YouAttest
#AuditTuesday GRC Podcast
Every Tuesday we're sharing valuable content for you with the leading authorities in GRC, Compliance and Identity Security.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
CPF Coaching: YouAttest Product of the Week for MSPs - Christophe Foulon 10.12.2024 31:13
Lots of products out there for MSPs to review and deploy - that’s why the market appreciates those that review the products for the consultants and managed service providers. This is exactly what Christophe Foulon and CPF Coaching did. They reviewed the products in the identity attestation and identity governance category - specifically w/ an eye to how MSPs would utilize the offering. The off...
HR-IAM Variance - Cleaning out Orphaned and Mis-Aligned Privileges, w/ Karina Klever 10.12.2024 13:34
HR systems for many enterprises is the identity store of record (ISoR). This is where identities are created, roles are assigned, and privileges are entitled. But these HR systems (HRS) are NOT enforcement points – they are the container of entitlements. The enforcement of these entitlements usually falls to identity and access management (IAM) systems. Hence comes the identity variance betwe...
Errors in Cyber Vendor Selection and Vendor Mgmt - w/ David Gilies 13.11.2024 12:32
Selecting a new vendor is wrought w/ problems and failed attempts. The decision is crucial - but the input is flawed. Relying on vendor-lead references leads to a lot of poor buying decisions. #AuditTuesday talks to David Gillies to improve the process. Need to automate your identity audits? Contact us at YouAttest - we will show you how - https://youattest.com/contact/
CISA and The Principle of Least Privilege - Identity Governance w/ David Worthington 13.11.2024 51:40
The world is finally becoming aware of the danger of excess privileges and unmanaged users. These are the accounts that the attackers love to take over and then stay resident in our enterprises and exfiltrate data while going undetected. NIST, the National Institute of Standards and Technology, has created a concept to remedy this situation. They label it the Principle of Least Privilege (NIST CSF...
Black Hat 2024 - Mel Reyes and Shaun Walsh 13.11.2024 51:40
More than 20,000 professionals will go to Black Hat 2024 this year. The who’s who of cyber security, hacking and prevention. Let’s get two professionals’ thoughts on this: Mel Reyes - everyone’s favorite cyber spokesperson Shaun Walsh, Chief Marketing Officer at Peak Nano Need to automate your identity audits? Contact us at YouAttest - we will show you how - https://youattest.com/contact/
The CDK Global (Car Dealership) Hack and the IAM/SSO Connection 13.11.2024 52:19
One of the largest hacks of 2024 is shaping up as the CDK software hack that has affected over 15,000 US and beyond car dealerships. The impact of the attack is affecting the entire U.S. economy -with over the loss could be between $4 billion and $16 billion in sales and depress total retail sales in the U.S. by 2.3 percent. So what was the cause of this attack? How was it related to identities?...
YouAttest Next-Gen IGA on AWS Marketplace w/ CloudArmee - #AuditTuesday 13.11.2024 26:53
AWS is the predominant cloud service for most enterprises w/ over $90B a year and growing. Which warrant security products that are not only designed to work in the AWS marketplace, but could be sold on the AWS marketplace. That’s why YouAttest, the fastest time-to-value next-gen identity governance tool, with dedicated functionality to AWS - is now offered on the AWS marketplace. So let’s learn:...
YouAttest CGEIT Study Session Domain 4 - Featuring Karina Klever and Kelly Gilmore 13.11.2024 1:02:12
Risk Optimization - This session will help you understand the frameworks that assist in governance, and that help an enterprise identify, analyze, monitor, manage, communicate and mitigate IT-relevant business risk.
YouAttest CGEIT Study Session - Summary, Episode 5 - Karina Klever and Kelly Gilmore 13.11.2024 1:04:39
Summary This will be the last session in our 5 part CGEIT prep series. We will summarize all that we have discussed in the past 4 sessions and will answer any questions that you might have regarding the certification exam.
Developing AI? Access Controls Matter - w/ GetSmart Cyber Defense 13.11.2024 43:28
Artificial Intelligence (AI) has revolutionized various industries, and its application in online security is proving to be a game-changer. But how AI is created is not longer a science project - it’s a regulated business. Key aspects of the creation of the AI components must be govern, especially for AI created from data that stems from regulated business. That is: How was the data collected?...
EU'S DORA and Identity Governance - Special Guest: Ralf Menegatti 26.06.2024 51:06
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) solves an important problem in the EU financial regulation. DORA mandates that enterprises augment their protection, detection, containment, recovery and repair capabilities against ICT-related incidents. But what does this mean for your enterprise - and what does this mean for your identity and identity governance efforts? To ans...
YouAttest CGEIT Study Session: Domain 3 - Featuring Karina Klever and Shannon Brewster 20.06.2024 1:03:56
Led by Karina Klever and Shannon Brewster, with assistance from YouAttest CEO Garret Grajek, CEH, CISSP, the sessions will cover Governance of Enterprise, Strategic Management, IT Resources, Benefits Realization and Risk Optimization, just like the exam. Great topic, great hosts, great value - let’s learn together! To learn more about YouAttest and how we can help secure your identities, contact u...
CGEIT Training Session - Domain #2 w/ Karina Klever and Kelly Gilmore 18.06.2024 1:01:25
A 5-part series is helping managers become better managers - starting with learning the basis of the CGEIT certification. (Certified in the Governance of Enterprise IT®) Whether you’re looking for a new career opportunity or want to advance within your existing company, becoming Certified in the Governance of Enterprise IT® proves your expertise in enterprise IT governance, resources, benefits and...
Cybersecurity 80-20 Rule - Start with Identity w/ Michael Andrewes of Yastis 18.06.2024 46:09
The 80/20 rule is crucial to many enterprise and life activities - but what about cybersecurity? Most definitely it is. The 80-20 rule guides us to take our limited resources and focus them on activities that would make the most difference. The same goes for cybersecurity. Michael Andrewes is a cyber and GRC specialist who will dialogue why and how we should focus our limited cyber budgets and...
Limiting the Identity Attack Surface - Red Cup IT Starring Dan Le 28.05.2024 52:19
Attack surface is the rage of cyber security today - we hear we have to reduce our attack surface. But how about the biggest vulnerability - our identities - and thus shouldn’t we be reducing our IDENTITY attack surface. Absolutely we should. Red Cup IT, a premier managed service provider focusing on security and YouAttest, a Next-Gen IGA solution - have teamed up together to reduce the identity a...
Before the Breach - Strategy on Identity Security 25.05.2024 48:08
Breaches happen - especially for enterprises who hold sensitive data: PHI for healthcare, PII for financial institutions and CUI for defense contractors. But what should be our strategy BEFORE the breach? Especially around the reason and most often, the source of the attack - enterprise identities This YouAttest #AuditTuesday podcast will focus on breach prevention with a focus on policy, pra...
CGEIT Training Session - Domain 1 w/ Karina Klever and Kelly Gilmore 25.05.2024 1:01:54
A 5-part series is helping managers become better managers - starting with learning the basis of the CGEIT certification. (Certified in the Governance of Enterprise IT®) Whether you’re looking for a new career opportunity or want to advance within your existing company, becoming Certified in the Governance of Enterprise IT® proves your expertise in enterprise IT governance, resources, benefits a...
Identity Governance in Healthcare - featuring Steve Taccogna 24.05.2024 39:16
This YouAttest Educational #AuditTuesday podcast highlights YouAttest in healthcare. Healthcare is under attack by ransomware groups and other hackers. In response, healthcare enterprises are under new regulations for the holding of identities and other personal healthcare information (PHI). To help explain the value and the functionality of identity Governance, we are lucky to have Steve Taccog...
Change Healthcare Hack: Update - PoLP Matters featuring Carrie Jabs 23.05.2024 12:42
This YouAttest Educational #AuditTuesday podcast discussed the updates known about the biggest hack in the history of U.S. healthcare- the Change Healthcare ransomware attack. It appears the hackers were in the environment for over a week. What does this mean, how does the effect security - and how can this type of attack be mitigated. To help explain the update, we have Carrie Jabs, - Cyber/GR...
Consequences of a MSP Breach - Financial, Legal and Cyber Implications - Featuring Cynthia Stamer, Peter Gailey and John Allen 04.04.2024 1:05:50
Breaches are not new - they affect every industry from A to Z - Advertising to Zoos. What’s new? Now the hacks of the services that manage the IT infrastructure and services are being compromised. These organizations are called MSP (Managed Service Providers) and MSSP (Managed Security Service Providers). Consider these firms as part of the Supply Chain for Technology Services. What are some of...
The Microsoft Email Hack - Service/User Accounts Used for OAUTH SSO w/ Greg Kutzbach 01.03.2024 27:06
Who: Greg Kutzbach, Digital Forensic Expert, Exhibit A Cyber Garret Grajek, CEH, CISSP, CEO of YouAttest Microsoft just suffered a major attack on their internal email systems. The culprits were deemed to be Russian state actors. It appears the attackers overtook “legacy” accounts and created malicious OAUTH access. Cyber forensic expert Greg Kutzbach, an expert on digital discovery,...
Ego and the Start-up Entrepreneur with Professor David Carlson 01.03.2024 29:39
Everyone loves the start-up - but no one loves the ego of the start-up entrepreneurs. It’s not a myth, it’s real and it hurts the endeavor. To explore this real world problem - is start-up expert and author: David Carleson. A seasoned veteran in the problem and author of, “Death By Ego: Lessons From Entrepreneurs Who Successfully Killed Their Companies”. David has researched and is an expert on...
Cyber Security and Cyber Law - Identity Governance w/ Stacey Cameron, Shawn Tuma and Justin Corker 01.03.2024 1:00:26
Cases like the SEC claims against SolarWinds and Tim Brown have made the general public aware that IT has governance and a legal responsibility to identify data. But SolarWinds isn’t the only case in the news - there were 246 class action lawsuits on data breaches in 2023 - and the SEC ruling on 4 day notification is predicted to make this number skyrocket. What are the lawsuits about? What are “d...
Why IGA is Failing Our Enterprises - Stacey Cameron, Mel Reyes, Tom Sabbe 07.02.2024 54:30
IGA has been seen as a failure in many enterprises. Why is this? Why are companies getting hacked for faulty governance? Why are companies being sued for faulting governance? Why are governance improvements in the future? And why do GRC projects never seem to meet expectations? We discuss this w/ Mel Reyes, Stacey Cameron and Tom Sabbe. Mel has execution expertise in delivering Business &...
Cybersecurity and Change Control, focus Identity - with John Young and Kelly Gilmore 31.01.2024 53:59
Cybersecurity is on everyone’s mind - but did you know cybersecurity starts w/ change control? Hackers love sloppy IT and sloppy identity practices? IT cowboys like to slap in changes w/ the rapid process and procedures - this makes the IT practices inviting to hackers who only need a single vulnerability to import their malware and exploit any weakness we give them. To discuss change control and...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.