Secarma
Hacked Off
Hacked Off demystifies the world of cybersecurity. Hosted by Secarma's Managing Director, Holly Grace Williams, it features weekly interviews delving beneath the headlines of the latest hacks, breaches and vulnerabilities, providing expert advice on how to stay safe online. This podcast is brought to you by global cybersecurity and penetration testing company, Secarma.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
033. The New Cyber Resilience Centre 19.09.2019 36:46
In the last 12 months, 822 cyber dependent crimes were reported into Greater Manchester Police, costing the victims £1.2 million. Neil Jones, the Detective Superintendent of GMP, is speaking to us today to raise awareness about his cyber investigation team and how they can support you after a cyber-attack. He also discusses how the new Cyber Resilience Centre, which is backed by GM police, can hel...
032. An Intro: Vulnerability Management 12.09.2019 36:20
What does vulnerability management, mean to you? How do you deal with these issues and track this information? Our Technical Director, Holly Grace Williams discusses the process of pulling together vulnerability information and how certain industry scoring systems for vulnerabilities can be misleading. Key points: 0’43 Keeping track of vulnerability information 3’30 Vulnerability aggregation 6’10...
031. A Month in Review (Aug ’19): Security Conference Controversy! 05.09.2019 36:54
Introducing our new monthly podcast updating you with the latest cybersecurity news, we kick off ‘A Month in Review’ with some security conference controversy! Our Technical Director Holly Grace Williams discusses the BSides Twitter battle about corporate involvement and the controversial talk Crown Sterling presented at Blackhat. Key points: 1’00 The benefits of security conferences 4’29 The ‘Twi...
030. Why Organisations Struggle with Security Basics 29.08.2019 54:48
Some of the most common cybersecurity issues have been around for decades and whilst basic security practices can help protect organisations against these threats, businesses are still struggling to implement security basics. We talk phishing, patching and supply chain risk with the new Head of InfoSec at The University of Salford, Greg van der Gaast and why organisations need to be playing the lo...
029. Leveraging Cybersecurity to Boost Your SME 22.08.2019 44:29
Cybersecurity isn’t just a barrier. If leveraged correctly, it can help to improve and grow your business. The Cyber Foundry project, a European regional development fund program, has been designed to encourage and demonstrate to SMEs how to do just that. In this episode, we speak to the Project Manager of The University of Manchester, Brian Higgins, who runs us through delivering this unique init...
028. An Intro: Election Security 15.08.2019 32:22
In 2016 it was reported that the Russian government targeted the US election system, and whilst there wasn’t any evidence that votes were tampered with, they could have changed data or even deleted voters. With the start of the US presidential 2020 election campaigns, we take a look at why you’d want to hack an election and the pros and cons of online voting. Key points: 1’00 Why would you want to...
027. Getting a Cybersecurity Advisor 08.08.2019 35:22
Ever wondered if you should be hiring a cybersecurity advisor or CISO, or whether the roles you currently have in place are right for your organisation? Mark Avery, Independent Cybersecurity Advisor, talks about the different CISO options, the pros and cons of these roles and how they can help support your organisation. He also discusses the challenges of the CISO role. How it is often misundersto...
026. The Benefits of Building a Peer Network in Cybersecurity 01.08.2019 47:54
Book author, founder of the IN Security movement, judge to numerous awards in business, books and security; Jane Frankland has worn many hats over her 22 years in cybersecurity. She talks with passion about her work with leaders and women in cybersecurity, helping them build enviable and impactful results, going from being burnt out and under appreciated to being motivated, connected and sought af...
025. The Misconceptions of the British Airways Breach 25.07.2019 28:58
Whilst the British Airways breach of 2018 is 'old news' it has been bought to the fore front of everyone's mind with the recent announcement that they face a record-breaking GDPR fine of £183 million. Secarma's Technical Director discusses what we know about the BA breach, the misconceptions over what may have happened and the remediation steps you can take after a data breach. 2'25 - What happene...
024: Security in the ‘good old days’ and the future of the CISO role 18.07.2019 59:58
Mike Koss, Head of Security and Risk at N Brown Group reminisces about the ‘good old days’ when security was just a hobbyist thing, his career in IT security and how he believes the future of the CISO role it should be developed into a business position and a separate technical position. Key points include: 0’30 Guest introduction 1’38 IT security in retail 11’21 Security relationships with the bo...
023. The different challenges of the CISO role 11.07.2019 54:54
Secarma’s Technical Director Holly Grace Williams speaks to Mo Ahddoud Security Consultant and interim CISO, about his vast experience in the cybersecurity industry. They cover everything from the difference between a Security Manger and CISO role, the benefits of working with start ups and a little bit about his experience working with critical infrastructure. 0’49 Guest introduction 1’50 The Sec...
022. Certifications and Upskilling in Cybersecurity & IT 04.07.2019 42:09
We talk to Zeshan Sattar, Director of Learning & Skills Certification at CompTIA, about how organisations like CompTIA can help people not only in getting certified, but reskilling, upskilling and networking within IT and Cybersecurity. 1’53 What is CompTIA? 6’00 Developing the exams with industry experts 8’24 Continuing professional development with certifications 13’56 Who are these certificatio...
021. Thomas Ballin: The Evolution of Penetration Testing 27.06.2019 47:39
We talk to Senior Security Consultant Thomas Ballin, on what he thinks are the major facets of red team engagements, how they can differ by provider or scenario, and how he thinks they might evolve over time. 0’32 Thomas’ unconventional route into the cybersecurity industry and his role at Secarma 4’31 The many ‘definitions’ of penetration testing 7’30 The benefits of red teaming and where to star...
020. Malicious Software – Past, Present & Future 20.06.2019 33:18
We take a look at the history of malicious software, some of the oldest known attacks and how it has changed over the years. Holly also speaks about her own personal experience of the 2017 Notpetya attack and predicts what the future holds for malicious software attacks. It doesn’t look good… 1’22 Different types of malicious software 5’33 The oldest known malware attacks 12’13 Dealing with the No...
019. Cybersecurity Maturity Assessments 13.06.2019 38:49
We share the talk we presented at UKFast’s recent Cybersecurity 101 workshop, in a little more detail, discussing where companies should start with cybersecurity and how they can be comfortable that they have covered a broad enough area of security to be safe. 1’41 What is Cyber Essentials and is it right for your company? 5’57 Risk management – building a security culture and getting the board in...
018. Your Security Awareness Training isn't Working 06.06.2019 36:19
Just 27% of businesses in the UK reported that staff had attended internal or external training on cybersecurity in the last 12 months* and more often than not, what is being taught is either incomplete or no longer relevant. This talk, which our Technical Director Holly Grace Williams presented at InfoSecurity Europe, discusses the miseducation of cybersecurity aspects such as physical security,...
017. Equifax Breach: The Inside Story 30.05.2019 43:10
In 2017 Equifax, one of the largest credit agencies in the world, became the victim of a major breach resulting in over 150 million records being stolen. In this podcast we speak to Graeme Payne, the CIO of Equifax during their breach about the lessons learnt and his personal experience. 0’48 Graeme Payne, guest introduction 3’48 The timeline of the Equifax breach 6’47 How incident planning can he...
016. An Intro: A Checklist for Security 23.05.2019 18:50
Looking to take the first steps to ensuring your business is secure but not sure where to start? Holly Grace takes a fresh look at some basic, fundamental security steps that every business should be adopting. Highlights include: 0’53 Software updates 2’08 Passwords 4’06 Network Segmentation 5’40 Manage out of band 6’26 If you don’t need it, disable it! 8’58 Pre-shared keys 10’09 Network access co...
015. An Intro: The Stages of Penetration Testing 16.05.2019 15:21
We’ve previously discussed the difference between Penetration Testing and Red Teaming, so in this episode we delve a little deeper into the different stages of PenTesting. For organisations who are considering this security assessment, it’s is an excellent starting point to better understand the process. The discussion includes: 2’00 What is a Penetration Test? 3’02 How is it performed? 5’03 An ex...
014. An Intro: Hardware Hacking 09.05.2019 11:28
The ‘Internet of Things’ is evolving fast and more and more companies are seeing the value it can bring by increasing business productivity and efficiency. However, adding IOT devices to a company can increase security vulnerabilities in a way that businesses might not have considered. We take a look at hardware hacking as an aspect of penetration testing and how IoT can affect an organisation's s...
013. An Intro: Cloud Security Testing 02.05.2019 10:25
Cloud computing offers many benefits, such as scalability and elasticity; but with new technologies and terminologies some companies worry about the security implications. In this week's episode Holly Grace gives us an intro to Cloud Security Testing perspectives. Here's what she covers: 0’52 Perspectives when looking at Cloud hosted systems 3’15 Where are things the same? 4’41 Where do we start i...
012. An Intro: Is a bug bounty program right for your business? 25.04.2019 16:47
In 2018 it was reported that there had been a 36% increase in total bug bounty payouts*, but does this mean this kind of security testing is best for your business? We take a look at the pros and cons of bug bounty programs and how it compares to penetration testing. Key points include: 1’13 A brief definition of penetration testing and bug bounties 1’53 How the costing works 3’05 The difference b...
011. An Intro: Social Engineering and Physical Access 18.04.2019 32:26
Security risks aren’t always found through vulnerability scanning and hacking. Holly Grace talks us through how physical access testing and social engineering can be used to demonstrate security risks in a target organisation. This introduction to social engineering talks about how these assessments are performed and their benefits, through some funny on-the-job stories. 1’43 What is social engine...
010. An Intro: Becoming a Penetration Tester 11.04.2019 11:08
We’re often asked about the career pathway to becoming an ethical hacker, or penetration tester. So, we thought it would be best to let a current penetration tester share her thoughts on working in the industry. Whether you’re interested in penetration testing, computer science or security in general, Holly Grace's intro to becoming a penetration tester is packed full of tips you can use when gett...
009. An Intro: Penetration Testing vs Red Teaming 04.04.2019 8:48
You’ve probably heard of the term ‘penetration testing’ and ‘red teaming’, but are you clear about what they really mean? Our Principal Security Consultant, Holly Grace Williams talks us through the difference between these two security tests, elaborating why you’d choose them, how they work and the benefits of each one. 1’44 What is penetration testing? 3’55 What is a Red Team engagement? 7’42 Su...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.