Secarma

Hacked Off

Hacked Off demystifies the world of cybersecurity. Hosted by Secarma's Managing Director, Holly Grace Williams, it features weekly interviews delving beneath the headlines of the latest hacks, breaches and vulnerabilities, providing expert advice on how to stay safe online. This podcast is brought to you by global cybersecurity and penetration testing company, Secarma.

Author

Secarma

Category

Technology

Podcast website

www.secarma.co.uk

Latest episode

Apr 22, 2024

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

058. Starting Security From Scratch 23.04.2020

Many security guides out there presume that you're implementing security on an existing system or an existing product; look at what has been missed and improving things incrementally - but what if you're building something completely new? If it's a new product or a new company, things can be a different. When you're struggling with security many experts will tell you that you should have started s...

057. Lockdown: Final 16.04.2020

In this episode we follow up on recent news events including the Travelex Ransom payment, fraud linked to Covid-19, and US-Cert Guidance on the cyber risks from North Korea - plus Secarma announce a Charity Support Fund. Key Points: 2'45 Travelex: Paying the Ransom 4'28 Business Continuity and Getting Through Lockdown 5'25 FTC report on Covid-19 Fraud 8'35 Blurring nation states and organised crim...

056. Lockdown: Part 3 09.04.2020

We look into the importance of protecting user privacy and the difficulty of anonymising data - both in regards to COVID19 as well as broadly for businesses. Key Points: 0'45 The benefits of location-tracking 3'15 The risks of location tracking 6'36 Reducing risk through pseudonymisation 10'07 The risk of sharing data 12'00 Balancing benefit and protection 14'10 The 5 Data protection questions Lis...

055. Lockdown: Part 2 02.04.2020

In Lockdown Episode 2 we're talking about video conferencing vulnerabilities, staff complacency, and security awareness risks brought on by job role changes. Key Points: 2'00 Zoom under security researcher scrutiny 6'03 Stealing passwords from video-conferences 9'30 Network architecture and working from home 13'05 Staff complacency and risk 14'35 Job role changes and risk 16'12 Attack surface redu...

054. Lockdown: Part 1 26.03.2020

For this episode we're starting a new mini-series, investigating how recent news events are impacting companies; in part 1 we're looking at performing effective internal infrastructure tests, remotely. Key points: 5'08 Assessing VPN security 6'41 Differences with remote testing 8'30 Our (VOT) Virtual Onsite Testing Solution 9'30 Hackers hacking home WiFi 11'00 Making remote-internal testing effect...

053. COVID-19: The Impact on Your Business 19.03.2020

What do you do when a pandemic hits and you are forced to send your entire workforce to work from home? Is your business ready for the technical and security risks that comes with that? What have you missed? COVID-19 is presenting organisations with new challenges and testing their business continuity plans. Holly Grace Williams talks about these challenges and a few things you may not have alread...

052. An Intro: Wireless Security 12.03.2020

Secarma's Technical Director, Holly Grace Williams, discusses how threat actors could bypass your wireless security through guest WIFI, pre shared keys, or even enterprise wireless security. She talks about the benefits of network segmentation and how your networks may not be as separate as you think! Key Points: 1'20 Network segmentation 3'38 Technologies to protect wireless networks 5'56 Open wi...

051. The Truth about Cybersecurity Marketing Buzzwords! 05.03.2020

There seems to be a colour for all the different types of cybersecurity teams these days, but is there any value behind these marketing buzzwords and what do they really mean? Holly Grace Williams takes us through the different 'team' definitions and how to look beyond their colourful names! Key Points: 1'41 The difference between penetration testing and red teaming 3'25 Red Teaming and Blue Teami...

050. Month in Review: The Redcar and Cleveland Borough Breach 27.02.2020

On Saturday 8th February 2020, Redcar & Cleveland Council was hit with, what is thought to be, ransomware. Holly Grace Williams discusses the wider impact of hacking a council, and the brand damage that can come from this kind of attack. Key points: 1'27 What happened to Redcar & Cleveland Council? 1'50 Do people really understand what ransomware is? 4'll The timing of ransomware attacks 6'44 Why...

049. James Mckinlay: Why I turned antivirus off! 20.02.2020

Is your antivirus working for you? It wasn't for James Mckinlay, the Group Information Security Officer at Barbican Insurance, so he made the controversial decision to switch it off! James discusses why he made this decision and infrastructure he built to replace it. Key points: 1'18 The decision to turn off antivirus 2'35 Alternatives to antivirus 4'10 Application whitelisting 13'28 Cyber Essenti...

048. Cybersecurity Predictions: Do things really change that much? 13.02.2020

Every year we are asked the question, 'what are your cybersecurity predictions for this year?', but is there really any value in predictions and have cybersecurity threats really changed that much over the years? Holly Grace Williams, takes a look back at last years predictions to see how accurate they really were, and to discusses the most prominent threats for 2020. Key points: 3'35 Cloud outage...

047. Mike Koss: Hear no evil, see no evil 03.02.2020

We invite our most popular interviewee of last year, Mike Koss, back into the studio to discuss one of the emerging cyber threats of the modern day – deepfakes. Mike discusses how this machine learning model, fakes content, and the impact it can have on business. Key Points: 0’43 What is a deepfake? 3’32 What fake content might be used for 10’00 Faking audio 14’13 Faking videos 16’56 Faking photos...

046. The Travelex Ransomware Attack 30.01.2020

Ransomware has been around since the 80's and unfortunately, due to it's effectiveness, it's not going away. Holly Grace Williams's discusses the recent Travelex ransomware attack - what we can learn from it, how to deal with being held to ransom and predictions for the future. Key points: 0'35 The Travelex breach 7'14 A two-part ransomware attack 9'17 Keep your systems up to date! 10'41 Why attac...

045. Pauline Norstrom: Who's Watching You? 23.01.2020

According to the BSIA's report on CCTV surveillance, there is approximately 6 million cameras in the UK. But who owns these cameras and how is the data being stored and used? Pauline Norstrom, the Founder & CEO of a boutique consultancy focusing on technology for video surveillance, joins us to discuss facial recognition and the future of AI in the industry. Key points: 0’22 Guest introduction 3’5...

044. Jenny Radcliffe: Hacking the Human 16.01.2020

We are kicking off our new season of the Hacked Off podcast with an interview with Jenny Radcliffe, Founder & Director of Human Factor Security. Jenny speaks to Secarma’s Technical Director Holly Grace Williams, about the fascinating world of social engineering. 0’26 Guest introduction 6’05 Where companies should start with social engineering 9’32 Exploiting the pattern of life 10’56 The importanc...

043. Month in Review - Nov ' 19: The Disney Plus hack 28.11.2019

Catch up on November's cybersecurity news with our month in review. From the Labour Party DDoS attack to the phising attack on the new Disney Plus streaming service, Holly Grace William's discuss the importance of balancing user experience and security. 0'32 Cybersecurity highlights of November 1'05 The Labour Party DDoS attack 7'23 The Disney Plus hack 9'46 Password managers 11'48 Balancing user...

042. Do Pentesters ever Uncover Data Breaches? 21.11.2019

'When you're doing a penetration test, do you ever find hackers?' After receiving this question a few times recently, our Technical Director Holly Grace Williams discusses how likely it is for a pentester to discover that an organisation has been breached and how to deal with this situation. Key points: 1'10 What a pentester will do when they discover a beach 1'46 The signs of a breach 3'05 Differ...

041. Cybersecurity for Black Friday, Cyber Monday & Christmas 14.11.2019

With Black Friday and Cyber Monday only round the corner, Holly Grace Williams talks about cybersecurity during busy retail periods from both a consumer and retailer's point of view. Here's what to keep an eye out for and how to stay safe! 1'49 The NCSC's guidance for Black Friday. 2'47 The kind of phishing attacks consumers need to keep an eye out for. 9'44 Attackers aren't always after your cred...

040. Password Managers vs Multi-Factor Authentication 07.11.2019

After running a poll on Twitter earlier in the year asking "Is SMS based multi-factor authentication better than no multi-factor authentication or should it never be used?", Holly Grace Williams discusses the pros and cons of password managers and multi-factor authentication. Key points: 1'15 How passwords managers work 2'21 The concerns with password managers 4'00 Weighing up the risk 6'29 Two-fa...

039. A Month in Review (Oct '19): The NordVPN Server Breach 31.10.2019

There have been a lot of security breaches this month, including NordVPN, Avast and Adobe all falling victim to cyber crime. Holly Grace Williams takes a look at the NordVPN's server breach, what we can learn from it and then discusses why you might want to choose a Virtual Private Network. Key points: 1'03 The NordVPN breach 2'08 Why use a Virtual Private Network? 4'37 Which VPN should you use? 8...

038. Catching a Hacker! 24.10.2019

Our technical director, Holly Grace, speaks to Ian Murphy the Co-Founder of LMNTRIX about different ways of catching attackers - such as threat hunting, adversarial deception, and threat intelligence. Key Points: 0'32 Guest introduction 1'22 LMNTRIX 3'40 An over reliance on logs 8'44 What is threat hunting? 11'10 Where do you start with threat hunting? 18'30 What is deception? 32'48 Machine learni...

037. Cost vs Risk: Deciding how much to spend on security 17.10.2019

How much should you spend on cybersecurity? Whilst there isn't a definitive answer to this question or a one-size-fits all answer, our Technical Director Holly Grace Williams, takes a look at how to measure your risk to determine an answer suitable for your organisation. 0'39 According to statistics... 2'09 Estimating breach costs 6'19 Cybersecurity insurance 7'53 What's your cybersecurity maturit...

036. Common Cybersecurity Misconceptions 10.10.2019

Secarma’s Technical Director Holly Grace Williams, is joined by Secarma’s People & Event manager Lucy Leaper, to discuss some of the most common cybersecurity misconceptions. From money concerns to the ‘it won’t happen to me’ attitude, Holly debunks certain cybersecurity beliefs, which may be leaving your organisation vulnerable. Key points: 1’00 “There’s no ROI with security testing” 5’39 “Cybers...

035. A month in review (Sept ’19): The New iPhone Vulnerability 01.10.2019

Last month an iPhone bootrom exploit dubbed ‘checkm8’ was discovered by researcher axi0mX. This unpatchable vulnerability could give hackers access to iPhones but is it really something we need to be concerned about? 1’40 The new iPhone vulnerability 4’37 Discovering ‘checkm8’ and how it works 11’30 What we can learn from this vulnerability? 13’36 The price of vulnerabilities – bug bounties and br...

034. Propogating Malware 26.09.2019

For those who missed The Future of Cyber Security in Manchester this week, our Technical Director Holly Grace Williams, presents her talk on malicious software and how automation will increase the impact of malware attacks. She also discusses the conversation she had with the Q&A panel on cybersecurity insurance. Key points: 1'23 Malicious software hasn't really changed 2'06 A look back on some hi...

Listen to the Hacked Off podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.