The Southern Fried Security Podcast
Join Andy Willingham, Martin Fisher,Steve Ragan, Yvette Johnson, and Joseph Sokoly as they discuss information security, news, and interview interesting people. Get in the discussion at www.southernfriedsecurity.com.

For the first time we can think of it's just Yvette and Martin on this episode.  The two of them talk about what to think about and what you might do if you run into some extra budget at the end of the year.  Do you invest in shiny? What about services? Some training might be nice?  Or so you score points with the team down the hall?

Direct download: SFS_Podcast_-_Episode_185.mp3
Category:general -- posted at: 6:46am EDT

We interview Nick Selby (@nselby) about a recent blog post where he had a less than optimal experience with a managed security service provider.

 

https://nselby.github.io/When-Security-Monitoring-Provides-Neither-Security-Nor-Monitoring/

 

 

Direct download: SFS_Podcast_-_Episode_184.mp3
Category:general -- posted at: 8:29pm EDT

Martin, Andy, and Steve talk about third party risk programs in light of breaches at Target, Banner Health, and other unfortunate souls.

Direct download: SFS_Podcast_-_Episode_183.mp3
Category:general -- posted at: 7:19am EDT

Joseph is on sabbatical but the rest of the crew talks about how infosec professionals should focus on their problems and how to effectively interact with "the business".

 

 

Direct download: SFS_Podcast_-_Ep182.mp3
Category:general -- posted at: 9:28am EDT

Guillaume’s last visit to the show: Episode 167
Last year’s WWDC episode

WWDC 2016 Security Rumors and Wishes
Possible Touch ID changes
Touch ID for the Mac?

Wishlist
Encrypted iCloud Backups
Permissions and Pairing
Granular Location Access
Better Public Wi-Fi, VPN And SSL/TLS Handling

Reduced Annoyances and Increased Security on iOS

Find us on Twitter:
@gepeto42
@SFSPodcast
@armorguy
@jsokoly
@andywillingham
@SteveD3
@jetsetyvette

And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. And if you’ve found our Facebook page, we’re sorry. We’re going to fix that up.

 

Direct download: SFS_Podcast_Ep_-_181.mp3
Category:podcasts -- posted at: 10:35pm EDT

This evening, Martin sat down with Patrick Heim from Dropbox. Enjoy the interview, and the gang will be back next episode.

Direct download: SFS_Podcast_Ep_-_180.mp3
Category:podcasts -- posted at: 9:00pm EDT

The 2016 DBIR
OSVDB Thoughts on the DBIR
Analyzing the 2016 Verizon Data Breach Investigations Report » Digital Shadows
The DBIR’s ‘Forest’ of Exploit Signatures – Trail of Bits Blog
Response to Kenna Security’s Explanation of the DBIR Vulnerability Mess | OSVDB

Find us on Twitter:
@SFSPodcast
@armorguy
@jsokoly
@andywillingham
@SteveD3
@jetsetyvette

And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter.

 

Direct download: SFS_Podcast_Ep_-_179.mp3
Category:podcasts -- posted at: 8:36pm EDT

This evening, Martin, Steve, and Joseph talk about overhyped vulnerabilities, and how that affects communication with the business.

Badlock’s Site
Sadlock
Hyping vulnerabilities is no longer helping application security awareness | TechCrunch

Find us on Twitter:
@SFSPodcast
@armorguy
@jsokoly
@andywillingham
@SteveD3
@jetsetyvette

And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. And if you’ve found our Facebook page, we’re sorry. We’re going to fix that up.

Direct download: SFS_Podcast_Ep_-_178.mp3
Category:podcasts -- posted at: 8:45pm EDT

Tonight, Martin and Joseph sit down and talk about communicating cautionary tales without turning them into FUD.

US-CERT advisory on ransomware

Find us on Twitter:
@SFSPodcast
@armorguy
@jsokoly
@andywillingham
@SteveD3
@jetsetyvette

And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. And if you’ve found our Facebook page, we’re sorry. We’re going to fix that up.

Direct download: SFS_Podcast_Ep_-_177.mp3
Category:podcasts -- posted at: 8:40pm EDT

InfoSec programs without money are like cereal but no milk, peanut butter but no jelly, Milli but no Vanilli… (Get over it, I’m old - Martin)

Martin is doing a talk on “The ABCs of Getting Your InfoSec Program Funded” and we’re going to discuss how this works in the real world at all of the different levels.

Find us on Twitter:
@SFSPodcast
@armorguy
@jsokoly
@andywillingham
@SteveD3
@jetsetyvette

And if you have any feedback, questions, or comments, drop us a comment or find us at @SFSPodcast on Twitter. And if you’ve found our Facebook page, we’re sorry. We’re going to fix that up.

Direct download: SFS_Podcast_Ep_-_176.mp3
Category:podcasts -- posted at: 10:06pm EDT