
From the usage of anti-money laundering software all the way to endpoint security, the enterprise space is always preparing for the next attack. Recognising the fact that as much as you train and prepare your organisation, adversaries will also continue to advance can be anxiety inducing. Yes, organisations lose billions every year to fraud and the beginning of 2021 was met with a huge influx in cybercrime, but it's the methods that the adversaries are using that is truly concerning.
Social engineering is a method used by adversaries in the cyberspace that works by gaining the trust of their target. By impersonating a colleague, bribing or blackmailing the victim or even just assuming the voice of an authoritative figure, adversaries are coercing employees into cooperating and, potentially, into wiring money to them. It's psychological warfare and it's not slowing down; social engineering attacks make up 98% of attacks every year, so what can you do to prevent it?
Educating us in this episode of The Next Phase of Cybersecurity is Greg Hancell, Senior Manager Fraud Consultancy a OneSpan. Greg details to us the use of automation in fraud operations, how AI is saving banks and what current methods an adversary might use in conducting a social engineering attack.
May 18, 2021
26 min

As businesses become more complex it opens up numerous issues that need to be accounted for including business processes, critical business and IT functions, and third-party relationships. These factors can be hard to coordinate across departments and this lack of visibility makes it difficult to prove and report that continuity and recovery plans are in place and will work as intended. Resiliency programs allow for a proactive approach in order to address and mitigate resiliency risk to your organisation. Resiliency requires building processes and technologies that naturally adapt to adverse conditions, make mid-course corrections, and avoid any negative impacts of disruption.
In this podcast, Ben Tuckwell, UK District Director at RSA Security talks about building business resiliency. To begin with, Ben explains how organisations can ensure they have optimal business continuity and processes in place. Furthermore, he explains how organisations should approach a business impact analysis to understand what is happening. Also, Ben outlines how to monitor third party ecosystems to manage related security, access, compliance, and resiliency risks. Finally, he talks about how to conduct risk assessments for understanding a vendor’s residual risk and reducing it.
Feb 15, 2021
18 min

The need to adapt corporate IT systems to support more flexible working is not new. The response of businesses to these trends over the last two decades has been on a spectrum from highly supportive – as much flexibility as possible – to highly conservative – the risks are too great. These risks, that have held many businesses back, include the loss of control over what employees are doing and who they are interacting with, to the danger of corporate and controlled personal data getting into the wrong hands. Since the forced lockdown even the most conservative businesses have recognised the benefits of homeworking for both employees and employers.
In this podcast, Bob Tarzey speaks to Kowsik Guruswamy, Chief Technology Officer at Menlo Security about the challenges related to remote working and the technology options available to support it. Kowsik explains the main risks that arise with increased home working especially for businesses who have not adopted it previously. He also explains how homeworkers can have an experience that is as secure as office workers. Finally, he outlines how to improve performance and security for home workers.
Feb 1, 2021
21 min

The impact of cyberattacks on organisations is widespread not only from a financial standpoint, but also the operational disruptions, damaged brand reputations, and trust within the organisation. Traditional email security solutions aren’t enough to protect businesses anymore. Processes need to be in place to actively defend against sophisticated email threats. These threats are often able to bypass defences by using numerous backdoor techniques.
In this podcast, Olesia Klevchuk, Senior Product Marketing Manager at Barracuda explores different email threat types and what measures can be taken to protect organisations. To begin with, Olesia explains some of the thirteen threats we’re currently seeing and the impact of these on organisations. Then, she outlines what gateway protection is and how this can be beneficial. Further to this, she explains how API-based inbox defence is implemented and what attacks it can block. Finally, Olesia showcases the strategies that organisations can implement to stay on top of rising risks.
Jan 18, 2021
26 min

The majority of organisations have been working from home for the last few months amidst the COVID-19 pandemic. This rapid change has bought many new challenges for organisations to overcome. One of these challenges has been how we secure remote users and maintain security control for the organisation. The concept of Zero Trust is emerging as the preferred remedy for addressing remote work security challenges. The fundamental goal is to avoid reliance on trusted networks and to treat every system as an untrusted host.
In this podcast, Chris Steffen speaks to Krupa Srivatsan, Director of Product Marketing at Infoblox. Firstly, Krupa outlines the new trends they have seen customers face around security problems and adapting to this new form of working. Then she offers advice for security professionals dealing with remote working challenges. Also, Krupa outlines her views on Zero Trust and how it affects remote workers in relation to improving security. Finally, she explains how Zero Trust can help with compliance-related challenges.
Jan 4, 2021
24 min

For organisations that want to ensure safe, scalable, and efficient access to their services, effective identity and access management solutions are essential. However, ensuring maximum security and maintaining a smooth user experience is a challenge. The more we move into the digital environment, the more each company must focus on these aspects and construct the identity and access management (IAM) programs with the users in mind.
In this podcast, Kris Imbrechts, Regional Director Northern and Southern Europe at Auth0 explains the business balancing act between user experience and security. To begin with, Kris explains the current state of IAM solutions in the market and how organisations are approaching implementation. Further to this, he outlines the build vs buy strategy and the importance of a seamless and almost invisible IAM solution. Finally, Kris looks at maintaining trust in users and the considerations needed for longevity and safety when implementing apps.
Dec 21, 2020
20 min

Keeping your business safe requires a proactive analysis of potential online threats. This requires more than details of latest malware and software vulnerabilities. Intelligence is also required about what is happening in cyberspace that may represent a specific threat to your business. The deepest recesses of the web need probing to gathering this intelligence. Not just the clear web, the websites that we all use on a day-to-day basis, but also the dark and, where possible, deep web.
In this podcast, https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) speaks with https://www.linkedin.com/in/cwillhoite/ (Charity Wright), Cyber Threat Intelligence Advisor and https://www.linkedin.com/in/etaymaor/ (Etay Maor), Chief Security Officer at https://intsights.com/ (IntSights). Firstly, they outline some use cases for external threat intelligence and the types of risks that can be mitigated. Then, they discuss how to probe the dark web in terms of identifying threats but also using analysis effectively. Finally, they explore how IntSights uses this analysis for mitigating threats.
Dec 7, 2020
25 min

Manual incident response processes, insufficient workflows and difficulty hiring security personnel leave security operations teams struggling to keep up with the growing volume of alerts. SOAR solutions combine automated data gathering, security automation, case management and analytics to provide organisations the ability to speed up the incident response process.
In this podcast, https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) speaks with https://www.linkedin.com/in/codycornell/ (Cody Cornell), Co-founder and CEO at https://swimlane.com/ (Swimlane), a U.S. based independent SOAR solution provider. Cody introduces how businesses are adopting SOAR tools and explains the ease in which they are deployed. He also provides some use cases for the type of workflows that SOAR enables that were previously hard to achieve. Finally, Cody details how different sized enterprises can access and use SOAR effectively and how he sees Swimlane evolving and contributing to the industry over the coming years.
Nov 23, 2020
18 min

As security requirements evolve, so must the policies surrounding them. Today, businesses are responsible for updating policies consistently across all relevant security devices regardless of function and supplier. Given the sheer volume, a manual approach would be too impractical. Thus, organisations must turn to specialist products that harness automation as a means to cover more diverse security requirements and enhance security analytics and intelligence.
In this podcast, https://www.linkedin.com/in/bob-tarzey/ (Bob Tarzey) speaks with https://www.linkedin.com/in/lintell/ (Andrew Lintell), Vice President and Managing Director, EMEA at https://www.firemon.com/ (FireMon). Andrew introduces the FireMon brand and how diverse the devices are that such vendors cater for. He also details the role that vendors like FireMon play in SecDevOps. As well as this, Andrew explains how FireMon helps in ensuring that organisations’ security systems are compliant and how it can prove this to the relevant regulatory bodies.
Nov 9, 2020
23 min

The advent of DevOps was hailed as a means to have all aspects of application deployment handled by one single team. However, over time, concerns surrounding security have begun to arise. Many feel that security should be more of a priority for Development and DevOps teams, particularly in regard to applications. On the one hand, apps are a modern necessity to drive business success. However, on the other hand, they come with a host of security problems that need special attention, necessitating DevSecOps in turn.
Joining us to lend his expertise on this matter is Jeff Martin, Senior Director of Product at WhiteSource. Firstly, Jeff explains whose responsibility AppSec actually is and how organisations ultimately create DevSecOps. He then demonstrates what the typical ‘DevSecOps’ workflow should look like. Finally, he outlines the benefits of open source tools and how important security procedures are for businesses and their DevOps efforts.
Oct 26, 2020
23 min
Load more
