Safe Mode Podcast

Safe Mode Podcast
undefined
Mar 6, 2025 • 29min

Chainguard’s Dan Lorenc on the next decade of software supply chain security

In this episode, Greg Otto talks with Dan Lorenc, CEO and co-founder of Chainguard. They explore the challenges organizations face with CVE management, where dealing with vulnerabilities often drains valuable engineering resources. They also discuss how new visualization tools are redefining this landscape by offering clear insights into CVE trends, empowering teams to make informed decisions and optimize both security and efficiency in their software development processes. In our reporter chat, Greg talks with Matt Kapko about the United States’ indictment of China-linked hackers.
undefined
Feb 27, 2025 • 34min

Virtru’s John Ackerly on how the feds are keeping data secure and interoperable

In this episode, Greg Otto talks with Virtru Co-founder and CEO John Ackerly , discussing the significance of open standards, the challenges and successes of implementing the Trusted Data Format across federal agencies, and the critical role of interoperability and compliance. John also gives us details on how close the country was to a national privacy law before the 9/11 attacks upended everything In our reporter chat, Greg talks with CyberScoop Tim Starks about a flurry of news around the Department of Homeland Security.
undefined
Feb 20, 2025 • 20min

FBI’s Cynthia Kaiser on Salt Typhoon’s ‘indiscriminate’ data collection

In this episode, you will hear Cynthia Kaiser, deputy assistant director in the bureau’s cyber division talk about the implications of the Salt Typhoon breach, which she spoke about during CyberScoop’s Zero Trust Summit. Kaiser characterized the breach as “a different level of insidiousness” from Beijing, one that reflects its “ambition and reckless aggression in cyberspace.” In our reporter chat, Greg talks with CyberScoop’s new cybercrime reporter Matt Kapko about a slew of reports around Russian nation-state cyber actors.
undefined
Feb 13, 2025 • 33min

Chainalysis’ Jackie Burns-Koven on the drop in ransomware payments

Greg Otto talks with Jackie Burns-Koven, Head of Cyber Threat Intelligence at Chainalysis. They discuss research from Chainalysis that shows a 35% drop in ransom payments over the second half of 2024. They also discuss the growing refusal of victims to pay ransoms and how attackers are adapting their tactics. Additionally, she highlights the influence of Ransomware-as-a-Service, the evolution of data leak sites, and the effectiveness of international collaboration in combating these cyber threats. In our reporter chat, Greg talks with Tim Starks about the Trump administration’s nominee for national cyber director.
undefined
Feb 6, 2025 • 27min

Google’s John Hultquist on how APTs are using generative AI

In this engaging discussion, John Hultquist, Chief Analyst for Google Threat Intelligence Group, and cybersecurity expert Derek B. Johnson unpack the evolving tactics of Advanced Persistent Threats (APTs) using generative AI. They highlight the qualitative differences between AI-generated and human-crafted social engineering tactics. The conversation dives into how AI accelerates cyberattacks and the pressing need for stronger defense systems. Additionally, they touch on the friction involving Elon Musk and cryptocurrency against a backdrop of federal cybersecurity challenges.
undefined
Jan 29, 2025 • 43min

Hugh Thompson on what the SEC got right (and wrong) with its cyber incident reporting mandate

Greg Otto talks with Hugh Thompson, Executive Chairman for RSAC Conference. Greg and Hugh discuss how the SEC's cyber disclosure regulations have fallen short of their intended purpose, failing to provide investors with enhanced transparency due to ongoing debates about materiality and insufficient market consequences. Additionally, they discuss the evolving regulatory landscape for 2025 and recent efforts to strengthen border gateway protocol (BGP) security. In our reporter chat, Greg talks to Derek B. Johnson on DeepSeek’s newfound fame and its time in the security spotlight.
undefined
Jan 23, 2025 • 40min

Gabrielle Hempel on AI regulation on the federal and state level

Greg Otto talks with Exabeam’s Gabrielle Hempel about the complex terrain of AI regulation at both the federal and state levels, offering a deep dive into the legislative challenges, and the balancing act of fostering innovation while protecting public interests. They also reflect on how public interaction with AI systems is shaping legislative efforts, aiming to provide a comprehensive exploration of the regulatory landscape and its implications for businesses. In our reporter chat, Greg talks to Tim Starks about a Congressional hearing that examined DHS’s elimination of the entire Cyber Safety Review Board’s roster. LINK: https://cyberscoop.com/removal-cyber-safety-review-board-members/
undefined
Jan 16, 2025 • 52min

Guidepoint Security’s Jason Baker on lessons learned from negotiations with ransomware groups

As we head into 2025, Greg talks with Jason Baker, a ransomware negotiator for Guidepoint Security, on how ransomware has shifted and evolved, and the challenges it poses for businesses and governments alike. Jason also sheds light on the top threat actors, the future of international regulations and where they might fall concerning the contentious issue of paying ransoms, and what businesses can do to limit the damage if they are ever attacked. In our reporter chat, Greg talks to Tim Starks about the conversations happening in Washington, D.C. regarding enhanced offensive cybersecurity operations. LINK: https://cyberscoop.com/aggressive-cyber-offense-trump-administration-us-strategy-debate/
undefined
Jan 8, 2025 • 41min

Phil Venables on the State of the CISO

In the first episode of 2025, Greg Otto dives into a conversation with Phil Venables, the Chief Information Security Officer of Google Cloud, who shares insights from his expansive career in cybersecurity. From his beginnings as Goldman Sachs' first CISO to his current role leading risk and security at Google, Phil discusses the evolving challenges CISOs face, including the impact of AI-powered cyber threats and strategies to prevent burnout. Discover Phil's perspectives on fostering a supportive organizational culture and the importance of proactive planning in strengthening cybersecurity resilience. In our reporter chat, Greg talks with Derek Johnson about a hacker scheme that abuses the guardrails in generative AI.
undefined
Dec 19, 2024 • 32min

Vik Phatak on the inherent issues in native cloud firewalls

In the latest episode of Safe Mode, Greg Otto talks with Vik Phatak, Chairman and CEO of CyberRatings.org. Cyber Ratings recently released a report assessing the native firewalls provided by major cloud service providers like Microsoft, Google, and AWS. These cloud-native firewalls, included with their instances, were put to the test by Cyber Ratings to evaluate their effectiveness. The findings reveal significant shortcomings in relying solely on these built-in security measures. In our reporter chat, Greg Otto talks with Tim Starks about two interesting stories that chronicle the latest in the shady world of spyware. LINK: https://cyberscoop.com/russian-surveillance-spyware-threat-citizen-lab/ https://cyberscoop.com/amnesty-international-exposes-serbian-polices-use-of-spyware-on-journalists-activists/

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app