Everybody’s Phishing - An Interview with Joe Gray of Advanced Persistent Security
Interview with Joe Gray of Advanced Persistent Security
Cyber Security Dispatch: Season 2, Episode 06
Show Notes:
Today on the show we welcome Joe Gray. Joe joined the U.S. Navy directly out of High School and served for seven years as a Submarine Navigation Electronics Technician. Today, Joe is a Senior Security Architect and lead blogger and podcaster at Advanced Persistence Security. He is also the inaugural winner of the DerbyCon Social Engineering Capture the Flag (SECTF) and has contributed material for the likes of AlienVault, ITSP Magazine, CSO Online, and Dark Reading, among others. In this episode, we learn all about phishing for awareness. Joe shares how you can mitigate the damage that can be caused by phishing and how white box pen testing relates to phishing overall. We also discuss the current cyber security landscape from a national and international perspective and the importance of companies setting up phishing engagements against their employees. Joe also shares some useful tips on how to limit the damage in securities within IoT devices, as well as how to use disinformation to protect your personal accounts. In an industry that focuses a lot on protecting business, Joe believes that we need to take a step back and look at how we protect people. By the end of this episode, you’ll have a more human perspective on phishing and cyber security and want to share this mindset with your colleagues, family and friends.
Key Points From This Episode:
- Learn more about phishing for awareness and what this entails.
- How Joe helps companies set up phishing engagements against their employees.
- Incident response and why phishing attempts are never going to be 100% effective.
- Assuring those who have been phished that their credentials aren’t necessarily usable.
- The difference between pen testing and red teaming in light of Haroon Meer’s work.
- Why less black box pen testing and more white box red teaming could be the way.
- How are organizations measuring both potential vulnerabilities and risk taking.
- Compliance versus privacy versus security: Why GDPR is winter and winter is coming.
- Learn more about national and international regulations for cyber security response.
- Find out more about the threats out there today (like IoT) that are terrifying Joe.
- Seriously, why would you need a Bluetooth controlled water heater in your home?
- Hear more about the $29 Amazon home router that Joe easily attacked.
- Why we need to go back to protecting people before protecting business.
- Joe gives a few simple steps toward better cyber security in the home.
- Learn more about using deceptive technologies and disinformation to secure yourself.
- Disinformation, trolls and bots and their influence on the US election.
- A current update on various state approaches to cyber security laws and bills.
- The positive movements that Joe is seeing in the field of cyber security today.
- And much more!
Links Mentioned in Today’s Episode:
- Joe Gray – https://advancedpersistentsecurity.net/about-us/joe/
- Joe Gray LinkedIn – https://www.linkedin.com/in/joegrayinfosec/
- Advanced Persistence Security – https://advancedpersistentsecurity.net/
- HackNYC – https://q22018.hacknyc.com/en/
- Key Findings From ISTR Security Report 2017 – https://www.websecurity.symantec.com/security-topics/istr-2017-infographic
- DMarc – https://dmarc.org/
- Mimecast – https://www.mimecast.com/
- Adrian Senabre’s “Killing The Pen Test” – https://www.infosecurity-magazine.com/news/rsac-time-to-kill-pen-test/
- Haroon Meer - https://www.biznews.com/global-citizen/2017/09/13/haroon-meer-buzz-global-tech/
- Have I Been Pwned – https://haveibeenpwned.com/
- DerbyCon Capture the Flag – https://www.social-engineer.org/wp-content/uploads/2017/11/SECTF-2017.pdf
- Decepticon by Joe Gray – https://www.youtube.com/watch?v=ZFvKmJbL924
- Georgia’s 2018 Threat to Cyber Security Bill – https://www.the-parallax.com/2018/02/08/georgia-315-cybersecurity-rights/
Introduction:
Welcome to another edition of Cyber Security Dispatch, this is your host Andy Anderson and in this episode, Everybody’s Phishing, we talk with Joe Gray, blogger and podcaster with Advanced Persistence Security. In this episode, Joe shares how you can mitigate the damage that can be caused by phishing and how white box pen testing relates to phishing overall.
Lastly, we hit upon how to limit the damage in securities within IoT devices. It was a great chat, I think you’ll enjoy it.