Artwork

Nội dung được cung cấp bởi Nisos, Inc.. Tất cả nội dung podcast bao gồm các tập, đồ họa và mô tả podcast đều được Nisos, Inc. hoặc đối tác nền tảng podcast của họ tải lên và cung cấp trực tiếp. Nếu bạn cho rằng ai đó đang sử dụng tác phẩm có bản quyền của bạn mà không có sự cho phép của bạn, bạn có thể làm theo quy trình được nêu ở đây https://vi.player.fm/legal.
Player FM - Ứng dụng Podcast
Chuyển sang chế độ ngoại tuyến với ứng dụng Player FM !

Building and Implementing Security Programs within Fast Growing Technology Companies

27:36
 
Chia sẻ
 

Manage episode 323720303 series 3331602
Nội dung được cung cấp bởi Nisos, Inc.. Tất cả nội dung podcast bao gồm các tập, đồ họa và mô tả podcast đều được Nisos, Inc. hoặc đối tác nền tảng podcast của họ tải lên và cung cấp trực tiếp. Nếu bạn cho rằng ai đó đang sử dụng tác phẩm có bản quyền của bạn mà không có sự cho phép của bạn, bạn có thể làm theo quy trình được nêu ở đây https://vi.player.fm/legal.

In episode 51 of The Cyber5, we are joined by Chris Castaldo. Chris is the Chief Information Security Officer for CrossBeam and has been CISO for a number of emerging technology companies.

In this episode, we talk about his newly released book, “Startup Secure” and how different growth companies can implement security at different funding stages. He also talks about the reasons security professionals should want to be a start-up CISO at a growing technology company and how success can be defined as a first time CISO. We also talk about how start up companies can avoid ransomware events in a landscape that is not only constantly changing but also gives little advantage for defenders of small and medium sized enterprises.

Two Topics Covered in this Episode:

  1. 4 Security Lessons for Founders of Start-up Technology Companies

When a B2B company is pre-seed or before Series A funding, customers might have leeway for lax cybersecurity controls. However, after an A round, policies, certifications (SOC2 or ISO27001), procedures will be required to ensure customer data is staying safe. A B2C technology company might not be asked by the public for certifications, but auditors and regulators may. Basic policies include:

  1. Single Sign-On or an Okta authentication into applications, cloud, and workstations
  2. Password management implementation (LassPass or OnePassword)
  3. Encryption at rest and transit
  4. Vulnerability scanning
  1. Combating Ransomware from The Inside-Out Approach and Integrating Threat Intelligence

Blocking and tackling from inside-out to get in front of ransomware is challenging. The simple items to tackle are the following:

  1. Auto-updates for patch management on operating systems
  2. Endpoint Detection and Response products
  3. Proper asset management to have full visibility on all network devices and services

At the point when resilience and compliance controls are in place and an organization can bounce back from an incident in a timely manner, adversary insights via threat intelligence is a logical next step.

  continue reading

91 tập

Artwork
iconChia sẻ
 
Manage episode 323720303 series 3331602
Nội dung được cung cấp bởi Nisos, Inc.. Tất cả nội dung podcast bao gồm các tập, đồ họa và mô tả podcast đều được Nisos, Inc. hoặc đối tác nền tảng podcast của họ tải lên và cung cấp trực tiếp. Nếu bạn cho rằng ai đó đang sử dụng tác phẩm có bản quyền của bạn mà không có sự cho phép của bạn, bạn có thể làm theo quy trình được nêu ở đây https://vi.player.fm/legal.

In episode 51 of The Cyber5, we are joined by Chris Castaldo. Chris is the Chief Information Security Officer for CrossBeam and has been CISO for a number of emerging technology companies.

In this episode, we talk about his newly released book, “Startup Secure” and how different growth companies can implement security at different funding stages. He also talks about the reasons security professionals should want to be a start-up CISO at a growing technology company and how success can be defined as a first time CISO. We also talk about how start up companies can avoid ransomware events in a landscape that is not only constantly changing but also gives little advantage for defenders of small and medium sized enterprises.

Two Topics Covered in this Episode:

  1. 4 Security Lessons for Founders of Start-up Technology Companies

When a B2B company is pre-seed or before Series A funding, customers might have leeway for lax cybersecurity controls. However, after an A round, policies, certifications (SOC2 or ISO27001), procedures will be required to ensure customer data is staying safe. A B2C technology company might not be asked by the public for certifications, but auditors and regulators may. Basic policies include:

  1. Single Sign-On or an Okta authentication into applications, cloud, and workstations
  2. Password management implementation (LassPass or OnePassword)
  3. Encryption at rest and transit
  4. Vulnerability scanning
  1. Combating Ransomware from The Inside-Out Approach and Integrating Threat Intelligence

Blocking and tackling from inside-out to get in front of ransomware is challenging. The simple items to tackle are the following:

  1. Auto-updates for patch management on operating systems
  2. Endpoint Detection and Response products
  3. Proper asset management to have full visibility on all network devices and services

At the point when resilience and compliance controls are in place and an organization can bounce back from an incident in a timely manner, adversary insights via threat intelligence is a logical next step.

  continue reading

91 tập

Tất cả các tập

×
 
Loading …

Chào mừng bạn đến với Player FM!

Player FM đang quét trang web để tìm các podcast chất lượng cao cho bạn thưởng thức ngay bây giờ. Đây là ứng dụng podcast tốt nhất và hoạt động trên Android, iPhone và web. Đăng ký để đồng bộ các theo dõi trên tất cả thiết bị.

 

Hướng dẫn sử dụng nhanh