#367 - RSM & IDAC Present - The Intersection of Attack Surface Management and Identity

#367 - RSM & IDAC Present - The Intersection of Attack Surface Management and Identity

Join hosts Jeff Steadman and Jim McDonald as they explore the critical intersection of attack surface management (ASM) and digital identity with Dan Lauritzen, Director with RSM Defense - RSM’s Managed Security Team. This episode dives deep into how identity has become a key component of your organization's attack surface and why breaking down silos between identity teams and Security Operations Centers is more crucial than ever.

Dan brings a unique perspective from his military background as a human intelligence collector to his current role in detection and response. Learn about the cyber kill chain, understand when you might have too much data, and discover practical strategies for treating identities as assets that need continuous protection.

Whether you're an identity practitioner looking to expand your security knowledge or a cybersecurity professional wanting to better understand identity's role in attack surface management, this conversation offers valuable insights and actionable takeaways.

Key topics include XDR platforms, ITDR tools, the evolution from legacy SIEM to modern detection systems, and why the future of security requires collaboration between traditionally separate teams.


Chapter Timestamps

00:00 - Introduction and Industry Trends

01:00 - AI and Technology Disruption Discussion

02:00 - Upcoming Conference Schedule and Discount Codes

04:00 - Podcast Milestone - Approaching One Million Downloads

06:30 - Introducing Dan Lauritzen and RSM Defense Team

09:00 - Dan's Background - From Military to Cybersecurity

12:00 - What is Attack Surface Management?

14:00 - Treating Identities as Assets

16:00 - The Cyber Kill Chain Explained

18:00 - Why Identity and SOC Teams Operate in Silos

21:00 - The Role of Data in Modern Security Operations

23:00 - Continuous Identity Management and Shared Signals Framework

26:00 - Can You Have Too Much Data?

29:00 - Breaking Down Silos Between Identity and SOC Teams

32:00 - Practical Collaboration Strategies

34:00 - SIEM vs XDR vs ITDR - Understanding the Tool Landscape

41:00 - Pragmatic Security Strategies and Metrics

44:00 - Biggest Misconceptions About Attack Surface Management

45:00 - Military Background - Human Intelligence Collection

48:00 - Communication Tips for Better Information Gathering

51:00 - Closing and Contact Information


Connect with Dan: https://www.linkedin.com/in/daniel-lauritzen-67545045/

Cyber Kill Chain: https://en.wikipedia.org/wiki/Cyber_kill_chain

Learn more about RSM:


Connect with us on LinkedIn:

Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/


Visit the show on the web at http://idacpodcast.com


Keywords

IDAC, Identity at the Center, Jeff Steadman, Jim McDonald, Dan Lauritzen, RSM, attack surface management, cybersecurity, digital identity, SOC, Security Operations Center, XDR, ITDR, SIEM, cyber kill chain, detection and response, identity security, human intelligence, military cybersecurity, continuous identity management, shared signals framework, UEBA, threat detection, zero trust, privileged access management, identity governance, security metrics, vendor management, cloud security, endpoint security, data correlation, security silos, collaboration strategies, identity assets, orphaned accounts, entitlement creep, attack surface reduction, security automation, AI in security, machine learning security, identity sprawl, security tools, cybersecurity consulting, managed security services, security monitoring, incident response, threat hunting, vulnerability management, risk assessment, compliance, security architecture, defense strategy


Avsnitt(392)

Identity At The Center #40 - IAM ROI

Identity At The Center #40 - IAM ROI

Jim and Jeff talk about how to develop a Return on Investment (ROI) strategy when it comes to IAM. Link to Auth0 Forrester report we discuss: https://auth0.com/forrester-total-economic-impact/ Risk Management Concepts: https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/security-and-risk-management/cissp-risk-management-concepts/ Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

20 Apr 202039min

Identity At The Center #39 - Digital Transformation and CIAM

Identity At The Center #39 - Digital Transformation and CIAM

Jim and Jeff talk about how consumer/customer IAM (CIAM) is a fundamental part of a digital transformation strategy. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

13 Apr 202042min

Identity At The Center #38 - Data Privacy Regulations are Dead On Arrival with Richard Bird

Identity At The Center #38 - Data Privacy Regulations are Dead On Arrival with Richard Bird

Jim and Jeff talk with Richard Bird, Chief Customer Information Officer at Ping Identity, about data privacy and why data privacy regulations are dead on arrival. LinkedIn article by Richard: https://www.linkedin.com/pulse/data-privacy-joke-your-town-nation-richard-bird/ Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

6 Apr 202050min

Identity At The Center #37 - Access Management with Andy

Identity At The Center #37 - Access Management with Andy

Jim and Jeff talk with Andy Clark, Principal Consultant at Okta, about access management including the why's of OIDC and SAML, scopes, and flows. To register for the free virtual Oktane 2020 conference, visit https://www.oktane20.com/ Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

30 Mars 202036min

Identity At The Center #36 - Assessing CIAM Maturity

Identity At The Center #36 - Assessing CIAM Maturity

Jim and Jeff talk about how assessing CIAM (customer/consumer identity & access management) can be different than an enterprise IAM assessment. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

23 Mars 202050min

Identity At The Center #35 - Managing IAM Through A Pandemic

Identity At The Center #35 - Managing IAM Through A Pandemic

Jim and Jeff talk about the current global health situation and things to consider from an IAM perspective. Jeff also finds a way to talk baseball with Jim as it relates to the Houston Astros and their brute force hacking of pitchers and catchers for the last few seasons (allegedly). Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

16 Mars 202045min

Identity At The Center #34 - Managing IAM Risk with Esteban

Identity At The Center #34 - Managing IAM Risk with Esteban

Jim and Jeff talk with Esteban about the approach he takes in managing IAM risk for his organization. The Institute of Internal Auditors (IIA) Position Paper: The Three Lines Of Defense In Effective Risk Management And Control Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

9 Mars 202035min

Identity At The Center #33 - IAM for IoT

Identity At The Center #33 - IAM for IoT

Jim and Jeff talk about a topic suggested by listener Kerem B.; How to approach IAM for IoT (Internet of Things). For more IoT Security info, visit www.iotsecurityfoundation.org Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

2 Mars 202029min

Populärt inom Teknik

uppgang-och-fall
natets-morka-sida
elbilsveckan
market-makers
rss-laddstationen-med-elbilen-i-sverige
rss-uppgang-och-fall
rss-elektrikerpodden
bilar-med-sladd
rss-badfluence
rss-technokratin
developers-mer-an-bara-kod
skogsforum-podcast
hej-bruksbil
rss-racevecka
rss-veckans-ai
bli-saker-podden
rss-digitala-influencer-podden
har-vi-akt-till-mars-an
rss-snacka-om-ai
under-femton