A weekly discussion of new developments and the latest cybersecurity threats, including ransomware, malware, phishing schemes, DDoS attacks and more, facing the U.S. industrial sector.
…
continue reading
Dataprivacy Podcasts
Sync Up is your one-stop shop for all things OneDrive. Join hosts, Stephen Rice and Arvind Mishra, as they shed light on how OneDrive connects you to all of your files in Microsoft and enables you to share and work together from anywhere, and any device! Hear from experts behind the design and development of OneDrive, as well as customers and Microsoft MVPs! Each episode will give you news and announcements, tips and best practices for your OneDrive experience, and some fun and humor!
…
continue reading
…
continue reading

1
The Wild & Weird of Industrial Cybersecurity
30:33
30:33
Play later
Play later
Lists
Like
Liked
30:33Send us a text When talking to the experts and leading authorities that have participated in the 140+ episodes of Security Breach, there’s always a slight pause when directing their attention specifically to the industrial sector. That’s because, well, we’re special. There’s the unique juxtaposition of old and bleeding edge technology. There’s the …
…
continue reading
Send us a text I know that we’re constantly talking about artificial intelligence - the best ways to use it, the ways hackers are using it, and the overall good, bad and ugly of implementing AI into your security infrastructure. But what if we took a little different route. In this episode we're going to explore how AI can help make your people bet…
…
continue reading
Send us a text Discussing the ever-expanding threat landscape is something we do a lot on Security Breach, but this episode is dedicated exclusively to topics like zero-day vulnerabilities, nation-state threats, phishing schemes, ransomware, and of course, the role artificial intelligence continues to play in making the good guys smarter and the ba…
…
continue reading

1
Cure Me or Kill Me - The Little Things That Escalate Attacks
43:18
43:18
Play later
Play later
Lists
Like
Liked
43:18Send us a text As loyal listeners of this podcast know, I’m a big believer in paying close attention to the little things, the blocking and tackling, the basics, the fundamentals. All those elementary elements that comprise the building blocks of stronger cybersecurity plans and successful defensive strategies. Spoiler alert – that comes through ag…
…
continue reading

1
Being 'Proactively Paranoid, Not Paralyzed'
36:54
36:54
Play later
Play later
Lists
Like
Liked
36:54Send us a text As all of you know, there are no silver bullets when it comes to cybersecurity success in the industrial sector. Every enterprise has its own unique characteristics, each plant floor its different connectivity elements, and each business is comprised of diverse human dynamics that fuel its culture. However, regardless of the environm…
…
continue reading

1
Why More Hackers Are Logging On Than Breaking In
32:27
32:27
Play later
Play later
Lists
Like
Liked
32:27Send us a text We’ve heard it before – hacker tactics are not changing, but the hackers are getting a lot smarter in how they deploy their time-tested attacks. Additionally, honing in on the human element of cybersecurity is nothing new. We’ve spoken with numerous guests about getting buy-in, improving training, and how creating a cyber-receptive c…
…
continue reading
Send us a text Who are you? This episode dives into one of the most challenging cybersecurity topics currently on the docket – identity management. My conversation with Brandon Traffanstedt, Sr. Director and Global Technology Officer at CyberArk, took us in two equally important directions. The first deals with individuals and how to properly manag…
…
continue reading
Send us a text I’m always tempted to start out each episode by talking about a problem, and then setting up our guest as the solution to that problem. It’s formulaic and a bit redundant, but it’s also effective. So I’ll apologize in advance because I’m about to do that very thing again. The difference is that Howard Grimes, the CEO of the Cybersecu…
…
continue reading

1
Behind the Scenes at the M365 Community Conference
56:35
56:35
Play later
Play later
Lists
Like
Liked
56:35Live from the M365 Community Conference in Las Vegas, Stephen and Arvind break down the biggest announcements in OneDrive, SharePoint, and Microsoft 365—from mind-blowing Copilot demos to Sync deployment best practices. Plus, guest Vlad Catrinescu shares insights on governance, Copilot readiness, and the power of community. Whether you’re an admin,…
…
continue reading
Send us a text Insider threats are creating new attack vectors, but old-school solutions could rise to the challenge. Regardless of the situation or dynamic, everyone likes to think that they’re special. However, with experience we learn that appreciating both the shared similarities, as well as some of those unique traits, are how we can best solv…
…
continue reading
Send us a text In many instances the biggest challenge facing OT cybersecurity practitioners is knowing where to focus resources, especially their time. In other words, what are the priorities for the enterprise, facility and people? I recently sat down with Securin's Lead Threat Intelligence Analyst - Aviral Verma. And while I anticipated a conver…
…
continue reading
Olga Dalecka joins Stephen Rice and Arvind Mishra on this month's Sync Up podcast to share how OneDrive’s mobile app is transforming the way users experience and manage their photos. From Moments of Joy and Photo Shuffle to AI-powered editing and seamless sharing, this episode dives into the innovations making OneDrive the trusted home for your mem…
…
continue reading

1
Why Ransomware, Credential Theft and Phishing Schemes Persist
39:22
39:22
Play later
Play later
Lists
Like
Liked
39:22Send us a text One of the great things about covering industrial cybersecurity is the number of reports, studies and white papers being produced right now to help provide intelligence on threats, research on new tools, and data on leading trends. The tough part is sorting through all this data and, at some point, prioritizing it in order to get the…
…
continue reading

1
Unsecure Webcam Was All a Ransomware Group Needed
31:23
31:23
Play later
Play later
Lists
Like
Liked
31:23Send us a text Endpoint security tools worked, but the hackers worked harder for their payday. While everyone likes to know how someone else might have screwed up and what the fallout looks like, the more import elements of episodes like this one come from the in-depth conversations about new tactics and strategies that are being used by the bad gu…
…
continue reading
Send us a text We talk a lot about the growing complexity of hacking groups and how their tools and tactics continue to evolve. One such evolution is the ongoing specialization that runs rampant throughout the black hat community – especially when it comes to ransomware. The rise of initial access brokers, affiliate programs, spoofing domain creato…
…
continue reading
In this episode of Sync Up, hosts Stephen Rice and Arvind Mishra sit down with David Johnson, one of Microsoft IT's key architects, to uncover how the company manages OneDrive and SharePoint at scale. From security and automation to self-service with guardrails, they explore the strategies that keep Microsoft’s data secure while enabling seamless c…
…
continue reading
Send us a text Breaking down silos while securing the cloud and leveraging secure-by-design advancements. The challenges facing the industrial OT landscape that emanate from external sources are … varied, complex and constantly evolving. Smarter hacking groups, AI-driven phishing schemes and deceptive malware viruses head the list of concerns. And …
…
continue reading

1
Observations of an Ethical Hacking Researcher
35:35
35:35
Play later
Play later
Lists
Like
Liked
35:35Send us a text One of the goals of the show is to help you better understand all the threats facing your OT assets, your data and your people. In order to do that, we work to identify those individuals with a feel and in-depth understanding of these threats and the evolving network of threat actors. And I can’t think of anyone better to break down …
…
continue reading
Send us a text When we talk about the threat landscape for the industrial sector, the eye-catching, headline-grabbing hacking groups with nefarious names typically lead the list of concerns. And while understanding their well-publicized exploits are important, what is often overlooked are all the little things these groups were able to do before dr…
…
continue reading
Join Stephen Rice and Arvind Mishra as they discuss the ins and outs of OneDrive Sync with legendary Sync expert, Gaia Carini. They cover everything from the basics of OneDrive Sync to more advanced features like Files on Demand and Known Folder Move (KFM). Gaia also shares best practices for deploying OneDrive Sync in organizations and highlights …
…
continue reading
Send us a text While we’re still in the infancy of 2025, the New Year has proven to have no issues in welcoming in a number of pre-existing challenges – whether we’re talking about cybersecurity or … other social topics. So, in continuing this trend, we tapped into a unique collection of voices to discuss a topic that has, and will continue to be, …
…
continue reading
Send us a text The continued evolution of the CyberAv3ngers hacking group and its IIoT-focused malware. We talk a lot about change on Security Breach. Some of it’s good and obviously some of it makes us want to tear our hair out. Well, this episode, surprisingly, should go easy on the scalp, even though it will focus on the IOCONTROL malware strand…
…
continue reading
Send us a text Winston Churchill famously stated that, “Those who fail to learn from history are doomed to repeat it.” His concerns about applying lessons learned to post WWII foreign policy initiatives rings just as true in the current cybersecurity climate. So, in an effort to ensure we repeat as few of 2024’s mistakes in 2025, we’re going to tak…
…
continue reading
Send us a text As we begin to close out 2024 and look ahead to 2025, I couldn’t resist the urge to revisit some of my favorite guests from the last couple of months. While I’m grateful for everyone we’ve had on the show, and all the support we continue to receive from the industrial cybersecurity community, I felt these comments were worth another …
…
continue reading

1
OneDrive's Year in Review & Unlicensed User Changes
34:04
34:04
Play later
Play later
Lists
Like
Liked
34:04With 2024 coming to a close, the Sync Up crew is reflecting on our favorite OneDrive features of the year, and looking forward to the Unlicensed User changes coming in 2025! Stephen Rice and Arvind Mishra are joined by keeper of the OneDrive roadmap, Irfan Shahdad, and Archive and unlicensed user expert Trent Green! Irfan will take you through the …
…
continue reading

1
AI Is Exposing Your Most Vulnerable Attack Surface
35:18
35:18
Play later
Play later
Lists
Like
Liked
35:18Send us a text According to Fortinet’s 2024 State of Operational Technology and Cybersecurity Report, 43 percent of those surveyed reported a loss of business critical data or intellectual property so far in 2024– a number this is up nearly 10 percent from last year. And we all know what happens with this hijacked data. Per the World Economic Forum…
…
continue reading
Send us a text Next to artificial intelligence, one of the biggest buzz terms in industrial cybersecurity right now might be SBOM, or software bill of materials. The term generates equal parts concern and eye roll as those entrusted with enterprise defense look to ensure that there are no embedded vulnerabilities amongst the data platforms they are…
…
continue reading

1
What Cybersecurity Can Learn from Tom Brady
52:41
52:41
Play later
Play later
Lists
Like
Liked
52:41Send us a text We assembled some "nerds from the basement" to cover a key strategy in combatting evolving threats. Today’s episode is going to take on a little different flavor, as we’re going to show you one particular tool that can impact a number of your security planning, training and discovery strategies. While table top exercises are nothing …
…
continue reading
Send us a text For this episode, instead of tapping into one source for feedback and updates on industrial cybersecurity, we’re going to look at some of the key insights previous guests have offered on the evolving threat landscape – from increased risks emanating from technological integrations and an uptick in automation, to the more traditional …
…
continue reading
Send us a text While there are plenty of unknowns when it comes to protecting the OT attack surface, there are some things that are undeniably true. We know that the frequency of attacks will continue to increase. We know that it’s not if your ICS will be probed, but when. And we also know that asset and connection visibility is an ongoing challeng…
…
continue reading

1
Phishing Attack Defense 'Not Rocket Science'
22:22
22:22
Play later
Play later
Lists
Like
Liked
22:22Send us a text Maybe you’re sick of hearing about phishing schemes and the way hackers are using this strategy to infiltrate your networks, access intellectual data, shut down production, or hold your assets for ransom. If that’s the case, then you’ve made a lot of hackers very happy. And based on Proofpoint’s 2024 State of Phish report, protecting…
…
continue reading

1
Legacy Mindsets Are Helping Hackers Weaponize Networks
42:09
42:09
Play later
Play later
Lists
Like
Liked
42:09Send us a text So, my daughters like to give me a hard time about growing old. Said another way, I’m a legacy asset - just like most of the devices many of you observe, manage and secure every day. Your machines are still in place because they work. While the technology around these assets has evolved, their core functionality and value to the prod…
…
continue reading

1
Using Force Multipliers to Protect Against Next-Gen Stuxnet
39:43
39:43
Play later
Play later
Lists
Like
Liked
39:43Send us a text While the justifications for additional cybersecurity spending is easy to explain, getting buy-in at the C-level can be difficult. However, some recent research might help you win over those controlling the purse strings. SonicWall’s Mid-Year Cyber Threat Report found that their firewalls were under attack 125 percent of the time dur…
…
continue reading
In this special episode of the Sync Up podcast, join Stephen Rice as he takes you behind the scenes of the OneDrive Fall Event "AI Innovations for Work and Home." Get exclusive insights from interviews with key speakers like Jason Moore, Arwa Tyebkhan and more as they reveal their favorite features, and share some of the exciting upcoming developme…
…
continue reading
Send us a text One of the most common topics we explore here on Security Breach is the ongoing challenge of asset visibility in the OT landscape. It's frustrating because it would seem that the solution starts with basic inventory management approaches, i.e. the first step in developing frameworks and plans for everything from tool selection to att…
…
continue reading
Send us a text According to Veeam’s 2024 Ransomware Trends Report, cyber victims stated that they were unable to restore 43 percent of whatever data was affected by ransomware attacks. This reaffirms what a number of Security Breach guests have stated about trusting hackers after paying their extortion demands. Another finding shows that 63 percent…
…
continue reading
In this episode of the Sync Up Podcast, hosts Stephen Rice and Arvind Mishra dive into the design of Copilot in OneDrive with special guest Ben Truelove, a veteran designer at Microsoft. Ben shares insights from his 27-year journey at Microsoft, including how the team designed and iterated to deliver the best Copilot experience to our customers. Tu…
…
continue reading
Send us a text The ongoing theme in industrial cybersecurity centers on two competing dynamics – the desire to expand our implementation of automation and Industry 4.0 technologies with the goal of using more and faster connections, along with the decision-making data each generates to improve the efficiency and quality of production. However, thes…
…
continue reading

1
Inside the Growing Complexity of Ransomware Hacking Groups
32:02
32:02
Play later
Play later
Lists
Like
Liked
32:02Send us a text We’re back to discuss an all-too-familiar topic – ransomware. Ironically enough, it seems the topics we describe in this manner become so familiar because we can’t figure out viable, long-term solutions. I think part of the challenge for industrial organizations dealing with ransomware is that we have to divide our energy and resourc…
…
continue reading

1
Time to 'Rip off the Band-Aid' to Ensure Security
39:13
39:13
Play later
Play later
Lists
Like
Liked
39:13Send us a text A smarter, well-funded hacker community means embracing basic, yet daunting cyber challenges. In manufacturing, regardless of your role, avoiding downtime is an obvious priority, and one of the motivating factors driving investments in cybersecurity. In working to mitigate potential DDoS attacks or malware drops, manufacturers are ta…
…
continue reading

1
Combating the 20th Century Mafia with a Stronger Human Firewall
46:07
46:07
Play later
Play later
Lists
Like
Liked
46:07Send us a text Sophos recently reported that 65 percent of manufacturing and production organizations were hit by ransomware last year, which, unlike other sectors, is an increase. Overall, these attacks have increased by 41 percent for manufacturing since 2020. Additionally, the cybersecurity firm found that 44 percent of computers used in manufac…
…
continue reading