Supply Chain Security & Zero Trust Tech with Ashish Rajan & Shilpi Bhattacharjee

Supply Chain Security & Zero Trust Tech with Ashish Rajan & Shilpi Bhattacharjee

Hacker Valley: On the Road is a curated collection of conversations that Chris and Ron have had during conferences and events around the globe. In this episode, Cloud Security Podcast’s Ashish Rajan and Shilpi Bhattacharjee speak with the Hacker Valley team at AISA CyberCon in Melbourne, Australia. Ashish and Shilpi discuss their respective talks on supply chain security and zero trust technology, SBOMs, and keynote speakers at this year’s Cybercon worth noting for the audience at home.

Timecoded Guide:

[00:00] Connecting & conversing at a cyber conference post-COVID

[06:50] Breaking down Shilpi’s presentation on supply chain threats & attacks

[11:45] Understanding the paradoxes & limitations of zero trust with Ashish’s talk

[26:13] Defining & explaining SBOM, or Software Bill of Materials

[33:16] Noticing key conversations & trends for those who didn’t attend AISA Cybercon

Sponsor Links:

Thank you to our sponsor Axonius for bringing this episode to life!

The Axonius solution correlates asset data from existing solutions to provide an always up-to-date inventory, uncover gaps, and automate action — giving IT and security teams the confidence to control complexity. Learn more at axonius.com/hackervalley

Shilpi, can you talk about the idea behind the talk you had at CyberCon?

The inspiration behind Shilpi’s conference talk was supply chain issues. Titling her talk, “Who’s Protecting Your Software in Supply Chain,” Shilpi hoped to further educate and advocate for security in the supply chain process. An estimated one in two companies will experience a supply chain attack in the coming years. Instead of fearing such a statistic, Shilpi hopes her talk inspired further security action to protect our supply chains.

“One staggering fact that I read is that one in every two companies is going to have some sort of a supply chain attack in the next three years. So, who's going to look after the supply chain? Is it going to be the organization? Is it going to be your third-party vendors?” —Shilpi

Ashish, what about your talk at Cybercon?

In contrast, Ashish’s talk was about the triple paradox of zero trust. When talking about and implementing zero trust, Ashish realized many companies don’t implement the cultural changes needed for zero trust and/or only talk about zero trust as a technology process. Zero trust has numerous layers beyond technology, and requires time and major changes in culture and technology to implement in most companies.

“I feel bad for bashing on finance, marketing, and HR teams. They're all smart people, but if you're going to add four or five layers of security for them, they almost always say, ‘I just want to do my job. I don't really care about this. It's your job to do security.’” —Ashish

Where would you recommend starting when it comes to trying to implement the ideas in your respective talks?

When push comes to shove about where cyber companies can start first with supply chain and zero trust, Ashish and Shilpi agree that companies have to discuss business priorities. When company leaders can take the opportunity to look at and understand their cyber hygiene, the next steps might look very different from another company’s tactics. Knowing what a business has is the foundational piece that impacts any new process in cyber.

“If I were to go back to the first principle of what we do with cybersecurity professionals, one of the biggest assets that we're all trying to protect is data. You can't protect what you can't see, that's the foundational piece.” —Ashish

For anyone that wasn't able to make the conference, what is one thing that you would want to share with the audience at home?

There were a lot of conversations taking place at Cybercon this year. Ashish wants the audience at home to know that cloud native, zero trust, supply chain, and leadership positions like CISOs were the main themes in many talks, panels, and conversations. Shilpi wants those who couldn’t attend to watch out for more talks and conversations about cyber from those outside of the industry to understand that the issues impacting cyber influence the world.

“I think there's that interest about cybersecurity being more than just a cybersecurity problem. Cybersecurity is not just a technical problem, it's a societal problem, a cultural problem. I very much agree, because a lot of the things that we're dealing with impacts everyone.” —Shilpi

---------------

Links:

Keep up with our guest Ashish Rajan on LinkedIn

Keep up with our guest Shilpi Bhattacharjee on LinkedIn

Listen to Ashish and Shilpi’s Cloud Security Podcast

Connect with Ron Eddings on LinkedIn and Twitter

Connect with Chris Cochran on LinkedIn and Twitter

Purchase a HVS t-shirt at our shop

Continue the conversation by joining our Discord

Check out Hacker Valley Media and Hacker Valley Studio

Jaksot(406)

Episode 54 - Hiring Leaders and Finding Talent with Alex Maestretti

Episode 54 - Hiring Leaders and Finding Talent with Alex Maestretti

In this episode we sit down to chat with Alex Maestretti, CISO of Remitly. In this conversation, we explore finding talent and the unique challenge of hiring managers. Chris also shares his unique relationship to Alex. Alex's LinkedIn: linkedin.com/in/maestretti Alex's Twitter Handle: @maestretti Remitly's Website: https://www.remitly.com/us/en

9 Huhti 202016min

Episode 53 - In the Depths of Deception with Jenny Radcliffe

Episode 53 - In the Depths of Deception with Jenny Radcliffe

Psychology is a major pillar of Social Engineering 🧠. In this episode, we brought in a true expert, Jenny Radcliffe - A burgular for hire, a professional con-artist, and an expert in Non-verbal communications. This episode had Chris and Ron on the edge of their seats. To learn more about Jenny Radcliffe: @Jenny_Radcliffe https://humanfactorsecurity.co.uk/

6 Huhti 202039min

Episode 52 - From Librarian to OSINT with Tracy Maleeff

Episode 52 - From Librarian to OSINT with Tracy Maleeff

Open Source Intelligence (OSINT) is "data collected from publicly available sources to be used in an intelligence context". Performing OSINT is a critical aspect in triaging cybersecurity related events. In this exciting episode, Ron and Chris bring in an OSINT expert with the ultimate background for finding open source data. Tracy Maleeff aka InfoSecSherpa, is a seasoned expert in library science and security analysis. Be sure to listen in on this episode and gain insight for how library science applies to all aspects of life.

1 Huhti 202040min

Episode 51 - A Threat Intelligence Journey with Doug Helton

Episode 51 - A Threat Intelligence Journey with Doug Helton

Can Threat Intelligence Analysts do the same in the professional space as the Threat Intel Analysts depicted in movies? Yes, as long as you have the same level of skills and tools as the characters in the movie. Doug Helton joins this episode to share his experience in Cyber Threat Intelligence and acquiring skills required to be highly effective.

30 Maalis 202023min

Episode 50 - 50th Episode and Beyond with Ron and Chris

Episode 50 - 50th Episode and Beyond with Ron and Chris

🎊Happy 50th Episode! This episode couldn't have been possible without our amazing guests and listeners! Looking into the future, we are excited to share new content and resources that we've been working on. HackerValley.Studio Website Hacker Valley Studio Patreon

25 Maalis 202028min

Episode 49 - What is Your Superpower with Yael Nagler

Episode 49 - What is Your Superpower with Yael Nagler

Everyone has a superpower and it's not uncommon to have more than one. In this episode, Chris and Ron discover and share what their super powers are with Yael Nagler. Yael is a security tinkerer and has an amazing ability of bringing together people in technology.

23 Maalis 202028min

Underrepresented Episode 2

Underrepresented Episode 2

This is the second episode of the Hacker Valley Studio and ITSP Magazine co-production focused on underrepresented populations in technology.In this episode we highlight Nelson Abbott from NPower and Charles Nwatu from /Dev/Color.So many powerful statements in this one about organizations fighting for representation and awesome thoughts on being a role model

19 Maalis 202045min

Episode 47 - The Role of a CISO with Lenny Zeltser

Episode 47 - The Role of a CISO with Lenny Zeltser

In this exciting episode, Lenny Zeltser - CISO @ Axonius joins the podcast. Lenny is someone we really enjoy speaking to and is an all around expert in malware, technical writing, and managing teams to success.

18 Maalis 202021min

Suosittua kategoriassa Koulutus

rss-murhan-anatomia
voi-hyvin-meditaatiot-2
psykopodiaa-podcast
rss-duodecim-lehti
aloita-meditaatio
rss-psykalab
jari-sarasvuo-podcast
rss-niinku-asia-on
rss-narsisti
rss-vapaudu-voimaasi
adhd-podi
kesken
psykologia
rss-koira-haudattuna
rss-anteeks-etukateen
aamukahvilla
ihminen-tavattavissa-tommy-hellsten-instituutti
rss-liian-kuuma-peruna
rss-valo-minussa-2
rss-metropolia-ammattikorkeakoulu