Obtenez 3 mois à 0,99 $/mois

OFFRE D'UNE DURÉE LIMITÉE
Page de couverture de Enterprise Security Weekly (Audio)

Enterprise Security Weekly (Audio)

Enterprise Security Weekly (Audio)

Auteur(s): Security Weekly Productions
Écouter gratuitement

À propos de cet audio

News, analysis, and insights into enterprise security. We put security vendors under the microscope, and explore the latest trends that can help defenders succeed. Hosted by Adrian Sanabria. Co hosts: Katie Teitler-Santullo, Ayman Elsawah, Jason Wood, Jackie McGuire, Sean Metcalf.© 2024 CyberRisk Alliance
Épisodes
  • Fix your dumb misconfigurations, AI isn't people, and the weekly news - Wendy Nather, Danny Jenkins - ESW #436
    Dec 8 2025
    Interview with Danny Jenkins: How badly configured are your endpoints?

    Misconfigurations are one of the most overlooked areas in terms of security program quick wins. Everyone freaks out about vulnerabilities, patching, and exploits.

    Meanwhile, security tools are misconfigured. Thousands of unused software packages increase remediation effort and attack surface. The most basic misconfigurations lead to breaches. Threatlocker spotted this opportunity and have extended their agent-based product to increase attention on these common issues.

    This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more!

    Interview with Wendy Nather: Recalibrating how we think about AI

    AI and the case for toxic anthropomorphism. When Wendy coined this phrase on Mastodon a few weeks ago, I knew that she had hit on something important and that we needed to discuss it on this podcast.

    We were lucky to find some time for Wendy to come on the show!

    Quick note: while this was not a sponsored segment, 1Password IS currently a sponsor of this podcast. That doesn't really change the conversation any, except that I have to be nice to Wendy. But why would anyone ever be mean to Wendy???

    Weekly Enterprise News

    Finally, in the enterprise security news,

    1. Dozens of funding rounds over the past two weeks
    2. Windows is becoming an Agentic OS? We talk about what that actually means.
    3. Some great free tools
    4. the latest cyber insurance trends
    5. we analyze some recent breaches
    6. the stop hacklore campaign
    7. some essays worth reading
    8. and a how a whole country dropped off the internet, because someone forgot to pay a GoDaddy invoice

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-436

    Voir plus Voir moins
    1 h et 35 min
  • From Misconfigurations to Mission Control: Lessons from InfoSec World 2025 - Marene Allison, Dr. Ron Ross, Ryan Heritage, Patricia Titus, Perry Schumacher, Rob Allen - ESW #435
    Dec 1 2025

    Live from InfoSec World 2025, this episode of Enterprise Security Weekly features six in-depth conversations with leading voices in cybersecurity, exploring the tools, strategies, and leadership approaches driving the future of enterprise defense. From configuration management and AI-generated threats to emerging frameworks and national standards, this special edition captures the most influential conversations from this year's conference.

    In this episode:

    -You Don't Need a Hacker When You Have Misconfigurations — Rob Allen, Chief Product Officer at ThreatLocker®, discusses how overlooked settings and weak controls continue to be one of the most common causes of breaches. He explains how Defense Against Configurations (DAC) helps organizations identify, map, and remediate configuration risks before attackers can exploit them.

    -Security Challenges for Mid-Sized Companies — Perry Schumacher, Chief Strategy Officer & Partner at Ridge IT Cyber, explores the evolving security challenges facing mid-sized organizations. He discusses how AI is becoming a competitive advantage, how mobility and third-party reliance complicate defenses, and what steps these organizations can take to improve resilience and efficiency.

    -The Rise of Security Control Management: Secure by Design, Not by Chance — Marene Allison, former CISO of Johnson & Johnson, introduces Security Control Management (SCM), a new software category that unifies control selection, mapping, validation, and enforcement. She explains how SCM transforms fragmented compliance programs into proactive, embedded defense.

    -Engineered for Protection: The Rise of Security Control Management — Ryan Heritage, Advisor at Sicura, continues the discussion on SCM, explaining how organizations can operationalize this approach to move from reactive reporting to proactive, data-driven defense. He highlights how automation and integration enable security decisions to be made at "the speed of relevance."

    -The AI Threat: Protecting Your Email from AI-Generated Attacks — Patricia Titus, Field CISO at Abnormal Security, explores how cybercriminals are weaponizing generative AI to create sophisticated phishing and social engineering attacks. She shares practical strategies for defending against AI-generated threats and emphasizes why AI-based protections are now essential for modern enterprises.

    -Igniting Change: A Conversation with Dr. Ron Ross — Dr. Ron Ross, CEO at RONROSSECURE, LLC, shares insights from decades of pioneering work in cybersecurity, including the Risk Management Framework and Systems Security Engineering Guidelines. He discusses how leaders can apply these principles to strengthen resilience, foster innovation, and drive meaningful change across the cybersecurity landscape.

    Segment Resources

    • ThreatLocker® Defense Against Configurations (DAC): https://www.threatlocker.com/platform/defense-against-configurations

    Book a demo to see DAC in action. Visit https://securityweekly.com/threatlockerisw to learn more!

    This segment is sponsored by Ridge IT Cyber. Visit https://securityweekly.com/ridgeisw to learn more about them!

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-435

    Voir plus Voir moins
    1 h et 43 min
  • Aligning teams for effective remediation, Anthropic's latest report, and the news - Ravid Circus - ESW #434
    Nov 24 2025
    Interview with Ravid Circus

    Ravid will discuss why security and engineering misalignment is the biggest barrier to fast, effective remediation, using data from Seemplicity's 2025 Remediation Operations Report. This is costing some teams days of unnecessary exposure, which can lead to major security implications for organizations.

    Segment Resources:

    • https://seemplicity.io/papers/the-2025-remediation-operations-report/

    • https://seemplicity.io/news/seemplicity-releases-2025-remediation-operations-report-91-of-organizations-experience-delays-in-vulnerability-remediation/

    • https://seemplicity.io/blog/2025-remediation-operations-report-organizations-still-struggle/

    Topic Segment: Thoughts on Anthropic's latest security report

    Ex-SC Media journalist Derek Johnson did a great job writing this one up over at Cyberscoop: China's 'autonomous' AI-powered hacking campaign still required a ton of human work

    There are a number of interesting questions that have been raised here. Some want more technical details and question the report's conclusions. How automated was it, really?

    I found it odd that Anthropic's CEO was on 60 minutes the same week, talking about how dangerous AI is (which is his company's primary and only product).

    I think one of the more interesting things to discuss is how Anthropic has based its identity and brand on AI safety. While so many other SaaS companies appear to be doing the bare minimum to stop attacks against their customers, Anthropic is putting significant resources into testing for future threats and discovering active attacks.

    News Segment

    Finally, in the enterprise security news,

    1. vendor layoffs have started again
    2. the sins of security vendor research
    3. the pillars of the Internet are burning
    4. selling out to North Korea isn't worth what they're paying you
    5. ransom payments, in 24 easy installments?
    6. a breach handled the right way
    7. we probably shouldn't be putting LLMs into kids toys
    8. ordering coffee from the terminal

    All that and more, on this episode of Enterprise Security Weekly.

    Visit https://www.securityweekly.com/esw for all the latest episodes!

    Show Notes: https://securityweekly.com/esw-434

    Voir plus Voir moins
    1 h et 39 min
Pas encore de commentaire