2023 BH #1
View Show IndexSegments
1. Understanding the Edge Ecosystem in Healthcare and Beyond – Theresa Lanowitz – BH23 #1
As more organizations explore edge computing, understanding the entire ecosystem is paramount for bolstering security and resiliency, especially within a critical industry like healthcare. In this segment, Theresa Lanowitz, Head of Cybersecurity Evangelism at AT&T Business, will provide a deep dive into the state of edge computing—specifically, how it is revolutionizing healthcare. She will discuss key findings from the “2023 AT&T Cybersecurity Insights™ Report: Focus on Healthcare” and provide insight into how to prepare for securing the healthcare edge ecosystem.
Segment Resources: Get the AT&T Cybersecurity InsightsTM Report: Focus on Healthcare
This segment is sponsored by AT&T Cybersecurity. Visit https://securityweekly.com/attcybersecuritybh to learn more about them!
Guest
Theresa Lanowitz is the Chief Cybersecurity Evangelist at LevelBlue, a strategic alliance between AT&T and WillJam Ventures, that simplifies cybersecurity for the businesses fueling our global economy.
With a distinguished career in the technology industry, she has held influential roles at companies including Gartner, Borland, Taligent, and Sun Microsystems, significantly impacting application security and emerging technologies.
Theresa is a globally respected leader known for her deep and diverse experience in cybersecurity. Theresa frequently speaks at major industry conferences, sharing her insights on high tech trends, AI integration, and the evolving threat landscape.
Theresa holds a Bachelor of Science in Computer Science from the University of Pittsburgh, Pittsburgh, PA.
Host
2. The Immeasurable Benefits of Securing your Browser – Mike Fey – BH23 #1
The modern web browser is the single most commonly used application by enterprises worldwide. Its power, simplicity, and usability makes it an essential tool at work. And yet, the browser is not an enterprise application. It lacks the fundamental controls enterprises require to ensure proper security, visibility, and governance over critical apps and data.
As a result, we surround the browser with a massive security ecosystem in an attempt to manage the intersection between users, web applications, and the underlying data. In the process, our technology stack becomes complex, expensive, and fragile to maintain, while end users are left with a frustrating experience. All because the consumer browser was not designed with enterprise needs in mind. The question is: What if there was a browser designed exclusively for the enterprise?
This segment is sponsored by Island. Visit https://securityweekly.com/islandbh to learn more about them!
Guest
Michael Fey is Island’s co-founder and CEO. Fey was President and COO at Symantec. Prior to Symantec, he was President and COO of Blue Coat. Prior to that, Mike was EVP & GM for enterprise products at McAfee and CTO of Intel Security playing a pivotal role in Intel’s acquisition of McAfee for $7.7 billion in 2010.
Fey holds a degree in Engineering Physics and Mathematics from Embry-Riddle Aeronautical University and was co-author of Security Battleground: An Executive Field Manual, providing a playbook for security obligated executives coping with the new realities of cyber security responsibilities to the board.
Host
3. Successful Active Directory Modernization – Mickey Bresman – BH23 #1
With Active Directory (AD) exploited in 9 out of 10 cyberattacks, delaying AD modernization—especially after a merger or acquisition—can compound security risks. Security is the most compelling reason to migrate to a pristine AD forest or perform an AD forest or domain consolidation, but many organizations delay such projects due to the effort and planning they require. Security Weekly talks with Semperis CEO Mickey Bresman about the keys to a smooth and secure AD modernization strategy.
Segment Resources: Why AD Modernization Is Critical to Your Cybersecurity Program
ACTIVE DIRECTORY MIGRATION & CONSOLIDATION
Top 15 Steps to a Successful AD Migration
This segment is sponsored by Semperis. Visit https://securityweekly.com/semperisbh to learn more about them!
Guest
Mickey began his technical career in the Navy. Mickey’s comfort zone is on the front lines, helping organizations thwart and respond to cyberattacks. The long-time cybersecurity expert and entrepreneur has an extensive track record of driving revenue growth and scaling organizations across the globe.
Prior to co-founding Semperis, Mickey held the position of CTO at YouCC Technologies, a Microsoft Gold Partner integration company. As a cybersecurity thought leader, Mickey has been quoted or featured in many major publications, including Forbes, CNBC, and others. He has a B.A. in Technical Management and a Minor in Electronic Engineering.
Host
4. How Tenzir Security Data Pipelines enable the Modern Data Stack for Security – Matthias Vallentin – BH23 #1
Security organizations are increasingly adopting data lakes and cloud services as additions or alternatives to traditional SIEMs, but face challenges like scarcity of data engineering expertise and high data ingestion and cloud compute costs. To overcome these, a new security data stack is emerging, guided by models like SecDataOps and supported by solutions like Tenzir, purpose-built for security data use cases. In this segment, we will be talking about what is driving the heavy use of data in security operations, why that is stressing traditional security operations tools and processes, and what some early-adopter organizations are doing to meet these challenges.
Segment Resources:
Release Announcement: https://tenzir.com/press/tenzir-launches-security-data-pipeline-platform?utmsource=bhusa&utmcampaign=interview
Release Blog: https://docs.tenzir.com/blog/introducing-tenzir-security-data-pipelines?utmsource=bhusa&utmcampaign=interview
This segment is sponsored by Tenzir. Visit https://securityweekly.com/tenzirbh to learn more about them!
Guest
Building on his PhD in scalable network forensics from UC Berkeley, Matthias Vallentin founded Tenzir. As CEO, he leads Tenzir’s mission to transform security data operations. Matthias has extensive experience in building large-scale distributed systems, which he now applies to developing a data-centric security analytics platform for threat detection and response.
Host
5. Creating Order from Chaos – Managing Threats in a High-Performance Environment – Richard Yew – BH23 #1
The rapid growth of APIs used to build microservices in cloud-native architecture has left many enterprises in the dark when it comes to knowing where, how many, and what types of APIs they have. With multiple teams creating their own API endpoints without shared visibility or governance, exposed APIs can become a critical threat vector for hackers to exploit.
According to the Veracode State of Software Security 2023, 74% of applications scanned in 2023 were found to have a high-severity vulnerability.
Edgio will address how its new advanced API security capabilities give customers integrated and unparalleled protection at the edge, protecting APIs that are critical to modern businesses. Edgio delivers these services as part of its fully integrated holistic Web Application and API protection solutions giving customers the ability to respond to threats quicker. With its ML-powered API discovery abilities, enterprises can easily onboard API endpoints on the Edgio platform via OpenAPI standards, and enforce encryption, rate limiting, and other controls across identified APIs without tedious manual processes or third-party bolt-on solutions. This ensures consistent security practices and mitigates the risk of unauthorized access or data breaches from unknown or hidden APIs without adding additional latency or tools to manage. Edgio will wrap up the podcast by talking about how an edge-enabled holistic security platform can effectively reduce the attack surface, and improve the effectiveness of the defense while reducing the latency of critical web applications via its multi-layered defense approach. Edgio will conclude with how its security platform “shrinks the haystacks” so that organizations can better focus on delivering key business outcomes.
This segment is sponsored by Edgio. Visit https://securityweekly.com/edgiobh to learn more about them!
Guest
Richard Yew is Senior Director, Product Management for Edgio Security. With more than 10+ years of security technology experience worldwide, Richard is on top of the latest trends and technologies including WAAP, DDoS protection, bot management and enterprise security. Richard comes to Edgio from Yahoo-Edgecast and, prior to this, he was with Verizon Media Platform for a number of years. Richard also spent a brief time at Akamai before moving back to Verizon Digital Media Services as Head of Product for Security. He has led teams involving technical scope and developed strategic solutions for customers and prospects. He was educated at the Illinois Institute of Technology, and later at DePaul University, rising through a technical and engineering background to a managerial role.
Host
6. Think like a Threat Actor to Proactively Reduce your Attack Surface – Antonio Sanchez – BH23 #1
Offensive security is a proactive approach that identifies weaknesses using the same exploitation techniques as threat actors. It combines vulnerability management with pen testing and red team operations to “expose and close” vulnerabilities before they are exploited.
Segment Resources: Meet Fortra Your Cybersecurity Ally
Think Like a Threat Actor to Identify Your Cybersecurity Blind Spots
Offensive Security Product Bundles
This segment is sponsored by Fortra. Visit https://securityweekly.com/fortrabh to learn more about them!
Guest
Antonio Sanchez is Principal Evangelist at Fortra. As a subject matter expert for Fortra’s security portfolio, Antonio helps drive market recognition for the Fortra brand. He joined Fortra from Alert Logic in 2023, where he developed the messaging, positioning, and technical content for the managed detection and response (MDR) business. Alert Logic was acquired by Fortra in 2022.
Antonio has over 20 years in the IT industry focusing on cybersecurity, information management, and disaster recovery solutions to help organizations of all sizes manage threats and improve their security posture. He is a Certified Information Systems Security Professional (CISSP).
Antonio has held various product management, technical sales, and strategic marketing roles with Dell, Forcepoint, and Symantec. At the latter, he was responsible for developing and leading the Competitive Intelligence Program for the core security unit.
Antonio is a life-long learner and skilled at translating complex topics into simple terms. He is also a big supporter of education for underprivileged communities and an active mentor for people from minority groups who are interested in a career in cybersecurity.
Host
7. MDR Evolved – Randy Watkins – BH23 #1
Join us at Black Hat as we delve into the world of Managed Detection and Response (MDR) providers. In this podcast, we'll explore the critical factors to consider when selecting an MDR provider, uncover the common shortcomings in their services, and discuss the necessary evolution required to ensure ongoing effectiveness and enhanced value for customers. Get ready to unravel the complexities of MDR and gain insights into the future of this vital cybersecurity solution.
This segment is sponsored by Critical Start. Visit https://securityweekly.com/criticalstartbh to learn more about them!
Guest
Randy Watkins is the Chief Technology Officer (CTO) for Critical Start and an emerging thought-leader in the security industry. As CTO, Randy is responsible for designing and executing the company’s strategic technology initiatives, which includes defining the strategy and direction of Critical Start’s Managed Detection and Response (MDR) services delivered by the Zero-Trust Analytics Platform (ZTAP).
Previously, Randy served as Critical Start’s Director of Security Architecture, where he set the strategy for emerging vendor technologies, created the Defendable Network reference architecture, and set product direction for the company’s internally-developed Security Orchestration Automation and Response platform. Watkins was employee number five when he joined Critical Start in 2012.
Randy is a respected author and speaker on security trends and is well-versed in applying security technologies, in practical and meaningful ways, to improve risk management and security infrastructure for enterprise customers. He holds numerous security certifications in data analysis, data science, computer science, and leadership. Randy earned a bachelor’s degree in Information Systems Security and an associate degree in Computer Networking Systems, both from ITT Technical Institute.
In his free time, Randy continues to contribute to the security community through his consultancy to security product manufacturers to help them drive value to the customer through their solutions.
Host
8. LastPass & The Journey to Password[less] and Beyond – Karim Toubba – BH23 #1
Hear from Karim Toubba, CEO of LastPass, on LastPass' journey to passwordless, the importance of a passwordless world and why authentication is becoming more complex and facilitating the ease of authentication for users at work and at home.
This segment is sponsored by LastPass. Visit https://securityweekly.com/lastpassbh to learn more about them!
Guest
Karim Toubba is the Chief Executive Officer of LastPass, having joined the company in 2022. A cybersecurity industry veteran with over 25 years of experience within the sector, Karim brings proven leadership and innovation to the security market with a focus on creating products that solve real-world challenges yet form the foundation for lasting change.
Host
9. Zscaler ThreatLabz Report Tracks Trends and Impacts of Ransomware Attacks – Deepen Desai – BH23 #1
Ransomware-as-a-Service has contributed to a steady rise in sophisticated ransomware attacks. Ransomware authors are increasingly staying under the radar by launching encryption-less attacks which involve large volumes of data exfiltration. Organizations must move away from using legacy point products and instead migrate to a fully integrated zero trust platform that minimizes their attack surface, prevents compromise, reduces the blast radius in the event of a successful attack, and prevents data exfiltration.
Segment Resources: Zscaler 2023 Ransomware Report Shows a Nearly 40% Increase in Global Ransomware Attacks
2023 Phishing Report Reveals 47.2% Surge in Phishing Attacks Last Year
This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerbh to learn more about them!
Guest
As Chief Security Officer at Zscaler, Deepen Desai is responsible for running the global security research operations as well as working with the product group to ensure that the Zscaler platform and services are secure. Deepen has been actively involved in the field of cybersecurity for the past 19 years. Prior to joining Zscaler, he held security leadership roles at Dell SonicWALL.