Greg Young & Bill Malik
Real CyberSecurity
The Real Cybersecurity Podcast decrypts the issues and business of technology security. But instead of just scaring you, these industry veterans provide real advice and analysis for organizations trying to make security real today. Hosted by Greg Young and Bill Malik.
Author
Greg Young & Bill Malik
Category
Podcast website
Latest episode
Dec 14, 2023
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 27 - How Virtual Cybersecurity Conferences Can Be Better. And Zoom Backgrounds 01.06.2021 36:07
Was in-person RSAC only a year ago? Selling passwords for candy bars, thinking back to RSA 2020, the good and bad of virtual events, and green M&Ms. Virtual cybersecurity events need to be a rethinking of the event format, not the worst of both worlds. And stop recording sessions months in advance. And Zoom backgrounds.
Episode 26 - 6G Security! Oh yeah and 5G Security. And Connected Cars. 23.04.2021 17:38
Greg talks 6G security, allowing Bill to explain the real cybersecurity of 5G security. this leads us to the nexus with how the next gen of communications will need trustworthiness for connected cars.
Episode 25 - SolarBurst, Commander Elon, Supply Chain Attacks, and Hoodies 09.03.2021 42:54
Bill and Greg dissect parts of the SolarBurst and water filtration hacks, and Bill confirms that all criminals wear hoodies so Greg proposes banning hoodies. We cover the issues of Supply Chain security.
Episode 24 - Guest: Brian Reed Talks Data Loss Prevention (DLP), and Working at Gartner 15.01.2021 52:25
Brian Reed is proof that you can be smart, nice, a great father, and successful in security. Brian is a long time Atlantan (the city in Georgia, not the underwater one) and has been doing security IBM, ISS, Gartner and Proofpoint. Brian talks about: - 2021 and the nexus between the upsides of DLP and the risks to privacy and surveillance if not done right. - Remote working and security. - Bill&ap...
Episode 23 - Backdoors, 5G Causes Security, & Security Clown Factories 08.01.2021 35:16
Bill shines a flashlight on the truth about 5G radiation, and shares his chicken recipes to demonstrate the difference in spiciness. We get seriousness about the security relationship between IoT and 5G and why they are so closely linked. Bill says good things about Christopher Krebs. Greg explains that investors and products buyers look at security companies differently. Greg laments the greed-o...
Episode 22 - Interview with John Pescatore of SANS 12.11.2020 53:43
Greg and Bill interview John Pescatore from SANS about what's going on in the whacky world of cybersecurity. We cover a lot of ground including the breadcrumbs that attackers leave, the history of SANS, what are the big topics in the SANS community, Zero Trust, supply chain security, 2FA - why isn't it standard?, bug bounty programs, and the idea for a Netflix reality series called "...
Episode 21 - Hacked Car Things, PrezentationKraft, & Sanctioned by A Foreign Government 31.08.2020 41:04
Bill updates us on some recent threat and vulnerability reports. Greg thinks that all CIOs need an animatronic CISO hype-man, and that people would pay money to have sanctions against them announced by an evil foreign government. Our oddball segment of the day is what mugs we have on our desk. How we build and deliver a great security presentation, but we talk about when we bombed. Bill says Moby...
Episode 20 - Live from Black Hat, Election Security Is Easy, Rogue Robots 10.08.2020 37:29
Live (virtually) from Black Hat we give an update on what is being focused on. We agree that presenting without a live audience requires a different approach than live stage presentations. Bill reaches for smelling salts when confronted with rogue industrial robots, and Greg thinks secure voting is easy. Yes, really.
Episode 19 - The Twitter Breach & Bitcoin, and Occam's Dumb Brother 29.07.2020 42:35
Bill and Greg cover the recent Twitter breach and try and unpack what maybe happened and what lessons we can learn from it. We invent a security axiom of "Occam's Younger Dumber Brother's Razor". We recount some insider cases, how too often good deeds are punished, and we give some career advice. And what is becoming a regular segment, we disclose what we're currently read...
Episode 18 - Foundations of Cloud Security, & Impacts of 5G and Cloud Garbage Collection 29.06.2020 41:36
We take a helicopter up a few thousand feet to suss out what cloud security is really about. What security problems does cloud fix? What security problems does it introduce? One hypothesis is that a lot of IT is unnecessarily 'custom', and so is the security with it. The reality in the world is there is still a lot of on-premises IT, multi-cloud, and shadow IT today. Bill brings up th...
Episode 17 - Big Trouble in Privacy and Surveillance, and the Cybersecurity "Channel" 11.06.2020 47:34
Current events are highlighting the nasty issues around privacy and broad surveillance. As some companies announce they will no longer support certain applications of facial recognition we discuss the shift in privacy to being up to the individual. We talk about "The Channel" during the week when Canalys releases their annual Global Cybersecurity Matrix. No not TV channels, but the c...
Episode 16 - Facebook Jail, Cybersecurity Lies, & Why You Don't Have to Speak at Sec Cons 02.06.2020 45:22
We discuss the issues of dishonesty in cybersecurity marketing, that it's OK to not speak at security conferences, a bunch of non-traditional book references for cybersecurity, and our favorite conferences . And Bill ends up in Facebook jail for crimes involving cat videos.
Episode 15 - Security Artificial Intelligence and False Positives, and Election Security 21.05.2020 43:44
Bill gets thrown in Facebook jail for crimes involving cat videos. We talk about how the importance minimizing Peak awesomeness is achieved when Bill gives us the security book recommendations from our listeners. And we lose our minds and go on a security book recommendation binge ourselves. We revisit election security. Greg has false negative brain syndrome because gets his spies mixed up (A...
Episode 14 - MITRE ATT&CK and Voting Security 12.05.2020 50:30
We return after Bill has recovered from a denial of service attack, and cover the basics of where MITRE ATT&CK fits into the security world, and how Greg is a fan of it after his initial skepticism. Where does IoT fit into MITRE? Bill poses a big question - is remote voting security possible? We agree that ML and AI in automated screening out of job candidates is a garbage practice, and fini...
Episode 13 - Secrets for Success and Failure for CISOs, and What XDR Is 22.04.2020 41:52
We kick off with much discussion on CISOs: the secrets and qualities of successful them, where they fit into the org chart and their role and how that has changed. XDR - what is it? We try and parse out what XDR means vs platforms, how it helps threat hunting, and how it deals with issues such as alert fatigue, and obfuscation. We also hear that Greg got a haircut from a professional stylist dur...
Episode 12 - Zoom Security, Spy Movies, and Lockpicking 14.04.2020 29:12
There's a lot of discussion about webconferencing security, so we do some more! We agree on and name the must-see movie about spies, the difference between stealth and force in locks and lockpicking, attackers playing the long game, and Bill mentions the Mythical Man Month (which is not a statutory holiday). The podcast Greg mentioned was "I Spy" by Foreign Policy. https://open.sp...
Episode 11 - Worst Security Practices, and Supply Chain Integrity 08.04.2020 43:28
This week we cover a few hot topics and it's a good one. Supply chain integrity is a big one. And we talk worst security practices. No, we aren't recommending these. We discuss about why Y2K provides us with lessons we need. Bill tells a great story about back up tape retrieval and airports, and some good advice on consequences and clear code. Greg relates the story of tampered typewr...
Episode 10 - Telework & Security - Interview with John Girard (Part 2 of 2) 31.03.2020 44:49
Telework is a big topic right now, and with any big topic we need to answer the questions about security. Who better to bring on and chat than John Girard? Recently retired (although up to more mischief than ever) John spent 25 years at Gartner, leading topics like SSL VPNs and mobile device management. So join John and us talk about telework security, but also some non-security telework advice...
Episode 9 - Telework & Security - Interview with John Girard (Part 1 of 2) 25.03.2020 34:08
Telework is a big topic right now, and with any big topic we need to answer the questions about security. Who better to bring on and chat than John Girard? Recently retired (although up to more mischief than ever) John spent 25 years at Gartner, leading topics like SSL VPNs and mobile device management. So join John and us talk about telework security, but also some non-security telework advice...
Episode 8 - Intro to Blockchain & Cryptocurrency - Fertilizer and Facts 17.03.2020 29:39
Spring is around the corner so when looking for a high grade fertilizer stronger than manure we decided to combine blockchain and cryptocurrency. Blockchain is great security technology, but it is usually just badly implemented or treated like magic. The anonymity and irrefutably are great features of cryptocurrency, but the evil side that stains the technology holds them back as ransomware payo...
Episode 7 - RSAC After Action Report, Worms, AI & DevOps Security 10.03.2020 29:13
Greg provides his post-RSA Conference report. We discuss the origins of worms and viruses, and continuous audit, Bill discloses his history in code testing, and why buffer overflows persist. We give a list of some cool AI-in-security use cases. There's even a SoundCloud analogy. And more!
Episode 6 - Interview of Richard Stiennon, and Security Company Leaders 03.03.2020 30:50
Bill and Greg interview Richard Stiennon, who discusses his new book Security Yearbook 2020 and how it is a survey and history of the industry. We discuss that how non-security CEOs fare in the security market, and why non-security companies don't lead in security. And how awesome/nasty an "I Told You So, Security Edition" book would be, how small the cybersecurity industry is, an...
Episode 5 - Backdoors, 5G Backdoors, and ...Intergalactic Slugs? 25.02.2020 28:24
Backdoors, software assurance, and supply chain are big topics in cybersecurity and related. Backdoors can be intentional or just sloppy design. The concern over manufacturer added backdoors in 5G has been a political and policy issue. Bill and Greg discover a shared love of Vancouver bar bands of the 80s, and Bill plants a Beastie Boys earworm.
Episode 4 - 5G Security - Say 'Gee, That's A Big Security Headache' 5 Times 18.02.2020 23:07
5G security is a real cybersecurity topic (play on words intended). It's not just a mere upgrade from 4G, like 3G to 4G was. The architecture of wireless communication is changing and driving more and different edge computing - security changes with that new reality. And if that weren't enough buzzword-bingo, IoT security will change, and so will privacy and lawful intercept.
Episode 3 - Cybersecurity Skills Shortage? Or Are We Bad At Peopling 12.02.2020 31:47
Bill and Greg measure the cybersecurity skills gap and find out that is may be measured in units of Mismanagementograms. Bill seems to know a lot of companies in Southern New Jersey. We give some career tips for anyone looking at getting into cybersecurity. Greg mentions feral donkeys, and rants about automated HR CV filters that filter out qualified candidates. Bill and Greg give shoutouts to...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.