Cyber security is dynamic and fast changing. Keep up-to-date with the latest news, vulnerabilities, threats and new research. For latest cyber security blogs, visit https://rasoolirfan.com and tweet @ → twitter.com/rasoolirfan
…
continue reading

1
Episode 40 - Rise of Enterprise Security Browsers
4:40
4:40
Play later
Play later
Lists
Like
Liked
4:40The emergence of the enterprise browser represents a significant step forward in cyber security innovation. Ignoring this evolution is no longer an option for security-conscious organizations looking to stay ahead of the curve in the ongoing cyber arms race
…
continue reading

1
Episode 39 - GenAI and guidance to cyber security practitioners
7:33
7:33
Play later
Play later
Lists
Like
Liked
7:33Cyber security leaders need to be empowered addressing below GenAI impacts What if my security team want to leverage GenAI use-cases? What if my business team want to evaluate, experiment, perform POCs around GenAI apps? What if my business team continue to consume the GenAI products? What if my organizations targeted by AI attacker?…
…
continue reading

1
Episode 38 - RSA Conference Innovation Sandbox 2023
8:03
8:03
Play later
Play later
Lists
Like
Liked
8:03The RSA Conference Innovation Sandbox is an annual competition that showcases the latest and most innovative cybersecurity startups and emerging technologies. Cybersecurity professionals can learn a lot from security innovations showcased at events such as the RSA Security Conference.
…
continue reading

1
Episode 37 - Manage effective Container/ K8 Security Assessments
7:54
7:54
Play later
Play later
Lists
Like
Liked
7:54Cybercriminals are using Docker containers to distribute malware due to its scale of operations. Get ready to compose security assessment on their containers comprising 4C’s (Code, Container, Cluster and Cloud Infra). Digital business require lean team with talented expertise to conduct assessment services.…
…
continue reading

1
Episode 36 - Vulnerability Management Maturity Assessment Program
6:04
6:04
Play later
Play later
Lists
Like
Liked
6:04Ensuring that existing vulnerability management program works well to enhance the operational maturity require assessment. Leverage external professionals to conduct assessments based on defined framework across building blocks and act to mature your vulnerability management program. Listen to this podcast for more details…
…
continue reading

1
Episode 35 - Threat Hunting Capability Development Framework
6:49
6:49
Play later
Play later
Lists
Like
Liked
6:49With increased adoption to digital by business and technology advancements consumed by bad actors makes threat hunting a ‘must to have’ program. Cyber threat intelligence enables security analysts with data enrichment, however good programming and coding skills helps threat hunter to uncover the unknowns.…
…
continue reading

1
Episode 34 - Cyber security table top exercise (TTX)
9:50
9:50
Play later
Play later
Lists
Like
Liked
9:50Organizational business continuity program should mandate CISO or CIO to have TTX periodically to rehearse the cyber security incident response plans. The level of participation and greater audience with variety of expertise to combat cyber security incidents quantify the TTX success.
…
continue reading

1
Episode 33 - Microsoft Endpoint DLP use cases
5:15
5:15
Play later
Play later
Lists
Like
Liked
5:15Microsoft Endpoint DLP helps organizations to adopt data protection strategies with most common use cases such as protecting sensitive data based on regulatory compliance, prevent unintentional or accidental exposure of critical data and restricting unwanted activities on windows devices.
…
continue reading

1
Episode 32 - Azure Information Protection - Getting Started and Best Practices
10:56
10:56
Play later
Play later
Lists
Like
Liked
10:56Enterprise today face data protection challenges to secure sensitive information across its life cycle and exploring solutions. Microsoft Azure Information Protection has been widely purchased by many customers, but struggling to find ways to get started and require assistance in adopting best practices. Let's explore it in this podcast.…
…
continue reading

1
Episode 31 - Multi cloud SIEM deployment cost considerations with IBM QRadar and Splunk
7:56
7:56
Play later
Play later
Lists
Like
Liked
7:56Cloud business leaders prefers multi cloud deployment strategies either within the region or across regions to have cost effective solution. IT security managers require security event management solutions prefers to have deployed on the cloud environment or either prefer SaaS offerings IBM QRadar and Splunk are the leading vendors in the market to…
…
continue reading

1
Episode 30 - Microsoft E5 can replace 16 Security vendors
7:02
7:02
Play later
Play later
Lists
Like
Liked
7:02Microsoft clients with E5 license can evaluate the below 16 functional domains to utilize the security use-cases and replace security vendors. However, if customer’s have unique requirements that are achievable only with marketplace security products should continue to leverage other security solutions.…
…
continue reading

1
Episode 29 - Simplify network security with SASE
6:45
6:45
Play later
Play later
Lists
Like
Liked
6:45SASE (Security access service edge) concept is to have all the functional components of network and security required for enterprise available on cloud based services that are globally accessible for the digital business
…
continue reading

1
Episode 28 - People is the most critical vulnerability in any organization
7:05
7:05
Play later
Play later
Lists
Like
Liked
7:05Every organization will have opportunity to learn from their security incidents. While performing root cause analysis, often organization fail to analyze deeper to figure-out the human element associated with it.
…
continue reading

1
Episode 27 - Five ideas to enhance the cyber immune system
5:36
5:36
Play later
Play later
Lists
Like
Liked
5:36IT security leaders are looking for cost effective security programs that enhance their cyber security immune systems. Listen to this podcast to learn those five key ideas.
…
continue reading

1
Episode 26 - CISO should redefine corporate security strategy
10:12
10:12
Play later
Play later
Lists
Like
Liked
10:12Cyber risk is business risk – CISO representation at board level is important to provide business solutions. Hence in the year 2020 – CISO’s should redefine the corporate security strategy.
…
continue reading

1
Episode 25 - Social media addiction is injurious to mental health
7:48
7:48
Play later
Play later
Lists
Like
Liked
7:48Increased adoption of digital make all generations to prey to social media platforms. With increase fake news or misinformation and lack of knowledge to perform fact check, mostly kids and adults are mentally affected and targeted for cyber bulling and online harassment.
…
continue reading

1
Episode 24 - Develop self defensing capabilities in applications
8:21
8:21
Play later
Play later
Lists
Like
Liked
8:21In mobile first market, organizations need to develop mobile applications that has self defensing capabilities. As the in-app protection technologies are new - DevOps leaders should invest time to learn and adopt implementing it for their high value applications. Listen to the self defensing capabilities here.…
…
continue reading

1
Episode 23 - Protection from Maze Ransomware
5:32
5:32
Play later
Play later
Lists
Like
Liked
5:32Maze is a file encrypting virus and also a successor to ChaCha. Organizations need to have protection strategies from being victim of similar cyber attacks. Listen to this podcast for more details
…
continue reading

1
Episode 22 - Recommendations to adopt Zero Trust principles
6:53
6:53
Play later
Play later
Lists
Like
Liked
6:53Organizations need to define zero trust strategy to enforce the security controls across the ‘defense in depth’ layers. Security in continuous process and require constant learning as the attacks are sophisticated and targeted. Adopting to Zero Trust principles keep the business safe from any breaches.…
…
continue reading

1
Episode 21 - India - The personal data protection bill, 2019
10:53
10:53
Play later
Play later
Lists
Like
Liked
10:53The Personal data protection bill, 2019 mandates to implement cyber security controls such as de-identification, encryption, protect integrity, prevent misuse, unauthorized access to modify, disclose or destruct of personal data. The bill has obligations to take prompt and appropriate action in response to a data security breach. It shall be liable…
…
continue reading

1
Episode 20 - Cyber security leaders need fraud prevention to protect their digital business
11:19
11:19
Play later
Play later
Lists
Like
Liked
11:19In this digital economy, online fraud detection systems are a necessary component in any security architecture and augment the basic application protection capabilities offered by a web application firewall and identity management solutions. Cyber security leaders need to know more about fraud management solutions. In this episode you'll hear key 4…
…
continue reading

1
Episode 19 - Digital business require ‘tailored’ security services
8:01
8:01
Play later
Play later
Lists
Like
Liked
8:01Every business is unique in its own way and adopting cyber security services that are ‘tailor-made’ with two-way communications will help address risks and challenges to safe-guard from data breaches.
…
continue reading

1
Episode 18 - Understand the MSSP (Managed Security Service Provider) services better
4:43
4:43
Play later
Play later
Lists
Like
Liked
4:43Enterprise prefer to outsource their IT security and believes that its cyber security operations are managed well. But - how well you understood their service descriptions. Listen to this episode to learn certain basic that are required for this digital business needs?
…
continue reading

1
Episode 17 - Enterprise can't protect threats, if they don't see it.
8:42
8:42
Play later
Play later
Lists
Like
Liked
8:42Data residency, compliance issues, and the need for visibility and monitoring of data continue to drive organizations to adopt data loss prevention capabilities. Enterprise can't protect threats, if they don't see it. Listen this podcast
…
continue reading

1
Episode 16 - How to bring 'WOW' factor in SOC visits
9:55
9:55
Play later
Play later
Lists
Like
Liked
9:55Experience is all about sense of feel, taste, music to ears, seeing and believing. Listen to this podcast that helps 'How to make the SOC visit as experience to bring the ‘wow’ factor'.
…
continue reading

1
Episode 15 - Digital workplace security for social media generations
6:46
6:46
Play later
Play later
Lists
Like
Liked
6:46Organizations need to have futuristic security strategy programs to enable digital workplace safe from cyber breaches. Business can’t expect that GenZ will only use emails channels for exchanging messages. They shall use social media platforms. Hence digital workplace security program should seamlessly identify, detect, protect and respond to cyber…
…
continue reading

1
Episode 14 - Machine first security operations delivery model
3:31
3:31
Play later
Play later
Lists
Like
Liked
3:31Machine first security delivery model require clear understanding of automation use cases and well document incident response playbooks. Organizations today finding ways and means to utilize both humans and machines in cyber security operations
…
continue reading
Zero Trust is taken from the principle of “never trust, always verify,” can achieve using micro segmentation by limiting the lateral movements between the network segments and only intended application access from outside. Trust security framework / Zero trust architecture helps customers to prevent unauthorized access, contain breaches, and reduce…
…
continue reading

1
Episode 12 - 72 hours for data breach notification
6:24
6:24
Play later
Play later
Lists
Like
Liked
6:24According to Article 33 – EU GDPR – “Notification of a personal data breach to the supervisory authority”; the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it. Unless organization has not prepared for data breach – it’s impossible to achieve the timeline of 72 hours notification and …
…
continue reading

1
Episode 11 - Deepfake – Seeing is no longer believing
5:40
5:40
Play later
Play later
Lists
Like
Liked
5:40Deepfakes exploit this human tendency using generative adversarial networks (GANs), in which two machine learning (ML) models duke it out. Deepfake technology is now being used to create high-fidelity phishing attacks where the phishing target, identity protection and fraud that're yet to come.
…
continue reading

1
Episode 10 - Enterprise should adopt active cyber defense strategy
5:49
5:49
Play later
Play later
Lists
Like
Liked
5:49Active cyber defense strategies unless do not violate regulation and law of the land are considered now as appropriate direct action to counter threats. Today’s security business function should have everything it needs to mount a competent defense of the ever-changing enterprise landscape
…
continue reading

1
Episode 9 - Unpatched vulnerabilities; Is it problem worth solving?
5:03
5:03
Play later
Play later
Lists
Like
Liked
5:03Organization continue to have ageing vulnerabilities remained unpatched and its serious problem that need solution that are effective to reduce the time that vulnerability discovered and patched. Listen to the four key strategic recommendations.
…
continue reading

1
Episode 8 - Cyber threat intelligence feeds for security operations
7:53
7:53
Play later
Play later
Lists
Like
Liked
7:53Organization need to detect the threat quickly and do not want to waste time investigating false negative alerts, thereby remediate the vulnerabilities and mitigating the attack vector more quickly. There are many cyber threat intelligence service providers in the market, and the number appears to be growing. Not all services that are marketed as t…
…
continue reading

1
Episode 7 - Application visibility is key for data center micro segmentation
5:55
5:55
Play later
Play later
Lists
Like
Liked
5:55Perimeter-based security approaches are no longer sufficient. The starting point for devising a micro-segmentation is discovering and identifying all the application flows within the data center. Listen to this podcast to understand it better.
…
continue reading

1
Episode 6 - Amazon focus on cyber security areas are AWS & Smart home security
5:52
5:52
Play later
Play later
Lists
Like
Liked
5:52Studies have indicated that most security breaches in the cloud (such as AWS) are due to settings errors, which a data breach costing an average of $6.5M, according to Cloudnosys. Amazon has two primary areas of focus for cybersecurity and data protection: Amazon Web Services (AWS) and smart home security.…
…
continue reading

1
Episode 5 - What Facebook doing to address cyber security gaps
6:03
6:03
Play later
Play later
Lists
Like
Liked
6:03After several cyber security and privacy issues reported against Facebook, its time to re-look their process, people and technology. Facebook began revamping its privacy policy, has restricted data access to various APIs, implemented a more stringent review process, and announced the hiring of an estimated 10,000 new employees who will focus on com…
…
continue reading

1
Episode 4 - Internet of things and cyber security recommendations
5:44
5:44
Play later
Play later
Lists
Like
Liked
5:44Internet connectivity is a two-way street. With these devices becoming a gateway to our homes, workplaces, and sensitive data, they also become targets for attacks. Lets learn what industry is doing with it and what recommendations are to be kept in mind while building security strategies.
…
continue reading

1
Episode 3 - Importance of security operational metrics and reports
7:16
7:16
Play later
Play later
Lists
Like
Liked
7:16Most organizations operate with limited financial and resource constraints, they need to prioritize security activities to maximize business benefits. When communicating to board on security financial reporting, its important to provide visibility beyond security operations and infrastructure. The measurements, metrics and reporting are vital in an…
…
continue reading
Backstory will become the backbone of many managed security service providers. In this episode, lets learn about Chronicle (Google Alphabet's project X moon shot) contribution to cyber security. Read my blog for more details https://rasoolirfan.com/2019/03/26/revolutionary-threat-hunting-platform-for-massive-data/…
…
continue reading

1
Episode 1 - Cyber security with MITRE ATT&CK
7:04
7:04
Play later
Play later
Lists
Like
Liked
7:04MITRE evaluates cybersecurity products using an open methodology based on our ATT&CK™ framework. In this podcast, lets get some basic knowledge on MITRE's contribution to industry with ATT&CK framework.
…
continue reading