2024 RSAC #2
View Show IndexSegments
1. One Big Problem SOC Teams can ACTUALLY Solve with AI – Jim McDonough – RSA24 #2
Artificial intelligence isn’t a magic wand… but could AI actually solve the alert triage problem every security operations center faces? In this interview with Jim McDonough from Intezer, we’ll talk about how 2023 was a tipping point for the maturity of AI tech, what these solutions actually bring to the table, how SOC teams in the real world are automating their processes with new AI tools, and why MSSPs are driving early adoption.
Segment Resources:
Growth of Autonomous SOC Platform Takes Off in 2023 - https://intezer.com/blog/incident-response/growth-of-autonomous-soc-platform-takes-off/
How Intezer's AI-Powered Autonomous SOC Platform Works - https://intezer.com/blog/incident-response/how-intezer-works/
How Artificial Intelligence Powers the Autonomous SOC Platform - https://intezer.com/blog/incident-response/artificial-intelligence-powered-autonomous-soc/
MSSPs moving fast to adopt AI for SOC automation - https://www.prnewswire.com/news-releases/intezer-launches-new-mssp-offering-for-ai-powered-autonomous-soc-platform-302091812.html
Intezer for SIEM Alert Triage - https://intezer.com/autonomous-soc-siem-triage-solution/
This segment is sponsored by Intezer. Visit https://securityweekly.com/intezerrsac to learn more about them!
Guest
Jim McDonough is the Vice President of Global Sales at Intezer, a leading provider of AI technology for automating security operations. Outside of work, you’re likely to catch him running in a marathon or on a trail outside Boston.
Host
2. How network transformation is driving demand for SASE and Zero Trust Edge services – Tim Roddy – RSA24 #2
In today's complex world, organizations are challenged to modernize their network while also improving their security posture to support digital transformation initiatives. Tim Roddy will talk about what is driving the need for network transformation efforts and why organizations are moving to IAM and SASE (also known as Zero Trust Edge) solutions to support these efforts. He’ll discuss the fast-growing SASE market and the demand for SASE delivered as a managed service due to talent shortages.
Segment Resources: https://resources.open-systems.com/wcc/eh/2470380/lp/4570505/open-systems-sase-experience-the-enabler-for-your-digital-journey
https://www.open-systems.com/sase_experience
This segment is sponsored by Open Systems. Visit https://securityweekly.com/opensystemsrsac to learn more about them!
Guest
As Vice President of Marketing for Open Systems, Tim is responsible for global marketing strategy, branding, messaging, communications, corporate website, and industry analyst relations. Tim brings over 25 years of go-to-market strategy, marketing, and partner expertise in cybersecurity, software, cloud, and SaaS, including 15 years of executive and leadership positions at iboss, Fidelis Cybersecurity, McAfee and Secure Computing. Tim earned an MBA from the Anderson School at UCLA and BS and MS degrees in Mechanical Engineering from the University of California, Berkeley
Host
3. From Vision to Reality: A CISO’s Perspective on Cybersecurity Marketplaces – Mike Lyborg – RSA24 #2
In this interview, join Swimlane Chief Information Security Officer, Mike Lyborg, and host Akira Brand as we discuss the value of cybersecurity marketplaces from a CISO perspective. Through insightful discussions, unpack the connection between outcomes-driven solutions and tangible business KPIs.
This segment is sponsored by Swimlane. Visit https://securityweekly.com/swimlanersac to learn more about them or visit Swimlane in person at RSA, booth #1957!
Guest
For over 15 years, Michael Lyborg has been a trusted leader in the information security space. He is known for his most recent experience as the Chief Information Security Officer (CISO) at Swimlane, the leader in automation for the entire security organization. During his time at Swimlane, he has also served as the Vice President of Global Consulting Services, and successfully led engineering teams and authored controls, policies, plans, and procedures for various compliance certifications, including SOC2, ISO 27001, and CMMC.
Previously, Michael made valuable contributions to Heska Corporation as the IT & Security Operations Manager. He has also served as an Operations Manager for the Marine Special Operations Command, following his service as Chief Instructor at the Marine Special Operations School and as an Infantry Leader of the 2nd Marine Division in the United States Marine Corps.
Host
4. How to revamp your cybersecurity in the middle of the chaos – Ricardo Villadiego – RSA24 #2
This interview examines the state and future of cybersecurity. Join the conversation as a cybersecurity expert delves into the failings of current defenses, the relentless tactics of attackers, and the imperative for innovative solutions. Explore how Lumu’s latest announcement delivers the innovation that cybersecurity analysts need to operate cybersecurity and meet the demands of the moment.
Segment Resources: Subscribe to the Lumu Blog: https://lumu.io/blog/ Lumu Autopilot: https://lumu.io/lumu-autopilot/
This segment is sponsored by Lumu Technologies. Visit https://securityweekly.com/lumursac to learn more about them!
Guest
Ricardo Villadiego (RV) is a seasoned entrepreneur and visionary technology leader focused on cybersecurity. His last 20 years have been spent in the quest of solving some of the most prevalent cybersecurity challenges organizations face. RV founded Easy Solutions, a global organization focused on the prevention and detection of electronic fraud. Subsequently, RV led the cybersecurity business unit at Cyxtera Technologies, where he developed a long-term vision and execution plan. His passion for technology and cybersecurity have triggered yet another venture, and he created Lumu Technologies with a clear objective: help the world measure compromise.
Along his career, Ricardo has held various leadership positions at IBM, Internet Security Systems and Unisys Corporation. He is an Electrical Engineer, avid reader, relentlessly curious, technology enthusiast, who currently lives in South Florida with his family.
Host
5. The Role of AI in Securing Software and Data Supply Chains – Josh Lemos – RSA24 #2
The cybersecurity landscape continues to transform, with a growing focus on mitigating supply chain vulnerabilities, enforcing data governance, and incorporating AI into security measures. This transformation promises to steer DevSecOps teams toward software development processes with efficiency and security at the forefront. Josh Lemos, Chief Information Security Officer at GitLab will discuss the role of AI in securing software and data supply chains and helping developers work more efficiently while creating more secure code.
This segment is sponsored by GitLab. For more information and to learn about how GitLab integrates security throughout the entire software development lifecycle please visit https://securityweekly.com/gitlabrsac!
Guest
Josh Lemos is the Chief Information Security Officer at GitLab Inc., where he brings 20 years of experience leading information security teams to his role. He is responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately protected, fortifying the Gitlab DevSecOps platform and ensuring the highest level of security for customers.
A talented security practitioner and technology leader, Josh is widely recognized for his strategic vision, his ability to drive growth and innovation, and his passion for building and empowering teams. He believes in technology’s potential to transform the world and the need to secure it against emerging threats. Josh has led security teams at numerous high-growth technology companies including ServiceNow, Cylance, and most recently Block (formerly known as Square).
Host
6. Bots are Taking Over the Internet: What That Means for Security – Erez Hasson – RSA24 #2
Bots accounted for nearly half of all internet traffic in 2023, with bad bot traffic rising for a fifth consecutive year. Malicious bot activity is a significant risk for businesses as it can result in account compromise, higher infrastructure and support costs, customer churn, and more. Tune in to learn about the security risks of these automated threats and what trends Imperva has monitored.
This segment is sponsored by Imperva. To learn more about the latest bot trends and how to protect your organization, download a copy of the 2024 Imperva Bad Bot Report at https://securityweekly.com/impervarsac!
Guest
Erez Hasson is an Application Security Specialist at Imperva. He oversees the go-to-market product strategy of Imperva Advanced Bot Protection, Imperva Account Takeover Protection, and Imperva Client-Side Protection. For nearly 10 years, Hasson has helped businesses understand how to protect their applications and websites from automated attacks and client-side threats. He holds a Bachelor of Arts degree from Sapir Academic College in Israel.
Host
7. Beyond Threats: The Shift to Proactive MDR – Randy Watkins – RSA24 #2
Traditional Managed Detection and Response (MDR) methods, centered on threat-based security, often miss the bigger picture of evolving cyber risks. This segment explores the shift towards a proactive, risk-based MDR approach, emphasizing the importance of anticipating and mitigating risks before they escalate into threats. We'll discuss the benefits of integrating risk management into security strategies and the key factors organizations should weigh when enhancing their cyber risk reduction efforts.
Segment Resources: https://www.criticalstart.com/proactive-reactive-cybersecurity-balancing-risk-management/
This segment is sponsored by Critical Start. For insights on blending proactive and reactive strategies seamlessly, visit criticalstart.com https://securityweekly.com/criticalstartrsac!
Guest
Randy Watkins is the Chief Technology Officer (CTO) for Critical Start and an emerging thought-leader in the security industry. As CTO, Randy is responsible for designing and executing the company’s strategic technology initiatives, which includes defining the strategy and direction of Critical Start’s Managed Detection and Response (MDR) services delivered by the Zero-Trust Analytics Platform (ZTAP).
Previously, Randy served as Critical Start’s Director of Security Architecture, where he set the strategy for emerging vendor technologies, created the Defendable Network reference architecture, and set product direction for the company’s internally-developed Security Orchestration Automation and Response platform. Watkins was employee number five when he joined Critical Start in 2012.
Randy is a respected author and speaker on security trends and is well-versed in applying security technologies, in practical and meaningful ways, to improve risk management and security infrastructure for enterprise customers. He holds numerous security certifications in data analysis, data science, computer science, and leadership. Randy earned a bachelor’s degree in Information Systems Security and an associate degree in Computer Networking Systems, both from ITT Technical Institute.
In his free time, Randy continues to contribute to the security community through his consultancy to security product manufacturers to help them drive value to the customer through their solutions.
Host
8. The evolving role of the CISO and the business of cyber – James Doggett – RSA24 #2
Semperis CISO Jim Doggett shares insights into the evolving role of the CISO. The daily onslaught of cyberattacks not only increases business risk, but also puts a company’s most important data at risk – data on the company, its employees, customers, and partners. Now, more than ever, the CISO is being asked to understand the business of cyber without being given much time to implement plans for protecting an organization’s infrastructure. There is a balance needed between being a technical and business leader, and Jim can share stories from his successful career to enlighten listeners.
Segment Resources:
Read: https://www.semperis.com/blog/5-itdr-steps-for-cisos/
Watch: https://www.semperis.com/resources/the-key-to-cyber-resilience-identity-system-defense/
This segment is sponsored by Semperis. Visit https://securityweekly.com/semperisrsac to learn more about them!
Guest
Jim is a veteran in information security and risk. The Ernst & Young retired partner helped build the company’s cybersecurity practice. He was CTRO at AIG, served as CSO and CTRO at Kaiser Permanente, and was JP Morgan Chase’s global leader of Information Risk and Resiliency, Treasury and Security Services.
Host
9. Zscaler Annual Phishing Report Finds a Near 60% Increase of Phishing Attacks in 2023 – Deepen Desai – RSA24 #2
The landscape of phishing attacks continues to rapidly evolve. In 2023, Zscaler ThreatLabz observed a year-over-year increase of 58.2% in global phishing attempts. This surge was characterized by emerging schemes, including voice phishing, recruitment scams, and browser-in-the-browser attacks.
Segment Resources: https://www.zscaler.com/campaign/threatlabz-phishing-report
This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerrsac to learn more about them!
Guest
As Chief Security Officer at Zscaler, Deepen Desai is responsible for running the global security research operations as well as working with the product group to ensure that the Zscaler platform and services are secure. Deepen has been actively involved in the field of cybersecurity for the past 19 years. Prior to joining Zscaler, he held security leadership roles at Dell SonicWALL.
Host
10. Business applications, they are the problem and the solution. – Chris Thomas – RSA24 #2
In this interview, we will discuss the network security challenges of business applications and how they can also be the solution. AlgoSec has spent over two decades tackling tough security issues in some of the world’s most complex networks. Now, they’re applying their expertise to hybrid networks—where customers are combining their on-premise resources along with multiple cloud providers.
Segment Resources: https://www.algosec.com/resources/
This segment is sponsored by AlgoSec. Visit https://securityweekly.com/algosecrsac to learn more about them!
Guest
Chris Thomas brings over 25 years of technology sales, partnerships and executive management experience. He has been part of the executive management teams which led four venture-backed companies to three successful acquisitions (Kontiki, Deja, Vidyo) and one $1.2B IPO (Intralinks).
Most recently, Chris was SVP, Worldwide Sales for Vidyo, an enterprise-grade unified communications platform for businesses and developers. Over a 10-year period Chris was responsible for Vidyo’s accelerated growth, Channel and Partners strategy and execution, and led Vidyo’s move to the cloud. Chris was also responsible for a vertical sales strategy and global expansion which led to Vidyo’s acquisition.
Prior to Vidyo, he was SVP of Worldwide Business Development at Intralinks, SVP Worldwide at Deja, President & CEO at Summitworks Technology, an IT solutions provider. Chris also held senior sales positions at Kontiki, Ziff Davis and IDG. He holds a BA in English with a minor in Business from The Catholic University of America.
Host
11. What is Unified SASE as a Service and Why Should You Care – Renuka Nadkarni – RSA24 #2
It’s not rocket science, it’s network security. And yet for many organizations, the road to securing employees and information often results in trade-offs to performance, agility, scalable services, and user experience. While first-generation SASE solutions promised companies a way out of this complexity, those early deployments failed to resolve the root causes of these growth pains--enter Unified SASE as a Service. Going beyond SASE learn what Unified SASE as a Service is and why you should care.
Segment Resources: https://www.aryaka.com/blog/aryaka-unified-sase-as-a-service-launch/
https://www.aryaka.com/docs/aryaka-unified-sase-as-a-service-overview.pdf
https://www.aryaka.com/press/aryaka-unified-sase-migration-acceleration-program/
https://www.aryaka.com/aryaka-security-services-complimentary-12-months-promotion/
https://www.aryaka.com/whitepaper/next-gen-sase/
https://www.aryaka.com/reports-and-guides/secure-network-transformation-report-2024/
This segment is sponsored by Aryaka. Visit https://securityweekly.com/aryakarsac to book a demo and learn more about them!
Guest
Renuka Nadkarni is a security veteran with 20 years of experience in launching startups and businesses within large publicly traded companies. She formerly held a CTO Security position at F5 Inc., where she was instrumental in driving their entry into the security market. Renuka holds an MS in Electrical Engineering from the University of Houston and a BS from the University of Mumbai.
Host
12. Identity is Under Attack: Navigating a New Era of “Verify More, Trust Less” – Andre Durand – RSA24 #2
Over the past 15 years, identity has evolved from a perimeter-based security model with clear boundaries to one that is fluid, flexible, and permeates every aspect of digital business. Simultaneously, AI has infiltrated every enterprise, becoming a double-edged sword for defenders, and fueling fraud attacks across every sector.
In this interview, Ping Identity CEO Andre Durand will walk through the evolution of the identity attack surface, and the opportunity decentralized identity has to dramatically improve both security and experience by putting users in control. He'll also discuss the increasing threats to individuals and businesses, given the influx of AI, and why we should consider this the era of “verify more, trust less.”
This segment is sponsored by Ping Identity. Visit https://securityweekly.com/pingrsac to learn more about them!
Guest
Andre Durand is the founder and CEO of Ping Identity, a leading provider of enterprise identity security serving over half of the Fortune 100 and 3 billion identities worldwide. Thoma Bravo acquired Ping in 2022 then combined with ForgeRock in 2023 to offer more choice and flexibility to address the varied needs of customers worldwide. Prior to founding Ping Identity in 2002, Durand founded Jabber which was acquired by Cisco in 2008.
Host
13. Harnessing the Power of Data and AI to Bridge Security Programs to the Business – Sivan Tehila – RSA24 #2
With new industry regulations, like the SEC’s Cybersecurity Disclosure Rules, there is an increasing demand on CISOs and security leaders to be able to quantify, communicate, and demonstrate how their cybersecurity programs and strategies are impacting the business. In this interview, Sivan Tehila, CEO and Founder of Onyxia Cyber, will discuss new advances in Cybersecurity Management and how CISOs and security leaders can harness the power of data intelligence, automation, and AI to proactively improve risk management, ensure organizational compliance, and align their security initiatives with business goals.
Segment Resources: https://rsac.vporoom.com/2024-04-30-Onyxia-Introduces-AI-to-Cybersecurity-Management-Platform-to-Power-Predictive-Security-Program-Management
This segment is sponsored by Onyxia. Visit https://securityweekly.com/onyxiarsac to learn more about them!
Guest
Sivan Tehila, CEO & Founder of Onyxia Cyber, is a cybersecurity expert and entrepreneur with more than 15 years of experience. Sivan started her career serving in Israel’s Intelligence Corps, initially as an Intelligence Officer, then CISO of the Research and Analysis Division, before becoming Head of the Information Security Department. Subsequently, Sivan consulted on cybersecurity for Israel’s critical infrastructures and defense industries, and later became Director of Solution Architecture for Perimeter 81.
Sivan is also the Program Director for the Masters in Cybersecurity program at NY’s Katz School of Science and Health, Yeshiva University. The course was ranked second in the US by Fortune magazine. An advocate of women in cybersecurity, she founded Cyber Ladies NYC and developed a unique cybersecurity program for Manhattan High School for Girls. Sivan has been recognized by SC Magazine as a ‘Woman to Watch’ and hailed as one of ‘25 Influential Women in IT Security’.
Host
14. Securing Health: Navigating Ransomware Threats in Partnership with an MSSP – Jim Broome – RSA24 #2
The interview will delve into the healthcare industry's tumultuous year in 2023, marked by 124 million breached health records across 725 hacking incidents (according to The HIPAA Journal). This interview will explore the critical role that MSSPs play in safeguarding health data and systems against potential security incidents, such as ransomware and business email compromise attacks. Jim Broome will share how to proactively prepare for an incident - including establishing a comprehensive incident response plan, outlining strategies for containment, restoration, and ongoing security operations, and how an MSSP can help.
Segment Resources: Tales from the Road Blog: An External Pen Test at a Healthcare Organization Reveals the Dangers of the Dark Web - https://www.directdefense.com/tales-from-the-road-an-external-pen-test-reveals-the-dangers-of-the-dark-web/
2023 Security Operations Threat Report: https://go.directdefense.com/2023-Security-Operations-Threat-Report
This segment is sponsored by DirectDefense. DirectDefense is offering a free reconnaissance and information gathering service to potential new clients. Visit https://securityweekly.com/directdefensersac to learn more!
Guest
Jim Broome is a seasoned IT/IS veteran with more than 20 years of information security experience in both consultative and operational roles. Jim leads DirectDefense, where he is responsible for the day-to-day management of the company, as well as providing guidance and direction for our service offerings.
Previously, Jim was a Director with AccuvantLABS where he managed, developed, and performed information security assessments for organizations across multiple industries. Prior to AccuvantLABS, Jim was a Principal Security Consultant with Internet Security Systems (ISS) and their X-Force penetration testing team.
Host
15. New Research from LevelBlue Reveals 2024 Cyber Resilience Trends – Theresa Lanowitz – RSA24 #2
In this segment, Theresa will unpack the complexities of cyber resilience, and dive into new research that examines dynamic computing. She’ll discuss how it merges IT and business operations, taps into data-driven decision-making, and redefines computing for the modern era.
This segment is sponsored by LevelBlue. Visit https://www.securityweekly.com/levelbluersac to download your complimentary copy of this groundbreaking report today!
This segment is sponsored by LevelBlue. Visit https://www.Securityweekly.com/levelbluersac to learn more about them!
Guest
Theresa Lanowitz is the Chief Cybersecurity Evangelist at LevelBlue, a strategic alliance between AT&T and WillJam Ventures, that simplifies cybersecurity for the businesses fueling our global economy.
With a distinguished career in the technology industry, she has held influential roles at companies including Gartner, Borland, Taligent, and Sun Microsystems, significantly impacting application security and emerging technologies.
Theresa is a globally respected leader known for her deep and diverse experience in cybersecurity. Theresa frequently speaks at major industry conferences, sharing her insights on high tech trends, AI integration, and the evolving threat landscape.
Theresa holds a Bachelor of Science in Computer Science from the University of Pittsburgh, Pittsburgh, PA.
Host
16. SBOMS for Evil: How Evil are they? – Larry Pesce – RSA24 #2
Software security is more critical than ever before, with cyber threats continuing to evolve. SBOMs (Software Bill of Materials) provide a comprehensive inventory of all components used in a software package, including their versions and dependencies. This transparency and visibility into the software supply chain enable organizations to make informed decisions about the security of their applications. Join us to learn how SBOMs can enhance penetration testing, by taking “SBOMs for Good,” and making them “SBOMs for Evil.”
Guest
Larry’s core specialties include hardware and wireless hacking, architectural review, and traditional pentesting. He also regularly gives talks at DEF CON, ShmooCon, DerbyCon, and various BSides. Larry holds the GAWN, GCISP, GCIH, GCFA, and ITIL certifications, and has been a certified instructor with SANS for 5 years, where he trains the industry in advanced wireless and Industrial Control Systems (ICS) hacking. Larry’s independent research for the show has led to interviews with the New York Times with MythBusters’ Adam Savage, hacking internet-connected marital aids on stage at DEFCON, and having his RFID implant cloned on stage at Shmoocon. Larry is also a Principal Instructor and Course Author for the SANS Institute for SEC617: Wireless Penetration Testing and Ethical Hacking and SEC556: IoT Penetration Testing. When not hard at work, Larry enjoys long walks on the beach weighed down by his ham radio, (DE KB1TNF), and thinking of ways to survive the impending zombie apocalypse.
Host
17. Making platformization beneficial to the cybersecurity industry – Maxime Lamothe-Brassard – RSA24 #2
Platformization could mean reduction in innovation, reduction in the ability to be flexible, and less competition. But it doesn't have to be this way. Like the IT industry, there are ways for the cybersecurity industry to platformize, but also to have this become a net benefit to the industry as a whole.
Segment Resources: Navigating the SecOps Cloud Platform webinar recording: https://www.youtube.com/watch?v=MbzvLX-W2KY
Recon Infosec Case Study: https://info.limacharlie.io/hubfs/Case%20Studies/LimaCharlieReconInfosecMSSPCase_Study.pdf
Blumira Case Study: https://info.limacharlie.io/hubfs/Case%20Studies/LimaCharlieBlumiraCase_Study.pdf
This segment is sponsored by LimaCharlie. Visit https://securityweekly.com/limacharliersac to get started for free!
Guest
Maxime began his career in cybersecurity working for the Canadian Security Establishment (CSE). CSE is Canada’s national cryptologic agency, providing the Government of Canada with information technology security and foreign
signals intelligence. As part of the Canadian Intelligence apparatus, Maxime worked in positions ranging from the development of cyber defense technologies, Counter Computer Network Exploitation, and Counter Intelligence.
After leaving the government, Maxime provided direct help to private and public organizations in matters of cyber defense. He was an early employee at Crowdstrike, then worked for Google where he eventually landed in Google X. Maxime left Google X – where he was a founding member of Chronicle Security – in 2018 to found LimaCharlie.