Enterprise Security Weekly Episode #261 – February 17, 2022
Subscribe to all of our shows and mailing list by visiting: https://securityweekly.com/subscribe
1. 0patch – Security Patching That Doesn’t Make Your Life Miserable – 03:00 PM-03:30 PM
Announcements
-
Don’t miss any of your favorite Security Weekly content! Visit https://securityweekly.com/subscribe to subscribe to any of our podcast feeds and have all new episodes downloaded right to your phone! You can also join our mailing list, Discord server, and follow us on social media & our streaming platforms!
Description
0patch is a simple but powerful service that provides tiny targeted security patches to Windows computers, eliminating the most critical vulnerabilities without restarting the computer or relaunching applications. A different approach to patching allows us to both create and deploy 0day patches much quicker than original vendors can with their traditional update processes.
Segment Resources:
0patch Blog with many posts on vulnerabilities and patches we make
https://blog.0patch.com/
0patch FAQ
https://0patch.zendesk.com/hc/en-us/categories/200441471
Guest(s)
|
Mitja Kolsek – Founder, CEO at ACROS Security @mkolsek After completing the computer sciences study, Mitja co-founded ACROS Security in 1999, offering application security assessments and penetration testing services to large, mostly US-based customers. Many discovered vulnerabilities and successfully penetrated customer networks later, he co-founded 0patch, a 3rd party security patching service aiming to make penetration testers’ – and more importantly, attackers’ – lives harder. |
Hosts
Adrian Sanabria @sawaba Senior Research Engineer at CyberRisk Alliance |
Katie Teitler @Katherinert15 Sr. Product Marketing Manager at Axonius |
Tyler Shields @txs CMO at JupiterOne |
2. Changing the TPCRM Game W/ Cyber Risk Intelligence Tools – 03:30 PM-04:00 PM
Announcements
-
Do you have a specific guest or topic that you want us to cover on one of the shows? Submit your suggestions for guests by visiting https://securityweekly.com/guests and completing the form! We review suggestions monthly and will reach out to you once reviewed!
Description
Definitions of the word intelligence include a collection of information of military or
political value as well as the ability to acquire and apply knowledge or skills. In
cybersecurity, when we possess intelligence, we feed that data in our Security
Operations Center (SOC) to further analyze the risk present. In this case, the risk is based on the probability of threats materializing and the impact they would have on the organization.
We’re calling the output of that SOC Cyber Risk Intelligence. Cyber Risk Intelligence is
the ability to think holistically about risk and provide information that decision makers
can act on…not just analyze.
Traditional Vendor Risk Management (VRM) processes focus on the gap, which is essentially information that needs to be further analyzed against the risk to the business. This is an additional step that takes time and effort, especially when different compliance frameworks and threats are constantly emerging.
Segment Resources:
https://www.cybergrx.com/resources/research-and-insights/blog/beyond-risk-management-how-cyber-risk-intelligence-tools-are-changing-the-tpcrm-game
This segment is sponsored by CyberGRX.
Visit https://securityweekly.com/cybergrx to learn more about them!
Guest(s)
|
Vikram Asnani – Sr Director Solution Architecture at CyberGRX Vikram is a CISSP and SABSA certified cybersecurity and privacy professional with 15 years of global experience in assisting clients across Risk Management, CyberSecurity Strategy, Third Party Risk, Cloud Migration, Business Continuity and Data Privacy, through Advisory and Managed Services offerings with a motto of using technology as an innovative solution for driving maturity. Vikram has worked with many assurance functions, risk managers as part of his experience of working with Big4 consultancy companies. He also has experience of leading a national practice for third party risk management, where he has built end to end TPRM programs including establishing governance and assurance functions. Vikram is currently a solution architect for a CyberGRX, which has revolutionized the way to manage TPRM program and has been assisting its clients in maturing their TPRM program using CyberGRX. |
Hosts
Adrian Sanabria @sawaba Senior Research Engineer at CyberRisk Alliance |
Katie Teitler @Katherinert15 Sr. Product Marketing Manager at Axonius |
Tyler Shields @txs CMO at JupiterOne |
3. Cisco/Splunk Rumors, Canonic Security, Unhelpful Legislation, & Securonix Round – 04:00 PM-04:30 PM
Announcements
-
We have a couple webcasts coming up soon. First, join us March 2nd to learn five things you can do to catch more bad guys! Then join us March 10th for an intro to KQL queries! To register for these webcasts visit https://securityweekly.com/webcasts. Don’t forget to check out our library of on-demand webcasts & technical trainings at https://securityweekly.com/ondemand.
Description
Finally, in the Enterprise Security News, Securonix raises $1B in Vista-led round (it’s like they ate a unicorn!), Salt Security becomes a Unicorn, has not been eaten (yet), Legit Security raises a totally legit $26.5M Series A, Vicarius and Calamu raise Series As
,Permit.io, KSOC, Titaniam, Canonic Security, Allure Security, and SecureThings all pick up seed funding! We look at Big Tech’s cybersecurity funding and acquisitions, The rumor mill goes nuts over a Cisco/Splunk deal that’s probably not happening (maybe?)
Why are cybersecurity asset management startups so hot right now?
New products, unhelpful legislation, a major acquisition, & of course a few squirrel stories!
Hosts
Adrian Sanabria @sawaba
Senior Research Engineer at CyberRisk Alliance |
|
Katie Teitler @Katherinert15
Sr. Product Marketing Manager at Axonius |
Tyler Shields @txs
CMO at JupiterOne |