Search this show’s transcripts

Cybersecurity Headlines

en us
Daily stories from the world of information security. To delve into any daily story, head to CISOseries.com.

Episodes

Page 35 · 50 per page
Published 2021-03-02

March 2, 2021

6 min
View

Gab user data leaked

Biden administration to keep tech export ban rules

Hackers give websites great SEO before installing malware

Thanks to our episode sponsor, TrustMAPP

First it was GDRP in the EU, then California's CCPA. Now Virginia is set to pass its own Consumer Data Protection Act. Are you ready? Get ready with TrustMAPP.

Extract Knowledge
Published 2021-03-01

March 1, 2021

7 min
View

Ryuk ransomware now self-spreads to other Windows LAN devices

Go malware sees 2000% increase, adopted by APTs and e-crime groups

Former SolarWinds CEO blames intern for 'solarwinds123' password leak

Thanks to our episode sponsor, TrustMAPP

Attention defense contractors! Are you ready for CMMC? TrustMAPP addresses your CMMC and NIST 800-171 maturity and compliance assessments needs today, and automatically builds a roadmap to achieve your desired level of maturity posture. For more information, visit TrustMAPP.com

For the stories behind the headlines, head to CISOseries.com.

Extract Knowledge
Published 2021-02-26

February 26, 2021

8 min
View

Biden orders review of supply chain security

China uses malicious Firefox Extension to spy on Tibetans

Attackers scan for unpatched VMware servers after PoC exploit release

Thanks to our episode sponsor, PlexTrac

PlexTrac is the Purple Teaming Platform. Use the Runbooks Module to facilitate your tabletop exercises, red team engagements, breach and attack simulations, and pentest automation to improve communication and collaboration. PlexTrac upgrades your program's capabilities by making the most of every team member and tool. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!

Extract Knowledge

Link to Blog Post

This week's Cyber Security Headlines – Week in Review, February 22-26, 2021, is hosted by Steve Prentice (@stevenprentice) with our guest, Naomi Buckwalter (@ineedmorecyber), director of information security and IT, Beam Technologies

Please join us live every Thursday at 4pm PT/7pm ET by registering for the open discussion.

Thanks to our episode sponsor, PlexTrac

PlexTrac is the solution to deal with your data. Aggregate findings from all assessments to produce the analytics needed to make informed decisions. Produce data visualizations and add them to reports with one click to communicate effectively to leadership. PlexTrac is the premier product for security data management. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!

All links and the video of this episode can be found on CISO Series.com

Extract Knowledge
Published 2021-02-25

February 25, 2021

6 min
View

Microsoft and FireEye push for breach reporting rules

US Federal Reserve hit with massive IT outage

Path cleared for California's net neutrality law

Thanks to our episode sponsor, PlexTrac

Solve your talent shortage with PlexTrac. Use PlexTrac to automate security tasks and workflows to keep your red, blue, and purple teams focused on the real security work. Gain precious time back in your team's day and improve their morale by making them more effective with PlexTrac. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!

Extract Knowledge
Published 2021-02-24

February 24, 2021

7 min
View

Most firms now fear nation state attack

Firefox 86 gets privacy boost with Total Cookie Protection

Shadow attacks let attackers replace content in digitally signed PDFs

Thanks to our episode sponsor, PlexTrac

PlexTrac is the solution to deal with your data. Aggregate findings from all assessments to produce the analytics needed to make informed decisions. Produce data visualizations and add them to reports with one click to communicate effectively to leadership. PlexTrac is the premier product for security data management. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!

For the stories behind the headlines, head to CISOseries.com.

Extract Knowledge
Published 2021-02-23

February 23, 2021

6 min
View

SHAREit fixes security holes

Organizations feel the impact of the Accellion exploit

China spyware cribs the NSA

Thanks to our episode sponsor, PlexTrac

Gain a real-time view of security posture with PlexTrac by consolidating scanner findings, assessments, and bug bounty tools. Visualize your posture in the Analytics Module to quickly assess and prioritize, creating a more effective workflow. Map risks to the MITRE ATT&CK framework to create a living risk register. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!

Extract Knowledge
Published 2021-02-22

February 22, 2021

7 min
View

Silver Sparrow malware found on 30,000 Macs has security pros stumped

SolarWinds hackers stole source code for Microsoft Azure, Exchange, Intune

New hack lets attackers bypass MasterCard PIN by using it as Visa card

Thanks to our episode sponsor, PlexTrac

PlexTrac is a powerful, yet simple, cybersecurity platform that centralizes all security assessments, pentest reports, audit findings, and vulnerabilities. PlexTrac transforms the risk management lifecycle, allowing security professionals to generate better reports faster, aggregate and visualize analytics, and collaborate on remediation in real-time. Check out PlexTrac.com/CISOSeries to learn why PlexTrac is the perfect platform for CISOs!

For the stories behind the headlines, head to CISOseries.com.

Extract Knowledge
Published 2021-02-19

February 19, 2021

7 min
View

Dating-app video calls could have been spied on

Microsoft pulls buggy Windows update that blocked security updates

Windows, Linux servers targeted by new WatchDog botnet

Thanks to our episode sponsor, Kenna Security

Ready to shift gears to risk-based vulnerability management? Now's the time. Through Kenna Security's on-demand educational series Kenna Katalyst, you can learn the six steps needed to start your own risk-based vulnerability management program and make vulnerability management … well, more manageable. And you can earn 1 CPE credit through (ISC)². Learn more at kennasecurity.com/katalyst.

Extract Knowledge

Link to Blog Post

This week's Cyber Security Headlines - Week in Review, February 15-19, 2021, is hosted by Steve Prentice (@stevenprentice) with our guest, Mike Johnson, co-Host CISO Vendor Relationship Podcast.

Thanks to our episode sponsor, Kenna Security

In just one hour, learn how to prioritize your riskiest vulnerabilities and lower your cyber risk through Kenna Katalyst, the newest on-demand educational series from Kenna Security designed to kickstart your risk-based vulnerability management program and equip you with expert tips you can implement today. Backed by (ISC)², participants can earn 1 CPE credit. Start now at kennasecurity.com/katalyst.

All links and the video of this episode can be found on CISO Series.com

Extract Knowledge
Published 2021-02-18

February 18, 2021

5 min
View

SolarWinds attack launched from within the US

Facebook restricts Australian news sharing

Security researcher finds native Apple Silicon malware

Thanks to our episode sponsor, Kenna Security

Ready to shift gears to risk-based vulnerability management? Now's the time. Through Kenna Security's on-demand educational series Kenna Katalyst, you can learn the six steps needed to start your own risk-based vulnerability management program and make vulnerability management … well, more manageable. And you can earn 1 CPE credit through (ISC)². Learn more at kennasecurity.com/katalyst.

Extract Knowledge
Published 2021-02-17

February 17, 2021

7 min
View

Security bugs left unpatched in Android app with one billion downloads

LastPass will restrict free users to only one type of device starting next month

North Korea accused of hacking Pfizer for Covid-19 vaccine data

Thanks to our episode sponsor, Kenna Security

In just one hour, learn how to prioritize your riskiest vulnerabilities and lower your cyber risk through Kenna Katalyst, the newest on-demand educational series from Kenna Security designed to kickstart your risk-based vulnerability management program and equip you with expert tips you can implement today. Backed by (ISC)², participants can earn 1 CPE credit. Start now at kennasecurity.com/katalyst.

For the stories behind the headlines, head to CISOseries.com

Extract Knowledge
Published 2021-02-16

February 16, 2021

6 min
View

France links Russian Sandworm hackers to hosting provider attacks

Privacy problems with Azure and Canonical

Microsoft estimates thousands of developers touched SolarWinds malware

Thanks to our episode sponsor, Kenna Security

Kenna Katalyst is Kenna Security's newest on-demand educational series designed to help you shift gears to risk-based vulnerability management. Get the six key steps you need to go risk-based along with actionable tips to help your team focus on the risks that matter most. Participants can earn 1 CPE credit through (ISC)². Learn more at kennasecurity.com/katalyst.

Extract Knowledge
Published 2021-02-15

February 15, 2021

7 min
View

SuperMicro supply chain hack used for counterintelligence for a decade

Egregor ransomware operators arrested in Ukraine

Scammers target US tax pros in ongoing IRS phishing attacks

Thanks to our episode sponsor, Kenna Security

Ready to shift gears to risk-based vulnerability management? Now's the time. Through Kenna Security's on-demand educational series Kenna Katalyst, you can learn the six steps needed to start your own risk-based vulnerability management program and make vulnerability management … well, more manageable. And you can earn 1 CPE credit through (ISC)². Learn more at kennasecurity.com/katalyst.

For the stories behind the headlines, head to CISOseries.com

Extract Knowledge
Published 2021-02-12

February 12, 2021

8 min
View

Pitiful password enabled recent water treatment facility hack

Border patrol scans millions of faces, catches 0 imposters at airports

India using a glitchy app to inoculate 300 million people by August

Thanks to our episode sponsor Altitude Networks

Wouldn't it be great if you could INSTANTLY KNOW if a file containing sensitive information was shared in the wrong way, anywhere in your company AND security had a real time slack notification with a magic "undo button"?! Altitude Networks solves these challenges and protects you from all data leak risks on G Suite and Office 365! Check it out at AltitudeNetworks.com and be sure your sensitive data isn't shared with the wrong people!

Extract Knowledge

Link to Blog Post

This week's Cyber Security Headlines - Week in Review, February 8-12, 2021 is hosted by Steve Prentice (@stevenprentice) with our guest, Johna Till Johnson (@JohnaTillJohnso), CEO, Nemertes Research.

Thanks to our episode sponsor, Altitude Networks

Imagine an employee just left and went to a competitor: did they take proprietary documents or critical roadmaps with them? Did they add a backdoor access via personal accounts to documents? You're a cloud-forward company on G Suite, how would you know your data is at risk? Altitude Networks can automatically tell you who is trying to steal your critical cloud data from G Suite and Office 365. Check it out at AltitudeNetworks.com and be sure your sensitive data stays when your employee leaves!

All links and the video of this episode can be found on CISO Series.com

Extract Knowledge
Published 2021-02-11

February 11, 2021

6 min
View

SIM swapping gang targeting celebrities arrested

Researcher demonstrates the vulnerability of open source to supply chain attacks

Google study looks at high-risk victims of email attacks

Thanks to our episode sponsor Altitude Networks

"Uh oh! Charles just accidentally shared the board deck by link on the company slack channel… and the link is open to all employees! I hope we can take it down before the M&A information leaks!" Does this scenario sound familiar? Make sure it doesn't happen at your company!! Altitude Networks provides always-on data security for GSuite and Office365. Check it out at AltitudeNetworks.com and be sure your data isn't shared to the wrong people.

Extract Knowledge
Published 2021-02-10

February 10, 2021

7 min
View

Office 365 will help admins find impersonation attack targets

U.S. agencies publish ransomware factsheet

Europol busts international cybercriminal group

Thanks to our episode sponsor Altitude Networks

Imagine an employee just left and went to a competitor: did they take proprietary documents or critical roadmaps with them? Did they add a backdoor access via personal accounts to documents? You're a cloud-forward company on G Suite, how would you know your data is at risk? Altitude Networks can automatically tell you who is trying to steal your critical cloud data from G Suite and Office 365. Check it out at AltitudeNetworks.com and be sure your sensitive data stays when your employee leaves!

For the stories behind the headlines, head to CISOseries.com

Extract Knowledge
Published 2021-02-09

February 9, 2021

6 min
View

A look at Iranian spyware operations

Florida water treatment plant hacked to distribute harmful chemicals

Microsoft to add 'nation-state activity alerts' to Defender

Thanks to our episode sponsor Altitude Networks

Remember that time when someone at work accidentally shared a Google document to your personal email? Well, that happens a lot and it leaves a backdoor to cloud data for former employees or contracts. Altitude Networks is the only solution that will protect you from this and many other data leak risks on G Suite and Office 365! Check it out at AltitudeNetworks.com and be sure your sensitive data isn't shared with the wrong people!

Extract Knowledge
Published 2021-02-08

February 8, 2021

7 min
View

New phishing attack uses Morse code to hide malicious URLs

Hacked by SolarWinds, Mimecast lays off staff despite record profits

Activists complain of weakened voting security standard

Thanks to our episode sponsor Altitude Networks

Uh oh, Johnny left the company 6 months ago, but still has access to numerous files in Google Drive via his personal account! Do you know how many other former employees and contractors still have access to our documents? It's a lot more than you might think. Altitude Networks automatically discovers sharing to personal accounts and can eliminate it with one click. Check it out at AltitudeNetworks.com and be sure your sensitive data isn't shared with the wrong people!

For the stories behind the headlines, head to CISOseries.com.

Extract Knowledge
Published 2021-02-05

February 5, 2021

7 min
View

Canada calls Clearview AI's facial recognition 'mass surveillance' Amazon pulls Big-Brother move, puts AI cameras in delivery vans Myanmar blocks Facebook following military coup

Thanks to our episode sponsor HID Global:

Evolving organizations need strong MFA. With the broadest selection of authentication options in the industry, HID Global's advanced multi-factor authentication solution is capable of building a frictionless user experience that blends convenience and protection. Learn more at www.hidglobal.com/mfa

Extract Knowledge
Published 2021-02-04

Week in Review: February 1 through 5, 2021

25 min
View

Link to Blog Post

This week's Cyber Security Headlines - Week in Review, February 1-5, 2021 is hosted by Steve Prentice (@stevenprentice) with our guest, Shawn Bowen, CISO, Restaurant Brands International (RBI)

Thanks to our episode sponsor HID Global

Evolving organizations need strong MFA. With the broadest selection of authentication options in the industry, HID Global's advanced multi-factor authentication solution is capable of building a frictionless user experience that blends convenience and protection. Learn more at www.hidglobal.com/mfa

All links and the video of this episode can be found on CISO Series.com

Extract Knowledge
Published 2021-02-04

February 4, 2021

6 min
View

Microsoft sees a rise in business email compromise attacks on schools

Facebook takes a proactive content stance after Myanmar coup

SolarWinds CEO says its email systems were compromised for months

Thanks to our episode sponsor HID Global:

Evolving organizations need strong MFA. With the broadest selection of authentication options in the industry, HID Global's advanced multi-factor authentication solution is capable of building a frictionless user experience that blends convenience and protection. Learn more at www.hidglobal.com/mfa

Extract Knowledge
Published 2021-02-03

February 3, 2021

6 min
View

Another SolarWinds vulnerability used to hack National Finance Center

SonicWall confirms actively exploited zero-day

Microsoft Defender now detects macOS vulnerabilities

Thanks to today's sponsors, HID Global:

Evolving organizations need strong MFA. With the broadest selection of authentication options in the industry, HID Global's advanced multi-factor authentication solution is capable of building a frictionless user experience that blends convenience and protection. Learn more at www.hidglobal.com/mfa

Extract Knowledge
Published 2021-02-02

February 2, 2021

7 min
View

Deloitte's CDC vaccine system comes up short

Myanmar internet and telecom disruptions continue due to coup

Sprite Spider emerges as one of the most destructive ransomware threat actors this year

Thanks to our sponsor, HID Global

Evolving organizations need strong MFA. With the broadest selection of authentication options in the industry, HID Global's advanced multi-factor authentication solution is capable of building a frictionless user experience that blends convenience and protection. Learn more at https://hidglobal.com/mfa

For the stories behind the headlines, head to CISOseries.com.

Extract Knowledge
Published 2021-02-01

February 1, 2021

7 min
View

Suspected Russian hack extends far beyond SolarWinds software

Russian hack brings changes and uncertainty to US court system

Section 230 emerges as Robinhood's shield from lawsuits

Evolving organizations need strong MFA. With the broadest selection of authentication options in the industry, HID Global's advanced multi-factor authentication solution is capable of building a frictionless user experience that blends convenience and protection. Learn more at https://hidglobal.com/mfa.

For the stories behind the headlines, head to CISOseries.com.

Extract Knowledge
Published 2021-01-29

January 29, 2021

7 min
View

Unhappy #DataPrivacyDay to us all

WhatsApp adds biometric authentication to web, desktop versions

Sources: Facebook preps suit against Apple over App Store rules

And now our sponsor Nucleus Security brings you "The Top 5 Antipatterns in Vulnerability Management":

Antipattern #4: "Homegrown Vulnerability Management Tools": Large enterprises are full of homegrown vulnerability management tools that were abandoned due to complexity or cumbersome builds. See how Nucleus automates your vulnerability management workflows, replacing the need for custom tools completely, at nucleussec.com/demo

Extract Knowledge

Link to Blog Post

This week's Cyber Security Headlines Week in Review, January 25-29, 2021, is hosted by Steve Prentice @stevenprentice with our guest, Steve Zalewski, Deputy CISO, Levi Strauss.

Thanks to our sponsor, Nucleus Security

All this week on our daily news podcast, Nucleus Security has been sharing some antipatterns in vulnerability management, such as relying on spreadsheets to track risks, relying on homegrown vulnerability management tools that were abandoned due to complexity or cumbersome builds, and the challenge of hiring enough vulnerability analysts to do triage. Learn how Nucleus can rescue you from these types of challenges and provide the data insights you need with a demo-on-demand at nucleussec.com/demo.

All links and the video of this episode can be found on CISO Series.com

Extract Knowledge
Published 2021-01-28

January 28, 2021

6 min
View

10-year old sudo bug patched

Mass Emotet uninstall planned for March 25th

Microsoft's security business exceeds $10 billion in revenue

And now our sponsor Nucleus Security brings you "The Top 5 Antipatterns in Vulnerability Management":

Antipattern #4: "Homegrown Vulnerability Management Tools": Large enterprises are full of homegrown vulnerability management tools that were abandoned due to complexity or cumbersome builds. See how Nucleus automates your vulnerability management workflows, replacing the need for custom tools completely, at nucleussec.com/demo

Extract Knowledge
Published 2021-01-27

January 27, 2021

7 min
View

Google's Threat Analysis Group warns of social engineering hack aimed at security researchers

Verizon outage started in Brooklyn

TikTok fixes flaws allowing theft of private user information

And now our sponsor Nucleus Security brings you "The Top 5 Antipatterns in Vulnerability Management":

Antipattern #3: "The Army of Analysts": Manual vulnerability analysis doesn't scale. In large enterprises, it's impossible to hire enough vulnerability analysts to manually analyze and triage vulnerability scan results fast enough. Learn how Nucleus automates vulnerability analysis and triage with a demo-on-demand at nucleussec.com/demo.

For the stories behind the headlines, head to CISOseries.com.

Extract Knowledge
Published 2021-01-26

January 26, 2021

6 min
View

Google's cookie replacement performs well in tests

Twitter Birdwatch pilot launches

WhatsApp wormable malware found on Android

And now our sponsor Nucleus Security brings you "The Top 5 Antipatterns in Vulnerability Management":

Antipattern #2: "CVSS prioritization": CVSS scores are useful, but you need much more than scores to determine what to fix and when to fix it; Business context and vulnerability intelligence are key to prioritizing vulnerabilities in large enterprises. Learn how Nucleus can help with intelligent vulnerability prioritization at nucleussec.com/demo

Extract Knowledge
Published 2021-01-25

January 25, 2021

7 min
View

President Biden takes on cybersecurity on day one

SonicWall firewall maker hacked using zero-day in its VPN device

Intel probes reports of quarterly earnings hack

And now our sponsor Nucleus Security brings you "The Top 5 Antipatterns in Vulnerability Management":

Antipattern No. 1: "Spreadsheet Hell": Relying on Microsoft Excel to track risks and answer questions about your vulnerability data is inefficient and insecure. Learn how Nucleus can rescue you from spreadsheet hell and provide the data insights you need with a demo-on-demand at nucleussec.com/demo.

Extract Knowledge
Published 2021-01-22

January 22, 2021

7 min
View

Technologists comb through Parler videos with facial recognition

EU privacy watchdogs go after employers who spy on workers

Google investigates top AI ethicist's exfiltration of thousands of files

Thanks to our episode sponsor Armis

Armis research shows that on average, companies are blind to 40% of the devices in their environment. This blind spot includes traditional desktops, laptops, cloud and virtual instances, BYOD, and IoT and more. Without a real-time, comprehensive view of all these assets —or the risks associated with them, businesses are vulnerable. Armis Asset Management can help by providing 5x more visibility over exciting solutions.

Extract Knowledge

Link to Blog Post

This week's Cyber Security Headlines Week in Review, January 18-22, 2021 is hosted by Steve Prentice @stevenprentice with our guest Joshua Scott, Head of Information Security at Postman.

Thanks to our episode sponsor Armis

Armis has research shows that on average, companies are blind to 40% of the devices in their environment. This blind spot includes traditional desktops, laptops, cloud and virtual instances, BYOD, and IoT and more. Without a real-time, comprehensive view of all these assets —or the risks associated with them, businesses are vulnerable. Armis Asset Management can help by providing 5x more visibility over exciting solutions.

All links and the video of this episode can be found on CISO Series.com

Extract Knowledge
Published 2021-01-21

January 21, 2021

6 min
View

Malwarebytes breached by the group that attacked Solarwinds

Google researcher finds security flaws impacting popular chat apps

Executive Order addresses malicious use of public clouds

Thanks to our episode sponsor Armis

Armis research shows that on average, companies are blind to 40% of the devices in their environment. This blind spot includes traditional desktops, laptops, cloud and virtual instances, BYOD, and IoT and more. Without a real-time, comprehensive view of all these assets —or the risks associated with them, businesses are vulnerable. Armis Asset Management can help by providing 5x more visibility over exciting solutions.

For more on any of these stories, head to cisoseries.com

Extract Knowledge
Published 2021-01-20

January 20, 2021

7 min
View

FireEye releases report and network auditing tool for SolarWinds-type hacks

SolarWinds malware arsenal widens with Raindrop

DNSpooq bugs let attackers hijack DNS on millions of devices

Thanks to our episode sponsor Armis

One of the biggest challenges security teams face is they do not have a clear picture of all assets in their environment. The resulting 'blind spot' means they have no way to efficiently, credibly, and automatically manage security. Armis Asset Management eliminates this blind spot providing 5X more visibility than other solutions. Head over to armis.com to learn more.

For more on any of these stories, head to cisoseries.com

Extract Knowledge
Published 2021-01-19

January 19, 2021

6 min
View

Parler resurfaces online

Darknet forum Joker's Stash shutting down

Microsoft Defender to enable auto-remediation by default

Thanks to our episode sponsor Armis

All cybersecurity programs start with gaining full visibility into all the assets in the environment. Yet security teams continue to struggle to see every thing they have. This asset blind spot means security teams don't have an accurate picture of what needs to be managed and secured. Head over to armis.com to see how Armis Asset Management helps you overcome this Cybersecurity Asset Management challenge.

For more on any of these stories, head to cisoseries.com

Extract Knowledge
Published 2021-01-18

January 18, 2021

7 min
View

Xiaomi added to Pentagon blacklist

Dating apps are using images from the siege to ban rioters' accounts

NSA suggests enterprises use designated DNS-over-HTTPS resolvers

Thanks to our episode sponsor Armis

Lack of complete visibility to all assets in any environment is a huge cybersecurity challenge for every organization. And fragmentation across tools and systems along with broken remediation makes Cybersecurity Asset Management near impossible. Armis Asset Management addresses this issue providing 5X the visibility of other solutions in the market today. Download our white paper today.

For more on any of these stories, head to cisoseries.com

Extract Knowledge
Published 2021-01-15

January 15, 2021

8 min
View

Hackers waltzed past MFA used by CISA on cloud accounts

Social media convulses after Capitol attack

Google fixes bug that delayed COVID contact-tracing apps

Thanks to our episode sponsor, IT Asset Management Group

Are you checking your IT asset disposal vendor's homework? Organizations should record unique IDs of each asset disposed of and reconcile their records against the data that is provided by their disposal vendor. This practice reduces exposures that can occur from poorly monitored data disposition events. You can learn more tips like this from IT Asset Management Group's free data disposition program guide. Download the program guide today at itamg.com/CISO

Extract Knowledge

Link to blog post

This week's Cyber Security Headlines Week in Review, January 11-15, 2021 is hosted by Steve Prentice @stevenprentice with our guest Allan Alford, @AllanAlfordinTX.

Thanks to our episode sponsor, IT Asset Management Group

Organizations must have adequate written policies and procedures to meet the regulatory requirements for the disposal of their retired data containing devices. These policies should be readily available and regularly reviewed by leadership. IT Asset Management Group offers a free policy template to help establish or improve your written policies for IT asset disposal practices. Download the policy template today at itamg.com/CISO

All links and the video of this episode can be found on CISO Series.com

Extract Knowledge
Published 2021-01-14

January 14, 2021

7 min
View

Europol confirms dark web marketplace takedown

Google to reportedly block all political ads... again

DoD halts deployment of cybersecurity system

Thanks to our episode sponsor, IT Asset Management Group

Are you checking your IT asset disposal vendor's homework? Organizations should record unique IDs of each asset disposed of and reconcile their records against the data that is provided by their disposal vendor. This practice reduces exposures that can occur from poorly monitored data disposition events. You can learn more tips like this from IT Asset Management Group's free data disposition program guide. Download the program guide today at itamg.com/CISO

For more on any of these stories, head to cisoseries.com

Extract Knowledge
Published 2021-01-13

January 13, 2021

7 min
View

Hackers leak stolen Pfizer COVID-19 vaccine data online

Social media's big terrible week

Parler archived due to "mind-numbing" mistake

Thanks to our episode sponsor, IT Asset Management Group

Poorly managed IT asset disposal, lack of due diligence, and a disposal program without clearly defined responsible parties has now resulted in millions of dollars in regulatory penalties. Is it clear who is responsible for the performance of your data disposition practice? IT Asset Management Group's free program guide includes tips for establishing stakeholders at your organization and expectations for all practitioners. Download the program guide today at itamg.com/CISO

For more on any of these stories, head to cisoseries.com

Extract Knowledge
Published 2021-01-12

January 12, 2021

6 min
View

SolarWinds breach now linked to Turla

UK ruling limits the reach of "general warrants"

UN data breach exposes staff records

Thanks to our episode sponsor, IT Asset Management Group

How does your organization measure a successful IT asset disposal program? Are decisions driven by dollars saved, ease of use, or security and compliance risk reduction? You should not have to choose one over the other. Utilizing IT Asset Management Group's best practices guide will ensure your data disposition program performs for all stakeholders in your organization. Download the program guide today at itamg.com/CISO

For more on any of these stories, head to cisoseries.com

Extract Knowledge
Published 2021-01-11

January 11, 2021

7 min
View

Parler removed from Apple, Google, and Amazon

Facial-recognition app Clearview sees a spike in use after Capitol attack

Emotet tops malware charts in December after reboot

Thanks to our episode sponsor, IT Asset Management Group

Organizations must have adequate written policies and procedures to meet the regulatory requirements for the disposal of their retired data containing devices. These policies should be readily available and regularly reviewed by leadership. IT Asset Management Group offers a free policy template to help establish or improve your written policies for IT asset disposal practices. Download the policy template today at itamg.com/CISO

For more on any of these stories, head to cisoseries.com

Extract Knowledge
Published 2021-01-08

January 8, 2021

7 min
View

Our sponsor, Omada's identity governance tip of the day

Deploy identity capabilities in phases. If you try to do a massive lift and shift problems will occur and it will probably take longer than you expect. See where you can add value early on. First, launch the solution's basic functionality. What can be done without writing custom code? Where you can deliver value at each iteration? You want to show continuous success rather than the fastest total completion time. Learn more at omada.net.

For links to the full stories, head over to CISOseries.com.

Extract Knowledge
Published 2021-01-08

Week in Review: January 4 through 8, 2021

20 min
View

Link to Blog Post

This week's Cyber Security Headlines Week in Review - January 4-8, 2021 is hosted by Steve Prentice, with our guest, Ross Young, CISO, Caterpillar Financial (LinkedIn).

Thanks to our episode sponsor, Omada

Get stakeholders on board early. Sounds simple, but the hard part is making sure everyone has the right level of information they need at the right time to do their job. So start thinking early about the needs of your CISO, the security staff, auditors, compliance officers, and intellectual property controllers. The goal is increased awareness for all which will reduce resistance for everyone. Discover how Omada can help at omada.net.

All links and the video of this episode can be found on CISO Series.com

Extract Knowledge
Published 2021-01-07

January 7, 2021

6 min
View

Rioters storm US Capitol, Trump's Twitter suspended

SolarWinds attackers accessed DOJ's email server

WhatsApp to share user data with Facebook

Our sponsor, Omada's identity governance tip of the day

According to Gartner, if you use a SaaS solution for identity governance and administration you'll save an average of 30 percent in initial integration costs. Here are some items to look for when choosing an IGA SaaS solution: Does it have high availability? Is it configurable to your specific business needs and can that be transferred to a tiered deployment environment? Learn more tricks to managing identity in the cloud at omada.net.

For links to the full stories, head over to CISOseries.com.

Extract Knowledge
Published 2021-01-06

January 6, 2021

7 min
View

Google, Alphabet employees unionize

NYSE no longer plans to de-list Chinese firms

Amazon banned from using AWS trademark in China

Our sponsor, Omada's identity governance tip of the day

Upon launching a project map your business priorities to best-practice identity processes. Then, perform a fit-gap analysis between functional areas in the process to the ideal goal. Where are key data and systems going? Where are there gaps? Are there deviations from best practices? You now have a blueprint of business processes and gaps. Knowing is half the battle. Let Omada help by visiting them at omada.net.

For links to the full stories, head over to CISOseries.com.

Extract Knowledge
Published 2021-01-05

January 5, 2021

6 min
View

Microsoft source code accessed by SolarWinds attackers

Slack suffers massive outage

UK judge denies Assange extradition to US

Our sponsor, Omada's identity governance tip of the day

Well-tested process frameworks are great starting points. No need to reinvent. Just tweak processes that have already proven effective such as automating identity management, access requests, cross-application segregation of duties, and least privilege access. Head over to omada.net to see how Omada can help you get two steps ahead with your identity management.

For links to the full stories, head over to CISOseries.com.

Extract Knowledge
Published 2021-01-04

January 4, 2021

7 min
View

Russian SolarWinds hack damage escalates

Backdoor account discovered in more than 100,000 Zyxel firewalls and VPN gateways

Wall Street to kick out Chinese telecom giants

Our sponsor, Omada's identity governance tip of the day

Get stakeholders on board early. Sounds simple, but the hard part is making sure everyone has the right level of information they need at the right time to do their job. So start thinking early about the needs of your CISO, the security staff, auditors, compliance officers, and intellectual property controllers. The goal is increased awareness for all which will reduce resistance for everyone. Discover how Omada can help at omada.net.

For links to the full stories, head over to CISOseries.com.

Extract Knowledge
Show details
Episodes
1845
Transcripts
0
0% coverage
Missing transcripts
1845
With chapters
0