07-07-20 - NYTimes Critic Called Our Security Theater "Unconvincing"

NYTimes Critic Called Our Security Theater "Unconvincing"

CISO | Security Vendor Relationship Series

This week's episode of CISO/Security Vendor Relationship Podcast

NYTimes Critic Called Our Security Theater "Unconvincing"

NYTimes Critic Called Our Security Theater "Unconvincing"

is hosted by me, David Spark, producer of CISO Series and Mike Johnson. Our guest is Shawn Bowen, CISO, Restaurant Brands International which handles restaurants such as Burger King, Popeye's, Tim Hortons, and Louisiana Kitchen.. All three of us discussed:

Security theater happens when no one questions its value.

Often security people fall into the trap of implementing security theater because either the client asks for it or there's constant scream to implement "best practices" without any regard to whether this "best practice" is actually making anything safer or reducing risk.

Know the difference between a cyber-attack and a cyber-prank.

The TikTok community took credit for the registration bombing of President Trump's Tulsa, Oklahoma rally. This wasn't a cyber attack, it was a cyber prank, or possibly even a cyber protest. It wasn't the security team's fault for not catching it. The fault here lies on the social media team having a blind eye to the TikTok community. 

Does your cyber criminal past preclude you from participating in ethical cybersecurity?

Are young people, even college age young (though still adult) aware of how damaging online criminal behavior is? Can it be seen as youthful experimentation and a growth experience? All depends on where you draw the line on online criminal behavior. 

Special thanks to this week's podcast sponsor, GitGuardian.

GitGuardian

empowers organizations to secure their secrets - such as API keys and other credentials - from being exposed in compromised places or leaked publicly. GitGuardian offers a threat intelligence solution focused on detecting secrets leaked on public GitHub and an automated secrets detection solution which tightly integrates with your DevOps pipeline.

Mike Johnson on the lack of a need for NDAs for threat hunters

This Friday [7-10-20] We're Hacking Passwords

CISO Series Video Chats are back this Friday with a great conversation on what the heck should we do with passwords?

Joining me will be Ori Eisen, CEO, Trusona and Alex Manea, former CSO, Blackberry and now chief security and privacy officer, Georgian Partners.

And YOU! These video chats are fun because we get heavy community involvement.

MORE upcoming CISO Series Video Chats7-17-20: Hacking Active Directory7-24-20: Hacking AutomationAll video chats are held on Fridays and start at 10 AM PT/1 PM ET.

Steve Zalewski, deputy CISO, Levi Strauss on the overwhelming nature of lots of low level attacks

SUBSCRIBE TO BOTH PODCASTS

Go ahead and click on any of these links to subscribe to the podcast feed of your favorite podcast catcher.

If you're already a subscriber, THANK YOU! If you like either or both shows, please tell all your friends on social media and write a review on iTunes.