DrZeroTrust - podcast cover

DrZeroTrust

Dr. Chase Cunninghamwww.patreon.com
Unlock the future of cybersecurity with the "Dr. Zero Trust Podcast" on all podcasting platforms! Join me as we delve into Zero Trust Security, redefining how we protect data and networks. Explore frameworks, threat prevention, identity management, exclusive interviews, and emerging tech. Whether you're a pro or just curious, trust me– this podcast is where those who value honesty and real insights go for their cybersecurity insights! Tune in on Spotify, Google, or ITunes now. #DrZeroTrustPodcast #Cybersecurity #ZeroTrust
Last refreshed:
Follow this podcast in the Metacast mobile app to refresh it and see new episodes.
Download Metacast podcast app
Podcasts are better in Metacast mobile app
Don't just listen to podcasts. Learn from them with transcripts, summaries, and chapters for every episode. Skim, search, and bookmark insights. Learn more

Episodes

Cyber Certifications - The Self Licking Ice Cream Cone of Misery

Why are certs hurting the industry? Are they really? How much does it cost to get an entry certification? Why so much? Is the process for certifications fair for everyone? Should companies have a fellowship track for non-manager technologists? How do we get past this problem? Is HR in the way of fixing the cyber security hiring crisis? How hard is it to fix the problem with management and onboarding? Could a CISO get their own job based on the HR filtering system? Those questions and more on thi...

Dec 08, 202231 minSeason 2Ep. 44

Cyber news and Zero Trust insights for 11/30/2022

Do buyers always configure vendor security solutions correctly? Is there a magic button to push and then your organization is secure? Do vendors have no risks or avenues of compromise? How bad is the MSQL database security that is out there right now (think millions). The DoD released it's strategy for Zero Trust, what should we take away from that? Amazon is offering a security data lake recently, is that a good thing? The White House and Starlink were hit by a threat group via a DDoS attack, s...

Dec 01, 202229 minSeason 2Ep. 45

What happens when two former analysts have a real conversation?

A former Forrester analyst and a former Gartner analyst talk about the market and a variety of topics. Is it a good idea for layoffs to be taking place right now in cyber as the economy takes a dive? How will that affect our collective security? What should you know about analyst reports like the Wave or the Magic Quadrant? Does security product bloat actually hurt operational capabilities? Should automation be everywhere? How does strategy start, and where? Why do customers still run towards po...

Nov 28, 202240 minSeason 2Ep. 44

Cyber news and Zero Trust insights for 11/17/2022

Zscaler has come up with their own certification for Zero Trust. Is that a good thing? What else is up with Medibank and how bad is the security for the Australian government that is pushing the formation of these new "hack back" teams? Is that even a thing? China is using universities to plunder research and intellectual innovations from America, so what? Why isn't that more of a problem? Don't we have a means to address this insider threat activity? Navigation systems for pilots were affected ...

Nov 17, 202231 minSeason 2Ep. 43

Cyber news and Zero Trust insights for 11/9/2022

A noted Russian "leader" openly admits to tampering with elections, does that close the book on whether or not that has happened? An article on the Hill says that "ignorance" is the issue for legislators regarding cyber. Is it "ignorance" or willful ignoring of the problem? With the midterm elections going on surely I can't find potentially insecure and misconfigured election related systems? Right? And surely the company that has been tasked with securing those election networks isn't at risk, ...

Nov 10, 202228 minSeason 2Ep. 42

Cyber news and Zero Trust insights for 11/2/2022

Banks have paid out a massive multi-billion dollar plus to ransomware operations, but where does all that money go? Is crypto entirely to blame? Dropbox had a compromise issue, but luckily it's never happened before? Right? And it's good that it wasn't related to any companies intellectual property. Oh wait. And then let's talk about Chegg. They get the award for continued cyber negligence I think. But the FTC is now suing them, even though this is the fourth breach in a few years. Good thing th...

Nov 03, 202229 minSeason 2Ep. 41

Cyber news and Zero Trust insights for 10/27/2022

A major insurance provider for an millions of people is dealing with a compromise, surely they have buttoned up the easy stuff? Right? Wanna bet. Can I find a misconfigured SSH server that pipes me directly into an adversary nations internal networks? Maybe. More problems with TikTok as it gets reported in Forbes that the company was working to access American citizens personal location data "without their knowledge". Uh oh. How about the new mandates from TSA for the rail companies? Do those re...

Oct 27, 202231 minSeason 2Ep. 40

Cyber news and Zero Trust insights for 10/19/2022

How long does it take to find possible vulnerable assets online, about 21 minutes. Yeah. Is the OPM data breach "settlement" even worth it? Surely I can't find admin usernames and passwords with 1234 on the internet, right? Certainly not for a state or local system, right? Is data security up to par after a breach? Why aren't states and local governments willing to work through the paperwork to get a cyber security grant? That's nuts! Is the job market getting any better for staffing? Do trends ...

Oct 19, 202232 minSeason 2Ep. 39

Cyber news and Zero Trust insights for 10/12/2022

Dell has setup a Zero Trust Center of Excellence, that's pretty cool. Real investment into strategic technology alignment sounds like a good idea to me. Disinformation around the hurricane Ian fiasco. How can we defend democracy when folks buy into this stuff? Are you using Reddit to gain insight into your customer experience, you should be. How secure is the organization that is forcing me to renew my business and cyber insurance policy, wanna guess? And what about the Uber CISO issue? Does tha...

Oct 13, 202229 minSeason 2Ep. 38

Cyber news and Zero Trust insights for 9/28/2022

How many VPN's are out there that might have a configuration issue? Are there any major companies that might be piping threats into their networks (the answer is probably). Has Uber fixed the low hanging fruit from it's recent issue? More ICS and SCADA vulnerable systems aren't out there, right? Research from ZScaler on the use and adoption of the VPN is interesting, has the tide shifted with this old technology? Are users really the weakest link, or has the security industry misled that group? ...

Sep 29, 202231 minSeason 2Ep. 37

Thoughts and Perspectives on the Twitter Whistleblower

Why are security leaders going "scorched earth" when they leave employers? How can an organization better be prepared to deliver on their promises? Does ethics apply in technology (it sure should)? What's the right and wrong way to go about blowing the whistle when the need is there? Does money paid out call into question the motives for speaking out? Is it better to go out with a bang or just fade away? Some hard hitting questions on this one!

Sep 19, 202247 minSeason 2Ep. 37

Cyber news and Zero Trust insights for 9/14/2022

What a wake up call this week when working with SMB's on their cyber security strategy and the reality of the space. Do SMB's use outsourced security, and is that smart? Does that hurt their overall awareness? Why aren't things getting patched the way they should even when we have been notified by CISA and others of "critical vulnerabilities"? Does the upcoming legislation around semi-conductors and silicon pointed at China have any impact on our national security and cyber future? Those questio...

Sep 15, 202227 minSeason 2Ep. 36

Cyber news and Zero Trust insights for 9/7/2022

Is the news media collaborating to manipulate our collective consciousness? How would that happen? Is local news "more true" than national news? What about OPSEC for the war in Ukraine? Could an organization cause a kinetic attack based on pictures that came from soldiers sharing via social media? How does politics play into the space around cyber and disinformation? Some hard hitting questions in this one to ponder.

Sep 07, 202231 minSeason 2Ep. 35

Security for Apps and Low or No Code Systems

How can you secure no code or low code applications? Is devsecops a real thing? Does anyone actually do this? How should organizations look at the risks from these types of "factory made" apps? Why is the 8200 unit such a big thing in the Israeli cyber scene? What types of pricing make sense for security applications that you might not own? How should the market approach the future of application security in an all cloud world? Those questions and more on this one.

Sep 01, 202229 minSeason 2Ep. 34

Cyber news and Zero Trust insights for 8/24/2022

An article from Recorded Future points out new legislation in North Carolina and Florida that bars state backed organizations from paying ransomware attacks. Surely that means they have their stuff on lock and have no misconfigured assets, right? Google has an AI and privacy program that seem to be intersecting and could impact all of us, and Apple is dealing with those issues as well. How do we handle this problem? According to new research from Tessian "apathy" is the biggest vulnerability for...

Aug 25, 202232 minSeason 2Ep. 33

Selling Zero Trust at enterprise scale.

Do enterprises really buy Zero Trust? How should they think about a strategic approach to a problem. What about rip and replace? Are there no-go's when it comes to working to help an enterprise adopt ZT? Where do they budget for these endeavors? Is this only a big business problem? Those questions and more on this episode.

Aug 22, 202232 minSeason 2Ep. 32

Cyber news and Zero Trust insights for 8/17/2022

Okta's Zero Trust study. What does it say about the market and the growth of ZT? More cyber insurance shenanigans, why does this keep coming up? Should we really use this "service"? Water treatment plant is hacked in the UK, but is it really a clear case of compromise? What happens if you try and send someone shit in a box (literally) and the service is hacked? Is that a PII violation, or HIPPA or what? How many devices are out there that are possibly exploitable right now (hint, it's a lot!). T...

Aug 18, 202231 minSeason 2Ep. 31

How to sell into the channel the right way.

Truths about selling into the channel market with a real expert. How should your organization go about selling to a channel? Is the market different? How can you use those partners smarter? Do you have to sell twice? What shouldn't you do to leverage that channel? How can you optimize your channel approach and force multiply your sales efforts? Those points and more on this episode!

Aug 16, 202236 minSeason 2Ep. 31

Cyber news and Zero Trust insights for 8/10/2022

How hard is it to find "internal use only" files with a simple crafted search? How about spreadsheets with passwords and admin logins? What should we think about this whole Trello thing? What happened when I got phished (yup, they got me). Was it even a problem? Is the national emergency alert system really vulnerable? How big does the Zero Trust market get in the next 9 years? Those points and more on this episode!

Aug 11, 202229 minSeason 2Ep. 30

Cyber news and Zero Trust insights for 8/3/2022

Are there potential ways to attack a nuclear site via online misconfigurations? What about water as a vital national resource, can you attack a water supply system? Or a dam? Are containers inherently secure, and does that matter when they are part of a cluster? PE firms keep buying up the security market players, is there an anti-trust issue there? Is your threat intelligence service pulling in IOC's from US Cyber Command? Was the Pelosi visit part of a cyber attack? Does that matter and is it ...

Aug 04, 202234 minSeason 2Ep. 29

Cyber news and Zero Trust insights for 7/27/2022

Can I find privacy violations with Shodan ? What companies are using hackable unpatched scada systems that are misconfigured? Can we find osint on a company that has government contracts but is not secure ? Why is phishing training still a multi-billion dollar business when a variety of reports indicate that the numbers for that "defense" don't justify that expense? Is the government really as secure as we think they are? What about finding illegal violations of compliance mandates in ics system...

Jul 28, 202229 minSeason 2Ep. 28

Applying Zero Trust to Cloud Workloads and Kubernetes.

More ideas and thoughts around applying Zero Trust to cloud workloads and kubernetes. How should we think about the inherent vulnerabilities in these application development environments? How can you secure something that only exists for minutes at a time? Can you use open source solutions to approach the problems in this space? Do developers really need to be security engineers, and should security people know how to build apps to make things more secure? Check this one out and look for a video...

Jul 18, 202223 minSeason 2Ep. 27

Cyber news and Zero Trust insights for 7/6/2022

Marriott got hacked again, say what? Does it mean anything? What about their fines, didn't that teach them something? Can I find vulnerable government assets that are misconfigured and make 30 grand in bug bounties in half an hour? What about cloud resources that the DoD uses? A billion records are stolen in China, what's up with that? Those questions and more on this episode!

Jul 07, 202226 minSeason 2Ep. 26

What's up with the WAF market?

What's up with the WAF market? Talking about how we should and shouldn't use a WAF with an expert. Is the WAF the best way to address the problems we face? Where is this market going? What about the evolution of the WAF and it's place in history? And some hard questions with data to challenge why we might need to move to a new approach.

Jul 05, 202228 minSeason 2Ep. 25

Cyber news and Zero Trust insights for 6/29/2022

Can I find medical offices open to the internet? How hard would it be to hack them? Why is phishing training a problem for enterprises and businesses? Deepfakes and PII are being used for nefarious purposes, say what? Those points and more on this episode.

Jun 30, 202227 minSeason 2Ep. 24

Cyber news and Zero Trust insights for 6/15/2022

Thoughts on RSA2022. New research from Digital Shadows breaks down key areas of concern for us. I find some vulnerable databases on the web (some are "security vendors"...uh oh). We are still failing at the basics, and the password is eating our lunch, why is this still a problem? A great new blog from the S/R team at Forrester on the economy and the security market. Did AI just go sentient? Those thoughts and more on this episode!

Jun 16, 202230 minSeason 2Ep. 23

What is Collaboration Security?

Can an organization be compliant if they are using Slack to share files, passwords, and other critical and risky data? How does an agent-less system keep up with all of those short communications in collaboration applications? Is there more risk if we use modern applications that allow unlimited interaction and collaboration? What about business context, is there value to deciphering risk?

Jun 09, 202229 minSeason 2Ep. 21

Cyber news and Zero Trust insights for 6/1/2022

RSA is next week, I really need a beard trim. See y'all out there! Finding vulnerable hospital systems on the internet shouldn't be this easy, but here we go. Don't worry though they all are HIPPA compliant lol. How powerful is pimeyes at finding images of people on the internet and how does that affect privacy and security? Should you be worried? The new Microsoft Zero Day, how bad is it? What about hacking tractors and affecting the food supply, that can't be a thing right? DHS took seven year...

Jun 02, 202235 minSeason 2Ep. 21

Cyber news and Zero Trust insights for 5/25/2022

Can you find vulnerable stuff online from 2003? Surely not? Uh oh. Do we need a cyber moonshot to get past the failures we face in cyber security? Is there more evidence that legislation isn't dealing with reality, and that some of our leaders are missing the point? Using your phone SIM to do MFA, good or bad? Is DuckDuckGo really a "private" browser? Those points and more on this episode.

May 25, 202223 minSeason 2Ep. 20

Cyber news and Zero Trust insights for 5/18/2022

What matters more, targeting the "asset" (tractors) or the infrastructure for John Deere. Can you overthrow a government with a ransomware attack? Why are insurers changing their approach to cyber policies and why are they raising rates? What about the NSA guidance on best practices, is it really that different? Those questions and more on this one!

May 19, 202230 minSeason 2Ep. 19
For the best experience, listen in Metacast app for iOS or Android