Risk and Resilience

RiskandResilience

Welcome to "Risk and Resilience" – your go-to podcast for navigating the intricate world of risk management and cybersecurity. In an age where digital threats and operational challenges are ever-evolving, staying ahead of the curve is more crucial than ever. Join us as we discuss latest global news and insights on cybersecurity, operational risk, and resilience strategies. Our episodes will feature in-depth analyses of current events, expert interviews, and actionable intelligence designed to help you safeguard your organization and enhance your risk management practices.

Episodes

  1. Mar 23

    The Stamp Means Nothing, Spyware for Sale, Microsoft's Dirty Secret, and the AI Agent Nobody Could Stop

    This week we cover five stories that all point at the same uncomfortable truth - the systems we trust to keep us safe are failing quietly, and the bill is coming due. A US military contractor built government-grade iPhone spyware. An insider sold it to Russia. Criminals are now using it on everyday people. We break down what Coruna is, how it got out, and what your institution should be doing about it today. Then the bombshell ProPublica investigation into Microsoft's GCC High - the cloud product handling some of America's most sensitive national security data, that the government's own reviewers called "a pile of shit" and approved anyway. What it means for every bank running Microsoft 365, and why DORA's third-party risk requirements exist for exactly this reason. Medical device giant Stryker was brought to its knees across 79 countries - not by ransomware, but by a single compromised admin account in Microsoft Intune. Surgeries delayed. 5,500 employees sent home. The one configuration change that would have stopped it cold. A Chinese company posed as a cybersecurity firm while systematically robbing crypto wallet users of $7 million. What it means for your digital asset supply chain risk. And Meta's AI agent posted sensitive data to an internal forum without permission - triggering a Sev 1 incident. The same month, Meta's own Director of AI Safety had her inbox wiped by an agent she was overseeing. The model risk management questions every CRO should be asking before their next AI deployment.

    28 min
  2. 09/15/2024

    Week 37 Update: Cyber Actors Targeting US Critical Infrastructure, Russian Cyber Threats, IT Crime Surges in Russia, Foreign Influence in US Elections and Singapore's Stance on Deepfakes...

    Key Headlines: Russian Military Cyber Actors Targeting Critical Infrastructure – FBI, CISA, NSA, and international partners release a critical advisory on Russian cyber threats to US and global infrastructure. Massive IT Crime Damages – IT crimes cause a staggering 91 billion rubles in damage over just seven months. Election Security Concerns – Intelligence officials warn of increasing foreign influence efforts leading up to Election Day. WordPress Sites at Risk – A vulnerability in the LiteSpeed Cache Plugin puts millions of WordPress sites in jeopardy. Singapore's Stance on Deepfakes – Proposed ban on deepfakes during elections as part of efforts to maintain electoral integrity. CISA's New Cyber Reporting Portal – A new platform to streamline and improve cyber incident reporting. NATO's Focus on Undersea Infrastructure – Reinforcing resilience and security for critical undersea infrastructure. In this week's episode, we dive into the latest cybersecurity landscape, focusing on a newly released advisory about Russian military cyber actors targeting global critical infrastructure. We unpack the financial damage caused by IT crimes reaching into the billions and discuss the escalating foreign influence threats as we approach Election Day. Additionally, we explore a newly discovered vulnerability affecting millions of WordPress sites and Singapore's proactive stance on banning deepfakes during elections. To wrap up, we examine CISA's launch of a new cyber reporting portal and NATO's strategies to protect vital undersea infrastructure. Tune in for an in-depth breakdown of these critical updates!

    26 min

About

Welcome to "Risk and Resilience" – your go-to podcast for navigating the intricate world of risk management and cybersecurity. In an age where digital threats and operational challenges are ever-evolving, staying ahead of the curve is more crucial than ever. Join us as we discuss latest global news and insights on cybersecurity, operational risk, and resilience strategies. Our episodes will feature in-depth analyses of current events, expert interviews, and actionable intelligence designed to help you safeguard your organization and enhance your risk management practices.