The Cyber Security Council

Brian Greene and Scott Brammer

The Cyber Security Council (TCSC) is a community forum for Cyber leaders. Its mission is to elevate premier voices in cyber, and strengthen the cyber community itself. TCSC seeks to demystify and simplify cyber across the business landscape.

  1. 12/01/2024

    Hockey and Data Breaches with Bankim Tejani

    Can a Hockey Referee overcome a Data Breach? Yes. Summary In this episode of the Cyber Security Council Podcast, Scott Brammer interviews Bankim Tejani, a distinguished engineer and CISO, who shares his extensive experience in cybersecurity, particularly focusing on the MyFitnessPal data breach. The conversation explores Bankim's career journey from software development to security, the importance of emotional intelligence in crisis management, and the lessons learned from navigating organizational politics in application security. Bankim emphasizes the significance of trust, values, and leadership in incident response, particularly during high-pressure situations like data breaches. Takeaways - Bankim Tejani has a diverse background in software development and security. - The MyFitnessPal data breach was disclosed within four days, showcasing effective incident response. - Building trust within teams is crucial for effective incident management. - Emotional intelligence plays a key role in navigating crises. - Hockey refereeing has taught Bankim valuable decision-making skills under pressure. - Positioning within an organization can impact the effectiveness of security measures. - Organizational politics can hinder the implementation of effective security practices. - Lessons learned from past projects can shape future security strategies. - Values and leadership are essential in guiding incident response efforts. - The importance of timely communication during a data breach cannot be overstated. Special Guest Bankim Tejani https://www.linkedin.com/in/bankimtejani/ Senior Director of AppSec at major Texas-based company 👉 Follow The Cyber Security Council and tune in to our podcast! 🔔 Don't forget to follow, like and subscribe. The Cyber Security Council: Website: https://lnkd.in/gkbqBPW3 LinkedIn: https://lnkd.in/ggkcxHTi YouTube: https://bit.ly/4dlQErn Apple Podcast: https://bit.ly/3WpeCvd TCSC Host Scott Brammer LinkedIn: https://www.linkedin.com/in/scott-brammer TCSC President Brian Greene LinkedIn: https://www.linkedin.com/in/brigreene Keywords data breaches, cybersecurity, incident response, MyFitnessPal, security architecture, emotional intelligence, career progression, software development, AppSec, leadership

  2. 11/25/2024

    Open Source Security with Feross Aboukhadijeh

    Open Source Security is being revitalized. Summary In this conversation, Feross Aboukhadijeh, founder and CEO of Socket, discusses the evolution of open source security, the challenges faced in the software supply chain, and how Socket addresses these issues through real-time threat detection and developer education. He emphasizes the importance of trust in open source dependencies and shares insights on the proactive measures Socket takes to ensure security. The discussion also covers the integration of Socket into developer workflows and the company's success stories in the cybersecurity landscape. Feross is an entrepreneur with a successful exit on his resume. Feross is also a graduate of Stanford, an active venture capital investor, and a talented open source developer who has built WebTorrent, assisted Brave Software, and uplifted Javascript projects. Takeaways - Socket is a developer-first security platform. - Open source security has been an afterthought despite its widespread use. - Software supply chain attacks are on the rise, necessitating better security measures. - Socket provides real-time threat detection for open source dependencies. - The platform integrates seamlessly into developer workflows, enhancing security without hindering productivity. - Developers often pull in dependencies without reviewing their code, increasing risk. - Socket's deep package inspection identifies malicious activity in real-time. - The company has seen success with major clients in AI and finance sectors. - Socket's approach is proactive, addressing vulnerabilities before they can be exploited. - The team at Socket is focused on efficiency and strategic growth. Special Guest Feross Aboukhadijeh https://www.linkedin.com/in/feross/ CEO and Co-Founder at Socket https://www.socket.dev Sound Bites "Secure your dependencies, ship with confidence." "We're helping people to trust the foundation." "We're doing a much deeper scan of the package." "We want to get ahead of it and be as early as possible." "It's the easiest security tool that anyone's ever used." "Developers love it, really." "We're used at a lot of the largest AI companies." "A players hire A players, but B players hire C players." 👉 Follow The Cyber Security Council and tune in to our podcast! 🔔 Don't forget to follow, like and subscribe. The Cyber Security Council: Website: https://lnkd.in/gkbqBPW3 LinkedIn: https://lnkd.in/ggkcxHTi YouTube: https://bit.ly/4dlQErn Apple Podcast: https://bit.ly/3WpeCvd TCSC Host Scott Brammer LinkedIn: https://www.linkedin.com/in/scott-brammer TCSC President Brian Greene LinkedIn: https://www.linkedin.com/in/brigreene Keywords Socket, open source security, software supply chain, developer tools, cybersecurity, threat detection, software vulnerabilities, real-time scanning, developer education

  3. 11/17/2024

    Attack Chains with Sunil Gottumukkala

    When a leader in operating system security speaks, you would be wise to listen. Summary In this conversation, Scott Brammer interviews Sunil Gottumukkala, CEO and co-founder of Averlon, a cloud security platform. Sunil shares his extensive background in cybersecurity, including his time at Microsoft and Salesforce, and discusses the unique approach Averlon takes to address real-world breach risks. He emphasizes the importance of understanding how attackers operate and the need for effective communication between security and engineering teams. Sunil also reflects on his entrepreneurial journey, the milestones Averlon has achieved since coming out of stealth mode, and the innovative technologies that set Averlon apart in the cybersecurity landscape. Sunil covers the evolving landscape of AI in cybersecurity, emphasizing the importance of generative AI as a differentiator. He shares insights on targeting clients who are adopting cloud technologies and highlights success stories from early adopters. He reflects on his foundational experiences at Microsoft (running operating system security!!) and offers advice for aspiring leaders in the tech industry. He also delves into the challenges of navigating venture capital and the importance of software resilience and liability in cybersecurity. Takeaways - Averlon focuses on proactive cloud security. - Averlon aims to predict and prevent cloud attacks. - The long-term vision is to focus on exploitable risks. - Understanding attacker behavior is crucial for risk reduction. - Stealth mode can hinder valuable customer feedback. - Building a strong founding team is essential for success. - Generative AI can enhance cybersecurity solutions. - Effective communication with engineering teams is key. - Real-world breach risk should guide security efforts. - Customer conversations improve product execution. - Averlon's technology visualizes vulnerabilities in an attack chain. - The future of cybersecurity relies on collaboration and innovation. - AI is not just a buzzword; it's a key differentiator. - Generative AI must provide defenders with an asymmetric advantage. - Success stories highlight the importance of effective communication. - Microsoft taught me the discipline of building at scale. - Aspiring leaders should focus on the scope of their impact. - Sales and marketing skills are crucial for startup success. - Invest in resilience and demand it from vendors. Special Guest Sunil Gottumukkala https://www.linkedin.com/in/sunilgottumukkala/ CEO and Co-Founder at Averlon Former Microsoft Partner Former SVP Salesforce Also mentioned in this episode: Vishal Agarwal https://www.linkedin.com/in/vishal-agarwal-55789355/ CTO and Co-Founder at Averlon 👉 Follow The Cyber Security Council and tune in to our podcast! 🔔 Don't forget to follow, like and subscribe. The Cyber Security Council: Website: https://lnkd.in/gkbqBPW3 LinkedIn: https://lnkd.in/ggkcxHTi YouTube: https://bit.ly/4dlQErn Apple Podcast: https://bit.ly/3WpeCvd TCSC Host Scott Brammer LinkedIn: https://www.linkedin.com/in/scott-brammer TCSC President Brian Greene LinkedIn: https://www.linkedin.com/in/brigreene Keywords Averlon, cybersecurity, cloud security, AI planning, generative AI, Sunil Gotumukala, risk reduction, stealth mode, engineering collaboration, attack chain, AI, cybersecurity, cloud security, generative AI, venture capital, software resilience, startup challenges, client success, leadership advice, software liability

  4. 11/04/2024

    Browser Security with Ryan Boerner

    In this episode of the Cybersecurity Council podcast, host Scott Brammer interviews Ryan Berner, founder and CEO of KeepAware, a browser security service. They discuss Ryan's entrepreneurial journey, the mission and vision of KeepAware, and the unique features that set it apart in the cybersecurity landscape. Ryan shares insights on the importance of browser security, the challenges of identity management, and the company's growth trajectory. The conversation also touches on the technical differentiators of KeepAware, the current status of the startup, and the future roadmap for expanding its capabilities. Special Guest CEO/Founder Ryan Boerner https://www.linkedin.com/in/ryan-boerner-8bb0349b/ https://keepaware.com/ Takeaways - KeepAware focuses on browser security to prevent targeted threats. - Ryan Berner's entrepreneurial journey began with a passion for security. - The browser is often a blind spot for security teams. - KeepAware aims to provide additional visibility and prevention layers. - Ryan balances his role as CEO with hands-on technical work. - The company's secret sauce lies in DOM tree analysis. - KeepAware is currently in the seed stage, proving use cases. - Traction is seen in organizations heavily using browsers. - Identity management is crucial in the context of browser security. - The future roadmap includes expanding integrations beyond the browser. Sound Bites "I realized the browser is just really a blind spot." "Our mission is to stop people targeted threats." "We want to provide a prevention layer." 👉 Follow The Cyber Security Council and tune in to our podcast! 🔔 Don't forget to follow, like and subscribe. The Cyber Security Council: Website: https://lnkd.in/gkbqBPW3 LinkedIn: https://lnkd.in/ggkcxHTi YouTube: https://bit.ly/4dlQErn Apple Podcast: https://bit.ly/3WpeCvd

  5. 10/22/2024

    Reinventing Incident Response with Matt Hartley

    "We're reinventing incident management and incident response." In this episode of The Cyber Security Council podcast, Scott Brammer interviews Matt Hartley, co-founder and chief product officer of BreachRx, an innovative incident response platform. They discuss the importance of proactive incident management, the unique features of BreachRx, and how organizations can prepare for and respond to cybersecurity incidents effectively. Matt emphasizes the need for a structured approach to incident response that involves all facets of a business, not just the security team. The conversation also touches on the regulatory landscape and how BreachRx helps organizations navigate compliance requirements while minimizing legal risks. Matt Hartley discusses the evolution of incident response practices, emphasizing the importance of adapting to legal challenges and customer needs. He shares insights on how BreachRx is designed to facilitate effective incident response and the significance of tabletop exercises in enhancing organizational maturity. Hartley also reflects on his journey as a co-founder, the growth of his team, and the lessons learned from mentorship and community engagement. Takeaways - BreachRx is reinventing incident management and response. - Proactive preparation is essential for effective incident response. - Incident response is a business problem, not just a security issue. - Organizations must understand their obligations during an incident. - BreachRx operationalizes the entire incident response process. - The cost of a simple data breach can be as high as $10 million. - Companies of all sizes need incident response solutions. - Regulatory compliance is a key focus for BreachRx. - The platform helps prevent legal issues during incidents. - Effective incident response requires collaboration across the organization. - Incident response practices have significantly evolved in recent years. - Legal privilege is crucial in incident response communications. - Listening to customers is key to product development. - Tabletop exercises help organizations understand their incident response maturity. - Engaging all stakeholders in exercises enhances preparedness. - CISOs often lack knowledge about the legal implications of incidents. - The journey of co-founding BreachRx began with recognizing regulatory changes. - Team growth is essential for the success of a startup. - Mentorship and community engagement provide valuable insights. - Every skill learned in the past is utilized in building a startup. Special Guest Matt Hartley https://www.linkedin.com/in/wmhartl/ Chief Product Officer for BreachRx Sound Bites "We're reinventing incident management and incident response." "You have to be proactively prepared if you want a successful response." "We're the very first platform to operationalize the full incident response process." "You have to get out of your office." "This is the best exercise I've ever been in." "We need to make these decisions." 👉 Follow The Cyber Security Council and tune in to our podcast! 🔔 Don't forget to follow, like and subscribe. The Cyber Security Council: Website: https://lnkd.in/gkbqBPW3 LinkedIn: https://lnkd.in/ggkcxHTi YouTube: https://bit.ly/4dlQErn Apple Podcast: https://bit.ly/3WpeCvd TCSC Host Scott Brammer LinkedIn: https://www.linkedin.com/in/scott-brammer TCSC President Brian Greene LinkedIn: https://www.linkedin.com/in/brigreene Keywords cybersecurity, incident response, BreachRx, incident management, proactive preparation, regulatory compliance, business resilience, CISO, data breach, operational efficiency, incident response, cybersecurity, legal challenges, customer feedback, tabletop exercises, BreachRx, product development, team growth, mentorship, CISO

  6. 10/22/2024

    AI/ML Security with David Brauchler

    In this conversation, Scott Brammer interviews David Brauchler, the Technical Director and Head of AI/ML Security for North America at NCC GROUP. David shares guidance on AI security from his perspective as a penetration tester building one of the most dynamic teams in the country that hammers away at LLMs and other forms of Generative AI. The discussion covers the importance of frameworks, straightforward approaches, and the unique challenges of scoping AI projects. David stresses that guardrails are only the start of success, and that tangible security must be embedded in very stage of the AI development lifecycle. David calls out specific attention to the value of dataflow diagrams, and protecting trusted sources of information. He also addresses bias in AI algorithms, and offers some ninja insights on best practices for pen testing LLMs. Special Guest David Brauchler Technical Director Head of AI/ML for North America NCC Group: https://www.nccgroup.com/us/ 👉 Follow The Cyber Security Council and tune in to our podcast! 🔔 Don't forget to follow, like and subscribe. The Cyber Security Council: Website: https://lnkd.in/gkbqBPW3 LinkedIn: https://lnkd.in/ggkcxHTi YouTube: https://bit.ly/4dlQErn Apple Podcast: https://bit.ly/3WpeCvd TCSC Host Scott Brammer LinkedIn: https://www.linkedin.com/in/scott-brammer TCSC President Brian Greene LinkedIn: https://www.linkedin.com/in/brigreene Keywords AI/ML Security, AI, penetration testing, cybersecurity, David Brauchler, NCC Group, LLM, GenAI, artificial intelligence, data governance, risk management

  7. 10/17/2024

    AI Governance with Walter Haydock

    I got to talk to a Marine Recon veteran that is now a leader in AI governance. Pretty dang cool. 📣 ⚡ https://lnkd.in/gG2jdr77 In this conversation, Scott Brammer interviews Walter Haydock, the Founder and CEO of StackAware, a company specializing in AI governance and compliance. Walter shares his journey from military service to the tech industry, highlighting his experiences that led to the creation of StackAware. The discussion covers the importance of ISO 42001 certification, the challenges of AI governance, and the frameworks that guide compliance. Walter emphasizes the need for clear scoping when assessing client readiness for certification and the unique implications of building AI tools internally. The conversation also touches on the evolving landscape of AI regulations and the role of auditors in ensuring compliance. Walter reflects on the lessons learned from his military background and the value of an MBA. Takeaways - Walter Haydock's journey from military to tech is inspiring. - ISO 42001 certification is crucial for AI governance. - StackAware aims to help companies achieve compliance quickly. - Scoping is essential for assessing client readiness. - Building AI tools internally requires careful compliance considerations. - Frameworks like NIST and OWASP are important for AI governance. - Vetting LLMs involves understanding data retention and training. - Compliance can be subjective and requires clear definitions. - CISOs can leverage ISO 42001 to enhance data governance. - Regulations around AI are constantly evolving and need monitoring. Special Guest CEO Walter Haydock LinkedIn: https://lnkd.in/gqzBGHEF StackAware: https://stackaware.com/ StackAware Blog: https://lnkd.in/gY4MJvCf Sound Bites "Helping companies get ISO 42001 ready in 90 days." "We are not auditors; we are advisors." "Scoping is a very important aspect of the process." 👉 Follow The Cyber Security Council and tune in to our podcast! 🔔 Don't forget to follow, like and subscribe. The Cyber Security Council: Website: https://lnkd.in/gkbqBPW3 LinkedIn: https://lnkd.in/ggkcxHTi YouTube: https://bit.ly/4dlQErn Apple Podcast: https://bit.ly/3WpeCvd TCSC Host Scott Brammer LinkedIn: https://www.linkedin.com/in/scott-brammer TCSC President Brian Greene LinkedIn: https://www.linkedin.com/in/brigreene #AI #GenAI #ISO42001 #cybersecurity #DataManagement #RiskManagement #Governance #Compliance

  8. 10/14/2024

    Adopting GenAI with Arti Raman

    In this conversation, Arti Raman, CEO of Portal 26, discusses the critical role of her company in the governance of generative AI. She highlights the unique features of their platform, which focuses on safe adoption, risk management, and compliance in the rapidly evolving landscape of AI technology. Arti shares insights on the importance of customer feedback in shaping their offerings, the significance of partnerships in keeping pace with technological advancements, and the growth trajectory of Portal 26. She emphasizes the need for organizations to invest in governance alongside their AI technology investments to ensure responsible and effective use of generative AI. Takeaways - Generative AI adoption is outpacing governance. - Portal 26 provides a forensic vault for generative AI. - The platform enables organizations to manage AI risks effectively. - Customer feedback is crucial for product development. - Rapid deployment is a key differentiator for Portal 26. - AI governance includes both usage and model governance. - Partnerships enhance the capabilities of Portal 26. - The market for generative AI is vast and growing. - Investing in governance is essential for AI success. - Leadership and team dynamics are vital for transformation. - The Evolution of AI Adoption Strategies Sound Bites "Generative AI is here to stay." "We are the only game in town." "We enable auditability for generative AI usage." Special Guest Arti Raman LinkedIn: https://www.linkedin.com/in/arti-arora-raman/ Portal26: https://www.portal26.ai/ 👉 Follow The Cyber Security Council and tune in to our podcast! 🔔 Don't forget to follow, like and subscribe. The Cyber Security Council: Website: https://lnkd.in/gkbqBPW3 LinkedIn: https://lnkd.in/ggkcxHTi YouTube: https://bit.ly/4dlQErn Apple Podcast: https://bit.ly/3WpeCvd TCSC Host Scott Brammer LinkedIn: https://www.linkedin.com/in/scott-brammer TCSC President Brian Greene LinkedIn: https://www.linkedin.com/in/brigreene Keywords Arti Raman, Portal 26, generative AI, AI governance, cybersecurity, data security, enterprise solutions, risk management, technology adoption, innovation

About

The Cyber Security Council (TCSC) is a community forum for Cyber leaders. Its mission is to elevate premier voices in cyber, and strengthen the cyber community itself. TCSC seeks to demystify and simplify cyber across the business landscape.