HomePodcastDefense in Depth

Defense in Depth

Defense In Depth

Defense in Depth: Best Starting Security Framework

If you were building a security program from scratch, which many of our listeners have done, which framework would be your starting point? Check out...

Defense in Depth: Cyber Defense Matrix

A simple way to visualize your entire security program and all the tools that support it. Check out this post for the discussion that is...

Defense in Depth: User-Centric Security

How can software and our security programs better be architected to get users involved? Check out this post for the discussion that is the...

Defense in Depth: Securing the New Internet

If you could re-invent the entire Internet, starting all over again with security in mind, what would you do? Check out this post for the...

Defense in Depth: Resiliency

How fortified is the business to withstand cyberattacks? Can it absorb the impact of the inevitable hits? Would understanding the business' level of resilience...

Defense in Depth: Ransomware

Why is Ransomware so prevalent? Why are so many getting caught in its net? And what are some of the best tactics to stop...

Defense in Depth: Top CISO Communication Issues

Understanding risk. Communicating with the board. Getting others to understand and care about security. What is the most vexing cybersecurity issue for a CISO?...

Defense in Depth: Cybersecurity Excuses

"I've got all the security I need." "I'm not a target for hackers." These are just a few of the many rationalizations companies make when...

Defense in Depth: Employee Hacking

A cyber professional needs their staff, non-IT workers, and the board to take certain actions to achieve the goals of their security program. Should...

Defense in Depth: 100% Security

100% Security. A great idea that's impossible to achieve. Regardless, CEOs are still asking for it. How should security people respond and we'll discuss...

Defense in Depth Wants Trending InfoSec Topics

The co-hosts of the Defense in Depth podcast, myself and Allan Alford, recorded this video from Black Hat 2019 explaining the editorial model of...

Defense in Depth: Proactive Security

How proactive should we be about security? What's the value of threat intelligence vs. just having security programs in place with no knowledge of...

Defense in Depth: ATT&CK Matrix

Is the ATT&CK Matrix the best model to build resiliency in your security team? What is the best way to take advantage of the...

Defense in Depth: Hacker Culture

The hacker community needs a new PR campaign. Far too many people equate hacker with criminal. But hacker is a mindset of how one...

Defense in Depth: Bad Best Practices

All professionals like to glom onto "best practices." But in security, "best" practices may be bad out of the gate, become useless over time,...