Welcome to the Cybersecurity Readiness Podcast Site

Episodes

Jan. 3, 2023

Useful Technology Should Be Attack Agnostic

In this episode, Patricia Muoio, Ph.D., Partner at SineWave Ventures and Former Chief of Trusted Systems Research Group, National Security Agency , sheds light on the cybersecurity technology landscape and emphasizes the need...

Listen to the Episode
Dec. 20, 2022

Do you see what attackers see? Threat modeling done right

Threat modeling is an intrinsic part of information security governance and needs to be done well. However, research finds that many organizations don't do it well, some are pretty haphazard or chaotic in their approach. In t...

Listen to the Episode
Dec. 6, 2022

Implementing Phishing Resistant Multifactor Authentication

The Cybersecurity and Infrastructure Security Agency (CISA) recently (Oct 31, 2022) released fact sheets urging all organizations to implement phishing-resistant multi-factor authentication (MFA). In this episode, George Gerc...

Listen to the Episode
Nov. 22, 2022

How do SMBs protect themselves from ransomware attacks?

A recent Global SMB Ransomware survey finds that nearly half of small and medium-sized businesses (SMBs) have experienced a ransomware attack, yet the majority aren't sure they are a target, and most are not confident they ca...

Listen to the Episode
Nov. 8, 2022

Cybersecurity As A Strategic Opportunity

In this episode, Kal Sambhangi, Senior Vice President, Cybersecurity Strategy and Architecture at Truist , shares his vision of the future of cyber governance. According to him, the leadership mindset needs to change whereby ...

Listen to the Episode
Oct. 25, 2022

Comprehensive Asset Discovery

Comprehensive asset discovery is foundational to robust and proactive cybersecurity governance. The Cybersecurity and Infrastructure Security Agency recently issued a directive (BOD 23-01) requiring federal enterprises (civil...

Listen to the Episode
Oct. 11, 2022

Is Cybersecurity A Moving Target at Academic Institutions?

In a highly engrossing and in-depth discussion, Tej Patel, Vice President, and CIO at Stevens Institute of Technology sheds light on the various information security challenges that plague academic institutions and how best t...

Listen to the Episode
Sept. 27, 2022

Securely Migrating to the Cloud -- Insights from the American Cancer …

As more organizations embrace cloud-based services, securely migrating to the cloud is becoming an important capability. Keith Weller , former Vice President, Enterprise Technology Services, American Cancer Society (ACS), sp...

Listen to the Episode
Sept. 13, 2022

Detecting Malicious Insider Threats by Monitoring User Journeys

 Insider threats are often considered the biggest risk for organizations because they can cause the most destruction. Survey reports, and studies, have found that organizations have spent millions of dollars to recover from ...

Listen to the Episode
Aug. 30, 2022

Skilling Up for Security Operations Center Roles

The Security Operations Center (SOC) is at the heart of an organization's cyber defense system. Highly skilled and motivated personnel must work in these centers. James Risler, Senior Manager, Cisco Learning and Certification...

Listen to the Episode
Aug. 16, 2022

Bridging the Gap Between Intentions and Practicality in Cybersecurity

Daniela Almeida Lourenco, Chief Information Security Officer (CISO) at Tinka , firmly believes that CISOs have the very best of intentions -- "we all mean the best; we all want to protect the organization, and that is all we ...

Listen to the Episode
Aug. 2, 2022

Preparing for the Future of Device Management

With the growing move towards a hybrid and remote work environment, more and more people are relying on their smart devices to get work done. Keeping track of all of these devices, and ensuring that they are being used in a v...

Listen to the Episode
July 19, 2022

The State of Attack Surface Management

With increasing digitization and the use of cloud-hosted assets, managing attack surfaces continues to be a major challenge. A recent survey report on the state of attack surface management (ASM) finds security teams drownin...

Listen to the Episode
July 5, 2022

Global Security and Post Breach Management Best Practices

"If you can plan for the zombie apocalypse, you can probably face just about anything," said Tim Callahan, Senior Vice President, and Global Chief Information Security Officer, Aflac during a talk in my Master's level class o...

Listen to the Episode
June 21, 2022

How to Tackle Burnout in Cybersecurity

Security Operating Center (SOC) staff members are often consumed with tedious manual tasks that lead to burnout and can cost organizations millions of dollars in losses due to human error. Thomas Kinsella, Co-Founder & Chief ...

Listen to the Episode
June 7, 2022

Actionable Threat Intelligence and the Dark Web

In a recent news release, Reuters reported that "United States has offered a $15 million reward for information on Conti ransomware group. The FBI estimates that more than 1,000 victims of the Conti group have paid a total in...

Listen to the Episode
May 24, 2022

Reducing the Disconnect Between Security and Development Teams

How do you make security a first-class citizen of the software development process? According to an industry report, “many information security engineers don’t understand software development—and most software developers don’...

Listen to the Episode
May 10, 2022

Perspectives of a Global Chief Information Security Officer

In a wide-ranging discussion, Vishal Salvi, CISO & Head of Cyber Practice at Infosys , sheds light on a range of topics from CISO empowerment to creating and sustaining a high-performance information security culture. He high...

Listen to the Episode
April 26, 2022

Thinking Like A Hacker

Using compelling stories and metaphors, Ted Harrington, author of Hackable: How To Do Application Security Right, and Executive Partner at Independent Security Evaluators , explains the process of hacking and the importance o...

Listen to the Episode
April 12, 2022

Is Cybersecurity Regulatory Compliance Good Enough?

"The story of the RMS Titanic has served as a grim reminder that regulatory compliance does not guarantee safety or security. The ship was carrying 2,224 passengers and crew when it sank one April night in 1912, killing over ...

Listen to the Episode
March 29, 2022

Is Cyber Insurance Necessary?

"Security experts are split on cyber insurance and its place in business, with just as many arguing that it is a useless add-on as an essential business enabler." A KPMG study indicated that these policies were not overly tru...

Listen to the Episode
March 15, 2022

Dealing with Cyber Trauma

The phenomenon of cyber trauma is very real and individuals and organizations are often not adequately prepared to deal with it. Patrick Wheeler , a Luxembourg-based cybersecurity practitioner and Director of the Cyber Wayfin...

Listen to the Episode
March 1, 2022

A Deep Dive into Ransomware Attacks and Negotiations

Art Ehuan, Vice President, Palo Alto Networks, and Former FBI Special Agent , discusses at length the unfortunate evolution and escalation of ransomware attacks. He explains how the threat actors have upped their game and are...

Listen to the Episode
Feb. 15, 2022

Making Cybersecurity Communication Effective

Cybersecurity communication should be simple, immersive, attractive, continuous, and multi-channel, says Marcin Ganclerz , a subject matter expert. He passionately argues for creating a 'culture of enablement and not fear' so...

Listen to the Episode