LBMC

Cybersecurity Sense

Welcome to Cybersecurity Sense, the podcast where real-world security meets practical insights. Hosted by LBMC's Mark Burnette, this show goes beyond compliance checklists to explore the fast-moving world of cybersecurity.

Author

LBMC

Category

Technology

Latest episode

Dec 2, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Phishing Emails with 100% Click Rate 10.04.2018

In a recent report from Wombat Security Technologies based on data from millions of simulated phishing attacks, it was found that 76% of organizations said they experienced phishing attacks in 2017, and nearly half of information security professionals said that the rate of attacks increased from 2016 to 2017. F-Secure also recently released research data indicating that over one-third of security...

IIA Knoxville—Implementing Cloud-Managed Security 10.04.2018

When cloud-managed security was first introduced, there was some concern about the levels of security as compared to the security of data on an organization's premises. Today, security professionals have implemented the appropriate controls to help could-based data management be safe and effective. As many organizations are now embracing and migrating to the cloud, it is important to know the risk...

IIA Knoxville—Risky Business 19.03.2018

No matter the industry—government, healthcare, financial, or even smaller, mom-and-pop businesses—each deal with some type of sensitive customer information, and each has decisions to make when it comes to managing risk. Most security and audit frameworks (HIPAA, ISO, PCI, NIST, SOC 2, etc.) have requirements for risk assessment, making them one of the first things auditors or regulators ask for....

IIA Knoxville—Dear President Trump: How to Secure the United States & Demonstrate That Your Company Is 12.03.2018

In the information security world, we all wish we had more access to senior executives. Following that logic, if you're responsible for security at your organization, and you are lucky enough to ride on the same elevator with a senior executive from your company, you should be prepared with your "elevator pitch" on what to say about improving the cybersecurity posture of the organization. When ask...

IIA Knoxville—SOC for Cybersecurity 05.03.2018

The AICPA Cybersecurity Working Group brought to life a new type of cybersecurity examination report in 2017 known as SOC (System and Organization Control) for Cybersecurity. These reports are intended to provide a consistent approach for evaluating and reporting on an entity's cybersecurity risk management program and give management the ability to consistently describe its cybersecurity risk man...

5 Reasons Why Organizations Don't Detect a Cyber Breach 18.01.2018

Incident response consultants are often contacted by clients who are in complete shock that their systems or networks have been compromised. Many times, these clients are hoping our analysis will ultimately prove that the incident was just a "flesh wound" to their systems and that they didn't experience an actual data breach. It's quite common for organizations to assume that data breaches won't h...

2017 Year-End Healthcare Breach Review 12.01.2018

In comparison to previous years, 2017 was a good year as the number of healthcare records compromised was significantly down. As of December 30, there had been 341 breaches reported, affecting a little less than 5 million individuals. This compares to 327 breach reports in 2016 but with 16.6 million individuals affected. When this information is contrasted with 2015 statistics, fewer breaches (268...

Law Firms are Cybersecurity Targets 19.12.2017

A recent report from cybersecurity firm, FireEye revealed that Chinese hackers have been actively targeting a shortlist of multinational law firms since at least June of 2017. This was an apparent effort to spy on lawyers and steal confidential information, proving that not only are law firms targets of nation states, but attackers are also keeping up with current news, using well-designed phishin...

SOC for Cybersecurity 12.12.2017

Since business leaders and board members are not often technically-inclined, they tend to have many questions about cybersecurity. Because of this, the AICPA recently recognized the need for a new type of cybersecurity examination report and put together a task force to bring to life what's now known as SOC (System and Organization Control) for Cybersecurity. These reports will be beneficial in gi...

Information Security Questions for SMBs 05.12.2017

A key observation that can be made within the information security industry today is that cybersecurity is not extremely difficult, it is just hard and requires long-term dedication, focus, and commitment. Considering this observation, a key question all cybersecurity professionals must ask is, "If you don't know where you are, how do you know where you need to improve?" Knowing the answer to this...

Cloud Storage and User Authentication Compromises: Managing the Integrity of Your Data 27.11.2017

Often in the information security industry, professionals can be accused of spreading fear, uncertainty, and doubt with cybersecurity concerns. However, considering the implications of integrity attacks, it is essential to pay close attention to them. As more organizations move to cloud storage, user authentication compromises are increasing. If an organization has sensitive information that can b...

Manufacturing and Industrial Sectors Are Cybersecurity Targets 13.11.2017

As operational technology (OT) networks are used with specialized Industrial Control Systems (ICS) to monitor and control physical processes such as assembly lines, mixing tanks, and blast furnaces, these networks have become ripe targets for adversaries. The lack of basic protections like antivirus can enable attackers to quietly perform reconnaissance before sabotaging these physical processes a...

Attacking the InfoSec Supply Chain 01.11.2017

Though not in the recent limelight, it's no secret that espionage from nation states is happening once again. With sophisticated attacks on InfoSec supply chain companies in 2012, 2013—and as recently as the past few months—many people are left wondering who would target these specific companies? In the end, we know that despite agreements between countries, we have valuable intel within the Unite...

Kaspersky vs the U.S. Government 02.10.2017

For the past 20 years, Kaspersky Lab has provided deep threat intelligence and security expertise for businesses, critical infrastructure, governments, and consumers around the globe. More than 400 million users benefit from protection services provided by Kaspersky, in addition to approximately 270,000 corporate clients. Recently, Kaspersky has found itself under question from the U.S. Government...

Ransomware and Unintended Disclosure 24.09.2017

When an organization experiences a data breach, one would hope that a quick recovery is ideal, right? But, did you know that there are instances when a quick breach recovery can hurt an organization? For one healthcare facility, this was the case, as it fell prey to a ransomware attack. While the organization was able to quickly recover operations, it recovered so quickly that it failed to preserv...

Risks Rising for Email Data Breaches 14.09.2017

Sadly, email data breaches continue to be an increasing problem for businesses and organizations who retain large amounts of sensitive client and customer data. In fact, more than 700 million email accounts and millions of associated passwords were recently leaked in the biggest spambot dump ever. Breaches of this scale and impact have happened to Dropbox, LinkedIn, and Adobe in the past few years...

The Risks of Remote Access 28.08.2017

Remote access to networks has become commonplace in today's IT environments, as this access is mainly used for IT support, power users, and developers. While this capability can be provided in a safe and secure manner, it can also be deployed in a manner that leaves the organization at great risk. When Remote Desktop is enabled, attackers can brute force administrator credentials, because you can'...

Attacker Dwell Time 22.08.2017

Especially for healthcare IT systems, cyber attacks can lead to the exposure of patient data, service disruptions, time-consuming recovery processes, and high costs in the form of paying a ransom or spending money on new servers, security systems, or consultants. However, that is only when an organization is aware of the breach. Some network breaches can go on for months or even years before an or...

Combating Insider Threats 08.08.2017

It's true—insider threat events are typically much less frequent than external attacks. However, insider threats often pose a much higher severity of risk for organizations when they do happen. As insiders are given access to sensitive information for work purposes, there's a great potential for them to do a tremendous amount of damage to a business if they accidentally break policy or choose to s...

Business Email Compromise: When The Threat is Internal 08.08.2017

Since January of 2015, all 50 of the United States have reported an increase in business email compromise (BEC) attacks—a 1,300 percent increase, to be exact. Even worse, organizations have reported a loss of nearly one billion dollars. With everyone now being a potential target, it's been noted that reconnaissance, social media, and social engineering has played a crucial role, as cyber thieves m...

How To Create SIEM ROI 01.08.2017

SIEM, or security information & event management, is becoming a fairly common security control these days. It focuses on aggregation and analysis of log data. For this podcast we will assume you have a basic understanding of SIEM and how it's commonly deployed. If you don't have that base-level of understanding, you might want to check out one of our other podcasts that focuses on SIEM fundamental...

The Value of Incident Response Table Top Exercises 26.07.2017

Are you prepared for a ransomware attack? Bill Dean, Senior Manager, LBMC Information Security, discusses a low-cost approach method to determine how well you will respond to computer cybersecurity incidents, similar to those that you are reading about in the news, by performing incident response tabletop exercises. 

Listen to the Cybersecurity Sense podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.