Beta

Explore every episode of DrZeroTrust

Dive into the complete episode list for DrZeroTrust. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.

Rows per page:

1–50 of 199

Pub. DateTitleDuration
11 Sep 2023Surf Security and RBI00:31:16

What is Surf's new RBI extension? How does this fit with Zero Trust strategically? Why is RBI now a "thing" in security? Is this just for enterprises or all businesses? How hard is it to configure this thing? What about third parties and developers, does this help them be more secure? Those questions and more on this one!

07 Jul 2022Cyber news and Zero Trust insights for 7/6/202200:25:34

Marriott got hacked again, say what?  Does it mean anything?  What about their fines, didn't that teach them something?  Can I find vulnerable government assets that are misconfigured and make 30 grand in bug bounties in half an hour?  What about cloud resources that the DoD uses?  A billion records are stolen in China, what's up with that?  Those questions and more on this episode!

07 Jul 2021Cyber news and Zero Trust insights for 7/7/202100:25:05

Some really great reports published recently on a variety of issues in cyber.  Check it out.

23 Jan 2023Quantum and the Potential Problems Therein00:29:48

What the h*ll is quantum really?  Why should we care?  Does cracking an algorithm with quantum change the balance of power globally?  Is quantum potentially a WMD?  How can this technology be used by our government and others?  What about the banking system and quantum applications and risks?  Those questions and more on this very nerdy episode!

03 Nov 2022Cyber news and Zero Trust insights for 11/2/202200:29:14

Banks have paid out a massive multi-billion dollar plus to ransomware operations, but where does all that money go?  Is crypto entirely to blame?  Dropbox had a compromise issue, but luckily it's never happened before?  Right?  And it's good that it wasn't related to any companies intellectual property.  Oh wait.  And then let's talk about Chegg.  They get the award for continued cyber negligence I think.  But the FTC is now suing them, even though this is the fourth breach in a few years.  Good thing they moved fast.  Why does this keep happening and how are such major companies getting away with ignoring basic best practices?  Those questions and more on this episode.

12 Jul 2024The Dr Zero Trust Show00:27:32

In this conversation I discuss the Confucius Institute, cybersecurity search engines, ransomware defense evasion tactics, the GOP platform on protecting critical infrastructure, the OpenAI breach, cybersecurity concerns in the automotive industry, the White House's push for increased cyber funds, and the healthcare industry's pushback against cybersecurity reporting rules.


Takeaways


Augusta, Georgia is not an exciting place to visit

The Confucius Institute raises concerns about its funding and curriculum

Cybersecurity search engines like Greyhat Warfare can provide valuable information

Ransomware attackers are focusing on defense evasion tactics

The GOP platform emphasizes protecting critical infrastructure from hackers

OpenAI faced a breach but did not inform law enforcement

The automotive industry is increasingly concerned about cybersecurity

The White House is seeking increased cyber funds for federal agencies

The healthcare industry is pushing back against proposed cybersecurity reporting rules




04 May 2023Weekly(ish) Cyber and ZT News Analysis 5/3/202300:26:21

Are K-12 organizations and universities prepared for the onslaught of cyber threats? How long does it take me to find a vulnerable school district, it ain't long? An appeals court has upheld Merck's claim in the the NotPetya case. What does that mean for cyber insurance, and why does this make me so happy? Iran is moving quickly into the realm of influence operations, are they mirroring the Russian operations and how will this affect the upcoming election cycle? ChatGPT had a breach issue, how much of a threat or problem is this? Should we have expected anything less? Phishing is getting worse, statistically speaking, but how is this possible with all of the training we get? Is there a technical alternative that works? Those questions and more on this episode!

01 Feb 2023Addressing the Ransomware Problem with a Bold Strategy00:46:19

Can we have a national and international strategy that addresses ransomware?  How would that work?  Is it better to address the "how" of those attacks or the "why"?  What should we do to remove the incentive for these attacks?  Would a US first approach make us a bigger target?  What about kinetic attacks on those hacker groups?  Those questions and more on this super episode!

13 Dec 2024The Dr Zero Trust Show00:27:17

In this conversation, I discussed various aspects of cybersecurity, including the manipulation of narratives through social media, the implications of leadership structures within Cyber Command and the NSA, personal liability for cybersecurity leaders, emerging trends for 2025, and significant supply chain vulnerabilities. The discussion also reflects on the challenges faced by cybersecurity professionals and highlights key incidents from the past year.

Takeaways

Social media can easily manipulate narratives, impacting public perception.

The dual leadership of Cyber Command and NSA raises concerns about authority and effectiveness.

CISOs face increasing personal liability, affecting their role and decision-making.

Ransomware incidents are expected to remain high, posing ongoing risks to organizations.

Supply chain vulnerabilities can have cascading effects across industries.

Generative AI poses new threats, enhancing the capabilities of malicious actors.

Cybersecurity leaders are experiencing burnout, with many considering leaving their roles.

The importance of reassessing functional dependencies in cybersecurity insurance is critical.

Fortune 100 companies are significantly affected by recent vulnerabilities in web application firewalls.

The year in cybersecurity was marked by significant breaches and challenges, indicating a need for improved practices.




05 Apr 2022Deploying Zero Trust at the Enterprise Level00:29:22

Working with big enterprise ZT, how does one engage the leadership effectively?  Is this about more tech?  Who holds the keys to the kingdom on budget?  Where does it make sense to start with a big time roll out?  How hard is it to get ZT in place?  How long is the journey?  Where does one go after they solve their first problem?  And why is Sean Connery on the line for this call?

11 Apr 2022Cyber Insurance, Truth and Consequences with an Expert00:32:28

Is cyber insurance worth it?  Do insurers actually know what they are doing, and why are policies not being honored?  Is a strategy useful for better security and helping lower a premium?  What data is being used to validate a policy, or is that even a thing?  Is this a big deal for small business, or is cyber insurance better suited for enterprises?  And am I wrong by saying it's a "rip off"?  Those questions and more on this very cool episode.

08 Nov 2024The Dr Zero Trust Show00:27:12

In this conversation, I discussed various aspects of cybersecurity, including recent TSA regulations, stock market trends related to cybersecurity companies, emerging threats from AI-driven phishing scams, the importance of veteran employment in the cybersecurity field, rising salaries and stress levels among cybersecurity professionals, and the need for organizations to address vulnerabilities and improve their security measures. The discussion emphasizes the importance of proactive measures in cybersecurity and the potential for financial gain in the stock market following breaches.


Takeaways


The TSA is proposing new cybersecurity regulations for surface transportation.

Investing in cybersecurity stocks can be profitable after breaches.

AI is increasingly being used in sophisticated phishing scams.

Veterans can fill the talent gap in cybersecurity roles.

Cybersecurity salaries are rising, but so is job-related stress.

Organizations need to patch vulnerabilities promptly to avoid exploitation.

Emerging tools and resources can aid in cybersecurity efforts.

The importance of reporting significant security concerns is emphasized.

Cybersecurity professionals are seeking better work-life balance and training opportunities.

Proactive measures are essential to combat evolving cyber threats.



08 May 2024InfoBlox and Meerkats - What You Should Know00:27:54

Meerkats are dangerous, I guess. Especially in DNS. Yeah, that Meerkat. Why should we know about this type of attack? How does China play in here? Where is the risk? Does this type of attack merit increased concern?

27 Oct 2021Cyber news and Zero Trust insights for 10/27/202100:29:27

Disinformation with lobsters?  What about the Missouri Governor and "hacking" that website?  Does the new ransomware plan make much difference?  New threats in email from Microsoft and how do humans detect them?

01 Sep 2022Security for Apps and Low or No Code Systems00:28:54

How can you secure no code or low code applications?  Is devsecops a real thing?  Does anyone actually do this?  How should organizations look at the risks from these types of "factory made" apps?  Why is the 8200 unit such a big thing in the Israeli cyber scene?  What types of pricing make sense for security applications that you might not own?  How should the market approach the future of application security in an all cloud world?  Those questions and more on this one.

15 Jul 2021Cyber news and Zero Trust insights for 7/15/202100:34:20

A Congressional bill on Deepfakes?  What about the trend in phishing and ransomware?  Do APT nation state leaders care about our "requirements"?  And what happens when a law firm sues a ransomware gang?

16 Jun 2023Weekly(ish) Cyber and ZT News Analysis00:29:16

Samsung is dealing with an insider threat that tried to copy their entire chip manufacturing plant, wow! CISA issued a "binding" directive for ZT, but how binding is it really? The top 10 from the Verizon DBIR, what does that tell us about the space? Another Presidential candidate uses a deepfake to target their adversaries, should we worry? A mother deals with a deepfake voice attack where her daughter is "kidnapped", does this bode well for our collective future if criminals are vectoring in on this type of attack? 99% of organizations expect an identity related compromise this year, jeez (#killthepassword already). Those points and more on this one!

22 Dec 2021Big Dollars and the Cyber Security Market...00:29:41

Do the crazy valuations of companies help them or hurt them?  Does big money in cyber security investing fix the problem?  Why do some people continue to build businesses even after they cash out?  

28 Jul 2021Cyber news and Zero Trust insights for 7/28/202100:29:38

Masks everywhere at Blackhat?  Why does Kaseya have a ransomware decryptor NDA?  Why the lack of MFA in Twitter?  Are we getting better at fixing vulnerable software?  And What is the Ransomware Sheriff?

22 Sep 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:31:26

How does a CEO of a unicorn company view cybersecurity? How does the board of such a company look at the risks of cyber threats? Does insurance make sense for those leaders? What about the big acquisition in recent days, does that affect the overall market? Those questions and more on this episode!

20 Jul 2024The Dr Zero Trust Show00:32:35

DDoS hosts get arrested, but is it really a legit punishment? Cisco has an issue with remote access and a level 10 vuln, uh oh! Deepfakes are up over 1000% in countries with elections in 2024! And Snowflake adds MFA, after their issue, hurray! Buckle up!

15 Dec 2021Why Golf is the best strategy sport there is...and how it relates to cyber security.00:29:16

What can we learn from the game of golf and security strategy?  What telemetry matters most?  Do you practice right in cyber or in your golf game?  What's your favorite course?  And many more great golf analogies!

22 Aug 2022Selling Zero Trust at enterprise scale.00:31:37

Do enterprises really buy Zero Trust?  How should they think about a strategic approach to a problem.  What about rip and replace?  Are there no-go's when it comes to working to help an enterprise adopt ZT?  Where do they budget for these endeavors?  Is this only a big business problem?  Those questions and more on this episode.

05 Jul 2021AppSec, SDLC, and baking with Sandy Carielli00:37:30

Sandy has forgotten more about SDLC, AppSec and software security than most folks will ever know.  I was very lucky to get to pick her brain for a few minutes on how this affects the software lifecycle, and discuss her thoughts on how we "shift left" on building secure code.  

11 Aug 2021Cyber news and Zero Trust insights for 8/11/202100:29:43

Was Blackhat worth the trip, no.  What happens when you ransom a tractor?  How big is the ZT market?  Another hospital is shut down due to an attack, did patients die?  What about JCDC?

13 Oct 2022Cyber news and Zero Trust insights for 10/12/202200:29:24

Dell has setup a Zero Trust Center of Excellence, that's pretty cool.  Real investment into strategic technology alignment sounds like a good idea to me.  Disinformation around the hurricane Ian fiasco.  How can we defend democracy when folks buy into this stuff?  Are you using Reddit to gain insight into your customer experience, you should be.  How secure is the organization that is forcing me to renew my business and cyber insurance policy, wanna guess?  And what about the Uber CISO issue?  Does that scenario really affect us all?  Those questions and more on this episode.

11 Aug 2022Cyber news and Zero Trust insights for 8/10/202200:29:01

How hard is it to find "internal use only" files with a simple crafted search?  How about spreadsheets with passwords and admin logins?  What should we think about this whole Trello thing?  What happened when I got phished (yup, they got me).  Was it even a problem?  Is the national emergency alert system really vulnerable?  How big does the Zero Trust market get in the next 9 years?  Those points and more on this episode!

13 Sep 2021Threatlocker, the next Unicorn in cyber security.00:32:58

Thoughts from a guy running a cyber security company on everything from growth, hiring, and how he keeps his company secure even though he knows they are a real target.

28 Jul 2022Cyber news and Zero Trust insights for 7/27/202200:28:38

Can I find privacy violations with Shodan?  What companies are using hackable unpatched scada systems that are misconfigured?  Can we find osint on a company that has government contracts but is not secure?  Why is phishing training still a multi-billion dollar business when a variety of reports indicate that the numbers for that "defense" don't justify that expense?  Is the government really as secure as we think they are?  What about finding illegal violations of compliance mandates in ics systems?  Isn't breaking the law a bad thing?  Those questions and more on this podcast!  

16 Aug 2021Zero Trust conversation with John Kindervag00:46:03

A conversation on Zero Trust with the person noted for coining the term and starting the ZT movement.

29 Sep 2022Cyber news and Zero Trust insights for 9/28/202200:30:56

How many VPN's are out there that might have a configuration issue?  Are there any major companies that might be piping threats into their networks (the answer is probably).  Has Uber fixed the low hanging fruit from it's recent issue?  More ICS and SCADA vulnerable systems aren't out there, right?  Research from ZScaler on the use and adoption of the VPN is interesting, has the tide shifted with this old technology?  Are users really the weakest link, or has the security industry misled that group?  Those questions and more on this one!

06 Oct 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:29:29

What's the scariest sound you can hear in the middle of the night? It's not what you think. Microsoft and Bing have some "splaining" to do as their system is helping generate images of SpongeBob and other cartoons attack the World Trade Center. WithSecure has some really solid insights on the tactics and tools that bad guys use. Cisco Talos found that QakBot is back, shocker. And how will AI and deepfakes affect elections, ask Slovakia. Those points and more on this episode!

14 Apr 2022Cyber news and Zero Trust insights for 4/14/202200:28:25

The dog barks, like always.  What is the Zero Trust market map?  How about Microsoft's new CVE issue, is that something that we should have fixed years ago (the answer is hell yes).  Can I find vulnerable assets with no authentication in real time?  Forrester research published some great data on enterprise breach activity globally, what does it mean and how should we think about it?  What about cyber and nuclear threats, do those relate?  Those questions and more on this episode.

08 Dec 2022Cyber Certifications - The Self Licking Ice Cream Cone of Misery00:31:06

Why are certs hurting the industry?  Are they really?  How much does it cost to get an entry certification?  Why so much?  Is the process for certifications fair for everyone?  Should companies have a fellowship track for non-manager technologists?  How do we get past this problem?  Is HR in the way of fixing the cyber security hiring crisis?  How hard is it to fix the problem with management and onboarding?  Could a CISO get their own job based on the HR filtering system?  Those questions and more on this episode.

03 Jan 2025The Dr Zero Trust Show00:21:41

In this conversation, Dr. Zero Trust reflects on the state of cybersecurity as the new year begins, discussing the persistent issues of phishing, social engineering, and weak passwords that continue to plague the industry. He reviews significant cyber incidents from the previous year, including data breaches and legal developments, while also sharing personal reflections on his own goals and challenges faced in 2024. The discussion emphasizes the need for a strategic shift in cybersecurity practices and the importance of addressing foundational issues to prevent ongoing failures in the field.


Takeaways


The most prevalent methods of exploitation in cybersecurity are still phishing and social engineering.

Weak passwords remain a significant security risk in 2024.

Recent legal developments include a U.S. ban on data sales to adversarial nations.

Cyber incidents continue to rise, with notable breaches affecting government and private sectors.

Personal reflections reveal the importance of honesty in assessing one's goals and achievements.

Organizations relying on outdated practices are more likely to face breaches.

The concept of 'cyberflation' highlights the financial impact of cybersecurity failures on consumers.

A strategic shift towards Zero Trust (ZT) is necessary for better security outcomes.

The need for public awareness and legislative action in cybersecurity is critical.

2024 was marked by a lack of significant progress in cybersecurity despite increased awareness.



24 Feb 2025The Dr Zero Trust Show00:28:56

In this conversation, Dr. Zero Trust discusses the current state of cybersecurity, focusing on leadership appointments, the confusion surrounding cyber threat naming, emerging threats, and the intersection of espionage and cybercrime. He critiques the lack of operational expertise in cybersecurity leadership, highlights the challenges posed by evolving cyber threats, and emphasizes the importance of understanding the implications of AI in cybersecurity operations. The discussion also touches on data privacy legislation efforts, ransomware trends, and the security vulnerabilities in the drone industry.


Takeaways


Leadership in cybersecurity should prioritize technical expertise over political loyalty.

The U.S. is currently losing the cyber war against adversaries.

Confusion in naming cyber threat actors complicates response efforts.

Emerging cyber threats are increasingly sophisticated and state-sponsored.

AI can significantly enhance cybersecurity operations and efficiency.

Data privacy legislation is often ineffective and redundant.

Ransomware groups are evolving and becoming more organized.

The cybercrime ecosystem is thriving with complex interconnections.

Drones present significant security vulnerabilities that could be exploited.

Public awareness of cybersecurity risks is crucial for protection.



04 Aug 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:31:38

Insider threats are a real thing, do you have the tools to detect malicious intent before it becomes a threat? How do we know if behavior equals threat? More data on ransomware and the insurance market. Companies selling insurance are considering "ratings" for premiums. Halcyon identifies "new" threat groups, or is the same one with a new fancy name? The new cyber workforce plan, good or bad? Those questions and more on this episode.

15 Sep 2022Cyber news and Zero Trust insights for 9/14/202200:26:57

What a wake up call this week when working with SMB's on their cyber security strategy and the reality of the space.  Do SMB's use outsourced security, and is that smart?  Does that hurt their overall awareness?  Why aren't things getting patched the way they should even when we have been notified by CISA and others of "critical vulnerabilities"?  Does the upcoming legislation around semi-conductors and silicon pointed at China have any impact on our national security and cyber future?  Those questions and a few more on this one.

04 Apr 2024Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:32:25

Was Incognito mode from Google really "private"? Don't think so. What does the report from the fed say about Microsoft's issues with the China hack? Attacks are already bypassing "AI" solutions, shocker. More on the XZ Linux backdoor as well. Check out this episode and tell me what you think!

07 May 2024Xage and the future of ZTNA00:22:45

Is the VPN a security technology? Should businesses still use that risky technology? How can an organization move off that old tech? Where do VPN's fit into Zero Trust? Xage Co-Founder gives some great insights here.

08 Feb 2022Cyber news and Zero Trust insights for 2/8/202200:33:42

More ways cyber insurers are getting out of paying.  Two students hack a school system and ask for a job, awesome.  Microsoft talks about the lack of good IAM for Azure.  Google breaks down cryptojacking in it's cloud.  The insanity around threat intelligence and naming a threat actor group, and more on this episode.

25 Aug 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:31:10

Thoughts on the recent RNC candidate debate where cybersecurity never came up, super. China is using Linkedin to recruit spies, how can you know when you are targeted? Trustwave published new research on BEC hacks, what do we get from that research? Two guys are arrested for laundering money via crypto, is that a treasonous act? MAC's get some new malware, hurray! Ransomware group deletes a providers entire customer base's data, whoops! Those and more on this one!

24 Sep 2024The Dr Zero Trust Show00:28:47

Den Jones talks about why he is launching 909 Cyber for smb's and other businesses. He and I chat about how to address critical strategic shortfalls for organizations and he runs us through how he put Zero Trust in place while at Adobe! Don't miss this one!

07 Apr 2023Cyber news and Zero Trust insights for 4/6/202300:29:38

How many vulnerable systems out there are connected to the internet with a ten year old vulnerability, with RCE, and have no authentication? Surely the answer is 0? Operation Cookie Monster took down a dark marketplace, so what? Should there be a victory lap? KnowBe4 published some research on state and local security and BEC statistics, what should we learn from that document? Fake ransomware attacks are taking place, what the hell is that? Crowdstrike and others are publishing on threat groups, but the nomenclature is all over the place. How do we know what attackers are doing what if we can't align on the naming conventions? More insights on the Silicon Valley Bank fiasco (the executives did some "questionable" things). What does that mean for the cybersecurity market at large? Those questions and more on this episode.

23 Feb 2022Cyber news and Zero Trust insights for 2/23/202200:26:22

Zero Trust world was a blast, well done Threatlocker!  Microsoft has done some great work in helping people to understand Zero Trust.  Misinformation for critical infrastructure and corporate security is hard to do without a solid technology in place, especially at scale.  Reference architectures for Zero Trust are available.  Is the IRS the agency that can finally help with the ransomware problem and crypto crime?  The Justice Department's three year plan to move to Zero Trust and how they are approaching the issue, and an example of a state and local government that is enabling Zero Trust.  Check it out!

07 Sep 2022Cyber news and Zero Trust insights for 9/7/202200:31:28

Is the news media collaborating to manipulate our collective consciousness?  How would that happen?  Is local news "more true" than national news?  What about OPSEC for the war in Ukraine?  Could an organization cause a kinetic attack based on pictures that came from soldiers sharing via social media?  How does politics play into the space around cyber and disinformation?  Some hard hitting questions in this one to ponder.

12 May 2022Cyber news and Zero Trust insights for 5/11/202200:30:31

Can we find vulnerable ICS and SCADA controls on the internet?  What about the physical doors that are in those facilities?  Have we really learned anything a year after the pipeline hack?  Microsoft has put out it's advise for ransomware defense, is it any good?  What about F5 and it's big new vulnerability, should you be worried?  Why shouldn't we talk about gangs "going down" in cyber, and does that hurt or help as we deal with those threats?  Those points and more on this episode!

08 Nov 2021IdRamp and SSI in the consumer and business space.00:29:04

Can I download and configure an SSI app during a live recording?  Is SSI useful for the average consumer use case?  How should we look at the combination of SSI and biometrics?  Does this ultimately help kill the password?

09 Aug 2021Discussions on Ransomware and Cyber Warfare with General John Davis.00:47:32

Is ransomware a weapon?  What do we do about these attacks?  What is the task force doing about this?  Do the folks on Capitol Hill get it?  And that one time I got beat up by a bully...

16 Nov 2021#killthepassword with Simon Moffatt00:29:50

What do consumers really think about passwords?  Can technology solve the problem of unsafe passwords?  Where does the market go for better user access?  Does cloud make a difference?  And more on this episode.

19 May 2022Cyber news and Zero Trust insights for 5/18/202200:30:28

What matters more, targeting the "asset" (tractors) or the infrastructure for John Deere.  Can you overthrow a government with a ransomware attack?  Why are insurers changing their approach to cyber policies and why are they raising rates?  What about the NSA guidance on best practices, is it really that different?  Those questions and more on this one!

02 Feb 2022Cyber news and Zero Trust insights for 2/2/202200:25:56

Interesting points on a Zero Trust report by Illumio.  How to stop the majority of ransomware, it's not that hard.  How did we allow the US DoD to buy drone technology that was financed by China?  And what about some Shodan results that we should be aware of (like a submarine)?

05 Jan 2023Cyber news and Zero Trust insights for 1/4/202300:31:47

Welcome to 2023 y'all.  Let's get into the new year by looking at some news you need to know.  A major FAA system went down and caused an outage for all of Florida.  How secure is the FAA, and what about other airport safety systems?  Surely, no misconfigurations there.  Right?  Links to study guides for OSCP cert via Reddit, pretty cool huh?  A hospital was hit with ransomware then the bad guys gave the key away for free.  What does that reveal about the business model for those threat actors?  The best example of how "useful" GDPR is, via a hack.  Lol.  Those points and more on this one!

26 Jul 2021What is a Zero Trust Overlay Network? Why do people with British accents sound so smart? Is Zero Trust achievable with today's digital infrastructure?00:45:14

What is a Zero Trust Overlay Network?  Why do people with British accents sound so smart?  Is Zero Trust achievable with today's digital infrastructure?  More on those topics and other interesting discussions on how to use SDN/SDP and what this all means for security practitioners.

18 Feb 2025The Dr Zero Trust Show00:28:56

In this conversation, Dr. Zero Trust discusses the current state of cybersecurity, focusing on leadership appointments, the confusion surrounding cyber threat naming, emerging threats, and the intersection of espionage and cybercrime. He critiques the lack of operational expertise in cybersecurity leadership, highlights the challenges posed by evolving cyber threats, and emphasizes the importance of understanding the implications of AI in cybersecurity operations. The discussion also touches on data privacy legislation efforts, ransomware trends, and the security vulnerabilities in the drone industry.


Takeaways


Leadership in cybersecurity should prioritize technical expertise over political loyalty.

The U.S. is currently losing the cyber war against adversaries.

Confusion in naming cyber threat actors complicates response efforts.

Emerging cyber threats are increasingly sophisticated and state-sponsored.

AI can significantly enhance cybersecurity operations and efficiency.

Data privacy legislation is often ineffective and redundant.

Ransomware groups are evolving and becoming more organized.

The cybercrime ecosystem is thriving with complex interconnections.

Drones present significant security vulnerabilities that could be exploited.

Public awareness of cybersecurity risks is crucial for protection.




06 Oct 2021Cyber news and Zero Trust insights for 10/6/202100:35:01

Cybersecurity awareness month at the White House, so what?  Big dollars for ZT in the DoD, really?  The demographics of cybercrime and what that means for the rest of us, and what about maritime cybersecurity?

25 Oct 2024The DrZeroTrust Show00:23:02

In this conversation, I discuss the ineffectiveness of compliance violations and fines in changing corporate behavior regarding cybersecurity. I present data showing that fines are often negligible compared to company revenues, making them merely a cost of doing business. I argue for a reevaluation of negligence in cybersecurity and emphasizes the need for accountability, suggesting that without significant consequences, organizations will continue to prioritize profit over security.

Takeaways

Compliance violations are often seen as a cost of doing business.

Fines do not significantly impact large corporations' revenues.

Cyber insurance can offset the costs of compliance violations.

Statistically, companies often see stock price increases after breaches.

The current compliance framework does not enforce real change.

Negligence in cybersecurity needs a clearer legal definition.

Fines for violations should be more substantial to deter negligence.

Government organizations often escape penalties for breaches.

The data suggests a need for a shift in accountability measures.

Compliance does not equate to actual security improvements.





06 Dec 2021Cyber news and Zero Trust insights for 12/06/202100:29:45

Is cyber insurance a rip off?  What do insurance providers do to get out of paying their policy holders?  Does cyberwar affect small businesses?  Is everything of value to defend?  Are humans really the biggest threat vector?  Should you pay attention to a CISA advisory?

22 Sep 2021Cyber news and Zero Trust insights for 9/22/202100:36:57

Bad OPSEC on social media?  Farmers COOP hit with ransomware?  State government organization down for 4 months after "sophisticated" attack?  What should you know about cyber insurance?  Banking industry sees 1300% increase in attacks in 2021!  10 ways to avoid failing at ZT and more in this episode.

08 Sep 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:27:27

Data from Blackberry points to the same methods of exploitation, shocker. Some recent revelations from the National Security Agency and #china threat. Additionally, more insights on some of the flaws in our #compliance and #regulatory #cyber spaces. SeeTickets gets hacked, again. What's up with that Dallas City hack? Those and more on this episode!

24 Mar 2022Cyber news and Zero Trust insights for 3/23/202200:33:46

What should we take from the Okta situation?  More legislation to mandate training for government cyber security, really?  Too many agencies are getting involved in cyber, right?  What about the White House's "guidance" on the Russian threats?  Deepfakes and disinformation can influence actual combat, say what?  More bad hiring practices in cyber and some real issues with state and local cyber practices.  Check it out!

27 Mar 2025The Dr Zero Trust Show (the SignalGate Analysis)00:16:50

In this conversation, Dr. Zero Trust analyzes a recent incident involving the leak of tactical action plans by high-ranking officials through unsecured communication channels. He discusses the implications of this leak on national security, the classification of information, and the accountability of government officials. The conversation highlights the discrepancies in how classified information is treated among different individuals and the need for integrity and accountability in leadership roles.


Takeaways


The incident involved a leak of tactical action plans.

High-ranking officials should use secure communication methods.

The classification of information is often misinterpreted.

There is a double standard in accountability for leaks.

Leadership must hold themselves accountable for their actions.

The integrity of government officials is crucial for national security.

Past incidents of information leaks show a pattern of behavior.

The consequences for lower-ranking individuals are harsher than for officials.

Public trust in government is eroded by lack of accountability.

The conversation emphasizes the importance of protecting classified information.



21 May 2024A conversation with TrueFort00:12:24

What should we know about micro-segmentation? How important is a policy engine to Zero Trust enterprises? Where does the focus for network controls need to be? And more on this one!

25 Aug 2022Cyber news and Zero Trust insights for 8/24/202200:32:09

An article from Recorded Future points out new legislation in North Carolina and Florida that bars state backed organizations from paying ransomware attacks.  Surely that means they have their stuff on lock and have no misconfigured assets, right?  Google has an AI and privacy program that seem to be intersecting and could impact all of us, and Apple is dealing with those issues as well.  How do we handle this problem?  According to new research from Tessian "apathy" is the biggest vulnerability for an organization, but don't we train our folks enough to mitigate that risk?  Those questions and more on this episode.

25 Apr 2024Lumu AutoPilot 00:10:11

What is Lumu's AutoPilot? How can you use this? Why did they build it? Who is it for? Can you afford it? Lots of great insight in this one! Congrats to Lumu on a new, innovative offering! Meet them and learn more at RSA2024!

14 Nov 2023A chat with the Alludo CEO00:34:34

How does a CEO of a tech company view security? How does she run a company that is totally remote? What does her relationship with her CISO look like? What should I tell my daughters about being a woman in tech based on her experience? And more on this one!

01 Sep 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:33:25

Cyberpsychology and the hacker mindset, what should we think? Malwarebytes and their funding and layoffs, what does that indicate about the market? AI and LLM's aren't people, stop treating them like they are from MIT. Compliance does not equal security, say what? Phishing as a service get smarter according to Microsoft. The FBI "brought down" a massive botnet, they'll never come back right? And a very suspect claim from a vendor on their "response time". All that and more on this one!

12 Jan 2022Cyber news and Zero Trust insights for 1/12/202200:27:21

Predictions from vendors for 2022.  Are the leaders on Capitol Hill actually doing anything on the cyber front?  The first log4j malware attacks are showing up, what can we do?  What about insider trading using hacked systems to gain a financial advantage?  Those questions and more on this episode!

20 Mar 2025The Dr Zero Trust Show00:19:42

In this conversation, Dr. Chase Cunningham, also known as Dr. Zero Trust, discusses the intersection of cybersecurity and finance, focusing on market trends, vulnerabilities, and the implications of recent cybersecurity incidents. He emphasizes the importance of understanding the financial aspects of cybersecurity, including stock performance and investment strategies, while also addressing the challenges faced by government programs and the ongoing threats from ransomware and state-sponsored attacks.


Takeaways


Cybersecurity is becoming increasingly intertwined with financial markets.

Investors should consider buying stocks after breaches for potential rebounds.

Government cybersecurity programs face significant vulnerabilities.

Microsoft has not patched a critical vulnerability for eight years.

Legislative bodies are scrutinizing the DHS's response to cyber threats.

Ransomware operations may have connections to state actors.

Investment opportunities exist in the cybersecurity sector despite volatility.

Fake updates are a common tactic used by ransomware gangs.

Understanding the financial impact of cybersecurity breaches is crucial.

Staying informed and proactive is essential for cybersecurity.





17 May 2024Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:31:03

Was that Nigerian prince who wanted to share his money with you real? The US DoJ files paperwork on a Russian Lockbit "mastermind", so what? How much is it going to take before we see real action based on the aggression we see from our adversaries? Those and more on this one! Don't miss it!

11 Jan 2023Is TikTok really a threat?00:24:28

Is TikTok really a threat to national security?  Why should we be concerned about this app?  Should your kids be on this thing?  What are the implications for national security and those folks who have clearances?  Where does this all go in the next year?  What about social media and the justice system?  Are you still able to get a fair trial in today's news cycle focused world?  How does that affect our future?  Those questions and more on this one with an expert who served in the FBI!

30 Jun 2021Cyber news and Zero Trust insights for 6/30/202100:21:23

Some really great reports published recently on a variety of issues from leadership in cyber to how the SEC is getting involved in enforcing fines in this space.  Check it out.

24 May 2023DrZeroTrust Podcast for 5/24/202300:23:41

Should we be concerned that our leaders (and former leaders) are posting deepfakes onto social media? What can we learn from the Uber case and the final decision by the lawmakers? What did the general counsel do in that case, what about the CEO? How should we plan for a ransomware attack? Can we learn from the lessons that a CISO has been through and be better prepared (hint: yes). When is the best time to learn when to fight, before the event or during? And was I wrong about my thoughts on executive punishment for breaches, probably...

25 Aug 2021Cyber news and Zero Trust insights for 8/25/202100:29:26

A government and industry meeting on cyber at the White House?  Why is cyber insurance such a crazy market sector?  What do ransomware actors do when they get on a system?  What should we learn from those tactics and how can we defend ourselves better?

19 Jan 2023Cyber news and Zero Trust insights for 1/18/202300:26:11

Checkpoint released a report on the wrap up from 2022, what can we learn from that analysis?  It's a super cool report by the way, ping me for the link!  How secure or insecure are the education systems in the US?  Can I find some glaring issues?  China wants to "work with" the UN on addressing disinformation, ok.  Lol, sure.  What do they mean?  A major shipping system is hit with ransomware, uh oh!  Orange published some research on the criminal mindset and motivations for ransomware operators.  Wow that is very interesting, but what should we take away from that research?  Norton got problems y'all, what can we learn from the problems they face?  Those points and more on this episode!

17 Nov 2022Cyber news and Zero Trust insights for 11/17/202200:31:23

Zscaler has come up with their own certification for Zero Trust.  Is that a good thing?  What else is up with Medibank and how bad is the security for the Australian government that is pushing the formation of these new "hack back" teams?  Is that even a thing?  China is using universities to plunder research and intellectual innovations from America, so what?  Why isn't that more of a problem?  Don't we have a means to address this insider threat activity?  Navigation systems for pilots were affected recently, did you hear about that on the news?  Why not?  How much financial impact can one tweet have on a major company?  It's a lot y'all.  Those questions and more on this episode.

21 Mar 2023New Approach to Security Strategy via Distributed Ledgers00:29:53

Not Blockchain...Or, kinda...But not really?  Anyway listen to smarter folks than me (lots of those) talk about how we can innovate around the use of distributed ledgers as part of a security strategy.  And how is this approach being accepted internationally, especially in Australia?  Cool new methods of enabling security with the folks from Tide (not the soap, the security guys).  Some solid conversation on this one y'all!

31 Jul 2024NHI and Zero Trust00:27:39

What are Non-Human Identities, and why should we care? What does a 4 time CISO have to say about this issue? Does Zero Trust stand up to his scrutiny? Don't miss this one!

27 Oct 2022Cyber news and Zero Trust insights for 10/27/202200:30:54

A major insurance provider for an millions of people is dealing with a compromise, surely they have buttoned up the easy stuff?  Right?  Wanna bet.  Can I find a misconfigured SSH server that pipes me directly into an adversary nations internal networks?  Maybe.  More problems with TikTok as it gets reported in Forbes that the company was working to access American citizens personal location data "without their knowledge".  Uh oh.  How about the new mandates from TSA for the rail companies?  Do those requirements really have teeth and will they help things?  How many standards for compliance and the legal requirements to do business via digital connections are there?  Guess.  FastCompany got hit via the use of really bad passwords, that must have been a really hard problem to solve.  Right?  Those questions and more on this episode.

18 Aug 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:28:55

How to defend from a "Zero Day" attack that is "not in any anti-virus" engine. Proxy wars from AT&T. Interesting data from Flashpoint on the underground market. Is CISA really enforcing effective controls if they rely on training? Irish police department have a data breach that might lead to terrorist targeting, yikes! And rethinking the terminology and understanding around cyberwar! Those points and more on this episode!

13 Jan 2025The Dr Zero Trust Show00:32:03

In this conversation, Dr. Zero Trust discusses various aspects of cybersecurity, focusing on ransomware attacks, their impact on educational institutions, challenges in the cybersecurity workforce, emerging startups, government initiatives, financial implications of data breaches, and the effectiveness of cybersecurity labeling programs. The discussion highlights the need for proactive measures in cybersecurity and the importance of addressing non-human identity security challenges.


Takeaways


Ransomware attacks are on the rise, with significant impacts on organizations.

Cybersecurity events have affected educational systems, compromising student data.

There is a critical shortage of qualified cybersecurity professionals despite high demand.

Emerging cybersecurity startups are receiving substantial funding but need to demonstrate efficacy.

Government initiatives are being introduced to enhance cybersecurity measures.

Data breach notification laws can increase borrowing costs for businesses.

The Cyber Trustmark program may not effectively address cybersecurity concerns.

Non-human identities pose significant security challenges that need to be addressed.



07 Jan 2022A look back at the major hacks of 202100:21:05

A look back at 2021 and the major hacks we endured.  How did they happen?  What should we learn?  Where did it all go wrong?  Can we defend ourselves from these threats in the future?  Does Zero Trust really make sense?

28 Mar 2022The Devil Never Sleeps new book review00:22:21

"The Devil Never Sleeps" is one of the best books out there that can help us better understand how to deal with today's never ending threats.  Juliette Kayyem has done a great job of helping break down a variety of past historical issues and applied realistic and insightful ways to help her readers think more intelligently about accepting the threats and dealing with them, rather than being fearful of them.  Her book is a must read, go get your copy now!

09 Feb 2023Cyber news and Zero Trust insights for 2/9/202300:32:09

Should we worry about the spy balloon?  Why not?  Gartner published some "research" on Zero Trust and how they don't see the strategy as a silver bullet.  Awesome.  Let's analyze that game changing paper.  Venturebeat also published a report on how to get wins from your Zero Trust endeavors this year, what should we pay attention to there?  Why wasn't cyber a topic during the State of the Union?  PWC published a good report on the executive sponsorship for security in large organizations, what can we learn there?  Those topics and more on this episode!

30 May 2023Crowdsec and collective security conversation00:26:55

Ever wanted to learn the difference between a Lama and an Alapaca, we talk about that here. Weird but interesting. Crowdsec discusses their approach to changing the way we handle malicious IP's and domains. Their approach to Zero Trust as part of a global network is innovative. We chat about how open source solutions can help businesses of all sizes better defend themselves. Some discussion on collective threat intelligence, and conversations about sharing information to dynamically defend the network.

30 Mar 2023Cyber news and Zero Trust insights for 3/29/202300:33:33

Did the Pope wear a puffy jacket? So what? How might applied deepfakes be used to manipulate the collective narrative? What about our political system? Cofense published their annual report on the state of email security. What can we learn from that? Cymulate also published their analysis of more than 1 million security assessments. What's in there for us to learn? Lloyds CEO said they might take a hit on their cyber insurance offering due to their policies around the "war clause. Ok, what's the big deal? Ivanti published a report on government cyber security status. Surely all is well if the government is involved (and this is a global analysis, not just the US y'all.) Those points and more on this episode!

16 Jun 2022Cyber news and Zero Trust insights for 6/15/202200:29:38

Thoughts on RSA2022.  New research from Digital Shadows breaks down key areas of concern for us.  I find some vulnerable databases on the web (some are "security vendors"...uh oh).  We are still failing at the basics, and the password is eating our lunch, why is this still a problem?  A great new blog from the S/R team at Forrester on the economy and the security market.  Did AI just go sentient?  Those thoughts and more on this episode!

22 Nov 2024The Dr Zero Trust Show00:16:57

In this conversation, Dr. Zero Trust and Kevin Brink discuss the challenges and innovations in implementing Zero Trust security frameworks, particularly within the Department of Defense (DoD). Kevin shares insights on the need for automation in Zero Trust assessments to overcome the limitations of manual processes, emphasizing the importance of empirical data for continuous evaluation. They explore the cost and scalability of Zero Trust solutions, as well as the value of assessing existing security measures against Zero Trust principles.

Takeaways


Automation is essential for effective Zero Trust assessments.

Manual assessments are labor-intensive and unsustainable.

Empirical data is crucial for validating security measures.

Zero Trust can be applied across various industries, not just DoD.

Breach and attack simulations provide quantitative data for assessments.

Cost-effective solutions can scale based on organizational needs.

Continuous monitoring is key to maintaining security compliance.

Zero Trust frameworks can help identify areas of inefficiency.

Integration with existing systems enhances the value of Zero Trust.

Understanding the specific needs of an organization is vital for implementation.


06 Feb 2025The Dr Zero Trust Show00:42:48

In this conversation, Dr. Zero Trust, Anne Saunders, and Jack discuss the complexities of cybersecurity, particularly in the context of IoT and operational technology. They explore the vast attack surface presented by IoT devices, the challenges of securing these devices, and the importance of embedding security into the design of technology. The discussion also touches on regulatory frameworks, investment trends in cybersecurity, and the future of IoT security solutions.


Takeaways


IoT represents a significant attack surface for cybersecurity.

Embedding security into device design is crucial.

Data collection from IoT devices poses security risks.

Regulatory compliance is becoming more stringent with NIS2.

Investment in cybersecurity is often driven by immediate results.

The cost of breaches can have a tangible impact on businesses.

AI is changing the landscape of cybersecurity discussions.

Supply chain security is a critical component of IoT security.

Static credentials are a major vulnerability in cybersecurity.

A holistic approach to cybersecurity is necessary for effective protection.



05 Jul 2022What's up with the WAF market?00:27:33

What's up with the WAF market?  Talking about how we should and shouldn't use a WAF with an expert.  Is the WAF the best way to address the problems we face?  Where is this market going?  What about the evolution of the WAF and it's place in history?  And some hard questions with data to challenge why we might need to move to a new approach.

17 Mar 2025The Dr Zero Trust Show00:33:49

In this conversation, Dr. Chase Cunningham and Barry Mainz, CEO of Forescout, discuss the pressing issues surrounding cybersecurity, particularly in critical infrastructure, legacy systems, and the importance of a zero trust approach. They critique the Netflix series 'Zero Day' for its portrayal of cybersecurity threats and explore the current state of security in various sectors, including healthcare and airports. The discussion emphasizes the need for compliance, business continuity, and the integration of cybersecurity into business strategies. They also touch on the future of cybersecurity investments and the importance of considering schools as critical infrastructure.


Takeaways


The portrayal of cybersecurity in media can be exaggerated.

Critical infrastructure is vulnerable and requires investment in security.

Zero trust principles should be applied to OT and IoT systems.

Legacy systems pose significant challenges for cybersecurity.

Compliance requirements for OT and IoT are lacking compared to other sectors.

Business continuity is a key driver for cybersecurity investments.

Cybersecurity discussions should focus on business impacts, not just technical details.

Heterogeneous environments require flexible security solutions.

Airports vary in their cybersecurity readiness based on age and investment.

Healthcare cybersecurity often reacts to breaches rather than preventing them.



18 Oct 2021Cyber Dollars and Market Shenanigans with an Industry Icon.00:27:50

Richard Stiennon (the OG Curmudgeon) and I discuss investments and market dynamics in cybersecurity.  He provides his views on a variety of topics and breaks down how he sees the market through his lens and vast experience.  Check out his books and his insights on this space every chance you get!

26 Apr 2024Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:32:31

Mandiant says attacker dwell time is "going down" but how is that measured? Is that accurate? TIkTok finally get's the treatment it "deserves" with a proposed sale or ban, but is that going to make a difference? Another agency is created for cyber diplomacy, yeah (your tax dollars at work). And a known Russian cyber group attacks a town's water supply and floods nearby areas, doesn't that constitute some reciprocity?

15 Sep 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:29:13

Should executives ever be exempt from security standards and practices, the answer rhymes with bell no. MGM got his with ransomware via a third party and some social engineering, but they spend hundreds of millions on security. So what should we learn from that? CISA wants to offer free scans for utilities, is that a good or bad thing? Congress wants to legislate around deepfakes for elections, how will that work? And a major university was found to be fudging their self certification for compliance, whoops! Those and more on this one!

10 Nov 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:28:46

Solarwinds fires back at the SEC! It's about to go down! Trustwave has some great insight on hacking medical devices, don't be tempted! The Okta breakdown of what happened and when. Github releases some "AI" to help with security "left of boom." And more on this episode!

20 Jun 2023Cytwist and their unique method for security analytics and threat hunting!00:28:33

Is it possible to take a different approach to threat detection and do better? Why are endpoint security solutions missing the threats that we buy them to detect? Is a counter-terrorism method applicable to threat hunting? How does malware evade allow listing in some instances? What gaps in coverage are we seeing from methodologies for threat intelligence? Those questions and more on this episode!

04 Aug 2022Cyber news and Zero Trust insights for 8/3/202200:34:20

Are there potential ways to attack a nuclear site via online misconfigurations?  What about water as a vital national resource, can you attack a water supply system?  Or a dam?  Are containers inherently secure, and does that matter when they are part of a cluster?  PE firms keep buying up the security market players, is there an anti-trust issue there?  Is your threat intelligence service pulling in IOC's from US Cyber Command?  Was the Pelosi visit part of a cyber attack?  Does that matter and is it cyberwarfare?  Weak security in the system used to track organ transplant systems, that's ok right?  And some points on how to stay motivated (lol) and my thoughts on dealing with trolls online.  My cool new swag from Lumu and more on this episode.  Check it out!

30 Nov 2023Weekly(ish) Cybersecurity and Zero Trust Market Analysis00:28:31

What's up with the Okta fallout? What does Uber's former CISO say about the SEC and dealing with a hack? How hard is it to find a hackable water control system when the problem with it is published in the news? Do companies really use "ai" to write fake articles? Are you paying for it? Those points and more on this episode!

24 Jan 2022Threat intelligence and the cyber security market with Brian Kime.00:37:45

What is threat intelligence, and what is the value in data?  Does brand defense make a difference?  Do his customers worry about deepfakes?  What is attack surface management and how is that market changing?  And more on this episode.

18 Jul 2022Applying Zero Trust to Cloud Workloads and Kubernetes.00:22:45

More ideas and thoughts around applying Zero Trust to cloud workloads and kubernetes.   How should we think about the inherent vulnerabilities in these application development environments?  How can you secure something that only exists for minutes at a time?  Can you use open source solutions to approach the problems in this space?  Do developers really need to be security engineers, and should security people know how to build apps to make things more secure?  Check this one out and look for a video demo on Tigera.io and their open source Calico solution soon!

Enhance your understanding of DrZeroTrust with My Podcast Data

At My Podcast Data, we strive to provide in-depth, data-driven insights into the world of podcasts. Whether you're an avid listener, a podcast creator, or a researcher, the detailed statistics and analyses we offer can help you better understand the performance and trends of DrZeroTrust. From episode frequency and shared links to RSS feed health, our goal is to empower you with the knowledge you need to stay informed and make the most of your podcasting experience. Explore more shows and discover the data that drives the podcast industry.
© My Podcast Data