Risky Business Podcast

Analysis and news podcasts published weekly

Risky Biz Soap Box: While you're watching a quiet one a noisy one will kill you

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

In this Soap Box edition of the show Proofpoint’s EVP of Cybersecurity Strategy Ryan Kalember joins host Patrick Gray to talk about why some security spending is just misguided. So much of the infosec industry is geared towards protecting organisations against exotic threats when, really, the trifecta of ransomware, BEC and staff being careless with data are the thing that will sink them.

Risky Biz Soap Box: While you're watching a quiet one a noisy one will kill you
0:00 / 0:00

Risky Business #664 -- The Spanish Prime Minister got Pegasus'd

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Spanish PM’s phone infected by Pegasus
  • Microsoft drops Ukraine research report
  • We can’t make heads or tails out of the FBI’s transparency report
  • France hit with coordinated fibre sabotage campaign
  • Why Musk’s algorithm pledge is meaningless
  • Much, much more

This week’s sponsor interview is with ExtraHop Networks’ CEO Patrick Dennis. He’s joining us this week to talk about how you can turn “Shield’s Up!” advice into something actionable.

Risky Business #664 -- The Spanish Prime Minister got Pegasus'd
0:00 / 0:00

Risky Business #663 -- Israel cracks down on spyware exports

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Israel Ministry of Defence is denying a lot of spyware export licences
  • Private detective in New York pleads guilty over BellTroX shenanigans
  • Scammers enrol stolen credit cards into Apple Pay
  • The Blackcat ransomware crew is very active right now
  • VirusTotal shells lol
  • Much, much more

This week’s sponsor interview is with Okta’s Brett Winterford, who talks in detail about the company’s brush with the Lapsus$ hacking crew. It’s unusual for a sponsor interview to be a must listen, but here we are.

Risky Business #663 -- Israel cracks down on spyware exports
0:00 / 0:00

Risky Business #662 -- It's a bad month to be an electricity grid

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray, Adam Boileau and Dmitri Alperovitch discuss the week’s security news, including:

  • Ukraine foils Russian ICS hack
  • US Government burns someone’s ICS toolkit
  • China gets all up in India’s energy gridz
  • The Heroku/Hithub/Travis CI story is very confusing
  • US DOJ removes GRU malware from Watchguard boxes under Rule 41
  • North Korea behind $540m crypto hack
  • Much, much more

This week’s sponsor interview is with Scott Kuffer, co-founder of Nucleus Security, and Jared Semrau of Mandiant. They’ll be joining us to talk about how you can now plug Mandiant data into the Nucleus vulnerability scan aggregator.

Risky Business #662 -- It's a bad month to be an electricity grid
0:00 / 0:00

Snake Oilers: Vectra, Google Security and SecureStack

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Snake Oilers isn’t our regular weekly podcast, it’s a wholly sponsored series we do at Risky.Biz where vendors come on to the show to pitch their products to you, the Risky Business listener. To be clear – everyone you hear in one of these editions, paid to be here.

We’ll hear from three vendors in this edition of Snake Oilers:

  • Kevin Kennedy from Vectra talks about the company’s cloud native detection – it crunches stuff like CloudTrail and AzureAD logs and correlates it with network event information
  • Paul McCarty from SecureStack on its software composition analysis and “SBOM plus” tool
  • Google Cloud’s Anton Chuvakin talks about cloud-based SIEMs like Chronicle
Snake Oilers: Vectra, Google Security and SecureStack
0:00 / 0:00

Risky Business #661 -- Viasat hack details firm up

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Why Spring4Shell isn’t all hype
  • How Viasat actually got owned
  • Russian war crimes likely extend to coercing sysadmis
  • Why lighter fluid and a box of matches is more effective than cyber in Belarus
  • Much, much more

This week’s sponsor interview is with Bernard Brantley, Corelight’s Chief Information Security Officer.

Corelight makes a network sensor you can use to plug in to your SIEM, among other things. It’s based on Zeek, the open source network sensor that Corelight maintains. Corelight is absolutely the industry standard for this sort of thing.

And they’ve just become the standard for something else, too: Microsoft Defender for IoT can now accept Corelight feeds. Bernard fills us in on that.

Risky Business #661 -- Viasat hack details firm up
0:00 / 0:00

Snake Oilers: PentesterLab, AttackForge and Sysdig

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Snake Oilers isn’t our regular weekly podcast, it’s a wholly sponsored series we do at Risky.Biz where vendors come on to the show to pitch their products to you, the Risky Business listener. To be clear – everyone you hear in one of these editions, paid to be here.

We’ll hear from three vendors in this edition of Snake Oilers:

  • Upskill your testers and developers with PentesterLab for US$20 a month
  • Manage penetration tests and reporting with AttackForge
  • How Sysdig can help herd your container cats (vuln management and detection for container environments)
Snake Oilers: PentesterLab, AttackForge and Sysdig
0:00 / 0:00

Risky Business #660 -- Lapsus$ arrests, latest on Okta incident

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Some arrests of suspected Lapsus$ members in the UK
  • Why the Okta incident is probably a fizzer
  • Four FSB officers indicted over Triton/Trisis malware
  • Kim Zetter interviewed Intrusion Truth
  • Australian government to upsize ASD
  • Wave bye bye to Finfisher
  • Much, much more

This week’s sponsor interview is with Mike Wiacek from Stairwell.

Stairwell makes a product that catalogues the files in your environment and lets you slice and dice that data. That makes threat hunting pretty easy and Mike is joining the show this week to talk about why organisations of all stripes should be doing threat hunting.

Risky Business #660 -- Lapsus$ arrests, latest on Okta incident
0:00 / 0:00

Risky Biz Soap Box: Why allowlisting is ready for prime time

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Airlock Digital co-founders Daniel Schell and Dave Cottingham join host Patrick Gray to talk about:

  • What an effective allowlisting program looks like
  • Why the third party allowlisting industry failed the first time
  • What you can achieve with Microsoft tooling versus specialist tools
  • How much effort is involved to do this right
Risky Biz Soap Box: Why allowlisting is ready for prime time
0:00 / 0:00

Risky Business #659 -- Okta and Microsoft meet LAPSUS$

Presented by

Patrick Gray
Patrick Gray

CEO and Publisher

Adam Boileau
Adam Boileau

Technology Editor

On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including:

  • Okta’s somewhat awful comms around its LAPSUS$ incident
  • Inside Microsoft’s brush with the same group
  • How Elon Musk’s Starlink service is being used to drop bombs on Russian tanks
  • US, UK governments warn of impending Russian cyberdoom
  • Much, much more…

This week’s sponsor interview is with Paul Lanzi, co-founder of Remediant. Paul joins the show this week to talk about cyber insurance. It’s a topic that has come up a lot for us lately – ransomware has borderline sunk the current cyber insurance model as payments ballooned and payouts made a lot of insurers adjust premiums to the. But all is not lost – Paul says this blowup means the insurance industry is actually adapting and could wind up being a driver of better security practices.

Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing.

Risky Business #659 -- Okta and Microsoft meet LAPSUS$
0:00 / 0:00