Enterprise Security Weekly Episode #257 – January 20, 2022
Subscribe to all of our shows and mailing list by visiting: https://securityweekly.com/subscribe
1. Vulnerability Management is Dead! – 03:00 PM-03:30 PM
Sponsored By

Visit https://securityweekly.com/detectify for more information!
Announcements
-
Join us February 16th to learn about validation techniques within applications. Then join us March 2nd to learn five things you can do to catch more bad guys! To register for these webcasts visit https://securityweekly.com/webcasts. Don’t forget to check out our library of on-demand webcasts & technical trainings at https://securityweekly.com/ondemand.
Description
Visit https://securityweekly.com/detectify for more information!
Announcements
-
Join us February 16th to learn about validation techniques within applications. Then join us March 2nd to learn five things you can do to catch more bad guys! To register for these webcasts visit https://securityweekly.com/webcasts. Don’t forget to check out our library of on-demand webcasts & technical trainings at https://securityweekly.com/ondemand.
Description
Modern tech stacks are becoming increasingly complex puzzles of components built in-house and sourced from third-party vendors. With DNS at the center of the infrastructure, and staging and production being sometimes just minutes apart, scanning for CVEs is not enough to stay on top of web threats.
There are lots of critical things traditional app scanners won’t catch, like dangling DNS records, subdomain takeover and open S3 buckets. To keep their growing attack surface secure, companies need to combine crowdsourced vulnerability detection with solutions that detect outliers and anomalies in their software – before these become an attack vector.
In this episode we’ll discuss:
– Why hunting for vulnerabilities is no longer enough to stay on top of threats
– Vulnerability Management vs Attack Surface Management
– How security teams can adapt their vulnerability management process to modern dev cycles.
Segment Resources:
More insights on how to secure your external attack surface: https://detectify.com/resources
Free trial of Detectify’s attack surface management solutions: https://detectify.com/product/surface-monitoring
https://detectify.com/product/application-scanning
This segment is sponsored by Detectify. Visit https://securityweekly.com/detectify to learn more about them!
Guest(s)
|
Rickard Carlsson – Co-founder & CEO at Detectify Entrepreneurial tech nerd Rickard Carlsson has grown Detectify from a group of ethical hackers with an idea on how to make the internet safer, to an international industry challenger of 140+ people. Rickard has a background in tech and management consulting, and has lived and worked in Sweden, India and the US. |
Hosts
Adrian Sanabria @sawaba Senior Research Engineer at CyberRisk Alliance |
Katie Teitler @Katherinert15 Sr. Product Marketing Manager at Axonius |
Tyler Shields @txs CMO at JupiterOne |
2. Architecture & Security from the Trenches – 03:30 PM-04:00 PM
Announcements
-
Do you have a specific guest or topic that you want us to cover on one of the shows? Submit your suggestions for guests by visiting https://securityweekly.com/guests and completing the form! We review suggestions monthly and will reach out to you once reviewed!
Description
An open discussion of challenges facing software and system architects in small and medium sized businesses.
Guest(s)
|
Will Clark – Software Architect at Accela |
Hosts
Adrian Sanabria @sawaba Senior Research Engineer at CyberRisk Alliance |
Katie Teitler @Katherinert15 Sr. Product Marketing Manager at Axonius |
Tyler Shields @txs CMO at JupiterOne |
3. McAfee MVISION XDR, Microsoft Acquires Activision Blizzard, & Tom Brady NFTs – 04:00 PM-04:30 PM
Announcements
-
Don’t miss any of your favorite Security Weekly content! Visit https://securityweekly.com/subscribe to subscribe to any of our podcast feeds and have all new episodes downloaded right to your phone! You can also join our mailing list, Discord server, and follow us on social media & our streaming platforms!
-
We had an absolute blast putting together this year’s SW Unlocked virtual event! All presentations are now available on-demand for your viewing pleasure. Please visit https://securityweekly.com/unlocked to register and watch now!
Description
In the Enterprise Security News: 1Password plans to do some shopping with their massive Series C, Devo announces a $250M round, Permiso Security and Tromzo emerge backed by both traditional VCs and industry execs, STG spins out McAfee’s MVISION XDR product as Trellix – the first of many spinouts, they say, Microsoft reminds us that, in addition to being the industry’s largest security vendor, they can also drop $70B on video games if they feel like it, More reminders that open source is essential, but orgs with massive budgets will still treat it as worthless and disposable, Real-world stories of CI/CD pipeline compromises, Is Uber’s former CSO going to jail?, and Tom Brady NFTs!
Hosts
Adrian Sanabria @sawaba
Senior Research Engineer at CyberRisk Alliance |
|
Katie Teitler @Katherinert15
Sr. Product Marketing Manager at Axonius |
Tyler Shields @txs
CMO at JupiterOne |