Filtra per genere
Feeling overwhelmed by cyber risk? You're not alone. In today's digital world, cyber threats are a complex issue and a strategic opportunity to strengthen your organization's resilience.
This podcast dives deep into the world of cyber governance and risk management. We'll have open conversations with experts to help you take your organization's cybersecurity posture from "as-is" to the next level.
Here's what you'll learn:
- Program and control assessments: Identify weaknesses in your current defenses.
- Risk identification and mitigation: Proactively address threats before they strike.
- Building a risk register: Track and prioritize your organization's vulnerabilities.
- Crafting effective mitigation plans: Develop strategies to minimize cyber risk.
- And much more!
Join us and learn how to navigate the ever-evolving cyber landscape with confidence.
- 108 - Seize Control: How CTEM Can Fortify Your Organization’s Defense
Send us Fan Mail In this episode, I will dive into Continuous Threat Exposure Management (CTEM) and how it revolutionizes vulnerability prioritization. I discuss the essential steps—scoping, discovery, prioritization, validation, and mobilization—required for effective risk management. Learn how to align your security efforts with mission-based goals and leverage CTEM to protect your organization's critical assets. Gain insights into overcoming implementation challenges and the necessity of i...
Fri, 29 Aug 2025 - 107 - The Unexpected Role of Impact in Cybersecurity Risk – A Must Know!
Send us Fan Mail Understanding Impact Assessment in Cybersecurity: A Deep Dive In this video, I tackle the questions: Does impact assessment exist in cybersecurity, and how is it conducted? I break down the fundamental formula of cybersecurity risk, which includes threat, vulnerability, and impact. The different types of impact—financial, reputational, and operational—and how to classify them. Discover the importance of context in impact analysis across device-level, application-level, and o...
Tue, 19 Aug 2025 - 106 - Missed Vulnerabilities: How to Fix and Prevent Them in Future Assessments
Send us Fan Mail It's a common, yet unsettling, scenario in cybersecurity risk assessment: discovering a crucial component was overlooked after an assessment is complete. The question often arises: "How do you handle missing risks in a risk assessment? What can you do in the situation, and how can you prevent this from happening again?" Let's unpack this compound query, focusing on mission-based cyber risk management and practical prevention strategies. Dr. B.
Thu, 31 Jul 2025 - 105 - Navigating the Human Element in Cybersecurity Risk Assessment
Send us Fan Mail As cybersecurity professionals, we often dive deep into the intricacies of networks, code, and vulnerabilities. We assume that identifying assets, scanning for weaknesses, and generating reports are the core of cybersecurity risk assessment. But if you've ever spent a day in a corporate environment, you know the biggest challenge isn't the technology; it's the people. Today, let's explore two critical points: how we got here and, more importantly, how we get out of it. Dr. B....
Fri, 25 Jul 2025 - 104 - Mastering Cyber Asset Sampling: Optimize Your Assessment Process
Send us Fan Mail Cyber Asset Assessment: Understanding the Importance of Sampling In this episode, I dive into the crucial step of sampling in cyber asset assessment. Learn why sampling is essential, especially when dealing with large environments and limited resources. Discover the various types of sampling methods, including probability and non-probability sampling, and understand how to statistically correlate your sample size to the total population of your cyber assets. Perfect for anyo...
Mon, 14 Jul 2025 - 103 - Unlocking the True Goal of Security: What You're Really Protecting
Send us Fan Mail In this episode, I dive into the essential first steps for a successful cybersecurity risk assessment. Unlike traditional methods, we emphasize the importance of aligning cyber protection with corporate objectives and mission-critical assets. Learn why it's crucial to go beyond regulatory requirements and how to accurately identify and cross-check your assets, from application servers to firewalls. Stay tuned for upcoming videos where we break down the comprehensive process f...
Mon, 07 Jul 2025 - 102 - Aggregate Risk Demystified: The Formula Every Business Needs
Send us Fan Mail How to Aggregate Vulnerability Risks Efficiently for Your IT Environment In this episode, we'll explore the comprehensive approach to scanning and evaluating the entire ecosystem of your application, including databases, firewalls, and routers. Discover a simple yet effective formula to aggregate the risks from hundreds of vulnerabilities and learn how to categorize these risks to support your corporate objectives and mission. This technique is especially useful for small to ...
Thu, 26 Jun 2025 - 101 - Unpacking Trump’s Cybersecurity Orders: Key Updates and What They Mean for National Security
Send us Fan Mail President Trump Amends Cybersecurity Executive Orders: Key Impacts and Analysis In this episode, we delve into President Trump's recent amendments to Executive Orders 13694 and 14144, primarily focusing on enhancing national cybersecurity. We outline six key areas of impact, including specific threat identification, secure software development, post-quantum cryptography preparations, AI in cyber defense, modernizing federal systems, and defining scope in sanctions and applica...
Thu, 12 Jun 2025 - 100 - Optimizing SIEM Storage Costs: Effective Logging Strategies
Send us Fan Mail Optimizing SIEM Storage Costs: Effective Logging Strategies Is storage really as cheap as people think? This episode delves into the true cost of storage in the context of Security Information and Event Management (SIEM) systems. We explore traditional logging practices and their impact on storage, especially with the rise of cloud computing and hybrid environments. The key focus is on identifying critical applications and underlying architectures to optimize logging process...
Fri, 06 Jun 2025 - 99 - One Insight from 1978 Could Change Your Cybersecurity Strategy
Send us Fan Mail The Importance of Managerial Controls in Cybersecurity: Insights from 1978 In this episode of Doctor's Advice, Dr. B discusses the critical idea presented by Steward Madnick in 1978, emphasizing that computer security can't rely solely on technical measures. Dr. B explains how operational computer security requires managerial controls, such as policies, standards, and procedures. The conversation highlights the importance of prioritizing the protection of systems that align w...
Mon, 02 Jun 2025 - 98 - The DeepSeek Deception - A Story of Skepticism, Cybersecurity, and the Pursuit of Truth
Send us Fan Mail The world is awash in information, but clarity is a rare commodity. We're bombarded with headlines, statistics, and pronouncements, all vying for our attention and belief. But in this age of information overload, a healthy dose of skepticism is not just valuable; it's essential. This is especially true in the realm of cybersecurity, where threats are constantly evolving, and the stakes are higher than ever. Take a listen. Dr. B.
Fri, 31 Jan 2025 - 97 - The AI Revolution: Humanity's Next Great Leap in Cybersecurity
Send us Fan Mail Ready to explore the fascinating intersection of AI and cybersecurity? My latest podcast episode is live, and it's packed with insights you won't want to miss! **In this episode, we delve into:** - **The AI Advantage:** Discover how AI is revolutionizing threat detection, prediction, and response, acting as a tireless guardian in the digital realm. - **The Human Element:** Understand why AI is not a magic bullet and how human intelligence remains crucial for setting the mis...
Thu, 30 Jan 2025 - 96 - Why Cybersecurity is Everyone's Responsibility
Send us Fan Mail 🛡️ Cybersecurity is EVERYONE'S Responsibility! 🛡️ Think cybersecurity is just for the IT department? Think again! In this episode, we break down the dangerous misconception that cybersecurity is just about firewalls and antivirus software. It's about protecting your organization's mission, values, and people. **Here's what you'll learn:** - **Why cybersecurity is a shared responsibility** - from the marketing team to the receptionist, everyone has a role to play. - **How ...
Thu, 23 Jan 2025 - 95 - Cyber Risk Appetite
Send us Fan Mail Forget the magic numbers. Cyber risk appetite isn't about finding a one-size-fits-all percentage of revenue. It's about protecting your company's dreams. In this episode, we dive deep into the WHY behind cyber risk appetite. We explore how a strong understanding of risk tolerance can safeguard your mission, reputation, and customer trust. Discover: The crucial factors that shape your cyber risk appetite (hint: it's more than just revenue!).Why a mission-driven approach to ...
Thu, 09 Jan 2025 - 94 - Cybersecurity in the Age of AI- Back to Basics
Send us Fan Mail An article from Gartner named "AI in Cybersecurity: Define Your Direction" explores the impact of AI, particularly generative AI (GenAI), on the cybersecurity landscape. While acknowledging the transformative potential of AI and the hype surrounding it, the article emphasizes that this technology also introduces new risks and challenges. Dr. B.
Thu, 19 Dec 2024 - 93 - Cybersecurity Risk Management A CISO's Guide to Leadership in an Evolving Threat Landscape
Send us Fan Mail Cybersecurity risk management has taken center stage for organizations across all industries in the wake of recent high-profile cyberattacks, such as the SolarWinds breach and the Colonial Pipeline ransomware incident. As a CISO, you know firsthand the challenges and complexities that organizations face in navigating this ever-evolving threat landscape. Today, I'll share insights and leadership advice on how to build a robust and resilient cybersecurity program using four key...
Thu, 12 Dec 2024 - 92 - Stronger Cybersecurity and Smarter Spending
Send us Fan Mail The Cyber Defense Matrix (CDM) model tackles the difficulties of cost-effective and resilient cybersecurity planning by offering a structured framework to select and implement the most critical security controls, considering factors like budget, risk tolerance, and usability constraints. Dr. B.
Thu, 05 Dec 2024 - 91 - Cybersecurity Compliance: Hype or Bust?
Send us Fan Mail In cybersecurity, organizations are constantly grappling with the question of compliance. Is it merely a checkbox exercise, a source of unnecessary overhead, or a fundamental pillar of a robust security posture? The debate surrounding cybersecurity compliance often centers on the perceived tension between agility and adherence to regulatory frameworks. Here, I aim to dive into this complex issue, examining the arguments for and against compliance and ultimately providing insi...
Thu, 28 Nov 2024 - 90 - Expert as the Instrument
Send us Fan Mail In cybersecurity, organizations face a relentless barrage of threats that can compromise their sensitive data, disrupt operations, and tarnish their reputation. While quantitative data and automated tools play a crucial role in identifying and mitigating risks, the value of human expertise remains paramount. As D. Hubbard eloquently stated in 2014, "The expert is the instrument,” emphasizing the irreplaceable role of experienced professionals in navigating the complexities of...
Thu, 21 Nov 2024 - 89 - Cybersecurity Risk Management Governance Process
Send us Fan Mail Organizations face an ever-increasing array of cyber threats. A proactive and strategic approach to cybersecurity risk management is essential to counter these risks. This process not only safeguards an organization's valuable digital assets but also elevates the visibility and influence of the cybersecurity team. The cybersecurity team can demonstrate its indispensable value by strategically aligning risk management practices with the core business objectives. This alignment...
Thu, 14 Nov 2024 - 88 - Cybersecurity and Emerging Technologies
Send us Fan Mail The rapid advancement of technology brings unprecedented opportunities and significant cybersecurity risks. The World Economic Forum's (WEF) October 2024 white paper, "Navigating Cyber Resilience in the Age of Emerging Technologies: Collaborative Solutions for Complex Challenges," offers a deep dive into these evolving risks and proposes a shift towards a more resilient approach to cybersecurity. Dr. B.
Thu, 07 Nov 2024 - 87 - The Human Factor vs. the Algorithm
Send us Fan Mail Organizations grapple with a complex challenge: striking the right balance between human expertise and algorithmic insights. As highlighted by Hubbard (2014), a prevailing trend is the tendency for individuals within organizations, including senior management, to overvalue their own opinions and ideas, even when confronted with data-driven insights generated by sophisticated algorithms. This phenomenon, often referred to as the "expertise paradox," can have significant implic...
Thu, 24 Oct 2024 - 86 - The Cybersecurity Analysis Placebo: Measuring for the Illusion of Control
Send us Fan Mail The adage "what gets measured gets managed" holds significant weight in cybersecurity. Organizations invest heavily in metrics, Key Performance Indicators (KPIs), and risk assessments, aiming to quantify their cybersecurity posture and demonstrate progress. However, a growing concern emerges: the "analysis placebo" effect, as highlighted by Hubbard (2014). This phenomenon suggests that the act of measuring itself can create a false sense of security, leading organizations to ...
Thu, 24 Oct 2024 - 85 - Risk Management for SMBs
Send us Fan Mail Cybersecurity is no longer a luxury but a necessity for small and midsize businesses (SMBs). Cyber threats are becoming increasingly sophisticated, and SMBs are often seen as easy targets due to their perceived lack of resources and security measures. However, with the right approach, SMBs can implement robust cybersecurity risk management programs that are both effective and affordable. Dr. B.
Thu, 17 Oct 2024 - 84 - 5 must-do’s for effective cyber risk management
Send us Fan Mail Establishing a robust cybersecurity risk management program is paramount for any organization. As a CISO, the task of safeguarding critical assets and sensitive data can be daunting. However, leveraging the Cyber Defense Matrix (CDM) as a strategic framework can lay a solid foundation for your cybersecurity program and proactively mitigate risks. This article outlines the first five crucial steps I would take if tasked with setting up a cyber risk management program, emphasiz...
Fri, 11 Oct 2024 - 83 - 2024 ISACA State of Cybersecurity
Send us Fan Mail Today, I discuss and present the report's findings and share some of my thoughts on each finding from this survey. Thanks. Dr. B.
Thu, 10 Oct 2024 - 82 - Endpoint Security
Send us Fan Mail Endpoints such as laptops, desktops, mobile devices, and servers remain a prime target for attackers. These devices, serving as gateways to critical business data and systems, are constantly under siege from malware, ransomware, phishing attacks, and other sophisticated threats. As a CISO, safeguarding your organization's endpoints is a matter of cybersecurity and a strategic financial imperative. Here, I will discuss endpoint security, exploring how solutions like antivirus,...
Thu, 10 Oct 2024 - 81 - Bolstering Application Security
Send us Fan Mail Applications have become the lifeblood of businesses, driving innovation and operational efficiency. However, this reliance on applications also exposes organizations to a myriad of cyber threats. Attackers are increasingly targeting vulnerabilities within applications to gain unauthorized access, exfiltrate sensitive data, and disrupt critical business functions. As a CISO, safeguarding your organization's application portfolio is paramount. Here, we dive into the domain of ...
Thu, 03 Oct 2024 - 80 - Network Security as a Financial Strategy
Send us Fan Mail As CISOs, you are entrusted with safeguarding our organizations' digital assets. However, this responsibility extends beyond mere technical implementation; it encompasses a financial imperative. In today's threat landscape, network security vulnerabilities can lead to devastating financial losses, from data breaches and regulatory fines to operational disruptions and reputational damage. Here, I’ll dive into the critical role of network security within the Cyber Defense Matri...
Thu, 26 Sep 2024 - 79 - IAM - The Keys to Your Cybersecurity Kingdom
Send us Fan Mail The critical role of Identity and Access Management (IAM) in today's complex digital landscape. IAM is essential for controlling access to valuable assets, both in the cloud and traditional datacenters. The cloud's dynamic nature requires a robust IAM strategy incorporating centralized identity management, dynamic authorization, and strong authentication, including multi-factor authentication (MFA). For datacenters, best practices include privileged access management (PAM), n...
Mon, 23 Sep 2024 - 78 - The CISO's Financial Imperative
Send us Fan Mail In the boardroom and the server room, today's CISO faces a dual challenge: safeguarding the organization's digital assets while demonstrating the tangible value of cybersecurity investments. The Cyber Defense Matrix emerges as a strategic bridge between these imperatives, offering a structured framework to identify security gaps, prioritize spending, and align defensive strategies with business goals. This podcast explores how CISOs can leverage the Cyber Defense Matrix to ma...
Thu, 19 Sep 2024 - 77 - Measuring Success
Send us Fan Mail Today, we’re tackling a crucial topic for any Chief Information Security Officer—how to validate your Cyber Defense Matrix using Key Performance Indicators or KPIs. This episode is for you if you're looking for actionable ways to measure and enhance your security posture. The Cyber Defense Matrix is an invaluable framework for organizing and understanding your cybersecurity strategy. But its true power comes into focus when its effectiveness is quantifiable. Today, we'll expl...
Mon, 16 Sep 2024 - 76 - Cybersecurity Risk Assessment - Unreliable
Send us Fan Mail Cybersecurity risk assessment is a very effective tool; however, it can not be done using a survey instrument. Here are my thoughts on the matter. 🎓 FREE MASTERCLASS: Learn all about cybersecurity project success, from pitch to approval! Join me: https://www.execcybered.com/cybersecurity-project-success-from-pitch-to-approval. 🚀 Connect with us on: 👥LinkedIn: https://www.linkedin.com/company/exceccybered/ 📺YouTube: https://bit.ly/3BGOtPA 🔒 Secure your knowled...
Mon, 03 Jun 2024 - 75 - Cybersecurity Risk Assessment - Device (Protect)
Send us Fan Mail Read more: https://buff.ly/3UST8aE FREE MASTERCLASS https://www.execcybered.com/cybersecurity-project-success-from-pitch-to-approval
Mon, 25 Mar 2024 - 74 - Cybersecurity Risk Assessment - Device (Identify)
Send us Fan Mail Read more: https://www.execcybered.com/blog/cybersecurity-risk-assessment-device-identify FREE MASTERCLASS https://www.execcybered.com/cybersecurity-project-success-from-pitch-to-approval
Mon, 26 Feb 2024 - 73 - Cybersecurity is a Business Issue
Send us Fan Mail Alarmed by "Have you heard cybersecurity is a business issue?" But WORRIED your education left you UNPREPARED to face it? Colleges and certificate programs rarely teach business, communication, or sales skills crucial for cybersecurity careers. Don't fret! My YouTube video talks about the essential soft skills missing from your education. Learn how to navigate business dynamics, communicate effectively, and even close deals in the cybersecurity field with my free trai...
Tue, 06 Feb 2024 - 72 - Zone Defense
Send us Fan Mail Zone Defense - Another strategy to add to your cybersecurity program. How to defend your organization from cybersecurity breaches and today's cyber attacks. One quick sec cybersecurity rule to add to your strategy arsenal is discussed here.
Tue, 30 Jan 2024 - 71 - Emerging Threats - Risk Management
Send us Fan Mail In this week's podcast, I discuss the required steps to establish a risk or vulnerability program in your organization. Check it out!
Mon, 22 Jan 2024 - 70 - AI Corporate Series - Policy and Governance
Send us Fan Mail Areas to Address:Adoption challengesRisksGovernanceRoles and responsibilities Scope to Consider:Can the users use Generative Artificial Intelligence (GAI)? (External GAI vs. Internal GAI)Which department is responsible for documenting the need for GAI and aligning it with corporate objectives?Third-party & GAI, including software featuresPrivacyContractual obligationsResponsible AIRegulatoryOutput qualityInherited bias Governance:Who is responsible?Who...
Thu, 22 Jun 2023 - 69 - Unveiling the Intersection The Impact of COVID-19, the Green Transition, the Rise of AI, Microeconomic Uncertainties, and Cybersecurity
Send us Fan Mail In an interconnected world, the impact of various global trends is not limited to individual domains. The convergence of COVID-19, the green transition, the rise of AI, microeconomic uncertainties, and cybersecurity have created a complex landscape with challenges and opportunities. Let's explore the intricate relationship between these forces, shedding light on cybersecurity's significant role in this new era. Read more here: https://www.execcybered.com/blog/unveilin...
Thu, 15 Jun 2023 - 68 - Upskilling and Reskilling in Cybersecurity
Send us Fan Mail With increasingly sophisticated cyber threats, organizations must prioritize protecting their sensitive data and networks. As a result, the demand for skilled cybersecurity professionals has skyrocketed, creating a unique opportunity for individuals to upskill or reskill in this high-demand field. Today, I will explore the significance of upskilling and reskilling in cybersecurity and provide valuable insights into navigating this dynamic industry effectively. Want to...
Fri, 09 Jun 2023 - 67 - ChatGPT
Send us Fan Mail Have you heard? ChatGPT 4.0 is here, so what is your corporate strategy? Let me give you a few pointers to think about.
Thu, 27 Apr 2023 - 66 - 5 Cybersecurity Controls - Reduce 85% of Cyber RiskThu, 20 Apr 2023
- 65 - A Hard Look
Send us Fan Mail A Hard Look Honest communication between board members and information officers is critical to good cybersecurity. Cyber experts must relay their insights through non-technical storytelling and make a pertinent business case. Business leaders should aim for a cyber-aware culture permeating an entire organization. Read more: https://www.weforum.org/agenda/2022/12/cybersecurity-board-collaboration/ ========== How can a vCISO help your organization? The CISO role is all ...
Thu, 13 Apr 2023 - 64 - Threat Modeling
Send us Fan Mail Is your organization using threat intelligence to run threat modeling? If not, that’s a miss-opportunity. Your organization should establish desktop exercises or an informal cross-functional team to run threat modeling scenarios. This team would do the following four steps: Identify and characterize the systems supporting the organization's mission and objectives as a starting point. Identify the cybersecurity stack capabilities protecting these systems. Identify and ...
Thu, 06 Apr 2023 - 63 - Neglected NIST Concepts
Send us Fan Mail The Neglected Pages of NIST When you download a NIST document, whether NIST 800-53, NIST 800-39, NIST 800-37, or the NIST Cybersecurity Framework, what page do you start reading first? ========== How can a vCISO help your organization? The CISO role is all about the strategy, leadership, management, and communication of how potential threats will be assessed and solved. The CISO will absorb the big picture and dismantle it and restructure it to ensure it meets the ini...
Thu, 30 Mar 2023 - 62 - Financial Institutions - Theft of Funds
Send us Fan Mail How a vCISO can help your organization? The CISO role is all about the strategy, leadership, management, and communication of how potential threats will be assessed and solved. The CISO will absorb the big picture and dismantle it and restructure it to ensure it meets the initiatives of the department and the organization. ========== How can a vCISO help your organization? The CISO role is all about the strategy, leadership, management, and communication of how potent...
Thu, 23 Mar 2023 - 61 - Financial Institutions - Theft of Information
Send us Fan Mail Theft of Information is present in every organization and varies widely concerning value. The value of information is directly related to its criticality to the business. However, information can be further characterized along a continuum of data, information, and knowledge that reflects variances. “Data becomes information when endowed with relevance and purpose;” there are numerous motivating factors for threat actors and criminals to steal data, such as aiding in t...
Thu, 16 Mar 2023 - 60 - Operational and Strategic Perspective
Send us Fan Mail Do you have an operational or strategic view when protecting your organization's systems? ========== How can a vCISO help your organization? The CISO role is all about the strategy, leadership, management, and communication of how potential threats will be assessed and solved. The CISO will absorb the big picture and dismantle it and restructure it to ensure it meets the initiatives of the department and the organization. Let E|CE help your Small Business Contact us: ...
Thu, 09 Mar 2023 - 59 - Acronyms, Jargons, and Idioms
Send us Fan Mail Acronyms, Jargons & Idioms Impacting Communication Between Board, C-Suite, and Specialists. Communication is a two-way street, and company executives must be prepared to ask their own questions exploring the data being presented to them. The questions can be simple and direct, such as Can you elaborate on how this presented data impacts our company's objective(s)? What percentage of these vulnerabilities impact the systems supporting our company's mission and obje...
Thu, 02 Mar 2023 - 58 - Mission-Centric Risk Metrics
Send us Fan Mail Mission-Centric Cyber Risk Metrics Understanding what to measure in a mission-critical risk program is important, so today, I'll discuss a framework you can use. 1. Identify the system's environment (production, development, test, etc.) 2. System's criticality 3. Business Area ownership 4. Solution(s) being hosted on the identified systems 5. Top controls being violated 6. Vulnerabilities identified 7. Minimum Security Baselines non-conformance 8. Internal audit findi...
Thu, 23 Feb 2023 - 57 - Expanding Cyber Risk Beyond IT
Send us Fan Mail Retail banking takes care of regular daily banking, for which most people know banks. This includes providing checking and saving services and issuing credit cards. Retail banking divisions may also be in charge of providing loans, mortgages, and other financings. Some other products and services may be offered under retail banking divisions: Lines of credit, Investment management and accounts, Insurance Retirement, and education accounts. Ask a simple, broad, and ope...
Thu, 16 Feb 2023 - 56 - Three Cybersecurity Checkups
Send us Fan Mail Technologies and the methods used to hack into them continuously evolve. If you’re looking for an effective and efficient way to check the cybersecurity health of your organization, I suggest the following three checkups: Vulnerability and Penetration: Test Once you know the mission-critical systems in your organization, I suggest performing these two cybersecurity tests on a continuous basis.Vulnerability Scans & Software Updates Scanning: your mission-critical s...
Thu, 09 Feb 2023 - 55 - Cybersecurity - A Core Business Risk
Send us Fan Mail Do you believe these are business challenges? UpskillingLow morale or quiet quittingHiring and talent retentionKeeping up with technology and toolsIf so, why aren’t you considering cybersecurity as a core business challenge? It takes 280 on average days to identify and contain a data breach, and the average cost is $3.86 million. Stolen or compromised employee credentials initiate the lion’s share of those breaches. Small business advisory boards and panels must star...
Thu, 02 Feb 2023 - 54 - A Worthy Mention - Antivirus Software
Send us Fan Mail Antivirus has become a necessary tool for preventing cyber incidents; while the market is crowded, you need to look for antivirus software that fits your organization’s needs. NIST has guidance that you can leverage; NIST 800-83 recommends key capabilities that an antivirus software must have: Scanning startup files and boot recordsReal-time scanning of emails and email attachments for malwareBehavior monitoring of emails, browsers, and instant messaging softwareScann...
Thu, 26 Jan 2023 - 53 - Greater than Cybersecurity
Send us Fan Mail Greater than Cybersecurity When we realize that our cybersecurity challenges are complex and intertwined with conscious living people who view their actions in light of stories with emotions and ideas attached, one sees the need for many different perspectives. Therefore, the solution for your cybersecurity challenges will require knowledge beyond its discipline; it will involve communication, marketing, business, psychology, and sociology, among others. Howev...
Thu, 19 Jan 2023 - 52 - Protective Techology
Send us Fan Mail Protective Technology The last item I want to mention under the Protect function that supports the attack surface reduction and limits the cyber events' impact on your systems is “protective technologies.” Remember, protecting your organization involves six critical cybersecurity categories: Access ControlAwareness and TrainingData SecurityInformation Protection Processes and ProceduresMaintenance Protective Technologies The restriction of removable ...
Thu, 12 Jan 2023 - 51 - Information Protection - Processes & Procedures
Send us Fan Mail Ideally and preferably, your cybersecurity program should follow established policies, standards, and procedures. These documents will govern all organization members, including staff, vendors, volunteers, and anyone working on the organization’s behalf. The first step towards information protection is to develop and maintain a baseline configuration for IT and OT systems if this applies to your organization that incorporates appropriate cybersecurity principles, suc...
Thu, 05 Jan 2023 - 50 - Protect - Data Security
Send us Fan Mail Data Security The third of the six critical cybersecurity categories I presented previously is “data security.” An organization's most valuable asset is data; hackers seek data sources to steal from businesses, governments, and non-profit organizations, including small and midsized companies. Data must be protected in transit and at rest. The NIST CSF addresses data security in its Protect function under its data security category (PR.DS). The first and second ...
Thu, 29 Dec 2022 - 49 - Protect - Awareness and Training
Send us Fan Mail Securing and protecting your organization also takes a village to make happen, so cybersecurity awareness and training become very important; there’s so much technology can do to protect against phishing and its infinite variations, including the most efficient one, the Business Email Compromise (BEC); the FBI calls it “one of the most financially damaging online crimes.” The NIST Framework addresses awareness and training in its Protect function under the category P...
Thu, 22 Dec 2022 - 48 - Education
Send us Fan Mail The problem educational narrative about “college” has created a false dichotomy between the two well-discussed college purposes. Some say college is about preparing a person for work – to help them get better employment or career. The other camp says college is about preparing an individual for success in life. Many of us see the purpose of college as both a job-driven and a career-driven purpose. However, our conversation is incredibly stuck in the either/or debate o...
Thu, 15 Dec 2022 - 47 - Addressing the Highest Risks Podcast
Send us Fan Mail Addressing the Highest Risks As we conclude the risk assessment and governance process, the last part will deal with the organization's highest risks, not the highest vulnerability, but rather the highest risks. This work could take the form of desktop exercises or brainstorming sessions. NIST cover this effort in the subcategory ID.RA-6 “Risk responses are identified and prioritized.” The process NIST lays out are: Implement a process to ensure the security p...
Thu, 08 Dec 2022 - 46 - Cybersecurity Risk Assessment
Send us Fan Mail Cybersecurity Risk Assessment Risk assessment is not necessarily scanning your network aimlessly; what should you expect from your team? First and foremost, adopt a risk assessment framework; it will be a helpful guide for determining what is assessed, who needs to be involved, and the criteria for developing risk criteria. Some of the frameworks you should consider are: OCTAVE from Carnegie Mellon University NIST 800-30 Guide for Conducting Risk Assessments I...
Thu, 01 Dec 2022 - 45 - Cybersecurity Governance
Send us Fan Mail Cybersecurity Governance Once you have your hardware and software inventories, the next step might not be obvious. Still, before performing a risk assessment, you’ll need to establish a governance structure to report risk and regulatory, legal, and operational requirements. This particular governance requirement is covered in the NIST CSF subcategory ID.GV-4 “governance and risk management processes address cybersecurity risk.” As cybersecurity risk continues to es...
Thu, 24 Nov 2022 - 44 - Cybersecurity Risk Management - Software Platforms
Send us Fan Mail The NIST CSF subcategory ID.AM-2 deals with the inventory of software platforms and applications used in your organization. Most organizations will that creating an inventory of software to be a bit more challenging than creating one for hardware. When developing the inventory, make sure to take a holistic view of your organization’s operations and functions to build a comprehensive list of the software used in each line of operations. Similar to the approach used...
Thu, 17 Nov 2022 - 43 - Cybersecurity Risk Management - Physical Devices
Send us Fan Mail Cybersecurity Risk Management - Physical Devices The risk management process entails four fundamental concepts, which can be further broken down; however, the fundamental concepts are: Frame risk Assess risk Respond to risk once determined Monitor risk on an ongoing basis However, before getting here, other fundamental steps must be in place, and one that I have discussed here in the past has been asset management. Today I want to give you a bit more detail on thi...
Thu, 10 Nov 2022 - 42 - Questions Boards Should Ask
Send us Fan Mail Questions Boards Should Ask The challenge for directors or investors is determining the organizational overall cybersecurity maturity relative to the risk. The board of directors, in particular, has an oversight problem to solve, not a management problem. To quickly explore organizational thinking and cybersecurity management, here are five questions to get the discussion started in the effort to provide oversight and due diligence. *** FREE GUIDE *** https://www.ex...
Thu, 03 Nov 2022 - 41 - Cybersecurity Confidence vs Performance
Send us Fan Mail Cybersecurity Confidence vs. Performance Several studies conducted in other fields showed how spending effort on analysis improved confidence even when the actual performance was not improved. A study by the University of Chicago in 2008 tracked the probability of outcomes of sporting events as assigned by participants. These participants were given varying amounts of information about the teams, except the team’s name or players. As fans were given more information...
Thu, 27 Oct 2022 - 40 - The MOST Important Cybersecurity Principle
Send us Fan Mail Asset management is most commonly associated with cybersecurity hygiene, which is associated with patching, anti-virus, access control, and other asset-specific protections. However, there are three NIST CSF sub-categories that I want to bring to your attention and how they align with a mission-based cybersecurity risk program. ID.AM-1: Physical devices and systems within the organization are inventoried. ID.AM-2: Software platforms and applications within the organ...
Thu, 20 Oct 2022 - 39 - 5 Focus Areas - Third-Party Risk Measurements
Send us Fan Mail There are two types of third-party risk: product vendors and service providers. Product vendors outsource software, platform, and infrastructure, known as SaaS, PaaS, and IaaS. According to some estimates, only 40% of applications are hosted on-premises. The service providers are consulting third-party vendors, such as management consultants, IT consultants, Cybersecurity consultants, and managed service consultants. However, regardless of the type of third-party ven...
Thu, 13 Oct 2022 - 38 - 5 Must-Have Cybersecurity Strategies for Small Businesses
Send us Fan Mail Cyber attacks targetting small businesses that often do not have the resources to defend against devastating attacks like ransomware have grown. As a small business CEO or CIO, you have likely come across outdated security advice that does not help prevent the most common attacks. The security landscape has changed, and your cybersecurity knowledge needs to evolve with it. Here are 5 tips to get you started: Establish a culture of [cyber] security Talk about cyberse...
Thu, 06 Oct 2022 - 37 - Third-Party Risk Management
Send us Fan Mail Third-Party Risk Management The third-party outsourcing trend will continue to grow in the coming years, which places third-party risk as a significant concern for organizations, large or small. Depending on which statistics you read, 39-63% of breaches are caused by third parties. One of the most notorious breaches is the case of Target, where the HVAC vendor’s credential was stolen, resulting in the retailer's breach of 40 million credit and debit card numbers and ...
Thu, 29 Sep 2022 - 36 - Chasing Perfection
Send us Fan Mail Chasing Perfection Pursuing perfection takes a lot of resources, financially and people. In Cybersecurity risk management, there are two key questions: When will enough be enough? What is the correct amount of time and effort should your organization spend to achieve a reasonable level of cybersecurity against an attacker?The answer to these questions will be your risk tolerance. Chasing perfection has challenges and may not get you where you want to be. Ch...
Thu, 22 Sep 2022 - 35 - Cybersecurity Risk & Budget Challenges
Send us Fan Mail Amid a global financial crisis and potentially facing cybersecurity budget challenges, you are now facing a tough decision; how to do more with less. What if I told you that you can; change the focus of your cybersecurity risk management program from a threat/vulnerability-centric focus to a mission-centric focus. Using the same people, processes, and technologies you have but targeting critical systems in your organization. This change in strategy will allow your cyb...
Thu, 15 Sep 2022 - 34 - 5 Rules for Cybersecurity Risk Metrics
Send us Fan Mail Rules for Effective Cybersecurity MetricsFirst, you must establish agreement among your leadership on the actual risk(s) to measure, then select which data will provide the most accurate representation of the risk. The following are 5 fundamental rules for measuring cybersecurity risk: Select informative measures with actionable value to leadershipResearch other subject matter experts have done and workedKeep the math simple and clearDevelop a standard reporting forma...
Thu, 08 Sep 2022 - 33 - Mission-Centric Risk Assessment - Preparation
Send us Fan Mail Mission Centric Risk AssessmentIn a mission-based risk assessment, the question is, how do you perform one? A four-layer approach will be a good start: Mission layerOperational layerApplication layerInfrastructure layer======== Blog: https://www.execcybered.com/blog Training: https://www.execcybered.com/iso27001foundationcourse Linkedin: https://www.linkedin.com/company/exceccybered/ Twitter: https://twitter.com/DrBillSouza Instagram: https://www.instagram...
Thu, 01 Sep 2022 - 32 - Top 2 Measurement Challenges
Send us Fan Mail When measuring risk in your organization, you’ll typically discover two challenges: First, top key risk measures that do not have supporting data (aspirational). Second, you’ll be developing middle to low measures with supporting data that do not entirely address the risk. The lack of data to calculate a particular measure is no reason not to measure the risk; these are your aspirational measures; setting an organizational ambition or goal for your cybersecurity...
Thu, 25 Aug 2022 - 31 - Cybersecurity Report BoD
Send us Fan Mail Cybersecurity Report Framework to the Board of Directors There is a three-point framework to keep in mind when preparing a report to the Board, especially if you are a small to medium-size business with annual revenue between $100M to $700M with [potentially] no CISO in your organization. What are key risks the Board should be aware of at a high level? What should they be offered a deeper understanding of?How do these risks align with the organization's strategic init...
Thu, 18 Aug 2022 - 30 - Business Value
Send us Fan Mail How do you understand a digital asset's business value? First, let’s define what a digital asset is; a digital asset is a system, process, data, and technology that is used. A cyber event could affect one or more of these digital assets, resulting in a loss for the business. These digital assets have a hierarchical relationship: OrganizationFunctionBusiness UnitOwn & UseBusiness ProcessOwn & UseSystemSupportsTechnology Process & StoreData TypeUndersta...
Thu, 11 Aug 2022 - 29 - SMB 4 Risk Management Pillars
Send us Fan Mail NIST has developed a cybersecurity risk management framework that addresses the issue as a comprehensive process that requires organizations to: Frame riskAssess the vulnerabilitiesRespond to risk once determinedMonitor risk on an ongoing basisThese four pillars must be addressed by all small and midsize businesses. A small and midsize business (SMB) is a business that, due to its size, has different IT requirements — and often faces different IT challenges — than do ...
Thu, 04 Aug 2022 - 28 - Risk Owners
Send us Fan Mail There are many stakeholders in cybersecurity, and it makes sense to outline roles and responsibilities in terms of how each role impacts cyber resiliency. The board of directorsFebruary 21, 2018, SEC guidance requires board oversight in terms of cyber (https://www.sec.gov/rules/interp/2018/33-10459.pdf).Chief Information Security Officer (CISO)There are two types of CISOs; a governance CISO and an Operational CISO.Data Privacy Officer (DPO)General Data Protection Regu...
Thu, 28 Jul 2022 - 27 - NISTIR 8286D
Send us Fan Mail The initial public draft of NIST IR 8286D provides comprehensive asset confidentiality and integrity impact analyses to accurately identify and manage asset risk propagation from system to organization and from organization to enterprise, which in turn better informs Enterprise Risk Management deliberations. This document adds expanded BIA protocols to inform risk prioritization and response by quantifying the organizational impact and enterprise consequences of compr...
Thu, 21 Jul 2022 - 26 - Cyber Frameworks - 3 Common Pitfalls
Send us Fan Mail Choosing a Cybersecurity FrameworkThree common pitfalls of cybersecurity or risk frameworks: Finding the “perfect” framework. No single framework fits an organization’s risk profile perfectly. Frameworks like ISO 27001, ISO 3100, NIST CSF, NIST RMF, COBIT, and many others. Using custom frameworks that do not map to regulators or industry standards.Failing to assign a single project leader with appropriate deadlines and resources. ======== Blog: https://www.e...
Thu, 14 Jul 2022 - 25 - Cybersecurity - 5 Measures & Metrics
Send us Fan Mail There are several measurements or metrics an organization can put in place to monitor; some of them can be turned into Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs). ======== Training: https://www.execcybered.com/iso27001foundationcourse Linkedin: https://www.linkedin.com/company/exceccybered/ Twitter: https://twitter.com/DrBillSouza Instagram: https://www.instagram.com/drbillsouza/
Thu, 07 Jul 2022 - 24 - Risk Assessment - What to Assess
Send us Fan Mail These 3 steps you can take to perform a risk assessment: Identify and document the scope and assets to be assessed. I suggest starting with your critical assets.Identify and collect your assessment data.Vulnerability scan (including applications)Minimum security baseline scanAccess management at the OS and application levelsStandard exceptions against your scoped systemsSecurity information and event management (SIEM) logging and alertingAnalyze and report The most im...
Tue, 28 Jun 2022 - 23 - What to Focus First
Send us Fan Mail What to Focus on FIRST Mission-based cybersecurity Systems supporting the mission, vision, and servicesRegulatory systems - PCI, HIPAA, SOX, GDPRPrioritizing remediation is based on quantifying the three primary financial impacts: Business interruption costData exfiltration costRegulatory cost=== Blog: https://www.execcybered.com/blog Training: https://www.execcybered.com/store Linkedin: https://www.linkedin.com/company/exceccybered/ Twitter: https://twitter.com/DrBil...
Mon, 27 Jun 2022 - 22 - Improving Risk Program - 5 Tips
Send us Fan Mail There are some simple rules that you can start today to ensure improvements to your cyber risk program. Define the problemDefine riskDefine criticalIdentify and inventory critical assets or systemsIdentify risksThese rules apply to small, medium, and large businesses with corresponding difficulty levels. Thanks. Dr. Bill Souza CEO | Founder E|CE - Executive Cyber Education https://www.execcybered.com
Mon, 27 Jun 2022 - 21 - Tackling Risk Probability and Impact
Send us Fan Mail Today I’ll discuss risk probability and impact and give you some examples to build your own impact and probability table. ProbabilityImpactThanks. Dr. Bill Souza CEO/Founder E|CE - Executive Cyber Education https://www.execcybered.com
Thu, 14 Oct 2021 - 20 - 5 Cybersecurity Challenges
Send us Fan Mail Today I’ll touch on the topic of Cyber Risk & Cyber Investment challenges. ImprovingExploitsAttack pathsAttacker behaviorInvestmentThanks. Dr. Bill Souza CEO/Founder E|CE - Executive Cyber Education https://www.execcybered.com
Sun, 26 Sep 2021 - 19 - Lacking Basic Cybersecurity Practices
Send us Fan Mail The show today is based on an article titled, “Global utilities lacking basic cybersecurity practices.” Although the article was focused on utilities, the guidance is applicable to every industry, so I will touch on a few recommendations that could be useful to you as well, regardless of industry. Links mentioned on the show: Article: Global utilities lacking basic cybersecurity practices says expert (powerengineeringint.com) Webinar: https://www.execcybered.com/nist...
Thu, 09 Sep 2021 - 18 - Cybersecurity Basics - What you Need to Know
Send us Fan Mail We are so focused on the threats and the vulnerabilities that allowed a hack to occur, that we forget the basics. The protection necessary to prevent or slow down these attacks already exists, and they exist for a long time. Thanks. Dr. Bill Souza CEO/Founder E|CE - Executive Cyber Education https://www.execcybered.com
Thu, 26 Aug 2021 - 17 - Cybersecurity Exceptions - Part 3 (FINAL)
Send us Fan Mail In today's episode, I will discuss exceptions tracking and expirations. This is the last episode in a three-part series on cybersecurity standard exceptions. Thanks. Dr. Bill Souza CEO/Founder E|CE - Executive Cyber Education https://www.execcybered.com
Thu, 19 Aug 2021 - 16 - Cybersecurity Exceptions - Part 2
Send us Fan Mail As I mentioned in my previous episode, there’s much more to discuss on cybersecurity exceptions, such as the risk they pose to the organization and the hidden dangers of cumulative risk. Blog: https://www.execcybered.com/blog/cybersecurity-exceptions-part-2 Thanks. Dr. Bill Souza Founder & CEO E|CE - Executive Cyber Education www.execcybered.com
Thu, 12 Aug 2021 - 15 - Cybersecurity Exceptions - Part 1
Send us Fan Mail If your cybersecurity standards were written to protect the organization, why do you have security exceptions? Your standard development team writes an excellent standard; it follows all the best practices of the NIST Cybersecurity Framework, the ISO 27001, or any other industry-recognized standards and frameworks, but most of all, it is common sense, right? Anyone working on or with a cybersecurity team in a large organization knows this does not happen! Exceptions h...
Thu, 05 Aug 2021 - 14 - Cybersecurity - Asset Classification
Send us Fan Mail Asset classification is the foundation of everything else to come in cybersecurity; it will help your organization, for example, small or large, to better understand, manage, identify, and classify your assets. Episode: Cybersecurity - Asset Classification (execcybered.com) Dr. Bill Souza Founder & CEO Executive Cyber Education
Fri, 30 Jul 2021 - 13 - Zero-Sum Game
Send us Fan Mail In this episode, I will discuss three challenging areas where cybersecurity education is falling short in preparing students and professionals to succeed in the field.
Thu, 31 Dec 2020 - 12 - Cybersecurity Investment & Risk Strategy
Send us Fan Mail In this episode, I discuss how to leverage your risk framework to make sound cybersecurity investment decisions. I addressed two critical questions that you will need to know the answers; first, how can you tell your program is doing the right thing? and second, How can you tell you are protecting the organization in a financially healthy way? Dr. B. Executive Cyber Education www.execcybered.com eBook: https://www.execcybered.com/risk-identification-ebook
Tue, 04 Aug 2020 - 11 - Critical Systems: Asking the Right Questions
Send us Fan Mail To get results you need to ask the right question, collect the data, analyze, and develop a robust and factual interpretation. This episode will guide you through the thought process and give you some ideas on how to develop a strong argument on where you should focus your cybersecurity investments and tools. Infographic: https://executive-cyber-education.mykajabi.com/identification-analysis Dr. B.
Sun, 14 Jun 2020 - 10 - Cyber Risk Identification
Send us Fan Mail Today’s episode I will discuss a strategy to identify critical systems in your organization. The steps I will discuss today will make sure your program is objective and repeatable. The eBook mentioned in this podcast can be downloaded here: https://executive-cyber-education.mykajabi.com/risk-identification-ebook Thanks. Dr. B. https://execcybered.com/podcast-1
Mon, 08 Jun 2020 - 9 - Key Risk Indicators
Send us Fan Mail Today’s episode we will discuss how to identify KRIs (key risk indicators). I’ll discuss a simple and effective way to do it; there seems to be a lot of confusion on what to measure and for a long time, subject matter experts believe we can’t measure Cybersecurity.
Sat, 25 Apr 2020
Podcast simili a <nome>
El Partidazo de COPE COPE
Herrera en COPE COPE
La Linterna COPE
Dante Gebel Live Dante Gebel
Panda Show - Sin Picante El Panda Zambrano
Es la Mañana de Federico esRadio
La noche de Cuesta esRadio
Hondelatte Raconte Europe 1
Au Coeur du Crime Europe1
Affaires sensibles France Inter
LEGEND Guillaume Pley
El colegio invisible OndaCero
La Rosa de los Vientos OndaCero
Les grands dossiers de l'Histoire par Franck Ferrand Radio Classique
Espacio en blanco Radio Nacional
Entrez dans l'Histoire RTL
Le grand récit RTL
Les Grosses Têtes RTL
Les histoires incroyables de Pierre Bellemare RTL
L'Heure Du Crime RTL
El Larguero SER Podcast
SER Historia SER Podcast
Un Libro Una Hora SER Podcast
HISTORIAS DE LA HISTORIA VIVA RADIO
