Adopting Zero Trust

Written by: Adopting Zero Trust
  • Summary

  • Buzzword? Architecture? Perhaps a true security approach for modern organizations? Join us as we chat with organizations of all types and sizes to learn about their Zero Trust adoption journey and as we answer these questions along the way.
    Copyright 2023 All rights reserved.
    Show more Show less
activate_Holiday_promo_in_buybox_DT_T2
Episodes
  • Behind the scenes of cybersecurity media and reporting
    Nov 21 2024

    Season 3, Episode 15: We gather a panel of journalists, communications, and a researcher to discuss how cybersecurity news and incidents are reported.

    You can read the show notes here.

    In the world of cybersecurity journalism, you can broadly divide it into four competing forces: reporters, communications teams, researchers, and readers. Each requires the other to accomplish its goals, but they all have very different priorities and goals.

    • Journalists have a duty to inform the public about security-related events.
    • Communication teams have a duty to inform the public about related incidents and research, but in a controlled setting.
    • Researchers help provide answers to communication teams and journalists.
    • Readers want to be informed of information that impact them, and their habits shape what kind of reporting is invested in the most.

    This week we explore some of these dynamics by bringing together a panel representing comms, journalism, and research to discuss the game of tug-of-war during incident response and incident reporting.

    Danny Palmer was a long-standing cybersecurity reporter at ZDNet prior to recently joining DarkTrace, Josh Swarz is the Senior Communications Manager at Microsoft focusing on threat intelligence, our host Neal Dennis is former NSA and has lived many lives around either keeping secrets or uncovering them, and producer Elliot Volkman has been a reporter for two decades and works with Josh on elevating research at Microsoft Threat Intelligence.

    Show more Show less
    1 hr and 5 mins
  • GRC tool or spreadsheets, that is the question | GRC Uncensored Preview
    Oct 24 2024

    In our final preview episode of GRC Uncensored, we explore a particularly bipolar debate: do you need a GRC tool to manage compliance, or will spreadsheets suffice?

    After this, we will be back to our regularly produced AZT episodes. The last episodes of our pilot for GRC Uncensored can be found on your favorite podcast app or newsletter on Substack.

    Show more Show less
    43 mins
  • Podcast Preview: GRC Uncensored and the commoditization of compliance
    Oct 10 2024

    We are interrupting our regularly scheduled podcast series to introduce you to a new series we developed: GRC Uncensored.

    This pilot season will elevate conversations about GRC that are often buried under millions of dollars in marketing spend. No boring talks about controls or frameworks, just unfiltered discussions with auditors and practitioners in the GRC space. We'll be back to our regular AZT episodes in a couple of weeks.

    -----

    In the first episode of 'GRC Uncensored,' hosts Troy Fine, dubbed the 'GRC Meme King,' and Elliot Volkman, alongside guest Kendra Cooley dive into the complexities of Governance, Risk, and Compliance (GRC) in cybersecurity. The discussion unravels the 'love-hate' relationship many security professionals have with compliance frameworks like SOC 2, exploring how they have become commoditized and possibly devalued over time.

    The conversation touches upon the challenges security practitioners face in conveying the true value of GRC to businesses, the potential pitfalls of 'SOC in a box' offerings, and the broader implications of compliance becoming a 'check the box' exercise. Moreover, the episode delves into the broader regulatory landscape and the ongoing debates about the role of government regulations in cybersecurity compliance. This candid dialogue sets the stage for future episodes that promise further to dissect the nuances of cybersecurity audits and standards.

    00:00 Welcome to GRC Uncensored

    01:34 Introducing Kendra Cooley

    02:05 Love-Hate Relationship with GRC

    03:16 The SOC 2 Debate

    04:33 Challenges with SOC 2 Audits

    09:10 The Value of SOC 2 in the Industry

    12:04 The Evolution of Compliance Frameworks

    20:39 False Sense of Security in Compliance

    24:46 The Buzz Around AI and Quantum

    25:10 Staying Updated as a Security Professional

    26:45 Challenges in Penetration Testing and Vendor Assessments

    27:37 Compliance and Its Impact on Security

    30:10 Government Regulations and Their Effectiveness

    32:23 The Complexity of Privacy Laws

    38:29 The Role of GRC Teams in Risk Management

    42:30 Concluding Thoughts and Future Episodes

    Show more Show less
    42 mins

What listeners say about Adopting Zero Trust

Average Customer Ratings

Reviews - Please select the tabs below to change the source of reviews.