Protecting the Neglected: Measuring County Cyber Risk with Dr. Ido Sivan Sevilla

Protecting the Neglected: Measuring County Cyber Risk with Dr. Ido Sivan Sevilla

Dr. Ido Sivan Sevilla joins host Caleb Tolin⁠⁠⁠ to break down battlefield stories from a massive analysis of over 3,000 local government entities. Dr. Sivan Sevilla, who serves as an Assistant Professor at the UMD College of Information and holds joint positions at the Hebrew University School of Public Policy & Governance and the School of Computer Science and Engineering, brings a multidisciplinary lens to the alarming reality of risk clusters. Their discussion moves past theory to explore how hundreds of counties share identical IP addresses and third-party service providers, creating centralized points of failure that attackers can identify using data. The dialogue highlights the dual-use nature of modern AI models. While these tools allow adversaries to automate exploit generation for open-source software, Dr. Sivan Sevilla, leveraging his expertise as founder of UMD's Tech Policy Hub, explains how defenders can use AI operations to map their own attack surfaces for free. By utilizing honeypots and large language models, limited-resource organizations can transition from reactive patching to a proactive posture. The episode concludes with a strategic look at identity resilience, advocating for adaptive regulations that learn from compliance data rather than static, outdated legislative mandates. Resources CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog This research was conducted by Dr. Ido Sivan Sevilla, Dr. Charles Harry, and Mr. Mark McDermot, with additional support from student researcher Mr. Parthav Poudel What You’ll Learn How to prioritize the 3% of vulnerabilities that actually result in real-world exploitation. The definition of attack surface diversity versus severity in measuring county level risk. The impact of LLMs on identifying flaws in open source software for attackers and defenders. Why risk clusters create a single point of failure for hundreds of independent county governments. Methods for conducting ethical passive reconnaissance to map organizational security postures from the outside. How adaptive regulations can improve compliance by learning from real-time security data and metrics. The strategic benefit of using honeypots to monitor targeted threats against limited-resource digital infrastructure.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(54)

Running the Inverted Offensive Campaign with Adam Karcher

Running the Inverted Offensive Campaign with Adam Karcher

What happens when the adversary’s dwell time is measured in years, but your defense is measured in tickets? Adam Karcher, FBI Supervisory Special Agent, Cyber Division, and a member of the Bureau’s AI...

26 Maj 35min

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

In this episode, host⁠ ⁠Caleb Tolin⁠⁠ explores the battlefield of enterprise defense, which has moved from simple data theft to ultra heinous crimes that put patient outcomes at risk. Guest⁠ ⁠Cynthia ...

5 Maj 29min

The Three-Layer Strategy for Autonomous Agent Governance with Joe Hladik and Amit Malik

The Three-Layer Strategy for Autonomous Agent Governance with Joe Hladik and Amit Malik

The race for AI dominance has created a dangerous imbalance between business velocity and cyber resilience. In this episode, host Caleb Tolin is joined by Joe Hladik, Head of Rubrik Zero Labs, and Sta...

21 Apr 32min

Detecting Adversary Intent: Analyzing Behavioral Tells in Admin Logs with Allison Wikoff

Detecting Adversary Intent: Analyzing Behavioral Tells in Admin Logs with Allison Wikoff

Adversaries are already logging into your network using your own admin credentials. In this episode, Caleb Tolin sits down with Allison Wikoff to move past the identity clichés and analyze the specifi...

14 Apr 20min

Downtime in Healthcare is Fatal: Achieving Resilience in Health & Life Sciences

Downtime in Healthcare is Fatal: Achieving Resilience in Health & Life Sciences

Cybersecurity in healthcare is undergoing a critical shift. What was once viewed as a back-office IT concern is now directly tied to patient safety and clinical outcomes. In this episode of Data Secur...

7 Apr 25min

AI Takes Over RSAC Conference (Now What?) with Dave Bittner.

AI Takes Over RSAC Conference (Now What?) with Dave Bittner.

In this RSAC Conference recap, Dave Bittner, Host of The CyberWire Daily, joins Data Security Decoded host Caleb Tolin from the guest seat to unpack the biggest theme dominating the conference: artifi...

31 Mars 16min

Your Backups Are Talking — Are You Listening?

Your Backups Are Talking — Are You Listening?

Security teams spend enormous effort chasing the latest threats, yet often overlook one of the most revealing sources of truth already in their environment: backups. In this episode of Data Security D...

17 Mars 17min

Populärt inom Business & ekonomi

framgangspodden
varvet
badfluence
rss-borsens-finest
uppgang-och-fall
svd-tech-brief
avanzapodden
fill-or-kill
lastbilspodden
24fragor
rss-dagen-med-di
bathina-en-podcast
rss-jossan-nina
borsmorgon
tabberaset
rss-kort-lang-analyspodden-fran-di
kapitalet-en-podd-om-ekonomi
rss-inga-dumma-fragor-om-pengar
rikatillsammans-om-privatekonomi-rikedom-i-livet
kvalitetsaktiepodden