CISO Tradecraft®

CISO Tradecraft®

Welcome to CISO Tradecraft®, your guide to mastering the art of being a top-tier Chief Information Security Officer (CISO). Our podcast empowers you to elevate your information security skills to an executive level. Join us on this journey through the domains of effective CISO leadership. read less
TechnologieTechnologie

Folgen

#182 - Shaping the SOC of Tomorrow (with Debbie Gordon)
20-05-2024
#182 - Shaping the SOC of Tomorrow (with Debbie Gordon)
This episode of CISO Tradecraft, hosted by G Mark Hardy, features special guest Debbie Gordon. The discussion focuses on the critical role of Security Operations Centers (SOCs) in an organization's cybersecurity efforts, emphasizing the importance of personnel, skill development, and maintaining a high-performing team. It covers the essential aspects of building and managing a successful SOC, from hiring and retaining skilled incident responders to measuring their performance and productivity. The conversation also explores the benefits of simulation-based training with CloudRange Cyber, highlighting how such training can improve job satisfaction, reduce incident response times, and help organizations meet regulatory requirements. Through this in-depth discussion, listeners gain insights into best practices for enhancing their organization's cybersecurity posture and developing key skill sets to defend against evolving cyber threats. Cloud Range Cyber: https://www.cloudrangecyber.com/ Transcripts: https://docs.google.com/document/d/18ILhpOgHIFokMrkDAYaIEHK-f9hoy63u  Chapters 00:00 Introduction 01:04 The Indispensable Role of Security Operations Centers (SOCs) 02:07 Building an Effective SOC: Starting with People 03:04 Measuring Productivity and Performance in Your SOC 05:36 The Importance of Continuous Training and Simulation in Cybersecurity 09:00 Debbie Gordon on the Evolution of Cyber Training 11:54 Developing Cybersecurity Talent: The Importance of Simulation Training 14:46 The Critical Role of People in Cybersecurity 21:57 The Impact of Regulations on Cybersecurity Practices 24:36 The Importance of Proactive Cybersecurity Training 26:26 Redefining Cybersecurity Roles and Training Approaches 30:08 Leveraging Cyber Ranges for Real-World Cybersecurity Training 36:03 Evaluating and Enhancing Cybersecurity Skills and Team Dynamics 37:49 Maximizing Cybersecurity Training ROI and Employee Engagement 41:40 Exploring CloudRange Cyber's Training Solutions 43:28 Conclusion: The Future of Cybersecurity Training
#181 - Inside the 2024 Verizon Data Breach Investigations Report
13-05-2024
#181 - Inside the 2024 Verizon Data Breach Investigations Report
In this episode of CISO Tradecraft, host G Mark Hardy discusses the findings of the 2024 Verizon Data Breach Investigations Report (DBIR), covering over 10,000 breaches. Beginning with a brief history of the DBIR's inception in 2008, Hardy highlights the evolution of cyber threats, such as the significance of patching vulnerabilities and the predominance of hacking and malware. The report identifies the top methods bad actors use for exploiting companies, including attacking VPNs, desktop sharing software, web applications, conducting phishing, and stealing credentials, emphasizing the growing sophistication of attacks facilitated by technology like ChatGPT for phishing and deepfake tech for social engineering. The episode touches on various cybersecurity measures, the omnipresence of multi-factor authentication (MFA) as a necessity rather than a best practice, and the surge in denial-of-service (DDoS) attacks. Hardy also discusses generative AI's role in enhancing social engineering attacks and the potential impact of deepfake content on elections and corporate reputations. Listeners are encouraged to download the DBIR for a deeper dive into its findings. Transcripts: https://docs.google.com/document/d/1HYHukTHr6uL6khGncR_YUJVOhikedjSE  Chapters 00:00 Welcome to CISO Tradecraft 00:35 Celebrating Milestones and Offering Services 01:39 Diving into the Verizon Data Breach Investigations Report 04:22 Top Attack Methods: VPNs and Desktop Sharing Software Vulnerabilities 09:24 The Rise of Phishing and Credential Theft 19:43 Advanced Threats: Deepfakes and Generative AI 23:23 Closing Thoughts and Recommendations
#180 - There's Room For Everybody In Your Router (with Giorgio Perticone)
06-05-2024
#180 - There's Room For Everybody In Your Router (with Giorgio Perticone)
In this joint episode of the Security Break podcast and CISO Tradecraft podcast, hosts from both platforms come together to discuss a variety of current cybersecurity topics. They delve into the challenge of filtering relevant information in the cybersecurity sphere, elaborate on different interpretations of the same news based on the reader's background, and share a detailed analysis on specific cybersecurity news stories. The discussion covers topics such as the implications of data sharing without user consent by major wireless providers and the fines imposed by the FCC, the significance of increasing bug bounty payouts by tech companies like Google, and a comprehensive look at how edge devices are exploited by hackers to create botnets for various cyberattacks. The conversation addresses the complexity of the cybersecurity landscape, including how different actors with varied objectives can simultaneously compromise the same devices, making it difficult to attribute attacks and protect networks effectively. Transcripts: https://docs.google.com/document/d/1GtFIWtDf_DSIIgs_7CizcnAHGnFTTrs5 Chapters 00:00 Welcome to a Special Joint Episode: Security Break & CISO Tradecraft01:27 The Challenge of Filtering Cybersecurity Information04:23 Exploring the FCC's Fine on Wireless Providers for Privacy Breaches06:41 The Complex Landscape of Data Privacy Regulations16:00 The Economics of Data Breaches and Regulatory Fines24:23 Bug Bounties and the Value of Security Research33:21 Exploring the Economics of Cybersecurity33:50 The Lucrative World of Bug Bounties34:38 The Impact of Security Vulnerabilities on Businesses35:50 Navigating the Complex Landscape of Cybersecurity36:22 The Ethical Dilemma of Selling Exploit Information37:32 Understanding the Market Dynamics of Cybersecurity38:00 Focusing on Android Application Security38:34 The Importance of Targeting in Cybersecurity Efforts42:33 Exploring the Threat Landscape of Edge Devices46:37 The Challenge of Securing Outdated Technology49:28 The Role of Cybersecurity in Modern Warfare53:15 Strategies for Enhancing Cybersecurity Defenses01:05:25 Concluding Thoughts on Cybersecurity Challenges