Episode 215 Deep Dive: Edwin Kwan | Navigating the Wild West: Tools and Techniques to Assess the Security and Integrity of Open Source Software
KBKAST6 Okt 2023

Episode 215 Deep Dive: Edwin Kwan | Navigating the Wild West: Tools and Techniques to Assess the Security and Integrity of Open Source Software

In this episode, we are joined by Edwin Kwan (Head of Application Security and Advisory – Tyro Payments), as he sheds light on the meticulous risk acceptance process and shares his insights on using open source software to build applications swiftly with freely available parts. We explore the challenges of ensuring the security of open source software and the need for due diligence when downloading such software. Edwin raises thought-provoking questions about software verification, maintenance, and security, highlighting the tricky balance between maintaining security protocols and accommodating a wide range of individuals in the workplace.

Stay tuned as we examine the potential risks of using open source software and the complexities of explaining security issues to individuals who may not fully grasp their implications. Edwin shares captivating stories and real-life examples, including incidents where businesses chose to accept high-severity risks rather than investing in their mitigation.

Edwin a cybersecurity specialist whose approach towards security is to raise awareness, provide light touch controls to the software development life cycle to increase visibility of security issues, and work closely with engineering teams to quickly develop secure applications.

He started out as a software engineer and transitioned into application and information security to lead a range of security initiatives when the company was working towards obtaining an unrestricted banking licence.

He has presented at several events, including RSA, AISA, All Day Dev Ops, AppSec Day, OWASP and DevSecOps Leadership Forums.

Edwin is also a contributing journalist to the It’s 5:05 Podcast, a daily podcast on open source and cybersecurity news.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(435)

Episode 382 Deep Dive: Quinton Anderson | Trust the System, Not the Agent – Zero Trust for the Agentic Enterprise

Episode 382 Deep Dive: Quinton Anderson | Trust the System, Not the Agent – Zero Trust for the Agentic Enterprise

KB sits down with Quinton Anderson, founder of Aigentsphere, to challenge one of the most repeated lines in AI governance: that a human in the loop keeps you safe. His view is that asking people to ap...

26 Aug 49min

Episode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure

Episode 381 Deep Dive: Gijo Varghese | When a Cyber Attack Becomes a Public Safety Failure

Karissa Breen sits down with Gijo Varghese, Chief Security Officer at OT cyber security firm Secolve, to unpack an uncomfortable trade-off: the same connectivity and AI making power, water and transpo...

19 Aug 47min

Episode 380 Deep Dive: Mark Thomas | Owning a Policy PDF Doesn't Mean You Govern Your AI

Episode 380 Deep Dive: Mark Thomas | Owning a Policy PDF Doesn't Mean You Govern Your AI

In this episode, KB sits down with Mark Thomas, IT governance and risk veteran, ISACA Hall of Famer and president of Escoute Consulting, to pull apart a problem a lot of boards haven’t clocked yet – t...

12 Aug 47min

Episode 379 Deep Dive: Sean Duca | Confidence Is Not Permission - Rethinking Authority in the Autonomous SOC

Episode 379 Deep Dive: Sean Duca | Confidence Is Not Permission - Rethinking Authority in the Autonomous SOC

Most security vendors are shipping AI that treats capability as authority. Sean Duca thinks that’s the mistake customers are already paying for. Back on KBKast for a third time, now as co-founder and ...

5 Aug 42min

Episode 378 Deep Dive: Harman Kaur | Automation Isn't Transformation - From Intent to Outcome in Autonomous IT

Episode 378 Deep Dive: Harman Kaur | Automation Isn't Transformation - From Intent to Outcome in Autonomous IT

The old security math is broken. Teams used to get roughly 60 days between a vulnerability going public and attackers using it. Harman Kaur, Tanium’s CTO, explains why that number has flipped to negat...

29 Juli 39min

Episode 377 Deep Dive: Bradon Rogers | The Forgotten Workspace - Why Nobody Ever Secured the Browser

Episode 377 Deep Dive: Bradon Rogers | The Forgotten Workspace - Why Nobody Ever Secured the Browser

Bradon Rogers, Chief Customer Officer at Island, the company that created the enterprise browser category in 2020, joins KB to unpack why the industry spent two decades bolting security around the bro...

22 Juli 39min

From SAP Sapphire - KB On The Go | Legacy Risk and the AI Trust Gap

From SAP Sapphire - KB On The Go | Legacy Risk and the AI Trust Gap

KB is on the ground at SAP Sapphire 2026 in Orlando, where AI has moved beyond experimentation and into the center of enterprise decision making. In this KB On The Go episode, Maura Hameroff (CMO, Clo...

17 Juli 33min

Episode 376 Deep Dive: Anna Wheeler | Synthetic Confidence - When the Board Believes the Machine

Episode 376 Deep Dive: Anna Wheeler | Synthetic Confidence - When the Board Believes the Machine

In this episode, Anna Wheeler, CEO of SSAW LLC, joins KB as she explains why so many cyber teams are stuck in event-driven strategy while calling it the real thing, why the doers can’t climb out of it...

15 Juli 39min

Populärt inom Business & ekonomi

framgangspodden
rss-jossan-nina
varvet
badfluence
uppgang-och-fall
svd-tech-brief
rss-inga-dumma-fragor-om-pengar
skaraborgspodden
bathina-en-podcast
avanzapodden
rss-borsens-finest
tabberaset
rss-dagen-med-di
rss-kort-lang-analyspodden-fran-di
24fragor
dynastin
rss-hos-psykologen
borsmorgon
fill-or-kill
rikatillsammans-om-privatekonomi-rikedom-i-livet