DtSR Episode 642 - Chase Cunningham An Epic Zero Trust Keynote
Feb 25, 2025
auto_awesome
In this engaging discussion featuring Chase Cunningham, a retired Navy chief and cryptologist with a wealth of experience from the NSA, he dismantles outdated security dogmas. Topics include the pressing need for basic security practices amidst complex tech environments and how organizations can effectively implement a zero trust model. Cunningham emphasizes the importance of asset visibility and a red team approach to combat cybersecurity challenges. His insights reveal the necessity of strong leadership and clarity in navigating today's security landscape.
The podcast emphasizes the need for organizations to return to foundational cybersecurity practices like asset management and patching to improve security.
Chase Cunningham discusses the necessity of implementing a zero trust strategy to effectively manage evolving cybersecurity threats and third-party risks.
Deep dives
The Grand Delusion of Cybersecurity Practices
The discussion centers around the concept of a 'grand delusion' within the cybersecurity industry, where despite being driven by data and technology, organizations repeatedly make ineffective decisions. The speaker emphasizes that many in the field continue to overlook fundamental practices like proper asset management and patching. By not adhering to these basics, organizations find themselves facing increasingly complex challenges without understanding the consequences of their actions. The call is for a return to these foundational elements as a way to establish a more secure environment.
Challenges in Understanding Data and Security
A crucial insight is the difficulty organizations face in accurately assessing and managing their data, with the speaker highlighting that many executives do not know the location and status of their sensitive information. This lack of awareness hampers effective security segmentation and exposes organizations to greater risks. The conversation touches on the inadequacies of existing data loss prevention (DLP) solutions, which often only highlight the presence of data rather than its security implications. The emphasis is placed on needing improved visibility and analytics to better understand and manage data flows.
The Role of Zero Trust and Third-Party Risk Management
Zero trust is presented as a necessary strategy to combat evolving cybersecurity threats, with the speaker stressing the importance of identifying potential adversaries' success points and eliminating trust relationships accordingly. Additionally, the challenges associated with third-party risk management are brought to light, particularly the vulnerability that smaller companies face within supply chains. Smaller entities are often underprepared yet targeted for their connections to larger organizations, leading to significant security risks. Ultimately, the conversation highlights the need for better solutions tailored specifically for smaller firms to enhance their security postures.
TL;DR: This episode was recorded live from Zero Trust World 2025 in Orlando, FL sponsored by ThreatLocker. Chase Cunningham joins after finishing an epic keynote where he eviscerates security dogma and the repeated stupidity of the Cyber sector. Chase & Rafal discuss Zero Trust, implications, implementation, and value.
YouTube:
Big thanks to ThreatLocker for hosting Zero Trust World 2025 - can't wait to get back next year!