

Risky Business
Patrick Gray
Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.
Episodes
Mentioned books

Oct 1, 2024 • 40min
Snake Oilers: Sandfly Security, Permiso and Wiz
This episode features insights from guests representing Sandfly Security, Permiso, and Wiz. Sandfly discusses their innovative agentless approach to securing Linux systems, tackling challenges like SSH key management. Permiso emphasizes machine learning in identity security, focusing on proactive measures to detect threats. Wiz explores cloud security vulnerabilities and the importance of integrating safety measures into coding practices. Together, they shed light on the evolving landscape of cybersecurity and its critical role in today's digital world.

Sep 25, 2024 • 1h 6min
Risky Business #765 -- The Kaspersky switcheroo
Rob Joyce, a former U.S. cybersecurity advisor, shares insights on the pressures tech giants face from governments. He discusses Elon Musk's challenges with free speech in Brazil and TikTok's proactive stance against misinformation. Mike Wiacek, founder of Stairwell, highlights innovative malware detection techniques and the ongoing arms race in cybersecurity. The duo also explores Kaspersky's unexpected switch to an unfamiliar antivirus, demonstrating the complex dynamics in the security landscape.

8 snips
Sep 18, 2024 • 1h 3min
Risky Business #764 -- Mossad expands into telecommunications services
Luke Jennings, a security expert at Push Security with a focus on phishing kit analysis, joins to discuss the evolving tactics of cybercriminals. He sheds light on how phishing crews are driving an arms race in online security and emphasizes the importance of adapting detection methods to users' needs. The conversation includes a critical look at multi-factor authentication vulnerabilities and the necessity of enhanced browser security. Jennings also critiques current cybersecurity solutions and the overlooked potential for browser-level monitoring.

Sep 11, 2024 • 52min
Risky Business #763 – Microsoft un-patches critical bug
Paul Wells, an incident responder at Kroll Cyber, dives into the crucial topic of cyber incident preparedness. He emphasizes the significance of having a pre-established incident response plan to mitigate crises effectively. With examples from real-world breaches, Wells discusses the necessity of accurate backups and clear communication during recovery. The conversation also touches upon the complexities of modern cybersecurity threats like ransomware and how organizations can adapt their strategies for improved resilience.

Sep 6, 2024 • 38min
Snake Oilers: Authentik, Dropzone and SlashID
In this discussion, the guests include Authentik, an open-source identity provider gaining traction among large organizations, Dropzone AI, which utilizes LLMs to boost SOC analyst efficiency, and SlashID, focused on detecting identity threats through log analysis. They delve into the shift towards self-hosted identity solutions that enhance security and customization. The impact of AI in streamlining security workflows is highlighted, alongside the challenges of data privacy and cloud identity solutions. This episode brings fresh insights into the evolving security landscape.

6 snips
Sep 4, 2024 • 1h 5min
Risky Business #762 -- Brazil nukes X, Iranian APTs deploy ransomware
Ariel Kadeshevich, co-founder of Spera Security, dives into the chaotic world of identity security management. He discusses the Brazilian Supreme Court's ban on X, connecting it to broader free speech and cybersecurity issues. The conversation shifts to the risks of multi-factor authentication, emphasizing its often inconsistent implementation. Kadeshevich also explores the implications of identity vulnerabilities and how integrating AI and automation can enhance security practices, highlighting the urgent need for robust identity frameworks in today's digital landscape.

8 snips
Aug 28, 2024 • 1h 5min
Risky Business #761 – Telegram v frogs. Fight!
Aaron Unterberger, a vulnerability management expert, dives into the complexities of securing digital environments. He discusses recent high-stakes cyberattacks, including zero-day vulnerabilities linked to the Volt Typhoon group, revealing the dangers of unprotected surveillance systems. The conversation expands to Telegram's controversial role in communication, blending politics and crime. Unterberger emphasizes the need for systematic approaches to vulnerability management and highlights challenges like shadow IT that organizations face today.

Aug 26, 2024 • 30min
Feature interview: ASIO Director General Mike Burgess on encryption and access
Mike Burgess, the Director General of ASIO and a former CISO at Telstra, shares insights on national security's evolving landscape. He discusses the pressing challenges posed by encrypted messaging and the need for tech companies to cooperate with authorities. The conversation dives into the Assistance and Access Bill, emphasizing the delicate balance between privacy rights and public safety. Burgess explores modern intelligence gathering complexities and the implications of international cooperation in tackling encrypted communication platform challenges.

Aug 21, 2024 • 1h 5min
Risky Business #760 – Microsoft to make MFA mandatory
This week dives into significant security news, starting with Microsoft's impressive move to make multi-factor authentication mandatory for Azure admins. A massive public data breach reveals shocking vulnerabilities, linked to a certain 'Florida Man.' The US government points fingers at Iran for hacking the Trump campaign, raising tensions in cyberspace. Tech blunders abound as TP-Link faces scrutiny and a major Chinese RFID maker is exposed for hardcoded backdoors. Tune in for insights on hybrid cybersecurity challenges and bizarre cybercrimes that keep the hosts entertained!

Aug 19, 2024 • 36min
Wide World of Cyber: 2024 election interference, the media and Iran's hack and leak
Chris Krebs, former director of CISA who oversaw U.S. election security in 2020, and Alex Stamos, former CISO at Facebook during the 2016 election, delve into the looming threats of cyber interference in the 2024 election. They discuss Iran's recent hack and leak targeting political campaigns, the evolving disinformation tactics, and the ethical dilemmas faced by the media in reporting sensitive information. The duo also highlights advancements in cybersecurity since 2016 and stresses the need for effective collaboration to safeguard election integrity.


