney-data-breach-impacts-recent-applicants/

SEC Rule Puts Strain on CISOs https://www.darkreading.com/risk/proposed-sec-cybersecurity-rule-will-put-unnecessary-strain-on-cisos

10 Types of AI Attacks CISOs Should Track https://www.darkreading.com/threat-intelligence/10-types-of-ai-attacks-cisos-should-track


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Forever 21 Breach https://techcrunch.com/2023/08/31/forever-21-data-breach-half-million/Crackdown Against QakBot https://krebsonsecurity.com/2023/08/u-s-hacks-qakbot-quietly-removes-botnet-infections/Virtual CISO https://vcisoservices.com

Reality of Cyberinsurance https://www.securityweek.com/the-reality-of-cyberinsurance-in-2023/

Fake Version of Signal App  https://www.forbes.com/sites/thomasbrewster/2023/08/30/malicious-signal-app-planted-on-google-play-by-china-linked-cyber-spies/

Intersection of Cybersecurity and Mental Health https://www.softsideofcyber.com/cybersecurity-and-mental-health/amp/

SEC Regs Prompt 10 CISO Questions https://www.techtarget.com/searchsecurity/post/SEC-cyber-attack-regulations-prompt-questions-for-CISOs

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From March 1, 2023 - Caroline McCaffery is a lawyer who started a data privacy and cybersecurity technology company called ClearOPS to provide technology to virtual CISOs. B2B2B It is a customer relationship management tool + work automation for managing security programs, such as vendor management, gap analysis, security posture and security questionnaire response. She also hosts The vCISO Chronicles, a new podcast series focused on telling the stories of virtual CISOs.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

For this month's special last Wednesday episode, Dan Greenhaus, Senior Cybersecurity Analyst. joins us. He has two decades of experience involving healthcare and financial industries which has imbued him with versatility and broad-spectrum experience as a security and infrastructure professional. He has hands-on experience in preventing, detecting, and responding to real-world threats. He also was recently the victim of cyber bullying and offers insight into strategies to help - it is something that can happen to anyone.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Heather Noggle is the Owner of Codistac. People, processes, and technology are essential components of any modern successful business. Properly assessing risk and opportunity - paramount. Cybersecurity awareness and behavior within your organization is essential for your company’s reputation and ability to protect against potential cyber risks. Translating technical information and workflows into regular language (and back again) is her superpower. She is the host and producer of the YouTube series Cybersecurity for People (https://www.youtube.com/@heathernoggle).

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Poland Rail Cyber Attack https://www.bbc.com/news/world-europe-66630260

KmsdBot Targeting IoT https://thehackernews.com/2023/08/kmsdbot-malware-gets-upgrade-now.html

DeepFake Video Call Dangers https://www.bloomberg.com/news/articles/2023-08-25/deepfake-video-phone-calls-could-be-a-dangerous-ai-powered-scam

Customized LMs https://www.helpnetsecurity.com/2023/08/28/customized-llms/

Rhysida Ransomware Attack https://www.bleepingcomputer.com/news/security/rhysida-claims-ransomware-attack-on-prospect-medical-threatens-to-sell-data/

Initial Access Brokers https://cybersec.flare.systems/s/initial-access-brokers-russian-hacking-forums-and-the-underground-corporate-access-economy-10273

Five Skills to Learn for Ethical Hacking https://infosecwriteups.com/5-skills-to-learn-before-ethical-hacking-e3de68559c04

Cybersecurity for People https://www.youtube.com/@heathernoggle

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Service Providers Servers Wiped https://www.theregister.com/2023/08/23/ransomware_wipes_cloudnordic/

Critical Zoho Vuln Exploited https://thehackernews.com/2023/08/lazarus-group-exploits-critical-zoho.html

Virtual CISO Services https://vcisoserices.com

Wiffy Recon Malware https://thehackernews.com/2023/08/new-whiffy-recon-malware-triangulates.html

JupiterX WordPress Plugin Vuln https://www.bleepingcomputer.com/news/security/jupiter-x-core-wordpress-plugin-could-let-hackers-hijack-sites/

Duolingo’s Vulnerable API Exploited https://www.infosecurity-magazine.com/news/data-26m-duolingo-users-leaked/

Unplug Barracuda ESG Now https://www.scmagazine.com/news/fbi-unplug-exploited-barracuda-esg-appliances-now

Spear Phishing https://www.esecurityplanet.com/networks/how-to-prevent-spear-phishing-attacks/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From February 28, 2023 - Dennis Davoren is a vCISO, PhD Candidate, and Green Belt Six Sigma. He also is a veteran, having been an Air Force Instructor and Command Pilot along with being a Commander. He is an experienced leader with a demonstrated successful history of working in the Military, Marketing & Advertising industry, and Cyber Security/IT field. Skilled in Intelligence Analysis, Enterprise Risk Management, Financial Risk Management, Intelligence, and Risk Assessment. He is a Subject Matter Expert(SME) on Government Regulation Compliance(GRC) and CMMC 2.0 implementation. He holds a Master of Science degree focused on Cyber Security Management. We discuss the virtual CISO field and how risk management in flying translates to risk management in information security.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

J Wolfgang Goerlich is Advisory CISO at Cisco and is Faculty with IANS. In 1995, the movie Hackers came out. In 1995, the regional hospital trusted him with their IT. Coincidences. But? He has spent every day since keeping people out of the Gibson. || Strategist. Futurist. Chaotic good. Views expressed are his own.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Malware Turns Computers Into Proxy Servers https://thehackernews.com/2023/08/this-malware-turned-thousands-of-hacked.html

Chrome Extension Malware Warning https://www.bleepingcomputer.com/news/google/google-chrome-to-warn-when-installed-extensions-are-malware/

Virtual CISO Services https://vcisoservices.com

AI Helps Email Security https://www.helpnetsecurity.com/2023/08/21/ai-enabled-email-security/

Business Ban AI https://www.csoonline.com/article/648942/most-businesses-to-ban-chatgpt-generative-ai-apps-on-work-devices.html

AI Ransomware Threat https://blog.barracuda.com/2023/08/02/threat-spotlight-ransomware-attacks-double-ai-tactics Cloud Security Report https://www.cybersecurity-insiders.com/portfolio/2023-cloud-security-report-fortinet/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Apple iOS Airplane Mode Fake Out https://thehackernews.com/2023/08/new-apple-ios-16-exploit-enables.html

Patch Citrix https://www.theregister.com/2023/08/17/citrix_mft_exploit/

Regulators Not Going Far Enough https://www.washingtonpost.com/politics/2023/08/17/cyber-experts-say-regulators-arent-going-far-enough-with-their-rules/

LinkedIn Account Takeovers https://www.techradar.com/pro/security/linkedin-user-accounts-have-been-taken-over-in-huge-hacking-campaign

ISC2 Rebrand https://www.linkedin.com/posts/isc2_cybersecurity-activity-7097925448025661440-YyOF

Phishing Email Threat https://www.helpnetsecurity.com/2023/08/18/phishing-email-threat/

Cybersec Skills All Employees Should Have https://cybersec.thrivedx.com/s/cybersecurity-skills-every-employee-should-have-10098


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Jean-Christophe (J.C.) Gaillard is the founder and CEO of Corix Partners, a London-based Boutique Management Consultancy Firm and Thought-Leadership Platform focused on assisting CIOs and other C-level executives in resolving Cyber Security Strategy, Organisation and Governance challenges. He is a leading advisor, senior executive and global cyber security influencer with over 25 years of experience developed in several financial institutions in the UK and continental Europe, and a track-record at driving fundamental change in the Security field across global organisations, looking beyond the technical horizon into strategy, governance, culture, and the real dynamics of transformation. He is also the author of "Cyber Security: The Lost Decade - A Security Governance Handbook for the CISO and the CIO" and "The CyberSecurity Leadership Handbook for the CISO and the CEO". https://www.amazon.com/dp/B0BW51C5J1/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Russel Spitler is the Co-Founder and Chief Executive Officer at Nudge Security. Nudge Security is the world's first-ever SaaS security solution to discover shadow IT and curb SaaS sprawl across any device or location and nudges employees towards optimal security behavior. Nudge Security discovers SaaS assets, historically and as they are created across distributed organizations, maps digital supply chain risk, and automates SaaS security tasks, with a unique focus on automatically nudging employees to take steps to adopt and use SaaS securely. It's an interesting approach to dealing with the age-old issue of shadow IT!


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Microsoft Codesys Flaws https://www.infosecurity-magazine.com/news/microsoft-codesys-flaws-power-plant/

AI Risks https://www.helpnetsecurity.com/2023/08/14/generative-ai-risks-regulatory-challenges/

Virtual CISO Exchange https://www.linkedin.com/groups/12095465/

Ransomware Defense Strategies https://api.cyfluencer.com/s/ransomware-how-to-prevent-and-recover-from-an-attack-10070

Ransomware Report https://www.cybersecurity-insiders.com/portfolio/2023-ransomware-report-bullwall/

Enterprise Spending on Cybersecurity https://techcrunch.com/2023/08/14/enterprise-spending-on-cybersecurity-has-changed-and-vendors-must-adapt/

Vendor Agnostic Security Schema https://www.forbes.com/sites/tonybradley/2023/08/08/ocsf-announces-general-availability-of-vendor-agnostic-security-schema/amp/

Ford WiFi Vulnerability https://gbhackers.com/ford-cars-wifi-vulnerability/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

In this episode:

Rapid 7 Layoffs https://techcrunch.com/2023/08/09/rapid7-layoffs-second-quarter-earnings-loss/

Layoff Security Risks https://cybersec.cyolo.io/s/how-to-mitigate-security-risks-and-safeguard-your-business-during-mass-layoffs-10030

Virtual CISO and Risk Management Services https://vcisoservices.com

vCISO Survey Results https://www.hitchpartners.com/vciso-service-provider-survey-results-23

NIST CSF 2.0 https://www.nist.gov/news-events/news/2023/08/nist-drafts-major-update-its-widely-used-cybersecurity-framework

M365 Targeted Phishing https://www.csoonline.com/article/649242/takeovers-of-mfa-protected-accounts-increase-as-microsoft-365-phishing-campaign-shows.html

India Replace Windows with Maya https://www.cybersecurity-insiders.com/india-to-replace-all-its-defense-related-microsoft-systems-with-maya-os-due-to-ransomware/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From February 21, 2023 - Ray Harrison is a cyber security consultant with Abira Security, a consistent top sales performer, people oriented, reliable, and loyal. He also has a servant heart and leads the Faith in Jesus Forum, a LinkedIn group for Christians seeking to grow in their faith in Jesus and share with others along the way and those seeking to learn more about faith in Jesus.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Robert Pereira is passionate about creating an Information Technology system to be as frictionless as possible for the end users while still maintaining a level of security and privacy beyond just mandated compliance requirements to the level of truly protecting the data of the people and organizations stored at rest in or in transit from that system. We discuss prepping for and taking the CISSP exam, pivoting careers, and following God's path for us.

Links referenced:

https://www.blakes.com/pages/cybersecurity-trends-study-2023

https://www.blakes.com/insights/topic-centres/cybersecurity-privacy


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

On today's show:

Acoustic Attack - www.bleepingcomputer.com/news/security/new-acoustic-attack-steals-data-from-keystrokes-with-95-percent-accuracy

Crypto Scammers - https://thehackernews.com/2023/08/fbi-alert-crypto-scammers-are.html

Virtual CISO and Information Security Risk Management Services - https://vcisoservices.com

Credit Union Cyber Attacks - https://news.cuna.org/articles/122834-ncua-cyberattacks-against-credit-unions-service-providers-trending-upward

Finland Ransomware - https://securityaffairs.com/149244/hacking/ransomware-attacks-against-finland.html

Spain Attacks - https://www.infosecurity-magazine.com/news/russian-hacktivists-overwhelm/

Business Travel Strategic Planning https://www.securitymagazine.com/articles/99706-strategic-safety-planning-staying-ahead-of-business-travel-threats

Welcome Dean Heames - https://www.linkedin.com/feed/update/urn:li:ugcPost:7094293779993485313/

LIST – Certs - https://www.forbes.com/advisor/in/education/best-cyber-security-certifications/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

On today's show:

Russian Hackers Govt Org Teams Phish https://www.bleepingcomputer.com/news/security/russian-hackers-target-govt-orgs-in-microsoft-teams-phishing-attacks/

Tenable CEO Slams Microsoft Response https://www.bankinfosecurity.com/tenable-ceo-slams-microsoft-for-failing-to-quickly-patch-bug-a-22719

Virtual CISO Provider https://vcisoservices.com CFO Security Buy In https://cybersec.xmcyber.com/s/10-tips-to-get-buy-in-from-your-cfo-for-security-projects-9898

ChatGPT MacOS Malware https://www.hackread.com/chatgpt-to-expose-notorious-macos-malware/

Security Implications of ChatGPT Whitepaper https://cloudsecurityalliance.org/artifacts/security-implications-of-chatgpt/

CU Intersect Conference https://cuintersect.com/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From February 15, 2023 - Aaron Robel is a CISO with a positive, energetic, and transparent approach that fosters trust and collaboration across the business. He has a consistent track record for developing high-performing security programs and teams that bring business value while maintaining the organization's risk posture. We discuss infosec in the financial services sector, as his current role is CISO for a credit union and I am a former bank CISO and currently work with several financial institutions as a virtual CISO.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Carlos Rodriguez is CEO & Fractional Chief Information Security Officer - vCISO - Sr. Cybersecurity ConsultantCEO & Fractional Chief Information Security Officer - vCISO - Sr. Cybersecurity Consultant at CA2 Security. He specializes in enabling cyber risk management transformation, balance and simplification. We discuss SMB cybersecurity needs, the direction of the vCISO discipline, and the mission of service.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

US Hunts Chinese Malware https://thecyberwire.com/stories/f6e34b4362104d2aadbb814b9ae7557c/us-hunts-chinese-malware-staged-to-interfere-with-us-military-operations

Pentagon Suffers Air Force Comm Compromise https://www.forbes.com/sites/thomasbrewster/2023/07/29/exclusive-pentagon-suffers-critical-compromise-of-air-force-communications/

vCISO Services, LLC https://vcisoservices.com

Hackers Abusing Windows Search https://thehackernews.com/2023/07/hackers-abusing-windows-search-feature.html

Understanding New SEC Rule https://news.sophos.com/en-us/2023/07/31/understanding-the-new-sec-cybersecurity-rules-a-guide-for-executives/

Flipper Zero Third Party Apps https://www.bleepingcomputer.com/news/security/flipper-zero-now-has-an-app-store-to-install-third-party-apps/

LIST – Best Malware Protection Solutions https://cybersecuritynews.com/best-malware-protection-solutions/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

On today's episode:

SEC Cyber Incident Disclosure Rules https://www.helpnetsecurity.com/2023/07/26/sec-cybersecurity-incident-disclosure-rules/

VMWare Flaw https://www.infosecurity-magazine.com/news/vmware-patches-flaw-exposing-admin/

Tech Leaders Turn to Painkillers, Alcohol https://www.hr-brew.com/stories/2023/07/17/tech-turning-to-painkillers-alcohol

Iran Android Spyware https://www.hackread.com/iran-android-stalkerware-app-spyhide-hack/

Maximus Data Breach https://www.bleepingcomputer.com/news/security/8-million-people-hit-by-data-breach-at-us-govt-contractor-maximus/

Backdoor in Police Radios https://www.vice.com/en/article/4a3n3j/backdoor-in-police-radios-tetra-burst

Stern Security Healthcare Data Breach Report https://www.sternsecurity.com/blog/2023-velocity-healthcare-data-breach-report/

John Sternstein Discussion - https://youtu.be/0ll5SDxlSXk

Gary Chan Discussion - https://youtu.be/XR6Y27m5330

https://www.chicagomagiclounge.com/purchase-tickets-weekendhttps://www.chicagomagiclounge.com/now-appearing#the-weekend


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From February 14, 2023 - Ted Ilanchelian is President of CMIT Solutions of Brentwood and Franklin, a one-stop technology solution provider offering Small and Midsized Businesses (SMBs) enterprise-level IT infrastructure support and cybersecurity solutions at an affordable price. He is passionate about helping SMBs, noting that "attitude" is one of the most significant infosc threats SMBs face. Watch or listen to find out more!


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

James Bierly is the owner and principal cybersecurity consultant for Secure Point Solutions in Central Iowa. With 13 years in the Navy operating on both surface ships and submarines as a Sonar Analyst, he has had an unusual transition from military to civilian; from physical security to selling cars, he ultimately found opportunities to learn Information Technology while working overseas.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Denny Wan is a recognised global thought leader in Reasonable Security and cyber risk quantification methodologies. He is a Cyber Security Risk Expert with current certifications in CISSP, ISO 27001 LA, PCI Professional (converted from PCI QSA). He provides thought leadership in threat modelling, policy-based mitigation strategy development and process integration design. His recent article, "Targeting cyber security investment – the FAIR approach," is a practical guide for prioritising cyber security investments.

Webinar - "Defensible Cyber Risk Disclosure"

Event:

https://events.cpaaustralia.com.au/event/20a4d506-05b6-475f-ad12-805b9dcf6bbd/summary

Slide:

https://www.securityexpress.com.au/wp-content/uploads/2023/07/Defensible-Cyber-Risk-Disclosure-summary.pdf

  1. FAIRCON2023

October 17 & 18 at Fairmont Washington D.C. Hotel.

https://www.fairinstitute.org/2023-fair-conference


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

On today's episode:

Kevin Mitnick: https://www.msn.com/en-us/news/us/pioneering-hacker-kevin-mitnick-fbi-wanted-felon-turned-security-guru-dead-at-59/ar-AA1e8kyP

Mallox ransomware: https://thehackernews.com/2023/07/mallox-ransomware-exploits-weak-ms-sql.html

DDoS new methods: https://arstechnica.com/security/2023/07/attackers-find-new-ways-to-deliver-ddoses-with-alarming-sophistication/

Island browser on AWS Marketplace: https://www.helpnetsecurity.com/2023/07/20/island-enterprise-browser-aws-marketplace/

Poll: https://www.linkedin.com/feed/update/urn:li:ugcPost:7087465445724692480/

Europe IoT regulations: https://cy.bugprove.com/s/an-overview-of-iot-regulations-checklist-for-uk-psti-eu-red-and-cra-9756

Zyxel flaw: https://www.infosecurity-magazine.com/news/zyxel-flaw-exploited-ddos-botnets/

Previous video episodes of The Virtual CISO Moment podcast: https://youtube.com/vciso

My email: greg.schaffer@secondchancebook.org


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From February 7, 2023 - Dustin Sachs is an expert in cyber supply chain risk management, Sr. Manager GRC at World Fuel Services, a doctoral candidate at Colorado Tech, a mentor at Springboard, and a future CISO. He is passionate about giving back to the cybersecurity community and also about GRC.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Wes Spencer is VP and Channel Chief for FifthWall Solutions, one of the largest cyber insurance brokers in the country. He has served as a senior executive and advisor from Fortune 500 to funded startups and was awarded the 2020 Cybersecurity Educator of the Year by the Cybersecurity Excellence Awards. He has served on multiple advisory committees with distinguished organizations such as American Banker, Sentinel One, and FS-ISAC., and currently serves on the Department of Homeland Security AIS advisory committee.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Tom Kemp is a Silicon Valley-based entrepreneur, investor, author, and policy advisor. Tom is the author of the book Containing Big Tech: How to Protect Our Civil Rights, Economy, and Democracy (August 2023). Tom was the founder and CEO of Centrify (renamed Delinea in 2022), a leading cybersecurity cloud provider that amassed over two thousand enterprise customers, including over 60 percent of the Fortune 50. For his leadership, Tom was named by Ernst & Young as Finalist for Entrepreneur of the Year in Northern California. Tom is also an active Silicon Valley angel investor, with seed investments in over a dozen tech start-ups. In addition, Tom has served as a technology policy advisor for political campaigns and advocacy groups, including leading the campaign marketing efforts in 2020 to pass California Proposition 24—the California Privacy Rights Act (CPRA)—and co-authoring the California Delete Act of 2023.

ContainingBigTech.com - link to "Containing Big Tech: How to Protect Our Civil Rights, Economy, and Democracy"


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

TD Ameritrade MoveIT Breach https://www.investmentnews.com/charles-schwab-announces-td-ameritrade-data-breach-239887

Docker Hub Leak https://www.bleepingcomputer.com/news/security/thousands-of-images-on-docker-hub-leak-auth-secrets-private-keys/

Gamaredon APT https://securityaffairs.com/148488/apt/gamaredon-ttps.html

Teenage Hacker Criminals on Trial https://www.hackread.com/teenagers-trial-hacking-rockstar-revolut-uber/

USB Malware Delivery Increase https://www.scmagazine.com/brief/threat-intelligence/malware-delivery-via-usb-drives-significantly-increases

Cisco SD-WAN Vuln https://www.darkreading.com/remote-workforce/cisco-flags-critical-sd-wan-vulnerability

CISO Burnout https://www.techrepublic.com/article/top-cybersecurity-predictions/

Generative AI Board Questions https://www.mckinsey.com/capabilities/quantumblack/our-insights/four-essential-questions-for-boards-to-ask-about-generative-ai


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.bleepingcomputer.com/news/security/russian-state-hackers-lure-western-diplomats-with-bmw-car-ads/

vCISO Services, LLC - https://vcisoservices.com

Webinar - GRC Strategies - https://api.cyfluencer.com/s/top-security-and-grc-strategies-you-can-t-ignore-featuring-chris-roberts-ciso-boom-supersonic-9671

Ubuntu Citrix Flaw - https://securityaffairs.com/148405/security/citrix-critical-flaw-secure-access-client-for-ubuntu.html

National Cybersecurity Strategy - https://www.whitehouse.gov/briefing-room/statements-releases/2023/07/13/fact-sheet-biden-harrisadministration-publishes-thenational-cybersecurity-strategyimplementation-plan/

Honeywell Security Flaws - https://techcrunch.com/2023/07/13/security-flaws-in-honeywell-devices-could-be-used-to-disrupt-critical-industries/

LIST - 10 Summer Cybersecurity Tips - https://cybersec.xmcyber.com/s/https-www-xmcyber-com-blog-10-hot-cybersecurity-tips-during-your-summer-vacation-9641


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Derek Morris is a virtual Chief Information Security Officer (vCISO) with almost 3 decades in IT, Information Security, Cybersecurity. He possesses numerous industry certifications including: CISSP, CISM, CISA, CDPSE, PCI-QSA, CCSFP, CCNA, and MCSA. Bachelor's Degree in Computer Information Systems from Bryant University with a minor in Applied Statistics. We discuss the virtual CISO space and what to look for in a virtual CISO, including "IT empathy".


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Alec Sirois is the Co-founder and CEO at IGNITE Cyber Security. Join us for an interesting discussion on email security and what you can do to improve it. Also try a free email spoof test at emailspooftest.com!


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Central Bankers Framework https://www.infosecurity-magazine.com/news/central-bankers-framework-securing/

French Surveillance https://securityaffairs.com/148305/laws-and-regulations/french-government-surveillance-power.html

Android Apps Put Data At Risk https://www.cybercaptcha.com/news/your-ddata-is-at-risk-delete-these-apps-from-your-android-now/

Infosec Nashville https://issa-midtn.org/infosec-nashville-cybersecurity-conference/

Revolut Extortion https://thehackernews.com/2023/07/hackers-steal-20-million-by-exploiting.html

Coinbase Scam https://domainmagazine.com/exposed-scammers-exploit-coinbases-domain-name-to-target-investors/

Russia and China Spying https://www.politico.eu/article/russia-china-spying-germany-cybersecurity-intelligence/

Five IoT and ICS Security Challenges https://cybersec.cyolo.io/s/5-unique-security-challenges-facing-ot-ics-environments-9623


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

SecurityWeek Cisco Switch Vulns - https://www.securityweek.com/vulnerability-in-cisco-enterprise-switches-allows-attackers-to-modify-encrypted-traffic/

Bleeping Computer Google Apps Send Data to China - https://www.bleepingcomputer.com/news/security/apps-with-15m-installs-on-google-play-send-your-data-to-china/

vCISO Services Virtual CISO and Information Security Risk Management – https://vcisoservices.com

Vulcan What the Death of CentOS Means - https://cybersec.vulcan.io/s/what-the-death-of-centos-means-for-security-9582

Human Error Leading Cause Cloud Data Breaches - https://www.infosecurity-magazine.com/news/human-error-cloud-data-breaches/

Pen Testing and Cost of Cyber Insurance - https://thehackernews.com/2023/07/how-pen-testing-can-soften-blow-on.html

Medtech Dive  Vulns in Cardiac Data Systems - https://www.medtechdive.com/news/MDT-Medtronic-cybersecurity-vulnerability-CISA/654480/

BetaNews Cybercrime Third Largest Economy - https://betanews.com/2023/07/06/value-of-cybercrime-equivalent-to-the-third-largest-global-economy


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

BJ Withrow, Manager, Major Accounts, East Coast at Tenable, is a self-proclaimed geek at heart and cybernerd by trade. When he is passionate about something, it comes out in everything he does, and he loves what he does. We cover a variety of topics, including cybersecurity for small and midsized businesses, exercising, and the importance of a servant's heart. Note a production error resulted in mismatched video and audio for host, not guest. We have switched platforms going forward because of this issue.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Doug Copley is an executive IT and cybersecurity leader and advisor, founder of Data Protection Partners, and former founder of the Michigan Healthcare Cybersecurity Council. He is skilled at building IT, Security and Data Privacy programs from scratch; performing risk assessments; frameworks such as HITRUST/ISO/NIST/CMMC; and at managing security or regulatory "emergencies." He has specific expertise in healthcare. with prior experience in financial services, automotive, security software industry and management consulting.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.helpnetsecurity.com/2023/07/03/hybrid-cloud-security-breaches/

https://www.trendmicro.com/en_us/research/23/f/malvertising-used-as-entry-vector-for-blackcat-actors-also-lever.html

https://vcisoservices.com

https://cybersec.sentra.io/s/chatgpt-is-a-data-loss-disaster-9520

https://thehackernews.com/2023/07/cisa-flags-8-actively-exploited-flaws.html

https://securityaffairs.com/148059/cyber-crime/meduza-stealer-malware.html

https://www.darkreading.com/microsoft/3-ways-to-build-a-more-skilled-cybersecurity-workforce

https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/top-5-common-deployment-tips-for-us-government-agencies/ba-p/3857792

https://www.darkreading.com/microsoft/3-ways-to-build-a-more-skilled-cybersecurity-workforce


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.darkreading.com/physical-security/filipinos-rescued-forced-cybercrime-labor

https://www.channelasia.tech/article/707835/sec-notice-solarwinds-ciso-cfo-roils-cybersecurity-industry/

https://vcisoservices.net

https://www.iansresearch.com/resources/all-blogs/post/security-blog/2022/11/15/benefits-of-a-virtual-ciso

https://securityaffairs.com/147954/malware/thirdeye-infostealer.html

https://www.parealtors.org/blog/study-exposes-real-estate-industrys-most-common-passwords/

https://techcrunch.com/2023/06/29/high-school-changes-every-students-password-to-chngeme/

https://www.techrepublic.com/article/kaspersky-report-top-cyber-threats-smbs/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From January 17, 2023 - Brent Forrest is a leader, architect, and strategic advisor of holistic cybersecurity. He has developed security programs across Oil & Gas, Financial, Insurance, and Construction industries including architecture of endpoint visibility/protection, managed detection and response (MDR), and security awareness as well as leading real-world cyberbreach response efforts. He is a graduate of Western Governors University and a holder of CISSP, C|CISO, and other technology certifications.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Shaun Cook has an extensive career in information technology and cybersecurity and is a Strategic Account Manager with Island. Island is a true disruptor, an early entry into the emerging Enterprise Browser market. According to Gartner, “By 2030, enterprise browsers will be the core platform for delivering workforce productivity and security software on managed and unmanaged devices for a seamless hybrid work experience.” Listen why that is the case and how it may be a game changer in the post-COVID hybrid workforce reality.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Raj Joshi, Co-Founder of RiskOne.io, is a cybersecurity executive with over 25 years of experience in building, transforming, and delivering cybersecurity, product security and information technology programs. We discuss SMB cybersecurity challenges including how an example from Toyota in the 1980s can help with SMB security.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.helpnetsecurity.com/2023/06/23/microsoft-teams-deliver-malware/

https://www.infosecurity-magazine.com/news/us-authorities-seize-breachforums/

https://vcisoservices.com

https://api.cyfluencer.com/s/casb-vs-sspm-9454

https://securityaffairs.com/147801/cyber-crime/twitter-hacker-sentenced.html

https://www.bleepingcomputer.com/news/security/lastpass-users-furious-after-being-locked-out-due-to-mfa-resets/

https://www.nationalcybersummit.com/

https://issa-midtn.org/infosec-nashville-cybersecurity-conference/

https://www.helpnetsecurity.com/2023/06/26/free-online-cybersecurity-courses/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.bleepingcomputer.com/news/security/microsoft-hackers-hijack-linux-systems-using-trojanized-openssh-version/

https://www.infosecurity-magazine.com/news/apple-addresses-exploited-flaws-in/

https://vcisoservices.com

https://www.darkreading.com/risk/it-staff-saddled-data-protection-compliance

https://www.standard.co.uk/tech/cybersecurity-nhs-trust-hospitals-ransomware-hackers-b1089347.html

https://www.securityweek.com/new-information-stealer-mystic-stealer-rising-to-fame/

https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2023/pay-for-isaca-certifications-is-on-the-rise https://api.cyfluencer.com/s/how-to-get-executive-buy-in-for-your-security-compliance-platform-d56822b5-9390


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From January 10, 2023 - Mary-Michael Horowitz, CISM, is the Founding Partner/CEO at Asylas, LLC. Asylas is a cybersecurity solutions firm heavily focused on remarkable service and customized approaches to security, privacy and risk consulting. We discuss small and midsized business security challenges, including passwords and password managers.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Samuel Hill is the Product Marketing Director for Cyolo Security, where they created one unified platform that enables users to access all applications, servers, desktops, and files within an organization securely and with ease. Cyolo leverages agility, security, and productivity – whatever the situation, wherever their users may be. Hill is skilled in helping orchestrate and integrate critical device security. He also provides resilient IT strategies, supportive security ecosystems, and process integrity across industrial Extended Internet of Things and Commercial Cyber-Physical Systems.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.helpnetsecurity.com/2023/06/19/cve-2023-35708/

https://www.infosecurity-magazine.com/news/us-offers-10m-reward-for-moveit/

https://vcisocatalyst.org

https://www.hackread.com/microsoft-ddos-attack-cyber-attack-impact/

https://cybersec.xmcyber.com/s/a-comprehensive-guide-to-getting-and-calculating-cybersecurity-cpe-credits-086c3af7-9319

https://www.cyclonis.com/remove-lmao-ransomware/

https://www.scmagazine.com/news/compliance/sec-delays-final-rule-on-proposed-four-day-breach-notification-for-public-companies-until-october

https://cybersec.legitsecurity.com/s/new-techniques-attackers-are-using-to-harvest-your-secrets-9320


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.foxnews.com/politics/us-government-agencies-hit-cyberattack

https://knue.com/self-checkout-scam-spring-texas/

https://vcisoservices.com

https://cybersec.gitguardian.com/s/verizon-2023-dbir-credential-leaks-continue-to-be-a-major-issue-9238

https://www.itsecurityguru.org/2023/06/16/new-survey-reveals-critical-data-security-gap-in-the-financial-services-industry/

https://www.infosecurity-magazine.com/news/barracuda-zero-day-exploited/

https://www.darkreading.com/edge/10-important-security-tasks-you-shouldn-t-skip


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From January 3, 2023 - Dave Evangelista has 20 years of experience with financial institutions and currently is the Vice President Information Technology for a midwestern credit union where he is responsible for the tactical direction, control, and ongoing analysis and planning for the credit union’s IT environment. Infrastructure, Operations, Critical Systems, Information Security, Development, e-Services, Service Delivery, Digital and Technology Support. He also has 24 years law enforcement experience including as a Kentucky certified Cyber and Financial Crimes Investigator, Kentucky certified Advanced Internet Crimes Investigator, election consultant on crimes against children to former Governor Ernie Fletcher, founder and executive director for the United States Internet Crime Task Force (1998-2020), and is a recognized expert witness on digital forensics.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Sejal Lakhani-Bhatt is a serial Entrepreneur who has a passion for helping small and mid-sized companies. She is the top Skittle for TechWerxe, which provides small and medium sized businesses with Cyber security, Compliance, IT architecture design, infrastructure and maintenance in NY / NJ / PA. As CEO and co-owner of TechWerxe, She does a little bit of everything. From Sales and Marketing, to HR, Project Management and Finance...she covers it all. She partners with various CXO-levels to customize solutions that will enable your business to get to the next level. And she has fun doing it all!


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.bleepingcomputer.com/news/security/fortinet-fixes-critical-rce-flaw-in-fortigate-ssl-vpn-devices-patch-now/

https://securityaffairs.com/147299/security/new-moveit-transfer-sql-inj.html

https://vcisocatalyst.org

https://cybersec.xmcyber.com/s/from-vulnerability-management-to-exposure-management-maturity-model-9195

https://www.bleepingcomputer.com/news/security/strava-heatmap-feature-can-be-abused-to-find-home-addresses/

https://cybersec.vulcan.io/s/the-problem-with-google-s-new-zip-top-level-domains-9196

https://www.infosecurity-magazine.com/news/uni-manchester-data-breach-incident/

https://api.cyfluencer.com/s/into-the-breach-breaking-down-3-saas-app-attacks-in-2022-098ac386-9197

https://thehackernews.com/2023/06/microsoft-uncovers-banking-aitm.html

https://cybersec.vulcan.io/s/how-to-fix-cve-2023-32243-in-elementor-essential-addons-9198


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://cybersec.sentra.io/s/chatdlp-automatically-anonymize-sensitive-data-in-chatgpt-9073

https://www.bleepingcomputer.com/news/security/google-chrome-password-manager-gets-new-safeguards-for-your-credentials/

https://vcisoservices.com

https://www.scmagazine.com/brief/vulnerability-management/security-vulnerabilities-on-the-rise

https://cybersec.jetpatch.com/s/automated-patch-management-streamlining-your-process-9098

https://vcisoservices.net

https://thehackernews.com/2023/06/barracuda-urges-immediate-replacement.html

https://www.helpnetsecurity.com/2023/06/07/island-password-manager/


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From December 28, 2022 - Michelle Drolet is a highly experienced information security expert who is well respected by clients, information security peers and analysts. Ms. Drolet is a sought-out speaker, panelist, and is a regular contributor to leading online publications such as Forbes Technology Council, Wired.com and IDG CSO Online. We discuss SMB security needs and challenges and how services such as a virtual CISO can be an effective solution.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Thad Wellin is the CEO of TRW Security Solutions where he serves as a consultant for Risk Management Framework, Cyber Security Framework, and Defense Information Assurance Certification and Accreditation Process. Listen to hear first hand about his prep process for and taking of the Certified CMMC Professional exam and other CMMC-related tidbits, including a potential issue with Windows 11. Prerecorded. #podcast #CMMC #cybersecurity #infosec #vCISO #VirtualCISOMoment


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.bleepingcomputer.com/news/security/online-sellers-targeted-by-new-information-stealing-malware-campaign/

https://securityaffairs.com/146998/security/cisa-moveit-transfer-0day-catalog.html

https://vcisoservices.com

https://cybersec.legitsecurity.com/s/what-is-application-security-posture-management-insights-into-gartner-s-new-report-fb04e5f3-9004

https://cybersec.banyansecurity.io/s/banyan-ransomware-threat-update-may-2023-9005

https://redrays.io/redrays-major-cybersecurity-breach-affects-4800-domains/

https://www.tomsguide.com/news/over-400-million-infected-with-android-spyware-delete-these-apps-right-now

https://cybersec.gitguardian.com/s/are-your-company-secrets-safe-on-github-here-s-why-you-need-to-request-a-complimentary-audit-9003


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://www.bleepingcomputer.com/news/technology/amazon-faces-30-million-fine-over-ring-alexa-privacy-violations/

https://securityaffairs.com/146892/hacking/backdoor-like-behavior-gigabyte-systems.html

https://vcisoservices.com

https://cybersec.jetpatch.com/s/the-ultimate-guide-to-linux-server-patch-management-8887

https://api.cyfluencer.com/s/5-steps-to-choosing-the-perfect-grc-solution-57d7fd5a-8902

https://nakedsecurity.sophos.com/2023/05/31/serious-security-that-keepass-master-password-crack-and-what-we-can-learn-from-it/

https://thehackernews.com/2023/05/beware-of-ghost-sites-silent-threat.html

https://thehackernews.com/2023/05/6-steps-to-effective-threat-hunting.html

Music from #Uppbeat (free for Creators!): https://uppbeat.io/t/cruen/raw-power License code: OSDVYUTGJ3ESKUFQ


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Greg Flatt is the founder of Flatt Earth Networking, Inc. Since 1996, Flat Earth Networking, Inc. has provided mid- to large-sized businesses an authoritative approach to network security that includes superior enterprise products and effective problem-solving. Greg discusses his path beginning and growing Flat Earth Networking, Inc. over the past 26 years. From December 13, 2022.


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From August 20, 2020 - Metrics - security leaders talk about them often. But what is the one critical question they, and you, should ask about information security metrics?


Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

James McQuiggan has over 20 years of experience in cybersecurity. He is currently a Security Awareness Advocate for KnowBe4, where he is responsible for amplifying the organization's messaging related to the importance of, effectiveness of and the need for new-school security awareness training within organizations through social media, webinars, in-person presentations, industry trade shows and traditional media outlets. McQuiggan is also a part-time faculty professor at Valencia College in the Engineering, Computer Programming & Technology Division. Within the Central Florida community, he is the president of the (ISC)2 Central Florida Chapter and a member of the Trustee Board for the Center for Cyber Safety and Education.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://securityaffairs.com/146768/cyber-crime/rpmsg-messages-microsoft-365-phishing.html

https://thehackernews.com/2023/05/new-gobrat-remote-access-trojan.html

https://vcisoservices.com

https://cybersec.xmcyber.com/s/the-anatomy-of-a-healthcare-cyberattack-two-true-stories-8874

https://cy.bugprove.com/s/iot-security-resource-directory-8875

https://www.helpnetsecurity.com/2023/05/29/larger-organizations-cyberattacks/

https://www.hackread.com/stealing-wallets-browsers-bandit-stealer-windows/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://api.cyfluencer.com/s/mental-health-awareness-week-2023-no-more-empty-words-8810

https://www.bleepingcomputer.com/news/security/new-russian-linked-cosmicenergy-malware-targets-industrial-systems/

https://www.infosecurity-magazine.com/news/ncsc-warns-chinese-cyber-attacks/

https://securityintelligence.com/articles/cyber-risk-influences-company-credit-ratings/

https://www.helpnetsecurity.com/2023/05/25/chatgpt-phishing/

https://www.helpnetsecurity.com/2023/05/25/cve-2023-2868/

https://cy.bugprove.com/s/7-questions-and-answers-about-firmware-and-firmware-security-8815

https://bitdefender.f9tmep.net/c/4084356/1488530/4466

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Derek Andrews, Incident Response Manager at a Financial Institution, joins VCM to discuss his journey, incident response in the financial sector, and different types of virtual CISOs from the perspective of one who has worked with both the good and not so good. He also explains why he is the Resident Birdman of LinkedIn! From December 12, 2022.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

GE Scott Knauss is the Owner/CEO at Immauss Cybersecurity, President vCISO Catalyst, and Vice President (ISC)² US Military Germany Chapter. He has 26 years of experience with Linux, IP Networks and Security; 23 years of experience working with virtualized environments and Cloud technologies; and protected the US Navy’s Mediterranean fleet from cyber attacks while leading a team of engineers providing tier III support for a high paced Operations Center for 7 ½ years.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://bitdefender.f9tmep.net/c/4084356/1488530/4466

https://www.wsj.com/articles/cybersecurity-leaders-suffer-burnout-as-pressures-of-the-job-intensify-b0609ef1

https://www.infosecurity-magazine.com/news/experts-warn-of-voice/

https://www.bleepingcomputer.com/news/security/google-will-delete-accounts-inactive-for-more-than-2-years/

https://securityaffairs.com/146472/data-breach/luxottica-2021-data-breach.html

https://www.scmagazine.com/brief/threat-intelligence/taiwan-facing-more-cyberattacks-amid-tensions-with-china

https://www.bleepingcomputer.com/news/technology/hp-rushes-to-fix-bricked-printers-after-faulty-firmware-update/

https://infosecwriteups.com/5-best-cybersecurity-books-of-all-time-must-read-part-1-aaaff7730c63

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From November 30, 2022 - Jacob Horne was born with a rare genetic mutation that allows him to read NIST publications and government regulations without experiencing boredom like a normal person and has made a career out of using this power for good. He does a great job of using NIST SP 800-53 to clarify the bizarre, heavily tailored world of NIST SP 800-171 and CMMC - if you're interested in CMMC you must follow him on LinkedIn! He is also co-host of the Sum It Up podcast which sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Leon Kuperman is the co-founder and CTO at CAST AI. Formerly Vice President of Security Products OCI at Oracle, Leon’s professional experience spans across tech companies such as IBM, Truition, and HostedPCI. He founded and served as the CTO of Zenedge, an enterprise security company protecting large enterprises with a cloud WAF. Leon has 20+ years of experience in product management, software design, and development, all the way through to production deployment. He is an authority on cloud computing, web application security and Payment Card Industry Data Security Standard (PCI DSS), e-commerce, and web application architecture.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

https://bitdefender.f9tmep.net/c/4084356/1488530/4466

https://www.bleepingcomputer.com/news/security/hackers-use-public-exploit-to-attack-vulnerable-wordpress-sites/

https://securityaffairs.com/146200/data-breach/capita-warns-customers.html

https://www.infosecurity-magazine.com/news/doctor-accused-prolific-ransomware/

https://brave.com/privacy-updates/25-forgetful-browsing/

https://thehackernews.com/2023/05/new-phishing-as-service-platform-lets.html

https://www.reuters.com/business/autos-transportation/toyota-flags-possible-leak-more-than-2-mln-users-vehicle-data-japan-2023-05-12/

https://nakedsecurity.sophos.com/2023/05/12/whodunnit-cybercrook-gets-6-years-for-ransoming-his-own-employer/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Support us by supporting our sponsor Bitdefender! https://bitdefender.f9tmep.net/c/4084356/1488530/4466

https://www.infosecurity-magazine.com/news/ransomware-fails-to-extort-dragos/

https://www.bleepingcomputer.com/news/security/wordpress-elementor-plugin-bug-let-attackers-hijack-accounts-on-1m-sites/

https://securelist.com/new-ransomware-trends-in-2023/109660/

https://www.helpnetsecurity.com/2023/05/11/bitdefender-app-anomaly-detection/

https://arstechnica.com/tech-policy/2023/05/1-5m-crypto-scheme-leads-to-2-year-prison-term-for-ex-coinbase-manager/

https://www.sans.org/cyber-security-training-events/cybersecurity-small-businesses-summit-2023/

https://www.bleepingcomputer.com/news/security/top-5-password-cracking-techniques-used-by-hackers/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From November 29, 2022 - Cheri Hotman of the Hotman Group (https://hotmangroup.com) is a CPA, has her MBA, and is a CISSP - a combination rare in information security. She discusses her experiences and lessons learned managing a business providing quality virtual CISO services to a variety of clients, including navigating "the land of 1000 piranhas"!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Support us by supporting our sponsor Bitdefender!

https://bitdefender.f9tmep.net/c/4084356/1488530/4466

Wordpress vuln, Cactus ransomware, Bitmarck attacked, Apple Rapid Security Updates, generative AI in malware, CISA urges incorporating list in risk management plans, and SEC whistleblower payout record (and why that is meaningful to cybersecurity).

https://thehackernews.com/2023/05/new-vulnerability-in-popular-wordpress.html

https://www.bleepingcomputer.com/news/security/new-cactus-ransomware-encrypts-itself-to-evade-antivirus/

https://www.infosecurity-magazine.com/news/bitmarck-halts-operations/

https://arstechnica.com/gadgets/2023/05/seven-months-in-ios-and-macos-get-their-first-rapid-security-updates/

https://securityaffairs.com/145692/security/generative-ai-lure-malware.html

https://www.cisa.gov/news-events/alerts/2023/05/01/cisa-urges-organizations-incorporate-fcc-covered-list-risk-management-plans

https://www.sec.gov/news/press-release/2023-89

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

David Primor is the Founder and CEO of Cynomi, which addresses a critical gap in mid-market cyber protection - creating and executing a cyber and compliance strategy for companies with insufficient (or no) cyber personnel. He spent the first half of his career as a strategic cyber expert and leader, on the front lines of state-level cyber defense (8200, Israeli National Cyber Security Authority). He believes one of the next big challenges (and opportunities) in cyber is in the SMB space - providing optimal protection for companies with a very limited cyber budget and little to no in-house expertise. Cynomi’s AI powered offering does just that.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Dallas breach brings down systems, Cisco vuln, cyber risk index lowers, Brightline hack exposes patient data, university alert system hijacked, and the lock icon is going away.

https://bitdefender.f9tmep.net/c/4084356/1488530/4466

https://www.darkreading.com/attacks-breaches/dallas-city-systems-taken-down-by-royal-ransomware

https://thehackernews.com/2023/05/cisco-warns-of-vulnerability-in-popular.html

https://www.helpnetsecurity.com/2023/05/05/cyber-risk-index-2h-2022/

https://www.infosecurity-magazine.com/news/brightline-hack-exposes-data/

https://www.bleepingcomputer.com/news/security/ransomware-gang-hijacks-university-alert-system-to-issue-threats/

https://arstechnica.com/information-technology/2023/05/google-will-retire-chromes-https-padlock-icon-because-no-one-knows-what-it-means/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From November 22, 2022 - Robin Wilde is the Director of Business Solutions for TeamHealth. She is passionate about project management and cyber security, particularly Identity Management, as well as promoting women in cyber. She holds a variety of certifications, including the CISSP, CRISC, PMP, ACP, CSP, and Prosci, demonstrating her vast skillset and experience. She introduces the phrase "privilege sprawl" - listen to find out what that means!

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Nick Espinosa is the Chief Security Fanatic at Security Fanatics, author, speaker, and radio show host. An expert in cybersecurity and network infrastructure, Nick has consulted with clients ranging from the small business owners up to Fortune 100 level companies. Nick has designed, built, and implemented multinational networks, encryption systems, and multi-tiered infrastructures as well as small business environments. He is passionate about emerging technology and enjoys creating, breaking, and fixing test environments.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Hackers target Vveeam backup servers, has MFA failed us, man gets four years for stealing Bitcoins, ChatGPT back in Italy, critical bugs in illumina dna sequencing systems, why people skills matter, and today’s list- six Key Moments From House Republicans' Hearing on Warrant-Free FISA Surveillance

Links

https://www.bleepingcomputer.com/news/security/hackers-target-vulnerable-veeam-backup-servers-exposed-online/

https://medium.com/pcmag-access/has-multi-factor-authentication-failed-us-319ee10393dd

https://www.infosecurity-magazine.com/news/four-years-stealing-bitcoins/

https://thehackernews.com/2023/04/chatgpt-is-back-in-italy-after.html

https://cyber-reports.com/2023/04/28/cisa-warns-of-critical-bugs-in-illumina-dna-sequencing-systems/

https://securityaffairs.com/145483/hacking/esa-satellite-hack.html

https://securityintelligence.com/articles/why-people-skills-matter/

https://gizmodo.com/fisa-hearing-congress-republicans-6-key-moments-1850384660

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

PaperCut vulnerabilities leveraged by Clop, LockBit, Ukranian arrested selling data, an OS that resists ransomware, okcupid scams Florida man, cable cut in DC whacks Vermont services, NCSA HBCU scholarship, major bug in Google cloud, new ways to manage your ChatGPT data, and a new podcast shout out.

https://www.helpnetsecurity.com/2023/04/27/papercut-lockbit-clop/

https://www.infosecurity-magazine.com/news/ukrainian-arrested-selling-data/

https://cyberscoop.com/database-oriented-operating-system-rsa/

https://securityaffairs.com/145369/cyber-crime/cryptorom-okcupid-scam-florida-man.html

https://www.govtech.com/gov-experience/how-a-cut-cable-temporarily-downed-vermonts-state-websites

https://www.helpnetsecurity.com/2023/04/25/national-cybersecurity-alliance-hbcu-scholarship-program/

https://open.spotify.com/episode/7idaNBg4T9DiCloZ9i3IJp?si=jJLnF7uwR76wgyGcR3-EYQ

https://www.techradar.com/news/security-experts-found-a-major-bug-in-google-cloud

https://openai.com/blog/new-ways-to-manage-your-data-in-chatgpt

https://open.spotify.com/show/4TR7B5bZ1IO41tIsnzcg4J

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From November 16, 2022 - Lin Clark, the Carolina Cyber Center's SOC Director, discusses how the SOC benefits both the students in the Carolina Cyber Center program and the western North Carolina small business community. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022. Audio only.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Lisa Plaggemier, the Executive Director at National Cyber Security Alliance, joins us for our special April Wednesday end of month episode. She is a creative and revenue-driven Marketing and Strategy Executive. She excels at creating attainable strategic vision that inspires employees and attracts customers, is respected by CSOs and CISOs, is a winner of the SC Magazine’s Reboot Thought Leadership Award, and is a frequent speaker at RSA and SANS. She joins us to explain how the National Cyber Security Alliance helps with both personal and small and midsized business security, including a new initiative for SMBs.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Tracy Maleeff, Principal, Sherpa Intelligence LLC, is an Information Security Professional with a Master of Library and Information Science degree. A frequent author and speaker on InfoSec and research topics, she has presented at several Information Security industry conferences like Security BSides, DerbyCon, and DEF CON's Recon Village, as well many library/information professional events. She holds the GIAC Security Essentials (GSEC) certification. She also maintains an OSINT blog and cybersecurity newsletter at https://infosecsherpa.medium.com/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Low bandwidth resulted in low video quality.

https://securityaffairs.com/145183/cyber-crime/point32health-ransomware-attack.html 

https://www.helpnetsecurity.com/2023/04/22/next-dlp-reveal-chatgpt/ 

https://www.welivesecurity.com/2023/04/18/discarded-not-destroyed-old-routers-reveal-corporate-secrets/ 

https://osintteam.blog/dark-web-how-to-get-started-658409184c06 

https://www.bleepingcomputer.com/news/security/evilextractor-malware-activity-spikes-in-europe-and-the-us/ 

So You Want To Be An Information Security Consultant 

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From November 9, 2022 - Rob Bowker, Sales Director at EasyDMARC, explains the risks of email spoofing, the benefits of implementing DMARC in addition to DKIM and SPF, and how EasyDMARC helps to manage DMARC. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Matthew Dechant is the founder of MD3 Consulting, providing virtual CISO services to small and medium sized businesses. He is a seasoned executive building, operating, and scaling comprehensive information security programs that address business risk and adapt to emerging threats without affecting the speed of business.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

LockBit targets MacOS,China exploits Android bug, urgent Chrome update, LinkedIn ID verification, and Juice Jacking back in the news,but why. Plus today’s lists – we have two – top 5 cybersecurity risks every business should know and 4 things you should never do while chatting with ChatGPT, an extended version of the “So you want to be an infosec consultant” presentation at BSides Nashville and SE cyber summit dropping this afternoon, the 2023 recipient of the vCISO Services scholarship, and today’s shout out.

https://securityaffairs.com/144879/cyber-crime/lockbit-encryptor-targets-macos.html

https://www.bleepingcomputer.com/news/security/cisa-warns-of-android-bug-exploited-by-chinese-app-to-spy-on-users/

https://thehackernews.com/2023/04/google-releases-urgent-chrome-update-to.html

https://www.scmagazine.com/news/identity-and-access/linkedin-deploys-new-secure-identity-verification-for-all-members

https://krebsonsecurity.com/2023/04/why-is-juice-jacking-suddenly-back-in-the-news/

https://physicochemics.com/what-are-cybersecurity-risks-their-management/

https://bgr.com/tech/4-things-you-should-never-do-while-chatting-with-chatgpt/

https://www.linkedin.com/in/ereny-nagib-07a3a01b7/

https://youtube.com/@vciso

https://www.linkedin.com/in/markwdebry/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Iowa Medicaid breach, KFC-Pizza Hut breach, tax firms malwaretargeted, ChatGPT bug bounty, hybrid environment stressing CISOs, 33,000 lose$98M to investment fraud, four ways to harden your net perimeter, seven itemsyour ransomware playbook may be missing, and today’s shout out for Kevin Cecil.

https://www.infosecurity-magazine.com/news/20000-iowa-medicaid-members-data/

https://cybersecuritynews.com/kfc-pizza-hut-breach/

https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/

https://www.infosecurity-magazine.com/news/ethical-hackers-chatgpt/

https://www.helpnetsecurity.com/2023/04/12/hybrid-work-environments-stressing-cisos/

https://www.bleepingcomputer.com/news/security/five-arrested-after-33-000-victims-lose-98m-to-online-investment-fraud/

https://securityintelligence.com/posts/four-ways-to-harden-your-network-perimeter/

https://www.darkreading.com/attacks-breaches/7-things-ransomware-response-playbooks-missing

https://www.linkedin.com/in/kevincecil/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From November 8, 2022 - Jake Williams is a cybersecurity manager and aspiring CISO, currently pursuing his MBA. He is also well-versed in CMMC, and we dive into some elements of this somewhat confusing standard/requirement.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Davy Cox is the founder of Brainframe.com, an all in one ISMS/GRC/DMS/QMS that can help SMBs and vCISOs manage their information security programs.With a bachelor in ICT, a Master in Security (RSSI), a AWS Solution Architect - professional certification and more than 15 years hands on experience leading IT, infrastructure and infosec, he can highly augment the success, efficiency and stability of any challenging environment.Over the years he has built up a deep understanding and experience on ISO2700x security implementations, HDS compliance, GDPR compliance (with medical products) and effective hands on security hardening best practices for high traffic online services. He has built up a "security & privacy by design" mentality which he strives to spread among the people he works with.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Leaked NATO docs possibly altered, repeating to trick, new Apple zero days, five active exploits added to CISO KEV,  1 million WordPress sites infected, five cybersecurity myths, and today’s shout out featuring a cyber security pro looking for the next opportunity.

https://www.scmagazine.com/news/policy/us-nato-ukraine-docs-altered

https://www.helpnetsecurity.com/2023/04/10/simple-trick-disclose-personal-data/

https://www.bankinfosecurity.com/apple-issues-emergency-fix-for-spyware-style-zero-days-a-21652

https://heimdalsecurity.com/blog/five-new-actively-exploited-vulnerabilities-added-by-cisa-to-its-kev-catalog/

https://thehackernews.com/2023/04/over-1-million-wordpress-sites-infected.html

https://www.forbes.com/sites/forbesbusinesscouncil/2023/04/06/dispelling-the-myths-around-cybersecurity-for-small-businesses/?sh=358f76d81f63

https://www.linkedin.com/in/brianmartinliticode/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

A third of organizations cover up data breaches, Uber data exposed, crackdown on malicious Colbalt Strike servers, ChatGPT Samsung data leak, using ChatGPT as a risk and compliance enabler, and four steps to avoid a ransomware attack. Plus our first shout out for helping cybersecurity pros land their next great opportunity.

https://venturebeat.com/security/a-third-of-organizations-admit-to-covering-up-data-breaches/

https://www.infosecurity-magazine.com/news/uber-data-exposed-law-firm-breach/

https://www.bleepingcomputer.com/news/security/microsoft-and-fortra-crack-down-on-malicious-cobalt-strike-servers/

https://cybernews.com/news/chatgpt-samsung-data-leak/

https://securityintelligence.com/posts/using-chatgpt-as-an-enabler-for-risk-and-compliance/

https://www.eschoolnews.com/it-leadership/2023/03/30/4-steps-to-avoid-a-ransomware-attack/

https://www.linkedin.com/in/colemic/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

In a special Wednesday episode, Don Colliver joins us to discuss how to be successful making technical presentations. He is an Enterprise Communications Consultant and Technology Evangelist and the author of "Wink: Transforming Public Speaking With Clown Presence" available in paperback, eBook, hardcover, and audiobook through Amazon and all major retailers. He empowers leaders and enterprise organizations to connect more effectively through their messaging with new-school authenticity, spontaneous fun, and transformative results. For more information, check out:

https://www.winktechtalks.com

https://www.doncolliver.com/engage

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Ryan Spellman is the Managing Director, Cyber Risk Managing Director, Cyber Risk at K logix. There are many vCISO and other cyber security consultants who offer third-party risk services but have minimal exposure to the issues associated with third-party risk, which are markedly different than enterprise risk. Learn what a vTPCISO is, why it matters, and what questions to ask of your vCISO when they suggest adding third party risk service to their offerings.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

ChatGPT banned in Italy, regulatory action for internet connected medical devices, CISA KEV flaws affect 15 million public facing services, WordPress plugin active explout, German police raid DDoS hoster, Azure bug allowed critical system access, Cadbury Easter egg scam, and today's list - 12 tips for Microsoft Excel success.

https://www.bbc.com/news/technology-65139406

https://innovationorigins.com/en/us-regulator-takes-action-to-ensure-internet-security-in-connected-medical-devices/

https://www.bleepingcomputer.com/news/security/15-million-public-facing-services-vulnerable-to-cisa-kev-flaws/

https://hothardware.com/news/wordpress-sites-being-actively-exploited-thanks-to-plugins

https://krebsonsecurity.com/2023/03/german-police-raid-ddos-friendly-host-flyhosting/

https://www.scmagazine.com/news/cloud-security/azure-bug-allowed-access-to-critical-systems

https://www.infosecurity-magazine.com/news/cadbury-warns-of-easter-egg-scam/

https://cmitsolutions.com/blog/12-tips-for-microsoft-excel-success/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

IRS tax scam, phishing emails up over 500%, 3CX supply chain attack, insecure storing of work passwords, Defender oops, AlienFox, Apple security releases, Minnesota K-12, cyber legislation, and a preview of my BSides tak.

https://www.hackread.com/irs-tax-forms-w-9-email-scam-emotet-malware/

https://www.darkreading.com/attacks-breaches/phishing-emails-up-whopping-569-percent-2022

https://thehackernews.com/2023/03/3cx-supply-chain-attack-heres-what-we.html

https://www.infosecurity-magazine.com/news/70-employees-keep-work-passwords/

https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-mistakenly-tagging-urls-as-malicious/

https://securityaffairs.com/144239/cyber-crime/alienfox-toolset-cloud-service-providers.html

https://www.cisa.gov/news-events/alerts/2023/03/28/apple-releases-security-updates-multiple-products

https://sahanjournal.com/education/minnesota-legislature-education-cybersecurity-minneapolis-ransomware/

https://bsidesnash2023.sessionize.com/session/400189

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

For our special last Wednesday of the month episode for March, Greg van der Gaast joins us. Greg is an international speaker on Why Security Fails, IT Quality, Leadership, and Strategy. He also is a former hacker, FBI & DoD operative, author, advisor, CISO, and people and culture enthusiast. Listen to hear his fascinating story and what is a major threat for SMB information security that most don't consider. He can be reached at https://gregvandergaast.com/.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Bill Butler is an experienced Vice President Of Engineering with a demonstrated history of working in the hospital and health care and security compliance industry. He is the Founder and VP Engineering of PolicyCo (policyco.io), a platform that lets you tie Regulations, Policies, Procedures, Control Testing and Remediation together in a single platform, along with a host of other features like version control, reporting, sharing, attestations, and a public API.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Gordon Moore has died, ChatGPT bug exposed more, Windows snip vulnerability, a different take on BEC, North Dakota cyber education program, CISA pre-ransomware notifications initiative, proposed SWEC cyber regs, and today's list - 5 tips for cyber beginners.

  • https://nakedsecurity.sophos.com/2023/03/27/in-memoriam-gordon-moore-who-put-the-more-in-moores-law/
  • https://www.hackread.com/chatgpt-bug-exposed-payment-details/
  • https://thehackernews.com/2023/03/microsoft-issues-patch-for-acropalypse.html
  • https://www.bleepingcomputer.com/news/security/fbi-business-email-compromise-tactics-used-to-defraud-us-vendors/
  • https://www.kxnet.com/news/state-news/north-dakota-is-first-state-to-approve-required-cybersecurity-education/
  • https://securityaffairs.com/143990/security/cisa-pre-ransomware-notifications-intiative.html
  • https://www.natlawreview.com/article/divided-sec-proposes-slew-cybersecurity-regulations-securities-market-entities
  • https://alebogadodev.medium.com/5-essential-cybersecurity-tips-for-beginners-7544cf7d5a9c

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

GitHub rotates exposed private key, fake ChatGPT Chrome extension, ChatGPT bug leaked users' conversation histories, what type of identity are you talking to,SharePoint phishing scam, a common user mistake can lead to compromised Okta login credentials, update on the Dole breach, and today's list - six ways to secure an organization on a smaller budget.

https://www.bleepingcomputer.com/news/security/githubcom-rotates-its-exposed-private-ssh-key/

https://thehackernews.com/2023/03/fake-chatgpt-chrome-browser-extension.html

https://www.bbc.com/news/technology-65047304

https://www.darkreading.com/vulnerabilities-threats/are-you-talking-to-a-carbon-silicon-or-artificial-identity-

https://www.infosecurity-magazine.com/news/sharepoint-phishing-scam-targets/

https://www.helpnetsecurity.com/2023/03/23/discover-valid-okta-credentials/

https://securityaffairs.com/143902/data-breach/dole-food-company-data-breach.html

https://securityintelligence.com/articles/six-ways-to-secure-organization-on-smaller-budget/

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

From October 26, 2022 - In October 2022's special end of month Wednesday episode we talk with Marci McCarthy, CEO and President at T.E.N. CEO and Chairman at ISE® Talent. She founded T.E.N.’s flagship program, the Information Security Executive® of the Year (ISE®) Program Series, which is lauded by the IT industry as the premier recognition and networking program for security professionals in the U.S. and Canada. She is a 2012 recipient of a 4th Congressional District of Georgia Citation for fostering greater visibility and professionalism for the IT security industry, naming March 13th “Marci McCarthy Day.” She was listed as one of IFSEC Global’s Security and Fire Influencers for 2018 as #3 of 20 total leaders in their Cybersecurity category; she was also the highest-ranking woman on the list. She is also the DeKalb GOP Chairman (Georgia). She joins us to discuss information security and election integrity.

--- Send in a voice message: https://podcasters.spotify.com/pod/show/virtual-ciso-moment/message

View Details

Michael Lines is CISO for Open Technology Solutions, an expert in developing and leading information security and risk programs for organizations ranging from global enterprises to SaaS startup, and is authoring a book titled Heuristic Risk Management, dealing with why most risk management efforts are ineffective and what to do about it.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

NBA breach, Hinatabot botnet DDoS threat, Fortinet vuln exploited, Samsung zero days, ChatGPT cybersecurity potential, are cybersecurity jobs recession proof, and today's list - mistakes working from home.

https://securityaffairs.com/143693/data-breach/nba-data-breach.html

https://www.bleepingcomputer.com/news/security/new-hinatabot-botnet-could-launch-massive-33-tbps-ddos-attacks/

https://thehackernews.com/2023/03/chinese-hackers-exploit-fortinet-zero.html

https://www.scmagazine.com/news/device-security/18-zero-day-samsung-android-wearables-telematics

https://www.helpnetsecurity.com/2023/03/17/chatgpt-cybersecurity-potential/

https://www.techtarget.com/searchsecurity/tip/Is-cybersecurity-recession-proof

https://erikchristianjohnson.com/working-from-home-mistakes-you-dont-want-to-make/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Ransomware gangs breached the networks of at least 860 critical infrastructure organizations last year, multiple threat actors exploited a critical three-year-old security flaw in Progress Telerik to break into an unnamed federal entity in the U.S., two us citizens charged for hacking into DEA portal in 2022, Chinese influence operations are growing more aggressive, Lockbit broke into Maximum Industries (which makes parts for SpaceX), Chinese and Russian hackers using SILKLOADER malware to evade detection, UK bans TikTok from government mobile phones, plus The LIST - Sophos best practices for securing your firewall.

https://www.bleepingcomputer.com/news/security/fbi-ransomware-hit-860-critical-infrastructure-orgs-in-2022/

https://thehackernews.com/2023/03/multiple-hacker-groups-exploit-3-year.html

https://www.hackread.com/us-citizens-charged-hacking-dea/

https://cyberscoop.com/china-worldwide-threats-cyber/

https://www.theregister.com/2023/03/13/lockbit_spacex_ransomware/

https://thecybersecurity.news/general-cyber-security-news/chinese-and-russian-hackers-using-silkloader-malware-to-evade-detection-25218/

https://www.theguardian.com/technology/2023/mar/16/uk-bans-tiktok-from-government-mobile-phones

https://news.sophos.com/en-us/2023/03/16/best-practices-for-securing-your-firewall/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From October 25, 2023 - Albert Whale, Founder and CEO of IT Security Solutions, Inc and the developer of ITS Safe which provides real-time continuous protection at machine speed. He has over 30 years of experience with reducing the risk for business owners, minimizing their liabilities and overall risk. He has extensive experience in the techniques that criminal hackers use and identifies the probability and impact risks to exploit their business. He is the author of #Hacked and the primary author of #Hacked2.  https://its-safe.com/ https://thehackedbook2.com/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Carlota Sage is the Founder and Community CISO for Pocket CISO, thrives in that squishy area where business and technology meet human nature, and builds the relationships that get security, technology, business processes and people working together better, and has a background that includes information architecture, enterprise infrastructure, information security, and knowledge management. Among other things we discuss the vCISO space and the importance of brake lines!

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Silicon Valley Bank fallout, AI risks to business, AI generated YouTube risks, how to master cyber threat intel skills, and eight websites to check if an email address was compromised.

https://www.nbcnews.com/business/business-news/treasury-says-will-back-silicon-valley-bank-deposits-rcna74570

https://nypost.com/2023/03/13/hsbc-will-buy-uk-subsidiary-of-collapsed-silicon-valley-bank/

https://www.helpnetsecurity.com/2023/03/13/svb-cyber-fraud/

https://securityaffairs.com/143394/security/company-data-chatgpt-risks.html

https://thehackernews.com/2023/03/warning-ai-generated-youtube-video.html

https://infosecwriteups.com/how-to-master-in-real-cyber-threat-intelligence-build-military-grade-intelligence-skills-7df418b4b508

https://infosecwriteups.com/8-free-websites-to-check-if-your-email-address-is-compromised-7e8742e099c6

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.tsa.gov/news/press/releases/2023/03/07/tsa-issues-new-cybersecurity-requirements-airport-and-aircraft

https://www.bleepingcomputer.com/news/security/sonicwall-devices-infected-by-malware-that-survives-firmware-upgrades/

https://thehackernews.com/2023/03/lastpass-hack-engineers-failure-to.html

https://www.theregister.com/2023/03/08/acer_confirms_server_breach/

https://krebsonsecurity.com/2023/03/sued-by-meta-freenom-halts-domain-registrations/

https://www.bleepingcomputer.com/news/security/duckduckgo-launches-ai-powered-search-query-answering-tool/

https://www.nist.gov/itl/applied-cybersecurity/nice/resources/veteran-resources

https://www.hackread.com/businesses-focus-on-cybersecurity/

https://www.helpnetsecurity.com/2023/03/08/building-perfect-cybersecurity-startup/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From October 19. 2022 - Jon Sternstein is the Founder and Principal of Stern Security, a cyber security company headquartered in Raleigh, NC. He is co-author of the Cisco Press course titled “Security Penetration Testing (The Art of Hacking) LiveLessons”, holds many security certifications including: GIAC Penetration Tester and Certified Information Systems Security Professional (CISSP), is a featured cyber security expert, and talks with us about managing risks - and a little guitar! Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Dave Sobel is the host of the Business of Tech podcast (https://www.businessof.tech/), a leading IT services focused news and analysis podcast and YouTube show, and owner of MSP Radio. He is regarded as a leading expert in the delivery of technology services, with broad experience in both technology and business. He owned and operated an IT Solution Provider and MSP for over a decade, both acquiring other organizations and eventually being acquired. Dave holds a bachelor's degree in Computer Science from the College of William and Mary. He is a dynamic voice within the IT community, a former member and facilitator for Heartland Technology Groups and passionate about collaborating with clients and peers on utilizing technology to advance organizations.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.washingtonpost.com/technology/2023/03/05/ai-voice-scam/

https://securityaffairs.com/143051/data-breach/credential-stuffing-chick-fil-a.html

https://www.bitdefender.com/blog/hotforsecurity/recent-cybersecurity-study-reveals-top-us-states-to-suffer-data-breaches/

https://www.sfgate.com/tech/article/oakland-ransomware-attackers-may-leak-data-17818589.php

https://www.cisa.gov/news-events/alerts/2023/03/01/cisa-releases-decider-tool-help-mitre-attck-mapping

https://www.helpnetsecurity.com/2023/03/01/burp-suite-penetration-testing-extensions/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.wsj.com/articles/biden-national-cyber-strategy-seeks-to-hold-software-firms-liable-for-insecurity-67c592d6

https://www.reuters.com/technology/white-house-gives-agencies-30-days-impose-federal-device-tiktok-ban-2023-02-27/

https://krebsonsecurity.com/2023/02/hackers-claim-they-breached-t-mobile-more-than-100-times-in-2022/

https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/

https://piunikaweb.com/2023/03/02/windows-calendar-app-crashing-or-not-opening-fix-in-works/

https://www.insurancejournal.com/news/national/2022/08/30/682564.html

https://www.bankinfosecurity.com/10-belt-tightening-tips-for-cisos-to-weather-downturn-a-21321

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From October 19, 2022 - Keith Maune, Founder & COO at Acumen Technology, discusses his IT and cybersecurity path, from doing consulting work for companies needing website design and programming services, working after school and full-time during the summers, pursuing a BS and MBA while working full-time as co-owner and CIO of Advanced Network Solutions, earning a law degree, and launching Acumen Technology, a comprehensive managed services organization that serves Middle Tennessee as the premier IT services provider for community banks, healthcare providers, and professional services organizations.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Caroline McCaffery is a lawyer who started a data privacy and cybersecurity technology company called ClearOPS to provide technology to virtual CISOs. B2B2B It is a customer relationship management tool + work automation for managing security programs, such as vendor management, gap analysis, security posture and security questionnaire response. She also hosts The vCISO Chronicles, a new podcast series focused on telling the stories of virtual CISOs.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Dennis Davoren is a vCISO, PhD Candidate, and Green Belt Six Sigma. He also is a veteran, having been an Air Force Instructor and Command Pilot along with being a Commander. He is an experienced leader with a demonstrated successful history of working in the Military, Marketing & Advertising industry, and Cyber Security/IT field. Skilled in Intelligence Analysis, Enterprise Risk Management, Financial Risk Management, Intelligence, and Risk Assessment. He is a Subject Matter Expert(SME) on Government Regulation Compliance(GRC) and CMMC 2.0 implementation. He holds a Master of Science degree focused on Cyber Security Management. We discuss the virtual CISO field and how risk management in flying translates to risk management in information security.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.smh.com.au/national/fake-russian-diplomats-revealed-as-heart-of-hive-spy-ring-in-australia-20230223-p5cmxz.html

https://www.businessinsider.com/hackers-ransomware-getting-laid-off-amid-better-cybersecurity-report-2023-2

https://www.abc.net.au/news/2023-02-27/national-cyber-office-to-be-established-in-wake-of-optus-hack/102026156

https://www.secureworld.io/industry-news/european-commission-tiktok-ban

https://www.darkreading.com/risk/1-in-4-cisos-will-leave-cybersecurity-by-2025

https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF

https://www.tripwire.com/state-of-security/ways-cyber-attackers-are-looking-exploit-government-agencies

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.csoonline.com/article/3688988/5-top-threats-from-2022-most-likely-to-strike-in-2023.html

https://www.bitdefender.com/blog/labs/weaponizing-pocs-a-targeted-attack-using-cve-2022-47966/

https://www.foxnews.com/politics/us-military-email-server-left-exposed-two-weeks-allowing-internal-emails-leak

https://thehackernews.com/2023/02/apple-warns-of-3-new-vulnerabilities.html

https://techxplore.com/news/2023-02-illinois-supreme-court-massive-biometric.html

https://www.darkreading.com/analytics/cyberattack-dole-causes-temporary-salad-shortage

https://www.csoonline.com/article/3688554/what-is-traffic-light-protocol-and-how-it-supports-cisos-to-share-threat-data.html

https://www.csoonline.com/article/3688988/5-top-threats-from-2022-most-likely-to-strike-in-2023.html

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From October 12, 2022 - Michelle Pupoh is the Senior Director of Cybersecurity Education at the Carolina Cyber Center. She discusses the approach the center takes in training the next generation of cyber professionals, including the importance of ethics and soft skills. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Jean-Christophe (J.C.) Gaillard is the founder and CEO of Corix Partners, a London-based Boutique Management Consultancy Firm and Thought-Leadership Platform focused on assisting CIOs and other C-level executives in resolving Cyber Security Strategy, Organisation and Governance challenges. He is a leading advisor, senior executive and global cyber security influencer with over 25 years of experience developed in several financial institutions in the UK and continental Europe, and a track-record at driving fundamental change in the Security field across global organisations, looking beyond the technical horizon into strategy, governance, culture, and the real dynamics of transformation.He is also the author of "Cyber Security: The Lost Decade - A Security Governance Handbook for the CISO and the CIO" and "The CyberSecurity Leadership Handbook for the CISO and the CEO".

https://www.amazon.com/dp/B0BW51C5J1/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Ray Harrison is a cyber security consultant with Abira Security, a consistent top sales performer, people oriented, reliable, and loyal. He also has a servant heart and leads the Faith in Jesus Forum, a LinkedIn group for Christians seeking to grow in their faith in Jesus and share with others along the way and those seeking to learn more about faith in Jesus. 

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.cnn.com/2023/02/17/politics/fbi-cyber-incident-computer-network

https://www.bleepingcomputer.com/news/security/godaddy-hackers-stole-source-code-installed-malware-in-multi-year-breach/

https://iapp.org/news/a/proposed-cpra-regulations-finalized-cppa-targets-april-effective-date/

https://fortune-com.cdn.ampproject.org/c/s/fortune.com/2023/02/15/cost-cybersecurity-insurance-soaring-state-backed-attacks-cover-shmulik-yehezkel/amp/

https://www.forbes.com/sites/tracybrower/2023/01/29/managers-have-major-impact-on-mental-health-how-to-lead-for-wellbeing/?sh=58999ec32ec1

https://cyber-center.org/the-great-ciso-resignation/amp/

https://www.linkedin.com/posts/information-systems-security-association-issa-_did-you-catch-the-february-featured-article-activity-7032416184629174272-RyOm

https://www.linkedin.com/feed/update/urn:li:activity:7033179906029035520/

https://www.imdb.com/title/tt26748133/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.secureworld.io/industry-news/apple-security-update-patch-zero-day

https://www.theregister.com/2023/02/14/microsoft_adobe_patch_tuesday/

https://techmonitor.ai/technology/cybersecurity/lockbit-spree-hits-three-large-companies

https://cybernews.com/news/california-health-network-ransomware-attack/

https://thehackernews.com/2023/02/massive-http-ddos-attack-hits-record.html

https://www.bleepingcomputer.com/news/security/atlassian-says-recent-data-leak-stems-from-third-party-vendor-hack/

https://www.scmagazine.com/news/critical-infrastructure/what-to-expect-from-the-upcoming-national-cyber-strategy

https://www.csoonline.com/article/3687812/5-major-risks-third-party-services-may-bring-along-with-them.html

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From October 11, 2023 - David Leech is a vCISO using his global, operational, program management, and security experience together with leadership skills to drive digital transformation, product innovation, and risk reduction for business growth, involving work across Risk Management, Technical Architecture, Control Frame Works, HIPAA, FFIEC, PCI, HITRUST, FedRamp, and SOC compliance. He has supported clients in multiple sectors, including Finance, Manufacturing, Insurance, Healthcare and GovEd.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

In this special Wednesday edition, Aaron Robel is a CISO with a positive, energetic, and transparent approach that fosters trust and collaboration across the business. He has a consistent track record for developing high-performing security programs and teams that bring business value while maintaining the organization's risk posture. We discuss infosec in the financial services sector, as his current role is CISO for a credit union and I am a former bank CISO and currently work with several financial institutions as a virtual CISO.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Ted Ilanchelian is President of CMIT Solutions of Brentwood and Franklin, a one-stop technology solution provider offering Small and Midsized Businesses (SMBs) enterprise-level IT infrastructure support and cybersecurity solutions at an affordable price. He is passionate about helping SMBs, noting that "attitude" is one of the most significant infosc threats SMBs face. Watch or listen to find out more!

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.techrepublic.com/article/how-it-recruiting-dark-web-trick/

https://www.csoonline.com/article/3687222/yes-cisos-should-be-concerned-about-the-types-of-data-spy-balloons-can-intercept.html

https://thehackernews.com/2023/02/north-korean-hackers-targeting.html

https://www.darkreading.com/risk/reddit-hack-shows-limits-mfa-strengths-security-training

https://www.forbes.com/sites/forbestechcouncil/2023/02/09/why-cybersecurity-professionals-need-to-understand-a-hackers-perspective/

https://cioviews.com/5-reasons-to-hire-a-virtual-chief-information-security-officer-in-2023/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.darkreading.com/vulnerabilities-threats/lessons-from-the-cold-war-how-quality-trumps-quantity-in-cybersecurity

https://www.secureworld.io/industry-news/cybersecurity-experts-super-bowl

https://thehackernews.com/2023/02/critical-infrastructure-at-risk-from.html

https://www.techrepublic.com/article/execs-expect-cyberattacks/

https://www.csoonline.com/article/3687137/vulnerabilities-and-exposures-to-rise-to-1900-a-month-in-2023-coalition.html

https://www.careersincyber.com/article/cybersecurity-predictions-for-2023/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From October 5, 2023 - Joe Jakubielski is a Cyber Defense Analyst with the Carolina Cyber Center. He discusses his recent pivot to a new career in cyber, including challenges and opportunities ahead. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Dustin Sachs is an expert in cyber supply chain risk management, Sr. Manager GRC at World Fuel Services, a doctoral candidate at Colorado Tech, a mentor at Springboard, and a future CISO. He is passionate about giving back to the cybersecurity community and also about GRC.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

https://www.reuters.com/legal/legalindustry/sec-reveals-2023-priorities-new-agenda-2023-01-31/

https://www.darkreading.com/mobile/hornetsecurity-combats-qr-code-phishing-with-launch-of-new-technology

https://www.secureworld.io/industry-news/security-concerns-businesses-chatgpt

https://thehackernews.com/2023/02/new-wave-of-ransomware-attacks.html

https://www.techrepublic.com/article/the-importance-of-data-retention-policies/

LIST

https://www.darkreading.com/edge-articles/what-cisos-can-do-about-brand-impersonation-scam-sites

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

  • https://thehackernews.com/2023/02/new-high-severity-vulnerabilities.html
  • https://nakedsecurity.sophos.com/2023/02/01/password-stealing-vulnerability-reported-in-keypass-bug-or-feature/
  • https://www.techrepublic.com/article/cybersecurity-bec-attack-mimics-vendors/
  • https://financialit.net/news/security/romance-scammers-break-over-60-hearts-and-wallets-every-week-warns-tsb-bank-reveals
  • https://www.cnn.com/2023/01/31/politics/ransomware-attack-schools-nantucket/index.html
  • https://techunofficial.com/openai-launches-chatgpt-plus-starting-at-20-per-month
  • https://cybersecurity.att.com/blogs/security-essentials/the-top-8-cybersecurity-threats-facing-the-automotive-industry-heading-into-2023

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From October 4, 2022 - Gary Chan of Alfizo LLC helps businesses stay secure from hackers and insider threats, meet legal and regulatory compliance, and enable sales by meeting their customers' expectations for security. He is also a "security mentalist", and if you're like me and have never heard of this term, you need to check out this episode - it's fascinating!

Gary's websites:

• Creating memorable experiences for corporate audiences, https://www.gschan2000.com/
• Helping organizations build their information security programs, https://alfizo.com/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Derek Morris is a virtual Chief Information Security Officer (vCISO) with almost 3 decades in IT, Information Security, Cybersecurity. He possesses numerous industry certifications including: CISSP, CISM, CISA, CDPSE, PCI-QSA, CCSFP, CCNA, and MCSA. Bachelor's Degree in Computer Information Systems from Bryant University with a minor in Applied Statistics. We discuss the virtual CISO space and what to look for in a virtual CISO, including "IT empathy".

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Links:

  • https://www.bbc.com/news/business-64452986
  • https://heimdalsecurity.com/blog/new-mimic-ransomware-uses-windows-search-engine-to-find-and-encrypt-files/
  • https://www.bankinfosecurity.com/blogs/targets-opportunity-how-ransomware-groups-find-victims-p-3365
  • https://www.securityweek.com/the-effect-of-cybersecurity-layoffs-on-cybersecurity-recruitment/
  • https://coruzant.com/security/three-essential-proactive-steps-for-keeping-enterprises-cybersecure/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Article links: 

  • https://www.theguardian.com/us-news/2023/jan/26/hive-ransomware-servers-seized-us
  • https://www.msn.com/en-us/news/technology/microsoft-365-outages-affect-office-teams-and-more/ar-AA16IX6
  • https://www.securityweek.com/us-government-agencies-warn-of-malicious-use-of-remote-management-software/
  • https://www.darkreading.com/application-security/compromised-zendesk-employee-credentials-breach
  • https://www.usnews.com/news/national-news/articles/2023-01-25/americas-broken-system-for-classifying-information
  • https://thehackernews.com/2023/01/is-once-yearly-pen-testing-enough-for.html
  • https://www.csoonline.com/article/3686118/9-api-security-tools-on-the-frontlines-of-cybersecurity.html

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From September 28, 2022 -  Mark Burnette, Shareholder-In-Charge at LBMC Information Security, discusses his path from Senior IT Auditor to overseeing and directing LBMC’s Risk Services practice nationwide. He is very active in the information security community, including as co-founder and past president of the Middle Tennessee ISSA chapter (one of the largest in the world), and co-founder and board member of the Southern CISO Security Council. His certifications include CPA, CISA, CISSP, CISM, and CRISC, and he frequently speaks on information security topics, including a fabulous TEDx talk on the Humanity Behind Cyber Attacks - https://www.ted.com/talks/mark_burnette_the_humanity_behind_cybersecurity_attacks.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

BJ Withrow, Manager, Major Accounts, East Coast at Tenable, is a self-proclaimed geek at heart and cybernerd by trade. When he is passionate about something, it comes out in everything he does, and he loves what he does. We cover a variety of topics, including cybersecurity for small and midsized businesses, exercising, and the importance of a servant's heart.

Note a production error resulted in mismatched video and audio for host, not guest. We have switched platforms going forward because of this issue.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Southwest upgrades, NIST CSF update, ransomware affects 1000 ships' connectivity,  ransomware threat in next 24 months, iOS 12 zero-day fix, SCOTUS infosec risk management fails, securing IoT (list), my appearance this morning on the KAJMasterclass, and a thanks to Cynomi for including me as a top vCISO influencer.

  • https://www.ciodive.com/news/southwest-airlines-technology-data-upgrades-FAA/640890/
  • https://news.yahoo.com/southwest-didnt-heed-calls-upgrade-020007630.html
  • https://www.nextgov.com/cybersecurity/2023/01/nist-releases-potential-updates-its-cybersecurity-framework/381970/
  • https://www.theregister.com/2023/01/19/ransomware_attack_cuts_1000_ships/
  • https://www.darkreading.com/attacks-breaches/organizations-likely-to-experience-ransomware-threat-in-the-next-24-months-according-to-info-tech-research-group
  • https://nakedsecurity.sophos.com/2023/01/24/apple-patches-are-out-old-iphones-get-an-old-zero-day-fix-at-last/
  • https://www.csoonline.com/article/3685938/us-supreme-court-leak-investigation-highlights-weak-and-ineffective-risk-management-strategy.html#tk.rss_all
  • https://www.techrepublic.com/article/securing-edge-securing-iot-devices/
  • https://www.youtube.com/watch?v=vHyQyfRa4So&ab_channel=TheKAJMasterclassLIVE
  • https://www.cynomi.com/blog/top-12-vciso-influencers/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

T-Mobile breach (again), MailChimp breach (again), ransomware payments down, TikTok fined for cookie issue, Avast posts decryptor for BianLian, five trends for 2023, and leveraging LNK files. 

  • https://www.wsj.com/articles/t-mobile-says-hackers-stole-data-on-about-37-million-customers-11674166048
  • https://techcrunch.com/2023/01/19/t-mobile-data-breach/
  • https://www.msn.com/en-gb/money/technology/mailchimp-suffers-another-major-data-breach-following-employee-hack/ar-AA16w1Z3
  • https://www.theregister.com/2023/01/19/ransomware_payments_down/
  • https://www.secureworld.io/industry-news/tiktok-fined-cookie-policies
  • https://www.scmagazine.com/news/ransomware/avast-posts-decryptor-for-the-bianlian-ransomware
  • https://www.enterprisetimes.co.uk/2022/12/22/the-security-outlook-for-2023-five-trends/
  • https://thehackernews.com/2023/01/new-research-delves-into-world-of.html
  • https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rise-of-lnk-shortcut-files-malware/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From September 27, 2022 - Cy Sturdivant, Director at Forvis (Cybersecurity Division), joins us to discuss his path from accounting and finance to cybersecurity and the audit field. We dive into controls, the Three Line of Defense model, and how audit as the third line helps organizations achieve and maintain a solid information security posture.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Brent Forrest is a leader, architect, and strategic advisor of holistic cybersecurity. He has developed security programs across Oil & Gas, Financial, Insurance, and Construction industries including architecture of endpoint visibility/protection, managed detection and response (MDR), and security awareness as well as leading real-world cyberbreach response efforts. He is a graduate of Western Governors University and a holder of CISSP, C|CISO, and other technology certifications.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Malware attack on CircleCI, FortiOS vuln exploited, RTU ransomware attack, Lifelock compromise, Cloudflare and .gov, how and why to improve security culture, and nine top-of-mind issues for CISOs in 2023.

  • https://thehackernews.com/2023/01/malware-attack-on-circleci-engineers.html
  • https://www.csoonline.com/article/3685670/attackers-deploy-sophisticated-linux-implant-on-fortinet-network-security-devices.html#tk.rss_all
  • https://industrialcyber.co/industrial-cyber-attacks/hacker-group-discloses-ability-to-encrypt-an-rtu-device-using-ransomware-industry-reacts/?
  • https://www.darkreading.com/remote-workforce/norton-lifelock-warns-on-password-manager-account-compromises
  • https://www.darkreading.com/attacks-breaches/cloudflare-wins-cisa-contract-for-registry-and-authoritative-domain-name-system-dns-services
  • https://www.tripwire.com/state-of-security/c-suite-security-how-it-teams-improve-security-culture
  • https://blogs.cisco.com/security/nine-top-of-mind-issues-for-cisos-going-into-2023

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

US air grounding due to one engineer's error, vuln in chromium browsers, Citrix vuln, Tech Republic bundle offer, 10 penetration testing decision factors, and why soft skills are necessary in infosec.

  • https://www.dailymail.co.uk/news/article-11628753/FAA-flight-grounding-debacle-stranded-tens-thousands-hours-caused-engineer.html
  • https://thehackernews.com/2023/01/experts-detail-chromium-browser.html
  • https://www.csoonline.com/article/3685414/royal-ransomware-group-actively-exploiting-citrix-vulnerability.html#tk.rss_all
  • https://www.techrepublic.com/article/explore-information-security-huge-course-bundle/
  • https://christianespinosa.com/blog/top-10-penetration-testing-decision-factors/
  • https://technative.io/why-soft-skills-are-key-to-filling-the-digital-talent-gap/

If you're interested in filling the gap for Tuesday's episode please send me an email at greg@gregschaffer.info.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From September 20, 2022: Adam Bricker has led many career lives, from working on Tomahawk missiles to cofounding the Carolina Cyber Center, focused on hardening community resources and continuing education to address the nation's critical cybersecurity talent shortfall. He currently provides consulting services for businesses in high tech, IT-enabled and emerging markets as the founder of ePower Learning, and his testimony of faith in relation to his callings is truly inspirational.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Mary-Michael Horowitz, CISM, is the Founding Partner/CEO at Asylas, LLC. Asylas is a cybersecurity solutions firm heavily focused on remarkable service and customized approaches to security, privacy and risk consulting. We discuss small and midsized business security challenges, including passwords and password managers.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Experian security flaw, CISOs focus on three trends, email services encryption, importance of SaaS user permissions, $24B MATIC coin risk, and today's list: 10 CRUCIAL cybersecurity tips for small business.

  • https://krebsonsecurity.com/2023/01/identity-thieves-bypassed-experian-security-to-view-credit-reports/
  • https://www.darkreading.com/microsoft/cisos-are-focused-on-these-3-trends-are-you-
  • https://www.techrepublic.com/article/cloud-email-services-bolster-encryption-against-hackers/
  • https://thehackernews.com/2023/01/why-do-user-permissions-matter-for-saas.html
  • https://www.cpomagazine.com/cyber-security/critical-vulnerability-that-put-24-billion-in-matic-coins-at-risk-patched-by-polygon/
  • https://esabda.com/10-crucial-cybersecurity-tips-for-small-business/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Flipper phish, Slack breach, LastPass last trust, Twitter account info for free, Iran DDoS attack, data privacy trends, and a question of whether or not to use a VPN firewall (feedback encouraged, email greg@gregschaffer.info).

  • https://www.bleepingcomputer.com/news/security/ongoing-flipper-zero-phishing-attacks-target-infosec-community/
  • https://cybernews.com/security/slack-admits-security-breach/
  • https://www.pcmag.com/opinions/lastpass-is-losing-our-trust
  • https://www.forbes.com/sites/petersuciu/2023/01/04/data-from-200-million-twitter-users-offered-for-free-on-hacker-forum/
  • https://www.jpost.com/middle-east/iran-news/article-726852
  • https://www.law360.com/articles/1559756/5-data-privacy-law-trends-that-will-continue-into-2023

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From September 13, 2022 - Elvis Huff is the Vice President - Director of Security/Information Security Officer for Wilson Bank and Trust. His path to bank ISO is not typical but is inspirational, with 12 years as a police officer prior to entering the world of banking. His reason for the transition involves faith and following a calling. He also produces an awesome security newsletter, Security Stuff with Elvis Huff - check it out at https://www.wbtsecurityblog.com/!

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

For our kickoff episode of Season Five, Dave Evangelista joins us. He has 20 years of experience with financial institutions and is currently the Vice President Information Technology for a midwestern credit union where he is responsible for the tactical direction, control, and ongoing analysis and planning for the credit union’s IT environment. Infrastructure, Operations, Critical Systems, Information Security, Development, e-Services, Service Delivery, Digital and Technology Support. He also has 24 years of law enforcement experience, including as a Kentucky certified Cyber and Financial Crimes Investigator, Kentucky certified Advanced Internet Crimes Investigator, election consultant on crimes against children to former Governor Ernie Fletcher, founder  and executive director for the United States Internet Crime Task Force (1998-2020), and is a recognized expert witness on digital forensics.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Twitter GDPR investigation, ransomware group clones victim's site, LockBit apologizes to children's hospital, ransomware ecosystem diversifying, IT Pros' cybersecurity fears, FinTech cybersecurity issues, and cybersecurity tools to keep you safe as a remote worker...sort of.

  • https://gdprbuzz.com/news/twitter-faces-investigation-in-ireland-over-data-breach/
  • https://www.bleepingcomputer.com/news/security/ransomware-gang-cloned-victim-s-website-to-leak-stolen-data/
  • https://www.bleepingcomputer.com/news/security/ransomware-gang-apologizes-gives-sickkids-hospital-free-decryptor/
  • https://www.csoonline.com/article/3684248/ransomware-ecosystem-becoming-more-diverse-for-2023.html
  • https://securityboulevard.com/2023/01/an-overview-of-cybersecurity-issues-faced-by-the-fintech-industry/
  • https://www.digitalinformationworld.com/2023/01/85-of-it-pros-fear-cybersecurity-issues.html
  • https://www.makeuseof.com/best-free-cybersecurity-tools-to-keep-you-safe-as-a-remote-worker/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Ransomware not covered by cyber insurance, cyberattacks may be impossible to insure without some changes, whatever happened to UEBA, 100,000 students have their data exposed, six tips for hiring cybersecurity talent, and my predictions for 2023.

  • https://www.jurist.org/news/2022/12/ohio-supreme-court-says-insurance-policy-does-not-cover-ransomware-attack-on-software/
  • https://www.techspot.com/news/97118-cyberattacks-could-soon-become-impossible-insure.html
  • https://www.darkreading.com/dr-tech/how-to-get-the-most-out-of-ueba?
  • https://www.bitdefender.com/blog/hotforsecurity/renowned-education-platform-leaks-personal-data-of-100-000-students-online/
  • https://www.forbes.com/sites/forbestechcouncil/2022/12/22/six-ways-to-pivot-hiring-strategies-to-attract-cybersecurity-talent/?sh=2b3a54af742e

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From September 6, 2022 - Donna Gallaher, President and CEO of New Oceans Enterprises, LLC, is a seasoned IT and information security pro providing virtual CISO and risk management services. She is a FAIR (Factor Analysis of Information Risk) evangelist and is passionate about growing the virtual CISO community, including serving on the Board of Directors for vCISO Catalyst, a Public Benefit Corporation supporting the improvement of cybersecurity programs of small and medium businesses. If you have never heard of FAIR or are interested in the virtual CISO field (or both), check out this episode!

New Oceans Enterprises, LLC - https://www.newoceansenterprises.com/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Michelle Drolet is a highly experienced information security expert who is well respected by clients, information security peers and analysts. Ms. Drolet is a sought-out speaker, panelist, and is a regular contributor to leading online publications such as Forbes Technology Council, Wired.com and IDG CSO Online. We discuss SMB security needs and challenges and how services such as a virtual CISO can be an effective solution.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

BetMGM breach, search engine ad attacks, ransomware with new encryption algorithm, new ransomware served by PrivateLoader, and an update on the LastPass breach, with some thoughts.

  • https://www.bleepingcomputer.com/news/security/leading-sports-betting-firm-betmgm-discloses-data-breach/
  • https://www.infosecurity-magazine.com/news/fbi-cyber-search-engine-ads-attacks/
  • https://cybersecuritynews.com/vice-ransomware-group-uses-custom-ransomware-with-new-encryption-algorithms/
  • https://thehackernews.com/2022/12/privateloader-ppi-service-found.html
  • https://www.msn.com/en-us/money/technology/if-youve-ever-used-lastpass-you-should-change-all-your-passwords-now/ar-AA15FqPc
  • https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Okta breach, Gmail client side encryption, avoid clicking bad links not enough, and more predictions!

  • https://www.bleepingcomputer.com/news/security/oktas-source-code-stolen-after-github-repositories-hacked/amp/
  • https://www.zdnet.com/article/google-brings-client-side-encryption-to-gmail-for-workspace/
  • https://www.ncsc.gov.uk/pdfs/blog-post/telling-users-to-avoid-clicking-bad-links-still-isnt-working.pdf
  • https://www.trendmicro.com/en_us/ciso/22/l/cyber-security-posture-2023-predictions.html
  • https://venturebeat.com/security/microsoft-cybersecurity-predictions/
  • https://venturebeat.com/security/2023-cybersecurity-forecasts-zero-trust-cloud-security-will-top-spending/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From August 31, 2022 - Scott Augenbaum was a special agent with the FBI and now continues his mission to help prevent businesses from becoming a victim of cybercrime as an author, speaker, and trainer. His story and mission is educational and inspirational! Check out https://www.cybersecuremindset.com/ and connect with Scott at https://www.linkedin.com/in/saugenbaum/.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

I'm producing a limited YouTube series on lessons I've learned from being a successful consulting business owner. It's not all sunshine and roses, and I've made a lot of mistakes, but I've learned from them. Here are the latest two episodes - Consulting: Cyber Concerns and Consulting: Business Concerns. If you find these interesting and useful, please subscribe to the vCISO Services, LLC YouTube channel (link below) to be notified when future episodes drop.

https://youtube.com/@vciso

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

NY hospitals cyber attack, AI to take phishing to new level, last two months busiest for ransomware, how to lower cyber insurance costs, joint advisory on BEC for stealing food, and Uber data breach caused by third-party vendor.

  • https://www.cbsnews.com/newyork/news/one-brooklyn-health-battling-cyber-attack-that-forced-some-critical-services-offline/
  • https://www.bankinfosecurity.com/new-ai-bot-could-take-phishing-malware-to-whole-new-level-a-20709
  • https://blog.knowbe4.com/october-and-november-have-been-the-two-busiest-months-for-ransomware
  • https://www.scmagazine.com/perspective/strategy/what-companies-can-do-to-lower-cyber-insurance-costs
  • https://us-cert.cisa.gov/ncas/current-activity/2022/12/16/fbi-fda-oci-and-usda-release-joint-cybersecurity-advisory
  • https://www.cpomagazine.com/cyber-security/uber-data-breach-of-employee-information-caused-by-third-party-vendor/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Infragard hacked, Google OSV Scanner tool, Atlassian issue, CSAF may help vuln management, reviewing the AUP, cybersecurity risks for banks and credit unions, and more predictions! Plus a word of advice regarding the job interview process based on a recent real-world example.

  • https://krebsonsecurity.com/2022/12/fbis-vetted-info-sharing-network-infragard-hacked/
  • https://thehackernews.com/2022/12/google-launches-largest-distributed.html
  • https://cloudsek.com/security-flaw-in-atlassian-products-jira-confluencetrello-bitbucket-affecting-multiple-companies/
  • https://www.darkreading.com/threat-intelligence/csaf-is-the-future-of-vulnerability-management
  • https://www.csoonline.com/article/3682760/how-acceptable-is-your-acceptable-use-policy.html
  • https://thefinancialbrand.com/news/banking-technology/rising-cybersecurity-risks-will-plague-banking-brands-in-2023-156888/
  • https://venturebeat.com/security/sans-cybersecurity-predictions/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From August 30, 2022 - Susan Richards is a dynamic director of Information Security concentrated in compliance, project management, application development, and database administration. She is skilled in IT Strategy, Management, Compliance Assurance, and Risk Management including HITRUST, NIST and ISO security frameworks. She is also very involved in the information security community, including ISSA chapter leadership and has this year started a local HITRUST chapter - plus we discuss election integrity!

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Greg Flatt is the founder of Flatt Earth Networking, Inc. Since 1996, Flat Earth Networking, Inc. has provided mid- to large-sized businesses an authoritative approach to network security that includes superior enterprise products and effective problem-solving. Greg discusses his path beginning and growing Flat Earth Networking, Inc. over the past 26 years.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

You can bet on increasing cyberattacks on casinos, new air gap attack method, education institutes have higher cyber risk this time of year, is cyber security being taught correctly, Sequoia PEO data breach, QA error turns ransomware into wiper, and cars' data easily accessed by law enforcement.

  • https://cdcgaming.com/experts-warn-of-further-cyberattacks-on-casinos/
  • https://heimdalsecurity.com/blog/covid-bit-a-new-attack-method-that-can-breach-air-gapped-pcs/
  • https://universitybusiness.com/for-cybercriminals-the-holidays-are-the-most-wonderful-time-of-the-year/
  • https://www.bcs.org/articles-opinion-and-research/is-cyber-security-being-taught-correctly/
  • https://www.wired.com/story/sequoia-hr-data-breach/
  • https://www.bitdefender.com/blog/hotforsecurity/design-flaw-accidentally-turns-open-source-ransomware-toolkit-into-wiper-malware/
  • https://www.forbes.com/sites/thomasbrewster/2022/12/01/10000-cars-can-be-data-raided-by-police-ice-cbp-love-it/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

Why SMBs should prioritize outsourcing cybersecurity, an interesting observation on the IHG cyberattack, log4j persists, the main cause of cybersecurity incidents, and this week's predictions discussed - plus why we made our next position entry level.

  • https://www.standard.co.uk/tech/why-smes-should-prioritise-outsourcing-cyber-security-b1006499.html
  • https://www.cpomagazine.com/cyber-security/it-should-not-take-a-cyberattack-to-force-changes-at-our-biggest-hotel-chains/
  • https://www.tenable.com/press-releases/tenable-research-finds-72-of-organizations-remain-vulnerable-to-nightmare-log4j
  • https://www.digit.fyi/whats-the-main-cause-of-avoidable-cybersecurity-incidents/
  • https://venturebeat.com/security/forrester-analysts-share-5-shocking-cybersecurity-predictions-for-2023/
  • https://www.indeed.com/job/information-security-analyst-i-7f8fce23ece0695f

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/message

View Details

From Auguat 23, 2022 - Vanessa Taylor is a small business owner, a business technology consultant, an educator, and a mentor. She is well-versed in many aspects of GRC and infosec risk management, and has a mission to aspire to inspire!

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/messageSupport this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Derek Andrews, Incident Response Manager at a Financial Institution, joins VCM to discuss his journey, incident response in the financial sector, and different types of virtual CISOs from the perspective of one who has worked with both the good and not so good. He also explains why he is the Resident Birdman of LinkedIn!

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/messageSupport this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Chome Zero Day (again), offshore energy vyber threats, Rackspace Exchange hit by "incident", Australia dramatically increases breach penalties, and a ping vuln in FreeBSD - plus a couple of thoughts for entry-level information security analysts.

  • https://cybersecuritynews-com.cdn.ampproject.org/c/s/cybersecuritynews.com/google-chromhe-9th-zero-day-bug/?amp
  • https://www.pipeline-journal.net/news/us-offshore-natural-gas-oil-infrastructure-faces-rising-cybersecurity-threats
  • https://www.securityweek.com/rackspace-shuts-down-hosted-exchange-systems-due-security-incident
  • https://www.bleepingcomputer.com/news/security/australia-will-now-fine-firms-up-to-au50-million-for-data-breaches/
  • https://thehackernews.com/2022/12/critical-ping-vulnerability-allows.html

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/messageSupport this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

LastPass second incident, aged domains, Trigona ransomware, unemployment benefit fraud, ConectWise flaw, attackers target FI customers, and this week's 2023 predictions from SpiceWorks - plus some thoughts  on cyber culture.

  • https://thehackernews.com/2022/12/lastpass-suffers-another-security.html
  • https://www.bleepingcomputer.com/news/security/crafty-threat-actor-uses-aged-domains-to-evade-security-platforms/
  • https://www.techradar.com/news/this-new-ransomware-is-seeing-rapid-growth-so-beware
  • https://www.infosecurity-magazine.com/news/eight-30m-unemployment-benefits/
  • https://krebsonsecurity.com/2022/12/connectwise-quietly-patches-flaw-that-helps-phishers/?
  • https://www.scmagazine.com/news/email-security/attackers-target-vulnerable-financial-customers-rather-than-the-institutions-themselves
  • https://www.spiceworks.com/it-security/cyber-risk-management/interviews/top-cybersecurity-trends-2023/

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/messageSupport this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Jack Poltorak discusses vCIO and vCISO services offered by MSSPs, how those services may not be exactly what a small or midsized business (SMB)  is looking for, and tips how an SMB can ensure they are getting the virtual CISO services they need.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/messageSupport this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

In this month's special end of month Wednesday episode we talk with Jacob Horne, who was born with a rare genetic mutation that allows him to read NIST publications and government regulations without experiencing boredom like a normal person and has made a career out of using this power for good. He does a great job of using NIST SP 800-53 to clarify the bizarre, heavily tailored world of NIST SP 800-171 and CMMC - if you're interested in CMMC you must follow him on LinkedIn! He is also co-host of the Sum It Up podcast which sums up the news and developments relevant to CMMC; DFARS and other regulations; and NIST standards such as SP 800-171, SP 800-53, the NIST Cybersecurity Framework, and others.

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/messageSupport this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Cheri Hotman of the Hotman Group (https://hotmangroup.com) is a CPA, has her MBA, and is a CISSP - a combination rare in information security. She discusses her experiences and lessons learned managing a business providing quality virtual CISO services to a variety of clients, including navigating "the land of 1000 piranhas"!

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/messageSupport this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Cyber Monday, FCC bans Chinese equipment, Twitter breach cover up, WhatsApp data leak, and BMC firmware flaws - plus thoughts about how the interconnected world got something wrong for me.

  • https://news.yahoo.com/fbi-warning-shoppers-online-holiday-172655986.html
  • https://securityaffairs.co/wordpress/138998/breaking-news/fcc-bans-import-chinese-equipment.html
  • https://www.cshub.com/attacks/news/iotw-twitter-accused-of-covering-up-data-breach-that-affects-millions
  • https://cybernews.com/news/whatsapp-data-leak/
  • https://thehackernews.com/2022/11/over-dozen-new-bmc-firmware-flaws.html

--- Send in a voice message: https://anchor.fm/virtual-ciso-moment/messageSupport this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Cybersecurity as part of business strategy, free resources from CISA, dysfunctional security team isn't good, AirAsia ransomware affects 5 million, and more predictions for 2023, this time from Deloitte - plus are we heading for a cybersecurity compensation bubble burst?

  • https://www.forbes.com/sites/forbestechcouncil/2022/11/21/why-cybersecurity-should-be-part-of-any-business-strategy/
  • https://www.helpnetsecurity.com/2022/11/21/5-free-resources-cybersecurity-and-infrastructure-security-agency-cisa/
  • https://technative.io/cybersecuritys-too-important-to-have-a-dysfunctional-team/
  • https://www.databreaches.net/airasia-victim-of-ransomware-attack-passenger-and-employee-data-acquired/
  • https://venturebeat.com/security/deloitte-cybersecurity-predictions-2023/

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From August 9, 2022 - CISO and vCISO Monica Rowe joins us to discuss cybersecurity in financial services; the benefits of sharing information through ISACs, presentations, and other means; and how to provide a sense of calm to the cybersecurity storm.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Robin Wilde is the Director of Business Solutions for TeamHealth. She is passionate about project management and cyber security, particularly Identity Management, as well as promoting women in cyber. She holds a variety of certifications, including the  CISSP, CRISC, PMP, ACP, CSP, and Prosci, demonstrating her vast skillset and experience. She introduces the phrase "privilege sprawl" - listen to find out what that means!


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

MS zero day (and a term I should have known), banning cyber ransom payments, FI IT staff greatest cybersecurity risk, cybersecurity is the C-Suite responsibility, and five "starter" certs.

  • https://www.bleepingcomputer.com/news/security/new-attacks-use-windows-security-bypass-zero-day-to-drop-malware/amp/
  • https://theconversation.com/australia-is-considering-a-ban-on-cyber-ransom-payments-but-it-could-backfire-heres-another-idea-194516
  • https://www.scmagazine.com/news/cloud-security/many-financial-institutions-say-their-own-it-staffs-pose-the-biggest-risk-to-cloud-security
  • https://www.mbanews.com.au/former-google-vp-believes-cyber-security-is-a-c-suite-responsibility/
  • https://www.businessnewsdaily.com/9661-cybersecurity-certifications.html

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From November 13. 2019 - Information security policies direct the governance of the information security program. What are elements of effective policies, and what mistakes do SMBs often make with their information security policy program?


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

CISA claims elections secure, US network hacked, 42,000 imposter domains used by attackers, iOS 16 security features, CheckPoint predictions, and the security posture of Twitter.

  • https://www.infosecurity-magazine.com/news/cisa-midterm-uncompromised-by/
  • https://cybersecuritynews.com/u-s-federal-network-hacked/
  • https://thehackernews.com/2022/11/chinese-hackers-using-42000-imposter.html
  • https://9to5mac.com/2022/11/16/5-important-ios-16-iphone-security-features/
  • https://www.expresscomputer.in/news/check-point-softwares-cybersecurity-predictions-for-2023-expect-more-global-attacks-government-regulation-and-consolidation/91777/
  • https://www.wired.com/story/twitter-mega-breach-what-if/

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From August 2, 2022 - Steve Mallard has over 20 years in Information Technology; is a Master Teacher in Information Technology/Infrastructure Management and Information Systems Manager at Tennessee College of Applied Technology - Shelbyville; is a private consultant for government organizations, higher-ed, and private corporations, a technical writer, and a public speaker on cybersecurity. He has also organized for many years the Middle Tennessee Cyber Conference (https://middletncyberconf.com/), held this year at Embassy Suites in Murfreesboro, Tennessee. In addition to his numerous career accomplishments, his contribution to the next generation of cyber professionals is unparalleled.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Lin Clark, the Carolina Cyber Center's SOC Director, discusses how the SOC benefits both the students in the Carolina Cyber Center program and the western North Carolina small business community. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022. Audio only.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

I've started a limited YouTube series on lessons I've learned from being a successful consulting business owner. It's not all sunshine and roses, and I've made a lot of mistakes, but I've learned from them. Here are the first two episodes - Consulting: Introduction and Consulting: Risk Assessment. If you find these interesting and useful, please subscribe to the vCISO Services, LLC YouTube channel (link below) to be notified when future episodes drop (episodes drop roughly weekly, and episode three will drop the week of November 14th).

https://youtube.com/@vciso


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

KmsdBot, email server extortion, Fed requirements and ITAM, CMMC advice, ways data can be exposed, and a primer on pen testing - plus thoughts on when pen tests aren't exactly pen tests (and the SMB loses out).

  • https://thehackernews.com/2022/11/new-kmsdbot-malware-hijacking-systems.html
  • https://www.infosecurity-magazine.com/news/mass-email-extortion-claims-server/
  • https://itassetmanagement.net/2022/11/07/us-federal-cybersecurity-requirements-raise-itam-for-all/
  • https://washingtontechnology.com/companies/2022/11/cmmcs-father-warns-companies-not-wait-final-rule/379617/
  • https://www.csoonline.com/article/3675542/8-strange-ways-employees-can-accidently-expose-data.html
  • https://www.intruder.io/blog/what-is-an-external-pentest

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Why phishing emails have typos, repeat ransomware demands, SMS used in banking attack, CISOs making job changes, Twitter CISO and CPO resign, plus some thoughts on the Twitter infosec exodus.

  • https://securityboulevard.com/2022/11/why-do-phishing-emails-have-such-obvious-typos/
  • https://www.insurancejournal.com/news/national/2022/11/09/694534.htm
  • https://thehackernews.com/2022/11/warning-this-widespread-malicious.html
  • https://www.zdnet.com/google-amp/article/cybersecurity-leaders-want-to-quit-heres-what-is-pushing-them-to-leave/
  • https://www.cnn.com/2022/11/10/tech/twitter-executives-resign/index.html

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From July 26, 2022 - Anthony Scarola is an IT Governance, Risk, and Compliance (GRC) expert; has many years in cybersecurity; is a U.S. Army veteran; holds the CISSP; and is a virtual CISO. And he's writing a security book! Listen to his wisdom as it pertains to risk management and learn one mistake many may make when discussing risk with the c suite and board of directors.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Rob Bowker, Sales Director at EasyDMARC, explains the risks of email spoofing, the benefits of implementing DMARC in addition to DKIM and SPF, and how EasyDMARC helps to manage DMARC. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Jake Williams is a cybersecurity manager and aspiring CISO, currently pursuing his MBA. He is also well-versed in CMMC, and we dive into some elements of this somewhat confusing standard/requirement.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

National Guard to assist with election cyber security, supply chain stops train, predictions for 2023, MFA fatigue explored, and CEO sanctioned in breach, plus thoughts on the C-Suite and Board of Directors responsibility.

  • https://www.politico.com/news/2022/11/04/nationa-guard-midterm-election-cybersecurity-00065236
  • https://www.securityweek.com/cyberattack-causes-trains-stop-denmark
  • https://www.proofpoint.com/us/blog/ciso-perspectives/cybersecurity-predictions-for-2023
  • https://www.theregister.com/AMP/2022/11/03/mfa_fatigue_enterprise_threat/
  • https://therecord.media/ftc-seeks-action-against-drizly-and-its-ceo-for-cybersecurity-failures/

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

2022 cybersecurity threat landscape report, election cybersecurity concerns, arrest in dark web market, five cybersecurity mistakes for businesses, and a primer on threat hunting - plus thoughts on career planning and management.

  • https://www.enisa.europa.eu/news/volatile-geopolitics-shake-the-trends-of-the-2022-cybersecurity-threat-landscape
  • https://www.helpnetsecurity.com/2022/10/31/election-cybersecurity/
  • https://www.bleepingcomputer.com/news/security/student-arrested-for-running-one-of-germany-s-largest-dark-web-markets/
  • https://venturebeat.com/security/5-cybersecurity-mistakes-that-will-haunt-you/
  • https://securityboulevard.com/2022/11/the-no-nonsense-benefits-of-threat-hunting/

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From July 19, 2022 - J.J. Powell of Cyber Defense Group (https://www.cdg.io/) discusses his career journey from police officer to system administrator to CISO and now as leading virtual CISO services. He is also a pivotal component into my decision to leave corporate and become an independent vCISO - listen to find out what was "the straw that broke the camel's back" for me!


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Dan Bradley, CIPP/E, CIPP/US, CIPM, is the Senior Associate General Counsel at Global Payments, Inc. and a former Federal Prosecutor. We discuss privacy regulations both for financial institutions and SMBs, including the importance of frameworks. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Christian Espinosa is the author of "The Smartest Person in the Room: The Root Cause and New Solution for Cybersecurity", Founder and CEO of Alpine Security, a cybersecurity engineer, certified high-performance coach, professor, and lover of heavy metal music and spicy food. He’s also an Air Force veteran and Ironman triathlete. He used to value being the “smartest guy in the room,” only to realize that his greatest contribution to the fight against cybercrime is his ability to bring awareness to the issue through effective communication. Christian is a speaker, coach, and trainer in the Secure methodology, helping to make the smartest people in the room the best leaders in the field. For more information, visit www.christianespinosa.com, and to order his book, visit https://www.amazon.com/dp/B08T6QK6FN.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Midterm election caution, OpenSSL critical update, copper producer Aurubis attached, possible intrusion at Bed Bath and Beyond, Liz Truss potential phone hack, and thoughts about the risks of using personal devices for corporate business.

  • https://www.reuters.com/world/us/complex-threat-environment-ahead-midterm-elections-top-cybersecurity-official-2022-10-30/
  • https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html
  • https://www.bleepingcomputer.com/news/security/largest-eu-copper-producer-aurubis-suffers-cyberattack-it-outage/
  • https://finance.yahoo.com/news/bed-bath-beyond-reviewing-possible-125236580.html
  • https://www.msn.com/en-us/news/world/unconfirmed-liz-truss-phone-hack-report-prompts-calls-for-investigation/ar-AA13xVrU

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Australia to increase breach fines, patients affected by breach do not have standing to sue, 22-year old vulnerability discovered, two POS malware used in breach, cyber insurance considerations from the NACD blog, and some thoughts on risk treatment.

  • https://www.abc.net.au/news/2022-10-21/data-breach-fines-increase-after-medibank-optus-hacks/101564614
  • https://www.vitallaw.com/news/hipaa-d-kan-patients-allegedly-victimized-by-computer-security-breach-at-county-hospital-lack-standing-to-assert-claims/hld01191d00ea3679403594877f366c89a047
  • https://thehackernews.com/2022/10/22-year-old-vulnerability-reported-in.html
  • https://thehackernews.com/2022/10/cybercriminals-used-two-pos-malware-to.html
  • https://blog.nacdonline.org/posts/crossroads-cyber-insurance-covered

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From July 12, 2022 - Johanan (Jo) Dixon talks about life in the Marine Corps, as an MMA amateur fighter, and as a Title boxing instructor, and how these helped prepare him for his journey to cybersecurity and his current role with Halcyon (https://www.halcyon.ai/). And he's starting up a new podcast!


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Marci McCarthy is CEO and President at T.E.N. CEO and Chairman at ISE® Talent. She founded T.E.N.’s flagship program, the Information Security Executive® of the Year (ISE®) Program Series, which is lauded by the IT industry as the premier recognition and networking program for security professionals in the U.S. and Canada. She is a 2012 recipient of a 4th Congressional District of Georgia Citation for fostering greater visibility and professionalism for the IT security industry, naming March 13th “Marci McCarthy Day.” She was listed as one of IFSEC Global’s Security and Fire Influencers for 2018 as #3 of 20 total leaders in their Cybersecurity category; she was also the highest-ranking woman on the list. She is also the DeKalb GOP Chairman (Georgia). She joins us to discuss information security and election integrity.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Albert Whale, Founder and CEO of IT Security Solutions, Inc and the developer of ITS Safe which provides real-time continuous protection at machine speed. He has over 30 years of experience with reducing the risk for business owners, minimizing their liabilities and overall risk. He has extensive experience in the techniques that criminal hackers use and identifies the probability and impact risks to exploit their business. He is the author of #Hacked and the primary author of #Hacked2. 

  • https://its-safe.com/
  • https://thehackedbook2.com/

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

"VSOC", nonprofit cybersecurity challenges, seven steps to defend healthcare agencies, workforce shortage, loss of GPS for flight navigation in Dallas, and some thoughts on aviation and navigation from my active pilot days.

  • https://www.theregister.com/2022/10/18/ntt_denso_security_for_cars/
  • https://www.csoonline.com/article/3676668/altruism-under-attack-why-cybersecurity-has-become-essential-to-humanitarian-nonprofits.html
  • https://www.helpnetsecurity.com/2022/10/18/7-critical-steps-defend-healthcare-sector-against-cyber-threats/
  • https://www.secureworld.io/industry-news/isc2-cybersecurity-industry-workforce-shortage
  • https://www.bloomberg.com/news/articles/2022-10-18/faa-warns-airline-pilots-as-gps-signals-disrupted-around-dallas

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Google forms COVID phish, US national cybersecurity strategy, Microsoft customer data breach, economic uncertainty and the effect on cyber risk, and skill resources and advice for CISOs - plus what I believe is an important certification for CISOs that is not talked about too often.

  • https://www.bleepingcomputer.com/news/security/google-forms-abused-in-new-covid-19-phishing-wave-in-the-us/
  • https://www.cyberscoop.com/inglis-previews-national-cyber-strategy/
  • https://www.bleepingcomputer.com/news/security/microsoft-data-breach-exposes-customers-contact-info-emails/amp/
  • https://www.helpnetsecurity.com/2022/10/17/economic-uncertainty-increasing-cybersecurity-risks/
  • https://www.csoonline.com/article/3676130/top-skill-building-resources-and-advice-for-cisos.html

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From July 5, 2022 - William Birchett, President of Logos Systems and creator of the vCISO Network, discusses the virtual CISO space including elements that make a successful vCISO, the biggest threat to SMBs (it's not ransomware!), and his future plans to help the vCISO field through Logos Systems, the vCISO Network, and other endeavors.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Jon Sternstein is the Founder and Principal of Stern Security, a cyber security company headquartered in Raleigh, NC. He is co-author of the Cisco Press course titled “Security Penetration Testing (The Art of Hacking) LiveLessons”, holds many security certifications including: GIAC Penetration Tester and Certified Information Systems Security Professional (CISSP), is a featured cyber security expert, and talks with us about managing risks - and a little guitar! Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Keith Maune, Founder & COO at Acumen Technology, discusses his IT and cybersecurity path, from doing consulting work for companies needing website design and programming services, working after school and full-time during the summers, pursuing a BS and MBA while working full-time as co-owner and CIO of Advanced Network Solutions, earning a law degree, and launching Acumen Technology, a comprehensive managed services organization that serves Middle Tennessee as the premier IT services provider for community banks, healthcare providers, and professional services organizations.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

AMLBot cleans house, Windows Zero Day details, White and Black Hat, Magnibar ransomware, and SMBs feeling financial pain from county system attack.

  • https://krebsonsecurity.com/2022/10/anti-money-laundering-service-amlbot-cleans-house/
  • https://www.hackademicus.nl/experts-disclose-technical-details-of-now-patched-cve-2022-37969-windows-zero-day/
  • https://www.bestcolleges.com/bootcamps/guides/white-hat-black-hat/
  • https://www.infosecurity-magazine.com/news/magniber-ransomware-adopts/
  • https://bronx.news12.com/county-vendors-feeling-the-pinch-of-suffolk-computer-systems-hack

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From January 1, 2020 Information security theater, improvements that look and sound good but make no real impact to overall security stance of an organization, can do more harm than good. Are you understanding the information security risks of your organization before designing and implementing controls?


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Update on Optus, why ji32k7au4a83 is a common password, Russia's version of GitHub, Lockbit used in attack, Malwarebytes new MDR, White House unveils IoT labeling initiative, and a new CMMC-focused podcast - plus a few thoughts on podcasts in general.

  • https://www.cisc.gov.au/news-media/archive/article?itemId=955
  • https://www.gizmodo.com.au/2022/10/why-ji32k7au4a83-is-a-remarkably-common-password/
  • https://cybernews.com/news/russias-version-of-github/
  • https://www.theregister.com/2022/10/14/nhs_software_hosting_provider_advanced_ransomware_lockbit/
  • https://www.securityweek.com/malwarebytes-launches-mdr-solution-smbs
  • https://www.cyberscoop.com/white-house-to-unveil-internet-of-things-labeling/
  • https://www.youtube.com/watch?v=VjmXH7b5kJU&ab_channel=Summit7Systems

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

In today's Throwback Thursday episode from June 28, 2022, Dick Wilkinson, CTO and Co-founder of Proof Labs, discusses securing space, the transition to entrepreneur, the vCISO discipline, and more!


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Michelle Pupoh is the Senior Director of Cybersecurity Education at the Carolina Cyber Center. She discusses the approach the center takes in training the next generation of cyber professionals, including the importance of ethics and soft skills. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

David Leech is a vCISO using his global, operational, program management, and security experience together with leadership skills to drive digital transformation, product innovation, and risk reduction for business growth, involving work across Risk Management, Technical Architecture, Control Frame Works, HIPAA, FFIEC, PCI, HITRUST, FedRamp, and SOC compliance. He has supported clients in multiple sectors, including Finance, Manufacturing, Insurance, Healthcare and GovEd.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Uber trial a lost opportunity to promote cyber governance, hacked IP scanning tool, leak of Alder Lake BIOS, LilithBot Malware as a Service, and healthcare provider IT incident likely malware - plus thoughts on the importance of business continuity table top exercises.

  • https://www.forbes.com/sites/jodywestby/2022/10/08/uber-trial-a-lost-opportunity-for-cyber-governance/amp/
  • https://www.scmagazine.com/analysis/network-security/backdoored-version-of-popular-network-admin-tool-hits-80-organizations-around-the-globe
  • https://thehackernews.com/2022/10/intel-confirms-leak-of-alder-lake-bios.html
  • https://www.theregister.com/2022/10/10/eternity_lilithbot_malware_bundle/
  • https://www.healthcaredive.com/news/commonspirits-it-security-incident-likely-cyberattack-security-expe/633509/

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Threat actors may influence US midterm elections, DIB org attached with APT, an interesting approach to password expiration policies, an updated primer and review on cyber insurance, and Uber's CISO convicted on two counts related to breach actions - plus more thoughts on ethics.

  • https://www.ic3.gov/Media/PDF/Y2022/PSA221006.pdf
  • https://www.bleepingcomputer.com/news/security/hackers-stole-data-from-us-defense-org-using-impacket-covalentstealer/amp/
  • https://www.helpnetsecurity.com/2022/10/04/mandatory-password-expiration-helping-or-hurting-password-security/
  • https://www.csoonline.com/article/3643054/cyber-insurance-explained.amp.html
  • https://thehackernews.com/2022/10/former-uber-security-chief-found-guilty.html
  • https://www.justice.gov/usao-ndca/press-release/file/1306781/download

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From June 21, 2022 - Nick Santora, CEO of Curricula (curricula.com), discusses information security awareness and how Curricula uses storytelling to make both short term and long term impressions, resulting in increased security across the organization. He also discusses his path to entrepreneur, challenges in the SMB infosec awareness space, and "wisdom walks"!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Joe Jakubielski is a Cyber Defense Analyst with the Carolina Cyber Center. He discusses his recent pivot to a new career in cyber, including challenges and opportunities ahead. Recorded at RETR3AT Cyber Conference Montreat College September 23, 2022.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Gary Chan of Alfizo LLC helps businesses stay secure from hackers and insider threats, meet legal and regulatory compliance, and enable sales by meeting their customers' expectations for security. He is also a "security mentalist", and if you're like me and have never heard of this term, you need to check out this episode - it's fascinating!

Gary's websites:

• Creating memorable experiences for corporate audiences, https://www.gschan2000.com/

• Helping organizations build their information security programs, https://alfizo.com/


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

ICO fines privacy-invading firms, disgruntled former admin does damage with unrevoked access, healthcare fraud results in fines and jail time, Comm100 supply chain attach, banks fined $1.8B for using unauthorized apps to communicate, and a few thoughts on shadow IT.

  • https://www.infosecurity-magazine.com/news/ico-fines-four-predatory/
  • https://www.bleepingcomputer.com/news/security/fired-admin-cripples-former-employers-network-using-old-credentials/amp/
  • https://www.infosecurity-magazine.com/news/health-care-company-jail-time-7m/
  • https://cybernews.com/news/live-chat-platform-spreads-malware/
  • https://www.reuters.com/business/finance/us-fines-16-major-wall-street-firms-11-billion-over-recordkeeping-failures-2022-09-27/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Microsoft Exchange zero days, Optus update, Brute Ratel cracked, 60% of cyber pros report "losing ground", more on the risk of deepfakes, and cyber insurance providers pivoting to requiring adherence to frameworks and risk management.

  • https://thehackernews.com/2022/09/microsoft-confirms-2-new-exchange-zero.html
  • https://www.bbc.com/news/world-australia-63056838
  • https://www.bleepingcomputer.com/news/security/hackers-now-sharing-cracked-brute-ratel-post-exploitation-kit-online/
  • https://www.businesswire.com/news/home/20220926005190/en/60-of-Cybersecurity-Professionals-Feel-They-Are-Losing-Ground-Against-Cybercriminals
  • https://www.theregister.com/2022/09/28/trend_deepfake_video/
  • https://community.microfocus.com/cyberres/b/sws-22/posts/cyber-insurance-customers-need-to-be-more-cyber-resilient

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From June 14, 2022: Matt Santill, Founder and CEO of Cyber Security Services https://www.cybersecurityservices.com/ discusses the challenges of a vCISO, what is the most significant business risk, how he became interested in information security, and his career progression to CISO and on to business owner.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

In this month's special end of month Wednesday episode Mark Burnette, Shareholder-In-Charge at LBMC Information Security, discusses his path from Senior IT Auditor to overseeing and directing LBMC’s Risk Services practice nationwide. He is very active in the information security community, including as co-founder and past president of the Middle Tennessee ISSA chapter (one of the largest in the world), and co-founder and board member of the Southern CISO Security Council. His certifications include CPA, CISA, CISSP, CISM, and CRISC, and he frequently speaks on information security topics, including a fabulous TEDx talk on the Humanity Behind Cyber Attacks - https://www.ted.com/talks/mark_burnette_the_humanity_behind_cybersecurity_attacks.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Cy Sturdivant, Director at Forvis (Cybersecurity Division), joins us to discuss his path from accounting and finance to cybersecurity and the audit field. We dive into controls, the Three Line of Defense model, and how audit as the third line helps organizations achieve and maintain a solid information security posture.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Anonymous injects into the Iranian protests, ChromeLoader injecting ransomware, Optus extortion, 543,000 added to ECL breach, IHG disruption for "fun", and thoughts about the need for ethics in cybersecurity.

  • https://cybernews.com/cyber-war/anonymous-takes-iran-in-support-of-women/
  • https://www.theregister.com/2022/09/21/vmware_microsoft_chromeloader_threat/
  • https://www.bankinfosecurity.com/optus-under-1-million-extortion-threat-in-data-breach-a-20142
  • https://www.scmagazine.com/analysis/ransomware/eye-care-leaders-fallout-grows-543k-wolfe-clinic-patients-added-to-breach-tally
  • https://www.bbc.com/news/technology-62937678

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

A little different today - we are recording live from the RETR3AT conference at Montreat College! Look for discussions to drop Wednesdays.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From June 7, 2022: James Farley, Partner Development Manager, Cybersecurity at ConnectWise (connectwise.com), discusses migrating from insurance to IT sales to supporting Managed Service Providers, as well as running to beat the stress, including reaching a goal many never achieve!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Recorded at the Middle Tennessee Cyber Conference September 13, 2022 - host Greg Schaffer walks through his 33 year career in information technology and security, providing lessons learned and what he has determined is, for him, the secret for success in cyber security. We had technical issues with the primary video and audio recording so this recording is not quite up to our standards, but we still felt it was relevant to share.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Adam Bricker has led many career lives, from working on Tomahawk missiles to cofounding the Carolina Cyber Center, focused on hardening community resources and continuing education to address the nation's critical cybersecurity talent shortfall. He currently provides consulting services for businesses in high tech, IT-enabled and emerging markets as the founder of ePower Learning, and his testimony of faith in relation to his callings is truly inspirational.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Criminals had internal access to LastPass for four days, Microsoft gaming click fraud, cyberattack costs increase, SaaS sprawl risks, and the necessity of collaboration in security and privacy.

  • https://www.bleepingcomputer.com/news/security/lastpass-says-hackers-had-internal-access-for-four-days/
  • https://thehackernews.com/2022/09/microsoft-warns-of-large-scale-click.html
  • https://www.darkreading.com/attacks-breaches/cyberattack-costs-for-us-businesses-up-by-80-
  • https://securityboulevard.com/2022/09/saas-security-issues-driven-by-sprawl-lack-of-visibility/
  • https://www.csoonline.com/article/3673943/collaboration-is-key-to-balance-customer-experience-with-security-privacy.html

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Uber cybersecurity "incident", Teams critical vuln, Lorenz ransomware exploits Mitel, Meta and Google fined for violating privacy laws, White House releases software security requirements, and the one piece of career advice I would tell my 19 year-old self.

  • https://www.digitaltrends.com/mobile/uber-investigating-cybersecurity-incident/
  • https://www.bleepingcomputer.com/news/security/microsoft-teams-stores-auth-tokens-as-cleartext-in-windows-linux-macs/
  • https://thehackernews.com/2022/09/lorenz-ransomware-exploit-mitel-voip.html
  • https://techcrunch.com/2022/09/14/google-meta-fined-71-8m-for-violating-privacy-law-in-south-korea/
  • https://www.theregister.com/2022/09/14/white_house_software_security_guidance/

My Cybersecurity Path YouTube playlist - https://youtube.com/playlist?list=PLZkMMBCZshiO0gu44pAZUM__fpHOrvTcv 


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On this week's Throwback Thursday, from May 31, 2022, Rob Black, Founder and CEO of Fractional CISO (https://fractionalciso.com) talks about providing fractional/virtual CISO services to midsized SaaS technical organizations as well as other businesses, his story of starting Fractional CISO, and how he sees the SMB threat environment.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Elvis Huff is the Vice President - Director of Security/Information Security Officer for Wilson Bank and Trust. His path to bank ISO is not typical but is inspirational, with 12 years as a police officer prior to entering the world of banking. His reason for the transition involves faith and following a calling. He also produces an awesome security newsletter, Security Stuff with Elvis Huff - check it out at https://www.wbtsecurityblog.com/!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Americans lost nearly $7B to cybercrime in 2021, ports at risk of breach, FBI alert about Vice Society, Wordpress plugin BackupBuddy zero-day vuln, HP notebook high severity flaws remain wihtout a patch, and a few thoughts about 9/11 21 years later.

  • https://www.cbsnews.com/miami/news/fbi-americans-lost-nearly-7-billion-to-cybercrime-last-year/
  • https://www.darkreading.com/attacks-breaches/why-ports-are-at-risk-of-cyberattacks
  • https://www.cybersecurity-insiders.com/fbi-issues-serious-cyber-threat-alert-about-vice-society/
  • https://www.cysecurity.news/2022/09/new-zero-day-flaw-in-backupbuddy-plugin.html
  • https://thehackernews.com/2022/09/high-severity-firmware-security-flaws.html
  • https://www.cnn.com/2022/09/11/politics/biden-september-11-remembrance-ceremony-pentagon/index.html

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

IHG cyberattack disrupts booking systems, Tik-Tok-Hak, North Face credential stuffing attack, fake Android AV and cleaner apps install malware, posting photos and the information security risks they bring, and thoughts about technology debt.

  • https://www.bleepingcomputer.com/news/security/intercontinental-hotels-group-cyberattack-disrupts-booking-systems/
  • https://www.msn.com/en-in/money/news/tiktok-hacked-over-2-bn-user-database-records-stolen-security-researchers/amp/ar-AA11u87N
  • https://www.bleepingcomputer.com/news/security/200-000-north-face-accounts-hacked-in-credential-stuffing-attack/
  • https://thehackernews.com/2022/09/fake-antivirus-and-cleaner-apps-caught.html
  • https://www.csoonline.com/article/3672869/how-posting-personal-and-business-photos-can-be-a-security-risk.html
  • https://technative.io/time-to-bring-the-cyber-security-technical-debt-under-control/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From May 24, 2022 - Kyle Cravens, Founder/Managing Principal of the staffing and recruiting firm Key Resource Group, LLC (https://www.krgnow.com/), joins us to discuss the IT and Information Security recruiting environment including tips on how a candidate can improve their chances of landing the position; how COVID and remote work has changed the environment, and how his faith guides his journey.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Donna Gallaher, President and CEO of New Oceans Enterprises, LLC, is a seasoned IT and information security pro providing virtual CISO and risk management services. She is a FAIR (Factor Analysis of Information Risk) evangelist and is passionate about growing the virtual CISO community, including serving on the Board of Directors for vCISO Catalyst, a Public Benefit Corporation supporting the improvement of cybersecurity programs of small and medium businesses. If you have never heard of FAIR or are interested in the virtual CISO field (or both), check out this episode!

New Oceans Enterprises, LLC - https://www.newoceansenterprises.com/


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

IRS leaks taxpayer info, student loan breach, breach affects KeyBank and possibly others, REvil hits Fortune 500 company, phishing scam for American Express customers, and what I did on Labor Day, and how it ties in to information security.

  • https://www.theepochtimes.com/mkt_app/irs-mistakenly-published-confidential-info-of-120000-taxpayers_4708384.html
  • https://threatpost.com/student-loan-breach-exposes-2-5m-records/180492/
  • https://www.securityweek.com/keybank-hackers-third-party-provider-stole-customer-data
  • https://cybernews.com/news/revil-claims-to-have-hit-a-fortune-500-company/
  • https://hackademicus.nl/a-new-phishing-scam-targets-american-express-cardholders/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Lockbit leaks Entrust data, older iPhone vulns patch available, apps leaking hard-coded AWS creds, organ transplant system needs strengthening, "ghost in the machine" a significant risk, very experienced security reporter gets fooled by a phish, and a lookback at Stuxnet.

  • https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-gets-aggressive-with-triple-extortion-tactic/
  • https://www.securityweek.com/ios-12-update-older-iphones-patches-exploited-vulnerability
  • https://thehackernews.com/2022/09/over-1800-android-and-ios-apps-found.html
  • https://www.bankinfosecurity.com/report-organ-transplant-data-security-needs-strengthening-a-19967
  • https://www.darkreading.com/edge-threat-monitor/ghost-data-increases-enterprise-business-risk
  • https://arstechnica.com/information-technology/2022/08/im-a-security-reporter-and-got-fooled-by-a-blatant-phish/
  • https://www.csoonline.com/article/3218104/stuxnet-explained-the-first-known-cyberweapon.html

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

From May 17, 2022 - Clark Cummings joins us to discuss enterprise risk management, how to recognize "risk collisions", and provide practical risk management advice for small and midsized businesses.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Scott Augenbaum was a special agent with the FBI and now continues his mission to help prevent businesses from becoming a victim of cybercrime as an author, speaker, and trainer. His story and mission is educational and inspirational! Check out https://www.cybersecuremindset.com/ and connect with Scott at https://www.linkedin.com/in/saugenbaum/.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Susan Richards is a dynamic director of Information Security concentrated in compliance, project management, application development, and database administration. She is skilled in IT Strategy, Management, Compliance Assurance, and Risk Management including HITRUST, NIST and ISO security frameworks. She is also very involved in the information security community, including ISSA chapter leadership and has this year started a local HITRUST chapter - plus we discuss election integrity!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Portland Oregon loses $1.4 million to BEC compromise, stolen Texas data possibly on dark web, 10 new actively exploited vulns added to CISA list, banking trojan targets industries in Spanish-speaking countries, an opinion piece on whether cybercriminals follow a moral code, and a new enterprise browser startup secures massive funding, which prompted my walk down memory lane of browsers over my 30-plus year career.

  • https://www.pcmag.com/news/portland-city-officials-accidentally-send-hacker-14-million
  • https://www.healthcareitnews.com/news/stolen-texas-health-data-may-be-posted-dark-web
  • https://thehackernews.com/2022/08/cisa-adds-10-new-known-actively.html
  • https://gbhackers.com/banking-trojan-targeting-automotive/
  • https://cybernews.com/security/attacking-healthcare-do-cybercriminals-follow-moral-code-/
  • https://www.securityweek.com/enterprise-browser-startup-island-snags-massive-funding-round

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Lastpass breach, counterfeit Microsoft USB installers, deepfake getting scary, dramatic rise in DDoS attacks, Apple iOS VPNs leak, and claiming to stop all malware ignites social media storm.

  • https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/
  • https://news.sky.com/story/criminals-posting-counterfeit-microsoft-products-to-get-access-to-victims-computers-12675123
  • https://www.infosecurity-magazine.com/news/scammers-create-ai-hologram-csuite/
  • https://www.govtech.com/blogs/lohrmann-on-cybersecurity/hacktivism-and-ddos-attacks-rise-dramatically-in-2022
  • https://www.theregister.com/2022/08/19/apple_ios_vpn/
  • https://www.crn.com/news/security/exec-s-claim-that-xcitium-stops-all-malware-ignites-msp-social-media-firestorm

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

In this episode from May 10, 2022, Mike Rastigue with Crum & Forster joins us to discuss cyber insurance and one way that his organization is helping SMBs to be both better prepared to meet cyber insurance underwriting requirements and increase their security posture.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Vanessa Taylor is a small business owner, a business technology consultant, an educator, and a mentor. She is well-versed in many aspects of GRC and infosec risk management, and has a mission to aspire to inspire!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Entrust data leaks, cyber war insurance exclusion definition updated, vulnerable RTLS systems, crypto stolen from hacked ATMs, draft US government cybersecurity acquisition requirements, and pragmatic infosec, and why that is important.

  • https://www.bleepingcomputer.com/news/security/lockbit-claims-ransomware-attack-on-security-giant-entrust-leaks-data/https://www.securityweek.com/lloyds-london-introduces-new-war-exclusion-insurance-clauses
  • https://thehackernews.com/2022/08/rtls-systems-found-vulnerable-to-mitm.html
  • https://thehackernews.com/2022/08/hackers-stole-crypto-from-bitcoin-atms.html
  • https://www.threatshub.org/blog/the-truth-about-that-draft-law-banning-uncle-sam-buying-insecure-software/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Apple zero-day vulns. poop hack, pregnancy app privacy concerns, UK water supply ransomware, tips for SMBs to avoid ransomware risks, and the most interesting CVE? Plus a few more thoughts on Twitter cyber drama.

  • https://thehackernews.com/2022/08/apple-releases-security-updates-to.html
  • https://www.bleepingcomputer.com/news/security/anonymous-poop-gifting-site-hacked-customers-exposed/
  • https://www.theregister.com/2022/08/17/mozilla_pregnancy_app/
  • https://www.bleepingcomputer.com/news/security/hackers-attack-uk-water-supplier-but-extort-wrong-company/
  • https://www.csoonline.com/article/3669855/ransomware-safeguards-for-small-to-medium-sized-businesses.html
  • https://www.techspot.com/news/95671-janet-jackson-song-1989-declared-cybersecurity-vulnerability-crashing.html

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On today's Throwback Thursday from May 3, 2022, Frank Platt of Infosec Alliance LLC (https://www.infosecalliance.com/) joins us to discuss many infosec topics, including risk management, and CMMC...and BBQ!

Note a production error resulted in this TT episode releasing on Friday August 19, 2022.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

In this presentation from 2014, Greg discusses SMB information security concerns with a group of small business owners in Tennessee. Most is relevant still today (though Greg notes he'd reevaluate his antivirus recommendations). Most of the video is dark (lights turned down to view slide deck off-screen).


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Jack Poltorak discusses vCIO and vCISO services offered by MSSPs, how those services may not be exactly what a small or midsized business (SMB)  is looking for, and tips how an SMB can ensure they are getting the virtual CISO services they need.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

BHG brief affects almost 200K, hackers target cybersecurity pros with fake job offers, Zeppelin ransomware multiple encryption, Russia wiper attacks on Ukraine, smartphone ransomware, 5G IOT API vulns, and thoughts on how to police the infosec community.

  • https://www.scmagazine.com/analysis/breach/behavioral-health-group-informs-198k-patients-of-data-theft-from-december
  • https://hackercombat.com/north-korean-hackers-target-crypto-experts-with-fake-coinbase-job-offers/
  • https://www.bleepingcomputer.com/news/security/fbi-zeppelin-ransomware-may-encrypt-devices-multiple-times-in-attacks/amp/
  • https://www.cybersecurity-insiders.com/russia-launching-wiper-malware-cyber-attacks-against-ukraine/
  • https://www.forbes.com/sites/daveywinder/2022/08/14/gmail-and-gpay-cookies-targeted-by-new-smartphone-ransomware-threat-to-200-apps/?sh=65e59f936743
  • https://arstechnica.com/information-technology/2022/08/one-of-5gs-biggest-features-is-a-security-minefield/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Starlink hack, Ukraine cyber chief at BlackHat, new GitHub alerts to potential vulns, new Malware as a Service, what caused that Google outage, Cloudflare phishing attack, two new tools for nonbank financial services companies, and a Cisco breach involving "MFA fatigue".

  • https://www.wired.com/story/starlink-internet-dish-hack/
  • https://www.reuters.com/world/europe/ukraine-cyber-chief-pays-surprise-visit-black-hat-hacker-meeting-las-vegas-2022-08-11/
  • https://thehackernews.com/2022/08/github-dependabot-now-alerts-developers.html
  • https://www.theregister.com/2022/08/08/dark_utilities_c2_service/
  • https://cybernews.com/news/google-apologizes-for-a-global-services-outage/
  • https://cybernews.com/news/cloudflare-targeted-by-a-sophisticated-phishing-attack/
  • https://www.csbs.org/newsroom/csbs-releases-nonbank-cybersecurity-exam-procedures
  • https://www.bleepingcomputer.com/news/security/cisco-hacked-by-yanluowang-ransomware-gang-28gb-allegedly-stolen/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On this week's Throwback Thursday from April 19, 2022, Don Baham is very active in both the local and on-line information security communities, as well as having extensive experience helping SMBs with information security needs. He joins us to discuss challenges and opportunities including observations on the cyber security supply chain issue and possible ways to address.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

CISO and vCISO Monica Rowe joins us to discuss cybersecurity in financial services; the benefits of sharing information through ISACs, presentations, and other means; and how to provide a sense of calm to the cybersecurity storm.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Critical flaws in Emergency Alert System and in some Cisco SOHO routers, new IoT threat, CISA adds Zimbra vulnerability to its Known Exploited Vulnerabilities Catalog, and what you need to do to land a six-figure cybersecurity job.

  • https://www.threatshub.org/blog/warning-critical-flaws-found-in-us-emergency-alert-system/
  • https://www.theregister.com/2022/08/05/cisco_smb_routers_critical_flaws/
  • https://thehackernews.com/2022/08/new-iot-rapperbot-malware-targeting.html
  • https://thehackernews.com/2022/08/cisa-adds-zimbra-email-vulnerability-to.html
  • https://fortune.com/education/business/articles/2022/07/27/what-you-need-to-land-a-six-figure-cybersecurity-job/
  • https://youtube.com/playlist?list=PLZkMMBCZshiO0gu44pAZUM__fpHOrvTcv

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Motherboard malware that survives OS reinstall, mobile apps leaking Twitter API keys, TVA EDR not OK, Defender defends against ransomware better, ransomware big brands migrating to more smaller bands, and Ukraine shutters major Russian bot network.

  • https://www.pcmag.com/news/malware-that-can-survive-os-reinstalls-found-on-asus-gigabyte-motherboards
  • https://thehackernews.com/2022/08/researchers-discover-nearly-3200-mobile.html
  • https://www.scmagazine.com/analysis/zero-trust/feds-begin-measuring-edr-at-tennessee-valley-authority-but-gaps-cited-in-audit
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-now-better-at-blocking-ransomware-on-windows-11/
  • https://www.bankinfosecurity.com/blogs/ransomware-ecosystem-value-big-name-brands-diminishing-p-3257
  • https://www.infosecurity-magazine.com/news/ukraine-shutters-major-russian-bot/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On this week's Throwback Thursday from April 12, 2022, Chris Bedel, President and CEO of Bedel Security (bedelsecurity.com) talks about how the virtual CISO fits in to, compliments, and enhances financial institutions' information security program and posture. He also touches on history and future of the virtual CISO. If you're a virtual CISO for financial institutions or are interested in how a virtual CISO benefits financial institutions, this is a must-see episode packed with useful information!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Steve Mallard has over 20 years in Information Technology; is a Master Teacher in Information Technology/Infrastructure Management and

Information Systems Manager at Tennessee College of Applied Technology - Shelbyville; is a private consultant for government organizations, higher-ed, and private corporations, a technical writer, and a public speaker on cybersecurity. He has also organized for many years the Middle Tennessee Cyber Conference (https://middletncyberconf.com/), held this year at Embassy Suites in Murfreesboro, Tennessee. In addition to his numerous career accomplishments, his contribution to the next generation of cyber professionals is unparalleled.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

More Pegasus, Chrome extension steals emails and creds, increase of critical infrastructure attacks, Robin Banks PhaaS, more Log4Shell, and top security news websites.

  • https://www.reuters.com/technology/exclusive-eu-found-evidence-employee-phones-compromised-with-spyware-letter-2022-07-27/
  • https://www.bleepingcomputer.com/news/security/cyberspies-use-google-chrome-extension-to-steal-emails-undetected/
  • https://securityboulevard.com/2022/07/cyber-attacks-against-critical-infrastructure-quietly-increase/
  • https://securityboulevard.com/2022/07/cyber-attacks-against-critical-infrastructure-quietly-increase/
  • https://www.csoonline.com/article/3668652/cisa-releases-iocs-for-attacks-exploiting-log4shell-in-vmware-horizon-and-uag.html
  • https://blog.feedspot.com/cyber_security_news_websites/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Arrests in nuclear plant attack, RaaS providers adjust business plans, new cybersecurity House legislation passes with significant bipartisan support, how to make risk assessments better, PrestaShop critical vulns exploited, new CMMC AB draft assessment guide, why it's a good idea to establish a solid relationship with a recruiter (e.g. it may reduce chance of being ghosted).

  • https://thehackernews.com/2022/07/spanish-police-arrest-2-nuclear-power.html
  • https://www.infosecurity-magazine.com/news/raas-groups-forced-change-payments/
  • https://www.theepochtimes.com/mkt_app/house-passes-cybersecurity-bill-to-protect-americas-energy-sector-infrastructure-from-hackers_4627765.html
  • https://www.securitymagazine.com/articles/98076-dreading-security-risk-assessments-6-ways-to-make-them-better
  • https://build.prestashop.com/news/major-security-vulnerability-on-prestashop-websites/
  • https://cyberab.org/Portals/0/Documents/Process-Documents/CMMC-Assessment-Process-CAP-v1.0.pdf
  • https://securityboulevard.com/2022/07/im-not-looking-for-a-new-cyber-security-role-so-why-should-i-have-an-introduction-with-a-recruiter/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On his week's Throwback Thursday from April 5, 2022, Bob Quandt, owner of Bullseye Compliance (https://bullseyecompliance.com) joins VCM for a conversation that ranges from issues and trends in SMB security, entrepreneurship and making a difference, fitness and stress management, application of military experience to infosec, and more!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

In this special Wednesday episode, from the CU Intersect Conference in Houston Texas July 19, 2022, vCISO Services, LLC Principal Greg Schaffer discusses how credit unions and other small and midsized businesses can optimize their vCISO to maximize their information security posture.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Anthony Scarola is an IT Governance, Risk, and Compliance (GRC) expert; has many years in cybersecurity; is a U.S. Army veteran; holds the CISSP; and is a virtual CISO. And he's writing a security book! Listen to his wisdom as it pertains to risk management and learn one mistake may make when discussing risk with the c suite and board of directors.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Rogers outage cause, 54 million Twitter accounts' information for sale for $3K, ransomware update, Entrust breached, an startups without a CISO are at a disadvantage - plus statistics, and why you need to both understand their context and source, using a well-known example of an information security "statistic" in the last article.

  • https://twitter.com/atoonk/status/1550896347691134977
  • https://www.bleepingcomputer.com/news/security/hacker-selling-twitter-account-data-of-54-million-users-for-30k/
  • https://venturebeat.com/2022/07/21/ransomware-attacks/
  • https://www.bleepingcomputer.com/news/security/digital-security-giant-entrust-breached-by-ransomware-gang/
  • https://venturebeat.com/2022/07/14/startups-without-a-ciso-youre-losing-out-on-a-big-business-opportunity/amp/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Ransomware infections and payments decline, CISO urges patching Windows 11 patch bug, more Chrome fixes, stress in cybersecurity, possibly regulating BGP, and commentary on the CU Intersect conference.

  • https://www.darkreading.com/threat-intelligence/ransomware-attempts-flag-as-payments-also-decline
  • https://threatpost.com/cisa-urges-patch-11-bug/180235/
  • https://www.forbes.com/sites/daveywinder/2022/07/20/google-sees-double-as-chrome-security-update-2-arrives-for-windows-mac--linux/
  • https://www.csoonline.com/article/3667490/cybersecurity-is-a-constant-fire-drill-that-s-not-just-bad-it-s-dangerous.html
  • https://www.nextgov.com/cybersecurity/2022/07/cisa-urges-fcc-prioritize-national-security-internet-routing-probe/374077/
  • https://cuintersect.com/
  • https://www.cubroadcast.com/episodes/cuintersect22-how-to-enhance-small-and-midsized-businesses-cybersecurity

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On this Throwback Thursday episode from March 29, 2022 - Email remains the most common vector for criminals to exploit. Chuck Sirois discusses how PhishFacts (https://phishfacts.com) can help SMBs identify misconfigured email configurations that criminals may leverage.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

J.J. Powell of Cyber Defense Group (https://www.cdg.io/) discusses his career journey from police officer to system administrator to CISO and now as leading virtual CISO services. He is also a pivotal component into my decision to leave corporate and become an independent vCISO - listen to find out what was "the straw that broke the camel's back" for me!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Shodan special offer, banks need to implement best practices, five key things from smal org CISOs, Netwrix Auditor bug, and on the road challenges.

  • https://www.shodan.io/
  • https://fintechmagazine.com/banking/banks-need-best-practices-to-fight-rising-cyberattacks
  • https://thehackernews.com/2022/07/5-key-things-we-learned-from-cisos-of.html
  • https://thehackernews.com/2022/07/new-netwrix-auditor-bug-could-let.html

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Phishing campaign bypasses MFA, healthcare debt collection agency ransomware breach 1.9 million records, Log4Shell endemic, criminal hackers targeting Indian students, Florida Atlantic University received grant, and my cybersecurity path, including learning Python?

  • https://threatpost.com/large-scale-hishing-bypasses-mfa/180212/
  • https://www.theregister.com/AMP/2022/07/13/19m_patients_medical_data_exposed/
  • https://www.computerweekly.com/news/252522789/Log4Shell-on-its-way-to-becoming-endemic
  • https://thehackernews.com/2022/07/pakistani-hackers-targeting-indian.html
  • https://www.fau.edu/newsdesk/articles/cybersecurity-grant
  • https://youtu.be/NzJlE0YLSiA
  • https://www.youtube.com/watch?app=desktop&v=7utwZYKweho&ab_channel=TheCyberMentor

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On this week's Throwback Thursday from 3/22/2022 - The Certified Information Systems Security Professional, or CISSP, is considered by some to be the pinnacle of information security professional certifications, on par with the CPA. But why is that, and what differentiates it from other certifications? And why is it important for virtual CISOs to have and maintain this certification?


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Johanan (Jo) Dixon talks about life in the Marine Corps, as an MMA amateur fighter, and as a Title boxing instructor, and how these helped prepare him for his journey to cybersecurity and his current role with Halcyon (https://www.halcyon.ai/). And he's starting up a new podcast!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Rogers service interruption, hacking a Honda, the future of certifications, and Monday thoughts.

  • https://www.reuters.com/business/media-telecom/rogers-communications-services-down-thousands-users-downdetector-2022-07-08/
  • https://blog.cloudflare.com/cloudflares-view-of-the-rogers-communications-outage-in-canada/
  • https://www.coguard.io/post/canada-rogers-outage-root-cause-analysis
  • https://www.vice.com/en/article/z34xnw/hackers-say-they-can-unlock-and-start-honda-cars-remotely
  • https://www.infosecurity-magazine.com/magazine-features/future-cybersecurity-certifications/
  • https://www.linkedin.com/posts/gregoryschaffer_motivationalmonday-mondaythoughts-career-activity-6952245177432387584-Knql

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Marriott breach third in four years, CISA alert for Maui ransomware, SMBs not leveraging MFA, free entry-level cybersecurity training, DoD bug bounty program, the illusion of short cuts, and a disturbing LinkedIn site allegedly distributing copyrighted cybersecurity books without author and publisher authorization.

  • https://www.cyberscoop.com/marriott-data-breach-baltimore/
  • https://www.cisa.gov/uscert/ncas/alerts/aa22-187a
  • https://www.helpnetsecurity.com/2022/07/08/smb-implement-mfa/
  • https://venturebeat.com/2022/07/04/dod-bug-bounty-program/
  • https://goodmenproject.com/featured-content/the-illusion-of-short-cuts-take-the-long-cut-kpkn/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On this week’s Throwback Thursday from 3/15/22, Ed Carroll joins us to discuss many of the initiatives he's involved with, including Edison Marks to apply AI to help SMBs (https://edisonmarks.com/), the Carolina Cyber Center to help with information security in North Carolina and beyond (https://carolinacybercenter.com/), and an update on the RETR3AT cyber security conference at beautiful Montreat College (https://www.montreat.edu/about/events/retr3at/).


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

William Birchett, President of Logos Systems and creator of the vCISO Network, discusses the virtual CISO space including elements that make a successful vCISO, the biggest threat to SMBs (it's not ransomware!), and his future plans to help the vCISO field through Logos Systems, the vCISO Network, and other endeavors.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Ransom returned with gains, cyber risks in space, NIST CSF 2.0 coming, HackerOne employee claims bug bounties for themselves, bug bounty programs offer hope for cyber skills gap, and thoughts on another approach to closing that gap.

  • https://www.dw.com/en/dutch-university-wins-big-after-bitcoin-ransom-returned/a-62337229
  • https://cybernews.com/editorial/in-space-cutting-losses-invite-cyberattacks/
  • https://insidecybersecurity.com/share/13585
  • https://www.bleepingcomputer.com/news/security/rogue-hackerone-employee-steals-bug-reports-to-sell-on-the-side/
  • https://www.computing.co.uk/sponsored/4050714/bug-bounty-cyber-skills
  • https://www.linkedin.com/feed/update/urn:li:activity:6949703194893578240/
  • https://www.linkedin.com/feed/update/urn:li:activity:6949499768611966977/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Microsoft Office 365 Office feature could enable ransomware infection, MedusaLocker alert from CISA, California breach of gun enthusiasts' PII, human error remains the top security issue according to a SANS report, and a tribute to an extraordinary man. 

  • https://www.itsecurityguru.org/2022/06/23/microsoft-office-365-feature-could-help-ransomware-attackers-infiltrate-cloud-files/
  • https://www.cisa.gov/uscert/ncas/alerts/aa22-181a
  • https://www.theregister.com/2022/06/30/california_websites_expose_personal_data/
  • https://www.techtarget.com/searchsecurity/news/252522226/SANS-Institute-Human-error-remains-the-top-security-issue
  • https://www.linkedin.com/feed/update/urn:li:activity:6948688755394318336/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On this week’s Throwback Thursday from 3/8/22, Craig Sandman of Symbol Security (https://symbolsecurity.com/) and vCISONews (https://www.vcisonews.com/) joins us to discuss the importance of effective security awareness training for SMBs and the virtual CISO role.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

On this episode of The Virtual CISO Moment podcast, Dick Wilkinson, CTO and Co-founder of Proof Labs, discusses securing space, the transition to entrepreneur, the vCISO discipline, and more!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Japanese man loses USB stick with citizen data after night of drinking, ransomware more about extortion, MITEL VOIP exploit, "the hateful eight" ransomware groups, new Colorado facia recognition law, and thoughts on the Offensive Security free Kali Linux Twitch stream training after two sessions.

  • https://www.bbc.com/news/world-asia-61921222.amp
  • https://www.theregister.com/2022/06/25/ransomware_gangs_extortion_feature/
  • https://www.crowdstrike.com/blog/novel-exploit-detected-in-mitel-voip-appliance/
  • https://securelist.com/modern-ransomware-groups-ttps/106824/
  • https://www.jdsupra.com/legalnews/colorado-law-restricts-use-of-facial-5065947/
  • https://www.twitch.tv/offsecofficial

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Pegasus in Europe, Log4Shell affecting VMware, voicemail scam (because it works), SMS Bomber malware, and how financial firms can benefit from a vCISO - plus more commentary and analysis of the vCISO field.

  • https://thehackernews.com/2022/06/nso-confirms-pegasus-spyware-used-by-at.html
  • https://www.helpnetsecurity.com/2022/06/24/log4shell-vmware-horizon/
  • https://threatpost.com/voicemail-phishing-scam-steals-microsoft-credentials/180005/
  • https://www.itsecurityguru.org/2022/06/23/chinese-hackers-distributing-sms-bomber-tool-with-malware-hidden-inside/
  • https://biztechmagazine.com/article/2022/06/what-vciso-and-how-can-financial-firms-benefit

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

This week's Throwback Thursday episode is from March 1, 2022 - Chief Information Security Officer David Baker gives insight into the challenges of an SMB CISO.

Guest opinions are their own and not the views of their employer.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Nick Santora, CEO of Curricula (curricula.com), discusses information security awareness and how Curricula uses storytelling to make both short term and long term impressions, resulting in increased security across the organization. He also discusses his path to entrepreneur, challenges in the SMB infosec awareness space, and "wisdom walks"!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Russian botnet shut down, CFOs see cybersecurity gaps, security lapses in SMBs, university students defeat 21st century vehicle boot, and a free pen testing class coming soon to Twitch! Plus my thoughts on this past weekend's #infosec Twitter conference issue.

  • https://thehackernews.com/2022/06/authorities-shut-down-russian-rsocks.html
  • https://www.cfodive.com/news/cfos-ceos-see-cybersecurity-gaps-accenture/624831/
  • https://www.scmagazine.com/brief/risk-management/cybersecurity-lapses-in-smbs-examined
  • https://driving.ca/auto-news/news/students-defeat-new-barnacle-parking-boot-skip-fines-and-get-free-internet
  • https://www.bleepingcomputer.com/news/security/offsec-to-stream-kali-linux-penetration-testing-course-on-twitch/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Internet Explorer is retired, risks with IoT, Facebook Messenger phish, diving into the Veeam ransomware report, and one of the hardest things I've had to do in my professional career.

  • https://www.cnn.com/2022/06/15/tech/internet-explorer-dead/index.html
  • https://www.forbes.com/sites/forbestechcouncil/2022/06/16/cybersecurity-and-risk-management-in-the-internet-of-things/
  • https://threatpost.com/acebook-messenger-scam/179977/
  • https://go.veeam.com/wp-ransomware-trends-report-2022

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Matt Santill, Founder and CEO of Cyber Security Services https://www.cybersecurityservices.com/ discusses the challenges of a vCISO, what is the most significant business risk, how he became interested in information security, and his career progression to CISO and on to business owner.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

A third of organizations hit by ransomware were forced to close temporarily or permanently, job cuts hit cybersecurity industry despite surging growth from ransomware attacks, four signs you may be ignoring your health for your career, and Cyber Security for Small Organisations webinar.

  • https://www.techrepublic.com/article/organizations-hit-by-ransomware-shut-down/
  • https://www.cnbc.com/2022/06/10/job-cuts-hit-cybersecurity-firms-despite-surging-growth-from-attacks.html
  • https://www.reefguardian.org/health-for-your-career/
  • https://ncsc-production.microsoftcrmportals.com/event/sessions?id=Digital_Loft_Template3613648229

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Small businesses aren't ready for a cyberattack, security leaders metrics and reporting, cloud migration, NIST supply chain guidance.

  • https://www.cnbc.com/2022/05/21/americas-small-businesses-arent-ready-for-a-cyberattack.html
  • https://biztechmagazine.com/article/2022/05/how-should-cybersecurity-leaders-report-their-progress
  • https://securityboulevard.com/2022/06/six-things-to-check-before-moving-to-the-cloud-to-avoid-pitfalls-in-the-long-run/
  • https://www.helpnetsecurity.com/2022/05/06/cybersecurity-supply-chain-risk/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

James Farley, Partner Development Manager, Cybersecurity at ConnectWise (connectwise.com), discusses migrating from insurance to IT sales to supporting Managed Service Providers, as well as running to beat the stress, including reaching a goal many never achieve! 


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Unpacking the Verizon Data Breach Investigations Report, a new "Man on the Side" attack (and what is that?),  this week's resource highlight - InfoSecSherpa, and "paying your dues".

  • https://securityboulevard.com/2022/06/verizon-dbir-2022-whats-worth-acting-on/
  • https://thehackernews.com/2022/06/chinese-luoyu-hackers-using-man-on-side.html
  • https://en.wikipedia.org/wiki/Man-on-the-side_attack
  • https://infosecsherpa.medium.com/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Confluence zero day, Microsoft zero day exploitation example, Ransomware roundup, and my reaction to a LinkedIn post about virtual CISO services that went semi-viral for the wrong reasons.

We need to do better in the virtual CISO space.

  • https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/
  • https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/
  • https://techcrunch.com/2022/06/01/china-backed-hackers-are-exploiting-unpatched-microsoft-zero-day/
  • https://www.csoonline.com/article/3662038/ransomware-roundup-system-locking-malware-dominates-headlines.html

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Rob Black, Founder and CEO of Fractional CISO (https://fractionalciso.com) talks about providing fractional/virtual CISO services to midsized SaaS technical organizations as well as other businesses, his story of starting Fractional CISO, and how he sees the SMB threat environment.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Microsoft Zero Day, CISA adds 75 vulns to critical list, and cybersecurity as Corporate Social Responsibility.

Today we honor all who gave their life for freedom.

  • https://thehackernews.com/2022/05/watch-out-researchers-spot-new.html
  • https://www.forbes.com/sites/daveywinder/2022/05/26/us-cybersecurity-agency-strongly-urges-you-patch-these-75-actively-exploited-flaws/?sh=7c03a1b26381
  • https://venturebeat.com/2022/05/26/cybersecurity-is-a-corporate-social-responsibility-especially-in-times-of-war/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Verizon DBIR, 10 exploited access points, email is still a problem (surprise), four tips for entry-level cyber analysts, and ransomware with a twist.

Be kind to each other. Please.

  • https://www.verizon.com/business/resources/reports/2022/dbir/2022-data-breach-investigations-report-dbir.pdf
  • https://www.securitymagazine.com/articles/97676-cisa-outlines-10-initial-access-points-exploited-by-hackers
  • https://www.scmagazine.com/analysis/email-security/employees-email-still-drives-most-of-the-data-loss-at-organizations
  • https://www.redglobal.com/news-blog/cybersecurity-jobs-4-tips-every-budding-cybersecurity-analyst-should-know
  • https://www.tripwire.com/state-of-security/security-data-protection/ransomware-demands-acts-of-kindness-to-get-your-files-back/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Kyle Cravens, Founder/Managing Principal of the staffing and recruiting firm Key Resource Group, LLC (https://www.krgnow.com/), joins us to discuss the IT and Information Security recruiting environment including tips on how a candidate can improve their chances of landing the position; how COVID and remote work has changed the environment, and how his faith guides his journey.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Conti disbands, DOJ directs good-faith security research should not be charged, governments consider ransomware self-insuring, and just say no to saying no in information security.

  • https://www.bleepingcomputer.com/news/security/conti-ransomware-shuts-down-operation-rebrands-into-smaller-units/
  • https://www.justice.gov/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act
  • https://www.govtech.com/computing/facing-cyber-insurance-woes-local-governments-find-other-options
  • https://www.helpnetsecurity.com/2022/05/17/security-department-refuses-request/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Remote work, IT and infosec staff stress and ransomware - a canary in the coal mine?

  • https://www.helpnetsecurity.com/2022/05/17/state-of-security/
  • https://www.helpnetsecurity.com/2022/05/18/it-help-desk-stress/
  • https://www.techtarget.com/searchsecurity/news/252518151/Iranian-APT-Cobalt-Illusion-launching-ransomware-attacks
  • https://thehackernews.com/2022/05/russian-conti-ransomware-gang-threatens.html
  • https://finance.yahoo.com/news/cybersecurity-research-76-organizations-admit-161500884.html
  • https://www.csoonline.com/article/3660636/cisos-worried-about-material-attacks-boardroom-backing.html
  • https://www.prnewswire.com/news-releases/nacd-responds-to-sec-rule-proposal-on-public-company-cybersecurity-risk-management-strategy-governance-and-incident-disclosure-301546494.html

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Clark Cummings joins us to discuss enterprise risk management, how to recognize "risk collisions", and provide practical risk management advice for small and midsized businesses.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

What is the secret to security (or any business) success? Listen to find out.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

The Virtual CISO Moment aims to inform and entertain. We hope you will join us! All episodes drop at 8:00 AM Central (US).

  • Monday - The VCM Quick Strike (audio only)
  • Tuesday - The Virtual CISO Moment Conversations (audio and video)
  • Friday - The Virtual CISO Moment Wrap Up

Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Many topics, including Lincoln College, CISA and MSPs, SEC and Board of Directors, and Pegasus.

  • https://www.engadget.com/lincoln-college-ransomware-attack-shut-down-covid-19-164917483.html
  • https://www.cisa.gov/uscert/ncas/current-activity/2022/05/11/cisa-joins-partners-release-advisory-protecting-msps-and-their
  • https://media-exp1.licdn.com/dms/document/C561FAQE9H1UdCeHoyg/feedshare-document-pdf-analyzed/0/1652377478990?e=1653523200&v=beta&t=h52Z9d1TKwui7If9gNJTf03j1YQUPLzIwQRyxAABFEQ
  • https://www.weforum.org/agenda/2022/03/cybersecurity-rules-prepare/
  • https://www.nytimes.com/2022/05/12/us/politics/fbi-pegasus-spyware-israel.html

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Mike Rastigue with Crum & Forster joins us to discuss cyber insurance and one way that his organization is helping SMBs to be both better prepared to meet cyber insurance underwriting requirements and increase their security posture.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Last week I came across two instances on LinkedIn of apparent predatory practices in the information security field - one related to regulatory compliance, another for a consultant certification. We have to do better as an industry.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Conti continues, ransomware payouts, supply chain breach in higher ed, and NIST 800-161r1 release.

  • https://www.providencejournal.com/story/news/politics/2022/05/04/malware-used-ripta-hack-identified-conti-strain-russian-cybercriminals/9635388002/
  • https://cybernews.com/security/russian-passport-details-exposed-by-database-leak/
  • https://thejournal.com/articles/2022/05/05/565-schools-over-1m-students-impacted-by-illuminate-data-breach-2nd-colorado-district-affected.aspx
  • https://www.helpnetsecurity.com/2022/05/06/cybersecurity-supply-chain-risk/
  • https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1.pdf

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Frank Platt of Infosec Alliance LLC (https://www.infosecalliance.com/) joins us to discuss many infosec topics, including risk management, and CMMC...and BBQ!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

A business continuity exercise to continue operations after a nuclear attack? Maybe not as crazy a scenario to plan for as we might have thought. Today's Quick Strike touches on that, including an interesting option for a data center that could possibly survive such an attack. It's not what you think...

  • https://www.amazon.com/Nuclear-War-Survival-Skills-Instructions/dp/1634502973/
  • https://www.amazon.com/Information-Security-Small-Midsized-Businesses/dp/1733066845/
  • https://www.linkedin.com/posts/todd-byars-9b669a6_solaronemonolith-toddwbyars-computerdudes-activity-6926164507580919808-EEKp/

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Advice and resources for those looking for a cybersecurity entry level position, updates on vulns/exploits.

  • https://www.wgu.edu/blog/guide-entry-level-cyber-security-jobs2102.html
  • https://blogs.cisco.com/security/the-more-you-know-job-searching-interviewing
  • https://www.linkedin.com/company/breaking-into-cybersecurity/
  • https://www.darkreading.com/vulnerabilities-threats/cisa-log4shell-most-exploited-vulnerability-2021
  • https://www.bleepingcomputer.com/news/security/okta-lapsus-breach-lasted-only-25-minutes-hit-2-customers/amp/
  • https://www.ic3.gov/Media/News/2022/220420.pdf
  • https://store.isaca.org/s/community-event?id=a334w000004TXbEAAW#/Overview

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

All small businesses have their own genesis story. vCISO Services began as many do; an idea in a home office, then a migration to an outside work environment, and then further growth. Recognizing, honoring, remembering, and respecting roots is a critical component of the success of a business.

Note - Because this was an on-site video and was not recorded in the studio; the video and audio quality is a bit less.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

CISA tools, improving communications, and scholarship recipient.

https://www.cisa.gov/free-cybersecurity-services-and-tools


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Conti, BlackCat/ALPHV, DDoSecrets.

  • https://ddosecrets.substack.com/
  • https://www.csoonline.com/article/3657875/ransomware-plagues-finance-sector-as-cyberattacks-get-more-complex.html
  • https://krebsonsecurity.com/2022/04/contis-ransomware-toll-on-the-healthcare-industry/
  • https://www.cisa.gov/uscert/ncas/alerts/aa21-265a
  • https://www.cyber.nj.gov/alerts-advisories/blackcatalphv-ransomware-indicators-of-compromise

This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Don Baham is very active in both the local and on-line information security communities, as well as having extensive experience helping SMBs with information security needs. He joins us to discuss challenges and opportunities including observations on the cyber security supply chain issue and possible ways to address.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Virtual CISO resources:

https://www.linkedin.com/groups/12095465/

https://www.vcisonews.com/

https://vciso.network/


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Discussed in this week's wrap up:

https://www.techrepublic.com/article/supply-chain-cyberattacks-jumped-51-in-2021/

https://threatpost.com/microsoft-zero-days-wormable-bugs/179273/

https://healthitsecurity.com/news/cisa-issues-guidance-on-cybersecurity-information-sharing

https://www.nationalcybersummit.com/

https://secondchancebook.org


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Chris Bedel, President and CEO of Bedel Security (bedelsecurity.com) talks about how the virtual CISO fits in to, compliments, and enhances financial institutions' information security program and posture. He also touches on history and future of the virtual CISO. If you're a virtual CISO for financial institutions or are interested in how a virtual CISO benefits financial institutions, this is a must-see episode packed with useful information!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Discussed in this week's wrap up:

https://www.techrepublic.com/article/credit-agency-warns-weak-cybersecurity-defenses-could-hurt-a-companys-credit-rating-even-before-an-attack/

https://www.techrepublic.com/article/fbi-investing-millions-in-software-to-monitor-social-media-platforms/

https://techcrunch.com/2022/02/07/irs-facial-recognition-id-me/

Ad link:

https://www.amazon.com/Information-Security-Small-Midsized-Businesses/dp/1733066845/

Finally, a correction: The Tennessee Bankers Association Strategic Technology, Risk, and Security Conference https://tnbankers.org/event/strategic-technology-risk-security-conference/ is April 27th, not April 28th as noted in the episode.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Bob Quandt, owner of Bullseye Compliance (https://bullseyecompliance.com) joins VCM for a conversation that ranges from issues and trends in SMB security, entrepreneurship and making a difference, fitness and stress management, application of military experience to infosec, and more!


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Email remains the most common vector for criminals to exploit. Chuck Sirois discusses how PhishFacts (https://phishfacts.com) can help SMBs identify misconfigured email configurations that criminals may leverage.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

The Certified Information Systems Security Professional, or CISSP, is considered by some to be the pinnacle of information security professional certifications, on par with the CPA. But why is that, and what differentiates it from other certifications? And why is it important for virtual CISOs to have and maintain this certification?


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Ed Carroll joins us to discuss many of the initiatives he's involved with, including Edison Marks to apply AI to help SMBs (https://edisonmarks.com/), the Carolina Cyber Center to help with information security in North Carolina and beyond (https://carolinacybercenter.com/), and an update on the RETR3AT cyber security conference at beautiful Montreat College (https://www.montreat.edu/about/events/retr3at/).


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

While watching a report on the news this morning about items to consider to counter possible Russian cyber attacks related to the Ukraine-Russia crisis, I felt sadness. The reason may surprise you, or not. Find out why on today's special midweek installment of The Virtual CISO Moment.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Craig Sandman of Symbol Security (https://symbolsecurity.com/) and vCISONews (https://www.vcisonews.com/) joins us to discuss the importance of effective security awareness training for SMBs and the virtual CISO role.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Chief Information Security Officer David Baker gives insight into the challenges of an SMB CISO. 

Guest opinions are their own and not the views of their employer.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Threat awareness sources are many. One that is often overlooked is the news. Hear why being plugged into current events in real time is important. (And Greg says "yes I know the difference between emulate and emanate").


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Information security is difficult without a plan. Don't spin your wheels. Find a framework, find a coach, and find success.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

We delve in a bit deeper into business continuity exercise types - which is right for your business? We also have a special invitation.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

The security posture of a company is rooted in the company's culture - its approach and attention to information security across all levels of the organization.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Morning thoughts on how the virtual CISO fits in an organization, using the Three Lines of Defense (3LoD) model to illustrate.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Business Continuity Table Top Exercises (or BCP TTX, since it's easier to type) are important for identifying gaps in business continuity, disaster recovery, and incident response programs. Don't ignore this essential exercise, and don't treat it as just an information technology exercise.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

The virtual CISO is not a new discipline, but it is evolving. Like other security specialties, there are different approaches and skills offered. This is the first of several upcoming discussions on the virtual CISO space.  greg.schaffer@vcisoservices.com


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

After a hiatus, The Virtual CISO Moment returns with useful information from security experts who understand small and midsized business (SMB) security needs. No frills, no glamour, no transparent whiteboard text, no complex graphics, and no script - just a few minutes every Tuesday discussing SMB information security risk issues.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Metrics - security leaders talk about them often. But what is the one critical question they, and you, should ask about information security metrics?


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

The episode compares COVID-19 and information security risks...through a Chihuahua.


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Many small business owners are frightened now, unsure of how their business will survive. Many in the United States have applied for the PPP. But the combination of economic calamity, fear of infection, stress from lives upended , all create an environment for criminals to exploit. It's okay to be afraid, but don't let it lead you to becoming a victim.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

The COVID-19 pandemic has disrupted business operations on an unprecedented scale. It also presents an opportunity to learn and grow business operations. This will end, and the time to prepare for the "new normal" is now.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

The "hacker in a hoodie" image has been used for years by the media to call attention to articles about cyber security incidents. It's time that graphic is retired. Here's why.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

FUD - Fear, Uncertainty, and Doubt - is sometimes used to sell products or services. One popular FUD element is statistics, whether spinning valid numbers or making them up. Regardless of the type of FUD, bowing to the instinctual urges to respond can obfuscate genuine information security risks.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Information security theater, improvements that look and sound good but make no real impact to overall security stance of an organization, can do more harm than good. Are you understanding the information security risks of your organization before designing and implementing controls?


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Information Security and Information Technology Security are not the same. If your program is focused on Information Technology Security only, you've got gaps.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

In order to stay healthy, we need to exercise regularly. To maintain our information security program's fitness, we need to exercise it as well.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Information security policies direct the governance of the information security program. What are elements of effective policies, and what mistakes do SMBs often make with their information security policy program?


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Learn how quantitative information security risk assessments can help community institutions (and all small and midsized businesses). A presentation to the Bankers' Bank of the West Information Security for Community Institutions conference October 25, 2019.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Governance, Risk, and Compliance - how it can benefit information security for businesses of all sizes.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

In this extended episode, vCISO Services principal Greg Schaffer speaks at InfoSec Nashville 2019 about what a virtual CISO is and how they help small and midsized businesses.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

vCISO Services principal Greg Schaffer discusses the virtual CISO role in a short interview at the National Cyber Summit.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Greg discusses the announcement of vCISO Services, LLC's licensed quantitative information risk assessment offering based on The Open Group Open FAIR™ Body of Knowledge. https://www.prnewswire.com/news-releases/an-answer-for-cybersecurity-cost-exposure-300911336.html


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Greg concludes a three-part series breaking down ISO 27001 and ISO 27002, international standards for information security. Part three dives into the second half of the ISO 27002 control requirements.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Greg continues a three-part series breaking down ISO 27001 and ISO 27002, international standards for information security. Part two dives into the first half of the ISO 27002 control requirements.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Greg begins a three-part series breaking down ISO 27001 and ISO 27002, international standards for information security. Part one lays out the history and a glimpse at the structure of ISO 27000 and why it's important for SMBs.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Taken from a Facebook Live video July 26th (hence the lower video quality), Greg explains why the Virtual CISO Minute is now the Virtual CISO Moment,  talks about possible future use of the Facebook Live channel to help small and midsized businesses with information security topics, and invites current vCISOs or those interested in the space to join the Virtual CISO Exchange LinkedIn group at https://www.linkedin.com/groups/12095465/. Produced by vCISO Services, LLC. https://vcisoservices.com


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

There is a growing rift between the information security “haves” and “have nots,” and the threat actors know that as well. Cyber criminals increasingly target small and midsized businesses (SMBs) because they know SMBs likely do not have information security programs as robust as those large organizations have in place. Nor do they have experienced information security leadership, as the average annual cost of nearly $260,000 for a full-time CISO is out of the reach of most SMB budgets.  The Virtual CISO, or vCISO, has emerged to fill this need. While most SMBs cannot afford a full-time CISO, most also do not need one, just access to CISO expertise. Often as little as ten hours per month of a virtual CISO can bolster an SMB's information security program and posture to nearly the same level as if they had a full-time CISO on staff.  This presentation discusses why the virtual CISO has become a viable option for businesses, what to look for in a virtual CISO, and what a virtual CISO can and cannot do for your small or midsized business.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Thirty-four years ago, I worked as a porter (janitor) at a hotel in New Jersey. I took a year off between high school and college to decide where I wanted to direct my life - and to earn money for college. I promised myself that one day, when I had become successful, I would stay in that hotel. Recently it happened. I realized I learned an early lesson applicable to information security then. Watch to find out what it was.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

You've heard the term, but what is a Virtual CISO, or vCISO? This week's Virtual CISO Minute explains


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Compensating Controls: Is an audit exception regarding a failing primary control absolute? Maybe, maybe not. The risk may be mitigated by other methods - compensating controls.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

The Nashville Technology Council's Veterans Peer Group helps veterans land civilian jobs and enhance their careers in IT and information security in the Nashville/Middle Tennessee region. SMBs should look to a veteran when trying to fill these positions.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Quantitative risk assessments and how they can help your SMB's information security posture.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Qualitative risk assessments - the ones that produce those "heat maps" with the red (high risk), yellow (medium risk) and green (low risk) are a standard method for communicating information security risk. But they have limitations.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Information security risk assessments - why are they important?


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

SOC1, SOC2, what do they mean for your small business?  Find out in this week's installment of The vCISO Minute.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

A recent breach highlights the need for incident response testing, particularly about notification.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Microsoft released a patch for out-of-support operating systems this week, but that's usually not the case. If your business requires running old operating systems, usually due to legacy software or systems,  you need to reduce the risk running an outdated operating system brings by not relying on patches. Music by https://www.bensound.com/


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

The annual Verizon Data Breach Investigation Report will come out soon. What is it, and how does it benefit small and midsized businesses?


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

vCISO Services, LLC Principal Greg Schaffer discusses information security opportunities at the 2018 InfoSec Nashville conference. The Virtual CISO Moment (Minute) video series/podcast spun off from this discussion.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

vCISO Services, LLC Founding Principal Greg Schaffer explains Information Security as Risk Management at the National Cybersecurity Summit, Huntsville, Alabama, June 2018


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

Presentation at the Middle Tennessee State University Cyber Summit 2013


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

You treat your small or midsized business like a large corporation, why not secure it like one?

From the Virtual CISO Moment pre-series archives (2019).


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support

View Details

vCISO Services, LLC Founding Principal Greg Schaffer explains the purpose and calling for launching vCISO Services, LLC to the Christian Business Leaders Roundtable in 2017.


This episode is sponsored by · Anchor: The easiest way to make a podcast. https://anchor.fm/app


Send in a voice message: https://anchor.fm/virtual-ciso-moment/message Support this podcast: https://anchor.fm/virtual-ciso-moment/support