Easy Prey

Auteur(s): Chris Parker
  • Résumé

  • Chris Parker, the founder of WhatIsMyIPAddress.com, interviews guests and tells real-life stories about topics to open your eyes to the danger and traps lurking in the real world, ranging from online scams and frauds to everyday situations where people are trying to take advantage of you—for their gain and your loss. Our goal is to educate and equip you, so you learn how to spot the warning signs of trouble, take quick action, and lower the risk of becoming a victim.
    Voir plus Voir moins
Épisodes
  • CISOs: The Ultimate Stress Test With Jill Knesek
    Feb 12 2025

    The CISO role is constantly changing. With all the shifts in cybersecurity, it's crucial to find ways to attract new talent to close the growing skills gap. CISOs now juggle complex systems managed at multiple levels and handle burnout amongst many other responsibilities.

    Today's guest is Jill Knesek. Jill is the Chief Information Security Officer for Blackline, a company that does financial SaaS solutions. It’s based out of the Los Angeles area. She’s been there almost three years now as the CISO, running the information security team.

    She previously served as Chief Security Officer for BT Global Services. She has more than 15 years' experience directing security programs, including service as a special agent for the FBI assigned to the Cyber Crime Squad in Los Angeles Field Office, where she was involved in several high-profile cases, including Kevin Mitnick.

    In this episode, we cover the CISO role evolving from low visibility to a C-level position, managing multi-cloud infrastructures and aligning with other teams and the ongoing cybersecurity skills gap and burnout. Jill also talks about incident response and crisis management and collaboration within the cybersecurity community to fill the blind spots and strengthen the defenses.

    Show Notes:
    • [01:23] She's now the Chief Information Security Officer for Blackline, a company that does financial SaaS solutions.
    • [02:00] She was also an FBI special agent for 3 and 1/2 years working cybercrime. She was super excited, because this was her lifelong dream.
    • [03:35] She loved the FBI, but she knew she could do more for the industry on the private side.
    • [04:21] Jill talks about how the CISO role has evolved. It's now a C-level position.
    • [06:26] Some of the boards were very interested in what was going on with security. There has to be a balance with funding and proving your success.
    • [07:39] Now complexity is an issue.
    • [09:03] The cloud adds so many connecting services.
    • [11:45] CISOs are getting more responsibility and need more qualified people in their teams. There's a gap with not enough people coming into the cybersecurity industry.
    • [12:30] How the idea of stress and working nights and weekends can deter some graduates from the cybersecurity industry.
    • [15:15] Boards and executive committees expect the CISO to be right in the middle of things. They want real-time updates and to know what everyone is working on right now.
    • [17:47] The importance of keeping a calm level-headed view when something goes wrong.
    • [21:41] We learn about the flow of straightening out curves or incidents. Learn during the small incidents and practice the process.
    • [23:57] The importance of not scolding the team for being too quick to react. It's better to have a false alarm than to ignore a serious problem.
    • [25:10] Jill does a one-to-one with everyone on her team each quarter. She tries to Mentor them with some of the things that she's learned.
    • [30:29] We hear about a couple of incidents where ransomware got into the environment.
    • [35:01] When someone else reported that something weird was going on in the network.
    • [38:27] To help with the talent gap, we need to start introducing cybersecurity at the high school level.
    • [42:15] It's important for CISOs to be connected with other groups and events.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • Jill Knesek at Blackline
    • Jill Knesek on LinkedIn
    Voir plus Voir moins
    45 min
  • AI, Automation, and the Future of Cybersecurity With Mike Lyborg
    Feb 5 2025

    With the increase in targeted cyber attacks, it's more important than ever for organizations to quickly identify and respond to threats. AI is helping security teams by acting as virtual analysts, handling much of the investigation work. However, human oversight is still essential for the final steps and judgment.

    Today's guest is Michael Lyborg. Michael is the Chief Information Security Officer at Swimlane. Prior to taking his current role, Michael was Global Vice President of Advisory Services, a highly sought-after expert by the world's largest Fortune 500 companies and global government agencies to advise on the creation and operation of industry-leading security operations.

    In this episode Michael shares his experience and wisdom on today’s cybersecurity challenges. We talk about the balance of automation and human oversight, the risks and rewards of putting AI into security operations, and defense in depth strategies. Michael also covers how military style threat assessments can help with cybersecurity, how AI is evolving for threat prioritization and analysis, and the need for continuous testing and monitoring to prevent automation failures. If you want to know how to stay ahead in a complex cyber world, this episode is full of practical advice.

    Show Notes:
    • [01:06] Michael has been with Swimlane for about 7 years mainly focusing on larger enterprises, government clients, and partners. He's helping with the automation journey and experience. He also built security programs for other companies and was a Marine.
    • [02:07] Prior to the Marines, he did IT and network security. Michael is originally from Sweden.
    • [04:22] Operational risk management or conducting a limited threat assessment. He's always thinking like a hacker and looking for gaps in security.
    • [06:29] Michael tells a story about his wife's recent experience with a cybersecurity scam.
    • [12:11] How a company decides what level of friction is appropriate to implement proper security.
    • [13:59] Michael talks about balancing what is and isn’t automated.
    • [16:16] Michael shares the story about his early days of automation.
    • [17:23] Continuously review and monitor your automations.
    • [18:41] Starting with documentation is a good first step.
    • [21:45] Michael talks about how awesome it is being able to work in security and automation and help businesses grow and achieve outcomes. He believes in automating the mundane tasks.
    • [22:26] We learn about AI being involved in the defensive side of cybersecurity.
    • [24:50] AI can also bridge the gap between the security team and non-technical people.
    • [26:33] We discuss places where AI probably shouldn't be used.
    • [27:58] Find where AI works for you and then think about incorporating it in your security services.
    • [31:01] The importance of having controls in place when using AI whether it's for security or data analysis.
    • [33:00] Risk can be reduced by training on specific tasks.
    • [34:18] Michael shares the value of mixing human and artificial intelligence through Swimlane.
    • [39:08] The importance of bridging gaps and getting rid of silos.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • Michael Lyborg on Swimlane
    • Michael Lyborg on LinkedIn
    Voir plus Voir moins
    42 min
  • Cybersecurity Training from Boring to Engaging With Howard Goodman
    Jan 29 2025

    The landscape of cybersecurity training and collaboration is changing, interactive education sessions and cross team communication is key. Building a security culture and staying ahead of the modern threats has never been more important. Today’s guest is Howard Goodman, Senior Technical Director at Skybox Security.

    With over 20 years of experience Howard has become a well known figure in the cybersecurity world, he combines strategic planning with hands-on application across many industries. In this episode we talk about; security culture, the evolution of cybersecurity training and how Howard got phished during COVID. We also cover organisational challenges, best practices and the future of cybersecurity.

    Show Notes:
    • [00:48] Howard has a doctorate in cyber operations from Dakota State University. Besides working for Skybox Security, he's also an adjunct professor teaching graduate courses about cyber security.
    • [01:48] Howard shares a phishing experience when he and his wife were selling on eBay during COVID.
    • [03:34] If the pros can fall for something, regular people can too. We need to be on our game 100% of the time.
    • [04:53] We talk about opportunities for adversaries to get in when companies have large cybersecurity teams with a lot of moving parts.
    • [05:29] A lot of people ignore phishing attempts instead of reporting them.
    • [06:04] It comes down to organizations training their people properly. Cyber security training is becoming more interesting, because the boring stuff just doesn't hold people's attention.
    • [10:13] When talking about threats, they focus on the exposure side and the exploitability side. With most businesses, functionality comes before security.
    • [12:47] Formal testing is required before upgrading security patches to make sure that they don't break down the whole system.
    • [13:47] The importance of being able to leverage other security controls while testing patches. Teams need to be able to communicate and act fast.
    • [14:52] Knowing about potential risk is the only way to be proactive.
    • [16:36] Looking at costs and gaps in technology. Failures are often due to a breakdown in communication.
    • [19:33] The approach of starting out security first.
    • [25:08] Best practices include cross-training. Working together and training together. Organizations need to run simulations and see how they react as an organization.
    • [31:06] Skybox talks to organizations about gaps in security.
    • [35:57] We discuss the loss that can happen from not having proper security measures in place.

    Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

    Links and Resources:
    • Podcast Web Page
    • Facebook Page
    • whatismyipaddress.com
    • Easy Prey on Instagram
    • Easy Prey on Twitter
    • Easy Prey on LinkedIn
    • Easy Prey on YouTube
    • Easy Prey on Pinterest
    • Dr. Howard Goodman - Skybox Security
    • Dr. Howard Goodman on LinkedIn
    Voir plus Voir moins
    40 min

Ce que les auditeurs disent de Easy Prey

Moyenne des évaluations de clients

Évaluations – Cliquez sur les onglets pour changer la source des évaluations.