Into the Breach by IBM

IBM
Into the Breach by IBM

Whether you are an individual who is always on your phone, an IT professional who lives through your laptop, or an organization that manages a vast amount of clients and services, a security breach can happen at any moment. Many of us think that we are prepared, but are we really? On this podcast, you’ll hear from a variety of cybersecurity professionals to better understand the underground world of cyber and you’ll walk away better prepared with tales, tools, and support to help you thrive in the face of uncertainty…

  1. 07/10/2023

    Cyber leaders: Stop being your own worst career enemy. Here’s how.

    Technically proficient people often face challenges when looking for (or being elevated to) leadership roles. In the cyber realm, this can become even murkier. We have hackers, who often view rules as guideposts (or even challenges, for that matter); incident responders and threat intelligence officers who tend to have great regard for rules and a well-developed (if not regimented) approach to unraveling mysteries; and product engineers who are astute at design and technical issue resolution. The net is this: Cyber brainiacs are really good at solving problems. And less good at inspiring (or even allowing) others to solve them. In this episode, host Mitch Mayne talks with Brian Donovan, author of "Leadership Is Changing the Game - The Transition from Technical Expert to Leader." They explore some of the critical components of cyber leadership—including Donovan’s perspective that the trick isn’t to develop an entirely new skill set—or superpower, as he puts it—but to hone your existing superpower and learn how to influence and inspire. If you’ve ever wondered how to get out of your own way and transition into cyber leadership, this may be the episode for you. Take a listen—and venture Into the Breach. Things to listen for: [00:05 - 01:20] Introduction[03:05 - 05:34] Mitchs' journey to leadership in the cyber world[06:07 - 07:42] Challenges technically smart people might run into when stepping into a leadership role[08:24 - 12:43] Turning your strengths into superpowers in leadership[18:09 - 20:50] Imposter syndrome within cyber leadership[29:02 - 31:10] What Brian learned from his best manager[32:20 - 34:49] Advice to be a great leader in cyber

    36 min
  2. 06/28/2023

    Threat sharing evolution: How groups offer less risk and better intelligence to members

    It’s been eight years since the Cybersecurity Information Sharing Act was signed into law, and today we have a thriving network of public/private threat sharing groups—like the Joint Cyber Defense Counsel (JCDC) and National Artificial Intelligence and Cybersecurity ISAO (NAIC/ISAO), offering platforms where member organizations can both share threat information and gain access to the larger collection. Yet, perception challenges still exist for threat sharing groups. These include both liability and confidentiality concerns, with some organizations wondering if information shared in a group could be traced back to—and used against—the organization that shared the data in the first place. In this episode, host Mitch Mayne talks with Michael Thiessmeier, Co-founder and Executive Director of the NAIC/ISAO, about the history of threat sharing and how the “public good” has benefitted. They also explore the perceived hurdles to entering threat sharing groups and explore whether or not those are legitimate concerns. Things to listen for: [00:05 - 01:41] Introduction[03:23 - 05:54] Notable wins as a result of groups sharing intelligence[06:19 - 07:23] What information to consider sharing in an information-sharing group[11:00 - 14:03] Has trust been restored that the government does the right thing in terms of privacy and surveillance?[20:09 - 21:23] Michaels information products[22:15 - 23:20] Why threat sharing is important

    25 min
  3. 03/23/2023

    Operational Technology: The evolving threats that might shift regulatory policy

    Attacks on Operational Technology (OT) and Industrial Control Systems (ICS) grabbed the headlines more often in 2022—a direct result of Russia’s invasion of Ukraine sparking a growing willingness on behalf of criminals to target the ICS of critical infrastructure. Conversations about what could happen if these kinds of systems were compromised were once relegated to “what ifs” and disaster movie scripts. But those days are behind us, and the threats to OT and ICS are real and ongoing. Roya Gordon and her team at Nozomi Networks keep a close eye on these kinds of threats, and recently released their biannual OT/IoT Security Report that examines what’s happened in the landscape for this sector in the latter half of 2022. She joins me in this episode to talk in-depth about what her team found—including the latest on the types of attacks hitting OT and IoT, what effect increased regulation may have on industries in this sector, how Russia’s invasion of Ukraine continues to change the landscape, and what may be on the horizon for cyber insurance. And maybe most importantly, she helps us understand what OT/IoT organizations can do to stay safer. Join us—and together we’ll venture Into the Breach. Things to listen for: [00:05 - 00:44] Introduction[01:00 - 02:50] Important pieces from Nozomi's security report[03:23 - 05:21] Threat actors Roya sees at Nozomi[06:16 - 08:10] Roya explains being anti-cyber insurance[11:40 - 15:21] Sector-specific plans: What do we know and are they needed?[16:19 - 17:21] International efforts for a safer sector[20:45 - 23:06] Advice for loT and OT friends

    32 min
  4. 02/21/2023

    2023 Cybersecurity Predictions

    In this episode, we’ll use 2022 as a lens to foretell what this year may have in store for us. Joining me is Dan Lohrmann, a well-known voice in cybersecurity whose resume boasts an impressive list of positions in cyber leadership in both the public and private sector, in addition to authorship of three books on cybersecurity.   Dan publishes an annual review of top cyber organization predictions (check out Part One and Part Two). Think of them like a content analysis of over two dozen industry leading reports. Among those surveyed is the 2022 IBM Security X-Force Threat Intelligence Index and our annual predictions blog published just last month. And of course, I’d miss the chance to humble-brag if I didn’t tease the fact that we’ll be releasing our 2023 Threat Intelligence Index in early February, too, so stay tuned for that one.     Given the hours he’s devoted to analyzing the market predictions, Dan’s view is both broad and deep. We’re going to utilize his expertise to focus on a few hot topics for 2023:   ·       Ransomware: How it will evolve, and who may be targeted ·       Social engineering: How increased sophistication (including attempts to bypass MFA) may impact business ·       Cyber insurance: Will it become more difficult to get in 2023 ·       The Ukraine war: What fallout we might expect this year ·       Crypto and social media: Given the tumult in 2022, what we might see changing both on a market and a policy front   Join us, and together we’ll venture Into the Breach. Things to listen for: [00:05 - 01:17] Introduction[07:21 - 08:58] What we got right in 2022[09:52 - 12:29] What we might see for ransomware in 2023[13:50 - 16:33] What we might see in terms of social engineering, and what will be the role of deep fakes?[17:37 - 19:55] Insurance providers in 2023[25:06 - 26:08] Changes in crypto, and will there be a push to regulate?[29:07 - 30:17] Potential positives to look for in 2023

    31 min

Ratings & Reviews

4.8
out of 5
5 Ratings

About

Whether you are an individual who is always on your phone, an IT professional who lives through your laptop, or an organization that manages a vast amount of clients and services, a security breach can happen at any moment. Many of us think that we are prepared, but are we really? On this podcast, you’ll hear from a variety of cybersecurity professionals to better understand the underground world of cyber and you’ll walk away better prepared with tales, tools, and support to help you thrive in the face of uncertainty…

To listen to explicit episodes, sign in.

Stay up to date with this show

Sign in or sign up to follow shows, save episodes, and get the latest updates.

Select a country or region

Africa, Middle East, and India

Asia Pacific

Europe

Latin America and the Caribbean

The United States and Canada