Guest Himaja Motheram from Censys discusses building a security program around unknown unknowns. The podcast explores strategies for anticipating, detecting, and responding to unknown unknowns. It emphasizes the importance of executive buy-in, resources, and individual involvement in creating a security culture. The distinction between known unknowns and unknown unknowns is explored, along with the role of technology and human creativity. The shift of security responsibility to the user is discussed, as well as the value of worst-case scenario simulations and relationship-building in cybersecurity.
Creating a security program to address unknown unknowns requires prioritizing them and effectively communicating the priorities to the organization.
Building resiliency through having a robust response plan in place and focusing on relationships, communication, and collaboration within the organization helps to deal with unknown unknowns effectively.
Deep dives
Importance of Uncovering Unknown Unknowns
The podcast episode discusses the fear and challenges security professionals face when it comes to unknown unknowns. These are the security issues or vulnerabilities that they are not even aware of. The episode explores the importance of creating a security program to address these unknown problems and how to prioritize them. It emphasizes the need to have a strategy for uncovering unknown unknowns and effectively communicating the priorities to the organization. Examples of strategies mentioned include building a culture of security, encouraging creativity and critical thinking, and simulating worst-case scenarios.
Resilience and Preparedness
The podcast highlights the concept of resiliency as a key aspect of dealing with unknown unknowns. Rather than focusing solely on prevention, the episode suggests that being able to quickly and efficiently respond to security issues is crucial. It emphasizes the importance of having a robust response plan in place and being prepared mentally and procedurally for any potential security incident. The idea is to build a security program based on known unknowns that can also serve as a foundation for dealing with unknown unknowns. The role of relationships, communication, and collaboration within the organization is also stressed.
Promoting a Security Culture and Creative Thinking
The podcast discusses the significance of developing a security culture throughout the organization. It highlights the importance of encouraging everyone to report anything suspicious or unusual and ensuring that the security team has the capacity and competence to follow up on these reports. By leveraging the diverse perspectives and skills within the organization, unknown unknowns can be identified and addressed more effectively. The episode also emphasizes the need for creative thinking and innovation when it comes to anticipating and discovering unknown unknowns. It suggests setting aside dedicated time for strategic thinking and utilizing the expertise of stakeholders from various departments to proactively uncover potential security risks.
How can one create a security program around unknown problems?
Don’t we know a lot of the things we lack visibility into that can cause security issues?
But what about the things you don't even know about in the first place?
Will that thing we don't even know to look at, ever cause a security issue?
Thanks to our podcast sponsor, Censys
Censysis the leading Internet Intelligence Platform for Threat Hunting and Exposure Management. We provide the most comprehensive, accurate, and up-to-date map of the internet, which scans 45x more services than the nearest competitor across the world’s largest certificate database (>10B). Learn more at www.censys.com.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode