CYBR.SEC.Media
CYBR.Signal
Boosting the Signal and Reducing the Noise for Cybersecurity Professionals
Autor
CYBR.SEC.Media
Categoría
Web del podcast
Último episodio
7 de jul. de 2026
¿Dónde escuchar?
Podcasts en la app Replaio Radio Muy prontoLos podcasts llegarán muy pronto a la app. Instálala ahora y sé el primero en descubrir una forma totalmente nueva de vivir los podcasts
Episodios
Reviewing Accepted Risk 29.10.2023 5:31
Reviewing accepted risks is a crucial part of a risk management program. In today's #cybersunday, Michael talks about some important best practices like considering risk tolerance changes, involving business units in your review process, and others. Want to reach out to the host? Email us at podcast@houstonseccon.com Hosted By: Michael Farnum Editing By: Lauren Lynch
Recent Social Engineering Attacks 22.10.2023 4:17
Some recent notable #cybersecurity breaches have come from #socialengineering attacks. Humans are always going to fall for this, but we can help lessen the success of these attacks via awareness training. Michael talks in today’s #cybersunday about how #securityawarenesstraining can be targeted and doesn’t have to be so boring and difficult. Want to reach out to the host? Email us at podcast@ho...
MDR is Not a Service 01.10.2023 5:50
If you're looking for an MDR (Managed Detection and Response) vendor, the temptation is to think of them as a product company versus a services company. On this #cybersunday, Michael talks about why that happens, why it can lead to more confusion when trying to decide which vendor to go with, and some of the things you need to think about that can help you choose. Want to reach out to the hos...
Barracuda ESG Flaw Thoughts 24.09.2023 5:29
The Barracuda ESG Vulnerability is still causing havoc, with the vendor telling their customers to replace the box. In this CyberSunday, Michael discusses some of the implications and considerations of this kind of vulnerability in an important and widely-deployed security device. Things Mentioned: · https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally · https://ww...
Is GRC Technical? 17.09.2023 5:15
There are a few paths to getting into cybersecurity, and not all of them are considered “technical”. But what does that mean? In this #CyberSunday, Michael talks about a discussion around GRC as a career path and if it is “technical” or not. Things Mentioned: · https://www.linkedin.com/posts/mikesportfolio_cybersecurity-informationsecurity-infosec-activity-7097581791925993472-6ZN7?utm_sour...
Security Champions: Secret Weapon Against Shadow IT 23.04.2023 4:37
How do you work towards a solution for a problem like Shadow IT with people when everyone wants to try to throw tech at it? On today's #CyberSunday, I talk about how using security champions in your company can help. #ShadowIT #cybersecurity #securitychampions
Shadow Security in a World of Shadow IT 26.03.2023 5:23
We all know about Shadow IT, and we know it is a big issue (bigger these days with the ease of workload deployment in the cloud). But are we also aware that there is Shadow Security? What is Shadow Security, and is it a problem? Here's my take on today's #CyberSunday. #shadowit #shadowsecurity #cloud #cloudsecurity #workloads #risk #cybersecurity
Wrong, Too Much, or Irrelevant Info: Know Your CyberSecurity Audience 20.03.2023 5:12
Knowing your audience when you're giving information about your #cybersecurity program, efforts, etc. is extremely important. Are they technical? Are they even in the field? Is the information helpful to YOU or to THEM? Make sure you're not wasting their time or yours by taking into consideration to whom you are speaking before you actually speak. On today's #CyberSunday, I talk ab...
The Importance of OpSec: Keep it Secret, Keep it Safe! 06.03.2023 5:24
Operational/Operations Security is the practice of making sure sensitive data/information about your operations doesn't leak out. in today's #CyberSunday, I give a few real examples of OpSec failure I have noticed recently and what some of the consequences could be. #OpSec #cybersecurity
A Couple of Post-Breach Lessons 27.02.2023 4:52
A friend of mine recently experienced a #breach in his organization. There were two lessons that stood out to me as he was going through the post-mortem, and I'm sharing them on today's #cybersunday. #Cybersecurity #lifelessons
Sweating the Small Cyber Things 29.01.2023 5:19
It's flooding a bit in Houston, and that made me... of course... think of #cybersecurity. On today's #CyberSunday, I am talking about making sure you pay attention to the small things in your program, so that they don't turn into bigger things.
Password Managers and Credential Stuffing: Not a Good Combo 16.01.2023 5:20
Credential stuffing is an often-used attack. But for the love of all that is holy, your master password in your password manager should not be susceptible to this!!! Today, I talk about what credential stuffing is, what password manager has been hit by it recently, and generally get grumpy about the whole thing. #CyberSunday #credentialstuffing #bigmistake #cybersecurity
CI/CD OWASP Top 10: What does it mean for you? 05.12.2022 5:33
The CI/CD OWASP Top 10 came out last month (not sure how I missed that!). What does that mean? Well, that depends on what you're responsible for in the CI/CD pipeline! Here are some thoughts form me on the topic on today's #CyberSunday. #cicd #cicdpipelines #owasp #owasptop10 #development #appsec
Holidays: Using This Time to Measure Managed Security Effectiveness 22.11.2022 3:30
The holidays should be a time to celebrate food, friends, and family (and football). Maybe this is also a good time to measure the effectiveness of your #managedsecurity provider. #mdr #securitymetrics #Thanksgiving #cybersecurity #CyberSunday
Setting Cybersecurity Priorities: Perspective Makes a Difference 14.11.2022 5:28
How you set priorities around building a #cybersecurity program differs based on your perspective. On today's #cybersunday , I talk about how the perspective of the advisor must be tempered by the perspective of the practitioner working day-to-day in the trenches. #prioritization #perspective
Asset Management and Vulnerability Management: Pair Them or Not? 09.10.2022 5:05
I was quoted in an article last week about the latest CISA directive on #assetmanagement and #vulnerabilitymanagement (link below). I was the cynical voice in that article, and I wanted to explain a little more on this #CyberSunday about whether these two #cybersecurity #fundamentals should be paired as closely as they are by #CISA . Link to article: https://securityboulevard.com/2022/10/cisa-dire...
Lift and Shift: Not Always Bad 02.10.2022 5:35
In today's #CyberSunday, I go a little outside the normal #cybersecurity discussion and talk about how #liftandshift isn't always negative when it comes to moving workloads into the cloud. I specifically talk about my experiences with a couple of different security vendors (I didn't name anyone specifically) who took different approaches and the positive and negatives associated wit...
Securing Digital Transformation: An Old Problem with Modern Concerns 26.09.2022 5:20
Securing the digital transformation is not a new problem. It is actually an old problem with modern concerns. A lot of people are talking about how concerned they are with machine identities, APIs, IoT, etc.. But these things aren't new. They've actually been in existence for quite a long time. What we're REALLY saying is that these things are proliferating out of control, and they&...
IT and Cybersecurity: the Importance of Knowledge and Empathy 18.09.2022 5:28
Dr. Gerald Auger and I gave a talk last week at the Houston Technology Summit titled "Building Cooperation and Understanding Between Security and IT". We talked a lot about the differences in skills and mission between the two groups, and how there should be more empathy between them. Here's my #CyberSunday quick take on our presentation. #cybersecurity #informationsecurity #informa...
Regulations vs Standards: a.k.a Necessity vs Fundamental 05.09.2022 4:57
Is regulatory compliance fundamental to your #cybersecurity program? In this #CyberSunday, I compare regulations against standards and talk about which one comes before the other. #regulations #compliance
Cybersecurity Products: Innovation vs Need vs Practicality 28.08.2022 5:00
There have a been a few times in the history of #cybersecurity product development when a new solution has been truly innovative. But what is extremely rare is when a tool is innovative, fills a true need, and is practical to install/deploy. In this #cybersunday , I give some examples of what I see as innovative products, talk about whether they filled a big need at the time they came out, and whe...
Discussions from BlackHat: People and Assets 14.08.2022 5:02
There were two big themes from discussions with our customers at #BlackHat. One is a commonly discussed problem these days (lack of people). The other takes us back to the fundamentals of #cybersecurity (asset management). And neither were buzzwords or #vaporware. #CyberSunday #SecurityFundamentals #SkillsShortage #assetmanagement #people
Cybersecurity Conferences: Local vs National and Talks vs Vendors 08.08.2022 4:58
I'm headed out to Vegas tomorrow for the #BlackHat #cybersecurity conference, and it made me think about a couple of questions that have been on my mind for a bit: do you prefer local cons or national cons, and do you mainly go to cons for the talks or checking out the vendors? I weigh in with my opinions (sorta - I'm a bit biased because I run #HouSecCon). What's your take? #CyberS...
Low Code No Code Dev Tools 01.08.2022 4:46
Low-Code/No-Code dev tools are fueling the rise of the "Citizen Developer", but there are real security implications around the tools that enable the non-developer to build applications. I'm just starting to research this more, but here are some of my initial thoughts on today's #CyberSunday . #lowcodenocode #appsec #cybersecurity
Vendor Feature Business Alignment 31.07.2022 4:39
While feature comparisons are important when choosing a #cybersecurity product, what do you do when two products are essentially the same? On this #CyberSunday , I talk about making sure the vendor has #alignment with your business when you've done the rest of your due diligence on features and functionality.
Podcasts similares
Replaio no es editor de podcasts; los nombres de los programas, las portadas y el audio pertenecen a sus autores y se distribuyen a través de canales RSS públicos