YouAttest
#AuditTuesday GRC Podcast
Every Tuesday we're sharing valuable content for you with the leading authorities in GRC, Compliance and Identity Security.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
YouAttest “Segregation of Duties” for Identity Security and Compliance w/ Shannon Noonan 27.01.2024 15:16
Segregation of Duties (S.o. D) is a KEY requirement for identity security and compliance. It is a principal requirement for a secure enterprise to fight against insider theft and to combat fraud. But how to automate, repeatedly, across all of your identity resources in a simple, deployable manner? And to execute without a seven figure budget? YouAttest has the answer. With its simple identity plug...
Security Audits - What’s Missing? w/ Dmitriy Sokolovskiy 27.01.2024 17:01
Given the amazing rash of hacks and ransomware attacks over the years - many enterprises are now either considering or beefing up their security audits. But are we getting full value out of these audits - what are we missing? Lending his expertise is Dmitriy Sokolovskiy, Cyber and Start-up Advisor So contact us at YouAttest - we will address your identity audit concerns - https://youattest.co...
What is Insider Threat and How Does GRC Address w/ Carrie Jabs 27.01.2024 6:53
“Insider Threat” is always a topic - and it became even more of a topic with the recent hacks. Why is it such a problem? What tools can be used to mitigate - and what practices should be implemented? This is reviewed in this short video on the topic. Lending his expertise is Carrie Jabs, Cyber and Compliance Specialist. She can be reached at: / carrie-braun-jabs-9790521 So contact us at Y...
Entitlement Audit of AWS for Security and Compliance - Featuring Raj Sawhney 27.01.2024 17:09
AWS is the premier IAAS vendor - AWS is the basis of most enterprise cloud strategy. To help us understand the important of AWS and AWS entitlements the video has Raj Sawhney, Managing Director, IT and Internal Audit, Cybersecurity and Business Process at CDW. But what roles have been created? Who has access? What is the identity security posture of the enterprise AWS server and services? ...
MSPs - It’s Time to Get Outside of the Box w/ Eldon Sprickerhoff 27.01.2024 8:27
Enterprises of all sectors are at the end of their ropes dealing with cyber attacks, ransomware and data breaches. Their only recourse is to hand off more of the cyber duties to outside services. The managed services, e.g. the MSPs and MSSPs, need to step up. But are they? We have one of the leading thought leaders in the managed service space, Eldon Sprickerhoff, sharing his insights. Eldon fo...
Halloween Scary Stories on Identity Hacking w/ Craig Guinasso and Paul Feather 27.01.2024 29:34
The past months have brought us more than just the infamous MGM identity hack - unfortunately much more. Identities themselves are no longer the target now it’s the entire identity infrastructure. To discuss these hacks we have security expert Paul Feather from Compu-netics and security expert Craig Guinasso. YouAttest’s own CEO, Garret Grajek will join in the discussion. These are indeed scary st...
AI and Search - What’s Next w/ David Novick 26.01.2024 14:19
Search has been big business for 30 years - and no one is bigger in the search industry than Google. But with new advances in AI, especially around LLM (Large Language Models), with working examples like Open AIs ChatGPT - is the dominance of Google over? Is there room for new search engines - and could the current Google-type search industry days be numbered? And where do the LLMs fit in sear...
Data Security and Identity Governance w/ Michael Andrewes 23.01.2024 9:14
Data security is foremost on everyone minds w/ ransomware and data attacks occurring daily. But what can be done to secure data? And what role does IGA, identity governance, play in the fight against attacks on data? To shed light on this topic, YouAttest interviewed MIchael Andrewes, a cybersecurity, governance and risk expert, on identity governance relates to data security - on an on-going basi...
CISA and The Principle of Least Privilege w/ CISA Security Advisor: Donald E. Hester 16.01.2024 59:21
The world is finally becoming aware of the danger of excess privileges and unmanaged users. These are the accounts that the attackers love to take over and then stay resident in our enterprises and exfiltrate data while going undetected. NIST, the National Institute of Standards and Technology, has created a concept to remedy this situation. They label it the Principle of Least Privilege (NIST CSF...
Another Okta Attack, Another IAM Attack - What to Do? (With SHI Security SE Josh Gold) 11.01.2024 8:03
First there was the MGM/Caesar’s hacks involving Okta. Then it broke that Okta support session tokens were hacked to break into Cloudflare, BeyondTrust and 1Password. There is no question that Okta installations are under attack - but so are other IAMs. Why are enterprises attacking Okta and the other IAMs? And what can be done? To discuss this and other topics - YouAttest invited noted cyber e...
AI Data and Sloppy Handling Will Get You Sued w/ Malcolm Harkins 11.01.2024 18:06
Everyone is racing to AI. And in the race a lot of data is being collected and not all of it w/ the proper security, controls and governance on these models. And it’s a problem. The 32 TB hack of Microsoft’s data for AI is the latest example. So what are the concerns on AI data and sloppy collection, storage, overall security and of governance. To answer these questions - #AuditTuesday is grat...
How Sloppy Identity Practices are Killing Us with Kevin Moss 11.01.2024 9:49
Identities are the #1 cause and mechanisms for hacks - malware insertion, ransomware and data exfiltration. We discuss this w/ Kevin Moss, a Financial Services expert - specializing in risk management for Fintechs and banking institutions. Kevin Moss is an industry practitioner, board member and advisor. He was Chief Risk Officer at SoFI.. He was previously Executive Vice President and Chief Risk...
The SEC 10-K and Mandated Cybersecurity Messaging w/ DV Subramanyam 11.01.2024 57:34
The “SEC Final Ruling” on cybersecurity and cybersecurity messages in law. The changes include mandatory documentation of cybersecurity practices in their annual 10-K filings. These include details on an adoption of the Risk Management Framework the enterprise utilizes. What does this mean? What is required? To help answer these questions we have DV Subramanyam, CEO of Essert.io. He has a w...
SEC Charges Against SolarWinds and Tim Brown w/ Peter Schawacker 11.01.2024 8:24
A milestone action occurred on October 30th, in the history of cyber and legislation. The U.S. Security Exchange Commission (SEC), moved to prosecute SolarWinds, the software company that was the root cause of major breaches including the infamous 2021 Colonial Pipeline shutdown. The breakthrough action in this case is that the SEC filed charges, not only against SolarWinds, but also against Timo...
GRC 2024 - What to Hope For - What to Expect w/ Carrie Jabs 03.01.2024 11:39
2024 looks to be the year of GRC - w/ multiple forces merging. Companies like SolarWinds being criminally charged for falsifying their identity and security filings - including their CISO. And Zero Trust looming on the horizon and CMMC finally rearing its hedging to formality. To help us on this discussion is Carrie Jabs, Cyber and Compliance Specialist So contact us at YouAttest - we will...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.