RSAC 2021
SubscribeRSAC 2021 #4
Full episode and show notesSegments
Metrics, Training, Culture – Why Your Phishing Program Isn’t Working – Drew Rose – RSA21 #4
Phishing reports have become the standard for measuring security awareness, and yet breaches keep happening. Something is broken. Knowing how to recognize a phishing attempt is a tiny part of creating a security-focused culture and protecting your business from attacks.
This segment is sponsored by...
Cyber Supply Chain Risk Management – Alyssa Feola – RSA21 #4
With the SolarWinds attack, supply chain attacks have been in the spotlight. Alyssa Feola joins us to discuss Cyber Supply Chain Risk Management.
Tech Consolidation and the Final Acts of Once Vital Point Solutions – Jess Burn – RSA21 #4
Of particular interest to me from our newly published “The Forrester Tech Tide™: Zero Trust Threat Detection And Response, Q2 2021” are what look like the final acts of several solutions once considered vital detection and response point products. While automated malware analysis (sandboxing) and ne...
Recent Attacks Against Software Integrity – Ed Skoudis – RSA21 #4
Ed Skoudis joins us to discuss recent attacks against software integrity, including:
- open source libraries
- session tracking for single sign on
- weak crypto
- machine learning (ML) algorithms used to detect malware
- ransomware attacks - how they are evolving
How to Build and Maintain a Resilient Web App Security Program – Kevin Gallagher – RSA21 #4
Prior to building a web security program, you have to have a plan. How does one create that plan? In this segment, Kevin will focus on some concrete steps to help you create an AppSec plan using a simple framework.
This segment is sponsored by Netsparker.
Visit https://securityweekly.com/netsparke...
RSAC 2021 #3
Full episode and show notesSegments
All Our Devices Aren’t Belong 2 Us – Scott Scheferman – RSA21 #3
Against the ubiquitous backdrop of Zero Trust initiatives, we have all come to accept the motto of "Verify, then trust". Yet, here we are building an entire stack of Zero Trust enabled technologies, upon a broken implicit-trust foundation. Nowhere is this risk more apparent, than at the device and f...
Zero Trust, Beyond the Buzzword – Steve Turner – RSA21 #3
Organizations continue to struggle understanding what Zero Trust is, how they move towards it, and ultimately how they implement it. There's been a lot of co-opting of the term and practitioners are so tired of it and sometimes react in disgust or think that it's marketing noise. I'd like to talk ab...
MalWare Labs, The Key to the Next Generation of Threat Hunting – Mario Vuksan – RSA21 #3
Threat hunters are under increased pressure to rapidly analyze, classify, detect and respond to malicious files. ReversingLabs is stepping forward to address these needs with its new Malware Lab Solution. The ReversingLabs Malware Lab solution powers the next generation of threat hunting by deliveri...
Third-Party Risk / Supply Chain Risk – Alla Valente – RSA21 #3
Why is third-party risk still such a challenge? Are companies using recent risk events (pandemic, solar winds, Colonial pipeline) as an opportunity to get better at risk management? How can firms better prepare for attacks to their third-party ecosystem?
Segment Resources:
https://go.forrester...
Don’t Fall Into the COVID-19 Trap: Prioritize Your Web App Security – Mark Ralls – RSA21 #3
The shift away from web application security, caused by the pandemic and the focus on remote workforces, resulted in an increased number of web vulnerabilities. In this segment, Mark talks about the best starting point for organizations to get back on track and prioritize your web app security.
h...
RSAC 2021 #2
Full episode and show notesSegments
Behind the Scenes of the Cyber Fight – Derek Manky, Michael Daniel – RSA21 #2
“Behind the scenes of the cyber fight” – talking about the good on the defender side, taking down cyber criminal supply chains, partnerships, taking down ransomware gangs.
This segment is sponsored by Fortinet.
Visit https://securityweekly.com/fortinet to learn more about them!
Adapt to the New, Unstable Normal: How to Secure the Roaring 2020s – Laura Koetzle – RSA21 #2
Security professionals must protect their organizations from the five shifts which will persist after the pandemic: 1) customers will demand safety and convenience; 2) brands will create hybrid experiences; 3) stakeholders will build the future of work; 4) smart firms will retire technical debt; and...
Why You Should Challenge Shift-Left Testing – Rickard Carlsson – RSA21 #2
The development life cycle as we know it is rapidly changing, and today’s AppSec testing needs to keep up with shorter and faster processes. A shift-left approach is no longer enough to protect web assets - you need much more dynamic tools and ways of working.
We want to talk about why enterpris...
A New Perspective on Cloud Security Resilience – Ganesh Pai – RSA21 #2
Cloud security, the next frontier. How do we build resilient services in the cloud and secure them. Ganesh Pai, CEO at Uptycs, joins us to discuss a new perspective on cloud security resilience.
This segment is sponsored by Uptycs.
Visit https://securityweekly.com/uptycs to learn more about ...
Security Shouldn’t be a Secret. Why Transparency Matters – Wayne Haber – RSA21 #2
Security can be somewhat of a mystery at a lot of organizations. Most companies choose to be tight-lipped about the security measures they have implemented. Rightfully so, there is an underlying fear that publicizing your security efforts could make you more vulnerable to security attacks and damage...
Application Security Trends in 2021 – Frank Catucci – RSA21 #2
A former Gartner analyst, Frank Catucci will share his thoughts on the latest application security trends that will impact the markets in 2021.
How Does the Cyber Risk Ratings Platform Market Need to Evolve? – Paul McKay – RSA21 #2
The cyber risk ratings market, comprised of companies providing a security rating based on what they can see of your external infrastructure is controversial. In my latest evaluative New Wave looking at this market, we identified a number of issues meaning this market is not ready for the prime time...
451 Research: Overall Security Industry Trends – Scott Crawford – RSA21 #2
Scott Crawford joins us to discuss some of the most frequent trends in the security industry today, including high profile incidents and their impact on the industry.
The Convergence of Security and Privacy on the Web – Deepika Gajaria – RSA21 #2
Data privacy and Web security teams are converging across enterprises and we are seeing more Privacy use cases like cookie banner consent and limiting data sharing (vendors like Facebook, Google etc. are capturing sensitive user data, accessing cameras, microphones, geolocation etc.) via security po...
RSAC 2021 #1
Full episode and show notesSegments
Web App and API Security Needs to Be Modernized: Here’s How – Sean Leach – RSA21 #1
The truth is, most web app and API security tools were designed for a very different era. A time before developers and security practitioners worked together, before applications were globally distributed and API-based. But attackers are developers too, and they aren’t bogged down by the limitations...
A “Great Equalizer”, Until It Isn’t: Regional Security in a Global Pandemic – Allie Mellen – RSA21 #1
In security, regions can impact available technical capabilities, manpower, and other resources. This has been felt more than ever in African countries given the dramatic shift to remote work during the pandemic. Allie's talk with Kerissa Varma dissects and compares regional responses to COVID from ...
API Security – Sandy Carielli – RSA21 #1
We are seeing API related breaches almost weekly - Experian, John Deere, Peleton, Starbucks, etc. Why are we seeing so many of these, and how do we need to change our thinking to improve API security? What makes this difficult?
Culture Matters – Put People At The Heart Of Security – Jinan Budge – RSA21 #1
Whether the human element means creating a toxic-free environment for your people, navigating the maze of organizational politics and detractors, building the human firewall, or marketing security: people and culture are central to security. We will discuss some tips to help listeners focus their pe...