CYBRIC CTO and Co-founder Mike Kail and I connected to discuss DevSecOps. First, Mike tells us what DevSecOps is and why we need it. We talk about the advantages and disadvantages (although we couldn’t really think of any compelling disadvantages) of changing the corporate culture of DevOps to include security. DevSecOps is really fixing the corporate mindset to include security in all facets of operations. It puts forth the radical notion that security is everyone’s responsibility. And, although I’m being a bit sarcastic with that previous comment, I do believe that for some companies and some individuals that this notion of everyone owning security is radical.
It shouldn’t be. Security affects us all. It affects us to the tune of $16+ billion in losses due to credit card fraud and identity theft. And that number grows every year.
Listen to the podcast for more details on DevSecOps and how you can help change the culture at your company to make security a priority for everyone.
Length: 16:52 mins. Format: MP3. Rating: G for all audiences and venues.
Copyright 2018 The SecurityNOW Podcast Show. License: CC BY.
I spoke with Exabeam‘s Chief Security Strategist, Steve Moore, about post-breach cleanup, specifically related to the healthcare industry. Steve and I discussed why the healthcare industry is a prime target for hackers, what steps to take after a breach, and some preventative steps. Post-breach cleanup can seem daunting and as we say in the podcast, “How do you know what’s clean?” The problem with breaches is that you don’t know what’s clean nor do you always know to what depth the breach has penetrated. I think it’s best to wipe a system clean and reimage it from scratch rather than trying to poke and prod your way through the maze of malware, backdoors, fake user accounts, and other persistent threats that remain after a breach. Opinions differ in this area but the peace of mind that comes with installing fresh is far more valuable and often less time-consuming that individually examining thousands of files, filesystems, and backups for elusive infections.
Length: 23:53 mins. Format: MP3. Rating: G for all audiences and venues.
Copyright 2018 The SecuritNOW Podcast Show. License: CC BY.
Ken “The Virus Doctor” Dwight and I sat down at SpiceWorld 2017 to discuss ransomware and other malware threats to you and your security. Ken Dwight has been in the cybersecurity business for as long as cybersecurity has been a thing and long before anyone coined the term, cybersecurity.
Ken also offers his book and a Virus Remediation class from his website. He has helped many companies recover from virus infestations, ransomware attacks, and various malware infections. He is a consultant, a speaker, and a practitioner in the dark art of virus killing.
It was a pleasure to speak with Mr. Dwight on camera at SpiceWorld 2017.
Copyright 2017 The SecurityNOW Show. License: CC BY.
Hillary Sanders and I sat down for a chat at SpiceWorld 2017 in Austin about data science and security. We discussed the ins and outs of data science, machine learning, neural networks, and how this data helps security researchers. Ms. Sanders is a data scientist and data science researcher at SOPHOS. As you’ll see in the video, she loses me in part of the discussion. I’m very familiar with biological neural networks but the computer ones are pretty complex. These neural networks and their reliance on big data is the significant first step toward some pretty impressive artificial intelligence (AI) possibilities.
Although Elon Musk and Stephen Hawking have warned us about the future of AI, I think that AI is the true future of computing. And I’ve thought so for a very long time, beginning back in the day when I wanted to learn LISP and Prolog programming. Unfortunately, I did not have the financial resources to learn those languages at the time. I digress.
Hillary explains data science and her work in such a way that I hope many more young people will be inspired to follow her into this next exciting chapter of computing. She is also an accomplished artist and you should view her work at hillarysanders.com. Her site isn’t just art, it’s also about her work as a data scientist and a programmer. Check out the Cheatsheets page.
Greetings SSH fans. Preston and I had the pleasure of speaking with SSH Communications Security founder Tatu Ylönen about keyless access and how system administrators and system security professionals should “manage access, not keys” when using the SSH protocol.
Preston and I debate the security of a decision to use passwordless and keyless access. During the call, we asked how to implement keyless access and what the deployment looks like to a system administrator. Preston and I are both system administrators, so we are definitely interested in the ins-and-outs of deployment.
As always, Tatu is very engaging and extremely knowledgeable about the topic of security, SSH, and access management.
Length: 15:52 minutes. Format: MP3. Rating: G for all audiences.
In our podcast, we cover the worst breaches plus additional content related to how to protect yourself from such breaches. Morey also mentions how BeyondTrust’s products can help protect you and your data.
Length: 21:30 minutes. Format: MP3. Rating: G for all audiences.