HomePodcastDefense in Depth

Defense in Depth

DEFENSE IN DEPTH

What Is Attack Surface Profiling?

Is attack surface profiling the same as a pen test? If it isn't what unique insight can attack surface profiling deliver? Check out this post for the...

How Can You Tell If Your Security Program Is Improving?

What’s your best indicator that your security program is actually improving? And besides you and your team, is anyone impressed? Check out this post for the discussion...

How Can We Improve Recruiting of CISOs and Security Leaders?

Interviewing for leadership positions in cybersecurity is difficult for everyone involved. There are far too many egos and many gatekeepers. What can be done...

How Is Our Data Being Weaponized Against Us?

How are nefarious actors using our own data (and metadata) against us? And given that, in what way have we lost our way protecting...

Can Security Be a Profit Center?

Is it possible to position your security team as a profit center instead of the traditional cost center reporting to the CIO? Check out this...

Getting Ahead of the Ongoing Malware Fight

For years we've been referring to malware protection as a cat and mouse game. The crooks come up with a new malware attack, and...

Defense in Depth: Building a Security Awareness Training Program

We all know and have experienced bad security awareness training. People can learn, and should learn about being cyber aware. How do you build...

Defense in Depth: Onboarding Cyber Professionals with No Experience

You want to bring on entry level personnel, But green employees, who are not well versed in security, IT, or your data, introduce risk...

Defense in Depth: Where’s the Trust in Zero Trust?

Zero trust is a hollow buzzword. In any form of security, there exist critical points where we have to trust. What we need is...

Defense in Depth: Who Investigates Cyber Solutions?

Cyber professionals, who is responsible on your team for investigating new solutions? Check out this post and this post for the discussion that are the basis...

Does the Cybersecurity Industry Suck?

In the cyber industry we pat each other on the back and give each other awards, all while the statistics for breaches appear to...

Defense in Depth: Are We Taking Zero Trust Too Far?

For some, the definition of zero trust has expanded from how we grant access to networks, applications, and data to how we trust individuals...

Defense in Depth: Is Shift Left Working?

Developers and security professionals have been heavily sold on the concept of "shift left" or deal with security issues early in development rather bolting...

Defense in Depth: Technical vs. Compliance Professionals

Do we have a Monitgue/Capulet rivalry between technical and compliance professionals? Why is this happening, and what can be done to improve it? Does...

Defense in Depth: Why Do So Many Cybersecurity Products Suck?

Why do we end up with so many bad security products? Who is to blame and how can we fight back an ecosystem that...