Listen "Is Security a Benefit or a Feature?"
Episode Synopsis
I recently came across a tweet that was shared during the Infosecurity Maganzine Conference in Boston, “Security is a benefit, but not always a feature.” Why? You can spend a lot of money and still be hacked or not spend a dime and not be hacked.
How did the Inside Out Security Show panel react? Here's what Mike Buckbee, Kilian Englert and Alan Cizenski had to say:
Buckbee: It’s all tradeoffs. It’s all a bet. If you go into a casino and putting money down…While it’s true you can spend a lot of money and still get hacked, it’s less likely than you spend nothing. Or not even so much spend, in terms of money, but in terms of effort. You spend the effort and time to make secure systems….so you’re trying to play the odds.
Englert: We can write it up as a true-ism…We’ve never been hacked before, so we must be secure. That’s the default security mindset, which is at odds with the truth…The best security in the world, only takes you so far.
Cizenski: When you’re spending money on security tools, at that point, at the very least, you’re gonna have an audit trail or something to look back at so you can say, “How did that happen?” Instead of just thinking, “We’ve never been hacked. We’re good.”…When it does happen, you can’t really do much about it [if you don’t have an audit trail].
Click play to learn more!
Additional comments include:
• A rogue admin who took down a former employer’s network
• Admins who experience burn out
• NIST announced guidance on SMS on two factor.
• Whether or not security problems are the user’s fault or not
• As well as the latest research report on security shortcomings on a heart device.
Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrimeMore from Varonis ⬇️ Visit our website: https://www.varonis.comLinkedIn: https://www.linkedin.com/company/varonisX/Twitter: https://twitter.com/varonisInstagram: https://www.instagram.com/varonislife/
How did the Inside Out Security Show panel react? Here's what Mike Buckbee, Kilian Englert and Alan Cizenski had to say:
Buckbee: It’s all tradeoffs. It’s all a bet. If you go into a casino and putting money down…While it’s true you can spend a lot of money and still get hacked, it’s less likely than you spend nothing. Or not even so much spend, in terms of money, but in terms of effort. You spend the effort and time to make secure systems….so you’re trying to play the odds.
Englert: We can write it up as a true-ism…We’ve never been hacked before, so we must be secure. That’s the default security mindset, which is at odds with the truth…The best security in the world, only takes you so far.
Cizenski: When you’re spending money on security tools, at that point, at the very least, you’re gonna have an audit trail or something to look back at so you can say, “How did that happen?” Instead of just thinking, “We’ve never been hacked. We’re good.”…When it does happen, you can’t really do much about it [if you don’t have an audit trail].
Click play to learn more!
Additional comments include:
• A rogue admin who took down a former employer’s network
• Admins who experience burn out
• NIST announced guidance on SMS on two factor.
• Whether or not security problems are the user’s fault or not
• As well as the latest research report on security shortcomings on a heart device.
Want to join us live? Save a seat here: https://www.varonis.com/state-of-cybercrimeMore from Varonis ⬇️ Visit our website: https://www.varonis.comLinkedIn: https://www.linkedin.com/company/varonisX/Twitter: https://twitter.com/varonisInstagram: https://www.instagram.com/varonislife/
More episodes of the podcast State of Cybercrime
Black Hat Cartels
31/10/2025
Supply Chain Attacks
20/09/2025
ShinyHunters' CRM Heist
18/08/2025
Salt Typhoon Returns
25/07/2025
Copilot's Zero-Click Vulnerability
18/06/2025
UK Retail Under Siege
21/05/2025
The Oracle Breach Debate
19/04/2025
$1.5B ByBit Crypto Heist
14/03/2025
DeepSeek Disruption
04/02/2025
U.S. Treasury Breach
15/01/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.