ReimaginingCyber is a series of fireside chats hosted by Rob Aragao and Stan Wisseman, Security Strategists with CyberRes, a Micro Focus line of business. In each episode, we’ll dive into the world of cybersecurity, exploring common challenges, trends, and solutions for today’s CISOs and CIOs. Every two weeks, a new guest—from industry experts to CISOs—will share what matters most to them. Each episode is short and bite-sized, running only 15-20 minutes.
CyberRes is a Micro Focus line of business, focused on helping companies protect, detect, and evolve their security framework and helping organizations become more cyber resilient. To learn more, visit CyberResilient.com. Micro Focus is a multinational software and information technology business, headquartered in the UK.
Hotel Wi-Fi has long been considered a cybersecurity risk—but what if you're connected to the correct network? In this episode of Reimagining Cyber, Tyler Moffitt examines CaptiveCrunch, a sophisticated campaign that compromises legitimate hotel and conference Wi-Fi infrastructure to intercept users before they ever reach the internet.
Discover how attackers manipulate DNS traffic, abuse device code authentication, bypass traditional phishing defenses, and deploy malware such as Cornflake and CocoShell to steal credentials, OAuth tokens, and corporate access. Tyler explains why familiar security signals—including genuine Wi-Fi networks, legitimate Microsoft login pages, and even multi-factor authentication—may no longer be enough to protect travellers.
Whether you're a business traveller, security leader, or IT professional, this episode offers practical guidance on reducing risk, securing remote connections, and adapting to a new generation of identity-based attacks.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Nearly 19,000 files reportedly connected to India’s Kudankulam Nuclear Power Plant appeared on a ransomware group’s leak site. The files allegedly included engineering drawings, facility layouts, supplier details, inspection records, project correspondence, and equipment photographs.
The plant’s operator says nuclear safety and security systems were not compromised. That distinction matters, but it does not make the exposed information worthless.
Ben interviews Tyler Moffitt about how attackers can collect intelligence without
penetrating a reactor, why contractors become attractive targets, and how individually mundane documents can combine into an operational map of critical infrastructure.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
A ransomware attack against Coca-Cola-owned Fairlife forced the company to temporarily suspend production across the United States. Product safety was not affected, but production-related systems were.
How does a cyberattack stop a physical product from being manufactured? Why would a company shut down production when there is no evidence that the product itself was compromised? And what does this tell us about the difference between restoring technology and restoring a business?
Ben interviews Tyler Moffitt about operational ransomware, manufacturing dependencies, containment decisions, and what organizations should learn from Fairlife’s response.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
What happens when a trusted ransomware negotiator secretly works for the very hackers he's supposed to stop?
In this episode of Reimagining Cyber, Tyler Moffitt unpacks one of the most shocking insider threat cases in recent cybersecurity history. A ransomware negotiator admitted to providing confidential victim information—including insurance limits and negotiation strategies—to the BlackCat (ALPHV) ransomware gang while representing organizations during active ransomware attacks.
Learn how ransomware negotiations really work, why information is the most valuable asset during a cyber incident, and what this case reveals about ransomware-as-a-service, cyber insurance, incident response, and insider threats. Whether you're a CISO, security leader, IT professional, or simply interested in cybersecurity, this episode offers practical lessons on trust, risk, and protecting sensitive information when every decision matters.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Federal prosecutors have charged an alleged member of the Scattered Spider cybercrime group in a case that highlights how modern cyber investigations are evolving. While the arrest itself made headlines, one detail stood out: investigators reportedly used Microsoft's Global Device ID (GDID), alongside other forensic evidence, to help connect the dots.
In this episode of Reimagining Cyber, Tyler Moffitt unpacks what makes this investigation so significant.
The conversation explores:
The biggest takeaway? Cybersecurity is no longer just about protecting user accounts. As attackers become more effective at impersonating people, defenders—and investigators—are increasingly relying on device identity, telemetry, and data correlation to uncover malicious activity.
If you enjoyed this episode, please rate, review, and share Reimagining Cyber. New episodes are released every Wednesday.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
For years, cybersecurity assumed attackers had to break into organizations.
Today, they increasingly just log in.
Valid credentials, stolen browser sessions, OAuth tokens, help desk social engineering,and underground marketplaces have fundamentally changed how attacks unfold.
So why are organizations still thinking about identity the same way they did five years ago?
In this episode, Tyler Moffitt discusses the biggest misconceptions around identity
security, why trust has become a commodity, and why cyber resilience requires more than prevention alone.
Relevant links:
'What defenders are still getting wrong' webcast series with Tyler Moffitt
https://www.brighttalk.com/webcast/8241/646699?utm_source=LinkedIn&utm_medium=brighttalk&utm_campaign=646699
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Every week brings another breach headline. A retailer is compromised. An airline suffers a cyberattack. A ransomware gang claims another victim. A cryptocurrency company loses sensitive data.
The victims change, the industries change, and the attackers sometimes change—but many of today's most significant breaches follow a remarkably similar pattern.
In this episode of Reimagining Cyber, Tyler Moffitt breaks down the common attack chain behind modern cyberattacks and explains why threat actors continue to rely on the same core tactics year after year. From phishing, social engineering, and credential theft to identity compromise, privilege escalation, data access, and extortion, the conversation explores the techniques that repeatedly appear across major incidents.
The episode examines why identity has become the primary target for attackers, how groups such as Scattered Spider have demonstrated the power of identity-based attacks, and why data theft and extortion are increasingly replacing traditional ransomware operations.
Rather than focusing on the company named in the latest headline, security leaders and practitioners should focus on the attack path itself. Understanding how attackers gain access, move through environments, and monetize breaches reveals the patterns that matter most—and the defensive strategies that can make the greatest difference.
Key topics include:
Whether you're a CISO, security practitioner, IT leader, or simply interested in the evolving threat landscape, this episode provides valuable insight into the techniques driving today's most impactful breaches—and why understanding the playbook is critical for defending against tomorrow's attacks.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
For years, cybersecurity leaders have focused on identity as the new perimeter. MFA, Zero Trust, SSO, and identity protection became the center of modern security strategies.
But while everyone was focused on identity, attackers never stopped targeting something much older: internet-facing infrastructure.
VPNs. Firewalls. Remote access appliances.
Recent attacks involving Check Point, Fortinet, Ivanti, SonicWall, and others show that the perimeter never really disappeared.
In this episode, Tyler Moffitt discusses why edge devices remain prime ransomware targets, why patch windows matter more than ever, and why vulnerability management remains one of cybersecurity's most important fundamentals.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Scattered Spider has become one of the most disruptive cybercrime groups in the world—not because of advanced malware or zero-day exploits, but because of its mastery of social engineering and identity attacks.
In this episode, Tyler Moffitt explores how the group is evolving its tactics. Rather than targeting organizations at random, Scattered Spider appears to be moving industry by industry, reusing successful playbooks across sectors including casinos, retail, insurance, and airlines. Once they understand how one organization handles identity verification, help desk requests, and MFA resets, they can apply those same techniques across an entire industry.
Tyler reveals:
The key takeaway: modern attackers don't always need to hack their way in—they can simply convince someone to open the door. As Scattered Spider continues to refine its approach, organizations must rethink not just how they secure systems, but how they verify trust.
Identity is the new perimeter—and Scattered Spider may be proving it better than anyone else.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
ClickFix is a fast-growing social engineering technique appearing in malware campaigns, compromised websites, fake CAPTCHA prompts, and browser verification scams.
In this episode Tyler Moffitt explains how attackers compromise legitimate sites by exploiting unpatched CMS or plugins, inject malicious JavaScript, and then trick visitors into “verifying” by opening Run/PowerShell and pasting a preloaded command that downloads malware, leading to info stealers and potentially ransomware.
ClickFix is effective because it leverages trusted brands, bypasses traditional phishing defenses, scales via high-traffic sites, and is increasingly polished through AI. They connect this to the shrinking “patch window,” emphasizing rapid patching, reducing internet exposure, monitoring website integrity, updating user training to avoid pasting commands, and layering defenses like EDR/MDR and DNS filtering.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
The 2026 Verizon DBIR is here — and one finding changes the conversation around cyber risk.
For years, the industry has focused on identity as the primary attack surface. But according to the latest Data Breach Investigations Report, vulnerability exploitation has now overtaken credential abuse as the most common initial access vector in breaches.
In this episode of Reimagining Cyber, Tyler Moffitt breaks down what the report really means for defenders, MSPs, and SMBs. He explores why attackers are moving faster than patch cycles, how AI is accelerating both exploitation and phishing, and why “identity vs. patching” is the wrong debate.
He also unpacks:
Key takeaway:
“Identity is the new perimeter, but vulnerability management is still the unlocked window.”
If you work in cybersecurity, IT, risk management, or support SMB environments, this episode delivers practical insight into where attackers are succeeding — and what organizations need to do next.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Google says it may have uncovered the first real-world case of threat actors using AI assistance during zero-day exploit development — but is this truly a cybersecurity turning point, or another overhyped AI headline?
In this episode of Reimagining Cyber, Tyler Moffitt unpacks what actually happened, what Google discovered, and why the reality is both less dramatic — and potentially more dangerous — than the headlines suggest.
Tyler looks at how AI is accelerating exploit research, lowering the barrier for mid-tier cybercriminals, and compressing the timeline between vulnerability discovery and active attacks. He explains why this isn’t “Skynet for hackers,” but rather AI acting as a force multiplier that makes attackers faster, cheaper, and more scalable.
The conversation also covers:
If you’ve been wondering whether AI is truly changing the threat landscape — or just accelerating the one we already have — this episode breaks it down clearly and practically.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of Reimagining Cyber, host Rob Aragao sits down with MK Palmore to explore why small and medium-sized businesses are becoming prime targets for cyberattacks — and why traditional enterprise security models often fail them.
Drawing on more than three decades of experience across the FBI and Fortune 500 leadership roles, MK shares how SMBs can rethink cybersecurity through a more scalable, cost-effective “fractional CISO” approach. The conversation covers the biggest mistakes growing companies make, why reactive security strategies create long-term risk, and how organizations can build security maturity without enterprise-sized budgets.
Rob and MK also discuss:
A practical and forward-looking conversation for business leaders, security practitioners, and growing organizations navigating today’s evolving cyber landscape.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this milestone 200th episode of Reimagining Cyber, hosts Rob Aragao and Tyler Moffitt reflect on the journey so far—exploring how cybersecurity has evolved over the past five years and where it’s headed next.
From the early focus on cyber resilience to today’s rapidly shifting threat landscape, they break down the biggest changes shaping the industry: the rise of ransomware as a business model, the growing impact of supply chain attacks, and why identity has become the new perimeter. They also debate a key question—are attackers getting more sophisticated, or just better at scaling what already works?
The conversation dives into the real-world impact of AI on both defenders and attackers, separating hype from reality, and examining how automation, tool overload, and complexity are affecting security teams. Rob and Tyler also tackle persistent challenges like phishing, human risk, and why even after decades of awareness training, the fundamentals still matter.
Looking ahead, they share candid perspectives on what organizations are getting wrong, where security investments should shift, and why prevention, prediction, and business alignment are more critical than ever. Plus, insights into the evolving role of the CISO as a true business leader.
Whether you’ve been listening since episode one or are just joining, this episode offers a thoughtful, no-nonsense look at the past, present, and future of cybersecurity.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Cybersecurity has entered a new era—and prevention alone is no longer enough. In this episode, Doug Merritt, CEO of Aviatrix and former CEO of Splunk, joins us to break down why security leaders must fundamentally rethink their approach. With decades of experience across Cisco, SAP, and the evolution of modern security operations, Doug brings a sharp, operator-level perspective on what’s changing—and what CISOs need to do now.
As AI accelerates attacker capabilities and cloud environments introduce unprecedented exposure, the traditional playbook is breaking down. Sophisticated threats are no longer rare—they’re scalable, automated, and increasingly successful. Meanwhile, most organizations are still over-investing in vulnerability patching while underestimating the importance of containment.
We explore what this shift really means in practice:
Using powerful analogies—like submarine breach containment—we break down how modern organizations can limit the damage of inevitable attacks and build true cyber resilience.
For CISOs and security leaders, this is a conversation about reframing success: not just keeping attackers out, but ensuring that when they get in, the business survives.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of Reimagining Cyber, Tyler Moffitt is joined by Mike DePalma to break down the biggest insights from the OpenText 2026 Cybersecurity Threat Report—and what they mean for MSPs and their customers.
They explore how today’s threats are becoming more targeted, automated, and AI-driven, why small and mid-sized businesses are the primary target, and what’s changing across phishing, ransomware, and identity-based attacks.
You’ll learn:
A fast, practical look at the trends shaping cybersecurity—and how to respond.
Relevant Links:
The report:
https://cybersecurity.opentext.com/threat-report/
Interactive Executive Summary:
https://indd.adobe.com/view/014203fa-4c23-44b7-87e6-5b786d93e628
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Inspired by the Artemis II mission, this episode explores cybersecurity in space and how NASA protects mission-critical systems. Rob Aragao speaks with NASA cybersecurity expert Tiffany Snyder about securing satellites, spacecraft, and space communications, and how cyber risk is managed across complex space missions.
Learn how NASA approaches space cybersecurity, risk management, supply chain security, and AI in cybersecurity, plus the challenges of protecting both ground systems and orbital infrastructure as the commercial space industryrapidly expands.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, cybersecurity expert Tyler Moffitt unpacks how modern cyberattacks have evolved into a seamless, scalable pipeline. What once appeared as separate threats—phishing, info stealers, credential theft, and ransomware—are now deeply interconnected stages of a single attack chain.
The conversation explores how attackers no longer need to “hack” their way in. Instead, they log in using stolen credentials and session data bought and sold in thriving underground marketplaces. With the rise of automated platforms and tools powered by AI, cybercrime has become more accessible, efficient, and difficult to detect than ever before.
Tyler breaks down the full attack lifecycle—from initial infection to credential theft, marketplace distribution, and eventual account takeover—highlighting why traditional defenses are struggling to keep up. The episode also examines the declining reliance on ransomware, as attackers increasingly favor silent data exfiltration and extortion tactics that are faster, quieter, and often more profitable.
For defenders, the message is clear: identity is now the frontline. With attackers blending in as legitimate users, organizations must shift their focus from keeping threats out to detecting suspicious behavior from within.
A sobering look at the current state of cybersecurity—and why the biggest threat may already be inside.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Identity has long been the foundation of cybersecurity—but what if that foundation is starting to crack?
In this episode of Reimagining Cyber, Tyler Moffitt unpacks a major shift happening right now: attackers aren’t breaking in anymore—they’re logging in. As AI accelerates phishing, fuels hyper-personalized social engineering, and powers a growing underground market for stolen credentials, traditional defenses like passwords and even MFA are being quietly bypassed.
Tyler explains how identity has become the new primary attack surface, why concepts like “trusted users” no longer hold up, and how session hijacking, info-stealer malware, and token theft are changing the rules of the game. From help desk impersonation attacks to the rise of deepfake-enabled fraud, this conversation reveals just how far attackers have evolved.
Most importantly, the episode explores what organizations are getting wrong—and what they need to do differently. From shortening trust windows and monitoring behavior to embracing layered defenses and a true zero trust mindset, this is a wake-up call for anyone relying on identity as a security perimeter.
If you’re still treating identity as proof of trust, it’s time to rethink everything.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of Re-Imagining Cyber, host Tyler Moffitt sits down with senior threat research analyst Kelvin Murray to unpack a hard truth: luck has nothing to do with surviving a cyber attack.
From the rise of AI-powered cybercrime to the persistence of old attack methods like RDP, the conversation explores why ransomware gangs continue to thrive in an increasingly industrialized underground economy. The duo breaks down how cybercrime now operates more like a business—complete with subscription models, affiliate programs, and even “ransomware-as-a-service.”
They also dive into:
The key takeaway? Technology alone isn’t the ultimate defense—preparation, training, and strong security fundamentals are.
If you think cyber resilience comes down to luck, think again.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
What if the next cyberattack doesn’t just steal your data—but turns off your water, power, or access to healthcare?
In this eye-opening episode, Josh Corman (I Am The Cavalry Dot Org) returns to unpack a rapidly evolving threat landscape where cyberattacks are no longer just about information theft—they’re about real-world disruption and destruction. From nation-state actors pre-positioning inside critical infrastructure to the chilling reality of “digital time bombs” lying dormant in water and power systems, Josh explains why the rules of cybersecurity are changing—and why we’re not ready.
The conversation dives into the rise of campaigns like Volt Typhoon, the strategic implications of a potential Taiwan conflict, and how adversaries are targeting civilian infrastructure to sow chaos and weaken response efforts. Josh also shares insights from his “Undisruptable 27” initiative, focused on protecting the most critical lifeline systems before it’s too late.
But this isn’t just about global conflict—it’s personal. Listeners will walk away with practical steps to protect their households, challenge assumptions about resilience and insurance, and rethink what preparedness really means in a world where cyber and physical risks collide.
This is a candid, sobering, and essential discussion on the future of cyber warfare—and what you can do about it today.
Relevant links:
I Am the Cavalry Dot Org
Undisruptable27
Institute for Security and Technology
Unrestricted Warfare - China's Master Plan to Destroy America
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
AI is transforming every corner of technology—but it’s also creating an entirely new frontier for cybersecurity.
In just a few short years, AI security has exploded into one of the fastest-growing segments in the industry. New startups are emerging almost weekly, regulators are racing to keep up, and security leaders are grappling with a fundamental question: how do you secure systems that are learning, evolving, and increasingly making decisions on their own?
Today’s guest has been tracking the cybersecurity industry longer—and more closely—than almost anyone.
Richard Stiennon is a renowned cybersecurity analyst, industry historian, and author of The Security Yearbook, widely regarded as the most comprehensive desk reference for the cybersecurity market. Now he’s turning his attention to the next era of digital risk.
His new book, Guardians of the Machine Age: Why AI Security Will Define the Future of Digital, is released this Wednesday, March 11—the same day this episode drops.
In this conversation, we explore why AI security has exploded so quickly, the forces driving this new market—from regulation to real-world attacks—and why Richard believes the standalone category of “AI security” may disappear entirely within the next year as AI becomes embedded in every security product.
We also dig into the rise of AI-driven SOC automation, what it means when machines begin triaging—and even responding to—threats autonomously, and the biggest misconceptions CISOs still have about securing AI systems.
If you want to understand where cybersecurity is heading in the age of intelligent machines, this is a conversation you won’t want to miss.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of Reimagining Cyber, host Rob Aragao sits down with EricMcAlpine, Founder and CEO of Momentum Cyber, to break down what’s really happening inside today’s cybersecurity market.
Drawing from insights in the latest Momentum Cyber Almanac, Eric shares a behind-the-numbers look at:
With record capital flows, accelerating innovation cycles, and trillion-dollar companies eyeing security, the stakes have never been higher.
If you want to understand where the cybersecurity market is headed in 2026 — and how to navigate the transformation — this episode delivers the strategic context you need.
Contact Eric McAlpine at Eric@momentumcyber.com.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Two weeks ago on Reimagining Cyber, we explored how agentic AI could become the next major security choke point. Since then, things have escalated.
Enterprises are restricting — even banning — AI agents. Security teams are scrambling to regain visibility. Vendors are rushing out “agent security” features. And early warning signs are already surfacing.
In this episode, Tyler Moffitt answers the critical question: Did agentic AI just move from innovation to crisis?
What changed in just a matter of weeks?
This discussion breaks down:
Tyler explains how agents don’t just generate responses — they take action. They hold API keys, access internal systems, modify code repositories, interact with cloud infrastructure, and execute workflows. When deployed without guardrails, logging, or least-privilege controls, they can quietly multiply an organization’s attack surface overnight.
The core issue isn’t that AI is malicious — it’s that AI has become an acceleration layer. And when autonomy meets overprivileged access, traditional security models break.
You’ll also hear practical, immediate steps security teams should be taking now — from credential rotation and agent inventories to sandboxing and behavioral monitoring.
This isn’t an anti-AI episode. It’s a maturity wake-up call.
Because the organizations that build guardrails now will move faster and safer. The ones that don’t may learn the hard way.
If you’re a CISO, security architect, developer experimenting with agents in production, or executive evaluating AI adoption — this is a conversation you can’t afford to miss.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
One year after the Digital Operational Resilience Act (DORA) came into force, what has actually changed?
In this follow-up episode of Reimagining Cyber, Rob Aragao welcomes back Dominic Brown of Graveslight Consulting to assess the reality of DORA in practice. Last time, the regulation was looming. Now, firms across the EU — and global financial institutions operating within it — have been living with it.
The conversation explores:
With enforcement expectations rising and supervisory scrutiny intensifying, year two marks the shift from preparation to proof. Boards, CISOs, and technology providers alike will need to demonstrate that operational resilience works in practice — not just on paper.
If year one was about Europe adapting to DORA, year two is about the world responding to it.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Agentic AI is moving fast — and it’s changing how risk shows up inside modern organizations.
Autonomous AI agents are no longer just answering questions. They’re wired into cloud consoles, internal tools, ticketing systems, and finance platforms, acting on our behalf with real permissions and real consequences. And in the rush to automate, many teams are quietly centralizing access in ways security models were never designed to handle.
In this episode, Ben sits down with Tyler Moffitt to break down what’s actually happening with agentic AI, why security teams are raising red flags, and how incentives around speed, automation, and scale are reshaping risk. They explore over-permissioned agents, token hygiene failures, broken separation of duties, and why AI agents are becoming the new security choke point.
The conversation also looks at how attackers are already using agentic AI to operate at machine speed — and what defenders can do now to design systems that assume compromise rather than perfection.
If you’re building, deploying, or securing AI agents, this is a conversation you can’t afford to miss.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
AI has officially moved from experimentation to execution—and regulation is racing to catch up.
In this episode of Reimagining Cyber, Tyler Moffitt is joined by Matt Aldridge to unpack what the rapidly evolving AI regulatory landscape means for security teams, businesses, and managed service providers heading into 2026.
From the EU AI Act and GDPR to California’s CPRA and emerging rules around automated decision-making, they explore how governments are trying to balance innovation with safety, privacy, and accountability. The conversation dives into the real-world security implications of agentic AI, autonomous decision-making, biased training data, and the growing risks of AI systems operating with minimal oversight.
Whether you’re an enterprise security leader, an SMB, or an MSP supporting multiple customers, this episode breaks down why AI regulation is no longer a future concern—and what practical steps organizations should be taking now to reduce risk, protect data, and responsibly govern AI adoption.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Microsoft Defender is often treated as “good enough” security—built in, always on, and quietly doing its job. But what happens when malware convinces Windows to turn it off without triggering alarms?
In this episode, cybersecurity expert Tyler Mofitt breaks down a real-world Windows malware campaign that disables Defender before anything else happens. No zero-days. No flashy exploits. Just a quiet abuse of built-in trust that causes Windows to step aside its own protection.
He walks through how shortcut files, PowerShell, and legitimate cloud services are used to blend into normal activity, why Defender doesn’t fail so much as follow the rules, and what defenders should be watching for when “installed” doesn’t always mean “active.”
A conversation about assumptions, visibility, and why the most dangerous attacks don’t look dangerous at all.
Link mentioned in the episode - threat intel hub with all the latest trends and stories going on with threat intelligence.
https://community.opentextcybersecurity.com/
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, Rob Aragao sits down with Theresa Lanowitz for a deep dive into the evolving meaning of cyber resilience and why it has become a true business imperative. Moving beyond traditional cybersecurity, the conversation explores how organizations must unite leadership, technology, and operations to withstand and recover from today’s most disruptive cyber events.
Theresa shares insights on the defining attacks of 2025, including the rise of AI-driven social engineering, software supply chain compromises, and credential-based intrusions from new-generation threat groups. The discussion also looks ahead to 2026, examining emerging risks around data misuse, non-human identities, insider threats, and the long-term impact of breached data.
Together, Rob and Theresa unpack why cyber resilience must be owned at the board and C-suite level, how software supply chain complexity has become a critical weakness, and what organizations can do to better govern, protect, and use their most sensitive data. This episode offers a strategic perspective for leaders looking to align cyber resilience with business outcomes in an increasingly connected and unpredictable digital world.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Low effort cybercrime continues to dominate the threat landscape as attackers rely on misconfigurations, exposed databases, stolen credentials, and extortion tactics—not advanced exploits—to cause real damage.
In this episode of Reimagining Cyber, cyber expert Tyler Moffitt breaks down recent stories including ShinyHunters extortion of Pornhub user activity
data and widespread MongoDB database exposure to explain why fundamentals like asset visibility, identity controls, and incident readiness matter more than ever in 2026.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Quantum computing is coming—but what does that actually mean for cybersecurity leaders today?
In this episode, Rob Aragao is joined by Morgan Adamski to break down key insights from PwC’s 2026 Global Digital Trust Insights Report and explore why quantum risk belongs on every CISO’s strategic roadmap. From geopolitical uncertainty to the shift from reactive to proactive cyber defense, the conversation cuts through the hype to explain what’s real, what’s next, and what leaders should be doing now.
Morgan demystifies quantum threats to encryption, explains the “harvest now, decrypt later” risk, and shares practical steps organizations can take today—starting with asset visibility, prioritization, and clear communication with the board.
If you’re thinking beyond today’s incidents and preparing for tomorrow’s threats, this episode is for you.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In part two of the 'Best of 2025' series of Reimagining Cyber, hosted by Rob Aragao, the focus is on the human elements influencing cybersecurity. The episode explores the challenges of burnout in the cybersecurity workforce as explained by Dr. Andrew Reeves, a cyber psychology expert. Betsy Cooper of the Aspen Policy Academy emphasizes the importance of integrating personal experiences and community voices in shaping cybersecurity policy. Lynn Dohm, Executive Director of Women in Cybersecurity (WiCyS), shares inspiring stories of individuals transitioning into cybersecurity careers. Finally, Craig Taylor of CyberHoot discusses a more effective approach to training that leverages positive reinforcement over punishment. The episode underlines that cybersecurity is not just about technology but also about understanding and supporting the people behind it.
00:00 Introduction to Reimagining Cyber
00:24 The Human Side of Cybersecurity: Burnout
04:43 Shaping Cybersecurity Policy with Personal Experience
07:00 Opening Doors: Women in Cybersecurity
10:27 Effective Cybersecurity Training: Positive Reinforcement
12:51 Conclusion: The Future of Cybersecurity
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
2025 was a defining year for cybersecurity. In Part One of Reimagining Cyber’s Review of 2025, we break down the biggest cybersecurity trends, threats, and technologies shaping the future. Topics include AI-driven security, automation, legacy systems in critical infrastructure, ransomware response, identity security, and deepfake attacks.
Hear expert insights from Richard Stein, Gary Kessler, Ed Gaudet, Tom Tovar, and former FBI executive Matt Gorham on maritime cybersecurity, healthcare cyber risk, federal incident response, and digital trust.
Part Two explores the human side of cybersecurity.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Christmas holiday cybercrime is back in focus—but this time, Reimagining Cyber goes deeper than scams and suspicious messages. In a previous episode, we explored the holiday threat landscape from the victim’s point of view: phishing emails, fake delivery notices, and gift-card fraud. In this episode, cybersecurity expert Tyler Moffitt shift perspectives to what most people never see—the malware and criminal infrastructure that make those scams possible in the first place.
The conversation dives into info stealers as the foundation of modern cybercrime, including a new malware-as-a-service offering dubbed “SantaStealer.” Tyler explains how stolen credentials and session tokens quietly enable account takeovers, fraud, and abuse at scale—often weeks before any scam ever reaches a user’s inbox. You’ll also learn why these threats spike during the holidays, how attackers bypass MFA without phishing, and what defenders should be prioritizing beyond traditional email security.
If the last episode covered what holiday scams look like, this one explains how they’re powered—and why the real compromise often happens long before anyone realizes they’ve been targeted.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
AI is evolving faster than most organizations can keep up with — and the truth is, very few companies are prepared for what’s coming in 2026. In this episode of Reimagining Cyber, Rob Aragao speaks with Ken Johnston, VP of Data, Analytics and AI at Envorso, about the uncomfortable reality: autonomous AI systems are accelerating, regulations are tightening, and most businesses have no idea how much risk they’re carrying.
Ken explains why companies have fallen behind, how “AI governance debt” has quietly piled up, and why leaders must take action now before the EU AI Act and Colorado’s 2026 regulation bring real financial consequences. From AI bias and data provenance to agentic AI guardrails, observability, audits, and model versioning — Ken lays out the essential steps organizations must take to catch up before it’s too late.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Operation Endgame didn’t just disrupt a single ransomware group — it shook the entire cybercrime economy. In this episode, we break down how the world’s largest coordinated cyber takedown dismantled the loaders, botnets, and access brokers that ransomware groups relied on… and what criminals are building in their place.
Cybersecurity expert Tyler Moffitt unpacks:
The threat landscape has changed dramatically — here’s what you need to know to stay ahead.
As featured on Million Podcasts'
Best 100 Cybersecurity Podcasts
Top 50 Chief Information Security Officer CISO Podcasts
Top 70 Security Hacking Podcasts
This list is the most comprehensive ranking of Cyber Security Podcasts online and we are honoured to feature amongst the best!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, Rob Aragao welcomes back cybersecurity expert and author Michael Echols to unpack the urgent realities behind his new book, AI Chaos.
Michael explains how AI is rapidly entering operational technology (OT) systems—the infrastructure that runs our power grids, water systems, transportation, satellites, and more. But with this transformation comes a critical problem: leaders don’t truly understand where AI is operating, how it behaves, or how to control it.
Together, Rob and Michael explore:
If your organization relies on OT, automation, or AI-driven systems, this conversation is a must-listen wake-up call.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Tis the season… for cybercrime. In this episode of Reimagining Cyber, senior security analyst Tyler Moffitt breaks down how cybercriminals exploit the Christmas and holiday season to launch phishing attacks, ransomware, smishing scams, and gift card fraud. From AI-powered fake delivery emails to cloned charity pages, learn how attackers are getting more sophisticated than ever—and what you can do to protect yourself, your business, and your customers during the busiest shopping months of the year.
Key Takeaways:
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Your devices may be giving away more than you think. In this episode of Reimagining Cyber, security expert Tyler Moffitt explores the hidden world of side-channel attacks — where everyday sensors reveal information you never intended to share.
From Android apps that can infer your two-factor codes without screenshots, to gaming mice that “hear” speech through micro-vibrations, to Wi-Fi routers that detect motion inside your home, Tyler breaks down the cutting-edge research that blurs the line between science fiction and reality.
He unpacks how these attacks work, what’s real versus proof-of-concept, and—most importantly—how to stay secure. Expect practical takeaways about permissions, firmware updates, passkeys, and a healthy dose of cybersecurity paranoia.
Key Topics:
Bottom Line:
If it hums, blinks, or vibrates—it could be talking.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Former FBI operative and cybersecurity strategist Eric O’Neill returns to Reimagining Cyber to discuss his new book Spies, Lies, and Cybercrime. Eric introduces his D.I.C.E.D. model—a spy-inspired framework for understanding how deception and espionage fuel today’s cyberattacks. He and host Rob Aragao dive into how AI is transforming impersonation scams, what the coming quantum era means for encryption and digital trust, and how CISOs can prepare for the evolving threat landscape.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this chilling Halloween special of Reimagining Cyber, cybersecurity expert Tyler Moffitt counts down the nastiest pieces of malware that defined 2025 — and the identity-driven attacks reshaping the threat landscape.
From AI-powered social engineering to ransomware “lawyer buttons”, this year’s cybercriminals blurred the line between hacking networks and hacking people. Tyler breaks down how attacks moved inside the perimeter — exploiting trust, voice, and identity — and what that means for businesses of every size.
Plus, Tyler shares a realistic survival playbook for modern threats — from identity hardening and privilege reduction to tabletop drills against voice scams and “click-fix” lures.
“The perimeter is now your people,” Tyler warns — and AI is supercharging the threat.
This episode drops ahead of Tyler’s live webinar on October 30, where he’ll go even deeper into the 2025 malware report.
Link to the webinar:
https://www.brighttalk.com/webcast/8241/646661?q=smb-cyber-security
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode, Rob Aragao sits down with futurist Heather Vescent to explore how strategic foresight can be applied to cybersecurity. Heather explains what it means to be a futurist—blending creativity with analytical research—and shares her journey from Silicon Valley to becoming a leader in foresight methodologies. She discusses her early work on the future of money, digital identity, and how that naturally led her into cybersecurity.
Together, they dive into topics such as spiral dynamics, scenario planning, and bias awareness, and how these tools help anticipate future threats and opportunities. Heather also breaks down the concept of agentic AI (digital employees), examining its potential as both an expanded attack surface and a defense enhancer. Finally, she previews her upcoming book, The Cybersecurity Futures Playbook, which translates foresight tools into practical frameworks for security professionals.
Listeners will walk away with new ways to anticipate threats, improve response readiness, and think differently about the future of cybersecurity.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
LockBit is back—and stronger than ever. After multiple takedowns and sanctions, the ransomware-as-a-service giant has resurfaced with LockBit 5.0, a version designed to hit harder, spread faster, and target virtualization at scale.
In this episode of Reimagining Cyber, Tyler Moffitt unpacks what’s changed, why LockBit 5.0 matters, and what organizations should be doing now to reduce risk. From hypervisor attacks and cross-platform payloads to cartel-style alliances among cybercriminal crews, we explore how ransomware continues to evolve—and what defenders can learn from it.
Whether you’re an enterprise IT leader, MSP, or simply tracking the ransomware economy, this episode offers practical actions and strategic insights you can put to work this week.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Why do cyber attackers always seem one step ahead — and how can defenders take back control?
In this episode of Reimagining Cyber, host Tyler Moffitt (Senior Analyst, OpenText) sits down with longtime colleagues Grayson Milbourne (Security Intelligence Director) and Troy Gill (Senior Manager, Threat Research) to explore how the cybersecurity battlefield is evolving — and what it takes to shift the balance toward defenders.
They break down:
You’ll also hear real-world insights from the threat-research trenches, plus practical advice for CISOs and IT leaders on creating a security-first culture, improving visibility, and staying ahead of fast-moving AI-powered threats.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, cybersecurity expert Tyler Moffitt unpacks one of the most shocking cybercrime stories in recent years—the rise and supposed shutdown of Scattered Spider. From social engineering mastery and high-profile breaches to teenage ringleaders and sudden “retirements,” this group has rewritten the playbook on digital extortion.
Tyler walks us through:
The episode closes with practical takeaways for CISOs: protecting identity, hardening help desks, modernizing MFA, and preparing for the next wave of copycats. Whether the group is gone for good or merely regrouping, their tactics will continue to echo across the threat landscape.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Women make up only a fraction of the cybersecurity workforce—and many hit a career ceiling just 6 to 10 years in. At the same time, millions of cyber roles remain unfilled, and the talent gap keeps growing. Lynn Dohm, Executive Director of Women in CyberSecurity (WiCyS), is working to change that.
In this episode, Lynn shares how WiCyS has grown from a single conference into a global nonprofit supporting 11,000+ members across 100 countries. She highlights groundbreaking research on the barriers women face in cyber, why skills-based advancement matters, and powerful success stories of women who’ve launched or transformed their careers through WiCyS programs.
If you’re passionate about advancing women in cyber, closing the talent gap, and building a stronger, more inclusive workforce, this conversation is one you won’t want to miss.
WiCyS Cyber Talent Study:
https://www.wicys.org/initiatives/the-wicys-cyber-talent-study/
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
This week on Reimagining Cyber, we unpack one of the biggest supply chain attacks of the year: the NPM hack. Attackers compromised widely used packages like Chalk and Debug—billions of weekly downloads—slipping in code that silently hijacked crypto transactions. Tyler Moffitt joins us to explain how it happened, who’s most at risk, and the practical steps every developer and security leader should take right now.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Headlines claimed that 2.5 billion Gmail accounts were hacked—but what really happened? In this episode of Reimagining Cyber, Ben and threat intelligence expert Tyler Moffitt break down the facts behind the so called Gmail hack
You’ll hear how cybercrime group ShinyHunters exploited a Salesforce system linked to Google—not Gmail itself—and why misleading headlines fueled unnecessary panic. We explore:
Tune in to understand what really happened, why it matters, and what you can do to stay secure in a world where perception spreads faster than facts.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Cyber resilience goes beyond checkboxes. In this episode, cybersecurity veteran Jerod Brennen (virtual CISO, executive advisor, and indie filmmaker) joins Rob Aragao to explore how storytelling, culture, and business alignment turn security into a true business enabler. Real-world lessons and practical steps help you shift from traditional cybersecurity to resilience.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
A ransomware attack shut down St. Paul, Minnesota—forcing a state of emergency and even the calling in of the National Guard. Cybersecurity expert Tyler Moffitt unpacks how it happened, who was behind it, and what cities and individuals can learn to avoid becoming the next target.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Rob Aragao sits down with Betsy Cooper, Director of the Aspen Policy Academy. Betsy shares how the Academy is helping to train cybersecurity professionals to effectively engage with and influence public policy. They discuss the importance of civic engagement, the need for technical voices in policymaking, and how the Academy fills a critical gap by offering accessible, actionable training for both experts and everyday citizens. Real-world success stories—including efforts to improve scam reporting tools for older adults and developing cybersecurity baselines for medical devices—highlight the Academy’s impact. Betsy also introduces a new initiative focused on cyber civic engagement to empower communities across the country.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
At Black Hat USA, cybersecurity experts revealed an eye-opening case of billion-dollar scams hiding in plain sight. In this episode, Ben is joined by cyber threat expert Tyler Moffitt to unpack the world of malicious ad tech, where criminal networks run like Fortune 500 companies. From the VexTrio traffic distribution system to its flashy partner network Los Pollos, discover how cybercriminals hijack legitimate ad frameworks to push fake apps, push notification scams, and credit card traps—while flaunting their wealth on Instagram. Learn why this form of organized cybercrime is so hard to shut down, and why your next redirect might not be as harmless as it looks.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Rob Aragao sits down with cybersecurity executive and domain security expert Ihab Shraim to spotlight one of the most overlooked yet critical areas of cyber risk—fraudulent domain registrations and DNS hijacking. As the digital attack surface expands, bad actors are exploiting unmonitored domain portfolios and exposed DNS infrastructure to launch phishing campaigns, malware distribution, and business email compromise—all while flying under the radar of traditional security tools.
Ihab explains why domain risk is a foundational weakness in many organizations' security postures and argues that without domain security, cybersecurity is incomplete. From shadow IT and orphaned domains to poor DNS hygiene and lack of domain portfolio governance, Ihab outlines the blind spots that make companies vulnerable—and provides actionable strategies CISOs and security leaders must adopt to regain control.
Whether you're managing brand reputation, protecting customer trust, or looking to tighten your security fundamentals, this episode delivers an eye-opening exploration into why domain risk needs to be a board-level conversation.
Key Takeaways:
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
“It's got a [vulnerability] score of a 9.8, and this is on a scale of 10 and I've really never seen 10. So 9.8 is basically just as bad as it gets.”
This episode is inspired by an ongoing global cybersecurity incident. In mid‑July attackers began actively exploiting Microsoft SharePoint vulnerabilities in what’s now known as the “ToolShell” exploit chain.
This flaw is classified as a remote code execution vulnerability with an extremely high CVSS (Common Vulnerability Scoring System ) score of 9.8, making it highly dangerous.
Featuring Tyler Moffitt, Senior Security Analyst at OpenText Cybersecurity, the episode explores the severity of this 9.8 CVSS score vulnerability and its impact on organizations that haven't applied the necessary patches. Learn about the attack kill chain, what makes this flaw so dangerous, and practical steps to safeguard your systems. Patch immediately, audit your access logs, and stay ahead of the threat.
CSA Advisory:
https://www.csa.gov.sg/alerts-and-advisories/advisories/ad-2025-016
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Rob Aragao talks with Richard Stiennon, author of the legendary 'Security Yearbook'. Stiennonn discusses his career as an industry analyst and his recent focus on mergers and acquisitions within cybersecurity. The conversation dives into the meticulous process behind the Security Yearbook, AI's growing role in cybersecurity, and the state of M&A activities in 2025. Stiennon also offers predictions for the cybersecurity landscape in 2026 and beyond, emphasizing the value of automation and the impact of AI on both cyber defense and attacks. Don't miss this insightful discussion on the future of cybersecurity.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Welcome back to Re-Imagining Cyber! In this episode, Tyler Moffitt, (Senior Security Analyst at OpenText) explores the emerging threat of generative AI in the hands of cyber criminals. Discover how AI models like ChatGPT, WormGPT, and FraudGPT have drastically lowered the skill floor for launching sophisticated attacks. Tyler breaks down the four major use cases: hyper-personalized phishing, real-time social engineering, AI-generated malware, and deep fakes. Learn the impact of this technology on real-world cyber crime and how AI-driven defense strategies are evolving to combat these threats. Tune in for essential insights and stay skeptical!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, Rob Aragao (Chief Security Strategist, OpenText) speaks with Ed Gaudet, CEO and founder of Censinet, about the high-stakes intersection of cybersecurity and healthcare. With hospitals increasingly reliant on connected medical devices and legacy systems, the risks extend beyond data breaches—they directly impact patient safety.
Ed shares insights into the unique cybersecurity challenges healthcare organizations face, including outdated systems, siloed risk management, and the complexity of biomed environments. He emphasizes how aligning cybersecurity and clinical engineering under a unified risk framework can improve compliance and operational efficiency. The conversation also explores the evolving role of medical device manufacturers, the importance of unique identifiers, and how actionable risk intelligence is key to improving outcomes.
A highlight of the discussion is the eye-opening research Ed and Censinet conducted with the Ponemon Institute, revealing a 20% increase in mortality rates tied to ransomware attacks—transforming cybersecurity from a technical concern into a patient safety crisis.
Key Takeaways:
This episode is a must-listen for healthcare leaders, cybersecurity professionals, and anyone interested in the future of safe, resilient healthcare systems.
Reports referenced in this episode:
Censinet/Ponemon Institute
CISA - Provide Medical Care is in Critical Condition: Analysis and Stakeholder Decision Support to Minimize Further Harm
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Welcome to Reimagining Cyber! In this episode, Tyler Moffitt (Senior Security Strategist, OpenText) , dissects one of the hottest—and most misunderstood—topics in tech: the AI bubble in cybersecurity. Is AI revolutionizing threat detection and response, or are we falling for another overhyped tech trend? Tyler draws parallels to the blockchain frenzy of 2017, warning of “AI-washing,” overblown marketing claims, and venture capital-fueled hype that may be outpacing real-world results.
The conversation dives into where AI is genuinely making an impact—like anomaly detection, threat intel summarization, and SOC automation—and where it's still falling short, from false positives and model drift to the black-box problem. With signs of a bubble already forming, including vendor consolidation and flashy tools that don’t deliver, Tyler urges security leaders to focus on co-pilot approaches, not full automation. Bottom line? AI can be a force multiplier, but only when paired with human expertise and solid cyber hygiene.
Whether you're skeptical of the buzz or curious about where AI in cybersecurity is actually working, this episode brings a grounded, no-fluff take on the state of the industry.
Key Topics:
Tune in to cut through the noise and get real about AI in cyber.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Re-Imagining Cyber, Rob Aragao (Chief Security Strategist, OpenText) revisits the impactful role of AI and AI governance in cybersecurity. Highlighting findings from a recent survey indicating that only 25% of CISOs believe their organizations have strong AI risk frameworks, Rob discusses the significance of AI in enhancing operational efficiency, security measures, and compliance efforts. Key themes include the strategic positioning of security practices, collaboration between security teams and product development, and the automation of threat detection and response. Rob also underscores the importance of trust and transparency in AI applications, along with the competitive advantages of efficient AI deployment. The episode aims to shed light on the early yet promising developments in AI governance and its potential business outcomes.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
What if everything we’ve been doing in cybersecurity awareness training is not just outdated — but harmful?
In this episode of Reimagining Cyber, Rob Aragao, Chief Security Strategist at OpenText, talks with Craig Taylor, co-founder and CISO at CyberHoot, who makes a bold claim: punishment-based training is not only ineffective — it’s counterproductive. Drawing from his background in psychology and years of cybersecurity leadership, Craig explains why we need to ditch outdated tactics and embrace positive reinforcement to reduce human risk.
From the failure of fake phishing tests to real-world results from forward-thinking organizations, Craig reveals a smarter, more human-centered way to train. If you're tired of scare tactics and want a strategy that actually builds cyber resilience, this episode is your wake-up call.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, we break down the key findings from the 2025 Cybersecurity Staff Compensation Benchmark Report from the Institute for Applied Network Security (IANS).
Host Ben sits down with Rob Aragao (Chief Security Strategist, OpenText) to explore why over 50% of cybersecurity professionals just below the CISO level are considering a job change—and it’s not just about burnout or pay.
From leadership bottlenecks and role creep to uncertainty around organizational change, we dive into what’s really driving attrition in cyber teams and what CISOs can do to keep their top talent engaged and growing.
🎧 Topics covered:
If you lead a cyber team—or plan to—this is a conversation you don’t want to miss.
🔔 Subscribe/Follow for more insights into the changing world of cybersecurity leadership.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
" I think it's a blind spot for the entirety of code driven or software based development."
Join host Tyler Moffitt in this episode of 'Reimagining Cyber' as he sits down with Dimitry Shvartsman, co-founder of PrimeSec, to explore the crucial topic of design stage security and the transformative role of AI in cybersecurity. Dimitry shares his journey from leading security at PayPal to co-founding PrimeSec and explains the importance of addressing security vulnerabilities early in the development process. They discuss the challenges and benefits of embedding security in the design stage, the universal problem of late-stage fixes, and the critical role of automation. Don't miss out on this insightful discussion to understand how to enhance your security strategy from the ground up
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In today's episode, OpenText's Tyler Moffitt (Sr. Security Analyst) delves into 'Operation Endgame,' one of the most extensive coordinated cybercrime takedowns in history. Learn about the multinational law enforcement efforts that targeted critical malware infrastructure, dismantling key botnets and loaders vital to ransomware attacks. Tyler provides an in-depth analysis of the operation's impact on the cybercriminal ecosystem, real-world implications, and predictions for the future of cybersecurity. Don't miss this eye-opening discussion!
🔗Sources and Additional Reading
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, Tyler Moffitt, Senior Security Analyst at OpenText Cybersecurity, delves inro the complex issue of insider threats. He concentrates on the two main types of insider threats: malicious insiders who knowingly abuse their access, and unintentional insiders who fall prey to phishing and other social engineering attacks. The conversation is highlighted by recent high-profile cases such as the Coinbase breach, where a third-party contractor was bribed, and the Scattered Spider group's attack on UK retailers like Marks and Spencer and Co-op. The episode explores the real-world financial impacts of these breaches and offers detailed strategies for defending against insider threats, emphasizing the importance of layered security, strict access controls, and thorough training. Listen to learn more about the evolving landscape of insider threats and how to protect your organization.
Links mentioned in this episode:
https://community.opentext.com/cybersec
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, Rob Aragao welcomes Matt Gorham, former Assistant Director of the FBI’s Cyber Division and current leader of PwC’s Cyber and Risk Innovation Institute. Gorham shares critical insights from his 25-year FBI career and discusses the evolution of ransomware—especially the rise of ransomware-as-a-service models and the business-like operations of Eastern European cybercriminal syndicates. He emphasizes the importance of cyber hygiene, incident response planning, and executive-level tabletop exercises. The discussion also covers the often-misunderstood relationship between private companies and law enforcement, as well as the implications of AI, onshoring manufacturing, and the shifting geopolitical cybersecurity landscape. A must-listen for CISOs, board members, and security leaders looking to turn preparation into resilience.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode Senior Security Analyst Tyler Moffitt unpacks the 2025 OpenText Cybersecurity Threat Report. He dives into alarming shifts like a 28% spike in malware infections, the relentless resilience of ransomware group LockBit, and the surge of AI-enhanced phishing campaigns. Tyler breaks down why old-school malware tactics still dominate, how affiliate-driven ransomware-as-a-service is thriving, and why European businesses are increasingly in the crosshairs. Plus, he explores what’s actually working—simple, disciplined defenses—and why “eating your cybersecurity vegetables” may be the most powerful strategy of all. Don't miss Tyler's predictions on AI’s evolving role in both attack and defense for the year ahead.
Find the report here:
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this eye-opening episode of Reimagining Cyber, host Tyler Moffitt is joined by Tom Tovar, co-creator of cybersecurity company Appdome, to unpack one of the fastest-growing threats in mobile security—deepfakes and biometric bypass attacks.
Tom explains why facial recognition, once considered a reliable security measure, was never designed to withstand today’s AI-powered spoofing tactics. From simple call interception techniques to sophisticated real-time face-swapping and buffer overrides, Tom walks us through the anatomy of modern biometric attacks. He also reveals why most mobile apps—and even top-tier facial recognition systems—are currently defenseless against these threats.
We dive deep into the vulnerabilities hiding in plain sight within mobile frameworks, and why defending facial recognition starts with the app itself, not the authentication system. Plus, Tom gives us a glimpse into how AI is being used to both attack and defend, and what the future of mobile app security might look like.
If you think your face is your password, think again.
Topics Covered:
Whether you're a security professional or just fascinated by the evolving threat landscape, this is a must-listen episode.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, Tyler Moffitt, Senior Security Analyst at OpenText Cybersecurity, explores the evolution of fast flux — a once obscure spamming tactic that has now become a serious national security concern. Learn how this evasive DNS technique enables ransomware groups and nation-state actors to stay resilient, hide their infrastructure, and extend the life of their attacks.
Tyler breaks down how fast flux works, why it’s seeing renewed attention from the NSA and CISA, and what security teams can do to detect and defend against it. From DNS filtering and anomaly detection to the role of ransomware affiliates and cybercriminal business models, this episode delivers deep insights into one of today’s most pressing cybersecurity threats.
Key topics:
Don’t miss this eye-opening discussion. Be sure to check out Tyler’s blog for a deeper dive.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, we set sail into the world of maritime cybersecurity with one of the foremost experts in the field, Dr. Gary Kessler. From GPS spoofing to autonomous vessels, Gary breaks down the evolving threats facing modern ships and ports as they become increasingly digitized and connected. With over 50 years of experience in cybersecurity and a lifelong connection to the water, Gary shares how his career merged passion and profession, leading to groundbreaking research in AIS spoofing and maritime threat mitigation.
We explore the real-world cyber risks impacting global logistics, including the infamous 2017 NotPetya attack on Maersk, the rise of ghost and dark fleets, and how pirates are using hacked logistics systems to target high-value cargo. Gary also explains why the term “cybersecurity” may miss the mark—and why protecting the information itself is what really matters.
Plus, hear about the upcoming Maritime Hacking Village at DEFCON and how you can get involved. If you're curious about the cyber threats lurking beyond the horizon, this episode is your compass.
Links:
Maritime Cybersecurity: A Guide for Leaders and ManagersMaritime Hacking Village
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Tyler Moffitt welcomes Tim Armandpour from PagerDuty to explore how organizations can assess and manage their cyber risk in an era of rapid technological change. They discuss the importance of continuous risk evaluation, building a culture of resilience, and the impact of AI on security practices.
Tim shares insights on zero trust architecture, lessons learned from major incidents like the CrowdStrike outage, and how businesses can adapt their security strategies to stay ahead. Whether you're a security leader or just interested in the evolving cybersecurity landscape, this episode offers valuable takeaways on managing risk, ensuring operational resilience, and preparing for the future of AI-driven security.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, threat research analyst Tyler Moffitt explores the evolution of cryptocurrency—from a libertarian dream to a key enabler of cybercrime. Tyler shares his personal journey into crypto mining and breaks down pivotal moments in Bitcoin’s history, including the rise of Silk Road, the emergence of ransomware, and the infamous WannaCry attack.
The discussion also dives into why criminals prefer privacy coins like Monero, how law enforcement is fighting back using blockchain analytics, and whether crypto can ever shake its association with illicit activities. Packed with expert insights and real-world examples, this episode is a must-listen for anyone curious about the intersection of cryptocurrency and cybersecurity.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, we dive into Europol’s latest report, The Changing DNA of Serious and Organised Crime, which highlights how AI is accelerating cybercrime and global information warfare. Rob Aragao, breaks down the report’s key findings, including AI-driven fraud, deepfake scams, and automated cybercrime operations.
We also explore the broader implications of AI in shaping misinformation campaigns, with major players like China, Russia, and Iran investing billions in disinformation efforts. As law enforcement agencies struggle to keep up, we discuss the challenges of combating AI-powered threats and what this means for cybersecurity on a global scale.
Rob also touches on how The U.S. is facing challenges in defending against AI-driven disinformation, as key institutions are shut down. This reduction in information validation and support makes it harder to track and counter adversarial efforts.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Significant changes are underway at the Cybersecurity and Infrastructure Security Agency (CISA), and the cybersecurity community is paying close attention. In this episode, we break down the recent funding cuts, layoffs, and restructuring efforts that could reshape the agency’s mission—and potentially impact national cybersecurity.
Join Rob Aragao as he analyzes:
🔹 The key drivers behind CISA’s transformation
🔹 How these changes affect state and local cybersecurity efforts
🔹 The debate between efficiency vs. security risks
🔹 What cybersecurity professionals should watch for next
With critical infrastructure and election security on the line, these shifts could have far-reaching consequences.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode, we’re diving into the world of LockBit, one of the most notorious ransomware groups out there, and how it’s keeping law enforcement on its toes. We’ll break down their latest moves, the battle between hackers and agencies like the FBI, and what it means for cybersecurity moving forward.
Here’s what we cover:
The Kash Patel Incident: Recently, LockBit took a jab at Kash Patel, the FBI Director, in a post on their leak site. The group congratulated him on his appointment and dropped a hint that they had info that could embarrass the FBI. It’s all part of LockBit’s strategy to keep itself in the headlines and make sure it stays relevant, even as law enforcement gets serious about shutting them down.
LockBit’s Operations: LockBit operates on a ransomware-as-a-service model. What does that mean? Well, they provide the tools and infrastructure for affiliates to carry out attacks. And those affiliates don’t hold back—LockBit has gone after hospitals, government agencies, and businesses, demanding huge ransoms in the process.
Takedowns and Law Enforcement’s Response: The FBI has had some wins, like taking down LockBit’s leak site during Operation Kronos. But LockBit? It’s not exactly slowing down. They’ve bounced back with new infrastructure and continued to wreak havoc. The group seems to enjoy the back-and-forth with law enforcement, using it to attract more affiliates and keep their operation growing.
LockBit’s Evolution: The group just dropped version 4.0 of their ransomware, and they’re still advertising on their site, offering affiliates big payouts and even luxury cars for successful attacks. Now, they’ve even started to position themselves as a kind of twisted “pen-testing” service—after they ransom someone, they’ll help them find security flaws in their systems.
Law Enforcement Struggles: Despite efforts from the FBI and other agencies, ransomware groups like LockBit keep adapting. The Russia-Ukraine conflict has only made things worse, and LockBit has shown no signs of slowing down. While law enforcement is certainly stepping up, the fact remains: no major figures have been caught yet.
Practical Tips for Organizations: We’ve got some actionable advice for businesses to stay ahead of these ransomware gangs. First off, enable two-factor authentication (2FA) wherever you can. Also, don’t ignore your software updates—many attacks exploit outdated systems. And if you can, hire a professional red team to conduct penetration testing and find the holes before the hackers do..
LockBit may not be invincible, but they’re still a huge threat. The group’s persistence and ability to evolve mean that ransomware operations are going to be around for a while. The battle between cybercriminals and law enforcement is far from over, and it’s only going to escalate as these groups get more sophisticated and resilient.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber we tackle two seismic shifts in digital security: the fight over encryption and the rise in quantum computing.
First up, the UK's aggressive push against encryption. With legislation like the Investigatory Powers Act and the Online Safety Bill, the UK government is pressuring tech giants to create backdoors for law enforcement. But what happens when those backdoors fall into the wrong hands? Cybersecurity expert Tyler Moffitt doesn’t mince words: “The moment you create a backdoor for the government, you open it up to everybody—cybercriminals, rogue states, you name it.” Apple initially took a hard stance, threatening to pull iMessage and FaceTime from the UK. But in a move that sent ripples through the industry, they recently scaled back their Advanced Data Protection feature for UK users. Is the result a chilling precedent that other governments may soon follow?
If that weren’t enough, encryption’s future faces another existential threat—quantum computing. Even the strongest cryptographic methods in use today could become obsolete once quantum processors reach critical mass. To explore this, we revisit Episode 43: Inside the Fight to Protect Data from Quantum Computers, featuring veteran cryptographic engineer Terence Spies. He warns that the fundamental rules of encryption could soon change forever. “Unlike other areas of software, cryptography is about proving what can’t happen,” Spies explains. “Quantum computing changes that equation entirely.”
With quantum breakthroughs on the horizon, governments and enterprises must scramble to adopt post-quantum cryptography—before it’s too late. Transitioning away from RSA and elliptic-curve encryption isn’t just a technical challenge; it’s a bureaucratic and logistical nightmare that could take decades. And yet, with quantum attacks potentially capable of breaking today’s encryption in mere hours, the race is on to secure our digital future.
Listen to the full episode of Reimagining Cyber and stay ahead of the encryption debate. The stakes have never been higher.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Rob Aragao explores the concept of shadow AI and its implications in cybersecurity. Inspired by the recent AI Action Summit in Paris, Rob delves into core areas such as threat detection, governance, and data privacy. He addresses the growing concerns around unauthorized AI implementations within organizations and emphasizes the importance of collaborative efforts and governance frameworks. Practical solutions like API secure gateways, data sandboxes, and centers of excellence for AI are discussed to mitigate risks and enhance cybersecurity practices.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, new co-host Tyler Moffitt talks about the intersection of blockchain technology and cybersecurity. He discusses the basics of blockchain, its differences from traditional databases, real-world applications, the current rate of adoption, and the challenges it faces. Tyler also shares his personal journey into the world of blockchain and his passion for the technology. The episode concludes with a discussion on the future of blockchain in cybersecurity and a fascinating tale about lost Bitcoin worth millions.
Links mentions in the episode:
https://en.wikipedia.org/wiki/Bitcoin_buried_in_Newport_landfill
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Rob Aragao explores the role of the Professional Association of CISOs (PAC) with Demetrius Comes, a CISO executive advisor at EVOTEK and a leader within PAC. Comes, who has held cybersecurity leadership roles at companies like GoDaddy and Warner Brothers Games, discusses PAC’s mission to support CISOs through professional development, peer collaboration, and industry education.
The conversation covers PAC’s initiatives, including local chapters, certification programs, and resources designed to help CISOs navigate leadership responsibilities, liability concerns, and emerging cybersecurity threats. Combs also provides insight into broader industry trends, such as the evolving role of CISOs, the importance of cyber hygiene, and the growing impact of AI in cybersecurity.
This episode offers valuable information for cybersecurity professionals looking to understand the benefits of PAC and the challenges facing modern security leaders.
Links relevant to this episode:
Professional Association of CISOs - https://theciso.org/
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode, we dive into the world of passkeys and how they’re revolutionizing online security. Say goodbye to password fatigue and phishing scams—passkeys promise a more secure and seamless authentication experience. We discuss what passkeys are, how they work, and why major tech companies are adopting them.
Topics Covered:
Key Takeaways:
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of 'Reimagining Cyber,' Rob Aragao explores major trends and focus areas for cybersecurity in 2025. The discussion includes regulatory impacts, particularly around the Digital Operational Resiliency Act (DORA) and the EU AI Act, the complexities of data privacy with eight new laws in the U.S., and the growing emphasis on compliance automation. Rob also delves into the evolution of identity and access management, the convergence of data and identity, and the critical importance of supply chain security. The episode wraps up with insights into the recent DeepSeek incident and its implications for national security and data privacy.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode, Reimagining Cyber's Rob Aragao dives into the World Economic Forum's recently released Cybersecurity Outlook for 2025. Key areas highlighted include the impact of geopolitical tensions on cyber espionage, the persistent threat of ransomware, the dual role of AI in bolstering cybersecurity and amplifying cyber attacks, and the ongoing cybersecurity skills shortage. The discussion also covers the importance of resilience in cybersecurity strategy and the critical need for improved collaboration across industries and with the public sector. The episode is packed with practical insights for C-suite leaders, particularly in how these findings can inform and strengthen organizational cybersecurity programs.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Join Reimagining Cyber's host Rob Aragao as he talks about the evolving role of the CISO in aligning cybersecurity with business objectives. Rob emphasizes the importance of integrating security early in development processes to foster business agility and protect customer trust. He highlights key strategies for CISOs to effectively communicate with executive leadership and align security initiatives with financial and operational goals. Tune in for expert advice on driving growth and efficiency through a robust cybersecurity framework.
00:00 Introduction and New Year Greetings
00:59 Reflecting on Past Episodes and Setting the Agenda
02:09 The Evolving Role of the CISO
03:03 Integrating Cybersecurity with Business Operations
03:37 Enhancing Business Agility and Reducing Friction
05:55 Protecting Customer Trust and Data Privacy
06:46 Mitigating Financial Losses from Security Incidents
07:36 Operational Efficiency and Early Security Integration
07:52 Communicating Cybersecurity to Stakeholders
13:08 Financial Literacy and Budget Justification
14:34 Challenges in Cybersecurity Communication
17:22 Concluding Remarks and Farewell
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Rob Aragao welcomes Dr. Andrew Reeves, a cyber psychology expert from the University of New South Wales Institute for Cybersecurity. They discuss Andrew's groundbreaking national study on mental well-being in the cybersecurity sector and the high burnout rates among cybersecurity professionals. Dr. Reeves compares these rates to those in other industries, notably frontline healthcare workers, and highlights the lack of appreciation and support for cyber professionals. He shares an example of a colleague who experienced a severe panic attack due to job stress, leading to early retirement. The episode explores systemic issues and potential resources for mental health support within the cybersecurity industry.
00:00 Welcome and Introduction
00:34 Exploring Cyber Psychology
00:44 Comparing Cybersecurity to Other Industries
02:47 Burnout in Cybersecurity
05:27 Personal Stories and Experiences
11:18 Resources and Final Thoughts
Links/resources mentioned this episode:
University of New South Wales Institute for Cybersecurity.
https://www.unsw.edu.au/research/ifcyber
Cybermindz
https://cybermindz.org/
University of Adelaide Defence and Security Institute
https://www.adelaide.edu.au/defence-security/
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Join Rob Aragao in this unique edition of Reimagining Cyber, as he takes you on a retrospective journey through the most impactful podcast moments of 2024. This episode features highlights from discussions on major topics, including the EU's Digital Operational Resilience Act with Dominic Brown, election defenses with Dr. Ben Adida, MasterCard's cyber defense efforts with John Brickey, global cybercrime insights with Craig Jones, NASA's cybersecurity approaches with Tiffany Snyder, and the advancements and challenges of AI in cybersecurity with Ashley Jess. Don't miss this comprehensive review and stay tuned for more exciting content in 2025!
00:00 Welcome to Reimagining Cyber
00:46 Inside DORA: EU's Cyber Resilience Path
04:12 Securing the Vote: Election Defenses
07:27 MasterCard's Cyber Defense Collaboration
09:52 Global Cybercrime Insights with Interpol
14:02 NASA's Cybersecurity in Orbit
17:38 AI and Deepfakes: New Cybersecurity Challenges
20:38 Conclusion and Future Episodes
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
Join Reimagining Cyber for a festive special filled with cybersecurity Christmas wishes from industry experts. Hear from Mike Echols on the importance of human error management, Ashley Jess on combating sophisticated scams with AI, Jim Routh's call for passwordless authentication and improved identity access management, Brett Thorson's plea for simplified cybersecurity products, Arun DeSouza's emphasis on IoT security, and Tammy Klotz's reflection on vigilance and proactive protection. Rob Aragao wraps up with thoughts on the convergence of identity and data, as well as the role of AI in enhancing threat detection and responses. Tune in for thoughtful reflections, expert insights, and a look back at the major cybersecurity themes of 2024.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, Rob Aragao revisits the critical topic of cyber threats to critical infrastructure. Rob shares recent alarming developments involving Iranian state-sponsored hacking group 'CyberAv3ngers' and their targeted attacks on U.S. and Israeli IoT and OT devices. The episode underscores the importance of security hygiene and the latest guidance from U.S. governmental agencies.
Rob also takes time to reflect on significant cybersecurity events and themes from 2024. Stay tuned for next week’s festive episode where past guests share their cybersecurity wish lists for Santa!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode, Rob speaks to Dr. Andrew Reeves, expert in cyberpsychology and current Deputy Director of UNSW Institute for Cyber Security.
They discuss the intersection of human psychology and cybersecurity. Andrew shares insights from his groundbreaking research including the first national baseline study on mental well-being in the cybersecurity sector.
The conversation explores three critical human dimensions in cybersecurity:
Packed with actionable advice and fascinating psychological insights, this episode is a must-listen for anyone in cybersecurity or interested in the human side of digital defense.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Rob welcomes Tony Gonzalez, Principal at Inner Vision Services LLC and former CISO for QBE North America. They delve into the topic of third-party risk management, exploring its evolution from a checkbox approach to a comprehensive part of an organization's risk posture. They discuss the challenges and responsibilities involving third, fourth, and even fifth-party risks, especially within large organizations across various sectors like financial services, insurance, and biotech. Regulatory influences such as NYDFS and PCI are also examined, along with practical advice for prioritizing and improving third-party risk assessment processes, highlighting the importance of strategic partnerships and efficient communication.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Rob is joined by Roland Cloutier, a principal at The Business Protection Group and former CISO at TikTok, to discuss key priorities for organizations in cybersecurity as they move into 2025. The conversation focuses on three major areas: the impact and evolution of AI, the importance of compliance and operational sustainability, and the critical need for enhancing cyber and digital resiliency. Roland emphasizes the convergence of data defense and identity access, providing insights on addressing emerging AI-driven threats, improving business continuity, and leveraging new technologies to better prepare for future challenges. The episode is filled with practical advice and strategic recommendations for security leaders.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this week’s episode of Reimagining Cyber, host Rob Aragao (live from Las Vegas!) dives into the convergence of identity security and data protection—a critical topic reshaping the cybersecurity landscape.
Rob unpacks the key drivers behind this shift, including regulatory mandates like GDPR and CCPA. The conversation emphasizes the need for organizations to bridge gaps, improve communication, and collaborate across teams for better security outcomes.
Tune in for insights on:
Other episodes relevant to this discussion:
Cyber Resilience - are your strategies for purpose? - Ep 115
IAM, CIAM, and ZTA, The Trifecta of Access Management - Ep 24
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In Episode 123 of Reimagining Cyber, Rob and the team dives into the complex world of cybersecurity for Industrial Control Systems (ICS) and Operational Technology (OT). Reflecting on insights from recent conversations with industry experts like Eric O'Neill and Tiffany Snyder, the show explores the evolving risks, vulnerabilities, and essential security measures in these critical infrastructure environments. They discuss the role of threat intelligence, the growing need for tailored incident response plans, and the challenges of securing legacy systems against modern cyber threats. Rob also unpacks findings from the latest SANS ICS/OT Cybersecurity Survey, shedding light on current trends such as cloud adoption, AI integration, and the ongoing struggle to bridge IT and OT security gaps. With potential threats looming, this episode underscores the urgent need to strengthen defenses across critical industries.
SANS ICS/OT Cybersecurity Survey:
https://www.sans.org/white-papers/sans-2024-state-ics-ot-cybersecurity/
Previous episodes mention in this edition:
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, host Rob Aragao is joined by Tyler Moffitt, Senior Security Analyst at OpenText, to dive into key findings from the 2024 Threat Hunters Perspective report. Tyler, a veteran in malware analysis, shares insights on the latest adversary tactics, cybercrime trends, and the methodology behind their research. They discuss the complex interplay of nation-state actors like Russia and China, who are leveraging cybercrime gangs to bolster their offensive campaigns, and explore the alarming regularity of DDoS attacks on critical infrastructure in response to geopolitical events.
The conversation also covers intriguing case studies, including real-time attacks on Western railway networks after public support for Ukraine, coordinated cyber disruptions during election cycles, and incidents where threat actors demonstrated insider intelligence on military shipments. Tyler offers predictions for the future, warning of an intensifying cyber arms race and the growing impact of generative AI on social engineering, deepfakes, and misinformation.
The episode wraps up with practical advice for improving cybersecurity hygiene, emphasizing the importance of patch management, multi-factor authentication, and understanding supply chain vulnerabilities. A compelling listen for anyone interested in staying informed and prepared in the evolving cybersecurity landscape.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode, Rob Aragao sits down with cybersecurity expert and former FBI operative, Eric O'Neill, to discuss the looming cyber threats to critical infrastructure. Eric delves into the vulnerabilities of the U.S. power grid, water systems, and communications networks, emphasizing how these vital sectors are targeted by hostile actors like Russia, China, North Korea, and Iran. He shares eye-opening examples of past attacks, probes, and the intricate nature of these digital threats, from the infamous Ukraine blackout to ongoing reconnaissance efforts.
As geopolitical tensions rise, Eric warns of the potential for catastrophic attacks on critical infrastructure and the growing risk of combined cyber-kinetic strikes. They explore how adversaries infiltrate SCADA networks, the importance of evolving cybersecurity measures, and the necessity of shifting from perimeter defense to active threat hunting.
Eric also gives a sneak peek into his forthcoming book, Invisible Threat, which teaches readers how to think like a spy and defend against modern cybercrime. Packed with real-world insights and practical advice, this episode is a must-listen for anyone concerned with the future of cybersecurity and national security.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
As featured on Million Podcasts' Best 100 Cybersecurity Podcast and Best 70
Chief Information Security Officer CISO Podcasts rankings.
In this episode of Reimagining Cyber, Rob Aragao sits down with Eric O'Neill, former undercover FBI operative, national security attorney, and bestselling author. Eric shares his gripping experience as the key operative in bringing down Robert Hanssen, the most damaging spy in U.S. history. Hanssen’s betrayal spanned over two decades, during which he sold highly classified information to the Soviet Union and Russia, affecting national security on an unprecedented scale.
Eric recounts how his undercover mission within FBI headquarters helped uncover Hanssen's espionage, an operation that also highlighted the emergence of cyber espionage. Hanssen was a pioneer in cyber spying, meticulously stealing sensitive data through compromised systems, and his actions ultimately set the stage for modern cybersecurity challenges.
The discussion evolves to focus on today’s cyber threats, particularly the intersection of espionage and cybercrime. Eric details how tactics used in traditional espionage have now infiltrated the digital world, with cybercriminals and state-sponsored espionage groups employing sophisticated techniques, including spear phishing and ransomware. The conversation also delves into notable cyberattacks like the SolarWinds and Kaseya incidents, highlighting the shared strategies between espionage and organized cybercrime.
With his extensive background in counterintelligence and cybersecurity, Eric offers a unique perspective on the current landscape of cyber threats, stressing the critical importance of understanding the attackers' mindset to effectively safeguard digital infrastructures.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
“We took what we know about nation-state actors... and we found that it was a really effective program. The program has about 1,000 companies enrolled in it to date, and it’s blocked 7 billion malicious domains since we started it.”
This episode features Kristina Walter, a key figure behind the NSA's Cybersecurity Collaboration Center (CCC), as she discusses the initiative's origins, mission, and future vision. Kristina shares insights into the challenges of protecting critical infrastructure, particularly the defense industrial base, and explains how the CCC bridges the gap between the public and private sectors to combat nation-state cyber threats. She highlights the success of cybersecurity services like DNS protection, attack surface management, and threat intelligence collaboration, as well as key partnerships, including a notable case with Viasat during the Ukraine conflict. Kristina also reflects on her role in the NSA's Future Ready Workforce Initiative and how it aims to evolve the agency’s talent pipeline in the face of modern challenges. Tune in for a deep dive into how collaboration, innovation, and partnerships are crucial to advancing national cybersecurity efforts.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, we are joined by Lisa Plaggemier, Executive Director of the National Cybersecurity Alliance (NCA), to discuss the NCA’s mission, current initiatives, and the importance of cybersecurity education. They highlight key programs, their collaboration with CISA on cybersecurity campaigns, and their efforts to simplify cybersecurity for the public and businesses. The conversation touches on challenges in public awareness, the role of AI in cybersecurity, and special initiatives for small businesses and historically Black colleges and universities (HBCUs). Tune in to learn how cybersecurity affects everyone from teens to seniors, and what you can do to stay safe online.
Key Takeaways:
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of Reimagining Cyber, host Rob Aragao is joined by Tiffany Snyder, the Deputy Chief of Cybersecurity Mission Integration at NASA. Tiffany delves into her journey from the Air National Guard to leading cybersecurity efforts at NASA, where she oversees the protection of one of the most technologically advanced organizations in the world. She highlights the unique cybersecurity challenges NASA faces, including safeguarding mission-critical systems that power space exploration and scientific discovery. Tiffany discusses the importance of collaboration across government agencies, international partners, and industry experts to strengthen NASA's cybersecurity posture.
The episode covers key areas such as supply chain security, ensuring the integrity of systems that support both space and ground operations, and how NASA handles massive amounts of data securely. Tiffany also touches on the role of emerging technologies, including artificial intelligence and machine learning, in enhancing NASA’s cybersecurity framework. Tune in to hear how NASA is navigating the complex landscape of cybersecurity in space and beyond.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, Rob Aragao talks about a recent joint cybersecurity advisory highlighting People's Republic of China-linked actors compromising routers and IoT devices for botnet operations. The advisory points to over 260,000 IoT devices, impacted by a botnet called Raptor Train.
It’s being alleged that Integrity Technology Group (Integrity Tech) are behind the incident. The report says
“[Integrity Technology Group is a] company based in the PRC with links to the PRC government. Integrity Tech has used China Unicom Beijing Province Network IP addresses to control and manage the botnet described in this advisory. In addition to managing the botnet, these same China Unicom Beijing Province Network IP addresses were used to access other operational infrastructure employed in computer intrusion activities against U.S. victims. FBI has engaged with multiple U.S. victims of these computer intrusions and found activity consistent with the tactics, techniques, and infrastructure associated with the cyber threat group known publicly as Flax Typhoon, RedJuliett, and Ethereal Panda.”
Detected by Lumen’s Black Lotus Labs, the advisory was issued by the FBI, NSA, and Cyber National Mission Force.
Rob explains that the botnet leverages code from the notorious Mirai malware, designed to exploit IoT devices running Linux-based systems, which has been in circulation for nearly a decade. He breaks down the architecture of the botnet, including its three-tier structure, and the role of compromised IoT devices, command-and-control servers, and management layers.
Additionally, the discussion explores China's growing focus on cybersecurity talent recruitment, including the Matrix Cup, a hacking competition co-sponsored by Integrity Technology Group. The episode also offers recommendations for mitigating IoT device vulnerabilities, such as strong password management, patch updates, and network segmentation.
Don't forget to rate, review, and subscribe to stay updated on future episodes!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In the latest episode of Reimagining Cyber, Rob interviews Bindu Sundaresan, Director of Cybersecurity Solutions at Level Blue, about the evolution and significance of cyber resilience. Bindu, with over 20 years in cybersecurity, discusses how the field has shifted from a focus solely on prevention to a broader approach that includes resilience and recovery.
Key points from the conversation:
Historical Focus: Traditionally, cybersecurity strategies concentrated on preventing attacks. However, the current threat landscape necessitates a shift towards resilience, acknowledging that breaches are inevitable.
Modern Approach: Organizations are now integrating business continuity planning and disaster recovery with cybersecurity efforts. This holistic approach ensures that operations can continue and recover swiftly after an attack.
Business Alignment: Bindu emphasizes that cybersecurity should be seen not just as a technical issue but as a business problem affecting overall operations. This shift in perspective helps align cybersecurity efforts with business outcomes and improves the strategic value of cybersecurity roles.
CISO's Role: For Chief Information Security Officers (CISOs), successfully integrating resilience into their programs involves understanding and prioritizing risks based on business impact. This requires effective communication with other business units and aligning cybersecurity investments with broader business goals.
Evolution of Cybersecurity: The conversation highlights the shift from compliance-driven approaches to risk-driven and resilience-focused strategies. This evolution is crucial for achieving digital resilience and
Identifying Sensitive Data: Organizations must first identify what constitutes sensitive data for their specific context, considering regulatory requirements, business use, and industry standards. Without this understanding, investments in data protection might be misallocated.
Data Classification and Flow: It is crucial to classify sensitive data and map how it flows within and outside the organization. This helps in applying appropriate security controls and prevents unnecessary complexity and expense.
Continuous Review: Data classification and protection are not one-time tasks. Organizations need to regularly update their data inventory and classification as their data environment evolves
Incident Response and Resilience: Organizations should develop tiered recovery plans that prioritize critical business functions during incidents. Regularly updated tabletop exercises should simulate realistic and current scenarios to test response plans effectively.
10.Cross-Functional Involvement: Effective incident response involves cross-functional teams, including IT, legal, PR, and executive leadership. Establishing what constitutes minimum viable operations helps prioritize recovery efforts and resource allocation during an incident.
11.Evolving Practices: The goal is to continuously refine incident response and recovery practices to improve resilience over time. Embracing a lifecycle approach to security and resilience can turn digital resilience into a competitive advantage.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of "Reimagining Cyber," host Rob Aragao continues his insightful conversation with Craig Jones, former Director of Interpol’s Global Cybercrime Directorate. They delve into the countries most targeted by cybercrime and the regions where these crimes often originate. Craig highlights the challenges of combating cyber threats in areas with limited law enforcement capabilities and underscores the critical need for international cooperation. The discussion explores successful regional collaborations, the development of international cybercrime conventions, and the importance of resilient infrastructures, especially for SMEs. Craig also emphasizes the need for security by design in technology, regular preparedness drills within organizations, and ongoing global efforts to enhance cybersecurity through awareness campaigns and private sector partnerships. Despite the challenges Interpol faces, the episode underscores the importance of operational relevance, capacity building, and community engagement in the fight against cybercrime.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of "Reimagining Cyber," host Rob Aragao interviews Craig Jones, the former Director of the Global Cyber Crimes Directorate at Interpol. Jones provides a comprehensive overview of Interpol's role in combating cybercrime, emphasizing its unique position as a non-executive body that facilitates international law enforcement collaboration among 196 member countries.
Jones discusses the structure and function of Interpol, noting how it connects various national police forces to coordinate cybercrime operations, despite being unable to directly run investigations. He explains how Interpol's cybercrime efforts are organized around prevention, detection, investigation, and disruption, aiming to reduce the global impact of cybercrime and protect communities worldwide.
The conversation also delves into the challenges of dealing with borderless cybercrime, such as ransomware, business email compromise, and data theft. Jones highlights the complexities of international cooperation, especially when cybercriminals operate across different jurisdictions. He also touches on the recruitment process for Interpol's cybercrime division, stressing the importance of diverse backgrounds and expertise.
Finally, the discussion explores the evolving landscape of cybercrime, the rise of the cybercrime economy, and the critical role of cyber resilience in protecting organizations. Jones and Aragao underscore the importance of involving board-level executives in cybersecurity decisions and the need for a comprehensive approach to cyber resilience, emphasizing the long-term benefits of such strategies in the face of ongoing cyber threats.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, Roland Clouthier, former CSO of TikTok and cybersecurity expert, explores the role of AI in cybersecurity, the evolving landscape of cloud security, and the critical importance of identity management. Roland shares insights on how to effectively allocate security budgets, the importance of understanding risk tolerance, and the need for transparency in AI governance. Tune in to gain valuable tips on future-proofing your organization’s cybersecurity strategy in the face of emerging challenges.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of "Reimagining Cyber," Rob Aragao hosts a conversation with Tammy Klutz, a best-selling author and current CISO at Trinseo. Tammy discusses her career trajectory, which includes leadership roles at Covanta Energy and Versum Materials, and shares insights from her recent book, Leading with Empathy and Grace: Secrets to Developing High-Performing Teams.
Additionally, she addresses the challenges women face in cybersecurity, offering advice on building confidence, taking risks, and overcoming barriers in a male-dominated field. The episode provides valuable takeaways for aspiring leaders and women looking to enter or advance in the cybersecurity industry.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of Reimagining Cyber, hosts Rob Aragao dives into the intersection of sports and cybersecurity, inspired by a cyber attack at the recent Paris Olympics.
The conversation takes a deep dive into the cyber threats that have historically plagued the Olympics, from the 2016 Rio Games to the 2018 Winter Olympics in Pyeongchang. They discuss the frequent denial of service attacks, ransomware, and phishing campaigns that target such high-profile events. The Tokyo 2020 Olympics saw an astounding 450 million cyber events, setting the stage for heightened vigilance at the Paris Games, where over 3 billion cyber threats were anticipated.
Rob and Ben explore the potential motivations behind these attacks, ranging from geopolitical tensions to the desire for disruption or financial gain. They emphasize the importance of rigorous preparation, including ethical hacking and advanced security measures, to protect such significant global events.
Tune in to hear how the world’s largest sporting event has become a prime target for cybercriminals and what it takes to defend against these sophisticated threats.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, we dive deep into the world of cybersecurity with Jon Brickey, Senior Vice President at MasterCard. With extensive experience across military, government, and corporate sectors, Jon offers unique insights into the evolving landscape of cyber threats and defenses.
Jon shares how MasterCard is at the forefront of fostering a culture of collaboration and partnership in cybersecurity. He highlights the company's commitment to collective defense, emphasizing the need for global consistency and innovation in building a future-ready cyber workforce. Learn about MasterCard's pivotal role in organizing the tri-sector cyber defense exercise, which unites the energy, telecom, and finance sectors with government agencies. This initiative aims to enhance cyber resilience through strategic collaboration and shared best practices.
Throughout the conversation, Jon underscores the importance of agile industry responses to cyber threats and the critical synergy between government and industry in addressing these challenges. He delves into the ways MasterCard is preparing for future cyber threats, from developing cutting-edge technologies to implementing robust training programs for their teams.
Listeners will gain valuable insights into the strategic initiatives that are shaping the future of cybersecurity. Jon's perspective on the importance of public-private partnerships, the role of innovation in cyber defense, and the need for a proactive approach to cybersecurity provides a comprehensive understanding of the current and future state of the industry.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this riveting episode of "Reimagining Cyber," host Rob Aragao continues his deep dive into the shadowy world of cyber threats with Ashley Jess, Senior Intelligence Analyst at Intel 471. As a follow-up to their previous discussion, Ashley delves into the alarming rise of deepfakes and disinformation.
Ashley sheds light on the evolving tactics of cybercriminals, from sophisticated "Know Your Customer" (KYC) bypass methods to the increasing use of AI in creating convincing deepfake videos and misinformation campaigns. She discusses the implications of these threats for both private and governmental organizations, emphasizing the importance of vigilance and proactive defense measures.
Listeners will learn about the significant risks posed by AI-generated content, the psychological impact of pervasive deepfakes, and the crucial role of basic cybersecurity hygiene in countering these advanced threats. Ashley also offers a glimpse into the future of cyber threats and the ongoing battle between cybercriminals and defenders.
Don't miss this insightful episode, and be sure to catch the first part of this conversation for a comprehensive understanding of the current cyber threat landscape.
Key Topics:
* Deepfakes and their impact on the Summer Olympics
* Evolution of AI-enabled KYC bypass methods
* Disinformation campaigns targeting elections globally
* The psychological and practical challenges of detecting AI-generated content
* Effective cybersecurity practices to defend against emerging threats
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of Reimagining Cyber, host Rob Aragao interviews Ashley Jess, a senior intelligence analyst at Intel 471. Ashley discusses her transition from the FBI to her current role, highlighting her expertise in malware trends and AI abuse. The conversation explores the rise of info stealers, the decline of drainer malware, and the increasing use of AI by cybercriminals for social engineering and fraud. Ashley also delves into specific cases like Worm GPT, illustrating the evolving tactics of threat actors.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
The latest episode of Reimagining Cyber dives into the recent major data breaches that have rocked the telecom sector, focusing on the latest AT&T incident.
It begins by reflecting on the historical context of cyberattacks in telecom, noting T-Mobile’s previous breach involving 85 million records and a hefty $500 million settlement.
Host of the show Rob Aragoa details the chronology of AT&T's breaches, starting with a lesser-known incident from 2021, where the hacker “ShinyHunters” initially infiltrated AT&T's systems.
Despite early warnings, AT&T dismissed the threat, leading to a subsequent data dump on the dark web in early 2023, exposing over 73 million records. Fast forward to the latest breach disclosed last week, impacting a staggering 110 million customers, with call and text message records from May to October 2022 being compromised.
Rob explains the intricate balance between national security concerns and public transparency, highlighting the role of the Department of Justice in delaying the breach announcement.
The discussion then shifts to the broader implications and accountability within the telecom industry. Rob references the FCC's recent update to their data breach notification rules, which were 16 years old, underscoring the urgent need for regulatory improvements.
Rob concludes by examining the steps AT&T and its cloud data provider, Snowflake, are taking to prevent future breaches, such as implementing mandatory multi-factor authentication. They stress the importance of basic cybersecurity hygiene and the necessity for ongoing vigilance in protecting sensitive customer data.
This episode offers a comprehensive look at the complexities and challenges in securing the telecom sector, leaving listeners with critical insights into how these breaches occur and the measures needed to prevent them. Tune in for an engaging and informative discussion on one of the most pressing issues in cybersecurity today.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Join hosts Stan Wisseman and Rob Aragao as they engage with Martin Roesch, CEO of Netography and creator of Snort. With over 25 years in cybersecurity, Martin discusses network security evolution, especially in network observability. He explains the shift from traditional deep packet inspection (DPI) to leveraging metadata for network analysis due to the rise of encryption and dispersed networks. This metadata approach offers a broader view of network activities, overcoming DPI limitations.
The conversation explores the complexities of maintaining security across different environments and the inefficiencies of disparate security tools for on-premises IT, AWS, Azure, and OT environments. Martin stresses the need for a unified security strategy adaptable to modern network architectures. He highlights metadata-based analysis for effectively detecting anomalies and reducing false positives, offering a clearer network activity picture.
Martin also addresses the challenge of tracking lateral movement within and across cloud environments. Current security tools often fail to monitor these movements in real time, complicating threat response. Adopting a metadata-centric approach enhances understanding and mitigation of lateral movements, bolstering security posture.
Rob Aragao further asks about emerging threats and key technologies in multi-cloud security. Martin emphasizes the promise of data security over identity as a perimeter and the need for unified, frictionless toolsets in multi-cloud environments to reduce operational friction. As enterprise networks expand, these low-friction architectures are vital for scalable, efficient security solutions, presenting opportunities for companies providing seamless multi-cloud capabilities.
Tune in to gain deeper insights into the current and future state of network security from a leading expert.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, we delve into the recent cyber attack on CDK Global, a leading technology provider for the automotive industry. This incident, which disrupted operations for thousands of car dealerships across the United States, serves as a stark reminder of the vulnerabilities in our interconnected digital landscape.
Join us as we explore the immediate and long-term impacts of the attack, including significant operational disruptions and financial consequences that are expected to linger for months, if not years. We discuss the crucial lessons learned from this incident, highlighting the importance of robust cybersecurity measures, proactive threat detection, and the continuous evolution of security best practices.
We also examine the broader implications for operational continuity and resilience. Discover why it's essential for businesses to prepare for potential threats, implement redundancy and alternative strategies, and demand better security assessments and visibility from their service providers.
Furthermore, we address sector-specific challenges faced by automotive dealerships, such as the variability in resources and support structures, and the role of manufacturers in providing alternative software solutions.
Finally, we touch on the regulatory and legal landscape, including SEC breach disclosure requirements and related lawsuits, underscoring the necessity of compliance and transparency in cybersecurity.
Tune in to gain valuable insights into the critical importance of cybersecurity in today's digital age and learn how organizations can stay vigilant and proactive in protecting their operations and data.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, Stan Wisseman and Rob Aragao welcome Justin Young to explore the transformative role of Software Bill of Materials (SBOMs) in enhancing software supply chain security. Justin shares his extensive experience and insights into how SBOMs contribute to the maturation of the software industry, drawing parallels with the auto and food industries' approaches to defect and ingredient tracking.
The discussion delves into the regulatory landscape, highlighting the FDA's SBOM requirements for medical devices, the U.S. National Cybersecurity Strategy, and various compliance mandates from CISA, DORA, PCI, and the EU CRA. Justin explains the importance of shifting liability to software vendors and away from end users and open-source developers, emphasizing the need for actively maintained and secure software components.
Listeners will gain an understanding of the different SBOM formats, Cyclone DX and SPDX, and their respective advantages. Justin also addresses the challenges organizations face in managing SBOMs, including procurement, validation, and the necessity of a dedicated SBOM program manager.
Finally, the episode explores the practicalities of SBOM implementation, from storage and cataloging to enrichment and vulnerability management, offering a comprehensive guide for organizations aiming to bolster their software security practices.
Tune in to learn how SBOMs are reshaping the software industry, driving transparency, and enhancing security across software supply chains.
Relevant Links:
Episode 88: Open-Source Software: Unlocking efficiency and innovation
Episode 41: Do a little dance, Time for some SLSA
Episode 26: Log4j Vulnerabilities: All you need to know and how to protect yourself
Episode 4: SolarWinds: Bringing down the building… Software Supply-Chain Pressure Points
Whitepaper: The need for a Software Bill of Materials
Software Supply Chain Hub page
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this podcast episode, hosts Rob Aragao and Stan Wisseman are joined by Arun DeSouza, a renowned expert in connected vehicle security and former CISO at leading automotive companies. Arun begins by highlighting the critical challenges facing connected vehicles, emphasizing the importance of security by design throughout the development lifecycle. He stresses the need for rigorous vulnerability assessments and penetration testing to prevent vulnerabilities that could lead to remote hacking or data breaches.
Arun discusses the vital role of infrastructure connectivity and encryption in securing data transmission between vehicles and the cloud. He emphasizes the necessity of secure over-the-air software updates to patch vulnerabilities promptly. Addressing the risks associated with peripheral devices connected to vehicles, Arun advocates for robust system interface protections and micro-segmentation strategies to isolate critical systems from non-critical ones.
Privacy and data security emerge as central concerns, with Arun emphasizing the importance of adhering to privacy-by-design principles. He discusses the implications of GDPR-like standards for protecting sensitive data collected by connected vehicles and underscores the need for user consent frameworks in data handling practices.
The conversation extends to the complex automotive supply chain ecosystem, where Arun stresses the importance of implementing robust security measures across third-party suppliers. He highlights the role of continuous security assessments and collaborative efforts within the supply chain to mitigate cybersecurity risks effectively.
Concluding the episode, Arun offers practical advice for consumers considering connected vehicles, suggesting they seek transparency from manufacturers regarding cybersecurity features. He encourages leveraging industry networks and expert advice to make informed decisions about vehicle purchases in 2024.
Join us for an insightful exploration of the evolving landscape of connected vehicle security.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, Rob Aragao and Stan Wisseman look at the intriguing transition from Chief Information Security Officer (CISO) to Chief Technology Officer (CTO). Drawing from a recent sidebar conversation among CISOs and an insightful article from Dark Reading, they examine why this trend is becoming more prominent. With examples from organizations like Bank of America, Fifth Third Bank, and Equifax, Rob and Stan discuss the key attributes that make this career move logical and beneficial.
The conversation highlights the importance of collaboration, strategic thinking, and the deep understanding of both technology and business impact that CISOs bring to the table. They delve into how the roles of CISO and CTO overlap, particularly in driving innovation, increasing revenue, and embedding security by design into business solutions.
Rob and Stam also consider the broader influence a CTO has on an organization's technology strategy, the operational experience both roles share, and the potential motivations behind CISOs seeking to transition—whether to escape the increasing personal liability associated with security breaches or to pursue new professional growth opportunities.
Additionally, the episode touches on the challenges CISOs might face in this transition, such as the need for expertise in product development and the software lifecycle.
As discussed in this episode:
https://www.darkreading.com/cybersecurity-careers/ciso-as-a-cto-when-and-why-it-makes-sense
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Reimagining Cyber is 100 episodes old! The podcast began in December 2020 as a bi-weekly dive into cybersecurity and cyber resiliency. It is now a weekly affair and has become a regular feature in the Apple Podcast Technology charts. It is also one of the most respected shows in the cybersecurity genre.
Hosts Rob Aragao and Stan Wisseman alternate between head-to-head discussions on the latest cyber topics of the day and guest interviews. This week’s guest is Mark Fernandes, Global CISO at CAE. Mark heads a team focused on cyber resilience, particularly in the critical sectors like aviation, defense and security. CAE is a prominent force in the defense and government, but it's also equally recognized in their commercial pilot training programs. With over 28 years of experience in cybersecurity, Mark has extensive knowledge in governance, analytics, intelligence, and advanced threat defense.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of Reimagining Cyber Rob and Stan look at the staggering costs and ongoing epidemic of data breaches and ransomware attacks. Did you know that the average cost of a mega breach involving 50 to 60 million records is a jaw-dropping $332 million? Ransomware, though less expensive, still costs businesses an average of $4.5 million per attack. It's clear that organizations must be better prepared to face these threats.
To shed light on effective strategies and insights Rob and Stan are joined by Shamoun Siddiqui, VP and Global CISO of the Upbound Group. He helps answer the burning question: Can businesses ever be truly breach-proof, even with unlimited funds? Shamoun emphasizes that while complete security is unattainable, companies can operate with risk management strategies, acknowledging limitations in funding, talent, and technology.
Shamoun shares real-world examples of vulnerabilities exploited during modernization efforts and stresses the importance of maintaining robust cybersecurity programs. He offers invaluable advice on building business justifications for cybersecurity investments, communicating effectively with boards of directors, and focusing on core security controls like multi-factor authentication and privileged access management.
He also delves into the critical role of external relationships with law enforcement and forensic companies during a breach, and how these interactions can impact the outcome. Shamoun highlights the importance of having a pre-established plan, managing internal and external communications, and the necessity of resilience and recovery strategies.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Cyber posture –what is its role in today’s digital landscape? What are the essential components that make up a robust cyber posture? What practical advice is there for organizations looking to bolster their defenses against ever-evolving cyber threats?
In this episode, Rob and Stan delve into the complex landscape of cybersecurity posture management. They dissect posture management solutions in the market, highlighting the need to cut through marketing hype to focus on tangible outcomes. Emphasizing the importance of continuous monitoring, they explore the evolution of posture management from a static assessment to an ongoing process. Drawing on examples like cloud security posture management and data governance, they stress the need for comprehensive visibility across diverse environments. Rob and Stan discuss the challenges faced by organizations of varying sizes in achieving effective posture management, considering resource constraints and the role of automation. They also touch on the intersection between posture management and regulatory compliance, advocating for a risk-based approach over checkbox compliance. Throughout the discussion, they underscore the significance of people, processes, and technology in shaping an organization's cyber resilience. Looking ahead, they contemplate the potential role of AI-driven interfaces in facilitating efficient posture management and adaptation to evolving threats.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In the latest episode of Reimagining Cyber, hosts Rob and Stan explore crisis management in cybersecurity with expert Kevin Dinino, founder of KCD PR. They stress the pivotal role of effective communication during cyber incidents, highlighting the need for a robust crisis communication plan, particularly for public companies. Kevin outlines key elements such as audience identification, messaging strategy, and communication methods. They delve into tailored responses for different incidents like ransomware attacks. The conversation underscores the importance of tabletop exercises in streamlining decision-making processes and avoiding unnecessary delays. They emphasize empowering teams to communicate promptly without excessive approvals. Establishing clear internal and external communication channels, including designated media contacts and backup methods, is critical. Proactively controlling the narrative and providing timely updates help prevent misinformation and maintain trust. Lessons learned include the necessity of alignment between parent and subsidiary companies in crisis communication. In essence, a proactive and coordinated approach is vital for successful crisis management in cybersecurity.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of "Reimagining Cyber," join hosts Stan Wisseman and Rob Aragao as they explore the cutting edge of cybersecurity. First, they discuss an upcoming live webinar where listeners can engage with them directly on the topic of cyber risk posture management. Then, they delve into the world of smart contracts and decentralized finance, examining both the revolutionary potential and the inherent risks. The conversation shifts to cybersecurity roadshows, where they highlight key insights from recent fireside chats with industry leaders about navigating the complexities of cybersecurity programs, gaining executive buy-in, and harnessing AI while maintaining data security.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode Stan and Rob delve into the critical issue of protecting seniors from cyber threats. Guest Michael Echols, author of "The Shield: Protecting Seniors From Hackers," sheds light on the alarming vulnerability of seniors in the digital age.
Drawing from personal experiences, Stan highlights how elderly family members are frequently besieged by scams, including fraudulent calls and phishing attempts. Michael unpacks the various tactics employed by cybercriminals, from romance scams to Medicare fraud, emphasizing the emotional manipulation used to exploit seniors' trust.
Michael also stresses the importance of proactive measures, such as credit freezes, to bolster cybersecurity defenses. He advocates for open dialogue and collaborative efforts within families and communities to combat cyber threats effectively.
Furthermore, the role of AI in both perpetrating and mitigating cyber risks is explored. While AI-driven attacks pose new challenges, innovative solutions like AI-powered call screening offer promising avenues for safeguarding seniors.
The episode concludes with a call to action: to recognize the gravity of the cybersecurity threat facing seniors and to take proactive steps to mitigate risks. By fostering awareness, implementing security measures, and fostering open communication, we can collectively shield seniors from the perils of cybercrime.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
What is an insider threat? How do you mitigate the impact of an insider theat? From malicious insiders driven by profit or spite to negligent insiders prone to carelessness, and compromised insiders unwittingly manipulated by external forces, Rob Aragao and Stan Wisseman try to unravel the layers of this critical cybersecurity concern.
Drawing from recent incidents like the Sisense breach and the XZ exploit, light is shed on the evolving tactics employed by malicious actors, highlighting the pressing need for robust detection and response mechanisms.
Links to points raised in this episode:
Blog by Stan -
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
"For nation states today their biggest bang for the buck is going to be to attack the perception of voting system security much more than the reality of voting system security."
Stan Wisseman and Rob Aragao delve into the critical realm of election security with Dr. Ben Adida, the co-founder and executive director of VotingWorks, renowned for his expertise in safeguarding our voting processes. Dr. Adida shares insights from his two-decade journey at the forefront of election security, offering a deep dive into the complexities of ensuring the integrity of our democratic process.
From the challenges of balancing ballot secrecy with verifiability to the evolving landscape of election security concerns, the conversation navigates through the intricate web of issues surrounding voting systems.
Dr. Adida sheds light on the pivotal role of voter-verifiable paper ballots and post-election audits in bolstering trust and transparency, emphasizing the need for modernizing voting technology to align with current security standards.
As the discussion unfolds, topics ranging from external influences on elections to the role of federal guidelines versus state autonomy are explored, providing a comprehensive overview of the multifaceted efforts to fortify election integrity. Dr. Adida's vision for the perfect voting system, grounded in openness, transparency, and layered defense mechanisms, offers a compelling roadmap for safeguarding democracy in the digital age.
https://www.eac.gov/voting-equipment/voluntary-voting-system-guidelines
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode Stan Wisseman and Rob Aragao delve into the critical yet often overlooked realm of API security. APIs, the linchpin of today's digital landscape, facilitate seamless communication between diverse software components, but they also present enticing targets for cyber threats. Through real-world examples and insightful analysis, Stan and Rob explore the escalating risks associated with APIs and offer strategies for fortifying your organization's defenses. From understanding your API inventory to implementing robust security measures, this episode equips listeners with essential knowledge to navigate the complex terrain of API security and safeguard their digital assets effectively.
Helpful links relevant to this episode:
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
“It’s only going to get worse if we don't pump the brakes and go, nope, we need to make sure we're doing this the right way.”
In this episode, Tim Fowler, an accomplished offensive security analyst and penetration tester from Black Hills Information Security, joins the podcast to discuss the intersection of cybersecurity and space systems.
Tim sheds light on:
Drawing from real-world examples like the ViaSat hack, Tim underscores the need for proactive cybersecurity measures, especially in the face of evolving threats and the increasing democratization of space technology.
The conversation also touches upon international collaboration and regulatory efforts in space cybersecurity, with Tim mentioning standards set by bodies like the Consultative Committee for Space Data Systems (CCSDS). However, challenges persist, including the cultural shift required to prioritize cybersecurity early in the space system lifecycle and address emerging threats effectively.
For details on Tim's Introduction to Cybersecurity and Space Systems class go to:
https://www.antisyphontraining.com/
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Join hosts Stan Wisseman and Rob Aragao as they explore the evolution of payment card security standards. With insights on PCI DSS 4.0, they dive into key changes and technology considerations. From data protection to application security, this episode offers crucial insights for organizations navigating compliance in an ever-evolving landscape.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, the Rob and Stan delve into a recent cyber attack targeting Change Healthcare, a key player in the healthcare sector. They highlight the unprecedented nature of the breach, its implications, and the collaborative efforts undertaken to mitigate its impact.
Change Healthcare, based in Nashville, Tennessee, disclosed the cyber attack on February 21st, causing significant disruptions across the healthcare ecosystem. The breach impacted various services, including claims processing and clinical decision support, affecting hospitals, pharmacies, and patients alike.
The attackers, identified as the ransomware group BlackCat, operated on a ransomware-as-a-service model. The hosts discuss the complex web of ransomware operations and affiliate relationships, shedding light on the intricate nature of cyber threats facing the healthcare industry.
The breach triggered a swift response from government agencies, with the Medical Group Management Association requesting assistance from the Department of Health and Human Services (HHS). HHS issued statements and provided alternative electronic data interchange options to minimize disruptions in patient care.
Rob and Stan look at the critical need for cybersecurity resiliency in the healthcare sector. They discuss proposed measures, including the adoption of HHS cybersecurity performance goals and the streamlining of funding opportunities to bolster cybersecurity defenses.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
What is the impact of open-source software (OSS) on modern software development?
This episode delves into the findings of a recent study commissioned by Open Text and conducted by Forrester called "Unlock Resources With Automated Open-Source Discovery And Intake". Stan and Rob unpack the evolving role of OSS, shedding light on both its opportunities and challenges.
With 70% of organizations reporting that over half of their coding efforts involve OSS, it's evident that OSS plays a pivotal role in accelerating innovation and reducing costs in software development. However, as the hosts discuss, this rapid adoption isn't without its hurdles.
From ensuring security and compliance to navigating through the complexities of OSS licensing, organizations face a myriad of challenges. Stan and Rob examine the ramifications of overlooking security vulnerabilities, compliance standards, and licensing terms, drawing from real-world examples to underscore the importance of diligent management practices.
But amidst the challenges lies a beacon of hope: automation. The hosts explore how automation is revolutionizing the discovery and integration of OSS components, paving the way for more secure and compliant software development processes. From streamlining discovery to prioritizing security early in the development cycle, automation holds the key to enhancing productivity and mitigating risks.
Looking ahead, Stan and Rob speculate on future directions in OSS management, emphasizing the need for collaboration, early detection of security issues, and continued innovation in the space. Whether you're a developer, a legal expert, or a cybersecurity enthusiast, this episode offers valuable insights into the ever-evolving landscape of open source software.
Tune in to gain a deeper understanding of the opportunities and challenges presented by open source software, and discover how organizations can navigate the open source seas with confidence and agility.
Report:
https://www.microfocus.com/en-us/assets/cyberres/automating-open-source-compliance
Debricked Open Source Select - a search engine where you can find, filter for and evaluate open source packages and repositories.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of Reimagining Cyber, hosts Rob Aragao and Stan Wisseman are joined by Dorota Wrobel, Chief R&D Officer for G2A, the world's largest digital marketplace for video games and software. Dorata discusses G2A's evolution from a regular online store to a two-sided marketplace for digital products, emphasizing the need for robust cybersecurity measures in the digital environment.
Dorota highlights the vulnerability of digital products to outside attacks and explains G2A's partnerships with top security companies to enhance security. She discusses G2A's strict seller verification processes and proof of purchase requirements to ensure trustworthiness and prevent fraud.
The conversation delves into G2A's regulatory compliance efforts, including adherence to security standards required by Payment Service Providers and membership in organizations like the Merchant Risk Council. Dorata explains how AI technology is utilized for fraud detection and response, augmented by human interaction and step-up authentication processes.
Looking to the future, Dorota discusses G2A's plans for further investment in monitoring systems and tokenizing payment options
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this conversation about threat hunting, Stan and Rob dive into why it's become such a crucial part of cybersecurity. They talk about how threat hunting isn't just about reacting to problems anymore, but it's become this proactive, creative way of spotting and tackling security issues before they become big headaches.
They reflect on how the role of a threat hunter has changed over the years. It used to be all about reacting to alerts, but now it's more about actively seeking out threats and analyzing them. And with the threat landscape changing so quickly, threat hunters have had to evolve their methods to keep up.
Stan and Rob also discuss the day-to-day workflow of a threat hunter. It's not just about sitting in front of a computer all day. It involves reviewing alerts, prioritizing threats, and collaborating with the team to share insights and strategies.
But it's not all smooth sailing. They talk about the challenges threat hunters face, like dealing with huge amounts of data and making sure their tools all work together seamlessly. Plus, there's the added pressure of compliance and legal considerations.
On the bright side, there's a whole arsenal of tools available to threat hunters, from fancy analysis platforms to simple note-taking apps. And with emerging tech like blockchain and quantum computing on the horizon, there's a lot of excitement about the future of threat hunting.
They also touch on the importance of team dynamics and management in threat hunting. It's not just about having the right tools—it's about having the right mindset and culture within the team. And diversity and inclusion play a big role in that, bringing different perspectives to the table and making the team stronger.
Overall, it's clear that threat hunting is more than just a job—it's a passion. And as long as there are cyber threats out there, there will always be a need for skilled threat hunters to track them down and neutralize them.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, Stan and Rob sit down with Felix Asare, a seasoned cybersecurity leader with extensive experience in the financial sector, including roles at Allianz and Putnam Investments. They delve into the cybersecurity landscape within the financial industry, exploring why it's a prime target for cybercriminals.
Felix breaks down the appeal of targeting the financial sector,
emphasizing the shift from physical to digital methods of theft due to the
lucrative nature of financial data. He highlights the importance of regulations
in setting security standards and explains how compliance, while necessary,
isn't sufficient for robust cybersecurity.
The conversation extends to the risks posed by the software
supply chain, particularly third-party vendors, and the challenges of
maintaining oversight in a complex ecosystem. Felix shares insights into
mitigating risks associated with open-source software and the need for rigorous
approval processes.
They also discuss the emergence of smart contracts and the
security implications of blockchain technology. Felix underscores the
importance of auditing smart contracts and maintaining vigilance in the face of
evolving threats like deepfake technology.
Lastly, the discussion turns to the role of AI in cybersecurity
defense, with Felix emphasizing its potential to enhance response times and
analyze data. However, he also cautions against overreliance on AI and the need
for human validation to combat emerging threats effectively.
Overall, the episode provides valuable insights into the
evolving cybersecurity landscape within the financial sector and the strategies
employed to mitigate risks and enhance security posture.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, hosts Rob and Stan explore the EU's Digital Operational Resiliency Act (DORA) with Dominic Brown, a cybersecurity expert. DORA addresses cyber threats to EU financial systems, emphasizing risk management, incident response, and third-party oversight. Dominic compares DORA to US regulations and advises organizations to build risk management teams and enhance cyber resilience before the 2025 deadline.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode of "Reimagining Cyber," Rob Aragao and Stan Wisseman welcome Adeel Saeed, discussing the importance of data protection in the evolving cybersecurity landscape. Adeel emphasizes the need to understand data sovereignty, navigate regulatory challenges like DORA, and implement a comprehensive data lifecycle strategy. The conversation delves into the nuances of technical debt related to data, the significance of cyber resilience, and the imperative for organizations to embrace a proactive approach in safeguarding their data assets.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Mother of All Breaches. The Midnight Blizzard attack. Nation state cyber conflicts. January 2024 has seen a blitz in cyber attacks. In this week's episode, hosts Stan Wisseman and Rob Aragao delve into the alarming start to the new year.
· Unprecedented Scale: Over 26 billion records compromised, impacting major platforms like Twitter, LinkedIn, Adobe, and Dropbox, along with government agencies worldwide.
· Data Complexity: The breach includes not only credentials but also sensitive data, creating substantial value for malicious actors.
· Organization: The breach was meticulously organized, posing a significant threat to data security and privacy.
· Notorious Group: Midnight Blizzard, also known as Cozy Bear and APT29, resurfaces
· Targeted Organizations: Microsoft and HPE were among the targets, with a focus on compromising Office 365 exchange environments.
· Attack Strategy: Utilizing password spraying and brute force, the attackers gained access to a legacy test nonproduction account, subsequently creating malicious OAuth applications.
· Specific Targeting: The attackers selectively targeted executives, cybersecurity teams, and legal teams, aiming to gather intelligence on Microsoft's activities.
· Escalating Tensions: Ongoing cyber warfare activities between Russia and Ukraine intensify, with a warning of disruptive and destructive attacks.
· Advanced Tactics: Russian cyber forces, particularly Midnight Blizzard, demonstrate advanced capabilities, impacting Ukrainian e-services, utility companies, and online banking.
· AI Integration: Ukraine effectively employs AI in its defense, utilizing facial recognition and cyber capabilities to counter cyber threats.
The hosts emphasize the importance of proactive measures, including password changes, multi-factor authentication adoption, and vigilant identity governance. The discussion underscores the evolving landscape of cyber warfare, encompassing both kinetic and cyber threats.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, hosts Rob and Stan explore the World Economic Forum's Global Cybersecurity Outlook 2024, a favorite annual report providing valuable insights into the cybersecurity landscape. Released early in the new year, the episode looks at the key themes, findings, and implications outlined in the report.
Main Themes:
· Report highlights dynamic changes and advancements in geopolitics and technology.
· Emphasis on impacts of geopolitical tensions, economic uncertainties, and technological advancements, especially in AI.
· Discussion on persistent challenges related to the shortage of cybersecurity skills.
· Acknowledgment of the critical role of cybersecurity in business, operations, and executive decision-making.
· Exploration of the growing importance of cyber resilience.
· Positive indicators of increased confidence among leaders in the resilience of cybersecurity programs.
· Examination of the disparity in cyber capabilities between larger and smaller organizations.
· Insights into challenges faced by smaller organizations, including resource constraints, skill shortages, and technology requirements.
· Discussion on the interconnected nature of cyber ecosystems.
· Emphasis on collaboration, threat intelligence sharing, and third-party assessments.
· Highlighting the significant impact of cyber attacks originating from third-party relationships.
Key Findings and Insights:
· Grave concerns among executives about advances in adversarial capabilities due to generative AI.
· Less than 10% believe generative AI will give an advantage to defenders over attackers.
· Observations on the changing landscape of cyber insurance, with a 24% drop in organizations obtaining cyber insurance.
· Recognition of cyber and privacy regulations as effective for risk reduction, though harmonization is needed.
· Increased involvement of CEOs and business leaders in prioritizing cybersecurity.
· 93% trust CEOs to speak externally about cyber risk, indicating growing alignment between cybersecurity and business strategy.
· Insights into executive concerns about operational disruption, financial impact, and brand reputation from cyber attacks.
· Balanced consideration of regulatory scrutiny, focusing on operational aspects and financial loss.
Conclusion: Rob and Stan encourage listeners to explore the detailed report for a deeper understanding of the evolving cybersecurity landscape. They emphasize the need for collaboration, proactive cybersecurity measures, and efforts to bridge the gap between larger and smaller organizations in building cyber resilience.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Welcome to another episode of "Reimagining Cyber." In this session, Rob and Stan dive into the critical role of IT auditors, a perspective rarely explored on the show. Their guest, Veronica Rose, brings extensive experience in shaping risk-based information security audit programs. She emphasizes the evolving nature of the IT audit environment and urges IT auditors to prioritize upskilling as technology and controls advance.
Veronica highlights the significance of professional communities, recommending affiliation with bodies like NACD and ISACA. Engaging in these communities not only provides access to valuable resources but also fosters global connections with like-minded professionals.
The discussion shifts to well-being, a crucial aspect often overlooked in the demanding field of IT audit. Veronica stresses the importance of mental health, exercise, and unplugging to maintain a clear mindset.
The conversation wraps up by addressing the career paths of IT auditors. Veronica encourages a mindset shift for those considering a transition, emphasizing the value of certifications and continuous upskilling.
Tune in to gain insights into the evolving world of IT audit, professional development, and holistic well-being.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, Rob Aragao and Stan Wisseman unravel the dynamic world of cybersecurity regulations, providing a sneak peek into the changes expected in 2024. From the upcoming PCI DSS 4.0 release strengthening cybersecurity postures to the FTC's push for timely breach notifications, and the SEC's implementation of breach disclosure rules, they navigate through the intricacies of compliance.
They shed light on the NIS2 directive, emphasizing the continuous evolution of cybersecurity practices, and delve into the EU Cyber Resiliency Act, encouraging security by design principles for products and services sold within the EU. The duo also examines the state-level privacy laws emerging across the United States, emphasizing the complexities organizations face in navigating this patchwork of regulations.
Tune in for insights on how these regulations impact businesses, the penalties associated with non-compliance, and the importance of a proactive, risk-based approach. Stay informed and ready for the evolving cybersecurity landscape in 2024!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, hosts Stan Wisseman and Rob Aragao reflect on the cybersecurity landscape of 2023 and discuss its potential impacts on the upcoming year, 2024. They delve into the alarming increase in incidents and breaches, noting a 30% rise. The conversation covers major breaches, such as the MOVEit and Okta incidents, emphasizing the growing threat of ransomware across various sectors.
The hosts highlight the interconnectedness of organizations, raising concerns about dependency on common platforms and the resulting ripple effect during security breaches. They stress the importance of reevaluating security controls and adopting a layered approach to mitigate vulnerabilities.
The episode also explores the escalating cyber warfare between nation-states, citing the ongoing conflict between Ukraine and Russia. Stan and Rob anticipate an increase in nation-state cyber threats, emphasizing the need for enhanced threat intelligence and proactive cyber defense measures.
Regulations, including the SEC cyber rule and the EU Act, are discussed as significant factors shaping the cybersecurity landscape. The hosts predict a continued evolution of regulations, emphasizing the need for organizations to adapt to changing compliance requirements.
The conversation touches on the emergence of generative AI and its impact on various industries, especially in cybersecurity. Stan and Rob acknowledge the dual nature of AI as both a tool for efficiency and a potential threat in the hands of malicious actors. They predict ongoing discussions about the regulation of AI and its implications.
Other topics include cyber insurance, where the hosts anticipate increased scrutiny and tighter requirements, and the importance of leveraging insurance requirements to drive cybersecurity improvements within organizations.
As the hosts look ahead to 2024, they emphasize the race between cybersecurity defenders and threat actors, acknowledging the potential for increased efficiency on the defenders' side but recognizing the challenges posed by the evolving threat landscape.
Other episodes mentioned in this edition:
Time to Take Them More Seriously - What's Iran Doing in Cyber? - EP 11
https://www.buzzsprout.com/2004238/episodes/10791018
Progress Over Perfection - Implementing the Executive Order - EP18
https://www.buzzsprout.com/2004238/episodes/10791011
SEC Cyber Rules Just Got Real - EP 69
https://www.buzzsprout.com/2004238/episodes/13875180
SEC Cyber Rules Forcing Boards to Pivot - EP 57
https://www.buzzsprout.com/2004238/episodes/12344694
US National Cybersecurity Strategy and EU Cyber Resilience Act - EP 61
https://www.buzzsprout.com/2004238/episodes/12532348
NIS2 Directive: Cyber Insights - EP 76
https://www.buzzsprout.com/2004238/14173706
AI and ChatGPT - Security, Privacy and Ethical Ramifications - EP 62
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, join hosts Rob Aragao and Stan Wisseman as they delve into the world of cybersecurity and data privacy with their esteemed guest, Shawn Tuma. Shawn, a seasoned cybersecurity and data privacy attorney, and partner at Spencer Fane, brings over two decades of experience to the table. As the co-chair of the firm's Cybersecurity and Data Privacy Practice Group, Shawn discusses his journey in the field, from the Y2K era to the present day.
The conversation covers key elements of cybersecurity, emphasizing the importance of a continuous, strategic approach to evaluating and managing risks. Shawn shares insights into prevalent issues such as RDP access, backup strategies, and the critical role of multifactor authentication, especially for users of Microsoft Office 365 and Google web-based email.
Reflecting on the evolution of cybersecurity, Shawn highlights the pivotal moment in 2013 with major data breaches at Target, Home Depot, and Neiman Marcus. He emphasizes the need for a proactive risk management framework and the significance of cybersecurity insurance in today's landscape.
The hosts and Shawn discuss the changing role of Chief Information Security Officers (CISOs) and the growing recognition of their strategic importance within organizations. Sean stresses the value of building relationships with law enforcement, particularly federal agencies like the FBI and Secret Service, to enhance incident response capabilities.
Throughout the episode, Shawn Tuma's passion for cybersecurity and practical, actionable advice shines through, making this conversation a must-listen for anyone navigating the complexities of cybersecurity in the modern business landscape.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Welcome to another episode of "Reimagining Cyber," where Stan and Rob explore the transformative landscape of cybersecurity regulations. In this insightful episode, they delve into the intricacies of the upcoming NIS2 directive from the EU, set to take effect in October 2024. Joining them is Bjørn Watne, Senior Vice President and Chief Security Officer at Telenor Group and an advisor to Europol, offering over 20 years of expertise in information security and cyber risk management.
The discussion revolves around the key changes introduced by NIS2, emphasizing a baseline cybersecurity approach across essential entities in diverse sectors. Bjorn sheds light on the directive's requirements for systematic security risk management, crisis management, and heightened resilience. The episode also navigates through the complexities of supply chain control, collaboration, and reporting vulnerabilities.
Drawing from Telenor Group's experience as a telecom operator, the hosts and guest unravel the distinct threat landscape faced by telecom companies, especially in dealing with advanced persistent threats and the significance of call detail records. Beyond traditional sectors, the conversation touches upon the implications of NIS2 on organizations, highlighting Telenor Group's compliance efforts.
Exploring the penalties associated with NIS2 noncompliance, the episode draws parallels with GDPR, underscoring the importance of these regulations in fortifying a secure digital infrastructure. As organizations prepare for NIS2, Bjorn shares practical advice, urging a proactive approach with asset inventory, business impact analysis, and comprehensive risk assessments.
Don't miss this episode packed with valuable insights into the NIS2 directive and actionable steps for organizations to elevate their cybersecurity readiness. Stay tuned and reimagine cybersecurity with Stan, Rob, and Bjorn on this informative podcast.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Welcome to another episode of Reimagining Cyber with Rob and Stan. In this episode, we dive deep into the crucial topic of data security. Stan shares insights from a recent cybersecurity event in Texas, emphasizing the growing threat of ransomware and the need for a dynamic approach to protect sensitive data.
Key Points:
Ransomware Challenges: Stan highlights the evolving landscape of ransomware attacks, where bad actors not only encrypt data but also extract and blackmail organizations. The importance of a robust backup strategy, including tiered storage with offline or air-gapped options, is emphasized.
Classification and Categorization of Data: Rob and Stan discuss the significance of understanding the types of sensitive data within an organization. They draw parallels to the Defense Department's classification system and stress the need for businesses to categorize their data to implement effective security measures.
SEC Cyber Ruling: The upcoming SEC ruling becomes a focal point, driving organizations to reassess their data security strategies. Rob explains how privacy regulations and regulatory actions, like the SEC ruling, act as catalysts for organizations to enhance their data security.
Discovering Hidden Risks: The hosts underscore the importance of comprehensive data discovery, revealing hidden risks and outdated systems. Stan likens undiscovered data to "toxic data" and emphasizes the need for continuous clean-up efforts to reduce both risk and costs.
AI and Bias in Data: The conversation shifts to the integration of AI in cybersecurity and the challenges of preventing bias in AI models. Stan discusses the importance of cleansing sensitive data before ingestion into AI models and the broader issue of unintentional biases in AI.
Conclusion: Rob and Stan wrap up the episode by reflecting on the evolution of cybersecurity terminology, from computer security to information assurance and now cyber security. They stress the multi-faceted nature of protecting information and the continuous effort required in today's dynamic threat environment.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Welcome to Reimagining Cyber, where we explore the evolving role of the Chief Information Security Officer (CISO). In this special episode, Stan and Rob present a compilation of insightful clips from previous episodes.
First up, Parham Eftekhari, Executive Vice President of the Cyber Risk Alliance, discusses the transformation of the CISO role into that of a business leader. He emphasizes the importance of understanding the business side of the organization and acting as a liaison between security priorities and business leaders.
Next, Tim Rohrbaugh, former CISO of JetBlue, shares his perspective on the budgeting process for information security organizations. He emphasizes the need for the CISO to have face time with the audit committee and stakeholders, suggesting that the budget should be tied to IT metrics.
Moving to the federal sector, Nick Ward, former CISO for the Department of Justice, discusses the executive order focused on enhancing cybersecurity. He delves into supply chain risk management and the tools provided by the executive order to prioritize and secure critical software.
Roland Cloutier, former TikTok CISO, explores the challenges of securing artificial intelligence implementations. He emphasizes the importance of understanding AI infrastructure, data stores, and API connections while highlighting the need for effective network protection.
Jeff Brown, CISO of the state of Connecticut, contrasts the role of a CISO in state government with that in the private sector. He emphasizes the benefits of information sharing and collaboration among state CISOs.
Taylor Hersom explores the concept of virtual CISOs, discussing the value of leveraging external expertise, especially for startups and scale-ups. He suggests that smaller companies can benefit from third-party resources before considering a full-time CISO.
In a special segment featuring female leaders in information security, Phyllis Woodruff, Tammy Schuring, and Lori Sussman share their experiences and insights. They highlight the importance of women owning their skills, embracing their unique attributes, and creating new pictures of leadership.
This episode provides a comprehensive overview of the evolving CISO role, covering topics such as business alignment, budgeting, federal cybersecurity initiatives, AI security, virtual CISOs, and the contributions of female leaders in the field. Join us as we continue to reimagine cyber in the ever-changing landscape of information security.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this insightful episode of "Reimagining Cyber," hosts Rob Aragao and Stan Wisseman underscore the criticality of deploying diverse testing methods, including Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST), for a comprehensive assessment and effective mitigation of vulnerabilities in the cyber landscape.
The hosts meticulously explore the nuances differentiating SAST and DAST, highlighting that SAST involves meticulous inside-out analysis through source code examination, while DAST employs a strategic outside-in analysis by rigorously testing running applications. Delving into the intricacies, they address challenges related to false positives in static analysis and illuminate coverage issues within dynamic testing methodologies.
The conversation seamlessly extends to emphasize the paramount importance of seamlessly integrating security testing into the development workflow, thereby minimizing friction for developers. The hosts delve into the evolving role of developers in the realm of security testing, showcasing a notable shift towards early integration of dynamic tests within the software development lifecycle.
Introducing the pivotal concept of Software Composition Analysis (SCA), the hosts accentuate its indispensable role in the identification and management of vulnerabilities stemming from open-source components. They underscore the significance of comprehensive awareness about the components utilized in applications, enabling swift responses to zero-day vulnerabilities and adeptly addressing licensing concerns.
Conclusively, the discussion advocates for a holistic approach to application security, encompassing SAST, DAST, and SCA methodologies. The hosts ardently stress the necessity of striking an optimal balance between development velocity and rigorous testing to proactively avert the potential high costs and repercussions associated with security breaches. Stay tuned for actionable insights that empower your cybersecurity strategy!
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Welcome to another compelling episode of the Reimagining Cyber podcast, where your knowledgeable hosts, Rob and Stan, explore the intricate landscape of Black Friday and Cyber Monday and the associated cybersecurity challenges that intensify during this festive shopping season.
Stan sheds light on the colossal scale of holiday spending, revealing that last year's Black Friday soared to an impressive 9 billion, while Cyber Monday skyrocketed to nearly 11 billion. With an astounding 197 million U.S. shoppers in the mix, the stakes are undeniably high, and the threats are alarmingly real.
The hosts pivot to the consumer side of the equation, drawing attention to the escalating sophistication of phishing emails. They caution listeners against succumbing to alluring offers that appear too good to be true and stress the paramount importance of verifying the authenticity of retail websites before divulging sensitive information.
Rob offers valuable insights into potential pitfalls for businesses, citing the recent Adobe update that addressed nine security vulnerabilities. The conversation delves into the multifaceted risks of payment fraud, ransomware attacks, and distributed denial of service (DDoS) attacks capable of disrupting e-commerce operations during this pivotal sales period.
Practical tips emerge as the hosts advocate for the crucial use of multi-factor authentication for online shopping accounts. They underscore the necessity of secure transactions facilitated by HTTPS protocols. Furthermore, Rob and Stan caution against using debit cards for online purchases and highlight the heightened risks associated with public Wi-Fi.
In summary, this episode provides not only a comprehensive understanding of the cybersecurity challenges during the holiday season but also actionable advice to navigate these threats successfully. Tune in for expert insights and safeguard your online experience during this bustling shopping period.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Former TikTok CISO Roland Clouthier emphasizes the imperative role of AI in staying competitive in the evolving business landscape:
"If my business is going to compete and succeed, and everyone else is using AI to reduce their OpEx and drive new technology to make us better than the next guy, I better be doing it too."
In this enlightening podcast episode, Clouthier explores crucial aspects of cybersecurity budgets in 2024, including cloud security, data protection, and personnel considerations. Uncover valuable insights as he shares his 'five key takeaways' for effective cyber budgets, stressing the significance of data protection: "A third of our job is going to be around how we protect data. You'll be able to engage and deliver things like AI if you can control your data."
Gain strategic guidance on addressing the evolving skills landscape with Clouthier's advice:
"Just look at your people. These are all new skills. These are all new areas. Make sure you're making the appropriate adjustments to your job families. You're migrating their skills through training, and then you're looking where you're getting your people from in the future."
Stay ahead in cybersecurity by delving into this insightful discussion on the latest industry trends.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Explore the fast-paced realm of cybersecurity with this Reimagining Cyber episode featuring insights from Tim Rohrbaugh, former global CISO of JetBlue. The conversation delves into the challenges of security control degradation and the risks associated with rapid changes. Rohrbaugh emphasizes the importance of strategic planning over relying on hope, stating, "Hope is not a strategy." The discussion also ventures into the delicate balance of cybersecurity budgets, where overspending can inadvertently support criminal activities.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Dive into the latest episode of "Reimagining Cyber" with Stan Wisseman and Rob Aragao as they discuss the imminent implementation of SEC cyber rules in December. Join the conversation as they revisit the key aspects, including the four-day disclosure period for cyber incidents deemed material, the evolving role of cybersecurity experts on boards, and insights from the Clorox cyberattack—a potential test case for the SEC cyber ruling.
Explore the financial implications and operational impacts of cyber incidents, with a focus on companies like Clorox, MGM, and Caesars, who have already navigated the disclosure process. Gain valuable perspectives on the potential reach of SEC regulations beyond public companies and the significance of the "How Material Is That Hack" website, which provides estimates of financial losses based on cybersecurity incidents.
Join Stan and Rob as they unravel the complexities of the SEC cyber rules and share their insights on the shifting cybersecurity landscape. Tune in for a comprehensive discussion on the latest developments and considerations for businesses in this evolving regulatory environment.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
23andMe promise that "protecting your privacy has been our number one priority." But how does that claim stack up in the light of their recent data breach?
That's the question posed by Rob and Stan in the latest episode of Reimagining Cyber.
23andMe provide DNA kits allowing users to obtain "the most comprehensive ancestry breakdown and 30+ trait reports." and the hackers targeted the individual accounts of hundreds of users.
So what does this cybersecurity failure mean for the victims?
What are the wider repurcussions?
Here are just a few of their views on the hack:
"What if a nation state leverages that type of information? They already have plenty of details on individuals through other breaches. This is a much heavier set of data they can take advantage of. They can potentially be much more targeted in some of their blackmailing"
"You said that this wasn't 23andMe's fault but at the same time, they could have done more. They could have by default had two factor authentication. They could also have had privacy checkups that many other social platforms have available."
"They're mapping the data together to make categorized sets of information available at a cost. So very targeted and can be used for many different extortion capabilities. Who knows what else is going to come of it."
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Live from Las Vegas*, Reimagining Cyber is back.
In this episode Rob and Stan find out how CISOs can battle the cybersecurity challenges in sustainability and transformation projects.
Their guest is Edward Amoroso one of the world’s first ever CISOs. Ed spent over 30 years at AT&T and since retiring in 2016 he has founded TAG Cyber LLC. TAG concentrates on global cybersecurity, artificial intelligence and sustainability, making him the ideal guest for this episode:
“[TAG] pick topics that we think are consequential to the world, things that have existential consequence if we get it wrong. In cyber we spend out whole life worrying about the implications of attacks on critical infrastructure and so on. We've all seen the beginnings of that. AI right now is certainly existential, I hope in a good way. I hope we we find ways to make use of AI to improve our world. There's certainly every reason to believe that we can but there's also a dark side to any innovation. Then on the sustainability front the sort of the clarity that's emerged in the last five years around how important it is to rethink manufacturing, rethink the way we do transportation and more than anything rethink energy. So all of those things come together in topics that are prone to misinformation, topics that businesses are seeing as really important.”
Some other key quotes from the episode:
"We’ve been doing cyber for 30 years, we've learned that if you're doing something consequential or potentially vulnerable, you probably ought to have one or two board members who help to set up the culture and mood and priorities."
"One of the reasons we focus on artificial intelligence is because I think the prospects are spectacular for artificial intelligence as a base for having a really amazing defense, cyber defense that scales."
"We’re dealing with a generation of young people that were raised to think very creatively. We in cyber just haven't learned these lessons and it's urgent."
"Being critical is an act of respect. It’s showing non-respect when we just say, “thank you for doing what you do” without taking a moment and saying, “let’s make this better.”"
"I don't know too many people that are as vocal as me. I get away with it because I'm old. I just say what I'm saying because I want to make it better."
"I'm not a big fan of the big analyst firms, I think most of them just rehash a lot of… I would use a curse word here that describes manure .It's not even data science. "
*Rob and Stan recorded the episode whilst at OpenText World 2023 in Las Vegas.
Follow or subscribe to the show on your preferred podcast platform.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
This week's guest is Dan Fritsche, CISO at RSI Security. He has security and compliance expertise that spans over 20 years. His experience is across multiple industries, but in this episode Rob and Stan explore his experience in the payment security area.
Glossary of terms used in this episode:
PCI SSC – Security Standards Council
PCI DSS - Payment Card Industry Data Security Standard
PA-DSS – Payment Application Data Security Standard
PCI SSF and SSS - Software Security Framework/Secure Software Standard
PCI Secure SLC - Software Life Cycle
PAN – Primary Account Number
SAD – Sensitive Authentication Data
SPoC - Software based PIN entry on COTS
CPoC - Contactless Payments on COTS
CDE - Cardholder Data Environment
Voltage SecureData Payments
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode Rob and Stan look at various cybersecurity risks in the critical infrastructure sectors - and how to mitigate against them It has been inspired by a series of blog posts written by Stan that focus on:
Healthcare and public health
Energy
Financial services
Critical manufacturing
"Some of the threats are common among the different sectors. Certainly these large scale kind of ransomware attacks is impacting healthcare. Bu it's also impacting the manufacturing sector. You know, 13% of all ransomware attacks last year were attributed to those in the manufacturing sector. Because if your production line’s down you're motivated to pay. And ransomware attackers know that."
" think the reality is we can no longer assume that we have a landscape where people will play nice. For example what's going on between Ukraine and Russia, where cyber is being used as one of the elements of war. And if we are in a conflict in the future, our adversary is most likely going to be leveraging cyber and will look for weaknesses in our infrastructure. We've got to change the priority and the voluntary approach doesn't seem to work. So whether it be through carrot or stick we need to motivate each of these operators to raise their game. Because time's running out."
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
“When we test cars no one would ever say that a brake test replaces a safety belt test. That would be silly. But when you get into software, sometimes people go, oh well I ran one tool. Why do I need these other ones?
It's because you're testing different things. Maybe we do a disservice to our people that we work with of not clearly explaining that in understandable ways. You can say ‘Software component analysis’ which makes sense to people in our industry.
But if you're an executive may not make any sense.”
In this episode we hear from Dennis Hurst, the Founder and President of Saltworks Security.
He’s been an application security leader since the earliest days of the industry. With over 30 years of experience across the entire software development lifecycle, he has helped launch startups and traveled the globe to aide multinational enterprises in successfully implementing their application security programs. Dennis is a recognized and trusted advisor for Fortune 500 companies that span multiple industries and concerns.
Dennis is a founding member of the Cloud Security Alliance where he co-authored the first two versions of its Application Security guidelines. He is also a contributor and advocate for the Open Web Application Security Project.
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Rob and Stan dissect the results of a couple of recent surveys to see if they really reflect the feelings of those at the coal face of cybersecurity.
Rob talks about a round table he led that discussed a survey report OpenTech Cybersecurity have produced in conjunction with the Osterman Research group.
The survey spoke to almost 300 CISOs and CIO across the globe to find out what their top cybersecurity investments are for this year.
Listen to find out what they are.
Stan talks about a recent report called the 2023 State of Cloud Security. The survey specifically interviewed AppSec professionals, to discover the main factors influencing tool adoption, as well as key implementation challenges..
Stan points out that some of the key findings concerned DevSecOps, and there was also concern about API security.
Links to the reports/surveys:
CISO Investment Priorities 2023
State of Code Security 2023
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
This episode features “the expert in ChatGPT”, Stephan Jou. He is CTO of Security Analytics at OpenText Cybersecurity.
“The techniques that we are developing are becoming so sophisticated and scalable that it's really become the only viable method to detect increasingly sophisticated and subtle attacks when the data volumes and velocity are so huge. So think about nation state attacks where you have very advanced adversaries that are using uncommon tools that won't be on any sort of blacklist.”
“In the past five years or so, I've become increasingly interested in the ethical and responsible application of AI. Pure AI is kind of like pure math. It's neutral. It doesn't have an angle to it, but applied AI is a different story. So all of a sudden you have to think about the implications of your AI product, the data that you're using, and whether your AI product can be weaponized or misled.”
“You call me the expert in ChatGPT. I sort of both love it and hate it. I love it because people like me are starting to get so much attention and I hate it because it's sort of highlighted some areas of potential risk associated with AI that people are only start now starting to realize.”
“I'm very much looking forward to using technologies that can understand code and code patterns and how code gets assembled together and built into a product in a human-like way to be able to sort of detect software vulnerabilities. That's a fascinating area of development and research that's going on right now in our labs.”
“[on AI poisoning] The good news is, this is very difficult to do in practice. A lot of the papers that we see on AI poisoning, they're much more theoretical than they are practical.”
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode, Rob and Stan look at a couple of drives to impose law and order on cybersecurity.
First the new US National Cybersecurity Strategy for the US.
“I actually see this as being a pretty sharp break from the past. If it's fully implemented, I think the potential to change the US cybersecurity posture will significantly be improved for the better.”
“The strategy does put an emphasis on holding software vendors more directly responsible for the security of their technologies. And it recognizes that if left to its own devices, the software market many times rewards vendors that under invest in security and get things out to market faster. It’s been proven time and time again that market pressures are not necessarily going to result in more secure products.”
“This is going to take time. They're talking about a 10 year window here for the cybersecurity act….so the implementation of this through various administrations who may have different priorities is going to be interesting.”
Rob and Stan also reflect on how the US strategy compares to the the EU Cyber Resilience Act, revealed in September 2022.
“They actually are very focused on personal data and ensuring that there's the protection and confidentiality and integrity of the data of the individuals. There are vulnerability disclosures that are required from the manufacturers.”
"If you are to improve compliance, you're not doing business in the EU. That's the one that really resonates, right? That's what's going to make people say “Well, I have to if I want to be able to generate the type of business I require from the entire EU marketplace.”"
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Reimagining Cyber is celebrating its Golden Jubilee. A half century of episodes has been published since the beginning of the podcast, and in this edition Rob and Stan reflect on some of the key themes that have been discussed.
You will hear from:
Josh Corman
Recently the Chief Strategist for CISA supporting COVID-19 and public health initiatives talks about the pandemic and its impact on cybersecurity.
Bill Hagestad
Cyber Warfare advisor, US Military looks at Iranian cyber strategy and its impact on the cyber space.
Raveed Laeb
Vice President of Product for KELA a cyber intelligence technology company,
gives a behind-the-curtain view of the world of cybercriminals
Parham Eftekhari
Executive Vice President, CISO Community, CyberRisk Alliance reveals the changes he’s seen in the CISO role and how the modern CISO can gain support from business line leaders to executives alike.
Jim Routh
A leader in the Cyber Security space for over two decades, Jim explores unconventional approaches to improve enterprise
Ty Sbano
CISO for Vercel, shares his unique perspective on running the security business in the start-up space
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Did you think the Oscar ceremony was over? Not quite. In this episode of Reimagining Cyber Extra! Stan & Rob are handing out the awards to the best cybersecurity movies ever made. What are they? You'll have to listen to find out, but here are a few clues:
"The first movie I recall that was really focused on cybersecurity & hacking."
"They sort of come upon this capability of decrypting anything and flash forward to our era or maybe 10 years from now when we're potentially able to use quantum computing to be able to crack any of the existing crypto algorithms, maybe it's not that far fetched."
"He hacked into the school computer system. He changes his grades, his attendance records. He's figured out the little loophole on how he can actually have a day for himself"
"There's a sequence of knocking down different parts of the critical infrastructures in the US, and the Feds are running around having no clue as to how to stop or fix this. They're always behind the curve. Which could be realistic unfortunately."
They're embezzling the money back out of the system. So they're “Hey, we're gonna slide under the radar. We're gonna take a little bit of the cash, pull it across and then we're out" But the worm goes out and spreads further, so much money that they now have a bigger issue to deal with."
"The NSA gets involved and there's all these thugs that steal a laptop, et cetera, et cetera. She comes across as somebody who's very resourceful, whether it be on a computer or physically and again there's lots of great action"
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
The guest this week is Dr Ron Ross, Fellow at the National Institute of Standards and Technology. He currently leads the NIST System Security Engineering Project (SSE) The jumping off point for this episode are two of his special publications-
SP 810-160 Volume 1 (updated Nov 22) , ‘Engineering Trustworthy Systems’ which describes a basis for establishing principles, concepts, activities & tasks for engineering trustworthy secure systems.
SP 810-160 Volume 2 – ‘Developing Cyber-Resilient Systems: A Systems Security Engineering Approach’ which focuses on cyber resiliency engineering
Key quotes:
"We live and die by information technology, whether that's a classic I.T. system, whether it's an operational technology like a power plant, SCADA system, part of the power grid, whether it's an I.O.T. device. The common denominator on all of these systems is that they're driven by software and firmware, and a lot of that code is not as trustworthy as it needs to be. So given that that's the deck that we've been dealt, how do we deal with that on a day-to-day basis? And that was really the driving force behind the two volumes of 800-160."
"The more information you have about the susceptibility of your system to these specific threats or vulnerabilities, and you can take those off the table, then that's always a good thing to do. Things like cyber-hygiene, I call it the basic blocking and tackling. And you know, if you can take 80% of the attacks off the table, you don't ever stop the attacks but that then still leaves the other 20%, and that's where cyber resiliency has to step up. But definitely with AI and machine learning our ability to understand threats and what they can do and how we can stop them is going to increase by orders of magnitude. But in complex systems, even that order of magnitude improvement is never going to be enough. And that leads us to the rest of our discussion today."
"We've kind of come to the conclusion that sophisticated adversaries - I'm not talking about the ones that we can stop with cyber hygiene, the 80%, but I'm talking about the 10-20% on the upper end - what happens when they get through your initial lines of defences, which are characterized by penetration resistance? Well now the bad guys are inside the house. Well, what if they came in the front door and then every room in your house there was a vault or a safe? That would be analogous to a security domain for each room in your house. And if you have the ability to add whatever safeguards and countermeasures you think are needed for that particular domain, assuming some of your valuables are more important than others, then you can tailor those controls and those safeguards to the specific criticality of the data or the valuables that you would like to and we're seeing those kinds of approaches now."
"It's not just about one aspect or one safeguard or one strategy. This is a multi-dimensional strategy with lots of different moving parts that are discussed in our cyber resiliency guideline, and are actually executed in a good engineering process that gives consumers a lot better hope of being able to operate those systems under attack and having a system that they have a confidence that they can recover and restore that system, even if it's in a degraded, debilitated state, they can get back to some sense of normal operations and not have the entire business or mission go under. "
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Woe betide the corporate board who doesn't take cyber security threats seriously.
The 2022 Security and Exchange Commission's cyber security proposals are expected to kick in the next few weeks. However, are the boardrooms ready? Worryingly, some reports suggest that the majority should be having last minute panic attacks.
In this edition of Reimagining Cyber Extra, Rob Aragao and Stan will be addressing discussing what corporate boards and CISOs need to be doing
Some key quotes:
"There's this vernacular that gets thrown around from a technology perspective that doesn't always jive to what the business or a board member for that matter is understanding"
"The rule is designed to compel boards that haven't been taking cybersecurity seriously to do so. But I do think it's also created some trepidation or some concern between the board of directors and those that are in the front lines, the CISOs or the directors of information security. I think it puts some tension on those relationships. And some uncertainties as far as who's going to actually do that reporting effectively"
"The role of the CISO is going to change even further than what we've seen. As an example, the CISO reports to the CIO in some cases, and in other cases it reports to other parts of the business. This is going to push it really, I would think, for most organizations to completely rethink where the CISO reporting structure is."
"I hope [it brings] a greater understanding on the stresses and the pressures on the CISO and the information security organization and what they have to deal with every day. Hopefully the board will give them the resources they need. I'm not saying that they aren't funding security. Many times they are, but they need to take the actions to help build in that resilience into the organization. And hopefully they get enough awareness of the topic area and the understanding of the vocabulary to be able to have true conversations about where to best fill in those gaps."
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
‘We have to counterbalance that cliche view that working in cyber means you are in your hoodie in the basement”
There’s something about being in demand that makes you feel warm inside. So, if you are in cybersecurity, you should have something of a spring in your step. As anyone in the industry knows, the cybersecurity talent gap in the US is growing. For example, the latest data available on the CyberSeek website shows that in the public sector alone there were over 45,000 online job listings for cybersecurity-related positions between January and December 2022
So, what is to be done? In this episode of Reimagining Cyber Rob and Stan look at one of the ways the U.S. government is dealing with the issue. The National Science Foundation's CyberCorps Scholarship for Service Program is “unique program designed to recruit and train the next generation of information technology professionals, industrial control system security professionals, and security managers to meet the needs of the cybersecurity mission for Federal, State, local, and tribal governments.”
Rob and Stan talk to Dr Victor Piotrowski, the lead programme director about the ins and outs of the program, its growing success, and the hurdles the program has overcome and still faces.
Links:
CyberCorps Scholarship for Service
sfs.opm.gov/
CyberSeek data:
www.cyberseek.org/heatmap.html
2021 SFS Biennial Report:
2021 SFS Biennial Report (nsf.gov)
How to get the federal government to pay for your cybersecurity degree:
How to get the federal government to pay for your cybersecurity degree | Fortune
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
It’s been a mixed few weeks if you are in the ransomware game. (If you listen to this podcast we presume you are not a cybercriminal, but do get in touch if you are and leave us your full contact details).
In this episode Rob and Stan look at the hacks that have made the headlines and suggest what can be done to stop it happening to you.
First up for discussion is ransomware-as-a-service malware LockBit hitting ION Trading UK:
“It left scores of brokers unable to process derivative trades and they had to resort to manual methods. Imagine them going back to using spreadsheets to figure out what's going on as far as their trades”
LockBit threatened to publish stolen data unless a ransom was paid and ION Trading did as they were told. Rob and Stan talk about the incident and the potential repercussions.
The episode also looks at a ransomware campaign targeting VMware ESXi technology:
“It's a previously known vulnerability. It's been out there for two years. But the reality is that organizations have been slow in patching it. There was a general warning put out by Italy's National Cybersecurity Agency, warning about a large-scale campaign now exploiting this vulnerability. Thousands of computer servers across Europe and North America could potentially be impacted. And this context is, well if you're not going to patch, we'll take a advantage of that”
But there's also been bad news for the threat actors.
Rob and Stan give their take on the sabotaging of the Hive ransomware group by the FBI and other law enforcement agencies.
“This take down shows that international enforcement against ransomware threat actors is increasing. I think this is a good sign. It may make it more difficult for some of these entities to target organizations in the future, but, they're still ongoing and so it's going to be difficult to truly mitigate this threat if you can't reach those that are behind it.”
There are call backs to other relevant episodes of the Reimagining Cyber podcast:
Episode 12, Brett Thorson, Colonial Pipeline fuels the fire: not the first, not the last, and how to protect for the future
www.buzzsprout.com/2004238/10791017
Episode 2, Jim Routh, Unconventional approaches to improve enterprise resilience
www.buzzsprout.com/2004238/10791027
Episode 27, Shawn Tuma Cyber insurance in the wake of Log4j
www.buzzsprout.com/2004238/10791001
Episode 15, Shawn Tuma – So you’ve been hacked, now what?
www.buzzsprout.com/2004238/10791014
Plus the Galaxy threat actors report
https://publications.cyberres.com/view/679673707/
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
Valentine’s Day is (almost) upon us, and Stan and Rob are marking this celebration of love by looking at online dating scams. Romantic, yes?!
Their guest is Dan Winchester, co-founder of Scamalytics. Scamalytics has a focus on helping dating sites automatically remove scammers from their sites in real-time.
Talking points:
How scammers affect a dating sites business model
“Most dating services are trying to move as many of their users as possible over to a subscription. You’re not going to pay a subscription when the product you're subscribing to looks like it's just full of junk and scammers”
On collecting data to prevent fraud
“There's a tension between privacy and safety. Users want to feel safe, but they also want to make sure that their privacy is respected. So you need to really be figuring out what's the minimum amount of data you can use in order to prevent the maximum amount of fraud.”
Relationships with service providers
“We often have quite a tricky relationship with the service providers themselves because they may not be taking as much action as we would like when fraud happens on their networks. And you know, some of these companies are obviously massive and it's quite hard to get them to really deal with these issues.”
On AI/machine learning
“We do a lot of machine learning stuff within Scamalytics, but I would always add a cautionary note that we find that the domain knowledge is way, way more useful than machine learning because when you're dealing with fraud, you've really got to be attuned to false positives and it's so easy for machine learning systems to get into false positive feedback loops and things like that.”
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this week's episode of the Reimagining Cyber podcast, we are after your help....
That's because hosts Rob and Stan taking a week off. They are busy recording episodes with some more great guests and of course exploring the cybersecurity world with their eyes wide open and their ears to the ground.
For example, next weeks episode is going to be a Valentines Day special, looking at dating app scams.
So, there are couple of things we'd like you to do whilst you have a moment.
If you listen via Apple Podcasts app, go to the Reimagining Cyber show page, scroll down, and you will see you have the option to write a review and rate the show.
It's great to get your feedback and it helps other cybersecurity fans find the show.
And finally, Reimagining Cyber has now built up quite a library of episodes, so why not go back and take a listen to them? There's about 50 episodes for you to binge on. Invite your friends over, have a Reimagining Cyber listening party and let us know how it went.
Rate and review the show on Apple Podcasts.
Share the show with others in the cybersecurity world.
Get in touch via reimaginingcyber@gmail.com
In this episode Rob talks about a recent event discussing the State of Cyber into 2023 Hosted by Dave DeWalt (founder & MD of NightDragon, one of the most successful business leaders in the cybersecurity industry) the event promised to take "a unique look at what products are really being adopted by cybersecurity buyers, what financial analysts are watching around skyrocketing valuations and what investors are watching for the next frontier of innovation. We’ll also look at the state of the cyber talent gap, public-private partnership efforts and how CISOs are responding to the latest threats."
Rob reacts to the thoughts of organisations such as EY, Kyndryl, Citi, Piper Sandler, AllegisCyber Capital, Team8, ForgePoint.
"What I took away as an extreme positive is the consistency of the CISOs on the panel, talking about how the shift in their approach and model is very much centered around how they're actually aligning with what the business needs from the cyber organization"
[Regarding the Wall Street perspective] "2023 could be the biggest opportunity for investing in the cyber market because of what those returns are going to look like going forward, because the reality of the business delivering on what they market has to come to fruition."
"The event and the timing of the event was very effective. The format of the event and the audience and the different segments and perspectives, I thought was a really nice balance."
“I think with any metric, the FedRAMP program has been viewed as...."
Listen to this edition of Reimagining Cyber EXTRA and find out what Rob and Stan think about FedRAMP.
Firstly, what is it?!
“[FedRAMP’s] whole purpose is to provide a standardized government-wide approach to security assessment, authorization, and continuing monitoring of cloud products and services used by the federal government agencies.”
Plus:
- FedRAMPs codification into law via the National Defense Authorization Act (NDAA)
- Action to making the process easier for vendors and agencies.
- Establishment of the Federal Secure Cloud Advisory Committee – what is it, what’s it for?
- Why does the NDAA not make vendors provide a SBOM? Will this change?
“The crystal ball is if you are a software supplier to the government, you have to be prepared in the future to be able to provide this kind of inventory of components that make up your software build. It's important to be able to react quickly to zero-days, to be able to understand what your software consists of to be able to mitigate open source security issues and risks”
“Everything that we're talking about in cyber always somehow turns itself back around to the software. The software supply chain is the common theme that we heard through last year. It's not going to slow down this year.”
"We got very good at testing things to failure"
Virginia “Ginger” Wright is the Energy Cybersecurity Portfolio Manager for Idaho National Laboratory’s Cybercore division within its National and Homeland Security directorate. She leads programs focused on cybersecurity and resilience of critical infrastructure for the Department of Energy, DARPA [Defense Advanced Research Projects Agency] and other government agencies.
Her recent research areas include cyber supply chain for operational technology components, instant response, critical infrastructure modeling and simulation and nuclear cybersecurity.
Some quotes from this episode:
"Idaho National Laboratory is the only national laboratory that is focused on nuclear energy. Part of that legacy was in testing what are today normal commercial nuclear installations and understanding where the boundaries of either operational resilience were, or the boundaries of particular material and installation methods that would cause that infrastructure to fail. We have, of course, taken that ability to turn things into failure and use that to develop our own adversary guided thinking about defensive cybersecurity."
"In the energy infrastructure, we have devices that are in regular use today that are decades old. In the IT world, I have Patch Tuesday where every week my critical infrastructure is updated. Then after about three years. I toss it and I get another one that is completely and wholly built on the more modern incarnation of technology. When we think about operational technology, applications, energy or water, we certainly can't re-engineer those systems on that cycle of replacement. So often we may not be able to patch or the technology that we are using is so old that the vendor is now no longer supporting patches."
"I think a lot of engineers understand materials that they build with. They understand wood, concrete, but they don't often get taught to think about digital systems in the same way they think about materials - that these systems have stress points and failure points and they can be trusted to a certain level but after that we need to build protections into our system to protect us from the ways that they can fail or be brought to failure by an adversary"
As usual, Stan's been rubbing shoulders with the top names in cyber security...
In this episode we hear about his participation in the Government Innovation Show - 'Transforming Government Through Technology-Driven Initiatives'
Rob and Stan react to talks given by:
- James Burd, Chief Privacy Officer for the Cybersecurity and Infrastructure Security Agency
- Dr Diana Janosek, Deputy Director of Compliance at the National Security Agency
PLUS:
- Recession, what recession? With cybersecurity budgets expected to rise in 2023, Rob and Stan give their thoughts on why.
- Have you heard of Youtube? Apparently it's quite popular. Reimagining Cyber is the latest convert, and the show can be found here:
www.youtube.com/@CyberRes
www.youtube.com/watch?v=PoVifXTIM…Ndcdjin-l2qxkAIwZ
"The major issue that we typically have is on The Hill. For years, we've seen bills coming out, which specified a direction of left or right or up the middle, and nothing happens. That leads a lot of us sceptics to believe that people on The Hill who are being funded by the largest tech companies don't move because it's not financially viable for their future campaigns. Our cyber life cannot be attached to the whims of politics. "
Rob and Stan are taking a well earned festive break, they'll be back in the new year.
So we've decided to do some Christmas re-gifting and dust down a terrific episode from a couple of years ago.
It features Michael Echols, CEO of MAX Cybersecurity, LLC and author of 'Secure Cyber Life: The Government Is Not Coming To Save You'
As you will hear, Michael is passionate about his subject and has conclusions that you could find rather disturbing.
In other words, perfect for a podcast episode.
Do share the reimagining cyber podcast with those who you think will find it useful, and if you use apple leave us a review. It really helps spread the word.
We'll be back in 2023 with more great guests.
“The medical field is rife for threat actors trying to take advantage of things, much like when it's tax time and you hear the latest IRS scam. That goes on a lot within the medical field. There are threat actors that impersonate DEA agents and try to gain access to everything from DEA numbers to prescription pads. Visiting the FBI website, they have a page dedicated to different scams out there and there's a couple that live persistently in healthcare that we make that we make sure our clinician side is aware of.”
In this episode, Rob and Stan talk to Louis Lerman, VP and CISO of Pediatrix Medical Group. Lewis has an extensive information security background. In addition to healthcare, Louis has supported government, defence, education, software development , financial sectors. In fact, prior to Pediatrix Medical Group, he served as the CISO of the Deloitte Consulting Group and also as Information Security Officer at the International Monetary Fund.
In this EXTRA! episode Rob and Stan talk about:
- Secret Service reports of Chinese hackers stealing tens of millions of dollars worth of U.S. COVID relief benefits since 2020.
- Microsoft's help for Ukraine
- What the latest data breach means for LastPass' business.
- Data breach at WhatsApp
On this week’s episode of Reimagining Cyber about launching the OWASP Verification Standard (OVS), Stan Wisseman and Rob Aragao talk with Tom Brennan, CIO for Mandelbaum Barrett law firm and North America Executive Director for CREST. The three of them talk about the history of CREST, the new OWASP Verification Standard (OVS), and its connection with the OWASP Application Security Verification Standard (ASVS).
CREST was established in 2006 as an international non-profit organization that represents the global cyber security industry. The organization’s goal is to help create a secure digital world for all by quality assuring its members and delivering professional certifications to the cyber security industry through a rigorous quality assurance process so others can have confidence in the cyber security services they consume. CREST Americas offers programs across six cyber security communities, which include: government, regulators, buying community, service suppliers, training and academia, and professional bodies.
Recently, CREST collaborated with the Open Web Application Security Project, better known as OWASP, to launch the OWASP Verification Standard (OVS). OVS is a new quality assurance standard for the global AppSec industry. It is designed to provide mobile and web app developers with superior security assurance and accredited organizations with improved access to the expanding application development industry. Brennan gave an overview of OVS’s ability to execute and deliver assessments related to the different levels of the OWASP Application Security Verification Standard (ASVS). ASVS provides a source for testing web application technical controls and provide developers a list of secure development requirements. Its aim is to normalize the variety of coverage and level of rigor accessible in the market to verify web application security by using a commercially workable open standard. By including ASVS, CREST was able to support the open-source community to build and support global standards.
Brennan believes that OVS is useful to many organizations, as long as they meet the qualifications needed. It gives you the opportunity to conduct assessments against existing codebases and determine where issues may exist before the buyer gets involved in code quality issues or licensing problems. Brennan also goes to say that “OVS allows not only the Americas, but for organizations around the world [to] demonstrate taking something that is a global, acceptable best practice by the OWASP individuals and experts… [so it] can be utilized in a commercial way very easily and quite honestly very accepted.” OVS is providing a global standard of expectations for consumers of software.
Over the past couple of years Reimagining Cyber has featured guests with lots of interesting perspectives and opinions, but it seems that our info hungry audience wants even more.
Hosts Rob Aragao and Stan Wisseman have been asked to share news of their own interactions and experiences, and who are they to say no?
So, in the first ever ‘Reimagining Cyber Extra!’ Rob and Stan bow to listener demand and address the following:
The unconventional way to build a cyber talent pipeline - featuring Jim Routh and Damon Carter
On this week’s episode of Reimagining Cyber, hosts Stan Wisseman and Rob Aragao welcomed guest Dan Lorenc, founder and CEO of Chainguard Inc., to talk about SLSA, software supply chain security risks, and his opinions on Software Bill of Materials (SBOMs).
Raveed Laeb, Vice President of Product for KELA (pronounced Kay-la), a cyber intelligence technology company, gives us a behind-the-curtain view of the world of cybercriminals in the latest Reimagining Cyber episode, “Inside cybercrime with Raveed Laeb.”
Dan Bowden, CISO at Marsh, gives us an under-the-hood view of how insurance companies mitigate cyber risk, thinks they look for, and how they support their clients, in this week’s Reimagining Cyber episode, “Under the hood of cyber insurance"
Taylor Hersom, CEO, and co-founder of Eden Data, an organization that provides startups and next-gen organizations with virtual CISO support and other services, shares his insights over the past two years in the start-up space.
Ty Sbano, CISO for Vercel, shares his unique perspective on running the security business in the start-up space, from how to approach the interview process, how to gain trust early, and how to remain focused on the right priorities.
John Keane, Software Angel of Death, discusses securing the supply chain, the important of contract language, and shares his unique perspective on the cyber space on the latest episode of Reimagining Cyber, “A discussion with the Software Angel of Death, John Keane.”
Chris Abramson, Senior Director of Cloud Security Engineering at Walgreens, and 20-year IT industry veteran shares what he learned from shifting from on-prem to Microsoft’s Azure Cloud on this week’s Reimagining Cyber episode, “Journey to securing the Cloud.”Abramson recommends adapting your strategy to your new environment. In on-prem, it’s all about firewalls and technology that’s wrapped around an environment, but in the Cloud, it’s how things communicate with each other, he cautions. By changing your thought process about how to work in this new environment, you’ll be able to better secure it.When changing IT infrastructures, security can get lost in the shuffle. To mitigate this, Abramson worked in lockstep with his Cloud Center of Excellence (COE), building security directly into the deployment model.“So, as our teams, whether it be an infrastructure team or even an application team, go to do that deployment, they're hitting the gates of security,” he says. “Not at the end, not after everything's deployed.”Security issues aren’t being discovered after the fact. Teams hit them as they come upon them, enabling them to make changes on the fly and deploy the appropriate fixes with the least amount of security risk in the environment.By checking out industry forums and CVE data on vulnerabilities in the Cloud that have been made public, learning from peers that have already been through it is key. This enables companies to bake the correct actions into the new Cloud environment.Abramson recommends working in lockstep with other teams, for example, deployment teams and security, to prevent any issues and enable reacting quickly when something happens.“This is one that fundamentally, really takes a lot of interaction between development teams and the security teams [to] make sure that they're thinking about what the impact is going to be if they pull from some rogue repository or just, you know, off the internet and things like that,” Abramson says.As the Cloud space evolves, so will the software development, deployment, and security space to adapt to the ever-changing Cloud environment.Many companies purchase software from a third party, embed it into their software, which gets embedded into yet another software. Enter the Russian Doll Syndrome.“[You’ve] got to think about software that you're buying from a third party. That now also embedded software from another third party, that likely embeds software from another third party. That's the Russian Doll Syndrome.”Abramson recommends considering how you’re connecting and the level of software integration to determine the level of risk. He also recommends implementing a strong vendor management program.“Talking with your partners, understanding their security practices, what they're doing, and how they're managing their code, their releases, their ingest of those same platforms, or same libraries, or same third-party integrations as well, too, [is helpful],” he says.Encrypting data offers its own challenges and isn’t always possible, but where it can be done, Abramson wholeheartedly recommends doing it.“Wrapping environments in a model that doesn't allow access to, or very limited access to, it's kind of, I'll call it the vaulted environment, you know, the no ability to touch, change, maneuver through or ingress or egress without somebody watching you do it. That stuff, it's expensive, and it's highly operational because there's a lot of eyeballs having to do that.”Encryption is the quickest and easiest way to protect your data, Abramson says. Abramson recommends partnering closely with the business and IT sides of the house to determine the best way to protect sensitive workloads shifting to the cloud and mitigating data exposure and privacy compliance risks. Sometimes, encryption just isn’t an option. In these cases, Abramson recommends bringing your own encryption keys and avoid reliance on key services provided by Cloud Service Providers (CSPs).
Jim Reavis, co-founder and CEO of the Cloud Security Alliance (CSA) and a noted leader within the cloud computing community, sheds light on how to solve for cloud security complexities in this week’s Reimagining Cyber episode, “Solving the cloud security puzzle.
Bob Almond is the Chief Operating Officer of Full Armor Corporation, a software development firm he co-founded. Bob has watched the industry evolve from single machines to internal networks, to the present, where people work from anywhere, whenever they want to work and needing to have access to the resources, they need to get their jobs done. Bob has had a focus on helping IT Admins rein in the complexities of AD group policies and enable admins to really focus on security and protecting their organization from the inside out. This is more important than ever as IT Admins deal with policies in Linux and Unix devices, Apple Mac, MDM for mobile devices, and Windows devices that are in the wild and aren’t joined to the AD domain
Kristen Bell, Senior Manager of Application Security Engineering at GuidePoint Security, is back, sharing her insights into “Building better AppSec teams: Communication, collaboration, and culture.” Two weeks ago, Bell joined the Reimagining Cyber team, Rob Aragao and Stan Wisseman, to share her perspective on “Governing a better AppSec program by empowering dev teams.”
Collaboration is Key To build a better AppSec team, Bell explains the importance of collaboration. Many developers have a bad taste in their mouths when it comes to automation. Developing a multi-phased approach where you can share each step and mitigate any barriers to adoption (for example, many developers don’t like a lot of “noise” or false positives), can be helpful. When it comes to the actual scanning itself, Bell recommends doing a lot of work on the front end to make it run as smoothly as possible, ensuring the highest-quality results for ease of use. Additionally, she recommends integrating a ticketing system like JIRA to provide a continuous feedback loop. This way, you can pull metrics to show return on investment. Lastly, Bell recommends getting buy-in from application developers and owners. With skin in the game and a seat at the table, they’ll have influence and investment in the security program’s direction.
Communicate, communicate, communicate Creating a streamlined and organized communications approach when building out your AppSec team is crucial. It is critical to have one centralized location to house all information for your security team, whether it’s standards or blueprints. “It's super important that if you're building a portal, or a Wiki, or this one-stop-shop, for the developers, to have these self-service options, they need to know it exists,” Bell says. Reiterating it in multiple ways (an All Hands call, a newsletter, an e-mail) is critical. You have to remind people 13 times before they’ll remember something.
Get out into the community There's OWASP, ISACA, (ISC)2, ISSA and lots of different kinds of AppSec and cybersecurity related organizationsthat team members can go and be active in in their local communities. I would also encourage people on the security team, if you go to a conference, invited the good AppSec-related speakers in to speak to the team or the developers. They usually are looking for opportunities to engage and are open to do it.
AppSec in the Cloud Building a Cloud-centric AppSec team has its challenges. Bell recommends: • Separation of duties: Developers don’t typically have access to production and don’t make changes in production. However, when it comes to the Cloud, that all changes. By creating different profiles and having people commit to certain tasks allows teams to divide and conquer. • Threat modeling: Bell recommends running threat models, testing different scenarios and looking at data flows and trust boundaries to help document repeatable processes and confirming adherence to compliance requirements (like geolocation of data). • Testing automation: DAST services allow you to now test GUI-less technologies to understand
Have you tried any of these tips when building out your AppSec team? Do you have any to add to Bell’s suggestions? Let us know in the comments.
Josh Corman, co-founder of the rugged software, and “I am the Cavalry” movements, and most recently Chief Strategist for CISA supporting COVID-19 and public health initiatives explains and shares the importance of movements like rugged software and “I am The Cavalry" in the cybersecurity space.
While organizations need to gain visibility into application security risks, it can be challenging to build and mature an effective application security program. In this episode of Reimagining Cyber, Kristen Bell, a Senior Manager of Application Security Engineering at GuidePoint Security, shares some the best practices that she’s used to help organizations overcome common obstacles to success. Bell uses a collaborative approach between AppSec team and developers that can create a positive security-aware development culture.
Jeff Brown, CISO for the State of Connecticut, discusses how the State of Connecticut is flipping the script and driving digital transformation at the state-level through communications in the latest Reimagining Cyber episode, “Digital Government - How the State of Connecticut has driven digital.”
Data privacy isn’t just about keeping sensitive information private. It’s about understanding what data you have (whether it’s structured or unstructured), where it is, and any risk associated with it. How do you decide what to keep? Or what’s important? It’s complicated, and the process of figuring it out can be daunting. In this episode of Reimagining Cyber Greg Anderson, Vice President and Chief Privacy Officer for E.W. Scripps Company, tackles this conundrum and also sheds light on the shift of data privacy from data governance to driving business outcomes.
Shawn Tuma, Cybersecurity and Data Privacy Attorney at Spencer Fane, LLP, shares his unique insights into the cyber insurance space on this week’s Reimagining Cyber podcast episode, “Cyber insurance in the wake of Log4j.” Tuma reflects on the recent industry changes he has witnessed firsthand and shares his insights into best practices for organizations looking for cyber insurance.
Steve Springett, who leads software security for ServiceNow in their product security team, is an open-source software (OSS) advocate and is also passionate about helping organizations reduce OSS associated risk. In this podcast episode Springett explains the Log4j vulnerabilities and their potential exploit. He also shares the process enterprises need to take to respond to OSS incidents and how some of the OWASP projects he is involved in can be used to mitigate OSS and software supply chain risks. Links to the resources we discuss are below:
OWASP Dependency-Track project: https://dependencytrack.org/
OWASP CycloneDX: https://owasp.org/www-project-cyclonedx/
OWASP Software Component Verification Standard (SCVS): https://owasp.org/www-project-software-component-verification-standard/
Vulnerability Exploitability eXchange (VEX): https://blog.adolus.com/what-is-vex-and-what-does-it-have-to-do-with-sboms
Sara Anstey, Data Analytics Manager at Novacoast, knows a thing or two about data and how it can drive business decisions and optimize business results. She’s spent years honing her craft, helping organizations understand risk by leveraging data and dashboards. In this week’s Reimagining Cyber episode, “Data Analytics in Cyber: Work Smarter, Not Harder,” Anstey shares her analytics expertise and how it can help shape an organization’s business and cyber model.
Gary Phillips, Vice President of Customer Identity Access Management (CIAM) with E-trade, now part of Morgan Stanley, shares his expertise in the IAM and CIAM space, how it has evolved, and why it matters, in the latest Reimagining Cyber Episode, “IAM, CIAM, and ZTA: The trifecta of access management.”
Brett Harris, Product and Solution Security Officer with Siemens Healthineers, brings a different perspective to cyber, from his career path to how he has changed the culture within Siemens. “New perspectives in cyber” dives into how Harris has leveraged his unique skill set to build out the Siemens Healthineers team and changed the culture to put product security first.
The Internet of Things (IoT) refers to the physical devices around the world, collecting and sharing data, via the internet. For example, things like cell phones, a lightbulb that’s turned on via a cell phone app, or even a Nest thermostat in your home. What was once isolated is now exponentially bigger and better connected. This has also greatly increased the attack surface which correlates to ransomware becoming a $6 trillion industry. This week’s Reimagining Cyber podcast episode, “IoT, not just alphabet soup,” with guest Kate Scarcella, Chief Security Architect with CyberRes, goes into a deep-dive into IoT, the ramifications of the field’s exponential growth, why securing it is critical, and how OT is different.
Lisa Plaggemier, the Interim Executive Director at the National Cyber Security Alliance, joins co-hosts Rob Aragao and Stan Wisseman, in this week’s “Reimagining Cyber” podcast episode, “Cyber – how to get people to care.”
Marian Merritt, Deputy Director for the National Initiative for Cybersecurity Education (NICE) at the National Institute of Standards and Technology (NIST), addresses the talent shortage gap, explores the root causes, and suggests how to close the gap in this week’s episode of Reimagining Cyber “Closing the cyber workforce gap.”
Arvind Seshadri, Senior Director of Security at Cognizant, shares the latest on how our ‘new normal’ post-pandemic life translates into work from home and the security industry in the recent “Reimagining Cyber” episode, “The New Normal in a Post-Pandemic World.” Seshadri’s 20+ years of experience of work with global organizations to drive security strategy, and particularly, his current role at Cognizant where he leads the service strategy offerings and partnerships give him a unique perspective on the subject.
Nick Ward, CISO for the Department of Justice with the U.S. Government and recent Cybersecurity Leader of the Year award winner, shares his views on the Executive Order and the key ways to make the changes outlined in the EO.
Parham Eftekhari discusses the changes he’s seen in the CISO role and how the modern CISO can gain support from business line leaders to executives alike.
Establishing a cybersecurity program is hard, and Bryan Galloway, Director of Information Security with Enphase Energy, has taken on the challenge twice from two different perspectives. The green sector is wrestling with a fast-moving market while determining how to best secure IoT devices and interface with the grid. Listen for more about how Bryan is taking on these challenges.
Shawn Tuma, Cybersecurity and Data Privacy Attorney and Partner at Spencer Fane, LLP, shares his experiences and best practices about what to do once you’ve been breached. Tuma’s decades-long career has focused on the litigation of cyber and privacy issues, proactive risk management, and incident response.
Ikjot Saini, Assistant Professor at the University of Windsor in Windsor, Ontario and connected and autonomous vehicle cybersecurity expert joins Rob Aragao and Stan Wisseman in this week’s Reimagining Cyber episode, “Connected Vehicles and the Cyber Equivalent of Seatbelts and Airbags“ to speak about the cybersecurity intricacies of autonomous cars, the importance of standards and regulations, working as a team, and thinking outside the box when it comes to automotive security.
Michael Echols, CEO of MAX Cybersecurity, LLC and author of "Secure Cyber Life: The Government Is Not Coming To Save You," does a deep dive into the importance of industry standards, cyber threat information sharing (ISO), and as we move to a more digitized society, how critical it is to educate the masses.
Brett Thorson, Principal at Platinion, the cybersecurity arm of Boston Consulting Group (BCG) goes into a deep dive of the recent Colonial Pipeline hack and how to prepare for future attacks.
Internationally recognized expert on nation state cyber threat actors, and author of “Chinese Cyber Crime: China’s Hacking Underworld,” “21st Century Chinese Cyber Warfare,” and “Red Dragon Rising,” Bill Hagestad, speaks about Iranian cyber strategy and its impact on the cyber space.
Marco Pineda, former Head of Cyber Technology and Innovation at the World Economic Forum discusses how to think creatively to drive innovation in an ever-changing cybersecurity landscape.
Lori Sussman, Assistant Professor in the Department of Technology at the University of Southern Maine, Phyllis Woodruff, Vice President, IT Risk and Compliance at Global Payments, Inc., and Tammy Schuring, Vice President and Global Leader, Voltage Data Privacy and Protection, at Micro Focus, discusses the challenges women in tech face, how to overcome them, and how to own your superpowers.
Jeremy Epstein, Lead Program Officer with the National Science Foundation (NSF), shares the importance of sociotechnics and sociotechnical research and how it can be used to improve one’s cybersecurity landscape.
In this week’s Reimagining Cyber podcast, we hear from Bob Guay, CISO at Momenta Pharmaceuticals, who discusses the importance of being cyber-savvy, having skin in the game, and getting buy-in from non-technical people in your organization.
In this week’s Reimagining Cyber podcast, we hear from BCG Platinion Managing Director, Nadya Bartol, who shares some wise tips on measurement best practices and how to keep your cybersecurity game strong.
In this week’s Reimagining Cyber podcast, Ron Ross, Computer Scientist and a fellow of NIST is back! In this episode, he expands on his previous discussion about strengthening cybersecurity
With guest John Pescatore, Director of Emerging Technology at SANS in Washington, D.C.. Pescatore speaks with Rob Aragao and Stan Wisseman about the recent SolarWinds security breach, how to mitigate against attacks, and three key tenants of a cybersecurity program: people, process and technology.
With guest Ron Ross, Computer Scientist and Fellow at the National Institute of Standards and Technology (NIST). Ron, Stan and Rob discuss the four goals of a strong cyber strategy.
Join us for episode #2 of Reimagining Cyber, where we hear from Jim Routh, Head of Enterprise Cybersecurity at MassMutual. As a leader in the Cyber Security space for over two decades, Jim has experienced it all, from facing the Office of the Comptroller of the Currency (OCC) on his second day in his first CISO role to shifting executive mentality around risk profiles and cyber-attacks
This podcast is brought to you by Micro Focus where our mission is to deliver cyber resilience by engaging people, process and technology to protect, detect and evolve.
Join us for the inaugural episode of ReimaginingCyber, hosted by Chief Technology Strategist’s Stan Wisseman and Rob Aragao. In this episode, hear from John Delk, General Manager of Micro Focus’s Security business, as he discusses cyber resiliency, industry trends, and the impact of COVID-19 on the Security field.
This podcast is brought to you by Micro Focus where our mission is to deliver cyber resilience by engaging people, process and technology to protect, detect and evolve.