
11.7K
Downloads
158
Episodes
A podcast that takes a deeper look at today’s most important issues in cyber security, and beyond.
Episodes

Mar 30, 2022
Mar 30, 2022
29 min
Distributed denial of service attacks -- or DDoS -- are up 14 per cent on 2019's figures, according to research by security firm NETSCOUT.
And attacks are becoming more complex, with some using as many as 26 different vectors.
At the same time, there is a massive online market for DDoS attacks, with a terabit-class attack costing as little as $6500. Sites on the dark web even offer criminal hackers free trials of their wares, so the barriers to entry are effectively zero.
What, then, can security teams do to counter the DDoS threat? And could governments do more? Our guest this week is Richard Hummel, ASERT Threat Intelligence Lead at NETSCOUT. He discusses this, and more, with editor Stephen Pritchard.

Mar 16, 2022
Mar 16, 2022
29 min
Are we underestimating the security threats to mobile devices – and indeed the threats to mobile infrastructure?
Organisations of all sizes now depend heavily on mobile devices. But, although mobile security rarely makes the headlines, the risks posed by ever more powerful devices, and networks, are all too real.
In fact, this week's guest argues that mobile devices were never designed to operate on corporate networks.
Andy Brown is the CTO at Mobliciti. His firm’s been running mobile infrastructure for enterprises since 2009, and he monitors the mobile threat closely. He discusses how the way mobile technology has changed the way we work, and what that means for cybersecurity, with Stephen Pritchard.

Feb 23, 2022
Feb 23, 2022
29 min
Stolen or compromised identities have been an attack vector for years, if not decades. Even now, organisations are failing to protect against compromised identity. Identity is one of security’s critical weak spots. But why is this?
Once an attacker breaches defences, it is still too easy for them to move laterally, and to attack higher value targets, or as we've seen recently, attack an organisation with ransomware.
Our guest this week is chief security architect and formally the chief deception officer at Attivo, Carolyn Crandall
She argues that it is changing technology and changing work patterns, with the need to access information anywhere, and at any time, that is making these attacks both more common, and more damaging.
Interview by Stephen Pritchard

Feb 9, 2022
Feb 9, 2022
29 min
What happens if your personal devices are stolen? Few victims of theft recover their goods. But the loss of the hardware might only be the start of their problems.
There is a growing black market in stolen devices, but also in tools that can unlock them, to steal credentials or to attack other networks. People who lose a device can be a victim twice over, if hackers then use their own property to target their identity.
In this week’s episode, security researcher Adalsteinn Jonsson explains how this is exactly what happened to his partner, and how the incident prompted him, to undertake their own investigations. He, and fellow researcher at cyber security company Cyren, Magni Reynir Sigurðsson, take up the story.
Interview by Stephen Pritchard

Jan 26, 2022
Jan 26, 2022
29 min
Is ageism a problem in cybersecurity, and IT?
The pandemic has accelerated a trend that observers were already warning about: older staff are leaving IT security. And with them, their knowledge and experience leaves too.
What then can be done to encourage older workers to stay in the industry? Is ageism a problem, and if it is, how do we counter it?
This week’s guests are inter-generational diversity expert and author, Henry Rose Lee and Gernot Hacker, from cybersecurity firm Appgate. Appgate recently commissioned a focus group study looking at attitudes to age in cyber security, as they explain.
Interview by Stephen Pritchard

Jan 12, 2022
Jan 12, 2022
29 min
The Internet of Things continues to grow at pace. But are its security flaws being addressed?
Industrial, operational technology and consumer devices are increasingly connected, but security is too often an afterthought, with flaws such as default passwords and insecure firmware. And many IoT devices are hard to patch, if they can be upgraded at all.
The result is an expanding attack surface, that risks undermining the benefits of IoT technology. But could 2022 be the year this is changes? The UK has introduced a voluntary code of practice, Secure By Design, and the Product Security and Telecommunications Infrastructure Bill should become law this year.
Our guest this week is John Moor, MD at the IoT Security Foundation. He discusses the risks posed by the technology, and how manufacturers, governments and end users can help to solve it, with Security Insights' editor Stephen Pritchard.

Dec 16, 2021
Dec 16, 2021
29 min
In this programme, Security Insights invites a selection of industry experts to look back at 2021, and to give their outlook for cybersecurity in 2022.
This episode's guests are:
Piers Wilson, director, Chartered Institute of Information Security
Dr Ian Pratt, Global Head of Security at HP
David Carroll, MD, Nominet Cyber
Jamie Collier, cyber threat intelligence consultant, Mandiant.
Episode edited by Stephen Pritchard

Dec 2, 2021
Dec 2, 2021
29 min
Respect In Security was founded earlier this year to tackle harassment and inappropriate behaviour in the cybersecurity industry.
And negative behaviour, online and face to face, is all too common.
Security Insights invited Respect In Security's co-founders, Lisa Forte and Rik Ferguson, to explain their mission - and why making the industry safer and more inclusive ultimately benefits everyone.
Interview by Stephen Pritchard

Nov 17, 2021
Nov 17, 2021
29 min
Can digital technology help people around the world who lack access to a documented identity?
Over a billion people worldwide lack access to basic papers, such as a birth certificate or passport. This makes it hard to access services such as health and education. For states, it makes it hard to prevent fraud, or detect crime.
Our guest this week is Julie Dawson, head of regulatory and policy at Yoti, a digital ID provider. She speaks to editor Stephen Pritchard about the identity gap, and also whether security companies should also have a social purpose.

Nov 3, 2021
Nov 3, 2021
29 min
The idea of building security in to new hardware and software products from the outset has gained ground over the last few years.
And the move to "shift left" and introduce security by design has gained ground, following growing concerns about supply chain attacks.
One way to achieve this is through threat modelling. Threat modelling is not, itself, new: Microsoft did pioneering work on it in the Nineties. But it is now being adopted by bodies such as NIST, with the goal of reducing zero-day vulnerabilities.
Our guest in this episode is Stephen de Vries. Co-founder and CEO of IriusRisk, he has worked on threat modelling for over a decade. He explains why organisations should add it to their security toolkit.
