Cyber Speaks LIVE

Cyber Speaks LIVE

By Cyber Speaks LIVE
Cyber Speaks LIVE is a weekly InfoSec podcast series hosted by Duncan McAlynn (@infosecwar) and his special guest co-hosts, where YOU get to participate in the discussions with full video and audio. Following the live recording, we add the audio-only stream into our podcast feed for our awesome subscribers.

Cyber Speaks LIVE gives YOU, the InfoSec community, a voice that can be heard around the world!

Follow us on Twitter for upcoming guests announcements and live recording invites, @cyberspeakslive.
Where to listen
Apple Podcasts Logo
Breaker Logo
Google Podcasts Logo
Overcast Logo
PodBean Logo
RadioPublic Logo
Spotify Logo
Edu, Certs or Exp: Which Matters Most?
In this episode, we're joined by the distinguished SANS Institute fellow Dr. Johannes Ullrich, expert red teamer, author and university instructor, Phillip Wylie, and veteran recruiter extraordinaire, Juliana Riahi. Together, along with our live online audience, we  discuss the various perspectives of what matters most when considering one’s career paths, salary ranges and challenges they may face along the way. Connect with our special guests co-hosts: Juliana - https://sttjobs.com/ Johannes - ‪@johullrich ‬ Phillip - @PhillipWylie Mentions: Internet Storm Center Daily Stormcast SANS Institute Pwn School Project Tribe of Hackers ISSA ISACA ISC(2) FBI InfraGard Meetup
1:04:09
March 17, 2020
Kushtaka: High-Fidelity Sensors for Under-Resourced Blue Teams
This week we are joined by Jared Folkins (@JF0LKINS) as he introduces us to his open source honeypot sensor system, Kushtaka, that helps you detect cyber attackers before they become entrenched. Jared will be joined by Nathan McNulty (@nathanmcnulty), to give his firsthand account of using Kushtaka in production. This week we also introduce a new segment where we'll be highlighting a non-profit charity or upcoming conference each episode. This week we'll be talking with wirefall, founder of @Dallas_Hackers and board member @BSidesDFW. About Jared: After surviving the dot-com crash of the late 90s, Jared Folkins went on to have a long career in systems and programming. In 2013 he turned a hobby into a career and has never looked back. Known for having technical chops and a high emotional IQ, he enjoys working with those who prioritize goals and people, while placing egos last. He currently Red Teams for ThreatHound.com, Blue Teams for Bend La Pine Schools, and breaks down software while building up people at OpsecEdu.com. If you want his help or you just need a new InfoSec friend, contact him at JaredFolkins.com. Connect with Jared: LinkedIn - https://www.linkedin.com/in/jared-folkins-b18783179/ Twitter - @JF0LKINS
58:09
February 20, 2020
Healthcare and IoT Device Security with Jennifer Reicherts, CEH
In this episode, we are joined by IoT security practitioner, Jennifer Reicherts. Jennifer currently works as a Senior Information Security Analyst for an independent Children's Hospital Network in Minneapolis, MN where she is using her passion for protecting patient care by applying her skills in the areas of IoT technology, Incident Response, Threat Intelligence, and Security Training.  Jennifer has spoken on the topic of the cybersecurity risks of IoT in Healthcare at conferences as well as private events.  She is a Certified Ethical Hacker, an Executive Board Member of her local InfraGard Member Alliance, and most recently will be joining a planning committee for the most popular cybersecurity event in Minnesota. Follow her on Twitter: @sniffsdapkts Connect with her on LinkedIn: https://www.linkedin.com/in/jennifer-r-6328624/ Links mentioned in the show: https://www.iamthecavalry.org/wp-content/uploads/2016/01/I-Am-The-Cavalry-Hippocratic-Oath-for-Connected-Medical-Devices.pdf https://www.newamerica.org/cybersecurity-initiative/reports/do-no-harm-20/ https://www.dhs.gov/sites/default/files/publications/Strategic_Principles_for_Securing_the_Internet_of_Things-2016-1115-FINAL_v2-dg11.pdf
49:35
February 20, 2020
Azure Security Center with Yuri Diogenes
In this episode, we are joined by the legendary Yuri Diogenes, Sr. Program Manager for Microsoft's Azure Security Center (ASC) product. Yuri has literally written the book on the subject and shares with us his keen insights into the platform, as well as CSPM and CWPP scenarios.  Here are some important links that Yuri has also shared with us: How to Effectively Perform an Azure Security Center PoC https://techcommunity.microsoft.com/t5/Azure-Security-Center/How-to-Effectively-Perform-an-Azure-Security-Center-PoC/ba-p/516874 Survival Guide to Drive your Secure Score Up in Azure Security Center https://techcommunity.microsoft.com/t5/Azure-Security-Center/Survival-Guide-to-Drive-your-Secure-Score-Up-in-Azure-Security/ba-p/752649 Azure Security Center documentation page https://docs.microsoft.com/en-us/azure/security-center/ Also be sure to grab a copy of Yuri's print or electronic book, Microsoft Azure Security Center 2nd Edition, from MS Press for 30% off during checkout using the special Cyber Speaks LIVE discount code, AZURESEC: https://www.microsoftpressstore.com/store/microsoft-azure-security-center-9780135752036. (Valid thru Nov. 28, 2019 only.)  PLEASE, also listen to and share the Ryen Macababbad episode on Vets in Cyber. It is probably the most important episode we've recorded to-date. The Azure product updates website mentioned during the show is available at: https://azurecharts.com. Enjoy! And, thank you to Nick Espinosa for providing data regarding the breaches of the week. Be sure to follow him on Twitter: @NickAEsp
1:01:35
December 2, 2019
Live from Microsoft Ignite - Cybersecurity in Local Government
In this special episode recorded live from #MSIgnite, I'm joined by Charles Burton of the Calcasieu Parish Police Jury and Mark Simos of Microsoft to discuss the topic of cybersecurity best practices in local governments.  Be sure to connect with our guest co-hosts and thank them for their appearance on the show: Charles Burton Information Technology Director, Calcasieu Parish Police Jury https://www.linkedin.com/in/cburton/ @CharlieBurton Mark Simos Lead Cybersecurity Architect, Microsoft https://www.linkedin.com/in/marksimos/ @MarkSimos
1:00:00
November 16, 2019
Transitioning Our Nation’s Vets into Cybersecurity with Sgt. Ryen Macababbad of Microsoft
With Veteran's Day upon us, I was truly blessed to be joined by US Army veteran Sgt. Ryen Macababbad from Microsoft to discuss veteran transition to civilian life and the crisis facing our nation with veteran suicide rates. This is my proudest episode yet. Please listen, like and share. You never know who may need to hear the message that Ryen is sharing.   Show references:  Veteran's Suicide Prevention Hotline: 1-800-273-8255  Connect with Ryen on Twitter:  https://twitter.com/Ryen_Mac (@ryen_mac)  LinkedIn's program to support US veterans:  https://socialimpact.linkedin.com/programs/veterans  Daniel Savage on LinkedIn:  https://blog.linkedin.com/author/d/daniel-savage Microsoft Transition Program for Veterans, servicemembers, and military spouses  https://aka.ms/mssa  The Ultimate LinkedIn Cheat Sheet  https://www.linkedin.com/pulse/ultimate-linkedin-cheat-sheet-michael-quinn  Purepost military translation tool  https://www.purepost.co/
28:36
November 7, 2019
Tribe of Hackers - Red Team Edition featuring Marcus J Carey, Beau Bullock and Phillip Wylie
This week we get inside the head of red teamers by talking with Marcus and the guys about the latest edition of his book series, Tribe of Hackers - Red Team: Tribal Knowledge from the Best in Offensive Cybersecurity. Beau and Phil get into the action as well, by sharing their unique perspectives as contributing co-authors to the book.  Tribe of Hackers Red Team: Tribal Knowledge from the Best in Offensive Cybersecurity https://www.amazon.com/Tribe-Hackers-Red-Team-Cybersecurity/dp/1119643325 Phil's Pwn School Project: https://pwnschool.com/about-pwn-school/ Follow Them on Twitter: Marcus - @marcusjcarey Phil - @PhillipWylie Beau - @dafthack Threatcare: https://threatcare.com
57:50
September 23, 2019
Why Pentesting is Broken Today with the AttackForge Team
Fil & Stas, founders of the disruptive AttackForge platform, were recently presenting at Black Hat USA Arsenal telling their story about why pen testing is broken – a term we do hear often in security - and how they are trying to solve the problems. In this episode of Cyber Speaks LIVE they shared their experiences and provided us with some keen insights for our listeners on this topic and provided a nice introduction to the AttackForge platform.
1:05:55
September 11, 2019
The Creepiness Behind Facebook and Google with Film Director M.A. Taylor
In this special edition of Cyber Speaks LIVE, we're joined by MA Taylor, the highly acclaimed film director of #TheCreepyLine to discuss how YOU are for sale and the data privacy & protection implications of #Google and #Facebook. We examine everything from the Cambridge Analytica scandal to confirmation bias to election manipulations and SO much more! This is a NOT TO BE MISSED episode! 
1:01:46
August 14, 2019
Cybersecurity Best Practices and Controls with Tony Sager of the Center for Internet Security (CIS)
*This is a special edition of Cyber Speaks LIVE, recovered from the archives.* In this episode we are joined by 34-year veteran of the NSA and now Center for Internet Security (CIS) Senior VP & Chief Evangelist, Tony Sager to discuss the history and formation of SANS Top 20 and how it's evolved into today's CIS Top 20 Security Controls and what Tony and the organization (along with hundreds of volunteers around the globe) are doing to help organizations of all sizes help protect and defend themselves. 
53:45
August 7, 2019
Data Beaches and Protecting Your Personal Data with Troy Hunt of haveibeenpwnd.com
Troy Hunt joins Cyber Speaks LIVE as a special guest co-host to discuss recent data breaches, personal information protection and measures we can take to help protect our personal and corporate online identities.  Troy is the founder of the wildly popular website, Have I Been Pwned (HIBP, https://haveibeenpwned.com), a free service that aggregates data breaches and helps people establish if they've been impacted by malicious activity on the web.  He is also an Australian Microsoft Regional Director, a Microsoft Most Valuable Professional (MVP) and a brilliant Pluralsight instructor. Links mentioned in the episode: Have I Been Pwned website: https://haveibeenpwned.com Troy's blog: https://troyhunt.com Troy's Twitter: https://twitter.com/troyhunt Have I Been Pwned Twitter: https://twitter.com/haveibeenpwned Security.txt File Search Engine: https://crawler.ninja The Creepy Line Documentary Film: https://thecreepyline.com
1:00:21
July 19, 2019
Ann Johnson Discusses Microsoft Cybersecurity, AI, Women in Tech & Diversity
Ann Johnson, Corporate Vice-President of Cybersecurity at Microsoft, joins us to talk about how the company has transformed itself into a global security leader and how machine learning & artificial intelligence come into play. We also discuss Women in Tech, Motherhood and how diversity is critical in InfoSec.  Links referenced in this episode: Security Advisor Alliance https://www.securityadvisoralliance.org/ Microsoft Software & Systems Academy https://aka.ms/mssa   OUR SPONSOR This episode proudly sponsored by Ivanti - makers of industry leading, enterprise-ready 3rd party patch management solutions for Microsoft System Center Configuration Manager. Find out more at:  https://www.ivanti.com/products/patch-management-for-sccm 
54:31
July 12, 2019
Insider Threats and the Science of How to Stop Them with Joe Carson of Thycotic
In this lively episode, fellow Irishman, Joe Carson, and I discuss a variety of inter-related cybersecurity topics with regards to the overarching theme of Insider Threats. We covered a lot of ground in a short time. Check it out!  ## Here's the episode timeline: 12:52 - Vendors talking risk. 17:44 - Business Risk 21:54 - Cyber Security Frameworks 24:46 - Insider Threats 33:50 - Cyber Insurance Fraud 35:54 - Data Classification & Shadow IT 48:15 - Q&A (Don't skip this!) #About Joe: Joseph Carson has more than 25 years of experience in enterprise security, an InfoSec award winner, author of Privileged Account Management for dummies and Cybersecurity for dummies.  He is a CISSP and an active member of the cybercommunity, speaking at conferences globally.  He’s a cybersecurity advisor to several governments, as well as critical infrastructure, financial, and maritime industries. ## Joe's Book, Least Privilege for Dummies ## Start a Privilege Manager Cloud Trial 
58:02
July 1, 2019
Cyber Acquisitions and Their Impact on the Industry with Gary Hayslip
In this episode, I'm joined by Gary R. Hayslip, Cybersecurity Strategist & CISO. Together we discuss the global impact of cybersecurity mergers & acquisitions, along with the impact that they are having on today's CISOs.  With over 25 years of information technology, security leadership, and risk management experience, Hayslip has an exceptional record of success leading multiple, diverse cross-functional security and risk governance teams in the planning, analyzing and implementation of information security programs to support organizational business objectives. Hayslip is a proven cybersecurity professional; he has established a reputation as a highly skilled communicator, author, and keynote speaker. Hayslip has developed the ability to work within all business channels of an organization and is extremely effective in communicating the nuances of cybersecurity in business/risk terms for executive management and boards of directors. Hayslip’s previous executive roles include multiple CISO, CIO, Deputy Director of IT and Chief Privacy Officer roles for the U.S. Navy (Active Duty), the U.S. Navy (Federal Government employee), the City of San Diego California, and Webroot Software. In all of these roles, Hayslip led diverse teams of 10 – 300 employees and built information technology and security programs from the ground up. He partnered with software development and agile teams, integrating security into innovative workflows and new services. Hayslip collaborated with customers, strategic partners, and executive leadership teams on the deployment of new products, merger & acquisition due diligence services, and the management of his organizations business risks. Hayslip recently co-authored the CISO Desk Reference Guide: A Practical Guide for CISOs – Volumes 1 & 2, which are considered among the leading books on enabling CISOs to expand their leadership and business expertise. He serves as an EvoNexus Selection Committee member, where he reviews and mentors cybersecurity and Internet-of-Things startups. He sits on the board of directors for both the Cyber Center of Excellence and Infragard’s San Diego chapter. Hayslip is an active member of the professional organizations ISC2, ISSA, ISACA, OWASP, and Infragard. He currently holds several professional certifications, including CISSP, CISA, and CRISC. Hayslip has a BS in information systems management from UMUC and an MBA from San Diego State University. LinkedIn Profile: http://www.linkedin.com/in/ghayslip Twitter: @ghayslip
56:24
June 22, 2019
OSINT Foundations and Best Practices with Katelyn Bowden
After discovering her own intimate images online without consent, Katelyn Bowden, a bartender and single mother from Ohio, formed B.A.D.A.S.S. (Battling Against Demeaning And Abusive Selfie Sharing), a nonprofit coalition of NCP victims working together to fight back against the practice.  While she remains the CEO of B.A.D.A.S.S., and manages all of the organizations projects and goals, her strength and focus lies in Open-Source Intelligence (OSINT), civilian cyber security education, law enforcement training and investigations. In less than two short years, she, along with the amazing humans involved with her organization, have managed to not only help thousands of NCP victims, but to change the landscape of online sexual abuse.  In this episode, Katelyn shares with us her pro tips for conducting OSINT investigations, along with how to protect yourself against NCP.    Katelyn's social links: Twitter: @badassbowden @theBADASS_army Instagram: @theBADASS_army Website: www.badassarmy.org
1:00:02
June 14, 2019
Jack Rhysider of Darknet Diaries Talks Podcasting, Prison and Intel Sharing
In this episode, we're joined by the prince of cyber podcasting, Jack Rhysider, host of Darknet Diaries. Jack takes us through the process of bringing you into his mind theater as he is researching, interviewing folks and creating his hugely popular podcast series.  About Jack Jack Rhysider is a veteran to the security world. He gained his professional knowledge of security by working in a Security Operations Center for a Fortune 500 company, a place to where threats are detected and stopped. During that time he was exposed to hundreds of client’s networks ranging from schools, to government, to banks, and commercial organizations. Now Jack spends his time making the Darknet Diaries podcast.  You can follow Jack on Twitter at:  https://twitter.com/jackrhysider  Stream his podcast from your favourite platform or from:  https://darknetdiaries.com/ 
58:09
June 7, 2019
Cyber Career Development and Overcoming the Challenges with InfoSecSherpa
In this episode, I am joined by the lovely Tracy Maleeff, better known in our circles as @InfoSecSherpa. We discuss career development and transition along with the importance of building bridges to close the gaps between InfoSec groups and our users. Tracy also shares with us how she's successfully built security awareness training programmes and other trainings for her companies and community. Before closing out, Tracy shares her one bit of advice for anyone seeking to get into the InfoSec field.  More about her: Tracy Z. Maleeff, @InfoSecSherpa, is a GIAC GSEC certified Cyber Analyst in the Security Operations Center for a global company. Prior to joining the Information Security industry, Tracy worked as a librarian in academic, corporate, and private law firm libraries. While a member of the Special Libraries Association, Tracy received the Dow Jones Innovate Award, the Wolters Kluwer Law & Business Innovations in Law Librarianship award, and was named a Fellow. She has presented at many conferences, both Library & Information Science as well as Information Security, on topics ranging from social media, networking, research strategies, and security awareness. She received the Women in Security Leadership Award from the Information Systems Security Association and is very active in the Info Sec community. Tracy holds a Master of Library and Information Science degree from the University of Pittsburgh, as well as undergraduate degrees from both Temple University (magna cum laude), and the Pennsylvania State University.
59:23
June 3, 2019
Dissecting Malware Variants and Defenses with Roger Grimes of KnowBe4
In this episode I'm honored to be joined by Roger A. Grimes, famed KnowBe4 evangelist, to discuss: Nine kinds of malware (literally!)  A flashback to the Microsoft Trustworthy Computing Initiative  Revisited WannaCry two years later - have we learned anything?  Debate whether Marcus Hutchins is a hero or a zero Episode Timeline: Top 3 Cyber Clusters (1:00) Roger Intro (7:00 9 Types of Malware & How to Detect & Defeat Them (9:56) WannaCry Revisited (48:48) Marcus Hutchins (52:31) Kevin Mitnick (56:27) About KnowBe4 (1:03:37) 9 Types of Malware & How to Detect & Defeat Them      1. Viruses 12:13      2. Worms 16:13 (Sidebar: Trustworthy Computing Initiative 17:53)      3. Trojans 12:42      4. Hybrids/Exotic Forms 27:54 (Sidebar: Botnets 27:07)      5. Ransomware 31:33      6. File-less (In-Memory Injection) 38:27      7. Adware 40:08      8. Malvertising 43:00 (Sidebar: 3rd Party Patching 45:18)      9. Spyware 47:15 CSO Online: 9 types of malware and how to recognize them Think you know your malware? Here's a refresher to make sure you know what you're talking about — with basic advice for finding and removing malware when you've been hit https://www.csoonline.com/article/2615925/security-your-quick-guide-to-malware-types.html
1:08:12
May 18, 2019
Security BSides co-founder, Jack Daniel and the BSides SATX Team Talking About Why Community Matters
Continuing our recent “community matters” theme, I invite the team behind the scenes of BSides San Antonio event to talk about the history and legacy of BSides and what makes these security conferences held around the world so unique and so special to us all. And, we have a very honored guest surprise the team with his cameo appearance on the show!  Mr. Jack Daniel, co-founder of Security BSides! What an honor!
52:07
May 9, 2019
Marcus Carey, CEO Threatcare and Founder of the Tribe of Hackers
In this inaugural episode of Cyber Speaks LIVE, I sit down with Marcus J Carey, CEO of Threatcare and Co-Author of Tribe of Hackers, to talk with our live audience about his growing up in Texas, doing crypto-communications in the US Navy, running a cyber startup and the birth of Tribe of Hackers. Marcus kindly takes questions from our audience that leads to some lively debate and engagement.
53:22
May 6, 2019