Security Weekly Podcast Network (Audio) cover image

Security Weekly Podcast Network (Audio)

Latest episodes

undefined
Dec 30, 2024 • 48min

Say Easy, Do Hard, Minimum Viable Security - Part 2 - Jon Fredrickson - BSW Vault

Check out this episode from the BSW Vault, hand picked by main host Matt Alderman! This segment was originally published on January 3, 2023. With the current macro economic head winds, 2023 budgets are either frozen or are flat. Where should CISOs focus these limited budgets to maximize the most out of their security program? In this segment, we invite Jon Fredrickson, Chief Risk Officer at Blue Cross Blue Shield of Rhode Island, to debate what should be in your minimum viable security program. This segment is part 2 and focuses on the minimum viable security vendors for our top 6 capabilities: Asset Management Patch Management IAM/MFA/PIM/PAM EDR/MDR/XDR Backup/Recovery Risk Management Show Notes: https://securityweekly.com/vault-bsw-16
undefined
Dec 27, 2024 • 34min

The Impact of Tariffs - SWN Vault

Josh Marpet and Doug talk about how Tariffs work and how you maybe should get ready for higher prices to replace equipment in the coming years if new rounds of tariffs are imposed on foreign goods and components. Show Notes: https://securityweekly.com/vault-swn-24
undefined
Dec 25, 2024 • 1h 17min

Hacker Heroes - Haroon Meer - PSW Vault

Unraveling Cybersecurity Complexity: A Conversation with Haroon Meer Haroon Meer, an influential figure in the world of cybersecurity, takes center stage in this podcast interview. With a deep reservoir of knowledge and a track record of tackling complex security challenges, Haroon has established himself as a key player in the InfoSec domain. As the founder of Thinkst Applied Research, Haroon brings a wealth of practical experience to the table. Join us as we explore his professional journey, from early forays into cybersecurity to pioneering innovations that have reshaped how organizations approach security. Haroon Meer's insights go beyond the theoretical, offering a pragmatic understanding of cybersecurity issues and solutions. Dive into the intricacies of threat landscapes, security architectures, and the evolving dynamics of cyber threats as Haroon shares his perspectives on the current state of cybersecurity. With a focus on practicality and a knack for simplifying complex concepts, Haroon Meer's interview is a must-listen for anyone interested in the nuances of cybersecurity. Gain a deeper understanding of the challenges faced by security professionals and uncover valuable takeaways that can enhance your approach to securing digital environments. Join us as we explore the mind of a cybersecurity luminary, unraveling the layers of InfoSec intricacies with Haroon Meer in this enlightening podcast episode. Show Notes: https://securityweekly.com/vault-psw-14
undefined
Dec 24, 2024 • 31min

Compliance & Privacy - SWN Vault

Josh Marpet, a compliance and privacy expert, joins the discussion with Doug to tackle the complex world of cybersecurity regulations. They share humorous insights about the absurdities of compliance procedures and the disconnect between management and IT. The conversation highlights data privacy challenges in a surveilled society and critiques regulations like GDPR for their loopholes. Marpet emphasizes the need for stricter penalties to enforce accountability, while reflecting on AI concerns and the evolving impact of social media on personal privacy.
undefined
Dec 23, 2024 • 27min

Say Easy, Do Hard, Minimum Viable Security - Part 1 - Jon Fredrickson - BSW Vault

CISOs face tough choices with flat budgets affecting security programs. The debate on minimum viable security strategies highlights key areas like identity management. Challenges of applying best practices in legacy environments are discussed. Patch and asset management are underscored as essential for vulnerable security postures. The conversation also emphasizes integrating risk management into business culture, promoting stakeholder engagement and transparency while tackling evolving cyber threats.
undefined
Dec 20, 2024 • 36min

Dysentery, TP-Link, Piracy, Calendar Scams, Tencent, TikTok, Aaran Leyland and More.. - SWN #439

Aaron Leyland, a mobile device security expert and contributor to Security Weekly News, shares insights on pressing cybersecurity topics. He discusses the potential ban of TP-Link routers due to security concerns and delves into the world of online piracy, highlighting recent takedowns. Leyland also warns about phishing risks through calendar invites, unpacks the alarming rise of spyware like Pegasus, and reflects on surveillance practices impacting privacy—a compelling blend of current threats and tech nostalgia.
undefined
Dec 20, 2024 • 1h 43min

D3FEND 1.0: A Milestone in Cyber Ontology - Peter Kaloroumakis - ESW #388

Since D3FEND was founded to fill a gap created by the MITRE ATT&CK Matrix, it has come a long way. We discuss the details of the 1.0 release of D3FEND with Peter in this episode, along with some of the new tools they've built to go along with this milestone. To use MITRE's own words to describe the gap this project fills: "it is necessary that practitioners know not only what threats a capability claims to address, but specifically how those threats are addressed from an engineering perspective, and under what circumstances the solution would work" Segment Resources: https://d3fend.mitre.org In the enterprise security news, a final few fundings before the year closes out Arctic Wolf buys Cylance from Blackberry for cheap, a sentence that feels very weird to say the quiet HTTPS revolution passkeys are REALLY catching on resilience keeps showing up in the titles of news items Apple Intelligence insults the BBC’s intelligence MITRE ATT&CK evals drama Lastpass breach drama continues All that and more, on this episode of Enterprise Security Weekly As we wrap up the year, we have an honest discussion about how important security really is to the business. We discuss some of Katie's predictions for AppSec in 2025, as well as "what sucks" in security! Visit https://www.securityweekly.com/esw for all the latest episodes! Show Notes: https://securityweekly.com/esw-388
undefined
Dec 19, 2024 • 2h 47min

When Public Payphones Become Smart Phones - Inbar Raz - PSW #855

If you've ever wondered how attackers could go after payphones that are "smart" we got you covered! Inbar has done some amazing research and is here to tell us all about it! Segment Resources: https://www.retro.unarmedsecurity.net/post/%D7%9E%D7%A1%D7%AA%D7%91%D7%A8-%D7%A9%D7%92%D7%9D-%D7%98%D7%9C%D7%A4%D7%95%D7%9F-%D7%A6%D7%99%D7%91%D7%95%D7%A8%D7%99-%D7%94%D7%95%D7%90-%D7%98%D7%9C%D7%A4%D7%95%D7%9F-%D7%97%D7%9B%D7%9D XSS is the number one threat?, fix your bugs faster, hacking VoIP systems, AI and how it may help fuzzing, hacker gift guides, new DMA attacks, hacking InTune, Rhode Island gets hacked, OpenWrt supply chain issues, we are being spied on, Germans take down botnet, Bill and Larry are speaking at Shmoocon!, and TP-Link bans. Visit https://www.securityweekly.com/psw for all the latest episodes! Show Notes: https://securityweekly.com/psw-855
undefined
Dec 18, 2024 • 56min

NAC is Back - How Network Access Control Can Protect Your Remote Devices and Data - Rob Allen - BSW #376

Rob Allen, Chief Product Officer at ThreatLocker, dives into how Network Access Control (NAC) is essential for safeguarding remote devices in today's borderless work environment. He discusses the vulnerabilities presented by a lack of corporate firewalls and the significance of direct connections over traditional VPNs. The conversation also touches on the evolving role of CISOs and their heightened accountability amid rising cyber threats, underscoring the need for proactive, endpoint-centric security measures in the age of hybrid work.
undefined
Dec 17, 2024 • 40min

Vogons, Task Scams, HiatusRat, Cellebrite, Deloitte, Quantum, Aaran Leyland, and More - SWN #438

Vogons, Task Scams, HiatusRat, Cellebrite, Deloitte, Quantum, WordPress, Aaran Leyland, and more on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-438

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode