Securing the Software Supply Chain

Securing the Software Supply Chain

Navigating Modern Cybersecurity: From Supply Chain Risks to AI Evolution. In this episode of ⁠Data Security Decoded⁠, ⁠Allison Wikoff⁠, a 20-year veteran in information security and threat intelligence, explores current cybersecurity challenges, emerging threats, and practical defensive strategies for organizations of all sizes. What You'll Learn: How to prioritize vulnerability management by focusing on critical edge devices and access points Why understanding your network architecture is crucial for effective threat defense The reality of AI in cyber attacks: current uses, limitations, and practical defense strategies How to build supply chain resilience through vendor assessment and backup supplier planning Why older vulnerabilities remain a primary attack vector and how to address them effectively The framework for developing an actionable threat profile tailored to your organization's needs Key Insights: Threat actors increasingly target known vulnerabilities over sophisticated zero-day exploits Supply chain security requires understanding vendor access levels and maintaining secondary suppliers AI adoption in cyber attacks remains focused on basic tasks like improving phishing emails and code generation Organizations should prioritize patching vulnerabilities in edge devices like VPNs and WAFs Building an effective security strategy starts with understanding your organization's specific threat profile Partnering with vendors and suppliers can help smaller organizations enhance their security capabilities Highlights: [00:00:00] Vulnerability Exploitation Trends Allison Wikoff reveals that vulnerability exploitation has become a dominant attack vector across both criminal and state-sponsored threat actors. The shift marks a departure from traditional assumptions that mainly espionage-focused groups leveraged vulnerabilities. [04:30] Supply Chain Security Essentials Wikoff emphasizes that modern supply chain security requires looking beyond just your own organization's defenses. Organizations must thoroughly understand their vendors' access levels and potential impact on operations. [07:23] AI in Cybersecurity: Reality vs Hype Tolin shares that while AI adoption by threat actors is increasing, it hasn't revolutionized attack tactics as many feared. Current AI usage focuses mainly on improving phishing email quality and assisting with malware code generation. [14:08] Threat Profile Development Tolin advocates for organizations to start by understanding what assets would interest attackers rather than chasing every new threat. The rapidly changing threat landscape makes it impossible to defend against everything, requiring a focused approach based on your specific risk profile. Episode Resources: Caleb Tolin on LinkedIn Allison Wikoff on LinkedIn PwC website PwC - Year in Retrospect Report 2024 Rubrik Zero Labs website

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(54)

Running the Inverted Offensive Campaign with Adam Karcher

Running the Inverted Offensive Campaign with Adam Karcher

What happens when the adversary’s dwell time is measured in years, but your defense is measured in tickets? Adam Karcher, FBI Supervisory Special Agent, Cyber Division, and a member of the Bureau’s AI...

26 Mai 35min

Protecting the Neglected: Measuring County Cyber Risk with Dr. Ido Sivan Sevilla

Protecting the Neglected: Measuring County Cyber Risk with Dr. Ido Sivan Sevilla

Dr. Ido Sivan Sevilla joins host Caleb Tolin⁠⁠⁠ to break down battlefield stories from a massive analysis of over 3,000 local government entities. Dr. Sivan Sevilla, who serves as an Assistant Profess...

19 Mai 26min

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

In this episode, host⁠ ⁠Caleb Tolin⁠⁠ explores the battlefield of enterprise defense, which has moved from simple data theft to ultra heinous crimes that put patient outcomes at risk. Guest⁠ ⁠Cynthia ...

5 Mai 29min

The Three-Layer Strategy for Autonomous Agent Governance with Joe Hladik and Amit Malik

The Three-Layer Strategy for Autonomous Agent Governance with Joe Hladik and Amit Malik

The race for AI dominance has created a dangerous imbalance between business velocity and cyber resilience. In this episode, host Caleb Tolin is joined by Joe Hladik, Head of Rubrik Zero Labs, and Sta...

21 Apr 32min

Detecting Adversary Intent: Analyzing Behavioral Tells in Admin Logs with Allison Wikoff

Detecting Adversary Intent: Analyzing Behavioral Tells in Admin Logs with Allison Wikoff

Adversaries are already logging into your network using your own admin credentials. In this episode, Caleb Tolin sits down with Allison Wikoff to move past the identity clichés and analyze the specifi...

14 Apr 20min

Downtime in Healthcare is Fatal: Achieving Resilience in Health & Life Sciences

Downtime in Healthcare is Fatal: Achieving Resilience in Health & Life Sciences

Cybersecurity in healthcare is undergoing a critical shift. What was once viewed as a back-office IT concern is now directly tied to patient safety and clinical outcomes. In this episode of Data Secur...

7 Apr 25min

AI Takes Over RSAC Conference (Now What?) with Dave Bittner.

AI Takes Over RSAC Conference (Now What?) with Dave Bittner.

In this RSAC Conference recap, Dave Bittner, Host of The CyberWire Daily, joins Data Security Decoded host Caleb Tolin from the guest seat to unpack the biggest theme dominating the conference: artifi...

31 Mar 16min

Your Backups Are Talking — Are You Listening?

Your Backups Are Talking — Are You Listening?

Security teams spend enormous effort chasing the latest threats, yet often overlook one of the most revealing sources of truth already in their environment: backups. In this episode of Data Security D...

17 Mar 17min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
lydartikler-fra-aftenposten
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
utbytte
rss-skravla-gar
finansredaksjonen
pengepodden-2
rss-pa-konto
pengesnakk
livet-pa-veien-med-jan-erik-larssen
stormkast-med-valebrokk-stordalen
tid-er-penger-en-podcast-med-peter-warren
morgenkaffen-med-finansavisen
liberal-halvtime
rss-markedspuls-2
okonomiamatorene
rss-sunn-okonomi