A Conversation with Abhishek Agrawal from Material Security

A Conversation with Abhishek Agrawal from Material Security

In this conversation, I speak with Abhishek Agrawal, co-founder and CEO of Material Security.

We talk about:

- Material's Security innovative approach to email security by not just preventing unauthorized access but also containing damage from potential breaches.

-Abhishek's background in data infrastructure at Dropbox and how product mangers can become successful CEOs due to their cross-functional expertise.

- The need for customized security measures for different organizations, the role of AI in detecting email threats, the importance of single-tenant environments for sensitive customers and the potential risk of default settings in productivity suites like Google Workspace.

Among other topics.

Abhishek's Background and Material Security (00:00:00)
Email Security and Productivity Suite (00:01:01)
Geographical Connection and Coffee Meetup (00:02:06)
Product Managers as CEOs and Co-founders (00:02:59)
Empowering Product Managers (00:05:01)
Product Management and Marketing Importance (00:08:04)
Email as a Content Repository (00:09:39)
Securing Email Content (00:11:03)
Data Protection for Email (00:12:10)
Redacting and Canaries (00:12:57)
Email Security vs. Data Security (00:14:53)
Abuse Cases and Control Layers (00:17:32)
Mailbox Compromise and Lateral Movement (00:17:39)
Threat Scenario Analysis (00:20:15)
Language Models for Detection (00:22:19)
Optimism in AI Tools for Defense (00:24:34)
Customized Detection Categories (00:25:52)
Security Controls Trend (00:26:20)
Security Concerns for Law Firms (00:27:07)
Email Copy Distribution (00:27:24)
API-Based Integration (00:29:08)
Monitoring LM Functionality (00:30:42)
Threat Intelligence and Detection (00:32:54)
Product Design Philosophy (00:35:56)
Data Protection (00:38:01)
Flexibility in Deployment (00:39:26)
Main Products (00:40:33)
Posture Management (00:44:01)
Broadening Product Coverage (00:48:49)
Google Workspace Threat Detection (00:50:05)
Challenges with CSP (00:51:13)
Contextual Intelligence (00:52:02)
Balancing Depth and Breadth (00:53:15)
Learning about Material (00:53:40)

Become a Member: https://danielmiessler.com/upgrade

See omnystudio.com/listener for privacy information.

Episoder(531)

Take 1 Security Podcast: Episode 3

Take 1 Security Podcast: Episode 3

START CONTENT * There was an issue with the Marriott website that exposed reservations and payment information. It’s now been fixed * Police are now using a new radar to see into peoples’ homes without a warrant * Security budgets are reportedly going up due to the mega-breaches in 2014 * Also leading to higher pay for CIOs * Anecdotally, I’d say it’s a pretty good time to be in infosec * A new security startup, PFP Cybersecurity, uses power consumption to detect malware * Meant initially to be used for SCADA type systems * The US hacked North Korean computers back in 2010 * This is reportedly the reasons we were so sure they hacked Sony * Recently leaked documents from Snowden show heavy offense * Snowden recently talked to Schneier at Harvard about a number of things * The NSA is becoming increasingly offensively oriented vs. defensive * The NSA supposedly uses compromised systems as jump points * Snowden said most NSA hackers are junior enlisted with limited skills * Russia reportedly hacking for geopolitical gain, not just money * Millions of gas stations could be at risk of shutdown * The Automated Tank Gauges can be remotely accessed by attackers * Could be manipulated to cause alerts * Potentially could be used to stop the flow of fuel * Microsoft gave Charlie Hebdo data to FBI in 45 minutes * Starwood hack based on bad passwords * Bad passwords, password re-use, and a brute forcing tool * Account harvesting is rough: user enumeration, weak passwords, and lack of account lockout * Flash has another major exploit. Update your stuff. * People continue to be worried that the President’s crackdown on hackers could hurt security professionals * Congress is meeting on the 27th of January to discuss breach notification * The wireless in around 2 million cars is highly vulnerable to attack * A polish company has created Mouse-Box, which is an entire computer inside of a mouse enclosure END CONTENT Play Podcast Notes * Sorry about the noise part way through. My girl walked in and started unpacking groceries. But when I say one take, I mean one take. Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

25 Jan 201510min

Take 1 Security Podcast: Episode 2

Take 1 Security Podcast: Episode 2

START CONTENT * UK police arrest 18-year-old in connection to Playstation and XBox attack * Major ASUS router bug * Local users can take full control without a password * Biggest issue there seems to be DNS hijacking * Legislative attacks on infosec profession and encryption * Anti-hacking law language ambiguous “according to owner” * Obama is said to agree with Cameron, but it’s complicated * Evidence of a plot is different than outlawing encryption * There’s other talk about it being illegal to see hack data * French reporting 19,000 DoS attacks since the shootings * Anonymous is going after ISIS and others * An attack on free speech is an attack on Anonymous * Google releases another Windows flaw that they didn’t fix * Verizon API vulnerability exposes customer email addresses * Issue was with a mobile API used by Android devices * Allowed him to retrieve peoples’ emails and send emails as them * On whether we should trust the FBI regarding the Sony attack * We now find out the attribution came from a previous NSA hack * It’s hard to criticize without data * This doesn’t mean they did it, or that the FBI is always right, or that they should always be trusted * It means be cautious when you don’t have any information, and the person you’re criticizing has all of it * Free speech and the Paris attacks * Where is the line for free speech? * I think it comes down to safety and taste * You can’t yell fire, and art matters * Quote of the week * No one is as happy as they seem on Facebook, as depressed as they seem on Twitter, or as employed as they seem on LinkedIn. END CONTENT Play Podcast Notes * I have a consolidated InfoSec news feed (here) that I use as a source for headlines. Become a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

19 Jan 201515min

Take 1 Security Podcast: Episode 1

Take 1 Security Podcast: Episode 1

Subscribe to the Podcast: iTunes | Android | RSS START HEADLINES * Google drops security updates for Android 4.3 and below * This is a problem since that’s most of the install-base * Only .1% of users are on Android 5 * Microsoft and Adobe Push Critical Security Fixes * Seems like Google’s been messing up recently, with their attack on Whitehat for the Aviator stuff, their dropping security updates for Android, and now this early release of a bug before there was a fix. * Obama is asking for the removal of a number of state laws that make it harder to get good broadband in the US. * Obama is asking for quicker laws around the disclosure of hacks * One potential law is the Personal Data Notification and Protection Act, which would require companies to notify within 30 days if they get hacked. * The CENTCOM Twitter account got hacked a couple of days ago by some pro-ISIS folks * Obama is looking to improve the sharing of cybersecurity information as a response to the hack * Sammy Kamkar has released a keylogger for Microsoft wireless keyboards, called Keysweeper * David Cameron wants to make encrypted messaging apps illegal * 1) I’m not sure how he thinks this is possible Subscribe to the Podcast: iTunes | Android | RSSBecome a Member: https://danielmiessler.com/upgradeSee omnystudio.com/listener for privacy information.

14 Jan 20153min

Populært innen Teknologi

romkapsel
rss-avskiltet
teknisk-sett
tomprat-med-gunnar-tjomlid
energi-og-klima
rss-impressions-2
shifter
nasjonal-sikkerhetsmyndighet-nsm
elektropodden
fornybaren
rss-alt-vi-kan
rss-alt-som-gar-pa-strom
smart-forklart
rss-snakk-om-sikkerhet
teknologi-og-mennesker
kunstig-intelligens-med-morten-goodwin
rss-bouvet-bobler
i-loopen
pedagogisk-intelligens
rss-digitaliseringspadden