CyberWire Daily

SafePay, unsafe day.

6 snips
Jul 7, 2025
Rob Allen, Chief Product Officer at ThreatLocker, discusses the pressing issue of security fatigue in cybersecurity. He argues that a 'Default Deny' strategy can mitigate this problem by enhancing security without overwhelming users. Recent high-profile cyber incidents, including a ransomware attack on Ingram Micro, highlight the evolving landscape of cybercrime and the need for smarter security measures. Allen also emphasizes the importance of user education in combating insider threats and improving compliance.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

EDR False Positives Frustration

  • A prospect complained about his EDR tool flooding him with false positives.
  • He showed that data exfiltration via PowerShell ran undetected, highlighting tool blindspots.
ADVICE

Default Deny Secures Better

  • Deny everything by default and only allow explicitly approved software.
  • This blocks unknown malware without needing to detect every threat.
ADVICE

Balance Deny With Exceptions

  • Combine 'deny by default' with 'permit by exception' to avoid disrupting users.
  • Allow users to use known necessary apps while blocking anything outside.
Get the Snipd Podcast app to discover more snips from this episode
Get the app