Securing the Software Supply Chain

Securing the Software Supply Chain

Navigating Modern Cybersecurity: From Supply Chain Risks to AI Evolution. In this episode of ⁠Data Security Decoded⁠, ⁠Allison Wikoff⁠, a 20-year veteran in information security and threat intelligence, explores current cybersecurity challenges, emerging threats, and practical defensive strategies for organizations of all sizes. What You'll Learn: How to prioritize vulnerability management by focusing on critical edge devices and access points Why understanding your network architecture is crucial for effective threat defense The reality of AI in cyber attacks: current uses, limitations, and practical defense strategies How to build supply chain resilience through vendor assessment and backup supplier planning Why older vulnerabilities remain a primary attack vector and how to address them effectively The framework for developing an actionable threat profile tailored to your organization's needs Key Insights: Threat actors increasingly target known vulnerabilities over sophisticated zero-day exploits Supply chain security requires understanding vendor access levels and maintaining secondary suppliers AI adoption in cyber attacks remains focused on basic tasks like improving phishing emails and code generation Organizations should prioritize patching vulnerabilities in edge devices like VPNs and WAFs Building an effective security strategy starts with understanding your organization's specific threat profile Partnering with vendors and suppliers can help smaller organizations enhance their security capabilities Highlights: [00:00:00] Vulnerability Exploitation Trends Allison Wikoff reveals that vulnerability exploitation has become a dominant attack vector across both criminal and state-sponsored threat actors. The shift marks a departure from traditional assumptions that mainly espionage-focused groups leveraged vulnerabilities. [04:30] Supply Chain Security Essentials Wikoff emphasizes that modern supply chain security requires looking beyond just your own organization's defenses. Organizations must thoroughly understand their vendors' access levels and potential impact on operations. [07:23] AI in Cybersecurity: Reality vs Hype Tolin shares that while AI adoption by threat actors is increasing, it hasn't revolutionized attack tactics as many feared. Current AI usage focuses mainly on improving phishing email quality and assisting with malware code generation. [14:08] Threat Profile Development Tolin advocates for organizations to start by understanding what assets would interest attackers rather than chasing every new threat. The rapidly changing threat landscape makes it impossible to defend against everything, requiring a focused approach based on your specific risk profile. Episode Resources: Caleb Tolin on LinkedIn Allison Wikoff on LinkedIn PwC website PwC - Year in Retrospect Report 2024 Rubrik Zero Labs website

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(65)

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

The Terrorist Designation: A New Red Line for Ransomware with Cynthia Kaiser

Please enjoy this encore of Data Security Decoded. In this episode, host⁠⁠ ⁠Caleb Tolin⁠⁠⁠ explores the battlefield of enterprise defense, which has moved from simple data theft to ultra heinous cri...

15 Sep 29min

Agentic AI and Identity Sprawl

Agentic AI and Identity Sprawl

Please enjoy this encore of Data Security Decoded. In this episode of ⁠Data Security Decoded⁠, join host ⁠Caleb Tolin⁠ as he welcomes back ⁠Joe Hladik⁠, Head of Rubrik Zero Labs, to unpack the findi...

8 Sep 24min

AI Moves Fast. Privacy Has to Move Faster.

AI Moves Fast. Privacy Has to Move Faster.

Enjoy this encore of Data Security Decoded. AI promises speed, scale, and efficiency—but it also magnifies privacy risk in ways many organizations aren’t prepared for. In this episode, ⁠Caleb Tolin⁠...

25 Aug 25min

The Real Risks of Agentic AI in the Enterprise

The Real Risks of Agentic AI in the Enterprise

Please enjoy this encore of Data Security Decoded. As enterprises race to adopt AI, many are discovering that traditional security models no longer hold. In this episode of Data Security Decoded, ho...

18 Aug 27min

Top CISO Priorities and Global Digital Trust with Morgan Adamski

Top CISO Priorities and Global Digital Trust with Morgan Adamski

Please enjoy this encore of Data Security Decoded. Welcome to ⁠Data Security Decoded⁠. Join host ⁠Caleb Tolin⁠ in conversation with ⁠Morgan Adamski⁠ who leads Cyber, Data, and Tech Risk at PwC and i...

11 Aug 23min

Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest

Building Automation Frameworks and Tackling Cloud Archiving with Fred Lhoest

This episode delivers operational insights from the frontlines of global telecommunications, drawing on Fred Lhoest's experience managing IT infrastructure across 60 countries at PCCW Global. The disc...

28 Jul 17min

Securing Research Infrastructure and Managing Shadow AI with Kevin Mortimer

Securing Research Infrastructure and Managing Shadow AI with Kevin Mortimer

This episode explores the technical hurdles of protecting academic research environments and navigating the shift to automated cloud architectures, drawing on Kevin Mortimer's twenty five years of tec...

21 Jul 29min

Shifting Security and Protecting the Pharma Supply Chain with Andy Hillis

Shifting Security and Protecting the Pharma Supply Chain with Andy Hillis

This episode provides a technical exploration of security engineering within highly scrutinized life sciences environments, drawing on Andy Hillis' decades of operational history at The Almac Group. T...

14 Jul 34min

Populært innen Business og økonomi

stopp-verden
dine-penger-pengeradet
e24-podden
rss-penger-polser-og-politikk
rss-borsmorgen-okonominyhetene
rss-pa-konto
rss-skravla-gar
pengepodden-2
livet-pa-veien-med-jan-erik-larssen
lederpodden
finansredaksjonen
tid-er-penger-en-podcast-med-peter-warren
stormkast-med-valebrokk-stordalen
rss-orjasater
pengesnakk
morgenkaffen-med-finansavisen
liberal-halvtime
utbytte
okonomiamatorene
rss-markedspuls-2