This Security Control Is So Good We Don’t Even Have to Turn It On (LIVE in Clearwater, FL)
Apr 1, 2025
auto_awesome
Christina Shannon, CIO of KIK Consumer Products, and Jim Bowie, CISO of Tampa General Hospital, discuss vital cybersecurity strategies. They highlight the need for continuous security awareness training over traditional compliance sessions. The duo explores the balance between high-pressure environments and team well-being. As they dissect the vulnerabilities of weak passwords versus phishing, they also share humorous incidents from training, emphasizing a collaborative and engaging approach to fostering a strong security culture.
Ongoing security awareness training is essential for creating a robust cybersecurity environment, necessitating long-term, adaptive training strategies tailored to high-risk areas.
The emergence of deep fakes accentuates the need for innovative security measures, including verbal passwords and enhanced multi-factor authentication to ensure identity verification.
Deep dives
Introduction of a New Show
A new initiative titled 'Security You Should Know' is launched, focusing on providing clear and straightforward insights about cybersecurity solutions directly from vendors. This show aims to cut through the marketing noise and deliver practical information that CISOs and security professionals genuinely need. The format involves interviews with security vendors where two CISOs ask targeted questions about their products, facilitating a more personalized approach to solution discovery. This aims to emulate the idea of 'phoning a friend' for reliable guidance in the competitive cybersecurity landscape.
Continuous Security Awareness Training
Ongoing security awareness training is emphasized as crucial for maintaining a secure environment, rather than relying solely on annual compliance sessions. Experts recommend developing a long-term training plan that focuses on various themes and targeted exercises tailored to high-risk areas within the organization. This continuous learning approach ensures that employees remain vigilant against evolving security threats, reinforcing the importance of adaptive training programs. Engaging training methods, including practical scenarios relevant to both home and workplace environments, help instill lasting positive habits in employees.
Addressing Stress in Cybersecurity Roles
Cybersecurity roles are recognized as high-stress positions, with many professionals contemplating leaving due to job pressure. Reports indicate that a significant percentage of security staff express concerns about stress and burnout, highlighting the need for better support and management strategies. Solutions include empowering employees through individualized project assignments and training opportunities, fostering a sense of ownership over their work. This approach not only combats burnout but also increases engagement, demonstrating that investing in employees' growth can lead to greater retention.
Best Practices Against Deep Fakes
The emergence of deep fakes is identified as a pressing concern in cybersecurity, necessitating new protective measures. One proposed method is implementing verbal passwords for verification during sensitive communications, ensuring authenticity even amid sophisticated impersonation attempts. Organizations are encouraged to enhance their multi-factor authentication strategies and raise awareness about the risks associated with deep fakes. Automation tools that verify identities through facial recognition and document checks can also play a critical role in maintaining security against these emerging threats.
HUGE thanks to our sponsors, Proofpoint, Cofense, & KnowBe4
With an integrated suite of cloud-based cybersecurity and compliance solutions, Proofpoint helps organizations around the world stop targeted threats, safeguard their data, and make their users more resilient against cyber attacks. Discover cutting-edge security insights and industry trends from leading experts at Proofpoint Power Series—a monthly virtual event designed to empower the security community. Learn more at proofpoint.com
Powered by 35 million trained employee reporters, the exclusive Cofense® PhishMe® Email Security Awareness Training with Risk Validation and Phishing Threat Detection and Response Platforms combine robust training with advanced tools for phishing identification and remediation. Together, our solutions empower organizations to identify, combat, and eliminate phishing threats in real-time. Learn more at cofense.com
KnowBe4's PhishER Plus is a lightweight SOAR platform that streamlines threat response for high-volume, potentially malicious emails reported by users. It automatically prioritizes messages, helping InfoSec and Security Operations teams quickly address the most critical threats, reducing inbox clutter and enhancing overall security efficiency. Learn more at knowbe4.com
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode