<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:psc="http://podlove.org/simple-chapters" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><title><![CDATA[Cloud Security Today]]></title><description><![CDATA[<p>The Cloud Security Today podcast features expert commentary and personal stories on the “how” side of cybersecurity. This is not a news program but rather a podcast that focuses on cyber leadership and understanding the threats most impacting organizations today.</p>]]></description><link>http://cloudsecuritytoday.com</link><generator>Riverside.fm (https://riverside.com)</generator><lastBuildDate>Wed, 15 Jul 2026 10:38:46 GMT</lastBuildDate><atom:link href="https://api.riverside.com/hosting/GZiZi25a.rss" rel="self" type="application/rss+xml"/><author><![CDATA[Matthew Chiodi]]></author><pubDate>Thu, 12 Mar 2026 19:35:40 GMT</pubDate><copyright><![CDATA[2026 Matthew Chiodi]]></copyright><language><![CDATA[en]]></language><ttl>60</ttl><category><![CDATA[Careers]]></category><category><![CDATA[How To]]></category><itunes:author>Matthew Chiodi</itunes:author><itunes:summary>&lt;p&gt;The Cloud Security Today podcast features expert commentary and personal stories on the “how” side of cybersecurity. This is not a news program but rather a podcast that focuses on cyber leadership and understanding the threats most impacting organizations today.&lt;/p&gt;</itunes:summary><itunes:type>episodic</itunes:type><itunes:owner><itunes:name>Matthew Chiodi</itunes:name><itunes:email>matt.chiodi@gmail.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Business"><itunes:category text="Careers"/></itunes:category><itunes:category text="Education"><itunes:category text="How To"/></itunes:category><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><item><title><![CDATA[Cyber and the NY Giants]]></title><description><![CDATA[<p><a rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/christinamorillo/" target="_blank"><b>Christina Morillo</b></a> shares her unconventional career journey from traditional IT to cybersecurity in the NFL, highlighting the importance of building trust, understanding business risk, and addressing misconceptions in cybersecurity.</p><p></p><p>Christina's book: <a rel="noopener noreferrer nofollow" href="https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/" target="_blank"><b>Zero Trust Networks</b></a></p>]]></description><guid isPermaLink="false">794e2d8a-62a8-4b01-86ab-842972d37f54</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 01 Jul 2026 16:33:06 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/4d27583ae9d5feb3d2cf36e4811ed8548893cf1190547a5f630e803e309e32f7/eyJlcGlzb2RlSWQiOiI3OTRlMmQ4YS02MmE4LTRiMDEtODZhYi04NDI5NzJkMzdmNTQiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmE0NTNlYjIyM2I3NGFmYTk1NjY5YTY4L2Nsb3VkLXNlY3VyaXR5LXRvZGF5LWNvbXBvc2VyLTIwMjYtNy0xX18xOC0yMi0xMC5tcDMifQ==.mp3" length="91999548" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/episodes/794e2d8a-62a8-4b01-86ab-842972d37f54/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;&lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.linkedin.com/in/christinamorillo/&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;Christina Morillo&lt;/b&gt;&lt;/a&gt; shares her unconventional career journey from traditional IT to cybersecurity in the NFL, highlighting the importance of building trust, understanding business risk, and addressing misconceptions in cybersecurity.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Christina&apos;s book: &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.oreilly.com/library/view/zero-trust-networks/9781492096580/&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;Zero Trust Networks&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:47:55</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:title>Cyber and the NY Giants</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Identity for AI agents]]></title><description><![CDATA[<p>AI agents are moving from answering questions to taking action. That changes everything for identity and access management.</p><p></p><p>In this episode, <a rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/kenhuang8/" target="_blank">Ken Huang</a> joins Matt to break down why traditional IAM was not built for agentic AI, where service accounts and OAuth scopes fall short, and what CISOs should do now to govern agents before they hit production at scale.</p><p></p><p><b>Episode Links</b></p><ul><li>Ken's <a rel="noopener noreferrer nofollow" href="https://kenhuangus.substack.com/" target="_blank">substack</a></li><li>Ken's <a rel="noopener noreferrer nofollow" href="https://www.slideshare.net/slideshow/up-2011ken-huang/10520962" target="_blank">paper from 2011</a> on AI (he was way ahead!)</li><li>NIST <a rel="noopener noreferrer nofollow" href="https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf" target="_blank">AI RMF</a></li></ul><p></p>]]></description><guid isPermaLink="false">ab4e40d4-ce34-4395-8496-8c8b080c9233</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sun, 10 May 2026 22:20:24 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/1af40f3271028c13831de28277e8f501a405ee9516985236d6f77fda3d1b9619/eyJlcGlzb2RlSWQiOiJhYjRlNDBkNC1jZTM0LTQzOTUtODQ5Ni04YzhiMDgwYzkyMzMiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNmEwMGZkYTkzYWVlNzQzZGI1NmQ2M2M2L2Nsb3VkLXNlY3VyaXR5LXRvZGF5LWNvbXBvc2VyLTIwMjYtNS0xMF9fMjMtNTAtMzMubXAzIn0=.mp3" length="87569181" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/episodes/ab4e40d4-ce34-4395-8496-8c8b080c9233/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;AI agents are moving from answering questions to taking action. That changes everything for identity and access management.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;In this episode, &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.linkedin.com/in/kenhuang8/&quot; target=&quot;_blank&quot;&gt;Ken Huang&lt;/a&gt; joins Matt to break down why traditional IAM was not built for agentic AI, where service accounts and OAuth scopes fall short, and what CISOs should do now to govern agents before they hit production at scale.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Links&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Ken&apos;s &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://kenhuangus.substack.com/&quot; target=&quot;_blank&quot;&gt;substack&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Ken&apos;s &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.slideshare.net/slideshow/up-2011ken-huang/10520962&quot; target=&quot;_blank&quot;&gt;paper from 2011&lt;/a&gt; on AI (he was way ahead!)&lt;/li&gt;&lt;li&gt;NIST &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf&quot; target=&quot;_blank&quot;&gt;AI RMF&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:45:37</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:title>Identity for AI agents</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The future of CISO]]></title><description><![CDATA[<p>In this episode, <a rel="noopener noreferrer nofollow" href="https://www.linkedin.com/in/moderncisosearch/" target="_blank">Michael Piacente</a> shares insights on career transitions in IT and security, the evolving role of CISOs, and the impact of AI on security talent and practices. Discover how community, storytelling, and strategic hiring shape the future of cybersecurity leadership.</p><p></p><p><b> Resources</b></p><p><a rel="noopener noreferrer nofollow" href="https://2026-ciso-survey.vercel.app/" target="_blank">The 2026 Global CISO Leadership Report</a></p><p><a rel="noopener noreferrer nofollow" href="https://hitchpartners.com/" target="_blank">Hitch Partners</a></p><p><a rel="noopener noreferrer nofollow" href="https://www.nist.gov/itl/ai" target="_blank">NIST AI Framework</a></p><p></p><p></p>]]></description><guid isPermaLink="false">028f7bd7-2b3a-4d30-a544-0376033478f7</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sat, 11 Apr 2026 17:34:16 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/9662dec6797c2356b67cc2fbf72ccaa8faeca8a61ee0cad7b8b3c038f89f66c5/eyJlcGlzb2RlSWQiOiIwMjhmN2JkNy0yYjNhLTRkMzAtYTU0NC0wMzc2MDMzNDc4ZjciLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvY2xpcHMvNjlkYTgzNGI1YjczNzYxMjc0ZjYxYjE4L2Nsb3VkLXNlY3VyaXR5LXRvZGF5LWNvbXBvc2VyLTIwMjYtNC0xMV9fMTktMjItMTkubXAzIn0=.mp3" length="63387943" type="audio/mpeg"/><podcast:transcript url="https://hosting-media.riverside.com/media/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/episodes/028f7bd7-2b3a-4d30-a544-0376033478f7/transcripts.txt" type="text/plain"/><itunes:summary>&lt;p&gt;In this episode, &lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.linkedin.com/in/moderncisosearch/&quot; target=&quot;_blank&quot;&gt;Michael Piacente&lt;/a&gt; shares insights on career transitions in IT and security, the evolving role of CISOs, and the impact of AI on security talent and practices. Discover how community, storytelling, and strategic hiring shape the future of cybersecurity leadership.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt; Resources&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://2026-ciso-survey.vercel.app/&quot; target=&quot;_blank&quot;&gt;The 2026 Global CISO Leadership Report&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://hitchpartners.com/&quot; target=&quot;_blank&quot;&gt;Hitch Partners&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a rel=&quot;noopener noreferrer nofollow&quot; href=&quot;https://www.nist.gov/itl/ai&quot; target=&quot;_blank&quot;&gt;NIST AI Framework&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:44:01</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:title>The future of CISO</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Matt joins a startup]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>This episode of the Cloud Security Today podcast is a little different from the others because this time host Matthew Chiodi gives the interviewer’s seat over to Yousuf Khan and they talk about an exciting new development in Matt’s career.<br /><br />Matt announces a big career move and talks about how he’s hoping to fix some of the biggest problems in SaaS security today. He tells Yousuf about his new role and the fresh approach that his new company is bringing to the field. At the end of the episode, they discuss working in a start-up environment and give advice to anyone considering working in a start-up.<br /><br />If you enjoyed this episode, subscribe, or follow Cloud Security Today wherever you get your podcasts.</p><p><b>Timestamps</b></p><p>[0:28] Matt introduces the topic for today’s episode</p><p>[1:50] Exciting news from Matt about his latest career move</p><p>[5:10] Matt explains one of the biggest challenges in app security today</p><p>[7:25] How have we managed app security up to now?</p><p>[9:20] So how does Cerby work?</p><p>[11:32] Matt’s new role at Cerby and an outline of his first few months</p><p>[12:50] Why Matt likes working in a start-up environment</p><p>[14:05] How Matt became interested in Cerby</p><p>[16:20] What’s next for Cerby?</p><p>[18:10] The advice that Matt would give to anyone looking to join a start-up</p><p>[20:40] Yousuf adds his thoughts about working for a start-up<br /><br /><b>Episode Links<br /></b><a href="https://ridge.vc/" rel="noopener noreferrer nofollow">Ridge Ventures</a><br /><a href="https://www.linkedin.com/in/yousufakhan/" rel="noopener noreferrer nofollow">Yousuf Khan's Linkedin Profile</a><br /><a href="https://www.cerby.com" rel="noopener noreferrer nofollow">Cerby's website</a><br /><a href="https://www.linkedin.com/in/mattchiodi/" rel="noopener noreferrer nofollow">Matt's Linkedin Profile</a></p>]]></description><guid isPermaLink="false">Buzzsprout-10836575</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 27 Jun 2022 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/9a385422a85f10569522c0a8bb8a58c01dddc2f1cd62ba48deea7ca598863658/eyJlcGlzb2RlSWQiOiJlZDBlZTNkMi1kZWNiLTQ2MzMtYTZjYS05MjQ4NmNjZGMzMDMiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZWQwZWUzZDItZGVjYi00NjMzLWE2Y2EtOTI0ODZjY2RjMzAzLzEwODM2NTc1LW1hdHQtam9pbnMtYS1zdGFydHVwLm1wMyJ9.mp3" length="16281752" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;This episode of the Cloud Security Today podcast is a little different from the others because this time host Matthew Chiodi gives the interviewer’s seat over to Yousuf Khan and they talk about an exciting new development in Matt’s career.&lt;br /&gt;&lt;br /&gt;Matt announces a big career move and talks about how he’s hoping to fix some of the biggest problems in SaaS security today. He tells Yousuf about his new role and the fresh approach that his new company is bringing to the field. At the end of the episode, they discuss working in a start-up environment and give advice to anyone considering working in a start-up.&lt;br /&gt;&lt;br /&gt;If you enjoyed this episode, subscribe, or follow Cloud Security Today wherever you get your podcasts.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamps&lt;/b&gt;&lt;/p&gt;&lt;p&gt;[0:28] Matt introduces the topic for today’s episode&lt;/p&gt;&lt;p&gt;[1:50] Exciting news from Matt about his latest career move&lt;/p&gt;&lt;p&gt;[5:10] Matt explains one of the biggest challenges in app security today&lt;/p&gt;&lt;p&gt;[7:25] How have we managed app security up to now?&lt;/p&gt;&lt;p&gt;[9:20] So how does Cerby work?&lt;/p&gt;&lt;p&gt;[11:32] Matt’s new role at Cerby and an outline of his first few months&lt;/p&gt;&lt;p&gt;[12:50] Why Matt likes working in a start-up environment&lt;/p&gt;&lt;p&gt;[14:05] How Matt became interested in Cerby&lt;/p&gt;&lt;p&gt;[16:20] What’s next for Cerby?&lt;/p&gt;&lt;p&gt;[18:10] The advice that Matt would give to anyone looking to join a start-up&lt;/p&gt;&lt;p&gt;[20:40] Yousuf adds his thoughts about working for a start-up&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Episode Links&lt;br /&gt;&lt;/b&gt;&lt;a href=&quot;https://ridge.vc/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Ridge Ventures&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;https://www.linkedin.com/in/yousufakhan/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Yousuf Khan&apos;s Linkedin Profile&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;https://www.cerby.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Cerby&apos;s website&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;https://www.linkedin.com/in/mattchiodi/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Matt&apos;s Linkedin Profile&lt;/a&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:22:31</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>7</itunes:episode><itunes:title>Matt joins a startup</itunes:title><itunes:episodeType>bonus</itunes:episodeType></item><item><title><![CDATA[Principles in cyber leadership]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this conversation, <a href="https://www.linkedin.com/in/mkpalmore/" rel="noopener noreferrer nofollow">MK Palmore</a> shares insights from his diverse leadership journey, spanning the Marine Corps, FBI, and cybersecurity. He emphasizes the importance of a people-centered leadership approach, the balance between technical and leadership skills, and the significance of effective communication. MK reflects on his experiences, the impact of mentorship, and the lessons learned from both successes and failures in leadership roles. MK highlights the challenges in attracting diverse talent to cybersecurity and the necessity of nurturing new professionals. He concludes with insights on continuous learning and the importance of maintaining a beginner's mindset.</p><p><b>Takeaways</b></p><ul><li>Diverse experiences shape leadership philosophy.</li><li>Mentorship plays a significant role in professional development.</li><li>Silence from leaders can lead to assumptions and uncertainty.</li><li>Leaders should increase communication during times of uncertainty.</li><li>Maintaining a mindset of continuous learning is vital for personal growth.</li></ul><p><b>Chapters<br /></b><br /></p><p>00:00<br />Introduction to Leadership and Music</p><p>02:57<br />Diverse Leadership Experiences</p><p>06:05<br />The Importance of People-Centered Leadership</p><p>09:05<br />Technical Skills vs. Leadership Skills</p><p>11:49<br />Communication as a Leadership Skill</p><p>14:53<br />Learning from Mistakes in Communication</p><p>18:01<br />The Impact of Silence in Leadership</p><p>20:44<br />Navigating Uncertainty in Leadership</p><p>25:06<br />Bridging the Gap: Technical and Business Communication</p><p>30:22<br />Building Personal Brand and Eminence</p><p>32:53<br />Overcoming Barriers in Cybersecurity Talent Acquisition</p><p>38:31<br />Staying Sharp: Continuous Learning and Adaptability</p>]]></description><guid isPermaLink="false">Buzzsprout-16846442</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sun, 23 Mar 2025 23:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/54796b3588bd7e00b5c6e74da2d9af3d19e070359d250172b8dc6536cf5a6f7d/eyJlcGlzb2RlSWQiOiIyNTZhYzIyOS0yYTVmLTRkMWItYjRkMy05NzE2ZjZjZWQ5MmEiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMjU2YWMyMjktMmE1Zi00ZDFiLWI0ZDMtOTcxNmY2Y2VkOTJhLzE2ODQ2NDQyLXByaW5jaXBsZXMtaW4tY3liZXItbGVhZGVyc2hpcC5tcDMifQ==.mp3" length="31010888" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this conversation, &lt;a href=&quot;https://www.linkedin.com/in/mkpalmore/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;MK Palmore&lt;/a&gt; shares insights from his diverse leadership journey, spanning the Marine Corps, FBI, and cybersecurity. He emphasizes the importance of a people-centered leadership approach, the balance between technical and leadership skills, and the significance of effective communication. MK reflects on his experiences, the impact of mentorship, and the lessons learned from both successes and failures in leadership roles. MK highlights the challenges in attracting diverse talent to cybersecurity and the necessity of nurturing new professionals. He concludes with insights on continuous learning and the importance of maintaining a beginner&apos;s mindset.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Diverse experiences shape leadership philosophy.&lt;/li&gt;&lt;li&gt;Mentorship plays a significant role in professional development.&lt;/li&gt;&lt;li&gt;Silence from leaders can lead to assumptions and uncertainty.&lt;/li&gt;&lt;li&gt;Leaders should increase communication during times of uncertainty.&lt;/li&gt;&lt;li&gt;Maintaining a mindset of continuous learning is vital for personal growth.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Chapters&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;00:00&lt;br /&gt;Introduction to Leadership and Music&lt;/p&gt;&lt;p&gt;02:57&lt;br /&gt;Diverse Leadership Experiences&lt;/p&gt;&lt;p&gt;06:05&lt;br /&gt;The Importance of People-Centered Leadership&lt;/p&gt;&lt;p&gt;09:05&lt;br /&gt;Technical Skills vs. Leadership Skills&lt;/p&gt;&lt;p&gt;11:49&lt;br /&gt;Communication as a Leadership Skill&lt;/p&gt;&lt;p&gt;14:53&lt;br /&gt;Learning from Mistakes in Communication&lt;/p&gt;&lt;p&gt;18:01&lt;br /&gt;The Impact of Silence in Leadership&lt;/p&gt;&lt;p&gt;20:44&lt;br /&gt;Navigating Uncertainty in Leadership&lt;/p&gt;&lt;p&gt;25:06&lt;br /&gt;Bridging the Gap: Technical and Business Communication&lt;/p&gt;&lt;p&gt;30:22&lt;br /&gt;Building Personal Brand and Eminence&lt;/p&gt;&lt;p&gt;32:53&lt;br /&gt;Overcoming Barriers in Cybersecurity Talent Acquisition&lt;/p&gt;&lt;p&gt;38:31&lt;br /&gt;Staying Sharp: Continuous Learning and Adaptability&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:42:58</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>5</itunes:season><itunes:episode>3</itunes:episode><itunes:title>Principles in cyber leadership</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Tackling cyber & AI in the boardroom]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Summary</b><br />In this conversation, <a href="https://www.linkedin.com/in/christopher-hetner-7969758/" rel="noopener noreferrer nofollow">Chris Hetner</a> discusses the evolving role of boards of directors in cybersecurity, emphasizing the need for improved communication and understanding of cyber risks. He highlights the challenges boards face in adapting to new SEC rules and the importance of leveraging AI responsibly. Hetner also shares insights on tools for quantifying cyber risk and prioritizing investments while advocating for continuous learning and proactive engagement with board members.<br /><br /><b>Takeaways</b></p><ul><li>Boards are becoming more aware of cybersecurity risks.</li><li>Cybersecurity discussions often receive limited airtime in board meetings.</li><li>The SEC's new disclosure rules can drive more frequent discussions on cyber risk.</li><li>AI governance is crucial as AI technologies become more prevalent.</li><li>Collaboration with general counsel and risk officers is essential.</li></ul><p><b>Chapters</b><br /><br />00:00 Introduction and Background on Cybersecurity and Boards<br />03:05 Current Challenges Facing Boards in Cybersecurity<br />06:11 Understanding Cyber Risk and Communication with Boards<br />08:58 Improving Board Engagement with Cybersecurity<br />11:56 Leveraging SEC Guidelines for Cyber Risk Discussions<br />15:02 The Role of AI in Cybersecurity Governance<br />18:05 Tools for Quantifying Cyber Risk<br />21:12 Prioritizing Cybersecurity Investments<br />24:02 The Importance of AI Governance<br />26:57 Staying Informed in Cybersecurity<br />30:13 Final Thoughts and Continuous Learning</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-15843802</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sun, 20 Oct 2024 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/8fccddaaa97ded1ea47d9e441f0492220ea53376f9f0faa987ec6b6a5122e35c/eyJlcGlzb2RlSWQiOiI4YTdlOTNjNC1lZWZhLTQ2MDEtYmYwNy1iZmNiNThlMmI4M2EiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvOGE3ZTkzYzQtZWVmYS00NjAxLWJmMDctYmZjYjU4ZTJiODNhLzE1ODQzODAyLXRhY2tsaW5nLWN5YmVyLWFpLWluLXRoZS1ib2FyZHJvb20ubXAzIn0=.mp3" length="33080760" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;br /&gt;In this conversation, &lt;a href=&quot;https://www.linkedin.com/in/christopher-hetner-7969758/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Chris Hetner&lt;/a&gt; discusses the evolving role of boards of directors in cybersecurity, emphasizing the need for improved communication and understanding of cyber risks. He highlights the challenges boards face in adapting to new SEC rules and the importance of leveraging AI responsibly. Hetner also shares insights on tools for quantifying cyber risk and prioritizing investments while advocating for continuous learning and proactive engagement with board members.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Boards are becoming more aware of cybersecurity risks.&lt;/li&gt;&lt;li&gt;Cybersecurity discussions often receive limited airtime in board meetings.&lt;/li&gt;&lt;li&gt;The SEC&apos;s new disclosure rules can drive more frequent discussions on cyber risk.&lt;/li&gt;&lt;li&gt;AI governance is crucial as AI technologies become more prevalent.&lt;/li&gt;&lt;li&gt;Collaboration with general counsel and risk officers is essential.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Chapters&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;00:00 Introduction and Background on Cybersecurity and Boards&lt;br /&gt;03:05 Current Challenges Facing Boards in Cybersecurity&lt;br /&gt;06:11 Understanding Cyber Risk and Communication with Boards&lt;br /&gt;08:58 Improving Board Engagement with Cybersecurity&lt;br /&gt;11:56 Leveraging SEC Guidelines for Cyber Risk Discussions&lt;br /&gt;15:02 The Role of AI in Cybersecurity Governance&lt;br /&gt;18:05 Tools for Quantifying Cyber Risk&lt;br /&gt;21:12 Prioritizing Cybersecurity Investments&lt;br /&gt;24:02 The Importance of AI Governance&lt;br /&gt;26:57 Staying Informed in Cybersecurity&lt;br /&gt;30:13 Final Thoughts and Continuous Learning&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:45:51</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>12</itunes:episode><itunes:title>Tackling cyber &amp; AI in the boardroom</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[SBOMs: Good but less than a silver bullet]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On today’s episode, Senior Advisor and Strategist at the Cybersecurity and Infrastructure Security Agency, Allan Friedman, joins Matt to discuss SBOMs. As Senior Advisor and Strategist at CISA, Allan coordinates the global cross-sector community efforts around software bill of materials (SBOM). He was previously the Director of Cybersecurity Initiatives at NTIA, leading pioneering work on vulnerability disclosure, SBOM, and other security topics.</p><p>Before joining the Federal government, Friedman spent over a decade as a noted information security and technology policy scholar at Harvard’s Computer Science Department, the Brookings Institution, and George Washington University’s Engineering School.</p><p>He is the co-author of the popular text <em>Cybersecurity and Cyberwar: What Everyone Needs to Know</em>, has a C.S. degree from Swarthmore College, and a Ph.D. from Harvard University.</p><p>Today, Allan talks about SBOMs and their adoption in non-security industries, Secure by design and secure by default tactics, and how to make software security second nature. What, exactly, is the SBOM? Hear about how SBOMs could’ve helped against significant attacks, the concept of antifragility, and why vulnerability disclosure programs are so important.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [02:27] Allan’s career path.</p><p>·       [05:10] Allan’s day-to-day.</p><p>·       [06:15] What has been most rewarding?</p><p>·       [08:00] SBOMs in non-security startups.</p><p>·       [10:50] Real-world examples of Secure by Design tactics.</p><p>·       [17:30] Will software security ever seem obvious to us?</p><p>·       [19:30] What is the SBOM, and will it solve all our problems?</p><p>·       [23:41] Could an SBOM have helped against the SolarWinds attack?</p><p>·       [27:52] Memory-safe programming languages.</p><p>·       [30:16] Misconceptions around Secure by Design, Secure by Default.</p><p>·       [32:00] The importance of vulnerability disclosure programs.</p><p>·       [35:37] Antifragility in cybersecurity.</p><p>·       [41:47] VEX.</p><p>·       [44:29] How to get involved with CISA.</p><p>·       [48:00] How does Allan stay sharp?</p><p> </p><p><b>Notable Quotes</b></p><p>·       “Sometimes, organizations need a good excuse to do the right thing.”</p><p>·       “It is bananas that software that we use, and pay for, still delivers with it not just the occasional vulnerability, but very real risks that require massive investments from customers.”</p><p>·       “When tech vendors make important logging information available for free, everyone wins.”</p><p>·       “The SB in SBOM doesn’t stand for Silver Bullet.”</p><p><b> </b></p><p><b>Relevant Links</b></p><p>Email:              <a href="mailto:sbom@cisa.dhs.gov" rel="noopener noreferrer nofollow">sbom@cisa.dhs.gov</a></p><p>Website:          <a href="https://www.cisa.gov/" rel="noopener noreferrer nofollow">www.cisa.gov</a></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/allanafriedman" rel="noopener noreferrer nofollow">Allan Friedman</a></p><p> </p><p><b>Resources:</b></p><p><a href="https://opensourcesecurity.io/category/podcast" rel="noopener noreferrer nofollow">Open Source Security Podcast</a></p><p><a href="https://www.risky.biz/" rel="noopener noreferrer nofollow">Risky Business Podcast</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-13507205</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Thu, 21 Sep 2023 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/853e44f8e7fa02ea9450eadf5c3acb8412f7a8e8a5e3521fdf09ea2a18c50077/eyJlcGlzb2RlSWQiOiJhNjUwNWY3My04ODc2LTQ3ZjctYWJlMC1hMWVmN2EwNmE3MjUiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvYTY1MDVmNzMtODg3Ni00N2Y3LWFiZTAtYTFlZjdhMDZhNzI1LzEzNTA3MjA1LXNib21zLWdvb2QtYnV0LWxlc3MtdGhhbi1hLXNpbHZlci1idWxsZXQubXAzIn0=.mp3" length="36420635" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On today’s episode, Senior Advisor and Strategist at the Cybersecurity and Infrastructure Security Agency, Allan Friedman, joins Matt to discuss SBOMs. As Senior Advisor and Strategist at CISA, Allan coordinates the global cross-sector community efforts around software bill of materials (SBOM). He was previously the Director of Cybersecurity Initiatives at NTIA, leading pioneering work on vulnerability disclosure, SBOM, and other security topics.&lt;/p&gt;&lt;p&gt;Before joining the Federal government, Friedman spent over a decade as a noted information security and technology policy scholar at Harvard’s Computer Science Department, the Brookings Institution, and George Washington University’s Engineering School.&lt;/p&gt;&lt;p&gt;He is the co-author of the popular text &lt;em&gt;Cybersecurity and Cyberwar: What Everyone Needs to Know&lt;/em&gt;, has a C.S. degree from Swarthmore College, and a Ph.D. from Harvard University.&lt;/p&gt;&lt;p&gt;Today, Allan talks about SBOMs and their adoption in non-security industries, Secure by design and secure by default tactics, and how to make software security second nature. What, exactly, is the SBOM? Hear about how SBOMs could’ve helped against significant attacks, the concept of antifragility, and why vulnerability disclosure programs are so important.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:27] Allan’s career path.&lt;/p&gt;&lt;p&gt;·       [05:10] Allan’s day-to-day.&lt;/p&gt;&lt;p&gt;·       [06:15] What has been most rewarding?&lt;/p&gt;&lt;p&gt;·       [08:00] SBOMs in non-security startups.&lt;/p&gt;&lt;p&gt;·       [10:50] Real-world examples of Secure by Design tactics.&lt;/p&gt;&lt;p&gt;·       [17:30] Will software security ever seem obvious to us?&lt;/p&gt;&lt;p&gt;·       [19:30] What is the SBOM, and will it solve all our problems?&lt;/p&gt;&lt;p&gt;·       [23:41] Could an SBOM have helped against the SolarWinds attack?&lt;/p&gt;&lt;p&gt;·       [27:52] Memory-safe programming languages.&lt;/p&gt;&lt;p&gt;·       [30:16] Misconceptions around Secure by Design, Secure by Default.&lt;/p&gt;&lt;p&gt;·       [32:00] The importance of vulnerability disclosure programs.&lt;/p&gt;&lt;p&gt;·       [35:37] Antifragility in cybersecurity.&lt;/p&gt;&lt;p&gt;·       [41:47] VEX.&lt;/p&gt;&lt;p&gt;·       [44:29] How to get involved with CISA.&lt;/p&gt;&lt;p&gt;·       [48:00] How does Allan stay sharp?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “Sometimes, organizations need a good excuse to do the right thing.”&lt;/p&gt;&lt;p&gt;·       “It is bananas that software that we use, and pay for, still delivers with it not just the occasional vulnerability, but very real risks that require massive investments from customers.”&lt;/p&gt;&lt;p&gt;·       “When tech vendors make important logging information available for free, everyone wins.”&lt;/p&gt;&lt;p&gt;·       “The SB in SBOM doesn’t stand for Silver Bullet.”&lt;/p&gt;&lt;p&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Email:              &lt;a href=&quot;mailto:sbom@cisa.dhs.gov&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;sbom@cisa.dhs.gov&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Website:          &lt;a href=&quot;https://www.cisa.gov/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;www.cisa.gov&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/allanafriedman&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Allan Friedman&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resources:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://opensourcesecurity.io/category/podcast&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Open Source Security Podcast&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.risky.biz/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Risky Business Podcast&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:50:29</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>9</itunes:episode><itunes:title>SBOMs: Good but less than a silver bullet</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Fed Clouds]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In a world where cyber-attacks are ever-changing, cybersecurity has to adapt accordingly. Joining us today to delve into the world of cloud security for federal agencies is Sandeep Shilawat, Vice President of Cloud and Edge Computing at ManTech. Sandeep has extensive experience in both Commercial and Federal technology markets. We’ll get to hear his predictions on where the cloud world is heading, as well as what the Federal Authority to Operate (ATO) process will look like in the future. We learn the benefits of cloud compliance standards, as well as how FedRAMP is leveling the playing field in federal cloud computing. We also touch on the role of 5G in cloud computing, and why its presence will disrupt going forward. Join us as we pick Sandeep’s brain for some insights into the present and future of federal cybersecurity.<br /><br /><b>Tweetables<br /></b>“Visibility has become [the] single biggest challenge and nobody's dealing with cloud management in a multi-cloud perspective from cradle to grave.” — <a href="https://twitter.com/shilawat" rel="noopener noreferrer nofollow">@Shilawat</a> [0:09:03]<br /><br />“I think that having a managed cloud service is probably the first approach that should be considered by an agency head. I do think that that's where the market is heading. Sooner or later, it will probably become a de facto way of doing cloud security.” — <a href="https://twitter.com/shilawat" rel="noopener noreferrer nofollow">@Shilawat</a> [0:19:43]</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-10071910</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 14 Feb 2022 15:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/95c8895365fcbce181436ebdca128a78de4388a2e434de32bd998d102510b994/eyJlcGlzb2RlSWQiOiI2NTc4ZGEzZC00NzAxLTQwMGQtOThiMy1hMGM5NDkzOTZiYTIiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNjU3OGRhM2QtNDcwMS00MDBkLTk4YjMtYTBjOTQ5Mzk2YmEyLzEwMDcxOTEwLWZlZC1jbG91ZHMubXAzIn0=.mp3" length="24717459" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In a world where cyber-attacks are ever-changing, cybersecurity has to adapt accordingly. Joining us today to delve into the world of cloud security for federal agencies is Sandeep Shilawat, Vice President of Cloud and Edge Computing at ManTech. Sandeep has extensive experience in both Commercial and Federal technology markets. We’ll get to hear his predictions on where the cloud world is heading, as well as what the Federal Authority to Operate (ATO) process will look like in the future. We learn the benefits of cloud compliance standards, as well as how FedRAMP is leveling the playing field in federal cloud computing. We also touch on the role of 5G in cloud computing, and why its presence will disrupt going forward. Join us as we pick Sandeep’s brain for some insights into the present and future of federal cybersecurity.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Tweetables&lt;br /&gt;&lt;/b&gt;“Visibility has become [the] single biggest challenge and nobody&apos;s dealing with cloud management in a multi-cloud perspective from cradle to grave.” — &lt;a href=&quot;https://twitter.com/shilawat&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@Shilawat&lt;/a&gt; [0:09:03]&lt;br /&gt;&lt;br /&gt;“I think that having a managed cloud service is probably the first approach that should be considered by an agency head. I do think that that&apos;s where the market is heading. Sooner or later, it will probably become a de facto way of doing cloud security.” — &lt;a href=&quot;https://twitter.com/shilawat&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@Shilawat&lt;/a&gt; [0:19:43]&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:34:08</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>2</itunes:episode><itunes:title>Fed Clouds</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[SEC-retly Telling All: The New Cyber-Disclosure Rules]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On this episode, Matt speaks with Senior Executive, Board Director, and leader in Cybersecurity, risk management, and regulatory compliance, Chris Hetner about cybersecurity and the newly-proposed SEC cybersecurity rules. With over 25 years of experience in the cybersecurity space, Chris has served in roles including as Senior Cybersecurity Advisor to the Chairman at the SEC, Managing Director of Information Security Operations at GE Capital, and SVP Information Security at Citi.</p><p>Today, Chris talks about understanding the proposed cybersecurity rules, defining materiality, and the importance of focusing on cyber-resilience. Where does the Cloud come into it? Hear about the cost of cyberattacks, the core risk exposures, and Chris’s formula to personal growth.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [02:47] Chris’s proudest moments.</p><p>·       [10:00] The new proposed rules.</p><p>·       [14:26] Defining materiality.</p><p>·       [23:56] Bridging the language gap.</p><p>·       [32:14] Focusing on cyber-resilience.</p><p>·       [35:36] Cybersecurity expertise on the board.</p><p>·       [41:27] The cloud.</p><p>·       [45:32] The formula to personal growth.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “Ransomware extortion is relatively insignificant relative to the overall cost of the event.”</p><p>·       “You can’t outsource the risk.”</p><p>·       “Realize that you’re not always the smartest person in the room.”</p><p>·       “We don’t know it all, and we never will.”</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-12081835</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sat, 21 Jan 2023 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/46432a4d9911cc18dbb6c95210d8c9521ec8835350be4350d7acb25917b96972/eyJlcGlzb2RlSWQiOiIyZDU4ODNjOS1hMjMyLTRjYzItYTczNC01YTc0YTM1OTVhOGIiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMmQ1ODgzYzktYTIzMi00Y2MyLWE3MzQtNWE3NGEzNTk1YThiLzEyMDgxODM1LXNlYy1yZXRseS10ZWxsaW5nLWFsbC10aGUtbmV3LWN5YmVyLWRpc2Nsb3N1cmUtcnVsZXMubXAzIn0=.mp3" length="34099105" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, Matt speaks with Senior Executive, Board Director, and leader in Cybersecurity, risk management, and regulatory compliance, Chris Hetner about cybersecurity and the newly-proposed SEC cybersecurity rules. With over 25 years of experience in the cybersecurity space, Chris has served in roles including as Senior Cybersecurity Advisor to the Chairman at the SEC, Managing Director of Information Security Operations at GE Capital, and SVP Information Security at Citi.&lt;/p&gt;&lt;p&gt;Today, Chris talks about understanding the proposed cybersecurity rules, defining materiality, and the importance of focusing on cyber-resilience. Where does the Cloud come into it? Hear about the cost of cyberattacks, the core risk exposures, and Chris’s formula to personal growth.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:47] Chris’s proudest moments.&lt;/p&gt;&lt;p&gt;·       [10:00] The new proposed rules.&lt;/p&gt;&lt;p&gt;·       [14:26] Defining materiality.&lt;/p&gt;&lt;p&gt;·       [23:56] Bridging the language gap.&lt;/p&gt;&lt;p&gt;·       [32:14] Focusing on cyber-resilience.&lt;/p&gt;&lt;p&gt;·       [35:36] Cybersecurity expertise on the board.&lt;/p&gt;&lt;p&gt;·       [41:27] The cloud.&lt;/p&gt;&lt;p&gt;·       [45:32] The formula to personal growth.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “Ransomware extortion is relatively insignificant relative to the overall cost of the event.”&lt;/p&gt;&lt;p&gt;·       “You can’t outsource the risk.”&lt;/p&gt;&lt;p&gt;·       “Realize that you’re not always the smartest person in the room.”&lt;/p&gt;&lt;p&gt;·       “We don’t know it all, and we never will.”&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:47:15</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>1</itunes:episode><itunes:title>SEC-retly Telling All: The New Cyber-Disclosure Rules</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Compliant Unicorns]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>Nearly all companies that have started in the last few years have been cloud-native from the very start. Someone who has experienced this is today’s guest Nate Lee. Nate is the Chief Information Security Officer for Tradeshift, a cloud-based business networking platform for supply chain payments, marketplaces, and applications. In this episode, Nate joins us to talk about the company’s journey, its success, and what he has learned here over the past seven years. Nate explains how Tradeshift’s vision is to digitize and connect everything that happens between a buyer and a seller anywhere in the world, and how being cloud-native from the start has supported this mission. We discuss how you can leverage automation and DevSecOps to scale on some very difficult items like ISO 27000 among other certifications. You will also hear how security has been the key differentiator that led to Tradeshift’s success, how the strategic focus of Tradeshift’s security program has shifted over time and the key metrics that Tradeshift tracks to maintain its certifications and compliance efforts.<br /><br /><b>Tweetables<br /></b>“[The vision] is connecting every company in the world. You can't do that with a bunch of islands running in individual data centers. It was an easy choice to be cloud-native back then, as well as a smart choice in general for any company starting these days.” — <a href="https://twitter.com/justanothernate" rel="noopener noreferrer nofollow">@JustAnotherNate</a> [0:08:56]<br /><br />"In security and software development these days, if you're not constantly learning, you're falling behind just as quickly.” — <a href="https://twitter.com/justanothernate" rel="noopener noreferrer nofollow">@JustAnotherNate</a> [0:32:48]<br /><br /><b>Links Mentioned in Today’s Episode</b></p><ul><li><a href="https://www.linkedin.com/in/nate-lee-2179302/" rel="noopener noreferrer nofollow">Nate's LinkedIn profile</a></li><li><a href="https://tradeshift.com" rel="noopener noreferrer nofollow">Tradeshift's website</a></li><li>Nate's blog on <a href="https://www.linkedin.com/pulse/20140710171256-8273971-transform-technical-debt-from-burden-to-tool/?articleId=5893048602372096000" rel="noopener noreferrer nofollow">Transforming Technical Debt from Burden to Tool</a></li><li><a href="https://www.amazon.com/Unicorn-Project-Developers-Disruption-Thriving-ebook/dp/B07QT9QR41" rel="noopener noreferrer nofollow">The Unicorn Project</a></li></ul><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-10289563</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 21 Mar 2022 16:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/bf918007386ade5fbd95aed29af127d0110f5b17bfa08379e6ad27bb7acc14fa/eyJlcGlzb2RlSWQiOiJmZDNlOWYxNi1jYjk2LTQwZjYtYjk1YS02Mzk2NjQwZjhmZWMiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZmQzZTlmMTYtY2I5Ni00MGY2LWI5NWEtNjM5NjY0MGY4ZmVjLzEwMjg5NTYzLWNvbXBsaWFudC11bmljb3Jucy5tcDMifQ==.mp3" length="26938924" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Nearly all companies that have started in the last few years have been cloud-native from the very start. Someone who has experienced this is today’s guest Nate Lee. Nate is the Chief Information Security Officer for Tradeshift, a cloud-based business networking platform for supply chain payments, marketplaces, and applications. In this episode, Nate joins us to talk about the company’s journey, its success, and what he has learned here over the past seven years. Nate explains how Tradeshift’s vision is to digitize and connect everything that happens between a buyer and a seller anywhere in the world, and how being cloud-native from the start has supported this mission. We discuss how you can leverage automation and DevSecOps to scale on some very difficult items like ISO 27000 among other certifications. You will also hear how security has been the key differentiator that led to Tradeshift’s success, how the strategic focus of Tradeshift’s security program has shifted over time and the key metrics that Tradeshift tracks to maintain its certifications and compliance efforts.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Tweetables&lt;br /&gt;&lt;/b&gt;“[The vision] is connecting every company in the world. You can&apos;t do that with a bunch of islands running in individual data centers. It was an easy choice to be cloud-native back then, as well as a smart choice in general for any company starting these days.” — &lt;a href=&quot;https://twitter.com/justanothernate&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@JustAnotherNate&lt;/a&gt; [0:08:56]&lt;br /&gt;&lt;br /&gt;&quot;In security and software development these days, if you&apos;re not constantly learning, you&apos;re falling behind just as quickly.” — &lt;a href=&quot;https://twitter.com/justanothernate&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@JustAnotherNate&lt;/a&gt; [0:32:48]&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Links Mentioned in Today’s Episode&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/in/nate-lee-2179302/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Nate&apos;s LinkedIn profile&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://tradeshift.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Tradeshift&apos;s website&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Nate&apos;s blog on &lt;a href=&quot;https://www.linkedin.com/pulse/20140710171256-8273971-transform-technical-debt-from-burden-to-tool/?articleId=5893048602372096000&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Transforming Technical Debt from Burden to Tool&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.amazon.com/Unicorn-Project-Developers-Disruption-Thriving-ebook/dp/B07QT9QR41&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;The Unicorn Project&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:37:13</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>3</itunes:episode><itunes:title>Compliant Unicorns</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[30 years in cybersecurity]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On this episode, InfoSec veteran, Aaron Turner, joins the show to talk about everything from Cloud to AI. Over the past three decades, Aaron has served as Security Strategist at Microsoft, Co-Founder and CEO of RFinity, Co-Founder and CEO of Terreo, VP of Security Products R&amp;D at Verizon, Founder and CEO of Hotshot Technologies, Founder and CEO of Siriux, Faculty Member of IANS, Board Member at HighSide, President and Board Member of IntegriCell, and most recently as CISO at a large infrastructure player.</p><p>Today, Aaron talks about the critical decisions that led to his success, the findings in his IANS research, and the importance of physical vs logical separation in home networks. What are the things that are lacking in current AI services? Hear about the security applications of behavioral AI, Aaron’s approach as he gets back into industry, and what it takes for Aaron to remain sharp.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [02:49] Getting started.</p><p>·       [10:53] Aaron’s keys to success.</p><p>·       [16:40] Aaron’s IANS research.</p><p>·       [20:42] Physical vs logical separation.</p><p>·       [24:19] Top mistakes that customers make.</p><p>·       [26:56] Real-world AI applications.</p><p>·       [32:13] Thinking about AI and risk.</p><p>·       [36:15] What’s missing in the current AI services?</p><p>·       [40:46] Getting back into the industry.</p><p>·       [45:22] How does Aaron stay sharp?</p><p> </p><p><b>Notable Quotes</b></p><p>·       “Get deep in something.”</p><p>·       “Make sure you put yourself in situations where people expect you to be sharp.”</p><p> </p><p><b>Relevant Links</b></p><p>LinkedIn:  <a href="https://www.linkedin.com/in/aaronrturner" rel="noopener noreferrer nofollow">Aaron Turner</a>.</p><p> <br /><b>Resources:</b></p><p><a href="https://www.iansresearch.com/" rel="noopener noreferrer nofollow">www.iansresearch.com</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-13918663</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 20 Dec 2023 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/a89f7292052b948ec0008a8e1caded14f4952288230e8ffd1a95b796e7631841/eyJlcGlzb2RlSWQiOiI5Y2U5ZDUxNy1iNjU5LTQzOGEtYjY5Mi0yYTVmMTcwYWM5OTMiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvOWNlOWQ1MTctYjY1OS00MzhhLWI2OTItMmE1ZjE3MGFjOTkzLzEzOTE4NjYzLTMwLXllYXJzLWluLWN5YmVyc2VjdXJpdHkubXAzIn0=.mp3" length="37698618" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, InfoSec veteran, Aaron Turner, joins the show to talk about everything from Cloud to AI. Over the past three decades, Aaron has served as Security Strategist at Microsoft, Co-Founder and CEO of RFinity, Co-Founder and CEO of Terreo, VP of Security Products R&amp;amp;D at Verizon, Founder and CEO of Hotshot Technologies, Founder and CEO of Siriux, Faculty Member of IANS, Board Member at HighSide, President and Board Member of IntegriCell, and most recently as CISO at a large infrastructure player.&lt;/p&gt;&lt;p&gt;Today, Aaron talks about the critical decisions that led to his success, the findings in his IANS research, and the importance of physical vs logical separation in home networks. What are the things that are lacking in current AI services? Hear about the security applications of behavioral AI, Aaron’s approach as he gets back into industry, and what it takes for Aaron to remain sharp.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:49] Getting started.&lt;/p&gt;&lt;p&gt;·       [10:53] Aaron’s keys to success.&lt;/p&gt;&lt;p&gt;·       [16:40] Aaron’s IANS research.&lt;/p&gt;&lt;p&gt;·       [20:42] Physical vs logical separation.&lt;/p&gt;&lt;p&gt;·       [24:19] Top mistakes that customers make.&lt;/p&gt;&lt;p&gt;·       [26:56] Real-world AI applications.&lt;/p&gt;&lt;p&gt;·       [32:13] Thinking about AI and risk.&lt;/p&gt;&lt;p&gt;·       [36:15] What’s missing in the current AI services?&lt;/p&gt;&lt;p&gt;·       [40:46] Getting back into the industry.&lt;/p&gt;&lt;p&gt;·       [45:22] How does Aaron stay sharp?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “Get deep in something.”&lt;/p&gt;&lt;p&gt;·       “Make sure you put yourself in situations where people expect you to be sharp.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:  &lt;a href=&quot;https://www.linkedin.com/in/aaronrturner&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Aaron Turner&lt;/a&gt;.&lt;/p&gt;&lt;p&gt; &lt;br /&gt;&lt;b&gt;Resources:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.iansresearch.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;www.iansresearch.com&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:52:15</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>12</itunes:episode><itunes:title>30 years in cybersecurity</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Microsoft 365 incident response]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><a href="https://www.linkedin.com/in/purav-da346393/" rel="noopener noreferrer nofollow">Purav Desai</a> is a Microsoft 365 incident responder at a large financial institution (name withheld to protect the innocent). He shares his journey and expertise in the field. He explains how his early exposure to Microsoft security solutions and their constant innovation led him to specialize in 365 security and incident response. He discusses the importance of mentors and influential figures in his career, highlighting the lessons he learned from them. He then dives into his popular project, <a href="https://github.com/PuravsPoint/DecipheringUAL" rel="noopener noreferrer nofollow">Deciphering UAL</a> (Unified Audit Logs), which aims to make sense of the complex logs in Microsoft 365. <br /><br />Purav shares an incident response scenario involving a banking Trojan and how he used telemetry and logging to investigate and remediate the issue. He concludes by discussing effective threat detection methods in Microsoft 365, including threat hunting with KQL and leveraging Zero-Hour Auto-Purge (ZAP) to prevent the spread of attacks. </p><p><b>In our conversation, we dive into:</b></p><ul><li>How specializing in Microsoft 365 security and incident response can be a wise choice due to the constant innovation and market demand for Microsoft solutions.</li><li>How having mentors and influential figures in your career can provide valuable guidance and inspire you to push yourself and try new things.</li><li>His personal project, <a href="https://github.com/PuravsPoint/DecipheringUAL" rel="noopener noreferrer nofollow">Deciphering UAL</a> (Unified Audit Logs), aims to make sense of the complex logs in Microsoft 365, providing insights for digital forensics and incident response.</li><li>How proper licensing and logging configuration are crucial for effective incident response.</li><li>How native tools like Purview Audit and eDiscovery provide valuable insights for forensic analysis.</li></ul><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-15505088</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Tue, 20 Aug 2024 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/29267f9baf90ea4c43d808b89737b73ce9f6852c92507fecde42a498381db3ac/eyJlcGlzb2RlSWQiOiI0YmEzMDVhOS02MjE1LTRmMDEtYmE0OS1iMzE4OGY2OWYzMzgiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNGJhMzA1YTktNjIxNS00ZjAxLWJhNDktYjMxODhmNjlmMzM4LzE1NTA1MDg4LW1pY3Jvc29mdC0zNjUtaW5jaWRlbnQtcmVzcG9uc2UubXAzIn0=.mp3" length="39626931" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/purav-da346393/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Purav Desai&lt;/a&gt; is a Microsoft 365 incident responder at a large financial institution (name withheld to protect the innocent). He shares his journey and expertise in the field. He explains how his early exposure to Microsoft security solutions and their constant innovation led him to specialize in 365 security and incident response. He discusses the importance of mentors and influential figures in his career, highlighting the lessons he learned from them. He then dives into his popular project, &lt;a href=&quot;https://github.com/PuravsPoint/DecipheringUAL&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Deciphering UAL&lt;/a&gt; (Unified Audit Logs), which aims to make sense of the complex logs in Microsoft 365. &lt;br /&gt;&lt;br /&gt;Purav shares an incident response scenario involving a banking Trojan and how he used telemetry and logging to investigate and remediate the issue. He concludes by discussing effective threat detection methods in Microsoft 365, including threat hunting with KQL and leveraging Zero-Hour Auto-Purge (ZAP) to prevent the spread of attacks. &lt;/p&gt;&lt;p&gt;&lt;b&gt;In our conversation, we dive into:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;How specializing in Microsoft 365 security and incident response can be a wise choice due to the constant innovation and market demand for Microsoft solutions.&lt;/li&gt;&lt;li&gt;How having mentors and influential figures in your career can provide valuable guidance and inspire you to push yourself and try new things.&lt;/li&gt;&lt;li&gt;His personal project, &lt;a href=&quot;https://github.com/PuravsPoint/DecipheringUAL&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Deciphering UAL&lt;/a&gt; (Unified Audit Logs), aims to make sense of the complex logs in Microsoft 365, providing insights for digital forensics and incident response.&lt;/li&gt;&lt;li&gt;How proper licensing and logging configuration are crucial for effective incident response.&lt;/li&gt;&lt;li&gt;How native tools like Purview Audit and eDiscovery provide valuable insights for forensic analysis.&lt;/li&gt;&lt;/ul&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:54:56</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>10</itunes:episode><itunes:title>Microsoft 365 incident response</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[LLMs: risks, rewards, and realities]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>Nate Lee discusses his transition from a CISO role to fractional CISO work, emphasizing the importance of variety and exposure in his career. He delves into the rise of AI, particularly large language models (LLMs), and the associated security concerns, including prompt injection risks. <br /><br />Nate highlights the critical role of orchestrators in managing AI interactions and the need for security practitioners to adapt to the evolving landscape. He shares insights from his 20 years in cybersecurity and offers recommendations for practitioners to engage with AI responsibly and effectively.<br /><br /><b>Takeaways</b></p><ul><li>Nate transitioned to fractional CISO work for variety and exposure.</li><li>Prompt injection is a major vulnerability in LLM systems.</li><li>Orchestrators are essential for managing AI interactions securely.</li><li>Security practitioners must understand how LLMs work to mitigate risks.</li><li>Nate emphasizes the importance of human oversight in AI systems.</li></ul><p>Link to <a href="https://cloudsecurityalliance.org/artifacts/securing-llm-backed-systems-essential-authorization-practices" rel="noopener noreferrer nofollow">Nate's research</a> with the Cloud Security Alliance.<br /><br /></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-15900036</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 20 Nov 2024 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/0f9d4f5df22c1d8bc3e0482d308112bfdfd269b19a438149e26a2a4171035cec/eyJlcGlzb2RlSWQiOiIyMWUyNjE1MC1mNGNiLTRjOWQtOTE3YS0wMDA0YzcwMDE2YjAiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMjFlMjYxNTAtZjRjYi00YzlkLTkxN2EtMDAwNGM3MDAxNmIwLzE1OTAwMDM2LWxsbXMtcmlza3MtcmV3YXJkcy1hbmQtcmVhbGl0aWVzLm1wMyJ9.mp3" length="34220846" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Nate Lee discusses his transition from a CISO role to fractional CISO work, emphasizing the importance of variety and exposure in his career. He delves into the rise of AI, particularly large language models (LLMs), and the associated security concerns, including prompt injection risks. &lt;br /&gt;&lt;br /&gt;Nate highlights the critical role of orchestrators in managing AI interactions and the need for security practitioners to adapt to the evolving landscape. He shares insights from his 20 years in cybersecurity and offers recommendations for practitioners to engage with AI responsibly and effectively.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Nate transitioned to fractional CISO work for variety and exposure.&lt;/li&gt;&lt;li&gt;Prompt injection is a major vulnerability in LLM systems.&lt;/li&gt;&lt;li&gt;Orchestrators are essential for managing AI interactions securely.&lt;/li&gt;&lt;li&gt;Security practitioners must understand how LLMs work to mitigate risks.&lt;/li&gt;&lt;li&gt;Nate emphasizes the importance of human oversight in AI systems.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Link to &lt;a href=&quot;https://cloudsecurityalliance.org/artifacts/securing-llm-backed-systems-essential-authorization-practices&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Nate&apos;s research&lt;/a&gt; with the Cloud Security Alliance.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:47:26</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>13</itunes:episode><itunes:title>LLMs: risks, rewards, and realities</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Accelerating security maturity]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On this episode, AWS Security Practice Manager, Chad Lorenc, joins Matt to talk about Cloud Security. Chad has spent over 20 years building and implementing security programs for numerous organizations, ranging from global Fortune 500 infrastructure teams to billion-dollar financial institutions. He has previously served as Senior Infrastructure Security Architect at Keysight Technologies, President of Montana Chapter, and Information Security and Risk Management Infrastructure Architect at Agilent Technologies.</p><p>Today, Chad talks about the roadmap to security maturity, security best practices, and benchmarking assessments. Why doesn’t AWS necessarily hire people with Cloud skills? Hear about The Five Pillars, when Cloud security goes wrong, CISO reporting Cloud security, and Chad’s formula for personal growth.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [01:24] A bit about Chad.</p><p>·       [03:13] Chad’s role at AWS.</p><p>·       [04:03] Transitioning to AWS.</p><p>·       [08:30] AWS doesn’t hire for Cloud skills.</p><p>·       [10:41] Where to start.</p><p>·       [13:54] Assessment benchmarking.</p><p>·       [15:09] Getting to security maturity.</p><p>·       [19:17] The Five Pillars.</p><p>·       [24:21] Cloud security gone wrong.</p><p>·       [32:14] The Cloud Center of Excellence.</p><p>·       [35:15] Reporting Cloud security maturity.</p><p>·       [40:54] Chad’s formula for personal growth.</p><p>·       [44:50] Chad’s words of wisdom.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “There’s no algorithm for compressing security experience.”</p><p>·       “Figuring out how to integrate Cloud into your operational processes and technology is key.”</p><p>·       “The key to growing fast is to prioritize ruthlessly.”</p><p> </p><p><b>Relevant Links</b></p><p>Website: <a href="https://aws.amazon.com/" rel="noopener noreferrer nofollow">aws.amazon.com</a></p><p> </p><p><b>Resources:</b></p><p><a href="https://awsfundamentals.com/" rel="noopener noreferrer nofollow">awsfundamentals.com</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-12447070</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sun, 21 May 2023 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/015349a292646bcd8c5d12ae8dcc6e958b9ce733592ca881ee613299069e0968/eyJlcGlzb2RlSWQiOiI3YzAxMjg4OS1kOThmLTQ4NjgtOWUzNi1mZDFjNTM1Y2MwYzQiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvN2MwMTI4ODktZDk4Zi00ODY4LTllMzYtZmQxYzUzNWNjMGM0LzEyNDQ3MDcwLWFjY2VsZXJhdGluZy1zZWN1cml0eS1tYXR1cml0eS5tcDMifQ==.mp3" length="33920068" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, AWS Security Practice Manager, Chad Lorenc, joins Matt to talk about Cloud Security. Chad has spent over 20 years building and implementing security programs for numerous organizations, ranging from global Fortune 500 infrastructure teams to billion-dollar financial institutions. He has previously served as Senior Infrastructure Security Architect at Keysight Technologies, President of Montana Chapter, and Information Security and Risk Management Infrastructure Architect at Agilent Technologies.&lt;/p&gt;&lt;p&gt;Today, Chad talks about the roadmap to security maturity, security best practices, and benchmarking assessments. Why doesn’t AWS necessarily hire people with Cloud skills? Hear about The Five Pillars, when Cloud security goes wrong, CISO reporting Cloud security, and Chad’s formula for personal growth.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:24] A bit about Chad.&lt;/p&gt;&lt;p&gt;·       [03:13] Chad’s role at AWS.&lt;/p&gt;&lt;p&gt;·       [04:03] Transitioning to AWS.&lt;/p&gt;&lt;p&gt;·       [08:30] AWS doesn’t hire for Cloud skills.&lt;/p&gt;&lt;p&gt;·       [10:41] Where to start.&lt;/p&gt;&lt;p&gt;·       [13:54] Assessment benchmarking.&lt;/p&gt;&lt;p&gt;·       [15:09] Getting to security maturity.&lt;/p&gt;&lt;p&gt;·       [19:17] The Five Pillars.&lt;/p&gt;&lt;p&gt;·       [24:21] Cloud security gone wrong.&lt;/p&gt;&lt;p&gt;·       [32:14] The Cloud Center of Excellence.&lt;/p&gt;&lt;p&gt;·       [35:15] Reporting Cloud security maturity.&lt;/p&gt;&lt;p&gt;·       [40:54] Chad’s formula for personal growth.&lt;/p&gt;&lt;p&gt;·       [44:50] Chad’s words of wisdom.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “There’s no algorithm for compressing security experience.”&lt;/p&gt;&lt;p&gt;·       “Figuring out how to integrate Cloud into your operational processes and technology is key.”&lt;/p&gt;&lt;p&gt;·       “The key to growing fast is to prioritize ruthlessly.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website: &lt;a href=&quot;https://aws.amazon.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;aws.amazon.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resources:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://awsfundamentals.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;awsfundamentals.com&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:47:00</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>5</itunes:episode><itunes:title>Accelerating security maturity</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Book review: CISO Evolution]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>On this episode, the Founder of CISO Evolution LLC, Matthew Sharp, joins Matt to talk about his book, CISO Evolution. Prior to founding CISO Evolution LLC, Matt served as a strategic advisor to CISOs of Fortune 500 and global institutions. He holds a Bachelor of Science (BS) in Electrical and Computer Engineering from the University of Colorado and a Master of Business Administration (MBA) from Colorado State University. Matt is a co-author of "The CISO Evolution: Business Knowledge for Cybersecurity Executives."</p><p>Today, Matthew talks about his 2012 sabbatical, walking the Camino de Santiago, and the CISO Evolution book. Why does process matter more than analysis? Hear about value creation, business negotiations, and Matthew’s formula for personal growth.</p><p><b>Timestamp Segments</b></p><p>·       [02:06] A bit about Matthew.</p><p>·       [04:30] Matthew’s sabbatical &amp; the Camino de Santiago.</p><p>·       [09:21] What prompted the book?</p><p>·       [12:23] Why does process matter more than analysis?</p><p>·       [19:08] Did Matthew’s MBA lead him down this path?</p><p>·       [24:22] Value creation.</p><p>·       [27:40] Standard metrics.</p><p>·       [31:23] Why is it important for a CISO to know terms?</p><p>·       [33:32] Negotiations and decision-making.</p><p>·       [37:19] What’s Matthew’s formula for personal growth?</p><p>·       [41:12] Matthew’s words of wisdom.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “If you want to be in the room where it happens, then you have to be equipped to participate in the conversation.”</p><p>·       “Ask the questions that go unasked.”</p><p>·       “Don’t be afraid to go and look like an idiot in front of another business stakeholder.”</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-12446986</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Tue, 21 Mar 2023 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/d0cc7b3a9a82ed1b26333f7d5f1c76a37aa1b816a424e864c0675efd7a2d175c/eyJlcGlzb2RlSWQiOiIzOTY5YzkyNi1mZTFkLTQ3ODAtODUyYS00ZDUwMmYwYzYyNzkiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMzk2OWM5MjYtZmUxZC00NzgwLTg1MmEtNGQ1MDJmMGM2Mjc5LzEyNDQ2OTg2LWJvb2stcmV2aWV3LWNpc28tZXZvbHV0aW9uLm1wMyJ9.mp3" length="31180653" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;On this episode, the Founder of CISO Evolution LLC, Matthew Sharp, joins Matt to talk about his book, CISO Evolution. Prior to founding CISO Evolution LLC, Matt served as a strategic advisor to CISOs of Fortune 500 and global institutions. He holds a Bachelor of Science (BS) in Electrical and Computer Engineering from the University of Colorado and a Master of Business Administration (MBA) from Colorado State University. Matt is a co-author of &quot;The CISO Evolution: Business Knowledge for Cybersecurity Executives.&quot;&lt;/p&gt;&lt;p&gt;Today, Matthew talks about his 2012 sabbatical, walking the Camino de Santiago, and the CISO Evolution book. Why does process matter more than analysis? Hear about value creation, business negotiations, and Matthew’s formula for personal growth.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:06] A bit about Matthew.&lt;/p&gt;&lt;p&gt;·       [04:30] Matthew’s sabbatical &amp;amp; the Camino de Santiago.&lt;/p&gt;&lt;p&gt;·       [09:21] What prompted the book?&lt;/p&gt;&lt;p&gt;·       [12:23] Why does process matter more than analysis?&lt;/p&gt;&lt;p&gt;·       [19:08] Did Matthew’s MBA lead him down this path?&lt;/p&gt;&lt;p&gt;·       [24:22] Value creation.&lt;/p&gt;&lt;p&gt;·       [27:40] Standard metrics.&lt;/p&gt;&lt;p&gt;·       [31:23] Why is it important for a CISO to know terms?&lt;/p&gt;&lt;p&gt;·       [33:32] Negotiations and decision-making.&lt;/p&gt;&lt;p&gt;·       [37:19] What’s Matthew’s formula for personal growth?&lt;/p&gt;&lt;p&gt;·       [41:12] Matthew’s words of wisdom.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “If you want to be in the room where it happens, then you have to be equipped to participate in the conversation.”&lt;/p&gt;&lt;p&gt;·       “Ask the questions that go unasked.”&lt;/p&gt;&lt;p&gt;·       “Don’t be afraid to go and look like an idiot in front of another business stakeholder.”&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:43:12</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>3</itunes:episode><itunes:title>Book review: CISO Evolution</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Supply Chain Security]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>Despite the media coverage afforded to the SolarWinds and Kaseya breaches, Palo Alto Networks, Unit 42 threat research indicates supply chain security in the cloud continues its growth as an emerging threat. Much remains misunderstood about both the nature of these attacks and the most effective means of defending against them. To better understand how supply chain attacks occur in the cloud, Unit 42 researchers analyzed data from a variety of public data sources around the world and, at the request of a large SaaS provider, executed a red team exercise against their software development environment. As you'll hear in the podcast, overall, the findings indicate that many organizations may still be lulled into a false sense of supply chain security in the cloud. Case in point: Even with limited access to the customer’s development environment, <b>it took a single Unit 42 researcher only three days to discover several critical software development flaws that could have exposed the customer to an attack similar to that of SolarWinds and Kaseya</b>. </p><p>In the podcast, Unit 42 researchers <a href="https://www.linkedin.com/in/qquist/" rel="noopener noreferrer nofollow">Nathaniel "Q" Quist</a> and <a href="https://www.linkedin.com/in/jaychen2015/" rel="noopener noreferrer nofollow">Dr. Jay Chen</a>, draw on Unit 42’s analysis of past supply chain attacks. The <a href="https://cloudthreat.report/" rel="noopener noreferrer nofollow">Cloud Threat Report</a> explains the full scope of supply chain attacks, discusses poorly understood details about how they occur, and recommends actionable best practices that organizations can adopt today to help protect their supply chains in the cloud. </p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-9725538</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 15 Dec 2021 16:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/30d4265ef8f82254b73a2e9f0fc2f346c8fd789e8f35f3d6f7ea14c796520218/eyJlcGlzb2RlSWQiOiI2MWZlYzlkYy05MmMzLTRhMmItOWRlZS05ZDhlYTYyZWQ1YTgiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNjFmZWM5ZGMtOTJjMy00YTJiLTlkZWUtOWQ4ZWE2MmVkNWE4Lzk3MjU1Mzgtc3VwcGx5LWNoYWluLXNlY3VyaXR5Lm1wMyJ9.mp3" length="23096060" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Despite the media coverage afforded to the SolarWinds and Kaseya breaches, Palo Alto Networks, Unit 42 threat research indicates supply chain security in the cloud continues its growth as an emerging threat. Much remains misunderstood about both the nature of these attacks and the most effective means of defending against them. To better understand how supply chain attacks occur in the cloud, Unit 42 researchers analyzed data from a variety of public data sources around the world and, at the request of a large SaaS provider, executed a red team exercise against their software development environment. As you&apos;ll hear in the podcast, overall, the findings indicate that many organizations may still be lulled into a false sense of supply chain security in the cloud. Case in point: Even with limited access to the customer’s development environment, &lt;b&gt;it took a single Unit 42 researcher only three days to discover several critical software development flaws that could have exposed the customer to an attack similar to that of SolarWinds and Kaseya&lt;/b&gt;. &lt;/p&gt;&lt;p&gt;In the podcast, Unit 42 researchers &lt;a href=&quot;https://www.linkedin.com/in/qquist/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Nathaniel &quot;Q&quot; Quist&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/jaychen2015/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Dr. Jay Chen&lt;/a&gt;, draw on Unit 42’s analysis of past supply chain attacks. The &lt;a href=&quot;https://cloudthreat.report/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Cloud Threat Report&lt;/a&gt; explains the full scope of supply chain attacks, discusses poorly understood details about how they occur, and recommends actionable best practices that organizations can adopt today to help protect their supply chains in the cloud. &lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:31:54</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>10</itunes:episode><itunes:title>Supply Chain Security</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[What Serverless Can Do For You]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>What Serverless Can Do For You? With Mark Gould</b></p><p><b>Episode Summary</b></p><p>On this episode, Cloud Security Engineer at Manhattan Associates, Mark Gould, joins Matt to talk about serverless computing. Mark is a Cybersecurity specialist, with a focus on the Google Cloud Platform, and is a Certified Google Architect.</p><p>Today, Mark talks about serverless computing, the security risk to consider, and working with DevOps teams. What are the top three metrics to start with for automation and security? Hear about cloud automation, Mark’s NSG alerting system, and his greatest accomplishments in recent years.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [01:22] About Mark.</p><p>·       [02:49] About Manhattan Associates.</p><p>·       [04:46] How does cloud fit in?</p><p>·       [06:16] Automation in the cloud.</p><p>·       [09:03] Modernization at Manhattan Associates.</p><p>·       [10:18] Serverless computing.</p><p>·       [14:39] Security risks with using serverless functions.</p><p>·       [17:58] Mark’s NSG alerting system.</p><p>·       [21:27] Three metrics for automation and security.</p><p>·       [23:33] What should security teams be doing differently when working with DevOps?</p><p>·       [25:43] What is Mark most proud of?</p><p>·       [27:45] How does Mark continue to learn?</p><p>·       [30:31] Is Manhattan Associates hiring?</p><p> </p><p><b>Notable Quotes</b></p><p>·       “You definitely have to pick what kind of processes you want to automate and make sure that you’re willing to put in the work to maintain them.”</p><p>·       “Sometimes serverless isn’t always the cheapest option.”</p><p>·       “Leaders are learners.”</p><p> </p><p><b>Relevant Links</b></p><p>Manhattan Associates:           <a href="https://www.manh.com/" rel="noopener noreferrer nofollow">https://www.manh.com</a></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/mark-gould-15a7a3149" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/mark-gould-15a7a3149</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-11127543</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Fri, 21 Oct 2022 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/e0a5f9ffec4d7b16a27d770b2d52af0152b3d7c52c4caa59bc978babee503b31/eyJlcGlzb2RlSWQiOiIzZDA4MDM0Ni1iMzM2LTRiY2QtYTc5OC1kZTFiMDBiNTk4Y2YiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvM2QwODAzNDYtYjMzNi00YmNkLWE3OTgtZGUxYjAwYjU5OGNmLzExMTI3NTQzLXdoYXQtc2VydmVybGVzcy1jYW4tZG8tZm9yLXlvdS5tcDMifQ==.mp3" length="23316966" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;What Serverless Can Do For You? With Mark Gould&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, Cloud Security Engineer at Manhattan Associates, Mark Gould, joins Matt to talk about serverless computing. Mark is a Cybersecurity specialist, with a focus on the Google Cloud Platform, and is a Certified Google Architect.&lt;/p&gt;&lt;p&gt;Today, Mark talks about serverless computing, the security risk to consider, and working with DevOps teams. What are the top three metrics to start with for automation and security? Hear about cloud automation, Mark’s NSG alerting system, and his greatest accomplishments in recent years.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:22] About Mark.&lt;/p&gt;&lt;p&gt;·       [02:49] About Manhattan Associates.&lt;/p&gt;&lt;p&gt;·       [04:46] How does cloud fit in?&lt;/p&gt;&lt;p&gt;·       [06:16] Automation in the cloud.&lt;/p&gt;&lt;p&gt;·       [09:03] Modernization at Manhattan Associates.&lt;/p&gt;&lt;p&gt;·       [10:18] Serverless computing.&lt;/p&gt;&lt;p&gt;·       [14:39] Security risks with using serverless functions.&lt;/p&gt;&lt;p&gt;·       [17:58] Mark’s NSG alerting system.&lt;/p&gt;&lt;p&gt;·       [21:27] Three metrics for automation and security.&lt;/p&gt;&lt;p&gt;·       [23:33] What should security teams be doing differently when working with DevOps?&lt;/p&gt;&lt;p&gt;·       [25:43] What is Mark most proud of?&lt;/p&gt;&lt;p&gt;·       [27:45] How does Mark continue to learn?&lt;/p&gt;&lt;p&gt;·       [30:31] Is Manhattan Associates hiring?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “You definitely have to pick what kind of processes you want to automate and make sure that you’re willing to put in the work to maintain them.”&lt;/p&gt;&lt;p&gt;·       “Sometimes serverless isn’t always the cheapest option.”&lt;/p&gt;&lt;p&gt;·       “Leaders are learners.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Manhattan Associates:           &lt;a href=&quot;https://www.manh.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.manh.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/mark-gould-15a7a3149&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/mark-gould-15a7a3149&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:32:17</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>11</itunes:episode><itunes:title>What Serverless Can Do For You</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Attracting and retaining cyber talent]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><a href="https://www.linkedin.com/in/andersonmeg/" rel="noopener noreferrer nofollow">Meg Anderson</a>, the CISO at <a href="https://careers.principal.com/careers-home/jobs?page=1&amp;sortBy=relevance&amp;categories=Engineering%20%26%20Technology" rel="noopener noreferrer nofollow">Principal Financial Group</a>, discusses her 17-year tenure as a CISO and the factors contributing to her long-term success. She attributes her longevity to her passion for the job and the opportunities for growth and development at Principal. Meg emphasizes the importance of understanding the business impact of cybersecurity and holding people accountable. She also highlights the significance of focusing on the basics of cybersecurity and not getting caught up in the latest trends. Meg shares her experience with mentorship and its role in her career. She also discusses the programs implemented at Principal to attract and retain cyber talent, such as a formal mentorship program and a robust internship program.<br /><br /><b>Takeaways</b></p><ul><li>Passion for the job and naivete can contribute to long-term success as a CISO.</li><li>Understanding the business impact of cybersecurity and holding people accountable is crucial.</li><li>Focusing on the basics of cybersecurity is essential, rather than getting caught up in the latest trends.</li><li>Mentorship plays a significant role in career development.</li><li>Taking time away from work is essential for personal growth and avoiding burnout.</li></ul><p><br /><b>Chapters</b></p><ul><li>00:00 Introduction and Long-Term Success as a CISO</li><li>03:15 The Importance of Naivete and Passion</li><li>06:34 The Role of Mentorship</li><li>10:54 Attracting and Retaining Cyber Talent</li><li>12:50 Organizing a Cyber Youth Summit</li><li>21:13 Building a Cyber Program Around Company Culture</li><li>28:07 Focusing on the Basics of Cybersecurity</li><li>36:19 Personal Growth and Parting Words</li></ul><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-15659573</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sun, 22 Sep 2024 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/4a723c649a05debff158616f9520c98328d0ba600e90ef6466847890add8c5ff/eyJlcGlzb2RlSWQiOiIwNDJiYmM3Zi02NTFlLTQ1OWItYWQ3NC1kYWEyNWUxODYwODYiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMDQyYmJjN2YtNjUxZS00NTliLWFkNzQtZGFhMjVlMTg2MDg2LzE1NjU5NTczLWF0dHJhY3RpbmctYW5kLXJldGFpbmluZy1jeWJlci10YWxlbnQubXAzIn0=.mp3" length="31110607" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/andersonmeg/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Meg Anderson&lt;/a&gt;, the CISO at &lt;a href=&quot;https://careers.principal.com/careers-home/jobs?page=1&amp;amp;sortBy=relevance&amp;amp;categories=Engineering%20%26%20Technology&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Principal Financial Group&lt;/a&gt;, discusses her 17-year tenure as a CISO and the factors contributing to her long-term success. She attributes her longevity to her passion for the job and the opportunities for growth and development at Principal. Meg emphasizes the importance of understanding the business impact of cybersecurity and holding people accountable. She also highlights the significance of focusing on the basics of cybersecurity and not getting caught up in the latest trends. Meg shares her experience with mentorship and its role in her career. She also discusses the programs implemented at Principal to attract and retain cyber talent, such as a formal mentorship program and a robust internship program.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Passion for the job and naivete can contribute to long-term success as a CISO.&lt;/li&gt;&lt;li&gt;Understanding the business impact of cybersecurity and holding people accountable is crucial.&lt;/li&gt;&lt;li&gt;Focusing on the basics of cybersecurity is essential, rather than getting caught up in the latest trends.&lt;/li&gt;&lt;li&gt;Mentorship plays a significant role in career development.&lt;/li&gt;&lt;li&gt;Taking time away from work is essential for personal growth and avoiding burnout.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;b&gt;Chapters&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;00:00 Introduction and Long-Term Success as a CISO&lt;/li&gt;&lt;li&gt;03:15 The Importance of Naivete and Passion&lt;/li&gt;&lt;li&gt;06:34 The Role of Mentorship&lt;/li&gt;&lt;li&gt;10:54 Attracting and Retaining Cyber Talent&lt;/li&gt;&lt;li&gt;12:50 Organizing a Cyber Youth Summit&lt;/li&gt;&lt;li&gt;21:13 Building a Cyber Program Around Company Culture&lt;/li&gt;&lt;li&gt;28:07 Focusing on the Basics of Cybersecurity&lt;/li&gt;&lt;li&gt;36:19 Personal Growth and Parting Words&lt;/li&gt;&lt;/ul&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:43:07</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>11</itunes:episode><itunes:title>Attracting and retaining cyber talent</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The Talent Shortage That Doesn’t Exist]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On this episode, Best Selling author of <a href="https://www.amazon.com/dp/173823410X/ref=tsm_1_fb_lk" rel="noopener noreferrer nofollow">Cyber for Builders</a> and blogger Ross Haleliuk joins the show to talk about his writing on the cybersecurity industry. Ross is active in the cybersecurity ecosystem as a startup advisor and angel investor, currently leading the VIS Angel Syndicate. He often writes about cybersecurity, security investment, growth, and building security startups on TechCrunch, in other leading industry media, and in his blog, Venture in Security, read by tens of thousands of security leaders every month.</p><p><br />Today, Ross talks about the usefulness of apprenticeship programs and the impact of AI on the talent shortage. What makes the talent shortage a qualitative issue? Hear about AI and cybersecurity problem-solving, Ross’s recently released book, and how Ross stays sharp (and fit).</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [02:23] Pivoting into cybersecurity.</p><p>·       [08:20] The role of project manager.</p><p>·       [11:24] The BISO role.</p><p>·       [13:41] The talent shortage as a qualitative issue.</p><p>·       [23:58] Apprenticeship programs.</p><p>·       [30:51] Qualitative vs quantitative talent shortage.</p><p>·       [33:15] The impact of AI.</p><p>·       [39:06] AI in cybersecurity.</p><p>·       [41:54] What is Ross writing about next?</p><p>·       [43:12] How Ross stays sharp.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “A lot of problems in cybersecurity are not unique to the space.”</p><p>·       “It is difficult to find an entry-level job in the technology space, period.”</p><p>·       “There is a shortage of senior talent, but there is also an oversupply of junior talent.”</p><p> </p><p><b>Relevant Links</b></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/rosshaleliuk" rel="noopener noreferrer nofollow">Ross Haleliuk</a></p><p> </p><p><b>Resources:</b></p><p><a href="https://ventureinsecurity.net/" rel="noopener noreferrer nofollow">ventureinsecurity.net</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-14085662</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sat, 20 Jan 2024 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/d7ed5450b360b0c37410c3e4a5a599ede782a3abdffa7e76ebc6ba544e045412/eyJlcGlzb2RlSWQiOiI3MTE2MWQzMy01NzI5LTQxZWEtOGQ2NS1lY2Y1ZDUxMDRjNmMiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNzExNjFkMzMtNTcyOS00MWVhLThkNjUtZWNmNWQ1MTA0YzZjLzE0MDg1NjYyLXRoZS10YWxlbnQtc2hvcnRhZ2UtdGhhdC1kb2Vzbi10LWV4aXN0Lm1wMyJ9.mp3" length="32936730" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, Best Selling author of &lt;a href=&quot;https://www.amazon.com/dp/173823410X/ref=tsm_1_fb_lk&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Cyber for Builders&lt;/a&gt; and blogger Ross Haleliuk joins the show to talk about his writing on the cybersecurity industry. Ross is active in the cybersecurity ecosystem as a startup advisor and angel investor, currently leading the VIS Angel Syndicate. He often writes about cybersecurity, security investment, growth, and building security startups on TechCrunch, in other leading industry media, and in his blog, Venture in Security, read by tens of thousands of security leaders every month.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Today, Ross talks about the usefulness of apprenticeship programs and the impact of AI on the talent shortage. What makes the talent shortage a qualitative issue? Hear about AI and cybersecurity problem-solving, Ross’s recently released book, and how Ross stays sharp (and fit).&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:23] Pivoting into cybersecurity.&lt;/p&gt;&lt;p&gt;·       [08:20] The role of project manager.&lt;/p&gt;&lt;p&gt;·       [11:24] The BISO role.&lt;/p&gt;&lt;p&gt;·       [13:41] The talent shortage as a qualitative issue.&lt;/p&gt;&lt;p&gt;·       [23:58] Apprenticeship programs.&lt;/p&gt;&lt;p&gt;·       [30:51] Qualitative vs quantitative talent shortage.&lt;/p&gt;&lt;p&gt;·       [33:15] The impact of AI.&lt;/p&gt;&lt;p&gt;·       [39:06] AI in cybersecurity.&lt;/p&gt;&lt;p&gt;·       [41:54] What is Ross writing about next?&lt;/p&gt;&lt;p&gt;·       [43:12] How Ross stays sharp.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “A lot of problems in cybersecurity are not unique to the space.”&lt;/p&gt;&lt;p&gt;·       “It is difficult to find an entry-level job in the technology space, period.”&lt;/p&gt;&lt;p&gt;·       “There is a shortage of senior talent, but there is also an oversupply of junior talent.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/rosshaleliuk&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Ross Haleliuk&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resources:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://ventureinsecurity.net/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;ventureinsecurity.net&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:45:39</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>1</itunes:episode><itunes:title>The Talent Shortage That Doesn’t Exist</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The art of security transformation]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On this episode, CISO at Palo Alto Networks, Niall Browne, joins the show to talk about Security, Cloud, and AI. Before joining Palo Alto Networks, he served as the CSO of Cloud platforms for the past sixteen years, including as the CSO and CTO at Workday.</p><p>Today, Niall talks about his journey starting in the early days of the Internet, his work during Palo Alto’s shift to Cloud and now AI, and how to keep track of risk with automation. How can teams do more with less? Hear about how to communicate risk to company board members, the usefulness of Gen AI, and the cyber skills shortage.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [01:39] Niall’s Bank of Ireland experience.</p><p>·       [05:07] How did the early internet catch Niall’s attention?</p><p>·       [08:56] What is Niall most proud of?</p><p>·       [11:34] Palo Alto’s shift to Cloud.</p><p>·       [16:43] Overcoming resistance to the shift.</p><p>·       [22:53] Keeping a pulse on risk.</p><p>·       [28:07] Communicating risk to boards.</p><p>·       [33:46] Doing More With Less.</p><p>·       [38:00] How does Gen AI make processes better?</p><p>·       [41:27] The cyber skills shortage.</p><p>·       [47:04] Niall’s personal growth formula.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “More with less is key.”</p><p>·       “Hiring the right skill set is very difficult.”</p><p> </p><p><b>Relevant Links</b></p><p>Website:          <a href="https://www.paloaltonetworks.com/" rel="noopener noreferrer nofollow">www.paloaltonetworks.com</a></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/niallbrowne" rel="noopener noreferrer nofollow">Niall Browne</a></p><p> </p><p><b>Resources:</b></p><p><a href="https://www.csoonline.com/article/573495/doing-more-with-less-the-case-for-soc-consolidation-2.html" rel="noopener noreferrer nofollow">Doing More with Less: The Case for SOC Consolidation</a>.</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-14632626</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 22 Apr 2024 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/9625be52cba8f0ca5a1a365d6ac267b0c1c656c52c541c9f30f802d44ec004f8/eyJlcGlzb2RlSWQiOiJkMTIzNWMxZi01Y2VmLTQ1YjEtYjg4OC0yYzZjYTVmZmUzNDIiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZDEyMzVjMWYtNWNlZi00NWIxLWI4ODgtMmM2Y2E1ZmZlMzQyLzE0NjMyNjI2LXRoZS1hcnQtb2Ytc2VjdXJpdHktdHJhbnNmb3JtYXRpb24ubXAzIn0=.mp3" length="36758855" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, CISO at Palo Alto Networks, Niall Browne, joins the show to talk about Security, Cloud, and AI. Before joining Palo Alto Networks, he served as the CSO of Cloud platforms for the past sixteen years, including as the CSO and CTO at Workday.&lt;/p&gt;&lt;p&gt;Today, Niall talks about his journey starting in the early days of the Internet, his work during Palo Alto’s shift to Cloud and now AI, and how to keep track of risk with automation. How can teams do more with less? Hear about how to communicate risk to company board members, the usefulness of Gen AI, and the cyber skills shortage.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:39] Niall’s Bank of Ireland experience.&lt;/p&gt;&lt;p&gt;·       [05:07] How did the early internet catch Niall’s attention?&lt;/p&gt;&lt;p&gt;·       [08:56] What is Niall most proud of?&lt;/p&gt;&lt;p&gt;·       [11:34] Palo Alto’s shift to Cloud.&lt;/p&gt;&lt;p&gt;·       [16:43] Overcoming resistance to the shift.&lt;/p&gt;&lt;p&gt;·       [22:53] Keeping a pulse on risk.&lt;/p&gt;&lt;p&gt;·       [28:07] Communicating risk to boards.&lt;/p&gt;&lt;p&gt;·       [33:46] Doing More With Less.&lt;/p&gt;&lt;p&gt;·       [38:00] How does Gen AI make processes better?&lt;/p&gt;&lt;p&gt;·       [41:27] The cyber skills shortage.&lt;/p&gt;&lt;p&gt;·       [47:04] Niall’s personal growth formula.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “More with less is key.”&lt;/p&gt;&lt;p&gt;·       “Hiring the right skill set is very difficult.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website:          &lt;a href=&quot;https://www.paloaltonetworks.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;www.paloaltonetworks.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/niallbrowne&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Niall Browne&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resources:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.csoonline.com/article/573495/doing-more-with-less-the-case-for-soc-consolidation-2.html&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Doing More with Less: The Case for SOC Consolidation&lt;/a&gt;.&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:50:57</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>4</itunes:episode><itunes:title>The art of security transformation</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Cybersecurity compensation 2025]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this conversation, <a href="https://www.linkedin.com/in/steven-martano-6263b124/" rel="noopener noreferrer nofollow">Steve Martano</a> discusses his journey from writing about baseball analytics to becoming a key player in cybersecurity executive search and strategy. He emphasizes the evolving role of CISOs, the importance of aligning with business objectives, and the need for strong leadership skills. The discussion also covers trends in CISO compensation, the mental health challenges faced by security leaders, and the significance of organizational culture in driving satisfaction and effectiveness in cybersecurity roles.<br /><br /><a href="https://www.iansresearch.com/resources/ians-ciso-compensation-benchmark-report" rel="noopener noreferrer nofollow">The Latest CISO Compensation Trends &amp; Benchmarks</a>.<br /><br /><b>Takeaways</b></p><ul><li>Understanding economics can enhance a CISO's effectiveness.</li><li>Compensation data must be contextualized for accurate benchmarking.</li><li>Low attrition doesn't always indicate job satisfaction.</li><li>CISOs face increasing pressures and scope creep in their roles.</li><li>The job market is expected to become more active in 2025.</li></ul><p><br /><b>Chapters</b><br /><br /></p><ul><li>00:00 The Journey from Baseball to Cybersecurity</li><li>05:53 The Intersection of Leadership and Cybersecurity</li><li>12:00 Mental Health and Satisfaction Among CISOs</li><li>17:49 Preparing for Future Attrition in Cybersecurity Roles</li><li>26:29 Engagement and Satisfaction Beyond Compensation</li><li>32:13 The Evolving Role of Cybersecurity Leadership</li><li>38:15 Mentorship and Professional Growth</li></ul><p><br /><br /><br /></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-16278348</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Fri, 20 Dec 2024 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/941be7c21efb2cd5ce38dd67fb2afa141ac625028ff0557ecc35be6d1427ba74/eyJlcGlzb2RlSWQiOiJiMzNhNTA2Yi1hYzAxLTQ4NGQtYTRlMi00ZTQwMmZkMTk4NzUiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvYjMzYTUwNmItYWMwMS00ODRkLWE0ZTItNGU0MDJmZDE5ODc1LzE2Mjc4MzQ4LWN5YmVyc2VjdXJpdHktY29tcGVuc2F0aW9uLTIwMjUubXAzIn0=.mp3" length="32904580" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this conversation, &lt;a href=&quot;https://www.linkedin.com/in/steven-martano-6263b124/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Steve Martano&lt;/a&gt; discusses his journey from writing about baseball analytics to becoming a key player in cybersecurity executive search and strategy. He emphasizes the evolving role of CISOs, the importance of aligning with business objectives, and the need for strong leadership skills. The discussion also covers trends in CISO compensation, the mental health challenges faced by security leaders, and the significance of organizational culture in driving satisfaction and effectiveness in cybersecurity roles.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://www.iansresearch.com/resources/ians-ciso-compensation-benchmark-report&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;The Latest CISO Compensation Trends &amp;amp; Benchmarks&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Understanding economics can enhance a CISO&apos;s effectiveness.&lt;/li&gt;&lt;li&gt;Compensation data must be contextualized for accurate benchmarking.&lt;/li&gt;&lt;li&gt;Low attrition doesn&apos;t always indicate job satisfaction.&lt;/li&gt;&lt;li&gt;CISOs face increasing pressures and scope creep in their roles.&lt;/li&gt;&lt;li&gt;The job market is expected to become more active in 2025.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;b&gt;Chapters&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;00:00 The Journey from Baseball to Cybersecurity&lt;/li&gt;&lt;li&gt;05:53 The Intersection of Leadership and Cybersecurity&lt;/li&gt;&lt;li&gt;12:00 Mental Health and Satisfaction Among CISOs&lt;/li&gt;&lt;li&gt;17:49 Preparing for Future Attrition in Cybersecurity Roles&lt;/li&gt;&lt;li&gt;26:29 Engagement and Satisfaction Beyond Compensation&lt;/li&gt;&lt;li&gt;32:13 The Evolving Role of Cybersecurity Leadership&lt;/li&gt;&lt;li&gt;38:15 Mentorship and Professional Growth&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:45:36</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>14</itunes:episode><itunes:title>Cybersecurity compensation 2025</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Bonus: AI and data security]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On this episode, Global Head of InfoSec and GRC Strategy at VMWare, Ashish Suri, joins the show to discuss data security and AI. Ashish has over 20 years of experience in business transformation, cybersecurity, data privacy, and enterprise risk management. He has served in numerous roles, including Head for Data Risk, Privacy, and Cybersecurity at Apple, Head of Technology Process and Controls at PayPal, and Senior Director of Finance Internal Controls at Visa.</p><p>Today, Ashish talks about the distinction between data secrecy and data security, data security in the Cloud, and the business benefits of investing in data security. How does AI fit into security? Hear about cost-effective risk mitigation strategies and the evolving DSPM space, and get Ashish’s formula for personal growth.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [01:33] Ashish’s role at Apple.</p><p>·       [04:27] Data secrecy vs data security.</p><p>·       [07:20] Data security in the Cloud.</p><p>·       [09:30] Ashish’s approach to data security.</p><p>·       [13:53] What does a business get out of data security?</p><p>·       [17:34] The CIA Triad.</p><p>·       [21:39] AI and Cloud security.</p><p>·       [24:24] AI in cybersecurity products.</p><p>·       [27:59] Cost-effective risk mitigation strategies.</p><p>·       [30:49] Wading through the DSPM space.</p><p>·       [35:15] Ashish’s growth formula.</p><p>·       [37:06] Being humble.</p><p>·       [38:00] Ashish’s parting words.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “The more we are out there in the Cloud, the larger our footprint becomes, and the risk continues multiplying in different directions.”</p><p>·       “Speed, accuracy, and automation will also get complimented with people, process, and technology.”</p><p>·       “Keep learning and keep listening.”</p><p> </p><p><b>Relevant Links</b></p><p>Website:          <a href="https://www.bedrock.security/" rel="noopener noreferrer nofollow">Bedrock Security</a></p>]]></description><guid isPermaLink="false">Buzzsprout-14979515</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 06 May 2024 23:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/3e2c988b556bd56aef3fbf34f108c2d8841e6018005a56f6624b5e98ec6c5f40/eyJlcGlzb2RlSWQiOiJjOWNmZjRjYy0wNzkzLTQxMDEtOTRmZi0yOWY3NjI2NWI4NWYiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvYzljZmY0Y2MtMDc5My00MTAxLTk0ZmYtMjlmNzYyNjViODVmLzE0OTc5NTE1LWJvbnVzLWFpLWFuZC1kYXRhLXNlY3VyaXR5Lm1wMyJ9.mp3" length="28141718" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, Global Head of InfoSec and GRC Strategy at VMWare, Ashish Suri, joins the show to discuss data security and AI. Ashish has over 20 years of experience in business transformation, cybersecurity, data privacy, and enterprise risk management. He has served in numerous roles, including Head for Data Risk, Privacy, and Cybersecurity at Apple, Head of Technology Process and Controls at PayPal, and Senior Director of Finance Internal Controls at Visa.&lt;/p&gt;&lt;p&gt;Today, Ashish talks about the distinction between data secrecy and data security, data security in the Cloud, and the business benefits of investing in data security. How does AI fit into security? Hear about cost-effective risk mitigation strategies and the evolving DSPM space, and get Ashish’s formula for personal growth.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:33] Ashish’s role at Apple.&lt;/p&gt;&lt;p&gt;·       [04:27] Data secrecy vs data security.&lt;/p&gt;&lt;p&gt;·       [07:20] Data security in the Cloud.&lt;/p&gt;&lt;p&gt;·       [09:30] Ashish’s approach to data security.&lt;/p&gt;&lt;p&gt;·       [13:53] What does a business get out of data security?&lt;/p&gt;&lt;p&gt;·       [17:34] The CIA Triad.&lt;/p&gt;&lt;p&gt;·       [21:39] AI and Cloud security.&lt;/p&gt;&lt;p&gt;·       [24:24] AI in cybersecurity products.&lt;/p&gt;&lt;p&gt;·       [27:59] Cost-effective risk mitigation strategies.&lt;/p&gt;&lt;p&gt;·       [30:49] Wading through the DSPM space.&lt;/p&gt;&lt;p&gt;·       [35:15] Ashish’s growth formula.&lt;/p&gt;&lt;p&gt;·       [37:06] Being humble.&lt;/p&gt;&lt;p&gt;·       [38:00] Ashish’s parting words.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “The more we are out there in the Cloud, the larger our footprint becomes, and the risk continues multiplying in different directions.”&lt;/p&gt;&lt;p&gt;·       “Speed, accuracy, and automation will also get complimented with people, process, and technology.”&lt;/p&gt;&lt;p&gt;·       “Keep learning and keep listening.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website:          &lt;a href=&quot;https://www.bedrock.security/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Bedrock Security&lt;/a&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:38:59</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>5</itunes:episode><itunes:title>Bonus: AI and data security</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The Software Factory]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>S2E8 - The Software Factory with Chris Hughes</b></p><p><b>Episode Summary</b></p><p>On this episode, CISO and Co-Founder of Aquia, Chris Hughes, joins Matt to talk about building security in the cloud using automation and compliance. Chris’s career spans over 20 years in the IT/Cybersecurity industry, as well as in active service in the US Military.</p><p>Chris talks about licensing and certifications, Cloud innovation, and achieving continuous ATO. How are software factories created and operationalized? Hear about the people side of the business, effectively building a community, and get Chris’s formula for personal growth.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [01:19] Chris’s 28 licenses and certifications.</p><p>·       [02:44] The value of certifications.</p><p>·       [05:08] Chris’s Air Force experience.</p><p>·       [06:25] About Aquia.</p><p>·       [07:46] DoD vs the federal civilian space.</p><p>·       [09:01] BatCave.</p><p>·       [10:04] Federal DoD compliance.</p><p>·       [12:55] How do agencies achieve Continuous ATO in the cloud?</p><p>·       [16:04] Software Factories.</p><p>·       [21:07] How it’s gone wrong.</p><p>·       [23:12] What it looks like to stand up a Software Factory.</p><p>·       [25:24] What works on the people side?</p><p>·       [28:42] What is an effective way to build a community?</p><p>·       [32:30] Why Chris reads physical books.</p><p>·       [35:07] Chis’s formula for personal growth.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “The journey is going to be unique to the organization. It’s not going to be the same for everyone.”</p><p>·       “Just be real.”</p><p> </p><p><b>Relevant Links</b></p><p>Aquia:              <a href="https://www.aquia.us/" rel="noopener noreferrer nofollow">https://www.aquia.us</a></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/chris-h-97680442" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/chris-h-97680442</a></p><p> <a href="https://github.com/chughes757/Federal-DoD-Software-Factory-Compliance" rel="noopener noreferrer nofollow">GutHub: Federal DoD Software Factory Compliance</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-11127478</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 22 Aug 2022 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/f48bfb056117e313cf00aec01c475a6fd22a22b908f187a20cae0531317da91b/eyJlcGlzb2RlSWQiOiJlNmZkN2YxYi1iZDgwLTRiMmUtOWJkNC0wZThhNTc3MTE2ZjciLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZTZmZDdmMWItYmQ4MC00YjJlLTliZDQtMGU4YTU3NzExNmY3LzExMTI3NDc4LXRoZS1zb2Z0d2FyZS1mYWN0b3J5Lm1wMyJ9.mp3" length="27243777" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;S2E8 - The Software Factory with Chris Hughes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, CISO and Co-Founder of Aquia, Chris Hughes, joins Matt to talk about building security in the cloud using automation and compliance. Chris’s career spans over 20 years in the IT/Cybersecurity industry, as well as in active service in the US Military.&lt;/p&gt;&lt;p&gt;Chris talks about licensing and certifications, Cloud innovation, and achieving continuous ATO. How are software factories created and operationalized? Hear about the people side of the business, effectively building a community, and get Chris’s formula for personal growth.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:19] Chris’s 28 licenses and certifications.&lt;/p&gt;&lt;p&gt;·       [02:44] The value of certifications.&lt;/p&gt;&lt;p&gt;·       [05:08] Chris’s Air Force experience.&lt;/p&gt;&lt;p&gt;·       [06:25] About Aquia.&lt;/p&gt;&lt;p&gt;·       [07:46] DoD vs the federal civilian space.&lt;/p&gt;&lt;p&gt;·       [09:01] BatCave.&lt;/p&gt;&lt;p&gt;·       [10:04] Federal DoD compliance.&lt;/p&gt;&lt;p&gt;·       [12:55] How do agencies achieve Continuous ATO in the cloud?&lt;/p&gt;&lt;p&gt;·       [16:04] Software Factories.&lt;/p&gt;&lt;p&gt;·       [21:07] How it’s gone wrong.&lt;/p&gt;&lt;p&gt;·       [23:12] What it looks like to stand up a Software Factory.&lt;/p&gt;&lt;p&gt;·       [25:24] What works on the people side?&lt;/p&gt;&lt;p&gt;·       [28:42] What is an effective way to build a community?&lt;/p&gt;&lt;p&gt;·       [32:30] Why Chris reads physical books.&lt;/p&gt;&lt;p&gt;·       [35:07] Chis’s formula for personal growth.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “The journey is going to be unique to the organization. It’s not going to be the same for everyone.”&lt;/p&gt;&lt;p&gt;·       “Just be real.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Aquia:              &lt;a href=&quot;https://www.aquia.us/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.aquia.us&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/chris-h-97680442&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/chris-h-97680442&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;a href=&quot;https://github.com/chughes757/Federal-DoD-Software-Factory-Compliance&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;GutHub: Federal DoD Software Factory Compliance&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:37:44</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>9</itunes:episode><itunes:title>The Software Factory</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[What Is Threat Intelligence?]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this episode (originally recorded in November of 2021) we speak with Palo Alto Networks, VP of Threat Intel, Ryan Olson. Ryan helps define what threat intelligence actually is and how to get started building a program. He aptly reminds us that producing threat intel for the sake of threat intel is a waste of time. More importantly you first have to ask yourself, “Who’s going to be using this information?”.</p><p><b>Tweetables</b></p><p>“Producing threat intel for the sake of threat intel is a waste of time. What you should be doing is thinking ‘Who’s going to take the information that I have produced and use that to make a better decision?’ Because that's the goal of threat intelligence, to help a system, or a person, or a team, or a company make better decisions that will help secure them better.” — Ryan Olson [0:04:24]</p><p>“If I could give people one recommendation, if you can get access to your SSL traffic so that you can decrypt it and you can inspect it, you will have a much better chance at detecting bad stuff in your network than you would without it.” — Ryan Olson [0:29:58]</p><p><br /></p><p>Links Mentioned in Today’s Episode:</p><p><a href="https://www.linkedin.com/in/ryan-olson-6777269/" rel="noopener noreferrer nofollow">Ryan Olson on LinkedIn</a></p><p><a href="https://unit42.paloaltonetworks.com/" rel="noopener noreferrer nofollow">Unit 42</a></p><p><a href="https://twitter.com/Unit42_Intel" rel="noopener noreferrer nofollow">Unit 42 on Twitter</a></p><p><a href="https://jobs.paloaltonetworks.com/en/jobs/" rel="noopener noreferrer nofollow">Unit 42 Palo Alto Networks Careers</a></p><p><br /><br /></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-10458245</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 18 Apr 2022 14:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/d91fbf388a0fe24349018b31a410fafbda9048578ea4653bea416b4e139fe869/eyJlcGlzb2RlSWQiOiI2ZmZiYmNhOC1lODU4LTQ5MDMtODY0YS1lYjU1ODE4NDU3MmYiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNmZmYmJjYTgtZTg1OC00OTAzLTg2NGEtZWI1NTgxODQ1NzJmLzEwNDU4MjQ1LXdoYXQtaXMtdGhyZWF0LWludGVsbGlnZW5jZS5tcDMifQ==.mp3" length="27056840" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this episode (originally recorded in November of 2021) we speak with Palo Alto Networks, VP of Threat Intel, Ryan Olson. Ryan helps define what threat intelligence actually is and how to get started building a program. He aptly reminds us that producing threat intel for the sake of threat intel is a waste of time. More importantly you first have to ask yourself, “Who’s going to be using this information?”.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Tweetables&lt;/b&gt;&lt;/p&gt;&lt;p&gt;“Producing threat intel for the sake of threat intel is a waste of time. What you should be doing is thinking ‘Who’s going to take the information that I have produced and use that to make a better decision?’ Because that&apos;s the goal of threat intelligence, to help a system, or a person, or a team, or a company make better decisions that will help secure them better.” — Ryan Olson [0:04:24]&lt;/p&gt;&lt;p&gt;“If I could give people one recommendation, if you can get access to your SSL traffic so that you can decrypt it and you can inspect it, you will have a much better chance at detecting bad stuff in your network than you would without it.” — Ryan Olson [0:29:58]&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Links Mentioned in Today’s Episode:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/ryan-olson-6777269/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Ryan Olson on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://unit42.paloaltonetworks.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Unit 42&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://twitter.com/Unit42_Intel&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Unit 42 on Twitter&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://jobs.paloaltonetworks.com/en/jobs/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Unit 42 Palo Alto Networks Careers&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:37:23</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>4</itunes:episode><itunes:title>What Is Threat Intelligence?</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Innovating at the Speed of Relevance]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>When thinking of innovation, the first things that usually come to mind are tech startups. It’s not often you think of examples from the US Government or, more specifically, the Department of Defense. Our guest today has unprecedented insight, not only into what it takes to build a startup but how to create a startup-like culture in massive organizations like the US Department of Defense. <br /><br />Nic Chaillan, has had tremendous success as an entrepreneur and, in 2016, decided to pursue public service when he took a job with the US government. Over the past 20 years, Nic has built hundreds of products that were sold to dozens of Fortune 500 companies. After taking a break from entrepreneurship, Nicolas served as the Chief Software Officer for the US Air Force and Space Force and introduced game-changing innovations to the government’s software operations. <br /><br />In our conversation with Nic, we discuss agile practices and how he used DevSecOps to elevate the Department of Defense’s software security. We unpack how his experience as an entrepreneur motivated him and why it was a commonsense decision to apply those lessons when he started in government.<br /><br />Tweetables:<br />“When you look at the desired outcomes, you realize pretty quickly that DevSecOps is the main enabler to get all of these things done fast while not creating more risk. In fact, I would argue, it reduces both cyber and operational testing risk as well.” — <a href="https://twitter.com/NicolasChaillan" rel="noopener noreferrer nofollow">@NicolasChaillan</a> [0:06:30]<br /><br />“That’s also something to think about: what kind of access control do you want to have in place when it comes to these kinds of tools and how do you mitigate the blast radius?” — <a href="https://twitter.com/NicolasChaillan" rel="noopener noreferrer nofollow">@NicolasChaillan</a> [0:16:39]<br /><br />“I am also a big believer that education and continuous learning has to drastically change and improve.” — <a href="https://twitter.com/NicolasChaillan" rel="noopener noreferrer nofollow">@NicolasChaillan</a> [0:33:59]<br /><br /><a href="https://www.linkedin.com/in/nicolaschaillan/" rel="noopener noreferrer nofollow">Nicolas M. Chaillan on LinkedIn</a></p><p><br /></p>]]></description><guid isPermaLink="false">Buzzsprout-9388196</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 18 Oct 2021 15:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/e9dcf0d57ba5b2a7a6d87c2a8885c77229ec9c8cd06f765079ece3415590e448/eyJlcGlzb2RlSWQiOiJiMmNiMDc1ZS1kZmFjLTQwYjktODMwMi0wMGJhMGM5NDRlM2EiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvYjJjYjA3NWUtZGZhYy00MGI5LTgzMDItMDBiYTBjOTQ0ZTNhLzkzODgxOTYtaW5ub3ZhdGluZy1hdC10aGUtc3BlZWQtb2YtcmVsZXZhbmNlLm1wMyJ9.mp3" length="25341207" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;When thinking of innovation, the first things that usually come to mind are tech startups. It’s not often you think of examples from the US Government or, more specifically, the Department of Defense. Our guest today has unprecedented insight, not only into what it takes to build a startup but how to create a startup-like culture in massive organizations like the US Department of Defense. &lt;br /&gt;&lt;br /&gt;Nic Chaillan, has had tremendous success as an entrepreneur and, in 2016, decided to pursue public service when he took a job with the US government. Over the past 20 years, Nic has built hundreds of products that were sold to dozens of Fortune 500 companies. After taking a break from entrepreneurship, Nicolas served as the Chief Software Officer for the US Air Force and Space Force and introduced game-changing innovations to the government’s software operations. &lt;br /&gt;&lt;br /&gt;In our conversation with Nic, we discuss agile practices and how he used DevSecOps to elevate the Department of Defense’s software security. We unpack how his experience as an entrepreneur motivated him and why it was a commonsense decision to apply those lessons when he started in government.&lt;br /&gt;&lt;br /&gt;Tweetables:&lt;br /&gt;“When you look at the desired outcomes, you realize pretty quickly that DevSecOps is the main enabler to get all of these things done fast while not creating more risk. In fact, I would argue, it reduces both cyber and operational testing risk as well.” — &lt;a href=&quot;https://twitter.com/NicolasChaillan&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@NicolasChaillan&lt;/a&gt; [0:06:30]&lt;br /&gt;&lt;br /&gt;“That’s also something to think about: what kind of access control do you want to have in place when it comes to these kinds of tools and how do you mitigate the blast radius?” — &lt;a href=&quot;https://twitter.com/NicolasChaillan&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@NicolasChaillan&lt;/a&gt; [0:16:39]&lt;br /&gt;&lt;br /&gt;“I am also a big believer that education and continuous learning has to drastically change and improve.” — &lt;a href=&quot;https://twitter.com/NicolasChaillan&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@NicolasChaillan&lt;/a&gt; [0:33:59]&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://www.linkedin.com/in/nicolaschaillan/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Nicolas M. Chaillan on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:35:04</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>8</itunes:episode><itunes:title>Innovating at the Speed of Relevance</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Cloud Native Pharma]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>The pharmaceutical industry has a reputation for being cautious when it comes to adopting new technologies. However, in this episode, you’ll hear from the CISO at Takeda Pharmaceuticals, Mike Towers, that for Takeda cloud has been a game-changer (albeit not without some challenges). As we like to do, we’ll start by diving into Mike’s background and then pivot to understand where Takeda is today in their cloud journey and where they are going over the next 24 months. </p><p>Get your pen ready because Mike is going to drop a massive amount of knowledge in a short period of time.</p><p><b>Tweetables:</b></p><p>“One of the things that's the toughest in the biopharmaceutical industry is focus because it's really easy to get tempted to try to solve a lot of different problems.” — <a href="https://twitter.com/MichaelATowers" rel="noopener noreferrer nofollow">@MichaelATowers</a> [0:02:47]</p><p>“We’ll be exclusively cloud, within probably, I would<b> say, 15 months from now.” — </b><a href="https://twitter.com/MichaelATowers" rel="noopener noreferrer nofollow"><b>@MichaelATowers</b></a><b> [0:17:51]</b></p><p><br /></p><p><b>Links Mentioned in Today’s Episode:</b></p><p><a href="https://prismacloud.io/" rel="noopener noreferrer nofollow"><b>Prisma Cloud</b></a></p><p><a href="https://twitter.com/MichaelATowers" rel="noopener noreferrer nofollow"><b>Mike Towers on Twitter</b></a></p><p><a href="https://www.linkedin.com/in/michaelatowersjr" rel="noopener noreferrer nofollow"><b>Mike Towers on LinkedIn</b></a></p><p><a href="https://www.takeda.com/" rel="noopener noreferrer nofollow"><b>Takeda</b></a></p><p><a href="https://www.paloaltonetworks.com/blog/2021/01/navigating-the-digital-age/" rel="noopener noreferrer nofollow"><b><em>Navigating the Digital Age</em></b></a></p><p><br /></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-9901609</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 17 Jan 2022 19:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/1d8f54467fc1791882af1eeed6a8002d6d6d93175b77b516e703e4bfe51a4ac7/eyJlcGlzb2RlSWQiOiIwZTcyMTA2MC05Y2ZmLTRjNDMtOGRhYy1hZjIxZjVkMDg0YTkiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMGU3MjEwNjAtOWNmZi00YzQzLThkYWMtYWYyMWY1ZDA4NGE5Lzk5MDE2MDktY2xvdWQtbmF0aXZlLXBoYXJtYS5tcDMifQ==.mp3" length="27683148" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The pharmaceutical industry has a reputation for being cautious when it comes to adopting new technologies. However, in this episode, you’ll hear from the CISO at Takeda Pharmaceuticals, Mike Towers, that for Takeda cloud has been a game-changer (albeit not without some challenges). As we like to do, we’ll start by diving into Mike’s background and then pivot to understand where Takeda is today in their cloud journey and where they are going over the next 24 months. &lt;/p&gt;&lt;p&gt;Get your pen ready because Mike is going to drop a massive amount of knowledge in a short period of time.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Tweetables:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;“One of the things that&apos;s the toughest in the biopharmaceutical industry is focus because it&apos;s really easy to get tempted to try to solve a lot of different problems.” — &lt;a href=&quot;https://twitter.com/MichaelATowers&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@MichaelATowers&lt;/a&gt; [0:02:47]&lt;/p&gt;&lt;p&gt;“We’ll be exclusively cloud, within probably, I would&lt;b&gt; say, 15 months from now.” — &lt;/b&gt;&lt;a href=&quot;https://twitter.com/MichaelATowers&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;@MichaelATowers&lt;/b&gt;&lt;/a&gt;&lt;b&gt; [0:17:51]&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Links Mentioned in Today’s Episode:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://prismacloud.io/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Prisma Cloud&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://twitter.com/MichaelATowers&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Mike Towers on Twitter&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/michaelatowersjr&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Mike Towers on LinkedIn&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.takeda.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Takeda&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/blog/2021/01/navigating-the-digital-age/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;&lt;em&gt;Navigating the Digital Age&lt;/em&gt;&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:38:16</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>1</itunes:episode><itunes:title>Cloud Native Pharma</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Unraveling unmanageable apps]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>On this episode, co-founder and CEO of Cerby, Belsasar Lepe, joins Matt to talk about unmanageable applications (apps that don't support critical security standards like SSO and SCIM). Belsasar was previously the Head of Product at Impira, where he led the company's product life cycle, helping drive a 4x increase in revenue. Before his role at Impira, Bel was co-founder and CTO at Ooyala, where he led a global product, design, and engineering team of 300+ Ooyalans spanning five countries and seven offices. Ooyala achieved two successful exits totaling over $440M.</p><p>Belsasar talks about unmanageable applications, Shadow IT, and why password managers should be considered legacy tech. </p><p> </p><p><b>Timestamp Segments</b></p><p>·       [02:14] A bit about Belsasar.</p><p>·       [04:57] Unmanageable Applications.</p><p>·       [07:07] Shadow IT.</p><p>·       [11:04] Quantifying the risk.</p><p>·       [14:50] How to identify Unmanageable Apps.</p><p>·       [17:46] Using different tools.</p><p>·       [21:03] Where do password managers fall in?</p><p>·       [22:53] Is passwordless the future?</p><p>·       [25:29] How Cerby solves the problem.</p><p>·       [27:11] A Cerby success story.</p><p>·       [30:48] The future of the market.</p><p>·       [32:35] Migration to Cloud.</p><p>·       [35:03] How Belsasar stays fresh.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “The first task is understanding the size of the problem.”</p><p>·       “The initial point of entry is often an unmanageable application.”</p><p>·       “More businesses will rely on end users for their security.”<br /><br /><a href="https://hubs.ly/Q01CPJN40" rel="noopener noreferrer nofollow">Cerby's website</a><br /><br /></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-12273369</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Tue, 21 Feb 2023 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/5b852e706a288bf962bbda4b5e36791b703b6a6d388d2c3b64cbd331f8b51444/eyJlcGlzb2RlSWQiOiI0YzMxYzM5OC01Y2E0LTQ1MjgtOWM0OC1jMDRkMDMyYzM2NmMiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNGMzMWMzOTgtNWNhNC00NTI4LTljNDgtYzA0ZDAzMmMzNjZjLzEyMjczMzY5LXVucmF2ZWxpbmctdW5tYW5hZ2VhYmxlLWFwcHMubXAzIn0=.mp3" length="27903646" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;On this episode, co-founder and CEO of Cerby, Belsasar Lepe, joins Matt to talk about unmanageable applications (apps that don&apos;t support critical security standards like SSO and SCIM). Belsasar was previously the Head of Product at Impira, where he led the company&apos;s product life cycle, helping drive a 4x increase in revenue. Before his role at Impira, Bel was co-founder and CTO at Ooyala, where he led a global product, design, and engineering team of 300+ Ooyalans spanning five countries and seven offices. Ooyala achieved two successful exits totaling over $440M.&lt;/p&gt;&lt;p&gt;Belsasar talks about unmanageable applications, Shadow IT, and why password managers should be considered legacy tech. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:14] A bit about Belsasar.&lt;/p&gt;&lt;p&gt;·       [04:57] Unmanageable Applications.&lt;/p&gt;&lt;p&gt;·       [07:07] Shadow IT.&lt;/p&gt;&lt;p&gt;·       [11:04] Quantifying the risk.&lt;/p&gt;&lt;p&gt;·       [14:50] How to identify Unmanageable Apps.&lt;/p&gt;&lt;p&gt;·       [17:46] Using different tools.&lt;/p&gt;&lt;p&gt;·       [21:03] Where do password managers fall in?&lt;/p&gt;&lt;p&gt;·       [22:53] Is passwordless the future?&lt;/p&gt;&lt;p&gt;·       [25:29] How Cerby solves the problem.&lt;/p&gt;&lt;p&gt;·       [27:11] A Cerby success story.&lt;/p&gt;&lt;p&gt;·       [30:48] The future of the market.&lt;/p&gt;&lt;p&gt;·       [32:35] Migration to Cloud.&lt;/p&gt;&lt;p&gt;·       [35:03] How Belsasar stays fresh.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “The first task is understanding the size of the problem.”&lt;/p&gt;&lt;p&gt;·       “The initial point of entry is often an unmanageable application.”&lt;/p&gt;&lt;p&gt;·       “More businesses will rely on end users for their security.”&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://hubs.ly/Q01CPJN40&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Cerby&apos;s website&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:38:39</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>2</itunes:episode><itunes:title>Unraveling unmanageable apps</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The human side of cyber]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this conversation, <a href="https://www.linkedin.com/in/tammyklotz/" rel="noopener noreferrer nofollow">Tammy Klotz</a> discusses her journey as a leader and author, focusing on her book 'Leading with Empathy and Grace.' She shares insights on the importance of empathy, vulnerability, and authenticity in leadership and the challenges and rewards of writing a book. The discussion highlights the significance of acknowledging personal lives in the workplace and the foundational role of trust in professional relationships. If you are an aspiring leader in Cyber, this episode is for you. Tammy shares her secrets to successful leadership.</p>]]></description><guid isPermaLink="false">Buzzsprout-17008862</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Tue, 22 Apr 2025 22:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/919b4c295915f3c6cd3a75c44fcf86351c9bfc17889d4cc1e07f20b36054f827/eyJlcGlzb2RlSWQiOiI5YmVlODdmYi1jZDMxLTQ0NDItYmI0Ny1hMGM5M2NiZDc1YjQiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvOWJlZTg3ZmItY2QzMS00NDQyLWJiNDctYTBjOTNjYmQ3NWI0LzE3MDA4ODYyLXRoZS1odW1hbi1zaWRlLW9mLWN5YmVyLm1wMyJ9.mp3" length="33313893" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this conversation, &lt;a href=&quot;https://www.linkedin.com/in/tammyklotz/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Tammy Klotz&lt;/a&gt; discusses her journey as a leader and author, focusing on her book &apos;Leading with Empathy and Grace.&apos; She shares insights on the importance of empathy, vulnerability, and authenticity in leadership and the challenges and rewards of writing a book. The discussion highlights the significance of acknowledging personal lives in the workplace and the foundational role of trust in professional relationships. If you are an aspiring leader in Cyber, this episode is for you. Tammy shares her secrets to successful leadership.&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:46:10</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>5</itunes:season><itunes:episode>4</itunes:episode><itunes:title>The human side of cyber</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Rethinking security awareness]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this conversation, <a href="https://www.linkedin.com/in/lancespitzner/" rel="noopener noreferrer nofollow">Lance Spitzner</a> shares his unique journey from a military tank officer to a pioneer in cybersecurity, detailing the evolution of his career and the inception of the <a href="https://www.honeynet.org/" rel="noopener noreferrer nofollow">Honeynet Project</a>. He emphasizes the importance of understanding the human element in security, advocating for a shift from mere security awareness to fostering a robust security culture within organizations. Spitzner discusses practical steps for security teams to enhance their approach, including leveraging AI to improve communication and engagement. He concludes by reflecting on the impact of his work and the growing recognition of the human side of cybersecurity.</p><p><b>Takeaways</b></p><ul><li>The Honeynet Project was born from a need for cyber threat intelligence.</li><li>Security culture is broader than security awareness; it encompasses attitudes and beliefs.</li><li>Changing the environment is key to changing organizational culture.</li><li>AI can be leveraged to enhance communication and simplify security policies.</li><li>Positive interactions with security teams build a stronger security culture.</li></ul><p><b>Chapters</b><br />00:00 From Military to Cybersecurity Pioneer<br />03:04 The Birth of the Honeynet Project<br />05:59 Understanding the Human Element in Security<br />09:13 Security Culture vs. Security Awareness<br />11:51 Changing Organizational Culture for Security<br />14:46 Practical Steps for Security Teams<br />17:55 Leveraging AI in Security Culture<br />21:11 Measuring Success in Cybersecurity Training<br /><br /><br /><br /></p>]]></description><guid isPermaLink="false">Buzzsprout-16674686</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sun, 23 Feb 2025 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/b1004029af34d6183334da2d02bb7e5652114dc7297cdeae8fbed4e4fafb0d98/eyJlcGlzb2RlSWQiOiI5YTVjYTJjMy1hNjFhLTRjYTgtYTcxZi1jMmMwMzEzZjg1NTciLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvOWE1Y2EyYzMtYTYxYS00Y2E4LWE3MWYtYzJjMDMxM2Y4NTU3LzE2Njc0Njg2LXJldGhpbmtpbmctc2VjdXJpdHktYXdhcmVuZXNzLm1wMyJ9.mp3" length="33010194" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this conversation, &lt;a href=&quot;https://www.linkedin.com/in/lancespitzner/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Lance Spitzner&lt;/a&gt; shares his unique journey from a military tank officer to a pioneer in cybersecurity, detailing the evolution of his career and the inception of the &lt;a href=&quot;https://www.honeynet.org/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Honeynet Project&lt;/a&gt;. He emphasizes the importance of understanding the human element in security, advocating for a shift from mere security awareness to fostering a robust security culture within organizations. Spitzner discusses practical steps for security teams to enhance their approach, including leveraging AI to improve communication and engagement. He concludes by reflecting on the impact of his work and the growing recognition of the human side of cybersecurity.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The Honeynet Project was born from a need for cyber threat intelligence.&lt;/li&gt;&lt;li&gt;Security culture is broader than security awareness; it encompasses attitudes and beliefs.&lt;/li&gt;&lt;li&gt;Changing the environment is key to changing organizational culture.&lt;/li&gt;&lt;li&gt;AI can be leveraged to enhance communication and simplify security policies.&lt;/li&gt;&lt;li&gt;Positive interactions with security teams build a stronger security culture.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Chapters&lt;/b&gt;&lt;br /&gt;00:00 From Military to Cybersecurity Pioneer&lt;br /&gt;03:04 The Birth of the Honeynet Project&lt;br /&gt;05:59 Understanding the Human Element in Security&lt;br /&gt;09:13 Security Culture vs. Security Awareness&lt;br /&gt;11:51 Changing Organizational Culture for Security&lt;br /&gt;14:46 Practical Steps for Security Teams&lt;br /&gt;17:55 Leveraging AI in Security Culture&lt;br /&gt;21:11 Measuring Success in Cybersecurity Training&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:45:45</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>5</itunes:season><itunes:episode>2</itunes:episode><itunes:title>Rethinking security awareness</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Dr. Zero Trust on zero trust]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this conversation, <a href="https://www.linkedin.com/in/dr-chase-cunningham/" rel="noopener noreferrer nofollow">Dr. Chase Cunningham</a>, aka Dr. Zero Trust, shares his unique journey into the cybersecurity field, emphasizing the importance of purpose and self-care in a high-stress industry. He discusses the challenges of implementing zero trust strategies in organizations, the significance of understanding offensive tactics to enhance defensive measures, and the need for systemic change in national cybersecurity. Dr. Zero Trust also provides valuable advice for aspiring cybersecurity professionals, highlighting the supportive community and the importance of continuous learning.<br /><br /><b>Takeaways</b></p><ul><li>Zero Trust is a strategy, not a product.</li><li>Self-care is critical in high-stress environments.</li><li>Understanding offensive tactics is essential for defense.</li><li>Start small when implementing Zero Trust.</li></ul>]]></description><guid isPermaLink="false">Buzzsprout-16461165</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 20 Jan 2025 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/28bb06d53ad5c25f6ea4c67b5ff846b3ed50214a05c0a29e0d45f59524888084/eyJlcGlzb2RlSWQiOiJlNDZkYjYyZS02YzM2LTQ4NGQtOThkMi1jZTM2ZTc3ZGEwYjkiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZTQ2ZGI2MmUtNmMzNi00ODRkLTk4ZDItY2UzNmU3N2RhMGI5LzE2NDYxMTY1LWRyLXplcm8tdHJ1c3Qtb24temVyby10cnVzdC5tcDMifQ==.mp3" length="26112925" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this conversation, &lt;a href=&quot;https://www.linkedin.com/in/dr-chase-cunningham/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Dr. Chase Cunningham&lt;/a&gt;, aka Dr. Zero Trust, shares his unique journey into the cybersecurity field, emphasizing the importance of purpose and self-care in a high-stress industry. He discusses the challenges of implementing zero trust strategies in organizations, the significance of understanding offensive tactics to enhance defensive measures, and the need for systemic change in national cybersecurity. Dr. Zero Trust also provides valuable advice for aspiring cybersecurity professionals, highlighting the supportive community and the importance of continuous learning.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Zero Trust is a strategy, not a product.&lt;/li&gt;&lt;li&gt;Self-care is critical in high-stress environments.&lt;/li&gt;&lt;li&gt;Understanding offensive tactics is essential for defense.&lt;/li&gt;&lt;li&gt;Start small when implementing Zero Trust.&lt;/li&gt;&lt;/ul&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:36:10</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>5</itunes:season><itunes:episode>1</itunes:episode><itunes:title>Dr. Zero Trust on zero trust</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Securing Democracy: DNC's Cyber Cop]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>On today’s episode, CSO at the Democratic National Committee, Steve Tran, joins Matt to talk about magic, AI, and cybersecurity. As the CSO for the DNC, Steve leads their IT, physical, and cybersecurity strategy. When not defending against dedicated adversaries, Steve can be found doing “off the cuffs” performances at the World-Famous Magic Castle in Hollywood.</p><p>Today, Steve talks about how he incorporates magic into cybersecurity, his transition from law enforcement to cybersecurity, and how to mitigate risk in a fast-moving environment. What are the potential risks of using generative AI? Hear about our susceptibility to mental malware, thinking strategically versus tactically to solve problems, and how Steve manages to stay sharp day-to-day.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [01:21] Steve, the magician.</p><p>·       [05:14] Parallels between magic and cybersecurity.</p><p>·       [07:21] Transitioning from law enforcement to cybersecurity.</p><p>·       [16:26] Using magic to manage mental health.</p><p>·       [21:25] The DNC.</p><p>·       [22:19] Decentralization and security.</p><p>·       [24:59] Getting buy-in.</p><p>·       [27:42] Thinking strategically.</p><p>·       [29:09] Mitigating risk in a fast-moving environment.</p><p>·       [36:00] AI and cyberattacks.</p><p>·       [43:25] Potential issues with AI.</p><p>·       [50:46] How Steve stays sharp.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “Mental health can really affect cybersecurity professionals.”</p><p>·       “Business isn’t meant to be just transactional.”</p><p>·       “One of the biggest barriers to why people don’t buy into it at first is because they don’t understand it.”</p><p>·       “Security issues don’t care if you don’t have a budget or don’t have a team.”</p><p>·       “Once you get people to feel a certain way, you can’t undo that.”</p><p>·       “There’s no better way to learn than to have to teach material yourself.”</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-13240454</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Fri, 21 Jul 2023 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/4e5b71f5fab19d699089c5536ba1bcc9e814689d91f718dbfe9b4a3b6f35bd3e/eyJlcGlzb2RlSWQiOiI1ZjVjMGZlOC05YzYzLTQyYjUtOWM5ZC01OTczNmIwMmIyZDMiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNWY1YzBmZTgtOWM2My00MmI1LTljOWQtNTk3MzZiMDJiMmQzLzEzMjQwNDU0LXNlY3VyaW5nLWRlbW9jcmFjeS1kbmMtcy1jeWJlci1jb3AubXAzIn0=.mp3" length="38481371" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;On today’s episode, CSO at the Democratic National Committee, Steve Tran, joins Matt to talk about magic, AI, and cybersecurity. As the CSO for the DNC, Steve leads their IT, physical, and cybersecurity strategy. When not defending against dedicated adversaries, Steve can be found doing “off the cuffs” performances at the World-Famous Magic Castle in Hollywood.&lt;/p&gt;&lt;p&gt;Today, Steve talks about how he incorporates magic into cybersecurity, his transition from law enforcement to cybersecurity, and how to mitigate risk in a fast-moving environment. What are the potential risks of using generative AI? Hear about our susceptibility to mental malware, thinking strategically versus tactically to solve problems, and how Steve manages to stay sharp day-to-day.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:21] Steve, the magician.&lt;/p&gt;&lt;p&gt;·       [05:14] Parallels between magic and cybersecurity.&lt;/p&gt;&lt;p&gt;·       [07:21] Transitioning from law enforcement to cybersecurity.&lt;/p&gt;&lt;p&gt;·       [16:26] Using magic to manage mental health.&lt;/p&gt;&lt;p&gt;·       [21:25] The DNC.&lt;/p&gt;&lt;p&gt;·       [22:19] Decentralization and security.&lt;/p&gt;&lt;p&gt;·       [24:59] Getting buy-in.&lt;/p&gt;&lt;p&gt;·       [27:42] Thinking strategically.&lt;/p&gt;&lt;p&gt;·       [29:09] Mitigating risk in a fast-moving environment.&lt;/p&gt;&lt;p&gt;·       [36:00] AI and cyberattacks.&lt;/p&gt;&lt;p&gt;·       [43:25] Potential issues with AI.&lt;/p&gt;&lt;p&gt;·       [50:46] How Steve stays sharp.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “Mental health can really affect cybersecurity professionals.”&lt;/p&gt;&lt;p&gt;·       “Business isn’t meant to be just transactional.”&lt;/p&gt;&lt;p&gt;·       “One of the biggest barriers to why people don’t buy into it at first is because they don’t understand it.”&lt;/p&gt;&lt;p&gt;·       “Security issues don’t care if you don’t have a budget or don’t have a team.”&lt;/p&gt;&lt;p&gt;·       “Once you get people to feel a certain way, you can’t undo that.”&lt;/p&gt;&lt;p&gt;·       “There’s no better way to learn than to have to teach material yourself.”&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:53:21</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>7</itunes:episode><itunes:title>Securing Democracy: DNC&apos;s Cyber Cop</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Zombie identities: the hidden threat in your cloud]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On this episode, Sandy Bird, CTO and Co-Founder of Sonrai Security, joins the show to discuss identity security in the Cloud. Prior to Sonrai Security, Sandy co-founded Q1 Labs, which was acquired by IBM. He then became the CTO and helped IBM Security grow to $2B in revenue.</p><p>Today, Sandy talks about his journey in cybersecurity and how to manage and eliminate dormant identities. Why should listeners be concerned about zombie identities? Hear about the permissions attack surface and where to start implementing zero trust policies.</p><p><b>Timestamp Segments</b></p><p>·       [01:41] Getting into cybersecurity.</p><p>·       [03:48] Key lessons from IBM.</p><p>·       [08:40] Zombie identities.</p><p>·       [12:53] Is it possible to manage and eliminate dormant identities?</p><p>·       [16:17] Tying the process into a CI/CD pipeline.</p><p>·       [21:01] The Dirty Dozen of Cloud Identity.</p><p>·       [24:13] The permissions attack surface.</p><p>·       [27:00] Zero Trust best practices.</p><p>·       [30:08] Creating nett new machine identities.</p><p>·       [33:17] Prioritizing identity misconfigurations.</p><p>·       [35:15] Sandy’s mentors and inspirations.</p><p>·       [37:37] How does Sandy stay sharp?</p><p> </p><p><b>Sound Bites</b><br /><br />"Nothing is a straight path in starting companies in your career."<br />"Zombie identities are identities that were part of previous projects and never get cleaned up."<br />"Fix the low-hanging fruit first, such as getting rid of zombie identities and locking down sensitive identities."</p><p> </p><p><b>Relevant Links</b></p><p>Website:          <a href="https://sonraisecurity.com/" rel="noopener noreferrer nofollow">sonraisecurity.com</a></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/sandy-bird-835b5576" rel="noopener noreferrer nofollow">Sandy Bird</a></p><p><a href="https://sonraisecurity.com/cloud-access-data-report" rel="noopener noreferrer nofollow">Quantifying Cloud Access: Overprivileged Identities and Zombie Identities</a></p>]]></description><guid isPermaLink="false">Buzzsprout-15134800</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 03 Jun 2024 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/6656a30bced3287d37ea47193274716033b9a2fc097de544f47a5c0e79077dce/eyJlcGlzb2RlSWQiOiJjZjgyZGUzYS0zZTE1LTQxMTItODU0OS1lMmJhODYxYjAyOTciLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvY2Y4MmRlM2EtM2UxNS00MTEyLTg1NDktZTJiYTg2MWIwMjk3LzE1MTM0ODAwLXpvbWJpZS1pZGVudGl0aWVzLXRoZS1oaWRkZW4tdGhyZWF0LWluLXlvdXItY2xvdWQubXAzIn0=.mp3" length="28589712" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, Sandy Bird, CTO and Co-Founder of Sonrai Security, joins the show to discuss identity security in the Cloud. Prior to Sonrai Security, Sandy co-founded Q1 Labs, which was acquired by IBM. He then became the CTO and helped IBM Security grow to $2B in revenue.&lt;/p&gt;&lt;p&gt;Today, Sandy talks about his journey in cybersecurity and how to manage and eliminate dormant identities. Why should listeners be concerned about zombie identities? Hear about the permissions attack surface and where to start implementing zero trust policies.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:41] Getting into cybersecurity.&lt;/p&gt;&lt;p&gt;·       [03:48] Key lessons from IBM.&lt;/p&gt;&lt;p&gt;·       [08:40] Zombie identities.&lt;/p&gt;&lt;p&gt;·       [12:53] Is it possible to manage and eliminate dormant identities?&lt;/p&gt;&lt;p&gt;·       [16:17] Tying the process into a CI/CD pipeline.&lt;/p&gt;&lt;p&gt;·       [21:01] The Dirty Dozen of Cloud Identity.&lt;/p&gt;&lt;p&gt;·       [24:13] The permissions attack surface.&lt;/p&gt;&lt;p&gt;·       [27:00] Zero Trust best practices.&lt;/p&gt;&lt;p&gt;·       [30:08] Creating nett new machine identities.&lt;/p&gt;&lt;p&gt;·       [33:17] Prioritizing identity misconfigurations.&lt;/p&gt;&lt;p&gt;·       [35:15] Sandy’s mentors and inspirations.&lt;/p&gt;&lt;p&gt;·       [37:37] How does Sandy stay sharp?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Sound Bites&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&quot;Nothing is a straight path in starting companies in your career.&quot;&lt;br /&gt;&quot;Zombie identities are identities that were part of previous projects and never get cleaned up.&quot;&lt;br /&gt;&quot;Fix the low-hanging fruit first, such as getting rid of zombie identities and locking down sensitive identities.&quot;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website:          &lt;a href=&quot;https://sonraisecurity.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;sonraisecurity.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/sandy-bird-835b5576&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Sandy Bird&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://sonraisecurity.com/cloud-access-data-report&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Quantifying Cloud Access: Overprivileged Identities and Zombie Identities&lt;/a&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:39:37</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>7</itunes:episode><itunes:title>Zombie identities: the hidden threat in your cloud</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[What (actually) Works In Cloud Security]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>Some of the most pertinent issues in cloud security are also very foundational. Questions like where to start, what works, and also what doesn’t work, can leave teams feeling frustrated and at a loss over how to proceed. Here to help us unpack these important questions is Jonathan Villa, the Cloud Security Practice director at GuidePoint Security. <br /><br />Jonathan’s career wasn’t always in security, he has spent time as an application developer, and as a pentester. All of this led him to build solutions in the cloud over a decade ago which organically transitioned into cloud security. In our conversation with Jonathan, we discuss what he learned about cloud security throughout his career, what he has found to be effective, both in terms of technology and managing teams. We explore important issues like how security has struggled with automation and how to address it. Later we address the challenges facing talent development in security and how to address them, including having leadership take a more long-term view and training junior staff members. Jonathan also discusses the RACI model, why so many companies struggle to implement it correctly and how best to be effective. Today’s episode offers key insight into cloud security, leadership, and the importance of teams, so make sure you tune in today!<br /><br /><a href="https://www.linkedin.com/in/jonathanvilla/" rel="noopener noreferrer nofollow">Jonathan's LinkedIn profile</a><br /><br />“I think that if security organizations really look to build more, they may attract more talent with development experience.” — Jonathan Villa [0:08:07]<br /><br />“When you look at the average tenure of a CISO, I don't know what it is now, it's like two years or something like that. It's like, how do you build a long-term talent development model if the leaders themselves are gone every two years?” — Jonathan Villa [0:20:39]</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-9235144</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Tue, 21 Sep 2021 16:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/903976c61ceb29fd18a3ffd14f03084340f1f32b41a9bb73ebcbba06bfe3fdb5/eyJlcGlzb2RlSWQiOiI1NDNmNGY5YS05M2U1LTQ0OGMtOGU4Yy03ZGNmNmQ3MWIyNDIiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNTQzZjRmOWEtOTNlNS00NDhjLThlOGMtN2RjZjZkNzFiMjQyLzkyMzUxNDQtd2hhdC1hY3R1YWxseS13b3Jrcy1pbi1jbG91ZC1zZWN1cml0eS5tcDMifQ==.mp3" length="27052241" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Some of the most pertinent issues in cloud security are also very foundational. Questions like where to start, what works, and also what doesn’t work, can leave teams feeling frustrated and at a loss over how to proceed. Here to help us unpack these important questions is Jonathan Villa, the Cloud Security Practice director at GuidePoint Security. &lt;br /&gt;&lt;br /&gt;Jonathan’s career wasn’t always in security, he has spent time as an application developer, and as a pentester. All of this led him to build solutions in the cloud over a decade ago which organically transitioned into cloud security. In our conversation with Jonathan, we discuss what he learned about cloud security throughout his career, what he has found to be effective, both in terms of technology and managing teams. We explore important issues like how security has struggled with automation and how to address it. Later we address the challenges facing talent development in security and how to address them, including having leadership take a more long-term view and training junior staff members. Jonathan also discusses the RACI model, why so many companies struggle to implement it correctly and how best to be effective. Today’s episode offers key insight into cloud security, leadership, and the importance of teams, so make sure you tune in today!&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://www.linkedin.com/in/jonathanvilla/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Jonathan&apos;s LinkedIn profile&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;“I think that if security organizations really look to build more, they may attract more talent with development experience.” — Jonathan Villa [0:08:07]&lt;br /&gt;&lt;br /&gt;“When you look at the average tenure of a CISO, I don&apos;t know what it is now, it&apos;s like two years or something like that. It&apos;s like, how do you build a long-term talent development model if the leaders themselves are gone every two years?” — Jonathan Villa [0:20:39]&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:37:27</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>7</itunes:episode><itunes:title>What (actually) Works In Cloud Security</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[How Common Identity Misconfigurations Can Undermine Cloud Security]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>Welcome to a brand new cloud security podcast, Cloud Security Today. Instead of focusing on the latest news, we’re exploring a different take on cloud security where we dig deeper into its eclectic “how-to” side. On Cloud Security Today, we are going to talk with experts from all over the community so you can do cloud security better. Today’s experts are Nathaniel Quist (Q) and Jay Chen, and they will be talking about Unit 42’s latest cloud threat research. First up Q and J, as we call them, introduce listeners to their professional histories before telling us how they choose their research projects. We then talk to Q and Jay about findings from their latest report on identity and access management. Together, they explain some of the common vulnerabilities that come with identity and access management, like misconfigured roles. Toward the end of the episode, we talk to Q about cryptojacking, as he explains the nuances to mining coins maliciously, the various teams behind the act, and how they use code against each other. </p><p> <b>Key Points From This Episode:</b></p><p>●      How to become a threat researcher. Q and Jay share a little bit about their background.</p><p>●      Watch your roles and look out for wildcards in configurations!</p><p>●      APIs don’t always behave as expected – test them!</p><p><b>Tweetables:</b></p><p>“My biggest surprise is that even in a multi-million-dollar enterprise environment with thousands of workloads, thousands of EC2 instances and databases, they still make very fundamental mistakes.” — Jay Chen <b>[0:09:55]</b></p><p>“The cloud has the potential to be so much more granularly controlled than just a normal on-prem environment. From the outside looking in, it's very complex. Complexity can bring some obscurity within the cloud environment.” — Nathaniel Quist <b>[0:17:00]</b></p><p><b>Links Mentioned in Today’s Episode:</b></p><p><b> </b></p><p><a href="https://www.linkedin.com/in/mattchiodi/" rel="noopener noreferrer nofollow">Matt Chiodi on LinkedIn</a></p><p><a href="https://twitter.com/mattchiodi?lang=en" rel="noopener noreferrer nofollow">Matt Chiodi on Twitter</a><br /><br /><a href="https://www.paloaltonetworks.com/prisma/unit42-cloud-threat-research" rel="noopener noreferrer nofollow">Unit 42 Cloud Threat Report</a></p><p><a href="https://www.linkedin.com/in/qquist/" rel="noopener noreferrer nofollow">Nathaniel Quist on LinkedIn</a></p><p><a href="https://www.linkedin.com/in/jaychen2015/" rel="noopener noreferrer nofollow">Jay Chen on LinkedIn</a></p><p><a href="https://github.com/prisma-cloud/IAMFinder" rel="noopener noreferrer nofollow">IAMFinder tool on GitHub</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-8117951</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 10 Mar 2021 23:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/202848341091d471600da9ed83885a7b195aa48e5b271788ff6db531255ed04a/eyJlcGlzb2RlSWQiOiJlMmZjNjI2ZS04YWM4LTRmOTYtOTUwMS02NjI1MDdlZjc4Y2IiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZTJmYzYyNmUtOGFjOC00Zjk2LTk1MDEtNjYyNTA3ZWY3OGNiLzgxMTc5NTEtaG93LWNvbW1vbi1pZGVudGl0eS1taXNjb25maWd1cmF0aW9ucy1jYW4tdW5kZXJtaW5lLWNsb3VkLXNlY3VyaXR5Lm1wMyJ9.mp3" length="33190391" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Welcome to a brand new cloud security podcast, Cloud Security Today. Instead of focusing on the latest news, we’re exploring a different take on cloud security where we dig deeper into its eclectic “how-to” side. On Cloud Security Today, we are going to talk with experts from all over the community so you can do cloud security better. Today’s experts are Nathaniel Quist (Q) and Jay Chen, and they will be talking about Unit 42’s latest cloud threat research. First up Q and J, as we call them, introduce listeners to their professional histories before telling us how they choose their research projects. We then talk to Q and Jay about findings from their latest report on identity and access management. Together, they explain some of the common vulnerabilities that come with identity and access management, like misconfigured roles. Toward the end of the episode, we talk to Q about cryptojacking, as he explains the nuances to mining coins maliciously, the various teams behind the act, and how they use code against each other. &lt;/p&gt;&lt;p&gt; &lt;b&gt;Key Points From This Episode:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;●      How to become a threat researcher. Q and Jay share a little bit about their background.&lt;/p&gt;&lt;p&gt;●      Watch your roles and look out for wildcards in configurations!&lt;/p&gt;&lt;p&gt;●      APIs don’t always behave as expected – test them!&lt;/p&gt;&lt;p&gt;&lt;b&gt;Tweetables:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;“My biggest surprise is that even in a multi-million-dollar enterprise environment with thousands of workloads, thousands of EC2 instances and databases, they still make very fundamental mistakes.” — Jay Chen &lt;b&gt;[0:09:55]&lt;/b&gt;&lt;/p&gt;&lt;p&gt;“The cloud has the potential to be so much more granularly controlled than just a normal on-prem environment. From the outside looking in, it&apos;s very complex. Complexity can bring some obscurity within the cloud environment.” — Nathaniel Quist &lt;b&gt;[0:17:00]&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Links Mentioned in Today’s Episode:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/mattchiodi/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Matt Chiodi on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://twitter.com/mattchiodi?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Matt Chiodi on Twitter&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/unit42-cloud-threat-research&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Unit 42 Cloud Threat Report&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/qquist/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Nathaniel Quist on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/jaychen2015/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Jay Chen on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/prisma-cloud/IAMFinder&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;IAMFinder tool on GitHub&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:46:04</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>1</itunes:episode><itunes:title>How Common Identity Misconfigurations Can Undermine Cloud Security</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Book Review: Startup Secure]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Book Review: Startup Secure with Chris Castaldo</b></p><p><b>Episode Summary</b></p><p>On this episode, CISO at Crossbeam and Author of <em>Startup Secure: Baking Cybersecurity into your Company from Founding to Exit</em>, Chris Castaldo, joins Matt to talk about startups and security. Chris is an industry-wide recognized CISO, having over 20 years of experience in cybersecurity.</p><p>Today, Chris talks about his book, <em>Startup Secure</em>, his move to startups from the public sector, and the different startup development phases. What should startups focus on during the different development phases? Hear about security trust centers, the top startup security sins, and get Chris’s formula for personal growth.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [02:03] What prompted Chris to write Startup Secure?</p><p>·       [04:57] What has changed during the writing process?</p><p>·       [06:47] Critical decisions throughout Chris’s career.</p><p>·       [11:17] Moving from public sector to startups.</p><p>·       [15:39] Startup development phases.</p><p>·       [20:16] When certifications don’t make sense.</p><p>·       [26:09] Mistakes in communicating to customers.</p><p>·       [30:16] Security trust centers.</p><p>·       [32:45] Startup security sins.</p><p>·       [35:38] Chris’s formula for personal growth.</p><p>·       [39:06] Chris’s parting words.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “You’re not the target. You’re just the jumping point to that target.”</p><p>·       “I don’t need to review the security of a company we’re buying desks from.”</p><p>·       “You just can’t expect everyone to be a cybersecurity expert.”</p><p> </p><p><b>Relevant Links</b></p><p>Buy the Book: <a href="https://www.amazon.com/Start-Up-Secure-Cybersecurity-Company-Founding/dp/1119700736" rel="noopener noreferrer nofollow">https://www.amazon.com/Start-Up-Secure-Cybersecurity-Company-Founding/dp/1119700736</a></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/chriscastaldo" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/chriscastaldo</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-11127520</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 21 Sep 2022 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/d6a73cdddecaf8a0a16aa597d62260b06712a12e0584931190cec12babb36ada/eyJlcGlzb2RlSWQiOiJkNGU5MzdiMC1kOTdjLTQyZjUtYjA4Zi1hOGY4NzE1MjYyZjciLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZDRlOTM3YjAtZDk3Yy00MmY1LWIwOGYtYThmODcxNTI2MmY3LzExMTI3NTIwLWJvb2stcmV2aWV3LXN0YXJ0dXAtc2VjdXJlLm1wMyJ9.mp3" length="29518325" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Book Review: Startup Secure with Chris Castaldo&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, CISO at Crossbeam and Author of &lt;em&gt;Startup Secure: Baking Cybersecurity into your Company from Founding to Exit&lt;/em&gt;, Chris Castaldo, joins Matt to talk about startups and security. Chris is an industry-wide recognized CISO, having over 20 years of experience in cybersecurity.&lt;/p&gt;&lt;p&gt;Today, Chris talks about his book, &lt;em&gt;Startup Secure&lt;/em&gt;, his move to startups from the public sector, and the different startup development phases. What should startups focus on during the different development phases? Hear about security trust centers, the top startup security sins, and get Chris’s formula for personal growth.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:03] What prompted Chris to write Startup Secure?&lt;/p&gt;&lt;p&gt;·       [04:57] What has changed during the writing process?&lt;/p&gt;&lt;p&gt;·       [06:47] Critical decisions throughout Chris’s career.&lt;/p&gt;&lt;p&gt;·       [11:17] Moving from public sector to startups.&lt;/p&gt;&lt;p&gt;·       [15:39] Startup development phases.&lt;/p&gt;&lt;p&gt;·       [20:16] When certifications don’t make sense.&lt;/p&gt;&lt;p&gt;·       [26:09] Mistakes in communicating to customers.&lt;/p&gt;&lt;p&gt;·       [30:16] Security trust centers.&lt;/p&gt;&lt;p&gt;·       [32:45] Startup security sins.&lt;/p&gt;&lt;p&gt;·       [35:38] Chris’s formula for personal growth.&lt;/p&gt;&lt;p&gt;·       [39:06] Chris’s parting words.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “You’re not the target. You’re just the jumping point to that target.”&lt;/p&gt;&lt;p&gt;·       “I don’t need to review the security of a company we’re buying desks from.”&lt;/p&gt;&lt;p&gt;·       “You just can’t expect everyone to be a cybersecurity expert.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Buy the Book: &lt;a href=&quot;https://www.amazon.com/Start-Up-Secure-Cybersecurity-Company-Founding/dp/1119700736&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.amazon.com/Start-Up-Secure-Cybersecurity-Company-Founding/dp/1119700736&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/chriscastaldo&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/chriscastaldo&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:40:54</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>10</itunes:episode><itunes:title>Book Review: Startup Secure</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Keeping Governments Secure in the Cloud]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>Cloud security is essential for any business but particularly for government agencies. On today’s episode, we speak with an expert in the field, Ravi Raghava, who is Chief Cloud Strategist at General Dynamics Information Technology (GDIT). Ravi speaks about his personal experience with dozens of cloud deployments for civil agencies and shares best practices.</p><p><b>Acronyms</b></p><ul><li>ATO = Authority to Operate</li><li>POAM = Plan of Action and Milestones</li><li>CDM = Continuous Diagnostics and Mitigation</li><li>OCM = Organizational Change Management</li></ul><p><b>Tweetables:</b></p><p>“Over the next few years, we will see a lot of traction and we will see accelerated workload migration to the cloud. It's not just one cloud but multiple clouds, and multi-cloud is becoming the new norm.” — Ravi Raghava [0:04:55]<br /><br />“We are very strong advocates of OCM, and we work with our government customers to have a well thought-through strategy, providing the right skills, the right training, right medium of training to people.” — Ravi Raghava [0:25:43]<br /><br />“Having those security frameworks in place, testing infrastructure, having those security tools in place nicely help you automate the entire thing because automation is key.” — Ravi Raghava [0:31:20]</p><p><b>Links Mentioned in Today’s Episode:</b></p><p><a href="https://www.linkedin.com/in/raviraghava/" rel="noopener noreferrer nofollow">Ravi Raghava on LinkedIn<br /></a><a href="http://www.gdit.com" rel="noopener noreferrer nofollow">GDIT<br /></a><a href="https://jfrog.com/" rel="noopener noreferrer nofollow">JFrog<br /></a><a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud.html" rel="noopener noreferrer nofollow">Prisma Cloud</a></p><p><br /></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-8859263</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Tue, 13 Jul 2021 20:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/1f751907470f4a2a477efc4d33f2d27a5138beed2a44af749d87069929b4de2d/eyJlcGlzb2RlSWQiOiI0OWE2ZjI0MC1jYjBjLTQ1ZWQtYTUxYS04OWEzZDQzNTRjMDUiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNDlhNmYyNDAtY2IwYy00NWVkLWE1MWEtODlhM2Q0MzU0YzA1Lzg4NTkyNjMta2VlcGluZy1nb3Zlcm5tZW50cy1zZWN1cmUtaW4tdGhlLWNsb3VkLm1wMyJ9.mp3" length="29003959" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Cloud security is essential for any business but particularly for government agencies. On today’s episode, we speak with an expert in the field, Ravi Raghava, who is Chief Cloud Strategist at General Dynamics Information Technology (GDIT). Ravi speaks about his personal experience with dozens of cloud deployments for civil agencies and shares best practices.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Acronyms&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;ATO = Authority to Operate&lt;/li&gt;&lt;li&gt;POAM = Plan of Action and Milestones&lt;/li&gt;&lt;li&gt;CDM = Continuous Diagnostics and Mitigation&lt;/li&gt;&lt;li&gt;OCM = Organizational Change Management&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Tweetables:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;“Over the next few years, we will see a lot of traction and we will see accelerated workload migration to the cloud. It&apos;s not just one cloud but multiple clouds, and multi-cloud is becoming the new norm.” — Ravi Raghava [0:04:55]&lt;br /&gt;&lt;br /&gt;“We are very strong advocates of OCM, and we work with our government customers to have a well thought-through strategy, providing the right skills, the right training, right medium of training to people.” — Ravi Raghava [0:25:43]&lt;br /&gt;&lt;br /&gt;“Having those security frameworks in place, testing infrastructure, having those security tools in place nicely help you automate the entire thing because automation is key.” — Ravi Raghava [0:31:20]&lt;/p&gt;&lt;p&gt;&lt;b&gt;Links Mentioned in Today’s Episode:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/raviraghava/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Ravi Raghava on LinkedIn&lt;br /&gt;&lt;/a&gt;&lt;a href=&quot;http://www.gdit.com&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;GDIT&lt;br /&gt;&lt;/a&gt;&lt;a href=&quot;https://jfrog.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;JFrog&lt;br /&gt;&lt;/a&gt;&lt;a href=&quot;https://docs.paloaltonetworks.com/prisma/prisma-cloud.html&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Prisma Cloud&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:40:03</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>5</itunes:episode><itunes:title>Keeping Governments Secure in the Cloud</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[CISO burnout and boardroom truths]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this conversation, <a href="https://www.linkedin.com/in/rinkisethi/" rel="noopener noreferrer nofollow">Rinki Sethi</a>, a seasoned cybersecurity leader, shares her journey from being a CISO at major companies to her current role at Upwind Security. She discusses the evolving landscape of cybersecurity, the impact of AI, and the importance of community in the industry. Rinki emphasizes the need for strong communication skills for CISOs, the significance of evaluating company culture before taking on new roles, and the necessity of leveraging AI to enhance cybersecurity programs. She also highlights the importance of personal growth and building supportive networks within the cybersecurity community.</p>]]></description><guid isPermaLink="false">Buzzsprout-17768077</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 01 Sep 2025 16:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/4899db03e848db3808eaafebd0f09ab9a1585d10a78cf41dea54a9b0a5c64c57/eyJlcGlzb2RlSWQiOiJkMDdhNmVmZS03Mjc2LTQ1YmUtYmI2Zi0xY2I4ODc3OTY1OWUiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZDA3YTZlZmUtNzI3Ni00NWJlLWJiNmYtMWNiODg3Nzk2NTllLzE3NzY4MDc3LWNpc28tYnVybm91dC1hbmQtYm9hcmRyb29tLXRydXRocy5tcDMifQ==.mp3" length="29136348" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this conversation, &lt;a href=&quot;https://www.linkedin.com/in/rinkisethi/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Rinki Sethi&lt;/a&gt;, a seasoned cybersecurity leader, shares her journey from being a CISO at major companies to her current role at Upwind Security. She discusses the evolving landscape of cybersecurity, the impact of AI, and the importance of community in the industry. Rinki emphasizes the need for strong communication skills for CISOs, the significance of evaluating company culture before taking on new roles, and the necessity of leveraging AI to enhance cybersecurity programs. She also highlights the importance of personal growth and building supportive networks within the cybersecurity community.&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:40:22</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>5</itunes:season><itunes:episode>7</itunes:episode><itunes:title>CISO burnout and boardroom truths</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[AppSec: Engineering, Attackers, and Defense]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>In today’s episode, AppSec CTO at Palo Alto Networks, Daniel Krivelevich, joins Matt to talk about AppSec for the modern engineering ecosystem. Daniel is a Cybersecurity expert and problem solver with a proven track record from working with numerous enterprises across several different industries, with a focus on Application and Cloud Security. He has served in the Intelligence Corps of the IDF, 8200, as a Security Specialist at LivePerson, and as the Cloud &amp; Application Security Lead at Sygnia. He is also the Co-Founder of Cider Security, which was acquired by Palo Alto Networks in December 2022.</p><p>Today, Daniel talks about how his views have been shaped by his experience on both sides of the equation, the rapid pace of software development, and the role of codification. Why is visibility such a vital part of mitigating threats? Hear about the changing role of security, the struggle with maintaining cybersecurity 101, and Daniel’s recommended sources to stay up to date.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [02:43] How Daniel’s experiences have shaped his AppSec views.</p><p>·       [09:27] The software engineering paradigm shift.</p><p>·       [12:24] The role of security.</p><p>·       [16:42] Is it realistic for security to keep up with software development?</p><p>·       [20:27] How the engineers’ freedom of choice impacts security.</p><p>·       [26:14] The role of codification to reduce the attack surface.</p><p>·       [30:21] Tools as targets.</p><p>·       [34:47] How to mitigate threats of the increasingly complex ecosystems.</p><p>·       [39:21] What’s next?</p><p>·       [44:40] The struggle with cybersecurity 101.</p><p>·       [47:03] How Daniel stays sharp.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “The attacks that abuse the engineering ecosystem, they’re not theory anymore.”</p><p>·       “The challenge is helping defenders focus on what matters.”</p><p>·       “Attackers always choose the path of least resistance.”</p><p>·       “Once you have that visibility, you are usually capable of significantly reducing your attack surface.”</p><p>·       “It’s not the zero days that are what’s leading.”</p><p> </p><p><b>Relevant Links</b></p><p>Website:          <a href="https://www.paloaltonetworks.com/" rel="noopener noreferrer nofollow">www.paloaltonetworks.com</a>.</p><p>LinkedIn:         <a href="https://il.linkedin.com/in/daniel-krivelevich" rel="noopener noreferrer nofollow">Daniel Krivelevich</a>.</p><p> </p><p><b>Resources:</b></p><p><a href="https://www.paloaltonetworks.com/blog/prisma-cloud/appsec-engineering-ecosystem/" rel="noopener noreferrer nofollow">AppSec for the Modern Engineering Ecosystem</a>.</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-13240472</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 21 Aug 2023 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/c8844d70c98ecd550ee63bb61ff8422aba5ea57f64d0bdeb61209750f20a5ae4/eyJlcGlzb2RlSWQiOiIyNzljY2QwOC1kNDRlLTQ5NDctOWY3NS0wY2IwODYzZTdiOTQiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMjc5Y2NkMDgtZDQ0ZS00OTQ3LTlmNzUtMGNiMDg2M2U3Yjk0LzEzMjQwNDcyLWFwcHNlYy1lbmdpbmVlcmluZy1hdHRhY2tlcnMtYW5kLWRlZmVuc2UubXAzIn0=.mp3" length="36320642" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In today’s episode, AppSec CTO at Palo Alto Networks, Daniel Krivelevich, joins Matt to talk about AppSec for the modern engineering ecosystem. Daniel is a Cybersecurity expert and problem solver with a proven track record from working with numerous enterprises across several different industries, with a focus on Application and Cloud Security. He has served in the Intelligence Corps of the IDF, 8200, as a Security Specialist at LivePerson, and as the Cloud &amp;amp; Application Security Lead at Sygnia. He is also the Co-Founder of Cider Security, which was acquired by Palo Alto Networks in December 2022.&lt;/p&gt;&lt;p&gt;Today, Daniel talks about how his views have been shaped by his experience on both sides of the equation, the rapid pace of software development, and the role of codification. Why is visibility such a vital part of mitigating threats? Hear about the changing role of security, the struggle with maintaining cybersecurity 101, and Daniel’s recommended sources to stay up to date.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:43] How Daniel’s experiences have shaped his AppSec views.&lt;/p&gt;&lt;p&gt;·       [09:27] The software engineering paradigm shift.&lt;/p&gt;&lt;p&gt;·       [12:24] The role of security.&lt;/p&gt;&lt;p&gt;·       [16:42] Is it realistic for security to keep up with software development?&lt;/p&gt;&lt;p&gt;·       [20:27] How the engineers’ freedom of choice impacts security.&lt;/p&gt;&lt;p&gt;·       [26:14] The role of codification to reduce the attack surface.&lt;/p&gt;&lt;p&gt;·       [30:21] Tools as targets.&lt;/p&gt;&lt;p&gt;·       [34:47] How to mitigate threats of the increasingly complex ecosystems.&lt;/p&gt;&lt;p&gt;·       [39:21] What’s next?&lt;/p&gt;&lt;p&gt;·       [44:40] The struggle with cybersecurity 101.&lt;/p&gt;&lt;p&gt;·       [47:03] How Daniel stays sharp.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “The attacks that abuse the engineering ecosystem, they’re not theory anymore.”&lt;/p&gt;&lt;p&gt;·       “The challenge is helping defenders focus on what matters.”&lt;/p&gt;&lt;p&gt;·       “Attackers always choose the path of least resistance.”&lt;/p&gt;&lt;p&gt;·       “Once you have that visibility, you are usually capable of significantly reducing your attack surface.”&lt;/p&gt;&lt;p&gt;·       “It’s not the zero days that are what’s leading.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website:          &lt;a href=&quot;https://www.paloaltonetworks.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;www.paloaltonetworks.com&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://il.linkedin.com/in/daniel-krivelevich&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Daniel Krivelevich&lt;/a&gt;.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resources:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/blog/prisma-cloud/appsec-engineering-ecosystem/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;AppSec for the Modern Engineering Ecosystem&lt;/a&gt;.&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:50:20</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>8</itunes:episode><itunes:title>AppSec: Engineering, Attackers, and Defense</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Navigating identity security]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this episode, Matt interviews <a href="https://www.linkedin.com/in/belsasar-lepe-975a203" rel="noopener noreferrer nofollow">Bel Lepe</a>, CEO and co-founder of Cerby, discussing the challenges and opportunities in identity security. They explore the significance of disconnected applications, the impact of shadow IT, and the importance of automation and AI in enhancing security practices. Bel shares insights from his previous experience at Ooyala and the lessons learned in building Cerby, including the recent Series B funding and future plans for the company.</p><p><b>Takeaways</b></p><ul><li>Disconnected applications pose significant risks in identity management.</li><li>Shadow IT is becoming a major part of the IT landscape, not just a side issue.</li><li>The startup journey involves learning from past experiences and adapting strategies.</li><li>The human element remains a critical factor in cybersecurity incidents.</li></ul><p><br /><br /></p>]]></description><guid isPermaLink="false">Buzzsprout-17243198</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Thu, 29 May 2025 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/372869183487a1fac6ffbf5e219cd8ac644705081e727e6f109ade9efd738980/eyJlcGlzb2RlSWQiOiI1NWMwY2U2OS02YmFkLTQzZTAtYTI2MC0xYWJkNWVmNjg4ODgiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNTVjMGNlNjktNmJhZC00M2UwLWEyNjAtMWFiZDVlZjY4ODg4LzE3MjQzMTk4LW5hdmlnYXRpbmctaWRlbnRpdHktc2VjdXJpdHkubXAzIn0=.mp3" length="24647769" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this episode, Matt interviews &lt;a href=&quot;https://www.linkedin.com/in/belsasar-lepe-975a203&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Bel Lepe&lt;/a&gt;, CEO and co-founder of Cerby, discussing the challenges and opportunities in identity security. They explore the significance of disconnected applications, the impact of shadow IT, and the importance of automation and AI in enhancing security practices. Bel shares insights from his previous experience at Ooyala and the lessons learned in building Cerby, including the recent Series B funding and future plans for the company.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Disconnected applications pose significant risks in identity management.&lt;/li&gt;&lt;li&gt;Shadow IT is becoming a major part of the IT landscape, not just a side issue.&lt;/li&gt;&lt;li&gt;The startup journey involves learning from past experiences and adapting strategies.&lt;/li&gt;&lt;li&gt;The human element remains a critical factor in cybersecurity incidents.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:34:08</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>5</itunes:season><itunes:episode>5</itunes:episode><itunes:title>Navigating identity security</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Cloud Native Security: A Year in Review]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>On this episode, the Chief Security Officer of Cloud at Palo Alto Networks, Bob West, joins Matt to discuss Palo Alto Network's latest State of Cloud Native Security Report. Bob joined Palo Alto Networks after more than 20 years in leadership roles with banks, product companies, and professional services organizations. Before joining Palo Alto Networks, Bob served as managing partner at West Strategy Group, managing director in Deloitte’s cyber risk services practice, managing director for CISO for York Risk Services, Chief Trust Officer at CipherCloud, CEO at Echelon One, Chief Information Security Officer (CISO) at Fifth Third Bank, and Information Security Officer at Bank One.</p><p>Today, Bob talks about the latest installment of the State of Cloud Native Security Report, the severe shortcomings in Cloud Security, and the elevated cost of Cloud Security. Why is it essential to think about security upfront? Hear about the daily mindset shift required to deploy quality code, minimizing complexity to maximize efficiency, and the significant delay in threat management.</p><p><b>Timestamp Segments</b></p><p>·       [01:46] Bob’s career-changing experiences.</p><p>·       [04:17] Bob’s advice.</p><p>·       [11:10] The 10,000-ft view.</p><p>·       [16:23] The elevated costs of Cloud security.</p><p>·       [22:36] Increased deployment frequency.</p><p>·       [24:54] How do security teams keep up?</p><p>·       [30:44] Security tooling in the Cloud.</p><p>·       [35:46] Holistic Cloud security.</p><p>·       [41:18] There will always be issues.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “Be nice to your vendors.” - Bob</p><p>·       “You never know who’s going to be able to help you out at any point.” - Bob</p><p>·       “You’ve got to build bridges before you need them.” - Matt</p><p>·       “Common sense isn’t necessarily common practice.” - Bob</p><p><b>Relevant Links</b></p><p>Website:   <a href="https://www.paloaltonetworks.com/" rel="noopener noreferrer nofollow">www.paloaltonetworks.com</a></p><p>LinkedIn:  <a href="https://www.linkedin.com/in/bowest" rel="noopener noreferrer nofollow">Bob West</a></p><p><b>Resources:</b></p><p><a href="https://www.amazon.com/Out-Crisis-Press-Edwards-Deming/dp/0262535947" rel="noopener noreferrer nofollow">Out of the Crisis</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-12689965</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Fri, 21 Apr 2023 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/f4b91f53501ab1becb9cdcbfaee347b2f8ea96eaf78dbe2886a0fa7907da7326/eyJlcGlzb2RlSWQiOiI2MzNlYTkyNy02NGQ3LTRkOTYtYTEzZi0zZmVkOGNhODVhYmUiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNjMzZWE5MjctNjRkNy00ZDk2LWExM2YtM2ZlZDhjYTg1YWJlLzEyNjg5OTY1LWNsb3VkLW5hdGl2ZS1zZWN1cml0eS1hLXllYXItaW4tcmV2aWV3Lm1wMyJ9.mp3" length="31715142" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;On this episode, the Chief Security Officer of Cloud at Palo Alto Networks, Bob West, joins Matt to discuss Palo Alto Network&apos;s latest State of Cloud Native Security Report. Bob joined Palo Alto Networks after more than 20 years in leadership roles with banks, product companies, and professional services organizations. Before joining Palo Alto Networks, Bob served as managing partner at West Strategy Group, managing director in Deloitte’s cyber risk services practice, managing director for CISO for York Risk Services, Chief Trust Officer at CipherCloud, CEO at Echelon One, Chief Information Security Officer (CISO) at Fifth Third Bank, and Information Security Officer at Bank One.&lt;/p&gt;&lt;p&gt;Today, Bob talks about the latest installment of the State of Cloud Native Security Report, the severe shortcomings in Cloud Security, and the elevated cost of Cloud Security. Why is it essential to think about security upfront? Hear about the daily mindset shift required to deploy quality code, minimizing complexity to maximize efficiency, and the significant delay in threat management.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:46] Bob’s career-changing experiences.&lt;/p&gt;&lt;p&gt;·       [04:17] Bob’s advice.&lt;/p&gt;&lt;p&gt;·       [11:10] The 10,000-ft view.&lt;/p&gt;&lt;p&gt;·       [16:23] The elevated costs of Cloud security.&lt;/p&gt;&lt;p&gt;·       [22:36] Increased deployment frequency.&lt;/p&gt;&lt;p&gt;·       [24:54] How do security teams keep up?&lt;/p&gt;&lt;p&gt;·       [30:44] Security tooling in the Cloud.&lt;/p&gt;&lt;p&gt;·       [35:46] Holistic Cloud security.&lt;/p&gt;&lt;p&gt;·       [41:18] There will always be issues.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “Be nice to your vendors.” - Bob&lt;/p&gt;&lt;p&gt;·       “You never know who’s going to be able to help you out at any point.” - Bob&lt;/p&gt;&lt;p&gt;·       “You’ve got to build bridges before you need them.” - Matt&lt;/p&gt;&lt;p&gt;·       “Common sense isn’t necessarily common practice.” - Bob&lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website:   &lt;a href=&quot;https://www.paloaltonetworks.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;www.paloaltonetworks.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:  &lt;a href=&quot;https://www.linkedin.com/in/bowest&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Bob West&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Resources:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.amazon.com/Out-Crisis-Press-Edwards-Deming/dp/0262535947&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Out of the Crisis&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:43:57</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>4</itunes:episode><itunes:title>Cloud Native Security: A Year in Review</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Security is a process]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On this episode, Co-Founder and CTO of Gutsy, John Morello, joins Matt to talk about Process Mining in Cybersecurity. Before co-founding Gutsy, John served as the CTO of Twistlock and VP of Product for Prisma Cloud.<br /><br /></p><p>John holds multiple cybersecurity patents and is an author of NIST SP 800-190, the Container Security Guide. Before Twistlock, he was the CISO of an S&amp;P 500 global chemical company. Before that, he spent 14 years at Microsoft, working on security technologies in Windows and Azure and consulting on security projects across the DoD, intelligence community, and at the White House. <br /><br /></p><p>John graduated summa cum laude from LSU and lives in Baton Rouge with his wife and two sons. A lifelong outdoorsman and NAUI Master Diver and Rescue Diver, he's the former board chair of the Coalition to Restore Coastal Louisiana and a current Coastal Conservation Association board member.<br /><br /></p><p>Today, John talks about governance challenges in cybersecurity, the importance of security as a process, and how to apply process mining. How is process mining useful in cybersecurity? Hear about process mining human actions and unstructured sources, and how John manages to stay sharp.<br /><br /></p><p> </p><p><b>Timestamp Segments</b></p><p>·       [02:20] John’s cybersecurity journey.</p><p>·       [07:43] Pivotal moments in John’s career.</p><p>·       [10:23] The most pressing governance challenges.</p><p>·       [14:07] What is process mining?</p><p>·       [19:03] How process mining can benefit certain functions.</p><p>·       [21:09] Security as a process, not a product.</p><p>·       [25:37] Why there’s not more focus on process.</p><p>·       [32:03] Applying process mining.</p><p>·       [38:07] Filling in the gaps.</p><p>·       [42:03] How John stays sharp.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “Security is a process, not a product.”</p><p>·       “In security, inefficiency and inconsistency are highly correlated with risk.”</p><p>·       “Almost everything in security is about process.”</p><p> </p><p><b>Relevant Links</b></p><p>Website:          <a href="https://gutsy.com/" rel="noopener noreferrer nofollow">gutsy.com</a>.</p><p>LinkedIn:         <a href="https://www.linkedin.com/in/john-morello" rel="noopener noreferrer nofollow">www.linkedin.com/in/john-morello</a>.</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-14519012</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Fri, 16 Feb 2024 22:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/17f5ebd6678c1289bd1014dd2ab900948120f7208c6f8bb399283b2a8ac929f8/eyJlcGlzb2RlSWQiOiJiYjU2YWY0NC0wYTJlLTQ2ZmEtODlhMC04ODY1OTQ0NDYyZmIiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvYmI1NmFmNDQtMGEyZS00NmZhLTg5YTAtODg2NTk0NDQ2MmZiLzE0NTE5MDEyLXNlY3VyaXR5LWlzLWEtcHJvY2Vzcy5tcDMifQ==.mp3" length="34169885" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, Co-Founder and CTO of Gutsy, John Morello, joins Matt to talk about Process Mining in Cybersecurity. Before co-founding Gutsy, John served as the CTO of Twistlock and VP of Product for Prisma Cloud.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;John holds multiple cybersecurity patents and is an author of NIST SP 800-190, the Container Security Guide. Before Twistlock, he was the CISO of an S&amp;amp;P 500 global chemical company. Before that, he spent 14 years at Microsoft, working on security technologies in Windows and Azure and consulting on security projects across the DoD, intelligence community, and at the White House. &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;John graduated summa cum laude from LSU and lives in Baton Rouge with his wife and two sons. A lifelong outdoorsman and NAUI Master Diver and Rescue Diver, he&apos;s the former board chair of the Coalition to Restore Coastal Louisiana and a current Coastal Conservation Association board member.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Today, John talks about governance challenges in cybersecurity, the importance of security as a process, and how to apply process mining. How is process mining useful in cybersecurity? Hear about process mining human actions and unstructured sources, and how John manages to stay sharp.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:20] John’s cybersecurity journey.&lt;/p&gt;&lt;p&gt;·       [07:43] Pivotal moments in John’s career.&lt;/p&gt;&lt;p&gt;·       [10:23] The most pressing governance challenges.&lt;/p&gt;&lt;p&gt;·       [14:07] What is process mining?&lt;/p&gt;&lt;p&gt;·       [19:03] How process mining can benefit certain functions.&lt;/p&gt;&lt;p&gt;·       [21:09] Security as a process, not a product.&lt;/p&gt;&lt;p&gt;·       [25:37] Why there’s not more focus on process.&lt;/p&gt;&lt;p&gt;·       [32:03] Applying process mining.&lt;/p&gt;&lt;p&gt;·       [38:07] Filling in the gaps.&lt;/p&gt;&lt;p&gt;·       [42:03] How John stays sharp.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “Security is a process, not a product.”&lt;/p&gt;&lt;p&gt;·       “In security, inefficiency and inconsistency are highly correlated with risk.”&lt;/p&gt;&lt;p&gt;·       “Almost everything in security is about process.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website:          &lt;a href=&quot;https://gutsy.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;gutsy.com&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/john-morello&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;www.linkedin.com/in/john-morello&lt;/a&gt;.&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:47:21</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>2</itunes:episode><itunes:title>Security is a process</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The AI Episode]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>In today’s episode, AI Safety Initiative Chair at Cloud Security Alliance, Caleb Sima, joins Matt to talk about some of the myths surrounding the quickly evolving world of AI. With two decades of experience in the cybersecurity industry, Caleb has held many high-level roles, including VP of Information Security at Databricks, CSO at Robinhood, Managing VP at CapitalOne, and Founder of both SPI Dynamics and Bluebox Security.</p><p>Today, Caleb talks about his inspiring career after dropping out of high school, dealing with imposter syndrome, and becoming the Chair of the CSA’s AI Safety Initiative. Is AI and Machine Learning the threat that we think it is? Hear about the different kinds of LLMs, the poisoning of LLMs, and how AI can be used to improve security.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [01:31] Why Caleb dropped out high school</p><p>·       [06:16] Dealing with imposter syndrome.</p><p>·       [11:43] The hype around AI and Machine Learning.</p><p>·       [14:55] AI 101 terminology.</p><p>·       [17:42] Open source LLMs.</p><p>·       [20:31] Where to start as a security practitioner.</p><p>·       [24:46] What risks should people be thinking about?</p><p>·       [28:24] Taking advantage of AI in cybersecurity.</p><p>·       [32:32] How AI will affect different SOC functions.</p><p>·       [35:00] Is it too late to get involved?</p><p>·       [36:29] CSA’s AI Safety Initiative.</p><p>·       [38:52] What’s next?</p><p> </p><p><b>Notable Quotes</b></p><p>·       “There is no way this thing is not going to change the world.”</p><p>·       “The benefit that you're going to get out of LLMs internally is going to be phenomenal.”</p><p>·       “It doesn't matter whether you get in now or in six months.”</p><p> </p><p><b>Relevant Links</b></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/calebsima" rel="noopener noreferrer nofollow">Caleb Sima</a></p><p> </p><p><b>Resources:</b></p><p><a href="https://www.nbcnews.com/id/wbna6713649" rel="noopener noreferrer nofollow">Skipping College Pays Off For Few Teen Techies</a></p><p><a href="https://llm-attacks.org/" rel="noopener noreferrer nofollow">llm-attacks.org</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-13378970</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sat, 21 Oct 2023 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/a1040a168a6bccc32181d4e4e879393500e9aafc3936c80d6567335e1082d78f/eyJlcGlzb2RlSWQiOiIxYjgzMDAwOS04MGFhLTRiZWMtOWJmZi1hNzA3NGU4NTE0MGEiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMWI4MzAwMDktODBhYS00YmVjLTliZmYtYTcwNzRlODUxNDBhLzEzMzc4OTcwLXRoZS1haS1lcGlzb2RlLm1wMyJ9.mp3" length="30309182" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In today’s episode, AI Safety Initiative Chair at Cloud Security Alliance, Caleb Sima, joins Matt to talk about some of the myths surrounding the quickly evolving world of AI. With two decades of experience in the cybersecurity industry, Caleb has held many high-level roles, including VP of Information Security at Databricks, CSO at Robinhood, Managing VP at CapitalOne, and Founder of both SPI Dynamics and Bluebox Security.&lt;/p&gt;&lt;p&gt;Today, Caleb talks about his inspiring career after dropping out of high school, dealing with imposter syndrome, and becoming the Chair of the CSA’s AI Safety Initiative. Is AI and Machine Learning the threat that we think it is? Hear about the different kinds of LLMs, the poisoning of LLMs, and how AI can be used to improve security.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:31] Why Caleb dropped out high school&lt;/p&gt;&lt;p&gt;·       [06:16] Dealing with imposter syndrome.&lt;/p&gt;&lt;p&gt;·       [11:43] The hype around AI and Machine Learning.&lt;/p&gt;&lt;p&gt;·       [14:55] AI 101 terminology.&lt;/p&gt;&lt;p&gt;·       [17:42] Open source LLMs.&lt;/p&gt;&lt;p&gt;·       [20:31] Where to start as a security practitioner.&lt;/p&gt;&lt;p&gt;·       [24:46] What risks should people be thinking about?&lt;/p&gt;&lt;p&gt;·       [28:24] Taking advantage of AI in cybersecurity.&lt;/p&gt;&lt;p&gt;·       [32:32] How AI will affect different SOC functions.&lt;/p&gt;&lt;p&gt;·       [35:00] Is it too late to get involved?&lt;/p&gt;&lt;p&gt;·       [36:29] CSA’s AI Safety Initiative.&lt;/p&gt;&lt;p&gt;·       [38:52] What’s next?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “There is no way this thing is not going to change the world.”&lt;/p&gt;&lt;p&gt;·       “The benefit that you&apos;re going to get out of LLMs internally is going to be phenomenal.”&lt;/p&gt;&lt;p&gt;·       “It doesn&apos;t matter whether you get in now or in six months.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/calebsima&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Caleb Sima&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resources:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.nbcnews.com/id/wbna6713649&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Skipping College Pays Off For Few Teen Techies&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://llm-attacks.org/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;llm-attacks.org&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:42:00</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>10</itunes:episode><itunes:title>The AI Episode</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[MITRE + Cloud]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>As the world of cloud security continues to progress at high speed, new challenges and threats arise and morph on a constant basis. The MITRE Corporation is a body tasked by the US government with solving some of the largest threats in cybersecurity and beyond, and we are very lucky to welcome Tracy Bannon to the podcast today, who is the Senior Principal and Software Architect &amp; DevOps Advisor at MITRE. Tracy opens up about her career journey leading up to her current position, what drew her into the work at MITRE, and how the simplicity of the solutions-focused mission has embedded her loyalty and passion within the organization. The conversation also goes some way into exploring the potential and limitations of zero trust, and what it actually means to make progress towards safer environments. Along the way, our guest makes some interesting and quite unique arguments for why words matter, and why change is healthier through a philosophy centered on building. So to catch it all in this fascinating conversation, make sure to join us on Cloud Security Today!</p><p>Key Points From This Episode:</p><ul><li>Tracy unpacks a brief history of FFRDCs and their role as objective technology advisors.</li><li>The two main areas of Tracy's work at MITRE; digital transformation of software factories, and data centricity in data environments.</li><li>Understanding MITRE's practical application and validation of the principles of zero trust theory. </li><li>Weighing the validity of the negative reputation that developers have when it comes to security.</li><li>Issues with the terms DevOps, DevSecOps, and SecDevOps, and the overloading and rushing that often happens on security teams. </li><li>Why Tracy prioritizes 'culture building' over 'culture change' when thinking about progress. </li><li>Leading teams, modeling behaviors, and realistic expectations for human error. </li><li>Tools and safety nets in the cloud-native approach; Tracy's perspective on how much value to assign to these.</li><li>Why the mission at MITRE initially piqued, and subsequently retained, Tracy's interest! </li></ul><p>Tweetables:</p><p>“It’s not a recipe. It's not five things you have to do. It's understanding the principles and then applying them, being able to audit them, and validate consistently that they're happening. MITRE does both sides of that.” — <a href="https://twitter.com/tracybannon?lang=en" rel="noopener noreferrer nofollow">@TracyBannon</a> [0:07:44]</p><p>“Our job is not to land and expand. It’s impact. At all costs, it's to make impact. If it's one person, or a half of that person, it's really defined by the ability to keep the US safe.” — <a href="https://twitter.com/tracybannon?lang=en" rel="noopener noreferrer nofollow">@TracyBannon</a> [0:09:39]</p><p>Links Mentioned in Today’s Episode:</p><p><a href="https://www.linkedin.com/in/tracylbannon/" rel="noopener noreferrer nofollow">Tracy Bannon on LinkedIn</a></p><p><a href="https://twitter.com/tracybannon?lang=en" rel="noopener noreferrer nofollow">Tracy Bannon on Twitter</a></p><p><a href="https://www.mitre.org/" rel="noopener noreferrer nofollow">MITRE Corporation</a></p><p><a href="https://www.audible.com/pd/Revelation-Audiobook/B08W24H8NK" rel="noopener noreferrer nofollow"><em>Revelation</em></a></p><p><a href="https://www.amazon.com/Kill-Chain-Defending-America-High-Tech/dp/031653353X" rel="noopener noreferrer nofollow"><em>The Kill Chain</em></a></p><p><a href="https://www.amazon.com/Zero-Trust-Security-Enterprise-Guide/dp/148426701X" rel="noopener noreferrer nofollow"><em>Zero Trust Security</em></a></p><p><a href="https://www.amazon.com/Software-Architect-Elevator-Redefining-Architects/dp/1492077542" rel="noopener noreferrer nofollow"><em>The Software Architect Elevator</em></a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-10826348</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Tue, 21 Jun 2022 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/f767e0f04ff09d40b0a1020108294f474ca99193aa64992b1de848103b1f0c1b/eyJlcGlzb2RlSWQiOiIxYmZmNWQ5YS03MzJiLTQxYTMtYjliOC1kNTc1YjUzMzhlNTEiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMWJmZjVkOWEtNzMyYi00MWEzLWI5YjgtZDU3NWI1MzM4ZTUxLzEwODI2MzQ4LW1pdHJlLWNsb3VkLm1wMyJ9.mp3" length="29365575" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;As the world of cloud security continues to progress at high speed, new challenges and threats arise and morph on a constant basis. The MITRE Corporation is a body tasked by the US government with solving some of the largest threats in cybersecurity and beyond, and we are very lucky to welcome Tracy Bannon to the podcast today, who is the Senior Principal and Software Architect &amp;amp; DevOps Advisor at MITRE. Tracy opens up about her career journey leading up to her current position, what drew her into the work at MITRE, and how the simplicity of the solutions-focused mission has embedded her loyalty and passion within the organization. The conversation also goes some way into exploring the potential and limitations of zero trust, and what it actually means to make progress towards safer environments. Along the way, our guest makes some interesting and quite unique arguments for why words matter, and why change is healthier through a philosophy centered on building. So to catch it all in this fascinating conversation, make sure to join us on Cloud Security Today!&lt;/p&gt;&lt;p&gt;Key Points From This Episode:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Tracy unpacks a brief history of FFRDCs and their role as objective technology advisors.&lt;/li&gt;&lt;li&gt;The two main areas of Tracy&apos;s work at MITRE; digital transformation of software factories, and data centricity in data environments.&lt;/li&gt;&lt;li&gt;Understanding MITRE&apos;s practical application and validation of the principles of zero trust theory. &lt;/li&gt;&lt;li&gt;Weighing the validity of the negative reputation that developers have when it comes to security.&lt;/li&gt;&lt;li&gt;Issues with the terms DevOps, DevSecOps, and SecDevOps, and the overloading and rushing that often happens on security teams. &lt;/li&gt;&lt;li&gt;Why Tracy prioritizes &apos;culture building&apos; over &apos;culture change&apos; when thinking about progress. &lt;/li&gt;&lt;li&gt;Leading teams, modeling behaviors, and realistic expectations for human error. &lt;/li&gt;&lt;li&gt;Tools and safety nets in the cloud-native approach; Tracy&apos;s perspective on how much value to assign to these.&lt;/li&gt;&lt;li&gt;Why the mission at MITRE initially piqued, and subsequently retained, Tracy&apos;s interest! &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Tweetables:&lt;/p&gt;&lt;p&gt;“It’s not a recipe. It&apos;s not five things you have to do. It&apos;s understanding the principles and then applying them, being able to audit them, and validate consistently that they&apos;re happening. MITRE does both sides of that.” — &lt;a href=&quot;https://twitter.com/tracybannon?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@TracyBannon&lt;/a&gt; [0:07:44]&lt;/p&gt;&lt;p&gt;“Our job is not to land and expand. It’s impact. At all costs, it&apos;s to make impact. If it&apos;s one person, or a half of that person, it&apos;s really defined by the ability to keep the US safe.” — &lt;a href=&quot;https://twitter.com/tracybannon?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@TracyBannon&lt;/a&gt; [0:09:39]&lt;/p&gt;&lt;p&gt;Links Mentioned in Today’s Episode:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/tracylbannon/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Tracy Bannon on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://twitter.com/tracybannon?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Tracy Bannon on Twitter&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.mitre.org/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;MITRE Corporation&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.audible.com/pd/Revelation-Audiobook/B08W24H8NK&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;em&gt;Revelation&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.amazon.com/Kill-Chain-Defending-America-High-Tech/dp/031653353X&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;em&gt;The Kill Chain&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.amazon.com/Zero-Trust-Security-Enterprise-Guide/dp/148426701X&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;em&gt;Zero Trust Security&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.amazon.com/Software-Architect-Elevator-Redefining-Architects/dp/1492077542&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;em&gt;The Software Architect Elevator&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:40:35</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>6</itunes:episode><itunes:title>MITRE + Cloud</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The New SEC Rule]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>In this episode, Special Advisor for Cyber Risk at the NACD, Christopher Hetner, returns to the show to discuss the new SEC cybersecurity rules. Chris has over 25 years of experience in cybersecurity, helping protect industries, infrastructures, and economies, serving in roles including as SVP of Information Security at Citi, Senior Cybersecurity Advisor to the Chairman of the US SEC, Executive Member of IANS, the National Board Director of the Society of Hispanic Professional Engineers, Senior Advisor for the Chertoff Group, Senior Advisor to the CEO of Stuart Levine &amp; Associates, and Co-Chair of Nasdaq Cybersecurity and Privacy.<br /><br /></p><p>Today, Chris talks about the developments since January 2023, the timeframe requirements in practice, and normalizing cybersecurity incidents as business-as-usual. What is Inline XBRL? Learn how startups could prepare themselves for these changes, the scope of disclosure, and how risk management strategies might evolve to address Cloud-specific threats.<br /> </p><p><b>Timestamp Segments</b></p><p>·       [02:36] What has changed since January?</p><p>·       [06:49] Why things changed.</p><p>·       [08:51] Was it a good move?</p><p>·       [12:27] Determining the materiality of cybersecurity incidents “without unreasonable delay.”</p><p>·       [17:49] Is 4 days enough?</p><p>·       [22:19] The scope of disclosure.</p><p>·       [24:09] Normalizing cybersecurity incidents.</p><p>·       [26:24] Moving toward real-time monitoring.</p><p>·       [28:52] Is insurance becoming a forcing function?</p><p>·       [32:18] Evolving risk management strategies.</p><p>·       [36:05] Third-party disclosure requirements</p><p>·       [39:51] How do startups prepare?</p><p>·       [41:52] What is Inline XBRL?</p><p>·       [42:54] Inline XBRL to 8-k.</p><p>·       [43:30] How the tagging requirement impact the disclosure process.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “The magnitude of these events is the percentage of the event relative to revenue.”</p><p>·       “We’re going to see market forces drive these safety standards within our enterprises.”</p><p><b> </b></p><p><b>Relevant Links</b></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/christopher-hetner-7969758/" rel="noopener noreferrer nofollow">Christopher Hetner</a></p><p> </p><p><b>Resources:</b></p><p><a href="https://www.sec.gov/news/press-release/2023-139" rel="noopener noreferrer nofollow">https://www.sec.gov/news/press-release/2023-139</a>.</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-13962806</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 20 Nov 2023 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/ef171ed72668d2fe6c60a40a8dbb6d3a1b2cd14c60c09491c03943a10c1b650e/eyJlcGlzb2RlSWQiOiI1NWU1NzEwNC1lNGUyLTQwZjYtYmJkNS1kYzA2ZTMzNGJlZTEiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNTVlNTcxMDQtZTRlMi00MGY2LWJiZDUtZGMwNmUzMzRiZWUxLzEzOTYyODA2LXRoZS1uZXctc2VjLXJ1bGUubXAzIn0=.mp3" length="33383694" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In this episode, Special Advisor for Cyber Risk at the NACD, Christopher Hetner, returns to the show to discuss the new SEC cybersecurity rules. Chris has over 25 years of experience in cybersecurity, helping protect industries, infrastructures, and economies, serving in roles including as SVP of Information Security at Citi, Senior Cybersecurity Advisor to the Chairman of the US SEC, Executive Member of IANS, the National Board Director of the Society of Hispanic Professional Engineers, Senior Advisor for the Chertoff Group, Senior Advisor to the CEO of Stuart Levine &amp;amp; Associates, and Co-Chair of Nasdaq Cybersecurity and Privacy.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Today, Chris talks about the developments since January 2023, the timeframe requirements in practice, and normalizing cybersecurity incidents as business-as-usual. What is Inline XBRL? Learn how startups could prepare themselves for these changes, the scope of disclosure, and how risk management strategies might evolve to address Cloud-specific threats.&lt;br /&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:36] What has changed since January?&lt;/p&gt;&lt;p&gt;·       [06:49] Why things changed.&lt;/p&gt;&lt;p&gt;·       [08:51] Was it a good move?&lt;/p&gt;&lt;p&gt;·       [12:27] Determining the materiality of cybersecurity incidents “without unreasonable delay.”&lt;/p&gt;&lt;p&gt;·       [17:49] Is 4 days enough?&lt;/p&gt;&lt;p&gt;·       [22:19] The scope of disclosure.&lt;/p&gt;&lt;p&gt;·       [24:09] Normalizing cybersecurity incidents.&lt;/p&gt;&lt;p&gt;·       [26:24] Moving toward real-time monitoring.&lt;/p&gt;&lt;p&gt;·       [28:52] Is insurance becoming a forcing function?&lt;/p&gt;&lt;p&gt;·       [32:18] Evolving risk management strategies.&lt;/p&gt;&lt;p&gt;·       [36:05] Third-party disclosure requirements&lt;/p&gt;&lt;p&gt;·       [39:51] How do startups prepare?&lt;/p&gt;&lt;p&gt;·       [41:52] What is Inline XBRL?&lt;/p&gt;&lt;p&gt;·       [42:54] Inline XBRL to 8-k.&lt;/p&gt;&lt;p&gt;·       [43:30] How the tagging requirement impact the disclosure process.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “The magnitude of these events is the percentage of the event relative to revenue.”&lt;/p&gt;&lt;p&gt;·       “We’re going to see market forces drive these safety standards within our enterprises.”&lt;/p&gt;&lt;p&gt;&lt;b&gt; &lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/christopher-hetner-7969758/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Christopher Hetner&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Resources:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.sec.gov/news/press-release/2023-139&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.sec.gov/news/press-release/2023-139&lt;/a&gt;.&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:46:16</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>11</itunes:episode><itunes:title>The New SEC Rule</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Zero trust with no FUD]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In today’s episode, the Creator of Zero Trust, John Kindervag, joins Matt on the show to discuss implementing Zero Trust in your organization. While at Forrester Research in 2010, John developed Zero Trust, promising adequate and effective protection of an organization’s most valuable assets.</p><p>Today, John talks about the driving force behind Zero Trust, the concept of the Protect Surface, and Kipling Method Policies. Why is trust a vulnerability? Hear about Zero Trust, Shadow IT, and get John’s recommended resources.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [02:20] About John.</p><p>·       [05:29] How does John define Zero Trust?</p><p>·       [07:45] Why is trust a vulnerability?</p><p>·       [09:56] The Protect Surface.</p><p>·       [12:32] Kipling Method Policies.</p><p>·       [17:22] The roadmap to Zero Trust at scale.</p><p>·       [22:56] It’s the inspection that matters.</p><p>·       [28:26] Zero Trust in the Cloud.</p><p>·       [31:33] Shadow IT.</p><p>·       [38:54] Tracking specific metrics.</p><p>·       [40:58] John’s resource recommendations.</p><p> </p><p><b>Notable Quote</b></p><p>"We can never stop cyber attacks from happening, but we can stop them from being successful.”<br /><br /><b>Relevant Links</b></p><p>Recommended Reading:       <br /><a href="https://www.paloaltonetworks.com/blog/2020/04/network-zero-trust-learning-curve/" rel="noopener noreferrer nofollow">The Zero Trust Learning Curve</a>.<br /><a href="https://www.amazon.com/Antifragile-Things-That-Disorder-Incerto-ebook/dp/B0083DJWGO" rel="noopener noreferrer nofollow">Antifragile</a>, by Nassim Nicholas Taleb.<br /> <a href="https://www.amazon.com/Grand-Strategy-John-Lewis-Gaddis/dp/1594203512" rel="noopener noreferrer nofollow">On Grand Strategy</a>, by John Gaddis.<br /><a href="https://www.amazon.com/Winning-FastTime-Competitive-Advantage-Prometheus/dp/0971159149" rel="noopener noreferrer nofollow">Winning in FastTime</a>, by John Warden.</p><p>LinkedIn:         <a href="https://www.linkedin.com/in/john-kindervag-40572b1" rel="noopener noreferrer nofollow">https://www.linkedin.com/in/john-kindervag-40572b1</a></p><p>ISMG:              <a href="https://ismg.io/" rel="noopener noreferrer nofollow">https://ismg.io</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-10957455</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Thu, 21 Jul 2022 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/619ebc334fe963ba2006c00faf9931ac7c51157e685005ccaf213fea630afa3d/eyJlcGlzb2RlSWQiOiI0MTRkMGEwNS1hMjM0LTRlYjEtYTg3ZC0xZDdiNzQ2NWRhNmYiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNDE0ZDBhMDUtYTIzNC00ZWIxLWE4N2QtMWQ3Yjc0NjVkYTZmLzEwOTU3NDU1LXplcm8tdHJ1c3Qtd2l0aC1uby1mdWQubXAzIn0=.mp3" length="33493379" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In today’s episode, the Creator of Zero Trust, John Kindervag, joins Matt on the show to discuss implementing Zero Trust in your organization. While at Forrester Research in 2010, John developed Zero Trust, promising adequate and effective protection of an organization’s most valuable assets.&lt;/p&gt;&lt;p&gt;Today, John talks about the driving force behind Zero Trust, the concept of the Protect Surface, and Kipling Method Policies. Why is trust a vulnerability? Hear about Zero Trust, Shadow IT, and get John’s recommended resources.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:20] About John.&lt;/p&gt;&lt;p&gt;·       [05:29] How does John define Zero Trust?&lt;/p&gt;&lt;p&gt;·       [07:45] Why is trust a vulnerability?&lt;/p&gt;&lt;p&gt;·       [09:56] The Protect Surface.&lt;/p&gt;&lt;p&gt;·       [12:32] Kipling Method Policies.&lt;/p&gt;&lt;p&gt;·       [17:22] The roadmap to Zero Trust at scale.&lt;/p&gt;&lt;p&gt;·       [22:56] It’s the inspection that matters.&lt;/p&gt;&lt;p&gt;·       [28:26] Zero Trust in the Cloud.&lt;/p&gt;&lt;p&gt;·       [31:33] Shadow IT.&lt;/p&gt;&lt;p&gt;·       [38:54] Tracking specific metrics.&lt;/p&gt;&lt;p&gt;·       [40:58] John’s resource recommendations.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quote&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&quot;We can never stop cyber attacks from happening, but we can stop them from being successful.”&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Recommended Reading:       &lt;br /&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/blog/2020/04/network-zero-trust-learning-curve/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;The Zero Trust Learning Curve&lt;/a&gt;.&lt;br /&gt;&lt;a href=&quot;https://www.amazon.com/Antifragile-Things-That-Disorder-Incerto-ebook/dp/B0083DJWGO&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Antifragile&lt;/a&gt;, by Nassim Nicholas Taleb.&lt;br /&gt; &lt;a href=&quot;https://www.amazon.com/Grand-Strategy-John-Lewis-Gaddis/dp/1594203512&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;On Grand Strategy&lt;/a&gt;, by John Gaddis.&lt;br /&gt;&lt;a href=&quot;https://www.amazon.com/Winning-FastTime-Competitive-Advantage-Prometheus/dp/0971159149&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Winning in FastTime&lt;/a&gt;, by John Warden.&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/john-kindervag-40572b1&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://www.linkedin.com/in/john-kindervag-40572b1&lt;/a&gt;&lt;/p&gt;&lt;p&gt;ISMG:              &lt;a href=&quot;https://ismg.io/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://ismg.io&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:46:25</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>8</itunes:episode><itunes:title>Zero trust with no FUD</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[From GTA to MFA]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this conversation, <a href="https://www.linkedin.com/in/jnicoledove/" rel="noopener noreferrer nofollow">Nicole Dove</a> shares her unique journey into the cybersecurity field, highlighting her transition from a finance and audit background to becoming a leader in information security at Riot Games. She discusses the importance of continuous learning, the challenges of writing a book on cybersecurity, and the evolving role of Business Information Security Officers (BISOs) in aligning security with business goals. Nicole emphasizes the need for innovative problem-solving and relationship management in cybersecurity, while also reflecting on her personal routines for maintaining sharpness in her role.</p><p><br /><br /></p>]]></description><guid isPermaLink="false">Buzzsprout-18155126</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sat, 08 Nov 2025 18:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/9798949c5569248d6da941473dfaefc036a53250da56096d1d9407157eeb06ba/eyJlcGlzb2RlSWQiOiIwN2NmYzc4YS0zZDgyLTQzYjAtYjJlNi05MTYyZmExZGJjZGIiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMDdjZmM3OGEtM2Q4Mi00M2IwLWIyZTYtOTE2MmZhMWRiY2RiLzE4MTU1MTI2LWZyb20tZ3RhLXRvLW1mYS5tcDMifQ==.mp3" length="32506421" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this conversation, &lt;a href=&quot;https://www.linkedin.com/in/jnicoledove/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Nicole Dove&lt;/a&gt; shares her unique journey into the cybersecurity field, highlighting her transition from a finance and audit background to becoming a leader in information security at Riot Games. She discusses the importance of continuous learning, the challenges of writing a book on cybersecurity, and the evolving role of Business Information Security Officers (BISOs) in aligning security with business goals. Nicole emphasizes the need for innovative problem-solving and relationship management in cybersecurity, while also reflecting on her personal routines for maintaining sharpness in her role.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:45:03</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>5</itunes:season><itunes:episode>8</itunes:episode><itunes:title>From GTA to MFA</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Open Source Security: A Deep Dive]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>On this episode, the Co-Founder and CEO of Endor Labs, Varun Badhwar, joins Matt to talk about software supply chain security. Varun has a proven track record of building and leading enterprise security companies across Product Strategy, Marketing, Technical Sales, and Customer Success functions. He serves as a Member of the Forbes Technology Council, a Board Member of Cowbell, a Board Advisor of ArmorCode, and the former Founder and CEO of RedLock.</p><p>Today, Varun talks about open source risks, how to identify and mitigate risks, and how to incentivize the use of security tools. Where can organizations start? Hear about SBOMs, security in the Cloud, and software security best practices.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [01:42] A bit about Varun.</p><p>·       [04:48] Identifying and mitigating risk.</p><p>·       [10:32] Where should organizations start?</p><p>·       [14:42] The SBOM.</p><p>·       [19:51] Industry standards and best practices.</p><p>·       [22:26] Cloud security.</p><p>·       [25:50] Endor Labs.</p><p>·       [29:52] Incentivizing using security tools.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “Select, secure, maintain, comply.”</p><p>·       “The first thing that drives a lot of security shifts is compliance.”</p><p> </p><p><b>Relevant Links</b></p><p>Website:          <a href="https://www.endorlabs.com/" rel="noopener noreferrer nofollow">www.endorlabs.com</a></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/vbadhwar" rel="noopener noreferrer nofollow">Varun Badhwar</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-12447025</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 21 Jun 2023 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/c0dc3a177ba4e12be3a05f142f77d4d7e58a91970ae1d35f06f0909e16640ed2/eyJlcGlzb2RlSWQiOiI3YjI4ZjkyMy02Mzg0LTQ3MGYtODYyMy03NTMxMGM2OWE5YzEiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvN2IyOGY5MjMtNjM4NC00NzBmLTg2MjMtNzUzMTBjNjlhOWMxLzEyNDQ3MDI1LW9wZW4tc291cmNlLXNlY3VyaXR5LWEtZGVlcC1kaXZlLm1wMyJ9.mp3" length="25009079" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, the Co-Founder and CEO of Endor Labs, Varun Badhwar, joins Matt to talk about software supply chain security. Varun has a proven track record of building and leading enterprise security companies across Product Strategy, Marketing, Technical Sales, and Customer Success functions. He serves as a Member of the Forbes Technology Council, a Board Member of Cowbell, a Board Advisor of ArmorCode, and the former Founder and CEO of RedLock.&lt;/p&gt;&lt;p&gt;Today, Varun talks about open source risks, how to identify and mitigate risks, and how to incentivize the use of security tools. Where can organizations start? Hear about SBOMs, security in the Cloud, and software security best practices.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:42] A bit about Varun.&lt;/p&gt;&lt;p&gt;·       [04:48] Identifying and mitigating risk.&lt;/p&gt;&lt;p&gt;·       [10:32] Where should organizations start?&lt;/p&gt;&lt;p&gt;·       [14:42] The SBOM.&lt;/p&gt;&lt;p&gt;·       [19:51] Industry standards and best practices.&lt;/p&gt;&lt;p&gt;·       [22:26] Cloud security.&lt;/p&gt;&lt;p&gt;·       [25:50] Endor Labs.&lt;/p&gt;&lt;p&gt;·       [29:52] Incentivizing using security tools.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “Select, secure, maintain, comply.”&lt;/p&gt;&lt;p&gt;·       “The first thing that drives a lot of security shifts is compliance.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website:          &lt;a href=&quot;https://www.endorlabs.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;www.endorlabs.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/vbadhwar&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Varun Badhwar&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:34:38</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>3</itunes:season><itunes:episode>6</itunes:episode><itunes:title>Open Source Security: A Deep Dive</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The world of purple teaming]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>This month, we welcome Eric Gagnon, Team Lead of Adversary Simulation, Purple Teaming, and Tradecraft Development at Desjardins. The conversation covers a wide range of topics related to cybersecurity, including purple teaming, red teaming, blue teaming, and Eric's journey in cybersecurity. Eric shares insights on certifications, threat hunting, cloud security, and the importance of knowledge exchange between red and blue teams. He also discusses the use of AI in cybersecurity and the need to stay sharp in the field.</p><p><b>Takeaways<br /></b><br /></p><ul><li>Purple teaming involves collaborative operations to exchange ideas, evaluate security controls, and test out tactics, techniques, and procedures (TTPs) real threat actors use.</li><li>Certifications in cybersecurity, such as Offensive Security Certified Professional (OSCP) and Offensive Security Certified Expert (OSCE), provide valuable knowledge and an edge in the field.</li><li>Threat hunting involves looking for a granular activity that may indicate a compromise, filtering out the noise, and focusing on the suspicious behavior of threat actors.</li><li>Cloud security requires automation, cyber hygiene, and visibility, focusing on prioritizing techniques and testing them against the enterprise's environment.</li><li>Knowledge exchange between red and blue teams during a purple team engagement is essential and should include a common language, centralized documentation, and reporting against the MITRE ATT&amp;CK framework.</li><li>Staying sharp in cybersecurity involves continuous learning, participation in CTFs, engaging with passionate individuals, and challenging oneself through talks, podcasts, and specialized training.</li></ul><p><b>Chapters<br /></b><br /></p><p>00:00<br />Introduction to Purple Teaming and Cybersecurity Journey</p><p>08:09<br />Certifications and Insights in Cybersecurity</p><p>15:08<br />Threat Hunting and Granular Activity Detection</p><p>35:02<br />Knowledge Exchange in Purple Teaming: Red and Blue Collaboration</p><p>39:57<br />Staying Sharp in Cybersecurity: Continuous Learning and Engagement</p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-15160110</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sun, 21 Jul 2024 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/bfdb6467ef94d152d4ec99ba1c484567a449d632e20b5b6da2585c2446694f42/eyJlcGlzb2RlSWQiOiI1OWE4NDA0Zi02MjNlLTQ4OTktODhlZS0xMDk0ZDYxZmRkZTMiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNTlhODQwNGYtNjIzZS00ODk5LTg4ZWUtMTA5NGQ2MWZkZGUzLzE1MTYwMTEwLXRoZS13b3JsZC1vZi1wdXJwbGUtdGVhbWluZy5tcDMifQ==.mp3" length="33520226" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;This month, we welcome Eric Gagnon, Team Lead of Adversary Simulation, Purple Teaming, and Tradecraft Development at Desjardins. The conversation covers a wide range of topics related to cybersecurity, including purple teaming, red teaming, blue teaming, and Eric&apos;s journey in cybersecurity. Eric shares insights on certifications, threat hunting, cloud security, and the importance of knowledge exchange between red and blue teams. He also discusses the use of AI in cybersecurity and the need to stay sharp in the field.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Takeaways&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Purple teaming involves collaborative operations to exchange ideas, evaluate security controls, and test out tactics, techniques, and procedures (TTPs) real threat actors use.&lt;/li&gt;&lt;li&gt;Certifications in cybersecurity, such as Offensive Security Certified Professional (OSCP) and Offensive Security Certified Expert (OSCE), provide valuable knowledge and an edge in the field.&lt;/li&gt;&lt;li&gt;Threat hunting involves looking for a granular activity that may indicate a compromise, filtering out the noise, and focusing on the suspicious behavior of threat actors.&lt;/li&gt;&lt;li&gt;Cloud security requires automation, cyber hygiene, and visibility, focusing on prioritizing techniques and testing them against the enterprise&apos;s environment.&lt;/li&gt;&lt;li&gt;Knowledge exchange between red and blue teams during a purple team engagement is essential and should include a common language, centralized documentation, and reporting against the MITRE ATT&amp;amp;CK framework.&lt;/li&gt;&lt;li&gt;Staying sharp in cybersecurity involves continuous learning, participation in CTFs, engaging with passionate individuals, and challenging oneself through talks, podcasts, and specialized training.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Chapters&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;00:00&lt;br /&gt;Introduction to Purple Teaming and Cybersecurity Journey&lt;/p&gt;&lt;p&gt;08:09&lt;br /&gt;Certifications and Insights in Cybersecurity&lt;/p&gt;&lt;p&gt;15:08&lt;br /&gt;Threat Hunting and Granular Activity Detection&lt;/p&gt;&lt;p&gt;35:02&lt;br /&gt;Knowledge Exchange in Purple Teaming: Red and Blue Collaboration&lt;/p&gt;&lt;p&gt;39:57&lt;br /&gt;Staying Sharp in Cybersecurity: Continuous Learning and Engagement&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:46:27</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>9</itunes:episode><itunes:title>The world of purple teaming</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Building a SaaS security program]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>This month, we welcome Swathi Joshi, VP of SaaS Cloud Security at Oracle, to discuss key moments and decisions that shaped her career path, including rejections from Google and Twitter. She emphasizes the importance of learning from rejection and seeking feedback to improve. Swathi also shares insights on the role of mentors and advises on finding and working with mentors. In the second part of the conversation, she discusses building a SaaS security program as an enterprise consumer of SaaS. She highlights the importance of addressing misconfigurations, ensuring visibility and access control, and meeting compliance needs. <br /><br />Swathi also suggests asking about backup and exploring risk scoring for vendors. In this conversation, Swathi discusses best practices for managing vendor risk, vulnerability management through third parties, and incident response in SaaS applications. She also shares insights on privacy operations and critical privacy controls in SaaS. Swathi emphasizes the importance of collaboration, robust incident response plans, and data lifecycle management. She also highlights the need for identity and access control and the challenges of normalizing incident response across different SaaS platforms. Swathi's leadership philosophy is collaborative and pace-setting, and she emphasizes the importance of stress management.<br /><br /><b>Takeaways</b></p><ul><li>Learn from rejection and seek feedback to improve</li><li>Build long-term relationships with mentors and create a personal advisory board</li><li>When building a SaaS security program, focus on addressing misconfigurations, ensuring visibility and access control, and meeting compliance needs</li><li>Ask about backup and explore risk scoring for vendors. </li><li>Managing vendor risk requires close collaboration with privacy, legal, and contract partners.</li><li>Incident response in SaaS applications shares foundational principles with traditional on-prem software, but there are differences in data snapshotting and managing dependencies.</li><li>Privacy operations can be operationalized by focusing on identity, access control, and data lifecycle management.</li><li>Leadership should be collaborative, open to ideas, and adaptable to different situations.</li><li>Stress management is crucial for effective leadership and should be acknowledged and actively managed.</li></ul><p><b>Links</b><br /><a href="https://github.com/firstprinciplesecurity/Privacy-Operations-Template" rel="noopener noreferrer nofollow">Privacy Operations Template</a><br /><a href="https://www.linkedin.com/in/joshiswathi/" rel="noopener noreferrer nofollow">Swathi's LI Profile</a></p><p><b>Chapters</b><br /><br />00:00 Navigating Career Challenges and Learning from Rejection<br />08:13 The Role of Mentors in Career Growth<br />15:26 Building a Strong SaaS Security Program<br />21:20 Meeting Compliance Needs in a SaaS Environment<br />21:56 Backup and Risk Scoring for SaaS Vendors<br />22:38 Managing Vendor Risk<br />26:12 Improving Vulnerability Management through Third Parties<br />26:35 Navigating Incident Response in SaaS Applications<br />34:03 Operationalizing Privacy Operations in SaaS<br />40:50 The Importance of Collaboration in Leadership<br />43:04 Managing Stress for Effective Leadership<br /><br /><br /></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-15208647</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sun, 23 Jun 2024 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/10645d4f7f05a5039d9d99fc42d49b312687ab8543b69362abcf85b1213c2a86/eyJlcGlzb2RlSWQiOiJlMGY4N2ViMC05MTUzLTRkODgtOWY2OS03YzZmOTVmODYxOGUiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZTBmODdlYjAtOTE1My00ZDg4LTlmNjktN2M2Zjk1Zjg2MThlLzE1MjA4NjQ3LWJ1aWxkaW5nLWEtc2Fhcy1zZWN1cml0eS1wcm9ncmFtLm1wMyJ9.mp3" length="36460892" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;This month, we welcome Swathi Joshi, VP of SaaS Cloud Security at Oracle, to discuss key moments and decisions that shaped her career path, including rejections from Google and Twitter. She emphasizes the importance of learning from rejection and seeking feedback to improve. Swathi also shares insights on the role of mentors and advises on finding and working with mentors. In the second part of the conversation, she discusses building a SaaS security program as an enterprise consumer of SaaS. She highlights the importance of addressing misconfigurations, ensuring visibility and access control, and meeting compliance needs. &lt;br /&gt;&lt;br /&gt;Swathi also suggests asking about backup and exploring risk scoring for vendors. In this conversation, Swathi discusses best practices for managing vendor risk, vulnerability management through third parties, and incident response in SaaS applications. She also shares insights on privacy operations and critical privacy controls in SaaS. Swathi emphasizes the importance of collaboration, robust incident response plans, and data lifecycle management. She also highlights the need for identity and access control and the challenges of normalizing incident response across different SaaS platforms. Swathi&apos;s leadership philosophy is collaborative and pace-setting, and she emphasizes the importance of stress management.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Learn from rejection and seek feedback to improve&lt;/li&gt;&lt;li&gt;Build long-term relationships with mentors and create a personal advisory board&lt;/li&gt;&lt;li&gt;When building a SaaS security program, focus on addressing misconfigurations, ensuring visibility and access control, and meeting compliance needs&lt;/li&gt;&lt;li&gt;Ask about backup and explore risk scoring for vendors. &lt;/li&gt;&lt;li&gt;Managing vendor risk requires close collaboration with privacy, legal, and contract partners.&lt;/li&gt;&lt;li&gt;Incident response in SaaS applications shares foundational principles with traditional on-prem software, but there are differences in data snapshotting and managing dependencies.&lt;/li&gt;&lt;li&gt;Privacy operations can be operationalized by focusing on identity, access control, and data lifecycle management.&lt;/li&gt;&lt;li&gt;Leadership should be collaborative, open to ideas, and adaptable to different situations.&lt;/li&gt;&lt;li&gt;Stress management is crucial for effective leadership and should be acknowledged and actively managed.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Links&lt;/b&gt;&lt;br /&gt;&lt;a href=&quot;https://github.com/firstprinciplesecurity/Privacy-Operations-Template&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Privacy Operations Template&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;https://www.linkedin.com/in/joshiswathi/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Swathi&apos;s LI Profile&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Chapters&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;00:00 Navigating Career Challenges and Learning from Rejection&lt;br /&gt;08:13 The Role of Mentors in Career Growth&lt;br /&gt;15:26 Building a Strong SaaS Security Program&lt;br /&gt;21:20 Meeting Compliance Needs in a SaaS Environment&lt;br /&gt;21:56 Backup and Risk Scoring for SaaS Vendors&lt;br /&gt;22:38 Managing Vendor Risk&lt;br /&gt;26:12 Improving Vulnerability Management through Third Parties&lt;br /&gt;26:35 Navigating Incident Response in SaaS Applications&lt;br /&gt;34:03 Operationalizing Privacy Operations in SaaS&lt;br /&gt;40:50 The Importance of Collaboration in Leadership&lt;br /&gt;43:04 Managing Stress for Effective Leadership&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:50:33</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>8</itunes:episode><itunes:title>Building a SaaS security program</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Cloud Threat Report Vol 6]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>This episode of the <em>Cloud Security Today</em> podcast welcomes back favorite special guests Jay Chen and Nathaniel “Q” Quist to unpack the latest Cloud Threat Report. Join host Matt Chiodi as he shares insights from the report and analyzes the current state of cloud security.</p><p>Beginning with an in-depth look at Identity and Access Management (IAM) in cloud security, the guests talk about the latest changes in cloud security. They discuss the report’s findings on permissions and what cloud systems providers are currently doing (or not doing) to help keep cloud data secure. At the end of the episode, Jay and Q give tips on how to stay up-to-date on developments in the cloud security landscape and reveal the next projects that they’re working on. </p><p>If you enjoyed this episode, you can show your support for the podcast by rating and reviewing it and by subscribing to <em>Cloud Security Today </em>wherever you listen to podcasts. </p><p> </p><p>Show Notes/Timestamps</p><p>[2:11] Matt welcomes repeat guests Jay and Q onto the show</p><p>[3:36] So, what’s changed for Identity and Access Management over the last year? </p><p>[8:05] Jay lays out what makes good cloud governance so difficult</p><p>[11:50] Complicating factors in cloud security</p><p>[14:22] What does the research show about permissions and over permissions on cloud systems? </p><p>[17:28] “When you can’t figure out what to do, you add more permissions:” How permissions multiply</p><p>[20:19] Are cloud service providers helping or hindering cloud security?</p><p>[24:03] Debating the Infrastructure as Code framework</p><p>[28:13] Q breaks down the Cloud Threat Actor Index </p><p>[31:32] Q’s top five bad actors on the cloud security landscape</p><p>[35:11] Jay gives his recommendations for IAM</p><p>[39:55] How you can stay up-to-date on the latest developments in cloud security</p><p>[42:10] The next projects that Jay and Q are working on</p><p><br />Links</p><p>Check out this episode’s sponsor, <a href="https://www.prismacloud.io/" rel="noopener noreferrer nofollow">Prisma Cloud</a></p><p><a href="https://unit42.paloaltonetworks.com/#reports" rel="noopener noreferrer nofollow">Unit 42 reports</a></p><p><a href="https://unit42.paloaltonetworks.com/iam-deescalate/" rel="noopener noreferrer nofollow">IAM-Deescalate Tool</a></p><p><a href="https://cloudseclist.com/" rel="noopener noreferrer nofollow">Cloud Sec List</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-11414430</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 21 Dec 2022 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/cd303b97c9568189d10083b88292788c88ce9d82f81e4b49795b3a9b2ebba95f/eyJlcGlzb2RlSWQiOiJjMjBhNjg0Yi0zYTg1LTQ2YzMtYWUyZS1iNDE4ODIzM2UzMWIiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvYzIwYTY4NGItM2E4NS00NmMzLWFlMmUtYjQxODgyMzNlMzFiLzExNDE0NDMwLWNsb3VkLXRocmVhdC1yZXBvcnQtdm9sLTYubXAzIn0=.mp3" length="32331395" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;This episode of the &lt;em&gt;Cloud Security Today&lt;/em&gt; podcast welcomes back favorite special guests Jay Chen and Nathaniel “Q” Quist to unpack the latest Cloud Threat Report. Join host Matt Chiodi as he shares insights from the report and analyzes the current state of cloud security.&lt;/p&gt;&lt;p&gt;Beginning with an in-depth look at Identity and Access Management (IAM) in cloud security, the guests talk about the latest changes in cloud security. They discuss the report’s findings on permissions and what cloud systems providers are currently doing (or not doing) to help keep cloud data secure. At the end of the episode, Jay and Q give tips on how to stay up-to-date on developments in the cloud security landscape and reveal the next projects that they’re working on. &lt;/p&gt;&lt;p&gt;If you enjoyed this episode, you can show your support for the podcast by rating and reviewing it and by subscribing to &lt;em&gt;Cloud Security Today &lt;/em&gt;wherever you listen to podcasts. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Show Notes/Timestamps&lt;/p&gt;&lt;p&gt;[2:11] Matt welcomes repeat guests Jay and Q onto the show&lt;/p&gt;&lt;p&gt;[3:36] So, what’s changed for Identity and Access Management over the last year? &lt;/p&gt;&lt;p&gt;[8:05] Jay lays out what makes good cloud governance so difficult&lt;/p&gt;&lt;p&gt;[11:50] Complicating factors in cloud security&lt;/p&gt;&lt;p&gt;[14:22] What does the research show about permissions and over permissions on cloud systems? &lt;/p&gt;&lt;p&gt;[17:28] “When you can’t figure out what to do, you add more permissions:” How permissions multiply&lt;/p&gt;&lt;p&gt;[20:19] Are cloud service providers helping or hindering cloud security?&lt;/p&gt;&lt;p&gt;[24:03] Debating the Infrastructure as Code framework&lt;/p&gt;&lt;p&gt;[28:13] Q breaks down the Cloud Threat Actor Index &lt;/p&gt;&lt;p&gt;[31:32] Q’s top five bad actors on the cloud security landscape&lt;/p&gt;&lt;p&gt;[35:11] Jay gives his recommendations for IAM&lt;/p&gt;&lt;p&gt;[39:55] How you can stay up-to-date on the latest developments in cloud security&lt;/p&gt;&lt;p&gt;[42:10] The next projects that Jay and Q are working on&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Links&lt;/p&gt;&lt;p&gt;Check out this episode’s sponsor, &lt;a href=&quot;https://www.prismacloud.io/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Prisma Cloud&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://unit42.paloaltonetworks.com/#reports&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Unit 42 reports&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://unit42.paloaltonetworks.com/iam-deescalate/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;IAM-Deescalate Tool&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://cloudseclist.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Cloud Sec List&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:44:48</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>13</itunes:episode><itunes:title>Cloud Threat Report Vol 6</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Cybersecurity's secret weapon]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>In this episode, Jerich Beason, CISO at WM, joins the show to discuss becoming a CISO. Before joining WM, Jerich served in various roles at Lockheed Martin, RSA, Capital One, AECOM, and Deloitte.<br /><br /></p><p>Jerich talks about how he tailored his roles throughout his career, learning communication soft skills and his passion for sharing with others. <br /><br />Hear about how AI affects leadership, how Jerich would change the cybersecurity industry, and the true value of vendors (it's positive!).<br /><br /></p><p><b>Timestamp Segments</b></p><p>·       [02:51] When Jerich knew he wanted to be a CISO.</p><p>·       [04:52] Tailoring the roles.</p><p>·       [06:02] What is Jerich most proud of?</p><p>·       [07:17] Jerich’s best advice.</p><p>·       [13:22] Transitioning away from geek-speak.</p><p>·       [17:29] When Jerich developed the passion.</p><p>·       [20:28] The PRIME framework.</p><p>·       [25:20] What should be talked about with AI?</p><p>·       [29:09] What would Jerich change about the cybersecurity industry?</p><p>·       [30:33] Hiring the right people.</p><p>·       [33:37] How Jerich stays sharp.</p><p>·       [35:06] The value of vendors.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “Not every issue warrants a ‘sky is falling’ alert.”</p><p>·       “When it comes time to leave, leave a legend.”</p><p>·       “We don’t exist without vendors.”</p><p> </p><p><b>Relevant Links</b></p><p>Website:          <a href="https://www.wm.com/" rel="noopener noreferrer nofollow">www.wm.com</a></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/jerich-beason" rel="noopener noreferrer nofollow">Jerich Beason</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-14632651</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 20 Mar 2024 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/70bd42261bda3e235b4f6294faaa65db919dd3da96703016c95f061b5b199ab8/eyJlcGlzb2RlSWQiOiIwZGYyMzI0Yi0yNTU3LTQzYzctOTNhNi1kMjAxY2ViYmY1NDciLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMGRmMjMyNGItMjU1Ny00M2M3LTkzYTYtZDIwMWNlYmJmNTQ3LzE0NjMyNjUxLWN5YmVyc2VjdXJpdHktcy1zZWNyZXQtd2VhcG9uLm1wMyJ9.mp3" length="31097274" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;In this episode, Jerich Beason, CISO at WM, joins the show to discuss becoming a CISO. Before joining WM, Jerich served in various roles at Lockheed Martin, RSA, Capital One, AECOM, and Deloitte.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Jerich talks about how he tailored his roles throughout his career, learning communication soft skills and his passion for sharing with others. &lt;br /&gt;&lt;br /&gt;Hear about how AI affects leadership, how Jerich would change the cybersecurity industry, and the true value of vendors (it&apos;s positive!).&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:51] When Jerich knew he wanted to be a CISO.&lt;/p&gt;&lt;p&gt;·       [04:52] Tailoring the roles.&lt;/p&gt;&lt;p&gt;·       [06:02] What is Jerich most proud of?&lt;/p&gt;&lt;p&gt;·       [07:17] Jerich’s best advice.&lt;/p&gt;&lt;p&gt;·       [13:22] Transitioning away from geek-speak.&lt;/p&gt;&lt;p&gt;·       [17:29] When Jerich developed the passion.&lt;/p&gt;&lt;p&gt;·       [20:28] The PRIME framework.&lt;/p&gt;&lt;p&gt;·       [25:20] What should be talked about with AI?&lt;/p&gt;&lt;p&gt;·       [29:09] What would Jerich change about the cybersecurity industry?&lt;/p&gt;&lt;p&gt;·       [30:33] Hiring the right people.&lt;/p&gt;&lt;p&gt;·       [33:37] How Jerich stays sharp.&lt;/p&gt;&lt;p&gt;·       [35:06] The value of vendors.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “Not every issue warrants a ‘sky is falling’ alert.”&lt;/p&gt;&lt;p&gt;·       “When it comes time to leave, leave a legend.”&lt;/p&gt;&lt;p&gt;·       “We don’t exist without vendors.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website:          &lt;a href=&quot;https://www.wm.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;www.wm.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/jerich-beason&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Jerich Beason&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:43:05</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>3</itunes:episode><itunes:title>Cybersecurity&apos;s secret weapon</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Pockets of Innovation]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Pockets of Innovation with John Chavanne</b></p><p><br /><b>Episode Summary</b></p><p>On this episode, Solutions Architect at Palo Alto Networks, John Chavanne, joins Matt to talk about his career of innovation. John’s career spans over 20 years at HSBC before transitioning into DevOps and Cloud Solutions at Palo Alto Networks.</p><p>Today, John talks about his career arc, transitioning to cloud, and the value of communities of practice groups. Where should organizations start with deploying a CNAP? Hear about the challenges with deploying cloud platforms, and John’s greatest accomplishments.</p><p> </p><p><b>Timestamp Segments</b></p><p>·       [01:30] About John.</p><p>·       [02:54] John’s career.</p><p>·       [05:47] What is something that cloud makes easier?</p><p>·       [07:09] Transitioning from network to DevOps and Cloud.</p><p>·       [10:15] Starting the move to cloud at HSBC.</p><p>·       [13:15] Cloud communities of practice.</p><p>·       [18:47] Sharing code.</p><p>·       [21:27] John’s biggest accomplishment.</p><p>·       [23:23] Prisma Cloud.</p><p>·       [26:25] Organizational challenges with deploying cloud platforms.</p><p>·       [29:41] Where to start with deploying a CNAP.</p><p>·       [33:54] How does John stay fresh?</p><p> </p><p><b>Notable Quotes</b></p><p>·       “You can test things out in the cloud and the price of failure is almost zero.”</p><p>·       “Innovation happens in pockets.”</p><p>·       “Reduce waste and build habits that reduce waste.”</p><p> </p><p><b>Relevant Links</b></p><p>Recommended reading:         <a href="https://www.amazon.com/Toyota-Way-Management-Principles-Manufacturer/dp/0070587477" rel="noopener noreferrer nofollow">The Toyota Way</a>.</p><p>                                                <a href="https://www.amazon.com/Kubernetes-Enterprise-Effectively-containerize-applications/dp/1803230037" rel="noopener noreferrer nofollow">Kubernetes - An Enterprise Guide</a>.</p><p>KodeKloud:     <a href="https://kodekloud.com/" rel="noopener noreferrer nofollow">https://kodekloud.com</a></p><p>Twitter:            <a href="https://twitter.com/jjchavanne" rel="noopener noreferrer nofollow">https://twitter.com/jjchavanne</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-11127558</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 21 Nov 2022 11:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/5ef1840118c72b2d514ac97200be979fefc1d95133acdc5b4006031bc428c70c/eyJlcGlzb2RlSWQiOiJkZmZhZWJlNS1jODU5LTRmNzctYmViMS04MzA1MmI3NWQ5MjciLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvZGZmYWViZTUtYzg1OS00Zjc3LWJlYjEtODMwNTJiNzVkOTI3LzExMTI3NTU4LXBvY2tldHMtb2YtaW5ub3ZhdGlvbi5tcDMifQ==.mp3" length="27894541" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Pockets of Innovation with John Chavanne&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;On this episode, Solutions Architect at Palo Alto Networks, John Chavanne, joins Matt to talk about his career of innovation. John’s career spans over 20 years at HSBC before transitioning into DevOps and Cloud Solutions at Palo Alto Networks.&lt;/p&gt;&lt;p&gt;Today, John talks about his career arc, transitioning to cloud, and the value of communities of practice groups. Where should organizations start with deploying a CNAP? Hear about the challenges with deploying cloud platforms, and John’s greatest accomplishments.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Timestamp Segments&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [01:30] About John.&lt;/p&gt;&lt;p&gt;·       [02:54] John’s career.&lt;/p&gt;&lt;p&gt;·       [05:47] What is something that cloud makes easier?&lt;/p&gt;&lt;p&gt;·       [07:09] Transitioning from network to DevOps and Cloud.&lt;/p&gt;&lt;p&gt;·       [10:15] Starting the move to cloud at HSBC.&lt;/p&gt;&lt;p&gt;·       [13:15] Cloud communities of practice.&lt;/p&gt;&lt;p&gt;·       [18:47] Sharing code.&lt;/p&gt;&lt;p&gt;·       [21:27] John’s biggest accomplishment.&lt;/p&gt;&lt;p&gt;·       [23:23] Prisma Cloud.&lt;/p&gt;&lt;p&gt;·       [26:25] Organizational challenges with deploying cloud platforms.&lt;/p&gt;&lt;p&gt;·       [29:41] Where to start with deploying a CNAP.&lt;/p&gt;&lt;p&gt;·       [33:54] How does John stay fresh?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “You can test things out in the cloud and the price of failure is almost zero.”&lt;/p&gt;&lt;p&gt;·       “Innovation happens in pockets.”&lt;/p&gt;&lt;p&gt;·       “Reduce waste and build habits that reduce waste.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Recommended reading:         &lt;a href=&quot;https://www.amazon.com/Toyota-Way-Management-Principles-Manufacturer/dp/0070587477&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;The Toyota Way&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;                                                &lt;a href=&quot;https://www.amazon.com/Kubernetes-Enterprise-Effectively-containerize-applications/dp/1803230037&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Kubernetes - An Enterprise Guide&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;KodeKloud:     &lt;a href=&quot;https://kodekloud.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://kodekloud.com&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Twitter:            &lt;a href=&quot;https://twitter.com/jjchavanne&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;https://twitter.com/jjchavanne&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:38:38</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>12</itunes:episode><itunes:title>Pockets of Innovation</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Building security natively]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>Originally recorded in September of 2021...today’s guest is Justin Berman, the Vice President of Infrastructure and IT and the CISO at Thirty Madison. Thirty Madison is aiming to be a platform that everyone can use to deal with their chronic healthcare needs. Justin’s main focus is on building out the teams that enable scaling. With his development background, Justin has some unique ideas when it comes to cloud security, which makes for a fascinating interview. You’ll walk away from this episode with a new perspective on how to build security into products from the start and a better understanding of how to transition smoothly from on-prem to the cloud.<br /><br /><b>Tweetables<br /></b>“I see security as an engineering problem. What I mean by that is not that there aren't things that you solve with process, or with policy, or training, but rather that in as many places as possible if you want to have a scaled effect within security, you need to write code to solve a problem.” — @justinmberman [0:06:03]<br /><br /><a href="https://www.linkedin.com/in/jmberman/" rel="noopener noreferrer nofollow">Justin Berman on LinkedIn</a></p><p><a href="https://itrevolution.com/the-phoenix-project/" rel="noopener noreferrer nofollow">Phoenix Project</a></p><p><a href="https://simonsinek.com/" rel="noopener noreferrer nofollow">Simon Sinek</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-10656794</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Sat, 21 May 2022 14:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/fc01a233bdbbb9feea7f05f8dc1cc44a12fe6a08f6c312b2160024d033f60b9a/eyJlcGlzb2RlSWQiOiJiYzZiNjZlOS1mMDA5LTRkMmYtYjA1NS01YWExMjAzYzgzYmEiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvYmM2YjY2ZTktZjAwOS00ZDJmLWIwNTUtNWFhMTIwM2M4M2JhLzEwNjU2Nzk0LWJ1aWxkaW5nLXNlY3VyaXR5LW5hdGl2ZWx5Lm1wMyJ9.mp3" length="33772981" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Originally recorded in September of 2021...today’s guest is Justin Berman, the Vice President of Infrastructure and IT and the CISO at Thirty Madison. Thirty Madison is aiming to be a platform that everyone can use to deal with their chronic healthcare needs. Justin’s main focus is on building out the teams that enable scaling. With his development background, Justin has some unique ideas when it comes to cloud security, which makes for a fascinating interview. You’ll walk away from this episode with a new perspective on how to build security into products from the start and a better understanding of how to transition smoothly from on-prem to the cloud.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Tweetables&lt;br /&gt;&lt;/b&gt;“I see security as an engineering problem. What I mean by that is not that there aren&apos;t things that you solve with process, or with policy, or training, but rather that in as many places as possible if you want to have a scaled effect within security, you need to write code to solve a problem.” — @justinmberman [0:06:03]&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://www.linkedin.com/in/jmberman/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Justin Berman on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://itrevolution.com/the-phoenix-project/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Phoenix Project&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://simonsinek.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Simon Sinek&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:46:43</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>2</itunes:season><itunes:episode>5</itunes:episode><itunes:title>Building security natively</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Cloud Immigration]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>The journey toward the cloud is filled with challenges, but the benefits it brings make the struggle worthwhile. Today we talk about all things cloud adoption with Rob Brown, CTO at the US Citizenship and Immigration Services Group. We jump in with some introductory comments about who the USCIS are and what they do, with Rob giving listeners an idea of his role within the organization. We hear about the massive move toward digitization at USCIS and some of the biggest challenges the organization is facing as far as cloud adoption. From there, our conversation touches on the benefits of a multi-cloud approach, how USCIS is implementing Zero Trust with regards to cloud security, and how microsegmentation fits into all of this. Tuning in, listeners will also learn about the metrics Rob uses to assess the process of cloud adoption at USCIS, how the shift to the cloud has helped address the issue of siloing, and the benefits of implementing a unified pipeline grounded by standardization. We wrap up with some current initiatives Rob is most occupied with before hearing about how he likes to stay sharp using an approach grounded in experimentation and testing. Rob is filled with insights to help keep teams robust and agile during sticky situations, so be sure to tune in and hear them all.<br /><br /><b>Tweetables</b><br />“We have got a very good security team and a pretty savvy group of application developers and infrastructure folks that take security and shift it as far to the left as possible.” — Rob Brown [0:17:19]<br /><br />“Standardization, to me, has been critical in creating some of these unified pipelines.” — Rob Brown [0:29:14]<br /><br /><b>Links Mentioned in Today’s Episode:</b></p><p><a href="https://www.linkedin.com/in/robbrown/" rel="noopener noreferrer nofollow"><b>Rob Brown on LinkedIn</b></a><b><br /></b><a href="https://www.uscis.gov/" rel="noopener noreferrer nofollow"><b>US Citizenship and Immigration Services</b></a><b><br /></b><a href="https://www.usajobs.gov/Search/Results?a=HSAB&amp;p=1" rel="noopener noreferrer nofollow"><b>Jobs at USCIS</b></a></p><p><br /></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-9525396</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 10 Nov 2021 15:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/c96853f1dc330911b37dcaa2df709b5cc7d462574dd691abf19a0fc0318d9010/eyJlcGlzb2RlSWQiOiIzNjMyMTY5ZS05ZTVkLTRhZDItODdiMS04OTU3NjVjM2E2YzAiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMzYzMjE2OWUtOWU1ZC00YWQyLTg3YjEtODk1NzY1YzNhNmMwLzk1MjUzOTYtY2xvdWQtaW1taWdyYXRpb24ubXAzIn0=.mp3" length="25108494" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The journey toward the cloud is filled with challenges, but the benefits it brings make the struggle worthwhile. Today we talk about all things cloud adoption with Rob Brown, CTO at the US Citizenship and Immigration Services Group. We jump in with some introductory comments about who the USCIS are and what they do, with Rob giving listeners an idea of his role within the organization. We hear about the massive move toward digitization at USCIS and some of the biggest challenges the organization is facing as far as cloud adoption. From there, our conversation touches on the benefits of a multi-cloud approach, how USCIS is implementing Zero Trust with regards to cloud security, and how microsegmentation fits into all of this. Tuning in, listeners will also learn about the metrics Rob uses to assess the process of cloud adoption at USCIS, how the shift to the cloud has helped address the issue of siloing, and the benefits of implementing a unified pipeline grounded by standardization. We wrap up with some current initiatives Rob is most occupied with before hearing about how he likes to stay sharp using an approach grounded in experimentation and testing. Rob is filled with insights to help keep teams robust and agile during sticky situations, so be sure to tune in and hear them all.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Tweetables&lt;/b&gt;&lt;br /&gt;“We have got a very good security team and a pretty savvy group of application developers and infrastructure folks that take security and shift it as far to the left as possible.” — Rob Brown [0:17:19]&lt;br /&gt;&lt;br /&gt;“Standardization, to me, has been critical in creating some of these unified pipelines.” — Rob Brown [0:29:14]&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Links Mentioned in Today’s Episode:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/robbrown/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Rob Brown on LinkedIn&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;a href=&quot;https://www.uscis.gov/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;US Citizenship and Immigration Services&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;a href=&quot;https://www.usajobs.gov/Search/Results?a=HSAB&amp;amp;p=1&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Jobs at USCIS&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:34:42</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>9</itunes:episode><itunes:title>Cloud Immigration</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[AI agents and the future of cyber]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><a href="https://www.linkedin.com/in/kellybissell/" rel="noopener noreferrer nofollow">Kelly Bissell </a>shares his extensive experience in cybersecurity, from early internet security challenges to the transformative impact of AI and machine learning. Discover practical insights on risk management, organizational culture, and the future roles of cybersecurity professionals in an AI-driven world.<br /><br /></p><p><b>Emerging AI Standards</b></p><ul><li>https://www.aiuc-1.com/</li><li>https://cloudsecurityalliance.org/ai-safety-initiative</li></ul><p>The book Matt couldn't remember: https://www.amazon.com/Cuckoos-Egg-Tracking-Computer-Espionage/dp/0385249462</p><p><br /></p><p><br /></p>]]></description><guid isPermaLink="false">Buzzsprout-18826489</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Wed, 11 Mar 2026 01:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/3d6d51092b494da30f23ca302ec332bf5df1f233d203f46044446a6188dcae9b/eyJlcGlzb2RlSWQiOiI1MDRlNjZhZC1iYjY4LTRlMmMtYmE0OC0wYjg5NzU1MjdlZTIiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNTA0ZTY2YWQtYmI2OC00ZTJjLWJhNDgtMGI4OTc1NTI3ZWUyLzE4ODI2NDg5LWFpLWFnZW50cy1hbmQtdGhlLWZ1dHVyZS1vZi1jeWJlci5tcDMifQ==.mp3" length="35175960" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/kellybissell/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Kelly Bissell &lt;/a&gt;shares his extensive experience in cybersecurity, from early internet security challenges to the transformative impact of AI and machine learning. Discover practical insights on risk management, organizational culture, and the future roles of cybersecurity professionals in an AI-driven world.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Emerging AI Standards&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;https://www.aiuc-1.com/&lt;/li&gt;&lt;li&gt;https://cloudsecurityalliance.org/ai-safety-initiative&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The book Matt couldn&apos;t remember: https://www.amazon.com/Cuckoos-Egg-Tracking-Computer-Espionage/dp/0385249462&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:48:45</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>6</itunes:season><itunes:episode>1</itunes:episode><itunes:title>AI agents and the future of cyber</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[The future of cybersecurity in healthcare]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p><b>Episode Summary</b></p><p>Corey Elinburg, a cybersecurity leader, discusses the importance of approaching cybersecurity as a transformational force and empowering the business. He emphasizes the need to avoid draconian controls and adopt a mentality of finding solutions rather than saying no. Corey also shares insights on hiring security leaders and building relationships with vendors. He highlights the value of cloud-based security services in rapidly aligning IT with the business and shares examples from his experience. Corey emphasizes the importance of digital trust in healthcare and the need to prioritize patient safety. He also discusses personal growth and staying up to date in cybersecurity.<br /><br /><b>Takeaways</b></p><ul><li>Approach cybersecurity as a transformational force that empowers the business.</li><li>Avoid draconian controls and focus on finding solutions rather than saying no.</li><li>Embrace innovation and set the terms of adoption to drive business transformation.</li><li>Build trust and empower your team to enable scalability and focus on strategic initiatives.</li><li>Cloud-based security services offer agility, scalability, and rapid alignment with the business.</li><li>Build relationships with vendors by understanding their value proposition and engaging in problem-solving.</li></ul><p><b>Chapters</b></p><p>·       [02:10] Kind words about Corey.</p><p>·       [03:13] Transforming business through IT.</p><p>·       [05:20] Where security programs go wrong.</p><p>·       [06:35] Corey’s hiring persona.</p><p>·       [07:50] Embracing innovation.</p><p>·       [14:26] Principles to accomplish your vision.</p><p>·       [17:20] Cloud-based security models.</p><p>·       [23:55] Bringing value to businesses.</p><p>·       [28:09] From practitioner to leader.</p><p>·       [33:41] Unifying security and developers in purpose and practice.</p><p>·       [38:15] Implementing digital trust.</p><p>·       [41:28] Corey’s growth formula.</p><p>·       [42:53] Corey’s parting words.</p><p> </p><p><b>Notable Quotes</b></p><p>·       “It’s not just controls. It’s empowering the business to operate in a resilient way.”</p><p>·       “Too often in cyber, we forget that we’re selling in every interaction.”</p><p>·       “When you engage trying to solve a problem rather than engage trying to sell a product, you’re immediately on a better footing.”</p><p> </p><p><b>Relevant Links</b></p><p>Website:          <a href="https://www.commonspirit.org/" rel="noopener noreferrer nofollow">www.commonspirit.org</a></p><p>LinkedIn:         <a href="https://www.linkedin.com/in/celinburg" rel="noopener noreferrer nofollow">Corey Elinburg</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-14933850</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 20 May 2024 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/71a6c13a5f3e4775edf1852d911e0a77b928dfeb264498d32542922a1037fb46/eyJlcGlzb2RlSWQiOiIyZGYwZjkzZi04ZjMwLTQ3N2ItOGQwZS0wNjZhMGVmZGNiNTgiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMmRmMGY5M2YtOGYzMC00NzdiLThkMGUtMDY2YTBlZmRjYjU4LzE0OTMzODUwLXRoZS1mdXR1cmUtb2YtY3liZXJzZWN1cml0eS1pbi1oZWFsdGhjYXJlLm1wMyJ9.mp3" length="31696489" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Episode Summary&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Corey Elinburg, a cybersecurity leader, discusses the importance of approaching cybersecurity as a transformational force and empowering the business. He emphasizes the need to avoid draconian controls and adopt a mentality of finding solutions rather than saying no. Corey also shares insights on hiring security leaders and building relationships with vendors. He highlights the value of cloud-based security services in rapidly aligning IT with the business and shares examples from his experience. Corey emphasizes the importance of digital trust in healthcare and the need to prioritize patient safety. He also discusses personal growth and staying up to date in cybersecurity.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Takeaways&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Approach cybersecurity as a transformational force that empowers the business.&lt;/li&gt;&lt;li&gt;Avoid draconian controls and focus on finding solutions rather than saying no.&lt;/li&gt;&lt;li&gt;Embrace innovation and set the terms of adoption to drive business transformation.&lt;/li&gt;&lt;li&gt;Build trust and empower your team to enable scalability and focus on strategic initiatives.&lt;/li&gt;&lt;li&gt;Cloud-based security services offer agility, scalability, and rapid alignment with the business.&lt;/li&gt;&lt;li&gt;Build relationships with vendors by understanding their value proposition and engaging in problem-solving.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Chapters&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       [02:10] Kind words about Corey.&lt;/p&gt;&lt;p&gt;·       [03:13] Transforming business through IT.&lt;/p&gt;&lt;p&gt;·       [05:20] Where security programs go wrong.&lt;/p&gt;&lt;p&gt;·       [06:35] Corey’s hiring persona.&lt;/p&gt;&lt;p&gt;·       [07:50] Embracing innovation.&lt;/p&gt;&lt;p&gt;·       [14:26] Principles to accomplish your vision.&lt;/p&gt;&lt;p&gt;·       [17:20] Cloud-based security models.&lt;/p&gt;&lt;p&gt;·       [23:55] Bringing value to businesses.&lt;/p&gt;&lt;p&gt;·       [28:09] From practitioner to leader.&lt;/p&gt;&lt;p&gt;·       [33:41] Unifying security and developers in purpose and practice.&lt;/p&gt;&lt;p&gt;·       [38:15] Implementing digital trust.&lt;/p&gt;&lt;p&gt;·       [41:28] Corey’s growth formula.&lt;/p&gt;&lt;p&gt;·       [42:53] Corey’s parting words.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Notable Quotes&lt;/b&gt;&lt;/p&gt;&lt;p&gt;·       “It’s not just controls. It’s empowering the business to operate in a resilient way.”&lt;/p&gt;&lt;p&gt;·       “Too often in cyber, we forget that we’re selling in every interaction.”&lt;/p&gt;&lt;p&gt;·       “When you engage trying to solve a problem rather than engage trying to sell a product, you’re immediately on a better footing.”&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;b&gt;Relevant Links&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Website:          &lt;a href=&quot;https://www.commonspirit.org/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;www.commonspirit.org&lt;/a&gt;&lt;/p&gt;&lt;p&gt;LinkedIn:         &lt;a href=&quot;https://www.linkedin.com/in/celinburg&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Corey Elinburg&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:43:55</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>4</itunes:season><itunes:episode>6</itunes:episode><itunes:title>The future of cybersecurity in healthcare</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Iron Maiden and cloud security]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this month's installment, <a href="https://www.linkedin.com/in/toniblyx/" rel="noopener noreferrer nofollow">Toni De La Fuente</a> shares his journey into cybersecurity, detailing his early experiences with computers and his passion for hacking. He discusses the creation of <a href="https://hub.prowler.com/" rel="noopener noreferrer nofollow">Prowler</a>, an open-source cloud security tool, and its differences from commercial solutions. The conversation explores cloud security challenges, the importance of open-source solutions, and the dynamics of scaling a startup. Toni also emphasizes the significance of passion in one's career and offers advice for aspiring tech professionals.<br /><br />And yes...we also talk about his LOVE for <a href="https://youtu.be/gJ1jeBNUR4c?si=5ZQYflLIcsJUCzgK" rel="noopener noreferrer nofollow">Iron Maiden</a> ;-)</p>]]></description><guid isPermaLink="false">Buzzsprout-17505367</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 14 Jul 2025 22:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/0404f9344ec8336b13f320b6ecab57ad700e425ba9aa6f462dd00b46d0fe415e/eyJlcGlzb2RlSWQiOiJiMDYwYWRmOS0wOWU3LTRhYzItYmRiYS0wOTVjZDFkYjEwMmQiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvYjA2MGFkZjktMDllNy00YWMyLWJkYmEtMDk1Y2QxZGIxMDJkLzE3NTA1MzY3LWlyb24tbWFpZGVuLWFuZC1jbG91ZC1zZWN1cml0eS5tcDMifQ==.mp3" length="32906710" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this month&apos;s installment, &lt;a href=&quot;https://www.linkedin.com/in/toniblyx/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Toni De La Fuente&lt;/a&gt; shares his journey into cybersecurity, detailing his early experiences with computers and his passion for hacking. He discusses the creation of &lt;a href=&quot;https://hub.prowler.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Prowler&lt;/a&gt;, an open-source cloud security tool, and its differences from commercial solutions. The conversation explores cloud security challenges, the importance of open-source solutions, and the dynamics of scaling a startup. Toni also emphasizes the significance of passion in one&apos;s career and offers advice for aspiring tech professionals.&lt;br /&gt;&lt;br /&gt;And yes...we also talk about his LOVE for &lt;a href=&quot;https://youtu.be/gJ1jeBNUR4c?si=5ZQYflLIcsJUCzgK&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Iron Maiden&lt;/a&gt; ;-)&lt;/p&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:45:36</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>5</itunes:season><itunes:episode>6</itunes:episode><itunes:title>Iron Maiden and cloud security</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Putting the Sec in DevOps]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>Today’s guest is Guy Eisenkot and he joins us to talk about how culture is a critical aspect of shift-left security and DevOps. Guy is the Co-Founder of Bridgecrew, a tool that solves the talent shortage gap for building secure infrastructure in the public cloud. Our conversation begins with Guy giving some insight about his path into development and security, and he details his training in the Israeli military and subsequent experience building security tools for the civil market. In today’s discussion, Guy gets into how the security responsibilities of platform and infrastructure teams have changed as well as what security teams are missing when it comes to DevOps security. He shares his insights about how security and DevOps teams have been able to synchronize and also gets into some of the biggest pitfalls in DevOps as far as cybersecurity best practices. We explore how infrastructure as code could be the driver of two paths, one leading to a dangerous amount of freedom, and the other, to the standardization necessary for automation. Toward the end of our conversation, Guy weighs in on the parts of the industry that show maturity as far as DevSecOps versus those that don’t, and he also talks about how the OpenSource tool Checkov helps solve poor security configurations during resource deployment. Tune in today and get ready to take some notes!</p><p><b>Tweetables:</b></p><p>“We were learning what are the limitations of these orchestration capabilities, and how we can take legacy infrastructure and promote it into a modern stack. And that's where we saw DevOps is practically everywhere.” — <a href="https://twitter.com/guysenkot?lang=en" rel="noopener noreferrer nofollow">@guysenkot</a> [0:06:28]</p><p><br /></p><p>“Bridgecrew essentially builds developer tools that help people from engineering organizations build secure infrastructure in the public cloud.” — <a href="https://twitter.com/guysenkot?lang=en" rel="noopener noreferrer nofollow">@guysenkot</a> [0:12:19]</p><p><br /></p><p>“Where both security and DevOps come together for me is when you realize that in the cloud both of these buckets of initiatives are sitting on the same infrastructure.” — <a href="https://twitter.com/guysenkot?lang=en" rel="noopener noreferrer nofollow">@guysenkot</a> [0:20:38]</p><p><br /></p><p><b>Links Mentioned in Today’s Episode:</b></p><p><a href="https://www.linkedin.com/in/guy-eisen-3012a597/?originalSubdomain=il" rel="noopener noreferrer nofollow"><b>Guy Eisenkot</b></a></p><p><a href="https://twitter.com/guysenkot?lang=en" rel="noopener noreferrer nofollow"><b>Guy Eisenkot on Twitter</b></a></p><p><a href="https://bridgecrew.io/" rel="noopener noreferrer nofollow"><b>Bridgecrew<br /><br /></b></a><a href="https://github.com/bridgecrewio/checkov" rel="noopener noreferrer nofollow"><b>Checkov</b></a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-9005760</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Tue, 10 Aug 2021 13:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/fc692af57840889eb8b7e13076507477293f3e177c59e12fc305ac356409ab0d/eyJlcGlzb2RlSWQiOiI5NDAyM2NiYy03YzM2LTQ2OWMtYjAwMi1mMzE0ZmFjNGJkYjciLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvOTQwMjNjYmMtN2MzNi00NjljLWIwMDItZjMxNGZhYzRiZGI3LzkwMDU3NjAtcHV0dGluZy10aGUtc2VjLWluLWRldm9wcy5tcDMifQ==.mp3" length="28653522" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Today’s guest is Guy Eisenkot and he joins us to talk about how culture is a critical aspect of shift-left security and DevOps. Guy is the Co-Founder of Bridgecrew, a tool that solves the talent shortage gap for building secure infrastructure in the public cloud. Our conversation begins with Guy giving some insight about his path into development and security, and he details his training in the Israeli military and subsequent experience building security tools for the civil market. In today’s discussion, Guy gets into how the security responsibilities of platform and infrastructure teams have changed as well as what security teams are missing when it comes to DevOps security. He shares his insights about how security and DevOps teams have been able to synchronize and also gets into some of the biggest pitfalls in DevOps as far as cybersecurity best practices. We explore how infrastructure as code could be the driver of two paths, one leading to a dangerous amount of freedom, and the other, to the standardization necessary for automation. Toward the end of our conversation, Guy weighs in on the parts of the industry that show maturity as far as DevSecOps versus those that don’t, and he also talks about how the OpenSource tool Checkov helps solve poor security configurations during resource deployment. Tune in today and get ready to take some notes!&lt;/p&gt;&lt;p&gt;&lt;b&gt;Tweetables:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;“We were learning what are the limitations of these orchestration capabilities, and how we can take legacy infrastructure and promote it into a modern stack. And that&apos;s where we saw DevOps is practically everywhere.” — &lt;a href=&quot;https://twitter.com/guysenkot?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@guysenkot&lt;/a&gt; [0:06:28]&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;“Bridgecrew essentially builds developer tools that help people from engineering organizations build secure infrastructure in the public cloud.” — &lt;a href=&quot;https://twitter.com/guysenkot?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@guysenkot&lt;/a&gt; [0:12:19]&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;“Where both security and DevOps come together for me is when you realize that in the cloud both of these buckets of initiatives are sitting on the same infrastructure.” — &lt;a href=&quot;https://twitter.com/guysenkot?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@guysenkot&lt;/a&gt; [0:20:38]&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;Links Mentioned in Today’s Episode:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/guy-eisen-3012a597/?originalSubdomain=il&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Guy Eisenkot&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://twitter.com/guysenkot?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Guy Eisenkot on Twitter&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://bridgecrew.io/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Bridgecrew&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;/a&gt;&lt;a href=&quot;https://github.com/bridgecrewio/checkov&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;&lt;b&gt;Checkov&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:39:41</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>6</itunes:episode><itunes:title>Putting the Sec in DevOps</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[How COVID-19 Impacted Cloud Security]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>In this episode, Nathanial Quist, also known as ‘Q’ returns along with Dr. Jay Chen, both of whom listeners might recognize from our inaugural episode where we discussed how common identity misconfigurations can undermine cloud security. Both Jay and Q are threat researchers with Palo Alto Networks Unit 42. Unit 42 is the global threat intelligence team at Palo Alto Networks and a recognized authority on cyberthreats, frequently sought out by enterprises and government agencies around the world.</p><p>In our conversation, they discuss what they found in their latest Cloud Threat Report examining the impact of the COVID-19 pandemic. We explore how the tremendous increase in remote work has affected cloud security and why Jay is more concerned over the <em>number</em> of mistakes that people are making, rather than the <em>type</em> of mistakes. Tuning in you’ll hear what organizations can do to curtail the recent rise in security incidents and some interesting observations that Q and Jay learned from their data, such as the fact that even malicious hackers need a holiday and don’t want to spend all their time in front of a computer cryptojacking :-) </p><p>Key Points From This Episode:</p><ul><li>Cloud security incidents grew, on average, 188% pre vs. post COVID-19 discovery.</li><li>Retail organizations saw the greatest increase in security incidents at 402%.</li><li>The cloud is no longer for low-impact data: 69% of data is PII.</li></ul><p>Tweetables:</p><p>“We saw a decrease in crypto mining operations during the holiday period between December 24th through January 3rd. It just kind of goes to show that even malicious crypto miners want to take a holiday.” — Nathanial Quist [0:25:26]</p><p>“Standardization can help you find the issue but automation can help you to prevent or mitigate [it].” — Jay Chen [0:32:02]</p><p>Links Mentioned in Today’s Episode:</p><p><a href="https://www.paloaltonetworks.com/prisma/unit42-cloud-threat-research-1h21" rel="noopener noreferrer nofollow">Cloud Threat Report</a></p><p><a href="https://www.youtube.com/watch?v=c1EyN9xTK94&amp;ab_channel=Movieclips" rel="noopener noreferrer nofollow">Clip from Tommy Boy</a></p><p><a href="https://www.linkedin.com/in/qquist/" rel="noopener noreferrer nofollow">Nathaniel Quist on LinkedIn</a></p><p><a href="https://www.linkedin.com/in/jaychen2015/" rel="noopener noreferrer nofollow">Jay Chen on LinkedIn</a></p><p><a href="https://www.cloudsecuritytoday.com/" rel="noopener noreferrer nofollow">Cloud Security Today</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-8681018</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 14 Jun 2021 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/1d66021c97650746aadc46e049e5d9f87ee5e57f926dbc935521b467ef5d7e7c/eyJlcGlzb2RlSWQiOiIxNGYzYjFiYi03NjA1LTQ2ZGUtYThhNi1lNjM3YzkxOGM4NDYiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMTRmM2IxYmItNzYwNS00NmRlLWE4YTYtZTYzN2M5MThjODQ2Lzg2ODEwMTgtaG93LWNvdmlkLTE5LWltcGFjdGVkLWNsb3VkLXNlY3VyaXR5Lm1wMyJ9.mp3" length="25031233" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this episode, Nathanial Quist, also known as ‘Q’ returns along with Dr. Jay Chen, both of whom listeners might recognize from our inaugural episode where we discussed how common identity misconfigurations can undermine cloud security. Both Jay and Q are threat researchers with Palo Alto Networks Unit 42. Unit 42 is the global threat intelligence team at Palo Alto Networks and a recognized authority on cyberthreats, frequently sought out by enterprises and government agencies around the world.&lt;/p&gt;&lt;p&gt;In our conversation, they discuss what they found in their latest Cloud Threat Report examining the impact of the COVID-19 pandemic. We explore how the tremendous increase in remote work has affected cloud security and why Jay is more concerned over the &lt;em&gt;number&lt;/em&gt; of mistakes that people are making, rather than the &lt;em&gt;type&lt;/em&gt; of mistakes. Tuning in you’ll hear what organizations can do to curtail the recent rise in security incidents and some interesting observations that Q and Jay learned from their data, such as the fact that even malicious hackers need a holiday and don’t want to spend all their time in front of a computer cryptojacking :-) &lt;/p&gt;&lt;p&gt;Key Points From This Episode:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cloud security incidents grew, on average, 188% pre vs. post COVID-19 discovery.&lt;/li&gt;&lt;li&gt;Retail organizations saw the greatest increase in security incidents at 402%.&lt;/li&gt;&lt;li&gt;The cloud is no longer for low-impact data: 69% of data is PII.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Tweetables:&lt;/p&gt;&lt;p&gt;“We saw a decrease in crypto mining operations during the holiday period between December 24th through January 3rd. It just kind of goes to show that even malicious crypto miners want to take a holiday.” — Nathanial Quist [0:25:26]&lt;/p&gt;&lt;p&gt;“Standardization can help you find the issue but automation can help you to prevent or mitigate [it].” — Jay Chen [0:32:02]&lt;/p&gt;&lt;p&gt;Links Mentioned in Today’s Episode:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/unit42-cloud-threat-research-1h21&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Cloud Threat Report&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=c1EyN9xTK94&amp;amp;ab_channel=Movieclips&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Clip from Tommy Boy&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/qquist/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Nathaniel Quist on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/jaychen2015/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Jay Chen on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.cloudsecuritytoday.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Cloud Security Today&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:34:39</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>4</itunes:episode><itunes:title>How COVID-19 Impacted Cloud Security</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[Did You Know You Have a SaaS Problem?]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>While most companies have significantly increased their investments in SaaS, they have not updated their security controls and processes to ward off threats posed by this medium. Leaving SaaS security to Cloud Access Security Brokers (CASB) is not sufficient. The security controls need to be placed around the data, APIs, and applications that are running inside a cloud environment, not outside its perimeter. This is the kind of security that AppOmni provides and today we have its CEO, Brendan O'Connor on the show to dive deeper into the subject of SaaS security. <br /><br />We begin with Brendan’s journey into IT and security and hear a bit more about what makes him tick. From there, we dive into the subject of security in the cloud as it pertains to SaaS specifically. Brendan does a great job of explaining why SaaS platforms are subject to so many misconfigurations and why these are not being recognized by security teams. He gets into how the cloud infrastructure is set up and uses a few brilliant analogies to describe how an attacker might get into a SaaS platform without security ever realizing. He talks about some basic security measures companies need to take and shares more about how solutions like AppOmni can automate security. For insight into the vulnerabilities of SaaS and how to guard against them, tune in today!</p><p><b>Key Areas From This Episode:</b></p><ul><li>Curiosity and a love for solving problems is Brendan’s method for keeping his edge.</li><li>Brendan’s recommendations for security guardrails that always need to be in place.</li><li>Hear Brendan’s argument about the need for automated SaaS security.</li><li>Brendan’s recommendations for setting up and measuring SaaS security.</li><li>Advice from Brendan about how security teams need to adapt in light of Solar Winds.</li></ul><p><b>Tweetables:</b></p><p>“Companies have significantly expanded their SaaS investment and footprint and the SaaS applications themselves have really grown in complexity. Most companies haven't updated their security controls to support SaaS, or invested in new technology to manage this problem. That's where AppOmni comes in.” — <a href="https://twitter.com/appomnisecurity?lang=en" rel="noopener noreferrer nofollow">@AppOmniSecurity</a> [0:01:54]</p><p>“I love solving puzzles. Enterprise security at scale is a hard problem. It's a puzzle. There is not a one-size-fits-all solution.” — <a href="https://twitter.com/appomnisecurity?lang=en" rel="noopener noreferrer nofollow">@AppOmniSecurity</a> [0:05:29]</p><p>“SaaS applications are becoming closer to operating systems in the cloud than a single simple web app. You can't watch what every individual is doing. You have got to put guardrails in place.” — <a href="https://twitter.com/appomnisecurity?lang=en" rel="noopener noreferrer nofollow">@AppOmniSecurity</a> [0:20:30]</p><p>“SaaS is a fundamentally different architecture than hosting things on-premise. You need to rethink, what is the value that you get from your security tools? How can you get that value today in an automated fashion in these new systems that support that new architecture?” — <a href="https://twitter.com/appomnisecurity?lang=en" rel="noopener noreferrer nofollow">@AppOmniSecurity</a> [0:24:44]</p><p><br /><b>Links Mentioned in Today’s Episode:</b></p><p><a href="https://www.linkedin.com/in/mattchiodi/" rel="noopener noreferrer nofollow">Matt Chiodi on LinkedIn</a></p><p><a href="https://twitter.com/mattchiodi?lang=en" rel="noopener noreferrer nofollow">Matt Chiodi on Twitter</a></p><p><a href="https://www.linkedin.com/in/securitybrendan/" rel="noopener noreferrer nofollow">Brendan O’Connor on LinkedIn</a></p><p><a href="https://appomni.com/" rel="noopener noreferrer nofollow">App</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-8305802</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 12 Apr 2021 12:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/f70aa53eca9ab4bf7ac742cf47984ea4ba47fc3e3fe9b658ac1117691de4aa92/eyJlcGlzb2RlSWQiOiIyOTQ3MWQ0OC00YTIzLTRhZjEtYTZhZS04ZTZkZTY3ZWJiMmUiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvMjk0NzFkNDgtNGEyMy00YWYxLWE2YWUtOGU2ZGU2N2ViYjJlLzgzMDU4MDItZGlkLXlvdS1rbm93LXlvdS1oYXZlLWEtc2Fhcy1wcm9ibGVtLm1wMyJ9.mp3" length="31260977" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;While most companies have significantly increased their investments in SaaS, they have not updated their security controls and processes to ward off threats posed by this medium. Leaving SaaS security to Cloud Access Security Brokers (CASB) is not sufficient. The security controls need to be placed around the data, APIs, and applications that are running inside a cloud environment, not outside its perimeter. This is the kind of security that AppOmni provides and today we have its CEO, Brendan O&apos;Connor on the show to dive deeper into the subject of SaaS security. &lt;br /&gt;&lt;br /&gt;We begin with Brendan’s journey into IT and security and hear a bit more about what makes him tick. From there, we dive into the subject of security in the cloud as it pertains to SaaS specifically. Brendan does a great job of explaining why SaaS platforms are subject to so many misconfigurations and why these are not being recognized by security teams. He gets into how the cloud infrastructure is set up and uses a few brilliant analogies to describe how an attacker might get into a SaaS platform without security ever realizing. He talks about some basic security measures companies need to take and shares more about how solutions like AppOmni can automate security. For insight into the vulnerabilities of SaaS and how to guard against them, tune in today!&lt;/p&gt;&lt;p&gt;&lt;b&gt;Key Areas From This Episode:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Curiosity and a love for solving problems is Brendan’s method for keeping his edge.&lt;/li&gt;&lt;li&gt;Brendan’s recommendations for security guardrails that always need to be in place.&lt;/li&gt;&lt;li&gt;Hear Brendan’s argument about the need for automated SaaS security.&lt;/li&gt;&lt;li&gt;Brendan’s recommendations for setting up and measuring SaaS security.&lt;/li&gt;&lt;li&gt;Advice from Brendan about how security teams need to adapt in light of Solar Winds.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Tweetables:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;“Companies have significantly expanded their SaaS investment and footprint and the SaaS applications themselves have really grown in complexity. Most companies haven&apos;t updated their security controls to support SaaS, or invested in new technology to manage this problem. That&apos;s where AppOmni comes in.” — &lt;a href=&quot;https://twitter.com/appomnisecurity?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@AppOmniSecurity&lt;/a&gt; [0:01:54]&lt;/p&gt;&lt;p&gt;“I love solving puzzles. Enterprise security at scale is a hard problem. It&apos;s a puzzle. There is not a one-size-fits-all solution.” — &lt;a href=&quot;https://twitter.com/appomnisecurity?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@AppOmniSecurity&lt;/a&gt; [0:05:29]&lt;/p&gt;&lt;p&gt;“SaaS applications are becoming closer to operating systems in the cloud than a single simple web app. You can&apos;t watch what every individual is doing. You have got to put guardrails in place.” — &lt;a href=&quot;https://twitter.com/appomnisecurity?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@AppOmniSecurity&lt;/a&gt; [0:20:30]&lt;/p&gt;&lt;p&gt;“SaaS is a fundamentally different architecture than hosting things on-premise. You need to rethink, what is the value that you get from your security tools? How can you get that value today in an automated fashion in these new systems that support that new architecture?” — &lt;a href=&quot;https://twitter.com/appomnisecurity?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;@AppOmniSecurity&lt;/a&gt; [0:24:44]&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;b&gt;Links Mentioned in Today’s Episode:&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/mattchiodi/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Matt Chiodi on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://twitter.com/mattchiodi?lang=en&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Matt Chiodi on Twitter&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/securitybrendan/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Brendan O’Connor on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://appomni.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;App&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:43:18</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>2</itunes:episode><itunes:title>Did You Know You Have a SaaS Problem?</itunes:title><itunes:episodeType>full</itunes:episodeType></item><item><title><![CDATA[How to Operationalize Cloud Security]]></title><description><![CDATA[<p><a href="https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms" rel="noopener noreferrer nofollow" target="_blank">Send a text</a></p><p>Keeping it simple is Brett’s mantra, and it has led to a great amount of success for him and the company he works for. As a security leader at Zoetis, the world’s largest animal healthcare company, Brett has managed to get ahead of the business in terms of adopting cloud securely. Although it may sound boring, standardizing security processes was a key element in the journey to automation for the Zoetis SOC. <br /><br />In today’s episode, Brett also talks about how he ended up in the world of cybersecurity after majoring in ecommerce, the different facets that make up his current role at Zoetis, as well as some of the tools that are extremely useful to Brett and his team. Brett also opines on how automation has led to a reduction in talent-drain on his team. We also briefly delve into the SolarWinds hack and how this changed the way Brett thinks and approaches supply chain security. </p><p>Key Points From This Episode:</p><ul><li>Getting ahead of the business, build it before they come!</li><li>Standardization MUST come before automation.</li><li>Automation reduces talent-drain.</li><li>Metrics that Brett and his team follow up on constantly.</li></ul><p>Tweetables:</p><p>“Standardization...I just live and die by our process. We're very process-oriented. You can do that in the cloud but you have to take time to do that, and that's how it should be done.” — Brett Tode [0:10:38]</p><p>“Your standardized processes are the things that really are going to keep you in control and keep you effective over time. Automation is really cool and great because it's going to save us time. But without that standardized process, you can never get to automation.” — Brett Tode [0:13:04]</p><p>“In almost everything I do, I try to keep things simple. Don't try to make something so complex from the get-go because it’s just never going to work.” — Brett Tode [0:24:49]</p><p>“We’re always going to strive to be better. I think everyone should do that because making yourself better is just providing more value for the company. At the end of the day, that's what we're all supposed to be doing.” — Brett Tode [0:25:52]</p><p><br /></p><p>Links Mentioned in Today’s Episode:</p><p><a href="https://www.linkedin.com/in/btode/" rel="noopener noreferrer nofollow">Brett on LinkedIn</a></p><p><a href="https://careers.zoetis.com/" rel="noopener noreferrer nofollow">Zoetis Careers</a></p><a href="https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;utm_medium=" rel="noopener noreferrer nofollow" target="_blank">The future of cloud security.</a><br />Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.<br /><br />Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.<br /><br />]]></description><guid isPermaLink="false">Buzzsprout-8479644</guid><dc:creator><![CDATA[Matthew Chiodi]]></dc:creator><pubDate>Mon, 10 May 2021 10:00:00 GMT</pubDate><enclosure url="https://api.riverside.com/hosting-analytics/media/a0c8ff588eddf0a794c6c84813b4fd645891358d34ab29e35dc60b36b8bc701e/eyJlcGlzb2RlSWQiOiI1NDE0NjFlNC04OThmLTRlN2UtYmEyNC1kMWNlZjdiNjZiNDMiLCJwb2RjYXN0SWQiOiI4YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEiLCJhY2NvdW50SWQiOiI2MDdjNGY0N2U4YjZhMjQ3ZDYzZGU2NTMiLCJwYXRoIjoibWVkaWEvaW1wb3J0cy9wb2RjYXN0cy84YTZhM2YyNC05MTUyLTQ3MTQtOGNjOS1mODliYjAyZDdjNjEvZXBpc29kZXMvNTQxNDYxZTQtODk4Zi00ZTdlLWJhMjQtZDFjZWY3YjY2YjQzLzg0Nzk2NDQtaG93LXRvLW9wZXJhdGlvbmFsaXplLWNsb3VkLXNlY3VyaXR5Lm1wMyJ9.mp3" length="26311529" type="audio/mpeg"/><itunes:summary>&lt;p&gt;&lt;a href=&quot;https://www.buzzsprout.com/twilio/text_messages/1723279/open_sms&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;Send a text&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Keeping it simple is Brett’s mantra, and it has led to a great amount of success for him and the company he works for. As a security leader at Zoetis, the world’s largest animal healthcare company, Brett has managed to get ahead of the business in terms of adopting cloud securely. Although it may sound boring, standardizing security processes was a key element in the journey to automation for the Zoetis SOC. &lt;br /&gt;&lt;br /&gt;In today’s episode, Brett also talks about how he ended up in the world of cybersecurity after majoring in ecommerce, the different facets that make up his current role at Zoetis, as well as some of the tools that are extremely useful to Brett and his team. Brett also opines on how automation has led to a reduction in talent-drain on his team. We also briefly delve into the SolarWinds hack and how this changed the way Brett thinks and approaches supply chain security. &lt;/p&gt;&lt;p&gt;Key Points From This Episode:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Getting ahead of the business, build it before they come!&lt;/li&gt;&lt;li&gt;Standardization MUST come before automation.&lt;/li&gt;&lt;li&gt;Automation reduces talent-drain.&lt;/li&gt;&lt;li&gt;Metrics that Brett and his team follow up on constantly.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Tweetables:&lt;/p&gt;&lt;p&gt;“Standardization...I just live and die by our process. We&apos;re very process-oriented. You can do that in the cloud but you have to take time to do that, and that&apos;s how it should be done.” — Brett Tode [0:10:38]&lt;/p&gt;&lt;p&gt;“Your standardized processes are the things that really are going to keep you in control and keep you effective over time. Automation is really cool and great because it&apos;s going to save us time. But without that standardized process, you can never get to automation.” — Brett Tode [0:13:04]&lt;/p&gt;&lt;p&gt;“In almost everything I do, I try to keep things simple. Don&apos;t try to make something so complex from the get-go because it’s just never going to work.” — Brett Tode [0:24:49]&lt;/p&gt;&lt;p&gt;“We’re always going to strive to be better. I think everyone should do that because making yourself better is just providing more value for the company. At the end of the day, that&apos;s what we&apos;re all supposed to be doing.” — Brett Tode [0:25:52]&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Links Mentioned in Today’s Episode:&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/in/btode/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Brett on LinkedIn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://careers.zoetis.com/&quot; rel=&quot;noopener noreferrer nofollow&quot;&gt;Zoetis Careers&lt;/a&gt;&lt;/p&gt;&lt;a href=&quot;https://www.paloaltonetworks.com/prisma/cloud?utm_source=cloud-security-today--amer-prismacloud&amp;amp;utm_medium=&quot; rel=&quot;noopener noreferrer nofollow&quot; target=&quot;_blank&quot;&gt;The future of cloud security.&lt;/a&gt;&lt;br /&gt;Simplify cloud security with Prisma Cloud, the Code to Cloud platform powered by Precision AI.&lt;br /&gt;&lt;br /&gt;Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.&lt;br /&gt;&lt;br /&gt;</itunes:summary><itunes:explicit>no</itunes:explicit><itunes:duration>00:36:26</itunes:duration><itunes:image href="https://hosting-media.riverside.com/media/imports/podcasts/8a6a3f24-9152-4714-8cc9-f89bb02d7c61/l5iwybq86u4x04n45k3sus74xes2.jpg"/><itunes:season>1</itunes:season><itunes:episode>3</itunes:episode><itunes:title>How to Operationalize Cloud Security</itunes:title><itunes:episodeType>full</itunes:episodeType></item></channel></rss>