Risky Business-logo

Risky Business

Technology Podcasts

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

Location:

United States

Description:

Risky Business is a weekly information security podcast featuring news and in-depth interviews with industry luminaries. Launched in February 2007, Risky Business is a must-listen digest for information security pros. With a running time of approximately 50-60 minutes, Risky Business is pacy; a security podcast without the waffle.

Language:

English


Episodes

Risky Business #652 -- Cyber Partisans take down Belarusian rail systems

1/25/2022
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: This week’s show is brought to you by Trail of Bits, the security engineering firm. Dan Guido joins us this week week to talk about zkdocs, a bunch of documentation Trail of Bits put together to provide guidance on how to implement some of these newfangled concepts – like zero knowledge proofs – that are popular in blockchain and cryptoland. Links to everything that we discussed are below and you...

Duration:01:02:02

Risky Business #651 -- Russia's ransomware diplomacy

1/18/2022
On this week’s show Patrick Gray, Adam Boileau and Dmitri Alperovitch discuss the week’s security news, including: This week’s sponsor interview is with HD Moore, the founder of Rumble. We’re talking through what how he and his team helped customers respond to the log4j drama. They quickly added the capability to scan customer’s environments for log4shell-affected tech. When asset discovery meets rapid vuln response! Links to everything that we discussed are below and you can follow...

Duration:00:59:55

Risky Biz Soap Box: Rolling your own threat intelligence with Steve Miller

1/13/2022
In this edition of the soap box we’re chatting with Steve Miller, a senior researcher at Stairwell. Steve has a long history doing this sort of stuff. He worked inside various bits of the US government doing cyber things, and also spent a decent chunk of his career at Mandiant. His new employer, Stairwell, makes a platform that collects information about all files present in your environment and let’s you do some fancy stuff with that information. You’ll hear a little bit more about what...

Duration:00:41:43

Risky Business #650 -- USG drops Russia advisory as Ukraine tensions mount

1/11/2022
On this week’s show Patrick Gray, Katie Nickels and Joe Slowik discuss the week’s security news, including: This week’s show is brought to you by Okta. Marc Rogers is the executive director of cybersecurity there and he’s joining us this week to talk about the log4j bug and some adjacent issues. He’s working on a paper with IST about the bug and what it all means, and he’s joining us this week to talk about why the log4j drama was different. Links to everything that we discussed are below...

Duration:00:56:58

Risky Business #649 -- Java being a fiddly mess saves the day

1/4/2022
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: This week’s show is brought to you by Airlock Digital. They make allowlisting software that has mostly been used in Windows environments, but as you’re about to hear they’ve now got a very, very nice solution for the bigger Linux distros, and their Mac agent is going to be launched in a few weeks. Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if...

Duration:00:13:00

Risky Biz Soap Box: Why Thinkst gives its honeytoken tech away for free

12/9/2021
This isn’t the normal weekly news episode of the show, if you’re looking for the regular weekly Risky Business podcast, scroll one back in your podcast feed. This is a Soap Box edition, a wholly sponsored podcast brought to you in this instance by Thinkst Canary. For those who don’t know, Thinkst makes hardware and virtual honeypots you can put on your network or into your cloud environments – they’ll start chirping if an attacker interacts with them. They’re a low cost and extremely...

Duration:00:47:31

Risky Business #648 -- Adios, 2021, it's been real

12/7/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: This week’s sponsor interview is with Andrew Morris of Greynoise. Greynoise has a bunch of sensors out there on the Internets, so they can tell you when and IP that’s hitting you is also hitting everyone else. If you work in a SOC, you know this is very useful. Greynoise has just signed a $30m deal with the US Department of Defense. As Andrew will explain in just a moment, this means if you work...

Duration:01:08:50

Risky Business #647 -- Israel slashes cyber exports, Interpol takes down 1,000 crooks

11/30/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: This week’s sponsor interview is with Ryan Kalember of Proofpoint. He’s the EVP of Cybersecurity Strategy there and he’s joining me this week to talk about how investment activity in cybersecurity is basically leaving everyone who isn’t a mega enterprise behind. Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing. Show...

Duration:00:58:47

Risky Business #646 -- Apple cracks the sads, sues NSO Group

11/23/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: This week’s show is sponsored by VMRay. We’ll be chatting with one of VMRay’s customers in this week’s sponsor interview. Jim Byrge works on the CSIRT team at Valvoline, and he’ll be along to talk about how they replaced their ageing, in-house developed SOAR platform with commercial tools. It was still harder than it should be in 2021, but they got there in the end. Links to everything that we...

Duration:00:57:41

Risky Biz Soap Box: DDoS crews will hit you creatively

11/18/2021
In this edition of the Risky Biz Soap Box podcast we chat with Sean Leach, the Chief Product Architect at Fastly, about the history and current status of the DDoS ecosystem. Despite never really making money for criminals, DDoS attacks are still a problem. CDNs have soaked up a lot of the problem, so DDoS crews are getting creative. Do you know where you’re vulnerable? Show notes Bouncy castle boss James Balcombe ordered arson hits on rivals

Duration:00:41:18

Risky Business #645 -- How Israel used NSO to make friends in low places

11/16/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: This week’s sponsor interview is with HD Moore. He’s the founder of Rumble, the network asset discovery scanner, and he’s joining us to talk about some new tricks he’s added to the product, like integrations with cloud service APIs and external discovery products like Censys. Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing. Show...

Duration:01:04:05

Risky Biz Soap Box: Linux is an infrastructure OS, act accordingly

11/11/2021
In this edition of the Soap Box podcast we’re chatting with Jake King. Jake is a co-founder of Cmd Security, a Linux Security startup that was recently acquired by Elastic. Cmd’s technology basically started out as a control and visibility tool for Linux systems that could restrict user actions. But over time, the product evolved to be more detection and response oriented. In this interview we talk to Jake about why Cmd wound up where it is, product wise, and what customers can expect now...

Duration:00:28:07

Risky Business #644 -- USA sanctions NSO Group, hits REvil

11/9/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: We’ll hear from Corelight’s CISO Bernard Brantley in this week’s sponsor interview. We’re talking about how attackers think in graphs and defenders think in lists.. Microsoft’s John Lambert wrote a post about that back in 2015, and Bernard joins the show this week to talk about why it’s just as relevant as ever. Stick around for that one. Links to everything that we discussed are below and you...

Duration:01:02:53

Risky Business #643 -- Iranian fuel stations targeted, PNG ransomware a regional security risk

11/2/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: We’ll be hearing from Senetas CEO Andrew Wilson in this week’s sponsor interview. He’s joining us to talk about how the global semiconductor shortage is making him a very, very sad panda. Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if that’s your thing. Show notes Iran says sweeping cyberattack took down gas stations across country Cyber...

Duration:01:13:01

Risky Biz Feature Interview: Mark Dowd on the 0day market and future of exceptional access

10/18/2021
This feature podcast was made possible by the Hewlett Foundation’s Cyber Initiative. The foundation has given us grant funding to produce this podcast series, which is designed to educate policymakers in cybersecurity so they can make better decisions. In this edition you’ll hear an interview I recorded with Mark Dowd. Mark is a world-renowned security researcher who, some years ago, co-founded a company called Azimuth Security. As you’ll hear, the original plan was to provide security...

Duration:00:56:24

Risky Business #642 -- Brits, Dutch and Aussies embrace Hounds Doctrine

10/12/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: Jonathan Reiber is this week’s sponsor guest. He’s senior director of cybersecurity at AttackIQ and he’s joining us to talk through the US Government’s executive order on Zero Trust. Jonathan says it is actually born of a realisation the US Government needs to do something differently, that the old approaches aren’t working. Links to everything that we discussed are below and you can follow...

Duration:00:59:07

Risky Business #641 -- Lawsuit: Ransomware contributed to baby's death

10/5/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: Nucleus co-founder Scott Kuffer is this week’s sponsor guest and the topic is actually a bit hilarious. They’ve found a killer use case that customers are clamouring for: Being able to map vulnerabilities to org groups within your enterprise so you can see who’s slacking off when it comes to patching. Links to everything that we discussed are below and you can follow Patrick or Adam on Twitter if...

Duration:01:00:37

Risky Biz Snake Oilers: Mike Wiacek launches Stairwell, Red Canary on modern MDR and Datadog pitches full stack monitoring

9/30/2021
In this edition of the Snake Oilers we’ll hear pitches from three vendors: Links to everything we talked about are in the show notes. [CORRECTION: Mike Wiacek was originally described as the co-founder of VirusTotal in this podcast. He is in fact a co-founder of Chronicle Security, which absorbed VirusTotal after launching.] Show notes Home - StairwellYour Cybersecurity Ally - Red CanaryDatadog - Security and Analytics Monitoring Platform

Duration:00:44:37

Risky Business #640 -- Huh. The CIA really was out to neck Assange

9/28/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: This week’s show is brought to you by Material Security. Material’s co-founder Ryan Noon will be along in this week’s sponsor interview to talk about smarter ways to do email retention and destruction. They have a product that interfaces with your mail provider’s API – whether you’re on Google Workspace or O365 – to do things like archive and redact email, and they’re finding their customers are...

Duration:01:08:04

Risky Business #639 -- USA's ransomware non-policy fails to meet its unstated objective

9/21/2021
On this week’s show Patrick Gray and Adam Boileau discuss the week’s security news, including: Brett Winterford is this week’s sponsor guest. These days Brett is a senior director of cybersecurity strategy at Okta, but the reason you might recognise his name is because he took a year off working for vendors to be our newsletter author – he was the founding editor of the Seriously Risky Business newsletter. He’ll be along to talk about legacy auth and why vendors should have deprecation...

Duration:01:03:19