Episode 3: Crowdstrike, North Korean Spies, and CISO Scapegoats episode artwork

EPISODE · Aug 12, 2024 · 1H 10M

Episode 3: Crowdstrike, North Korean Spies, and CISO Scapegoats

from Distilled Security Podcast · host Justin Leapline, Joe Wynn, and Rick Yocum

Episode 3 of the Distilled Security Podcast is here!Join us this week as we jump into: CrowdStrike Incident Analysis: A deep dive into a recent mishap by CrowdStrike that led to significant financial losses and operational disruptions, including 5.4 billion in estimated losses.Vendor Accountability: Exploring the legal and financial repercussions of security vendor failures.Business Continuity Planning: The importance of preparing for security vendor failures, including considering alternate vendors and the complexities of implementing such strategies.Kernel-Level Security Risks: A discussion surrounding kernel-level operations in security software, focusing on the controversy between CrowdStrike and SentinelOne.Manual Workarounds and Legacy Systems: The challenges of maintaining business operations during security incidents.Ransomware Recovery vs. Vendor Failures: Comparing ransomware attacks' impact and recovery processes with security vendor-induced failures.Password Management Vulnerabilities: The risks associated with dependency on password management systems like Thycotic/Delinea and LastPass, and the potential fallout if these systems experience downtime.BSides Pittsburgh Recap: the biggest BSidesPGH event yet. Hear the notes and highlights from the conference.North Korean Spy Hired By KnowBe4: Hear how a spy for N. Korea got by the defenses of KnowBe4, how they caught them, and steps they implemented to avoid this in the future.CISOs as Scapegoats: Are CISOs being pegged as scapegoats unfairly?LinksCrowdstrike Incident - https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/SentinelOne Response to Crowdstrike - SentinalOne on Crowdstrike Outage - https://www.crn.com/news/security/2024/sentinelone-ceo-on-crowdstrike-outage-not-just-an-honest-mistakeBSidesPGH - https://www.bsidespgh.com/TRISS - https://www.threeriversinfosec.com/KnowBe4 // N. Korean Spy - https://blog.knowbe4.com/cyberheistnews-vol-14-31-how-the-whole-world-now-knows-about-fake-north-korean-it-workersCISO as Scapegoats - https://www.thestack.technology/were-becoming-scapegoats-how-have-cisos-responded-to-sec-cyber-risk-disclosure-rules/SpiritsRabbit Hole Cavehill // Four Grain Tripple Malt - https://www.rabbitholedistillery.com/pages/cavehill/HostsJustin Leapline - https://www.linkedin.com/in/justinleapline/Joe Wynn - https://www.linkedin.com/in/wynnjoe/Rick Yocum - https://www.linkedin.com/in/rickyocum/Connect with UsWebsite: https://distilledsecuritypodcast.comTwitter: @DisSecPodEmail: [email protected]

Episode metadata supplied by the publisher feed · Published Aug 12, 2024

Embed this episode

Ready to play

Episode 3: Crowdstrike, North Korean Spies, and CISO Scapegoats

0:00 1:10:52

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Distilled Security Podcast?

This episode is 1 hour and 10 minutes long.

When was this Distilled Security Podcast episode published?

This episode was published on August 12, 2024.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Distilled Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!