ink8r
Ink8r (in·cu·ba·tor) Podcast
A podcast covering socio-technical themes, concepts, and technologies that matter to the modern enterprise
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode #29 - Tackling the biggest problem affecting code … dependency lifecycle management 02.05.2023 27:20
As it turns out, managing Open Source Software (OSS) dependencies is extremely difficult. Not all vulnerabilities are in runtime and/or reachable, not all exploits focus on high/critical CVSS, there is a time delay with patches when they are made available, and Semantic Versioning (SerVer) can make prioritization challenging when thinking through backward compatibility, upgrade paths, version pin...
Episode #28 - A discussion of data cloud economies and security, with Navindra Yadav 24.04.2023 26:49
Data platforms are evolving, allowing data clouds to connect with consumers and producers of data that may be external or internal to your organization. Sharing with upstream/downstream partners in this data economy presents significant challenges to protecting data. Join us as we discuss this economy and the security implications, with Navindra Yadav, CEO & Co-Founder of Theom.
Episode #27 - Promoting Open Standards Observability at a massive scale 03.04.2023 38:30
Nobody understands observability at scale quite like Chronosphere co-founders Martin Mao (CEO) and Rob Skillington (CTO). While at Uber they created, and open-sourced, the M3 metrics engine, which was capable of handling billions of data points that describe the most complex environments. Then, in 2019, they founded Chronosphere which is now valued at over a billion dollars. Chronosphere focuses...
Episode #26 - An Insider Threat Platform that Protects Individual Privacy 27.03.2023 34:31
When considering an Insider Risk Management (IRM) program a confluence of events complicates effective execution, including a general increase in financial hardship due to the current economic climate, an increasingly remote corporate workforce, steady growth in the gig economy, privacy concerns regarding individual liberties, and negative perceptions of organizations developing a 'surveillin...
Episode #25 - Helping Defenders focus on exceptions by offloading day-to-day, with StrikeReady 26.03.2023 40:50
The annual Cybersecurity Workforce Study conducted by (ISC)² modeled the existing talent shortage as 3.4 million professionals in 2022, up 26% from their 2021 study. The purchasing of a multitude of security products to offset skill gaps can fall short as operators struggle to adapt processes and extract value from toolchains that may or may not be flexible in handling an evolving threat landsca...
Episode #24 - Unifying Security Technology and Human Intelligence with Synack 08.03.2023 29:51
Disrupting traditional security testing approaches is where Synack specializes. They have long recognized that to thwart attacks in modern adversarial campaigns requires a maximal combined talent of human and AI-powered intelligence. Through the gamification and use of crowdsourced expertise across verifiable exercises, Synack leverages its Synack Red Team (SRT), a global network of ethical hacke...
Episode #23 - Cyber Defense Services Forged from the Front Lines 19.02.2023 25:52
At its core, BlueVoyant offers MDR and managed SIEM services for Splunk and Microsoft Sentinel, though they also provide EDR services, 24/7 security monitoring, alert investigations & incident response, forensics & litigation support, attacker simulation & penetration testing, supply chain defense, dark web investigations, compliance services, vulnerability assessments and remediation,...
Episode #22 - Operating at the nexus of Observability & Security data 30.01.2023 30:56
Cribl provides a real-time data stream management platform for MELT data that enables organizations to gain insights and take action on data in place (right at the source), data at rest (already stored in a data lake), and eventually data in motion (transitioning an observability pipeline). Back in May 2022 Clint and the C021 team signaled that they would be turning search on its head, and in Nov...
Episode #21 - Automating continuous Classifying, Modeling, & Auditing of data actions with Theom 06.11.2022 36:09
We at Ink8r have long been advocates for calibrating protection against threat modeling exercises to properly align protection for assets. When it comes to securing production resources in the cloud this often means extending beyond Cloud Security Posture Management (CSPM) and including Data Security Posture Management (DSPM), among other capabilities, to properly address threats. With Theom we...
Episode #19 - Constructing a versatile SSDLC pipeline that can simply do more 11.10.2022 46:59
How many pipelines does my organization need? What pipeline construction patterns are most acceptable to my developers? What intelligence should I inject into the pipeline? Nick Durkin, Field CTO & VP of Field Engineering from Harness answers these and more. Join us in this episode as we unpack some philosophical areas of SSDLC architecture, while diving into the Harness portfolio to see h...
Episode #18 - To truly understand the pervasive use of SaaS in your enterprise, turn to SSCP 21.09.2022 37:19
Enterprises rely on dozens to hundreds of Software-as-a-Service (SaaS) applications, both sanctioned and unsanctioned, for their workloads, data, and processes. This attack surface requires SaaS Security Posture Management (SSPM) to protect the enterprise, but how do enterprises truly discover all of the SaaS apps in use (particularly those unsanctioned SaaS apps)? Traditionally enterprises have...
Episode #16 - Harmonizing your AppSecOps Program 07.08.2022 47:50
Application delivery velocity is driving a need to bolster an organization's existing software security posture. One fundamental aspect in fortifying an AppSec strategy is to leverage the API’s of existing application portfolio management solutions, code repositories, open source code scanning, static code scanning, credential scanning, image scanning, and various dynamic application securi...
Episode #15 - Reimagining Observability and making it viable 02.07.2022 39:14
We heard a great quote at RESOLVE'22 this year which said, "customers pay for up time and companies pay for downtime". A rather adroit quote, and one that truly captures the Sisyphean challenge of ensuring applications are performant in the way we expect. When it comes to the Herculean task (wow - two mythological references in one opener!) of making modern observability viable, t...
Episode #14 - Enabling Collaborative IaC with specialized CICD 30.06.2022 34:40
Many, if not most, organizations operate as polyglots - polyglot environments, polyglot programming languages, polyglot persistence, and so on. Infrastructure-as-Code (IaC) automation is no exception to this complexity with organizations often supporting polyglot IaC CICD tooling. Teams introduce this variability to achieve specific ends as some frameworks are great for one task but not another...
Episode #13 - Running MELT through analytics at the edge 30.06.2022 46:00
There is always tremendous value in decreasing latency in any decision-making process, particularly when we are dealing with stream processing in support of system and application observability. By running Metrics, Events, Logs, and Trace (MELT) data through an analytics algorithm at time of creation, on the very devices emitting the signals, organizations can set parameters on what information i...
Episode #17 - An Observability breakout session from Resolve '22, with the Ink8r Team 02.06.2022 44:54
Satbir and Darren were interviewed in a breakout session at Resolve '22, a BigPanda-organized community event. It was a wonderful opportunity for the Ink8r team to share thoughts on the domain of Observability, as directed by Aaron Johnson (BigPanda SE). Join us in this episode as we cover topics such as the consequences of not starting a journey, key measurements to get started, finding y...
Episode #12 - Using AI to baseline good behavior to block malicious email 29.05.2022 34:04
Social engineering attacks such as Business Email Compromise (BEC), supply chain fraud, executive impersonation, and ransomware, are complex vectors that readily evade solutions that rely on conventional threat intelligence and known bad indicators. Modern attacks frequently bypass secure email gateways as they may come from trusted sources and do not contain malicious links or attachments. Abnor...
Episode #10 - Cloud-native security with a rules-optional intelligence platform 29.05.2022 42:06
Lacework has a patented platform, Polygraph Data Platform, which ingests data, analyzes behavior, and detects anomalies across an organization’s multi-cloud environment. Lacework continuously monitors user, app, process, and network behavior, as well as continuously evaluating vulnerabilities and cloud configurations. They use an agent and agentless approach to collect information to uncover unu...
Episode #11 - Building data security into DevOps infrastructure 28.05.2022 33:17
In the modern enterprise data spans multiple cloud providers, regions, databases, object stores, and data lakes. Users, developers, supply-chain vendors, and contractors all access data via multiple roles and applications. In a truly dynamic environment where developers instantiate instances, organizations need to be able to visualize how data flows, who is accessing that data, and how that data...
Episode #8 - Build trust in your software with the leader in AppSec 15.05.2022 47:04
Synopsys is a leader in Gartner’s Magic Quadrant for Application Security Testing (AST) for the 6th straight year. Their portfolio is among the most comprehensive in the market, supplementing the foundational aspects of AST with an acquired portfolio of award-winning products including SAST, DAST, IAST, and SCA - with advanced capabilities such as protocol fuzzing and API protection. Join us as...
Episode #7 - Protecting API business logic & vulnerabilities with Cequence Security 15.05.2022 38:17
Cequence Security understands API attack surfaces, protecting upwards of 6 billion API transactions on any given day. In this podcast episode, we speak with Vince Bryant, Senior Director of Business Development of Cequence Security. In an age characterized by velocity in execution, Cequence will be the first to state that, "digital transformation from the inside looks pretty messy". I...
Episode #6 - Moving Beyond Observability with Aaron Johnson 12.05.2022 47:39
As we begin emitting more signals from more endpoints in servitude of more complex transactions, it becomes clear that being observable isn't enough. Join us as we talk with Aaron Johnson (AJ), BigPanda as we explore the nature of correlation as a key component to ensuring services perform as intended. AJ has deep practitioner/leadership experience at companies performing correlation at sc...
Episode #5 - At the intersection of Observability and Security 30.04.2022 44:11
It’s in their DNA - sysdig (lower case ’s’) started as an open source troubleshooting tool, and the company has maintained that commitment to community. They donated Falco to CNCF as an incubating project with contributors that include AWS, Google, Microsoft, Cisco, and VMware, they leverage projects such as CloudCustodian in their cloud posture capability, and provide PromQL support for deep ana...
Episode #4 - Why Proactive API Security is Today's Imperative 11.04.2022 45:16
APIs have become the largest abuse vector with even the most sophisticated development organizations falling prey to exposure. This episode of the podcast discusses the landscape and where organizations can begin securing their interfaces with Matt Tesauro, Distinguished Engineer at Noname Security providing pragmatic advice.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.