The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/The Get Cyber Resilient Show
The Get Cyber Resilient Show artwork

Ep 136 | The end of the cyber road with Dan McDermott, Gar O'Hara and Vinh Nguyen

The Get Cyber Resilient Show · 2023-06-27 · 33 min

0:00--:--

Key moments - from our scoring

Substance score

26 / 100

Five dimensions, 20 points each

Insight Density6 / 20
Originality5 / 20
Guest Caliber3 / 20
Specificity & Evidence8 / 20
Conversational Craft4 / 20

The Get Cyber Resilient Show concludes with a retrospective discussion on current cybersecurity challenges and progress. The hosts examine Australian Prime Minister Albo's recommendation to reboot devices weekly, which aligns with NSA guidance on clearing in-memory malware payloads - a simple hygiene practice most users neglect. Gar O'Hara emphasizes this addresses real threats while acknowledging it's not a complete solution. The episode then pivots to operational technology vulnerabilities, with Vinh Nguyen discussing FortiGuard's analysis of OT vendors including Motorola and Siemens, focusing on Schneider Electric's power meters exposing credentials in plaintext. This represents a critical infrastructure risk requiring security-by-design approaches rather than retrofitted patches. The appointment of Air Vice Marshal Darren Goldie as Australia's Cyber Security Coordinator signals governmental maturity on cyber strategy, backed by AU$100 million in federal allocation and Claire O'Neill's aggressive National Office of Cyber Security initiatives since February. Finally, Vin outlines PCI DSS 4.0 compliance changes, emphasizing DMARC implementation by March 31, 2024 as non-negotiable for payment card compliance.

Key takeaways

  • →Weekly device reboots clear in-memory malware payloads and align with NSA recommendations, requiring only one to two minutes downtime but offering meaningful security improvement for most users.
  • →Schneider Electric's plain-text credential transmission in power meters highlights systemic OT security failures requiring security-by-design approaches in critical infrastructure rather than retroactive patching.
  • →Australia's appointment of Air Vice Marshal Darren Goldie as Cyber Security Coordinator demonstrates how cyber has matured globally and signals serious government commitment backed by AU$100 million in federal funding.
  • →PCI DSS 4.0 requires proper DMARC implementation by March 31, 2024, necessitating dedicated project management and stakeholder coordination rather than simple activation.
  • →Success in national cyber strategy may paradoxically reduce political visibility if threats are effectively prevented, creating communication challenges for demonstrating security effectiveness.

Guests

Gar O'HaraVinh Nguyen

Topics in this episode

Operational Technology (OT) securityDevice rebooting for malware mitigationNSA cybersecurity guidanceSchneider Electric Iron and PowerLogix power metersFortiGuard security analysisMotorola and Siemens OT vulnerabilitiesCVSS vulnerability scoringCritical National Infrastructure (CNI)Australia Cyber Security CoordinatorNational Office of Cyber Security

Questions this episode answers

Should I really reboot my phone weekly for cybersecurity?

Yes - rebooting weekly kills in-memory malware and privacy-concerning processes that persist while the device is on, a practice aligned with NSA recommendations. The NSA specifically recommends this because modern mobile malware often operates from memory rather than requiring persistent installation, making regular reboots an effective and cost-free security practice.

What's the vulnerability with Schneider Electric power meters?

Schneider Electric's Iron and PowerLogix power meters transmit user IDs and passwords in plain text, exposing them to network sniffing attacks. FortiGuard's analysis found this vulnerability scored 8.8 on the CVSS scale due to the potential downstream effects on power grid networks and critical infrastructure.

Who is Australia's new Cyber Security Coordinator?

Air Vice Marshal Darren Goldie, a former head of the Royal Australian Air Force's VIP operations with 5,000 hours of flying experience, was appointed as Australia's first Cyber Security Coordinator. He leads the National Office of Cyber Security, established in February 2024 as part of Australia's comprehensive cybersecurity strategy backed by over AU$100 million in federal allocation.

What is the PCI DSS 4.0 compliance deadline?

Organizations must comply with PCI DSS 4.0 requirements by March 31, 2024. Key new requirements include anti-malware mechanisms, anti-phishing protections, and DMARC implementation for organizations handling payment card data.

Why is DMARC important for PCI DSS 4.0 compliance?

DMARC is now a mandatory requirement for PCI DSS compliance and requires proper implementation through project management and stakeholder coordination - it cannot simply be activated without organizational planning to protect domain reputation and prevent email spoofing attacks.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

6 / 20

The episode is a lightweight news-roundup/farewell hybrid. Technical points (in-memory malware persistence, OT availability-vs-confidentiality tradeoff, DMARC as a PCI DSS 4.0 requirement) are real but surface-level and sparsely developed; a significant portion of runtime is consumed by DJ jokes, self-congratulatory banter, and a lengthy farewell sequence that delivers zero operator value.

a lot of the malware, a lot of the stuff that you're going to see on a mobile device, especially these days, really what they're trying to get into is like in memory payloads
it's integral that we actually put in security in the first place rather than having to try passion car work away backwards later on

Originality

5 / 20

Almost every take is recycled industry common sense: reboot clears in-memory malware (lifted from NSA guidance), OT was designed for availability not confidentiality, phishing is still the top threat, use a password manager. The one mildly contrarian observation - that political success in cyber looks like nothing happening, which is electorally useless - is interesting but underdeveloped.

good is nothing happens. And that doesn't work in politics. You know, politics is like the scary people are coming and, you know, everyone should, should be afraid all the time.
Probably no surprise. The headline news is that uh, phishing was the most common type of identity related incident in 2022. So you know, I don't even feel like that needs a fanfare

Guest Caliber

3 / 20

There are no external guests whatsoever in this episode; the three participants are the show's own hosts, who present as content-marketing and generalist cybersecurity commentators at Mimecast rather than senior operators who have built or defended infrastructure at scale. The farewell format makes practitioner depth irrelevant by design.

I'm Dan McDermott, your host for one last time, and I'm joined by our resident cybersecurity experts, Garrett o' Hara and Vinyuan
episode one came, uh, out on the 14th of October 2019. Would you believe that long ago? Um, yeah, it was. Myself and Gregor did the sort of air quotes news

Specificity & Evidence

8 / 20

The episode does pepper in real data points - 529 surveyed professionals, CVSS 8.8 for the Schneider vulnerability, 56 vulnerabilities in the OT Icefall report, a March 31 2024 PCI DSS deadline, ~AUD40M over four years for the National Office of Cyber Security - but these figures are name-dropped rather than analysed, and no actionable context is built around them.

they've sort of interviewed a bunch of people, 529 to be very specific, IT security and identity professionals from relatively large orgs. So those with over a thousand employees
this one, particularly like, has a CVSS vulnerability of 8.8 out of 10

Conversational Craft

4 / 20

Every question is a soft toss ('Gar, can this really help our cyber resiliency?', 'Vin, what do we need to be aware of here?') with no follow-up challenges, no probing for mechanism or evidence, and no productive disagreement anywhere in the episode. The farewell segment replaces any remaining craft with mutual appreciation.

Gar, uh, can this really help our cyber resiliency?
Fin, what do we need to be aware of here?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A60%
  • Speaker B24%
  • Speaker C15%

Most-used words

cyber33security14first13back12device11important11thanks11part10world9phone9away9sure9feel9cybersecurity8reboot8episode7

Episode notes

The end of the cyber road. This week we say goodbye to the Get Cyber Resilient show. Dan, Gar and Vinh take one last look behind the cyber news. In this episode, we start with Australian Prime Minister Anthony Albanese’s answer to cyber resiliency; we then jump over to the world of OT and how Schneider Power metres have been disclosing that they transmit user IDs and passwords in plain text. In our last deep dive, we review the appointment of Australia’s first Cyber Security Coordinator. As always, we wrap with a lightning round of the latest breaches and vulnerabilities to make the headlines. A big thank you goes out to everyone behind the show and also you, our listeners that have either been with us from the beginning or only found us recently; we appreciate every one of you for your support over the years.

Full transcript

33 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Welcome to episode 136 and final. Yes, that's right. This is our final ever episode of the Get Cyber Resilience show. We will do thank yous and farewells at the end, but first we have our final behind the Cyber News edition of the show to record. I'm Dan McDermott, your host for one last time, and I'm joined by our resident cybersecurity experts, Garrett o' Hara and Vinyuan. Today we will begin by looking into the advice from Australian Prime Minister Albo that turning it off and back on again is a good idea for cyber. Our next story is from the world of OT or operational technology, whereby Schneider power meters have disclosed that they transmit user IDs and passwords in plain text. And, uh, our final deep dive review is how, after announcing the position of Cyber Security Coordinator for Australia four months ago, Claire o' Neill has finally announced the first appointment to the role. And at the end, we will wrap up with a quick review and latest breaches and vulnerabilities to make the headlines. Let's kick off with Elbow's advice. Gar, uh, can this really help our cyber resiliency?

Speaker A: Yeah, yeah, we're. Look, the world needs to just accept that the, the absolute best advice you could give anybody for any is turn it off and turn it back on again. Uh, so Elbow's on the money. Apart from spinning decks, he's now giving out the, uh, the best of cyber advice. Look, it actually makes sense and I know it sort of, it probably sounds like something that a, uh, like a non cyber person is going to say, um, but it actually does hold weight. The NSA over in the US actually made the same recommendation a little while back. Um, and the thinking there is that a lot of the malware, a lot of the stuff that you're going to see on a mobile device, especially these days, really what they're trying to get into is like in memory payloads, so not really necessarily getting you to like, do the old school stuff of clicking m on things and, um, you know, compromising your device that way. So the idea here is that if you reboot your device that anything that's sitting in memory, all those processes that kind of run in the background, you know, listening to your voice, gathering data, uh, you know, doing whatever the malware or privacy concerning, um, operations that may be in place when you, when you reboot your phone, it kills all of those. And then when the device restarts, in theory, it kind of restarts clean with those not running anymore. So, like, not for a Second, is this going to solve, you know, all of your cyber concerns when it comes to using a mobile device? But if you think about most people these days, they tend to just leave their phone on all the time. You know, it's one of those things that, uh, like, it's, it's your alarm clock, it's your camera, it's your music device, it's like kind of everything. So people tend to just kind of have them on all the time. And like, I think many people these days, the first thing they reach for in the morning is their mobile phone. You know, see WhatsApp them overnight and all of that kind of good stuff. So people weirdly don't even have the patience to let a phone reboot over, uh, overnight. So like the, you know, the recommendation here is once a week in reality, like, I don't know, why wouldn't you just, just before you fall asleep, just have the thing reboot and then when you wake up in the morning, it's kind of clean, fresh, and in theory doesn't have any of the, any of the malware kind of running in the background. It actually goes to, um. And Dan, you and I have been chatting about this, uh, on, just on a different thread around the, you know, the concern of deep fakes and all of that stuff and how much airtime that's getting. Yeah, we need to be worried about it. But for most people, like, they really should be thinking about just kind of patching and doing the basics. Um, doing the basics, right, get good email security in place, blah, blah, blah. And this is one of those ones where this is such a simple thing to do, like literally reboot your phone. You don't have to install anything, it doesn't cost anything other than maybe an irritation of, you know, not having your phone available for what isn't probably one or two minutes. Um, but, you know, really simple, really easy and good advice from Alo.

Speaker B: Well, it does sound like to me that, like, if this prime minister gig thing doesn't work out so well, you know, he's at least got to fall back onto it help desk. So, um, it's good that, you know, elbow's giving yourself options, which is great.

Speaker A: Yeah, I think so, like, if it's not cyber, I, I mean, he's going to be running out of time with spinning, uh, the decks and is, uh, it Marilla, wherever he kind of does the guest DJing stuff. And um, you know, between that and the cyber stuff, he's definitely not going to be shy of a salary. But look, it Is funny but it actually points to a couple of things that I think are kind of good and kind of important. First one being that it's kind of hard, harder I should say to do kind of persistent threats. Um, same on, on computers like the, you know, first thing you want to do is compromise a uh, machine. Like you can do that quite often, not easily but easier than you can um, have a persistent presence on a machine. Sort of getting that persistence can be tricky. So whether that's Registry edits or we talked a little while about getting to the kind of ring zero stuff phones have the same thing. So like Apple, uh, Google, I think they're really the only two phone uh, manufacturers that people kind of pay attention to these days. But they're very good at kind of ringing the sort of core operating ah, system stuff away from applications. You know that idea of siloing things away so that if you do compromise an application or an application's doing something funky, it's kind of operating in a like pseudo sandboxy environment on your phone. So in theory like when you reboot it then it goes away unless you start the app again then you're probably going to be all right. So um, I think it's important. I um, think the mobile devices these days, let's be honest, are kind of a wild west. The amount of we, we actually spoke about this, right. I think it was years ago. Remember the. Wasn't there an app where you could put your photo up there and it basically made you into what you'd look like when you were 70?

Speaker C: Yeah.

Speaker A: And you know people just went bonkers and everyone sending the photos of what they looked like when they were 70 not realizing that in the background the, the app is basically just harvesting a ton of information and you know, kind of flicking that up to um, you know, central server. So the idea of mobile device security, I mean there's things to think about there. I would say, um, not just the reboot your device but being very mindful of what you install. Especially if it's one of those fun thing where you upload your photo or you answer a bunch of questions including what's your dog's name? What's your address? Um, with this sort of reward being a profile of you. But actually what you've just done is given away all your personally ah, identifiable information. Um, I think yeah, it's just part of that. Overall be careful of your mobile devices. They become such a huge source of information. Most people are doing their banking on their shopping on there. They're Talking to their friends, emails on there. Everything's on your mobile device. So um, yeah, you definitely want to be, I suppose, very, very careful of um, what you install and how you use them.

Speaker B: Well, uh, an excellent piece of cyber hygiene advice, ah, for the first story there and making sure that it's something that we all should be able to do and do easily. Um, and hopefully it does uh, create that help and that resilience that we're looking for. Vin. Our next story is from the world of operational technology or ot, where Schneider power meters have disclosed that they're transmitting user IDs and passwords in plain text. Now I'm no expert but this does not sound like cyber best practice to me.

Speaker C: It, uh, it's definitely not, um, it's a recurring theme that we generally see with um, OT as well operational technology. It's something that you know, we see continuous failings for honestly. And it's the importance that we need to kind of direct our focus to, which is security by design. Right. And with operational technology what we generally see is they need to work with critical uh, infrastructure and all these things that might have been 30, 50 years ago. So it's very hard to necessarily patch, not to this stage. So for us it's integral that we actually put in security in the first place rather than having to try passion car work away backwards later on. But really focusing on today's story, it was based off um, for Scout, a uh, global, ah, cybersecurity company who did a massive analysis, um, on all these different ot, uh vendors. Uh, we're looking at likes of Motorola, Simmons and part of a Wider report called OT Icefall found 56 different vulnerabilities and this one, particularly with Schneider Electric Iron and powerlogix power meters was the last one to be brought up. Um, the reason being, I think what Schneider Electric wanted was time to kind of let their customers know of this prior so they could then start to patch and work their way through the vulnerability first before announcing it out. But yeah, it's just one of those things where we've seen it time and time again. I think there was a recent interview guy that you did that was very OT related as well. But you know how many times you have to talk about this, um, before we actually then start to change the way that we actually Release things like OT IoT devices to make sure they are secure by design when released out to the general public.

Speaker A: Yeah, it's a, it is a consistent and ongoing conversation. Hey, like from the IoT stuff we talked about ages ago, even with Dmitri Alberovich, when we were talking about the supply into governments and how, you know, they needed to start to certify almost or vet those devices before they kind of got released into those operating environments. For that exact reason, Vin. Um, because they're used places that are potentially really, really, uh, really sensitive. I think the thing we're struggling with as societies is like that the OT stuff was designed generally with kind of resilience in mind. So like, the dam would work, the power stayed on. That was the absolute, you know, in the, the CIA triad. It was definitely all about availability and you know, not so much of a consideration to confidentiality.

Speaker B: Ah.

Speaker A: Or integrity. Um, because like, that's the reality. Like, if you think about when many of these things were built decades ago, we like, there was no GC or podcast. People were, People weren't talking about, uh, it would have been on vinyl. Imagine that we had the, you know, every episode released on a R8 track. Um, but it's that, right? It's, it's decades ago where availability was the absolute, as it should have been, um, requirements. So you build all these amazing systems for resilience, but then, you know, we're kind of retrofitting and trying to figure out now how do we do the uh, cybersecurity part of it. So, yeah, definitely sympathize with, um. Yeah, with, with, you know, Belinda Knoll, as you said, Vin, from. From Sakal, who talked about this at length. And just those champions at the OT World who are, you know, they're not in their 20s, they're probably more likely in their 50s and 60s and incredibly talented, knowledgeable people who are now dealing with a brand new, brand new way of thinking about something, um, that they've been doing their whole lives. So yeah, it's a huge challenge, but a really important one.

Speaker C: Yeah, definitely. I mean, this one's particularly like, has a CVSS vulnerability of 8.8 out of 10. Right. Like, I know it's not security for the sake of security. Like we're talking about, like you mentioned guard dams and like, you know, like fundamentally critical infrastructure. And what happens when there's a downstream effect where because of this and you know, you're able to change settings within a, uh, particular device or the firmware of the device, and it just kind of trickles down to the stage where it affects something like a grid network.

Speaker B: Right.

Speaker C: Worst case scenario, there's a blackout. And then from the blackout there could also be humanizer effect as well. Livelihood, like, who's to blame after that um, I'm assuming that's why it's got such a high vulnerability rating because there is potentially big effects that can come down the line there. But it's just one of those things where it's super important that we get this right.

Speaker B: Indeed, in this day and age of critical national infrastructure and really the heightened, I guess, intensity around making sure that we, we have resilience in all of those systems, you know, something that, you know is exposing usernames and passwords, um, and it can be detected by simply sniffing on a network is obviously those things that need to be, you know, shut down quickly blocked out and making sure that they are taken care of because there is already so much, you know, I guess, uh, scrutiny, um, and potential vulnerability that exists that we've got to be able to again, get rid of sort of those baseline things and like you said, been really secure by design out of the gates to ensure that we are meeting those standards and obligations that we all know that we need to hit in terms of national security, um, national critical infrastructure. Sorry.

Speaker C: Absolutely.

Speaker B: Excellent. Moving on to our final deep dive review is how. After announcing the position of Cybersecurity Coordinator for Australia four months ago, Claire her Neal has now announced the first appointment to the role. Ga. Congratulations. I knew it was only a matter of time that you'd be recognized.

Speaker A: Well, I mean that's, that's the reason the part is going away, right? I just won't have time now given all I'll be so busy.

Speaker B: Exactly. That's right.

Speaker A: I tell you what, Dan, um, the thing I took away from this story, you know, as I, as I close in on 50, um, you know, there's a few things that I've come to realize. I'm never going to be in a good band or even a bad band, and I'm never gonna have a title, uh, as cool as the, the this new person's, uh, titles have been in the past. The guy's name is Darren Goldie. So he's the former head of the Royal Australian Air Force's VIP operations and he's the current air commander, so air, uh, vice Marshal. And you know, every, every sort of part of me this morning I was kind of reading through this stuff in detail for this episode. You just think, yeah, haven't really done anything with my life. You look at all the, the times he spent 5,000 hours in the air flying. He's been all over the world in, in sort of hot zones and he's ridiculously good looking. His photo and the, in the media as you guys look at it looks like something from A Few Good Men. You know, he's got his military dress, dress, ah, uniform on. Um, but just the real deal. I definitely, I've never felt like such a failure as a dude on a Monday morning. It's the last thing you need. Um, he's a two star general so he's going to be kind of jumping in on, on this role which is a huge one. It's interesting to me, like it really points to how mature cyber has gotten globally, you know, and it's probably because this is the last episode. I'm sort of thinking back to when we started talking to people, like when we started the pod. Like this was, this just wasn't something that would have happened right. There wasn't so much of a focus on cyber. A role like this just wouldn't have existed. Um, so it, it's sort of heartening. You know, it's kind of a positive thing to think about. Um, he's come out and he's basically called the Challenge dar, which you know, I think is probably stating the obvious because he's got a huge task ahead of him like straddling multiple organizations, you know, civilian and military, and tying that all together and executing on uh, just a massively complex but massively important uh, you know, mission for, of a better expression. Um, which is, you know, it's part of the Australian um, cybersecurity strategy. And then Claire o' Neill has been very aggressive with, with that and her language around that. And I think, you know, there's, there's a general sense of kind of applause. You see that on LinkedIn. You see that in conversations with uh, peers in the cyber industry around her kind of vigor. And yes, she's a politician, but it does seem like she's actually kind of getting stuff done rather than, you know, a lot of talk and then nothing really happening. Like it does feel like there's movement here. Like in February, uh, this year she set up the, the National Office of Cyber Security which is, you know, first step. Um, there's money going towards that. So nearly 40 million over 44 years. Which like, it's not a huge amount but it's significant. Like it's, you know, it kind of makes you sit up and pay attention. And that's out of, you know, it's over 100 mil from federal allocations that went to multiple departments over five years as part of that strategy to kind of uplift our cybersecurity in Australia. But like, applause to Claire o'. Neill. For kind of getting, getting movement and getting stuff done and realizing how important this stuff is and raising the visibility of cyber, like that's the reality. She's done a really good job of being very vocal about how important this stuff is. And I think you look at the appointment of somebody like Darren Goldie, clearly incredible leader, um, has worked in basically the sort of response capabilities of Australia for something as complex as our Air Force. And there's some really good analogies to cyber because you think of the opening scenes of Top Gun where the bogeys are coming in and it's all quick response and coordinating a bunch of different people and doing it very quickly under high pressure situations. So somebody with that experience, that literally battle hardened experience, how awesome is that to have somebody to step into a role where, you know, when you think about what we're talking about here is um, the kind of attack that, you know, back to what Vin was talking about and you down around CNI like starts to hobble infrastructure and CNI and you know, really kind of meaningful impact to Australia. Like I feel better having somebody, um, like you know, him in, in that role and sort of able to handle the truth, you know, um, of this situation. That's a little, Few Good Men uh, reference there for, for those of a certain age, they may not get that, but I think I'm excited.

Speaker B: And you stole my punchline as well. G. I was going to say all of this sounds like you just can't handle the truth. So. But uh, it uh, it is an amazing appointment like you say. And I think it shows sort of where cyber sits, you know, in that world. You know, we've spoken a lot through obviously the Ukraine conflict and you know, how cyber versus the kinetic response, um, how the coordination of the two or lack thereof at times has you know, really impacted the way, you know, an actual war has run as well. Um, so it definitely has highlighted that sort of crossover between military and civilian life and what that means, um, on so many levels, um, across the nation. So yeah, fantastic appointment. Um, one that will be interesting to see what they're able to, you know, really show that they're able to achieve, um, and deliver. Because as you say, highly complex, complicated world and one where it's not always obvious to be able to show, you know, what success looks like. As we all know in cyber, you know, it's like, it's like nothing happened. That's a good thing. Like, you know, it's like how do you sort of go about sort of telling everybody it's okay, nothing happened. That's actually great. So, um, be fantastic to see how this, uh, rolls out over time.

Speaker A: You've. You got me worried again, because I think you've just raised something that's pretty important when it comes to the politics of this stuff, which is that's the problem here is that good is nothing happens. And that doesn't work in politics. You know, politics is like the scary people are coming and, you know, everyone should, should be afraid all the time. That's how you kind of often get things done or get budgets or get votes. You know, just kind of lie to people if you need to. Um, but to your point, Dan, like, if he, if they're really successful, like politically, is it one of those things that actually is just. People will forget how much of a worry cyber should be because actually they've done a good job. So hopefully that's not how this pans out.

Speaker B: No, it's going to be a difficult one. I think the communication, um, of what success is, is actually, you know, a really important part of the role and what they do because otherwise it can fall into that trap. Right. And so definitely one to see where this plays out to, um, and to see what that success actually looks like. And hopefully it is, you know, smooth, calm waters for us all, which is uh, really what we're looking for.

Speaker A: Well, he's just going to come out, you know that, right. Goldie's first thing will be come out and say, just reboot your phone and we can all just sit back and kind of relax.

Speaker B: Turn it off and on again.

Speaker A: Yeah.

Speaker B: Let's now, uh, wrap up with a quick review of the latest breaches and vulnerabilities. To make the headlines, the first news item is a public service announcement to ensure compliance with the updates to the PCI DSS 4.0 requirements. Vin, what do people need to be aware of here?

Speaker C: There is actually quite a bit, um, in this new edition of PCI 4.0. Uh, I think, fortunately we do have a little bit to go. We have till March 31, 2024 to get all our ducks in line. Um, but there's quite a bit there and there's a lot of it is focused on actually protecting your technology. There's a lot around anti malware mechanisms, anti phishing mechanisms. I think for me, um, the big one being dmarc. I know it's a project and then a technology or security that some organizations have thought of implementing. But the fact is, if you need to be compliant with PCI dss, you're going to have to have DMARC as well. Um, it's not one of those technologies that you can just say cool, you know, I've got dmar, I'm just going to turn on. It needs to be done properly, it needs to have a project sitting behind, it needs to have stakeholders and ownership. But it's one of those things that needs to be done now. So if you're an organization that falls under PCI DSS and you've been looking at a means to get DMARC m up and running across the Org to protect your domain, protect your brand reputation, then now's the time to do it.

Speaker B: Indeed, as more of these, you know, compliance and regulation items continue to come through, it's essential that everybody stays ahead of them. Right. And while they do give some leeway and time to get ready, that time goes very quickly. And so you've got to be able to prioritize your projects, um, get your funding in order, get your resourcing done, get your team skilled up. There's a lot to each one of these things that puts extra pressure back onto the cyber professionals. Um, and so everybody needs to be aware of it and be able to start planning for those things because there'll be multiple of these running at any one time. And so being able to do those in parallel and get up to speed and make sure that you're meeting those standards and meeting those regulations is going to continue to be critical um, as cyber continues to evolve. Next is insights from the latest cyber research report. This one is from the Identity Defined Security alliance or IDSA gar what have the IDSA found?

Speaker A: Probably no surprise. The headline news is that uh, phishing was the most common type of identity related incident in 2022. So you know, I don't even feel like that needs a fanfare or an intro drum roll I think you know, surprise, surprise. It seems to be the, the thing

Speaker B: that's been consistent amazing research that sounds

Speaker A: like yeah, fishing, you know, you know the, the uh, hits the news most years where they go through. I can't remember what it's called but it's the award for like the, the most redundant research in universities, you know where they, you know there's been $50,000 donated to some university to figure out the best scone recipe or you know things where you look really he looks what? Um, but look in a way like I think sometimes kind of doing a level set or you know kind of a benchmarking of like what is going on. Like sometimes it can change and maybe it's not the worst thing to actually go and kind of figure this stuff out. But um, yeah, look, they obviously have gone ahead and they've sort of interviewed a bunch of people, 529 to be very specific, IT security and identity professionals from relatively large orgs. So those with over a thousand employees and what you're looking at is basically phishing, spear phishing and things like phishing, smishing incidents. So um, yeah, again no real surprise. I think the point here is that obviously um, when it comes to identity related stuff then that's obviously something these days we want to um, sit up and kind of pay attention to because I think identity has become such an important part of um, cybersecurity, the management of, and the securing of identities and what those identities let you do given the kind of prevalence of cloud. And really it's the, it's the key for everything. So I think the click on the link and you'll get malware. Yeah, obviously that's a, no one wants that. It's scary. But I think the click on a link or get fished and give away your credentials, I think that's the one that has many cyber security professionals um, very worried because um, look, so many of the stories we've talked about in the last kind of year have related back to you know, something happened, some came in on an email, creds got pinched and you know, away they go. So um, it might seem kind of redundant and like surely you're pointing out the obvious but actually you know, sometimes it's good to just like I say, level set. Are we still where we thought we were? And in this case the survey seems to indicate that we are.

Speaker B: Yeah. And the cybercriminals never stop.

Speaker C: Right.

Speaker B: And that's the thing. And they're always going to, they're going to keep trying and they're going to try even everything from you know, the old sophisticated attacks as everything seems to be these days, to the most basic. Right. And they're always just going to be unrelenting in, in their pursuit. So we've got to make sure that we're just as unrelenting in the protection that is provided um, by organizations as well.

Speaker A: And use a password manager. Like if you're like just in your personal life, you know, it's, it's funny, I don't know, I'll keep saying it but um, like your corporation's probably managing your ID and has some good stuff in place. But um, use a password manager. Um, these days, the personal and the private. Sorry, the personal and the corporate, they overlap so much that those two things affect each other dramatically. So please use a password manager.

Speaker B: Always a good reminder. G and finally Apple have released patches for exploited zero day bugs. Fin, what do we need to be aware of here?

Speaker C: You need to turn it off and on again? No, no, it's um, it's a little bit more complicated than that. Um, which I think you know, going back to the story from earlier from Guard so you can turn it on and off again but there are some things that it doesn't just work for right. If you look at leaked credentials like doesn't matter how many times you turn on and off again, you have leaked credentials. So like little steps in security are always helpful. And Apple itself has pushed three uh, fixes uh for these zero day vulnerabilities. Now I've got the CVEs here it is 324-343-2435 which are being used. They campaign, they drop spyware on Target devices and 32434 being a kernel bug as well. So essentially it can uh, execute arbitrary code with kernel privileges. Um, I think the scary thing here is it actually allows a victim to be infected by malicious imessage without user interaction. Uh, that's always scary when you can have someone essentially affect your machine without you having the not need to do anything yourself. Um, but this is more of a heads up. I mean these fixes have been pushed out by Apple already but just kind of shows that even the likes of Apple like with any new patching or new features being released there will be vulnerabilities. And yeah, it's a constant kind of push and pull thing where yeah, we release something out that's new, there's going to be something that is missed and we have to kind of patch it up afterwards as well. So um, for Apple users it's already been pushed out but yeah just a heads up there, there are a few vulnerabilities out there um, that could be quite dangerous um, if they weren't patch four already.

Speaker B: Indeed. Always a good reminder and making sure that all of these things in terms of all the basics and the fundamentals are in place because that creates great cyber uh, hygiene overall. Well thank you Gar and Vin, appreciate your insights not only today but over the past nearly four years that the show has run for. I'd like to take a few moments to do a few shout outs to the people behind the scenes who have made our get Cyber m resilient journey possible. Firstly, a big thank you to Alex Bender and Pino Sorrow, who are fearless global marketing leaders that believed in our vision to create a community of cybersecurity professionals in APAC and provided a voice and dialogue to the ever evolving risk landscape and empowered us to fill a content gap in the regional market from global vendors. Next is the team at our agency greenhat, who have been there from day one and throughout every step with us to create a world class content marketing program. A big thank you to Andrew Tusha, Sean, Tiny Matt and especially Dave Stalker, uh, and the many others who have helped us along the way. Specifically for the podcast, I'd like to thank Gregor, Jeffrey and Gara Hara Gregory came to me in late 2019 and said, why don't we add a podcast on the Get Cyber Resilient platform? And I said, sure, sounds good. How do we do that? So Grego teamed up with GAR and from humble beginnings started recording the Get Cyber Resilient show podcast. Amazing innovation and an incredible dedication and expert interviewing from GAR to secure so many amazing guests who have been incredibly generous with their time and insights shared. Which leads me to our final thank you and that is to you, our incredible audience. With hundreds of thousands of articles read and over 1.5 million minutes spent listening to us, I'm very proud to have been able to serve you and provide valuable input into your cyber journey. Gar, I know you have a few thank yous as well.

Speaker A: I definitely do. And some of them overlap, I suppose. Um, episode one came, uh, out on the 14th of October 2019. Would you believe that long ago? Um, yeah, it was. Myself and Gregor did the sort of air quotes news and then we had Mitch Owen join us, um, on that first episode way, way, way back. So we've, we've definitely come a long way. I think when we were starting it, I think we were probably going to be proud of getting 10 episodes out. And um, yeah, I kind of look back in those days and they were kind of to your point, Dan. Like they were just kind of, let's just go, let's do it. Um, we'd sit in, um, in a room with a Zoom handy Pro recorder and just like have conversations with guests. And um, I'm sure the Green Hat team are cringing at the sound quality. Matt Spraggs, uh, probably hated me for a while, but the point was the content, not the quality of the audio. At the start we were just mostly interested in how to get really, really good guests, local expertise and their insights. And you know, my thanks go to them in such a big way. Um, I Feel incredibly, incredibly lucky to have spent the time with so many of those people. Just literally getting to ask them the questions that I, I always assumed that if I wanted to ask them, then other people out there would want to hear the answers. And hopefully we got that right. Um, obviously then, you know, big thanks to. To Gregor, as he said, and. And Bradley Singh, who was involved in the news episodes for a while, obviously Tvan the team at Green Hat. For me, you know, I think the most, um, interactions I had were with the. Even David Stalker and Matt Sprague. So those guys. But the whole team at Green had massive thanks to those. Huge thanks to all the guests, thanks to the listeners, as you said. Like, um, it's. It's an incredible thing to. To be somewhere and you guys know this story. I don't think I've ever mentioned it on the pod, but it was at a conference in New Zealand, um, last year, and getting my name badge from the, you know, they. They put the name badges in the desk and you pick yours up kind of thing. And, um, the guy behind me on the queue goes, oh, you gar. From the. Did you get serial podcast? I'm like, yep. And it was just such a cool, cool moment when, you know, the three of us are shouting off into the void and you kind of hope people are listening. And then you hear those, Those things where you're at a conference and somebody comes over and says, look, awesome show. Thanks so much for putting it out. And, um, you know, when Prescott Pim got that photo on, uh, LinkedIn, you know, he's sitting in a cab on his way somewhere and, um, you know, was kind enough to kind of give the shout out. So, like, it, it matters. At least it mattered to me. Um, I feel very proud of what we did and a massive thanks to you, Dan, because the easiest thing in the world is to say no to things. And like, that's the, you know, the. I think unfortunately, too often the default is the, you know, let's just say no, we can save some money. You know, it's less work. But actually the sort of brave and cool thing to do is like, yeah, let's. Let's just do it and, you know, we'll. We'll figure it out as we go. So massive, Massive thanks to you for the, uh, the belief. Well, actually don't know if it was belief at the start or maybe it was just a let's just see how we go. But whatever. I think the belief grew over the years and, um, you know, as the listenership grew. And, you know, it was something that I think was having a quite a lovely impact. And as you say, it was local, um, which has always kind of felt important. You know, there's a. There's a cyber community that's very strong in this region that, um, it was lovely to. Yeah, it's gonna get to be a part of. So, yeah, massive thanks. Um, there's obviously other podcasts out there. You know, fishy business. The Moncast pod is awesome. Definitely worth listen. KB cast Chris Breen's Dark Mode with, uh, Gabe, uh, Marzano, and, um, Ben Sullivan. Like, there's some really good ones out there, so plenty to still listen to. But, um, yeah, just massive thanks to everyone and feel really weird. I don't feel sad. I feel like we did an awesome thing, so I feel quite proud of it all.

Speaker B: Yeah, indeed. Well, for your cyber insights, Please jump onto mimecast.com and check out the APAC resources page for one last time. Thanks for listening, and as always, stay safe.

Speaker A: Sam.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Securing the Industrial Frontier with Frenos | The Pair Program Ep76The Pair Program · on Operational Technology (OT) security

More from The Get Cyber Resilient Show

All episodes →
  • Ep 135 | OT and Cyber Security with Belinda Noel, Chief Growth Officer at Secolve
  • Ep 134 | Behind the Cyber News: 13th of June 2023
  • Ep 133 | Filling the cyber talent gap with Matt Wilcox, Founder and CEO of FifthDomain
  • Ep 132 | Behind the Cyber News: 16th of May 2023
  • Ep 131 | Behind the Cyber News: 2nd of May 2023
Explore the best B2B Ops podcasts →
All The Get Cyber Resilient Show episodes →