silent-sector-us

The Cyber Rants Podcast

Bringing you cybersecurity insider tips, guidance, news, and rants!

apple-logo-white      spotify-podcasts     podcast-iheartradio

Episode #75 - Off the Cuff Rants of The Week!

This week, the guys discuss some cybersecurity trends, tips, and words to the wise that are timely and relevant in today's technology-centric world! They discuss: 

  • Are attacks ramping up and if so, why?
  • The pros and cons of spending your cybersecurity budget on Black Hat and DefCon
  • Why you need specific objectives in your penetration testing, not just the numbers
  • The wrong and right way to establish vendor relationships
  • And more! 

Open Episode

Episode #74 - An Expert's Approach to Attracting & Retaining the Best Technology Professionals

Does your company recruit IT and cybersecurity staff with the same methods used to fill other positions? If so, don't miss this episode. This week, the guys welcome Cammas Freeman, an expert on finding and retaining the best technology professionals. Cammas shares a unique approach for recruiting the best talent, using a methodology that saves a tremendous amount of time and money. She also shares tips to build a strong culture for less turnover.

Open Episode

Episode #73 - Backup and Recovery with Mr. Backup Himself - W. Curtis Preston

Cyber criminals are heavily focused on compromising backups so their attacks are as crushing and painful as possible for the victims. Good backups and the ability to quickly restore are a critical part of every infosec program but many organizations still treat backups as an afterthought. This week, the guys welcome the recognized authority on data backup W. Curtis Preston (aka. Mr. Backup) to reveal the backup and recovery trends he is noticing, tips organizations can implement to minimize risk, and what to look for in a backup solution.

Open Episode

Episode #72 - More Fun with PCI DSS Compliance!

This week, the guys discuss one of their favorite topics, Payment Card Industry Data Security Standards (PCI DSS)! Companies that transmit, process, or store credit card data need to be compliant but PCI has its own nuances. What level of PCI compliance do you need? How do you determine what is in scope? How do you work with auditors? The guys answer these questions and more, plus share some wizard-like tactics to help you maneuver through the PCI requirements.

Open Episode

Episode #70 - Securing Complex Organizations and Subsidiaries

Building and managing a cybersecurity program can be confusing for organizations with multiple product lines, subsidiaries, or industry divisions. How do you manage security across all business units? What can you do to set standards that the entire organization follows? How do you control the quality of the cyber risk management practices through different cultures? This week, the guys answer these questions and more, discussing the various aspects of implementing, assessing, managing, and normalizing cybersecurity across a complex organization. 

Open Episode

Episode #69 - News, Notes, and... Goodwill Hacking?

This week, the guys reconvene after a mini-hiatus and talk about some topics and tips in the news today such as 

  • Goodwill Ransomware Hacking
  • Safe Browsing - the hidden dangers people need to know
  • A word to the wise about Wordpress (even though they supposedly "don't talk about wordpress")
Open Episode

Episode #68 - Cybersecurity Offense - Can you hack back?

Is there really such a thing as "offense" in cybersecurity? This week, the guys discuss how it's possible to proactively protect organizations against criminals and how to identify potential attacks so you can stop them before it's too late. They share the realities of offensive cybersecurity and "hacking back."

Open Episode

Episode #65 - Dissecting Cybersecurity Frameworks - Part 1

A cybersecurity framework is the foundation of any good cyber risk management program but many people are not familiar with what a framework really is and what they include. This week the guys reveal the importance of following an industry-recognized cybersecurity framework and begin walking through the National Institute of Standards & Technology Cybersecurity Framework (NIST CSF) as an example. You'll understand why cyber risk management is not a mystical "make it up as you go" approach but a series of cybersecurity methods with easy to access, readily available guidance.

Open Episode

Episode #63 - Physical Security Controls for Data Protection & Compliance

This week, the guys discuss physical security controls (and lasers) to ensure that your organization is both secure and compliant! Cybersecurity doesn't stop at technology implementation. If you follow NIST 800-171, CMMC, PCI-DSS, or a number of other compliance requirements, you'll need physical security consulting to help secure your premises to protect systems and data. Hear what the guys have to say about implementing effective physical security controls.

Open Episode

Episode #62 - Eric Adams, FedRAMP Expert

This week, the guys are joined by Eric Adams, experienced CISO and FedRAMP Strategist discuss what precisely is FedRAMP, its relation with cloud security standards, and why should organizations consider it for their structure, as well as the steps to make it happen. 

Open Episode
10103417-small

Send Us Your Questions & Rants!