MySecurityTV
Operational Technology (OT) Cybersecurity - Episode 4
updated
A seasoned IT veteran with over 20 years of experience, Gavin has a deep technology background in areas like IT infrastructure, enterprise architecture, cybersecurity, and program management for a variety of industries. Prior to joining Salesforce, he has held C-level positions managing IT and transformation for some of Southeast Asia’s largest companies, such as Ayala Corporation and Meralco. Gavin also brings many years of experience in management consulting into his work for customers.
Gavin has a passion for emerging technologies and he regularly speaks at international conferences and other forums on the future of disruptive technologies and how they affect people and work.-
In this interview, Gavin discusses how, to drive AI adoption and reap the benefits of AI, businesses need accurate, complete data and humans in the driver’s seat. He highlights several key points:
• Trust and Value Gaps: Two main barriers to AI adoption are the trust gap and the value gap. Trust in generative AI is essential, as companies need to ensure that AI outputs are accurate, unbiased, and secure.
• Human at the Helm: Gavin emphasizes the importance of having humans oversee AI operations. AI should complement human work by enhancing capabilities while maintaining transparency and trust with customers.
• Quality Data: AI systems need to be grounded in high-quality, trusted data. Many companies struggle with AI outputs due to a lack of trust in the data used to train these models.
• Use Case Awareness: Understanding the appropriate use cases for AI is crucial. Companies need to educate employees and align AI implementations with specific business problems to maximize benefits.
• Governance and Training: Effective governance and training are necessary to build trust in AI. Organizations should focus on data accuracy, transparency, and the role of AI as a supportive tool, not a replacement for humans.
• Security and Privacy: Protecting customer and company data is paramount. Salesforce has implemented a trust layer that masks personal information, uses secure gateways, and ensures data is not retained by large language models (LLMs).
• Future of AI: Gavin anticipates that within a year, the AI landscape will evolve with more specialized LLMs tailored to specific industries and regions. Trust, security, and embedding AI into everyday workflows will remain critical factors for successful AI adoption.
Recorded 8th May 2024, 12noon, Singapore Marina Bay, Salesforce World Tour Essentials 2024 Singapore
The 'Testing Tech in Paradise Industry Sundowner' is a business and industry networking event to explore the opportunities for business collaboration and investment around the cross-sector nature of space, smart city applications, cybersecurity, critical infrastructure protection and advanced manufacturing which is thriving in the region and making a national and international impact.
Sunshine Coast Council is also inviting delegates on a complimentary guided Tech Tour of the Maroochydore CBD in the afternoon of Wednesday 3 July.
REGISTER HERE: mysecuritymarketplace.com/sunshine-coast-hub to register interest.
#sunshinecoast #testingtechinparadise #australiainspacetv #mysecuritytv
Adrian and Mary explained that many users rely on pre-existing machine learning (ML) models from public repositories rather than creating their own. This introduces vulnerabilities similar to those found in open-source software. Using in-house data requires careful handling to avoid bias and unintended consequences, while third-party models can be compromised.
They emphasized that downloading and running models from the internet can introduce malware. Attackers can backdoor models to alter their functions or insert malicious code, posing significant threats, especially in sensitive industries.
Adrian and Mary also stressed the importance of understanding the ML environment, ensuring proper logging, and having incident response plans in place. Companies should prepare by conducting tabletop exercises and securing their supply chains.
For more educational information on machine learning: gist.github.com/5stars217/236bab5d1d8d50e9785a4136aca8cf20
--------
Dropbox, Security Engineer - Adrian Wood, aka threlfall, currently works for Dropbox on their red team. He has worked as a red team consultant for WHITEHACK, a company he founded, and later as a lead engineer for an offensive security research team at a US bank. His research recently has been in supply chain attacks on CI/CD and ML systems, which includes maintaining the offsec ml playbook and has presented on these topics at DEFCON 30, 31, the DEFCON AI village, Cackalackycon and more.
Dropbox, Security Engineer - Mary Walker, aka mairebear, currently works for Dropbox on their threat intelligence team; she splits her time at work between research (primarily focused on ML) and building tooling to help her team move faster. She's previously worked at a major online retailer on their malware analysis and forensics team, a US bank on their red team, and an energy company in their SOC. Her background is primarily in DFIR and malware analysis, with a keen interest in production environments.
Recorded 18th April 2024, 4.30pm, BlackHat Asia 2024, Singapore
#BHAsia #mysecuritytv #blackhat
In this interview, Ron Jimerson, the Chief Information Security Officer (CISO) at the Port of Seattle, discusses various aspects of maritime cybersecurity at the Singapore Maritime Week 2024
Ron explores the intricate landscape of the maritime sector, extending beyond mere shipping to encompass port operators, financing companies, and logistics. He provides insight into the diverse array of stakeholders involved and the challenges posed by the rapidly evolving cyber threat landscape, fueled by the advancements in digitalization.
Furthermore, Ron underscores the significance of information sharing and collaborative partnerships in bolstering cybersecurity defenses. He highlights initiatives such as tabletop exercises and the establishment of Information Sharing and Analysis Centers (ISACs) as vital mechanisms in this regard. Ron underscores the susceptibility of the maritime sector to cyber threats, particularly ransomware attacks, exemplified by the impactful NotPetya incident that served as a catalyst for industry-wide awareness.
Ron also delves into the evolving strategies for cyber defense, notably emphasizing the pivotal role of AI and generative AI in threat analysis and simulation exercises. Additionally, he addresses the crucial human element in cybersecurity, underscoring the necessity of ongoing training and heightened awareness to mitigate human errors.
Lastly, Ron touches upon the challenges and considerations surrounding the implementation of AI, cautioning against excessive reliance on AI solutions and stressing the imperative of continual development and rigorous scrutiny in AI technology.
Recorded 19th April 2024, Singapore Maritime Week, Suntec Singapore Convention & Exhibition Centre.
#singaporemaritimeweek #smw2024
Co-organised by Singapore’s HTX, GIE Milipol, and Comexposium Singapore, the biennial event comes under the auspices of the Ministry of Home Affairs, Singapore and the Ministry of the Interior of France. Milipol Asia-Pacific’s trade exhibition will showcase the latest innovations in homeland security, and the TechX Summit will host prominent Government officials, industry leaders, and academia in a high-level conference.
For more information visit innovd.stengg.com/spotlight/milipolap-2024?utm_campaign=map24-pss&utm_source=mysec&utm_medium=banner&utm_content=static
#milipolap #milipol #mysecuritytv #stengineering
We speak with Yuri Miloslavsky, CEO and Founder of Sharepass, an online digital security solution for confidential information sharing and digital footprint management.
For more information visit sharepass.com
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
#gisec #gisecglobal #mysecuritytv #cybersecurity
We speak with Dheeraj Purohit, Practice Head, Managed IT and Security Services with Royal Cyber. Established in 2002, Royal Cyber Inc is a leading provider of digital solutions to businesses and individuals around the world.
For more information visit securacloud.io
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
#gisec #gisecglobal #mysecuritytv #cybersecurity
The Secasure VAPT comprises of a broad range of Security Assessment Services designed and tailored to identify, help fix & mitigate the Cybersecurity Exposures across diverse Organisational Elements and ensure BCP while safeguarding from any potential Data / Infrastructural Breach.
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
#gisec #gisecglobal #mysecuritytv #cybersecurity
Prudent Bit develops software products that streamline operations by simplifying the way data is sent and stored. Improving security is an important goal of our products aimed at preventing data theft, ransomware attacks, and security issues that are often ignored and overlooked.
To learn more visit prudentbit.com
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
#gisec #gisecglobal #mysecuritytv #cybersecurity
Their story began with the recognition of a key challenge: the increasing frequency of email-borne cyber attacks and the vulnerabilities posed by both incoming and outgoing email communications.
We speak with Murat Guvenc, Director of Global Business Development, CHannels and Alliances.
For more information visit beamsec.com
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
#gisec #gisecglobal #mysecuritytv
We speak with Ahmad Fida Weldali, Regional Sales Director for UAE, Qatar, Oman, Kuwait, Bahrain and LEVANT.
For more information visit linkshadow.com
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
#gisec #gisecglobal #mysecuritytv #ndr #cybersecurity
A C4S Officer with 27 years experience in Technology and Security, Francel is an International Lecturer, Moderator/Panelist and experienced Information Technology Professional with a demonstrated history of working in the Army Management Information Center catering to IS needs for the whole Armed Forces of the Philippines.
Francel is a former Top Women in Security ASEAN Region Awards finalist and Judge.
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
#gisec #gisecglobal #mysecuritytv #topwomeninsecurityASEAN #womenincybersecurity
KoCyber is a Managed Security Service Provider (MSSP) focused on helping corporates build a strong security foundation. We offer tailored security solutions that align with the unique needs and growth of emerging companies, ensuring their rapid development is secure and uninterrupted. With our specialized support, corporates can confidently accelerate their business goals, knowing their security is in expert hands.
KoCber has launched NextHook, their first-ever phishing awareness game! Perfect for individuals, corporates, and universities, NextHook is here to transform how we learn about cybersecurity. It's engaging, interactive, and incredibly effective in teaching the ins and outs of identifying phishing threats.
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
#gisec #gisecglobal #mysecuritytv
For more information visit www.kocyber.com
#KoCyber #NextHook #CybersecurityMadeFun #PhishingAwareness #MultiplayerMode #GameOn #EarlyBirdSpecials
Alina is a former Top 30 Women in Cybersecurity Singapore (now the Top Women in Security ASEAN Region Awards).
GISEC Global 2024 attracted more than 20,000 attendees from over 130 countries to the Dubai World Trade Center. Taking place over three days, April 23-25, the event provides a platform for more than 750 brands to showcase their innovations.
#gisec #gisecglobal #mysecuritytv #womenincybersecurity #topwomeninsecurityASEAN
MySecurity Media are media partners to #gisecglobal
We discuss how border security been affected by technology and the current landscape, emerging threats, and the importance of fostering collaboration between government and industry to ensure border management has the cutting-edge technologies to ensure security and efficiency.
Recorded 4 April 2024 at the Sands Expo & Convention Centre, Singapore.
#milipolap #maptxs #mysecuritytv #policing #customs #nationalsecurity
Nominated by President Biden in 2021, Dimitri Kusnezov was the deputy under secretary for artificial intelligence and technology at DoE (Energy), leading efforts to drive the use of AI and machine learning across the department’s core missions.
Australia and the United States of America signed a treaty on cooperation in science and technology (S&T) for domestic security on 21 December 2005.
Recorded 4 April, 2024 at the Sands Expo & Convention Centre, Singapore.
#milipolap #mysecuritytv #DHS #homelandsecurity #ai #nationalsecurity #nationalsecurityscience
Singapore’s Minister for Home Affairs and for Law, Mr. K Shanmugam was the guest-of-honour at the launch, and delivered the opening address. France’s Minister of the Interior, Mr. G. Darmanin also attended the event and delivered remarks.
Themed “Powering Innovation: A Safe & Secure Future”, the event is Asia Pacific’s flagship homeland security gathering covering both public and private sector security. More than 10,000 senior government officials, operational experts, industry leaders, security providers, integrators and academia are expected to converge on the event over the next three days to discuss security solutions, strategies, best practices, and challenges, as well as technological trends; and foster collaboration within the homeland security community.
#mysecuritytv #milipolap #maptxs
We speak with Jannis Utz, VP Global Sales Engineering at Pentera and get insights into Pentera's capabilities and what will be on display at Booth B20, Hall 8 at GISEC Global 2024, 23-25 April at the Dubai World Trade Centre.
#Pentera #gisecglobal #mysecuritytv
Prior to founding VAST, Renen led the architecture and development of an all-flash array at XtremIO, from inception to over a billion dollars in revenue while acting as VP R&D and leading a team of over 200 engineers. He holds a BA and an MSc in Computer Science, both summa cum laude.
Central to Renen's discourse is the pivotal role of data transformation in unlocking value within organizations in the AI era, and how businesses leverage vast unstructured data to derive valuable insights to gain a competitive edge.
Renen also notes the challenges and opportunities presented by AI in terms of cybersecurity. He delves into the dual role of AI as both a potential vulnerability and a defense mechanism against cyber threats.
Given the significance of scalable infrastructure in supporting the growing demands of AI-driven applications, Renen highlights platforms like Vast Data, which offer scalable solutions capable of handling vast amounts of data with high performance and minimal latency.
Recorded 13 March 2024, 11am. Singapore Shangri La Hotel, Breakfast Session with VAST Data
#mysecuritytv #AI #VastData
Zien has developed an IoT security vulnerability inspection solution that can prevent IoT security incidents in advance and reduce inspection cost and time.
For more information visit zi-en.io
Attending SECON & eGISEC at Kintex, South Korea, we speak with Sylvia Kim, Marketing Manager, ZIEN.
#ZIEN #SECON #eGISEC #cybersecurity #mysecuritytv #korea
The Coder owns the technology for embedding invisible codes to most objects and the possibility to utilize the DOT technology is limitless.
The Coder's DOT technology is already making significant contributions across various fields with global enterprises.
DOT is a restricted and independent code. Due to it being invisible and not an open source, it is inaccessible. If it is not an authorized device, it is impossible to verify. It can be utilized to establish a healthy distribution system and also be used to manage the product’s lifecycle.
Attending SECON & eGISEC at Kintex, South Korea, we speak with Soo-In Choi, A/Manager, Marketing Sales Division.
To find out more visit https://www.thecoder.co.kr/
#Thecoder #SECON #eGISEC #security #mysecuritytv #korea
Since its establishment in December 2018, swIDch has been recognized for its breakthrough technology and rapid growth through various Accelerator programmes and global awards organised by global organisations as well as the UK. Initially launched through GEP from UK government's Department for International Trade (DIT) and LORCA from UK government's Department for Culture, Media and Sport (DCMS), swIDch has experienced remarkable growth. OTAC (One-Time Authentication Code) technology developed by swIDch has already been provided to over 50 clients and is developing business models with organisations in a variety of industries.
SSenStone is the parent company of swIDch, proving its technological prowess and growth potential by taking first place with the best score in the "Baby Unicorn 200 project" of the Ministry of SMEs and Startups, Republic of Korea. Consisting of cybersecurity experts with over 10 years of experience, SSenStone continues to research and develop technologies that provide safer and more convenient identification and authentication between humans and devices or devices and devices in a rapidly changing ICT environment. For further information, please visit the official website of
SSenStone: ssenstone.com/eng
SwIDch: swidch.com
Attending SECON & eGISEC at Kintex, South Korea, we speak Chang-Hun Yoo, CEO & Founder.
#OTAC #SECON #eGISEC #cybersecurity #mysecuritytv #korea
The ML(Mobility LiDAR) is the simplest LiDAR sensor in the world. It is a solid-state scanning type with no mechanical moving components which enables maximizing productivity in terms of mass production. With powerful performance and durability - yet compact and light, it can be used in various purposes for next-generation mobility.
Attending SECON & eGISEC at Kintex, South Korea, we speak with Sangbin (Vincent) Lee, Senior Manager, SOS Lab.
For more information visit soslab.co
#LiDAR #SECON #eGISEC #mysecuritytv #korea
Attending SECON & eGISEC at Kintex, South Korea, we speak with Gin Kim, Director, Business Development. Korea and North Asia.
To find out more visit sans.org
#SANS #SECON #eGISEC #cybersecurity #mysecuritytv #korea
As the largest video surveillance manufacturer in South Korea, with headquarters and manufacturing facilities just outside of Seoul, IDIS operates across 50 countries and 100+ strategic partners. IDIS is a world-leading digital surveillance solution provider with more than two million recorders installed worldwide and over 16.5 million cameras utilizing IDIS technology.
The IDIS total surveillance solution meets the needs of an increasingly demanding security landscape. IDIS provides the benefit of an end-to-end, highest-quality total surveillance solution and delivers innovation that is user-friendly, flexible, scalable, and is able to meet every surveillance need—all with unrivalled performance, quality, and low total cost of ownership.
Attending SECON & eGISEC at Kintex, South Korea, we speak with Max Kim, MEA & Asia Business Development Team Manager, IDIS.
For more information visit idisglobal.com
#IDIS #SECON #eGISEC #CCTV #smartcity #mysecuritytv #korea
Premium robots are responsible for your safety, from patrol service that require a lot of time and manpower to quarantine and guidance services.
Attending SECON & eGISEC at Kintex, South Korea, we speak Hyerim Kim, Sales Manager with DOGU.
To find out more visit
dogugonggan.imweb.me
#securityrobot #SECON #eGISEC #robotics #mysecuritytv #korea
is dedicated to developing Korea’s Internet industry and information security
capabilities. As an Internet and information security promotion agency
armed with global competitiveness, KISA will maintain its commitment to
creating a safe and happy Internet world
The Korea Internet & Security Agency (KISA) has set ‘Internet Promotion’ for the future and ‘Information Security’ for our safety as its primary tasks, and is focusing on enhancing the information security capacity of Korea’s ICT industry while expanding global cooperative partnerships based on the K-ICT Security Development Strategy.
Attending SECON & eGISEC at Kintex, South Korea, we speak (with interpreter) with Son Kyoung-Ah, Deputy General Researcher about KISA's Security Product Fasttrack strategy.
#KISA #SECON #eGISEC #cybersecurity #mysecuritytv #korea
We speak with Mr THNG Chin Hwee, Vice-President, Public Safety & Security Cluster, ST Engineering about the capabilities on display at Milipol APAC and a must see at Booth 1910.
Find out more visit
innovd.stengg.com/spotlight/milipolap-2024
MySecurity Media will be coordinating a delegation at Milipol APAC 2024 - to find out more visit mysecuritymarketplace.com/event/milipol-asia-pacific
#stengineering #stengg #milipolapac #milipolap #mysecuritytv
The grand opening ceremony of SECON & eGISEC was attended by the Ministry of Science and ICT, the Ministry of the Interior and Safety, and VIP representatives and the SECON & eGISEC Organizing Committee, along with local and international media.
MySecurity Media are attending SECON & eGISEC – stay tuned!
#secon #egisec #mysecuritytv #southkorea #securitytechnology
Grant leads SEEK's global AI and Analytics teams at SEEK, who build and support the AI services that power SEEK's products including search, recommendations, candidate quality and pricing; and provide internal analytics and experimentation capability to better understand the performance of our products and drive continuous improvement and innovation.
Grant brings to this role his previous experience as Strategy Director at SEEK.
Prior to joining SEEK, Grant worked at L.E.K Consulting for over 10 years where he advised organisations and governments across Australia, New Zealand and the US on strategy, performance improvement and mergers and acquisitions.
Grant holds a Bachelor of Business (Economics) & Bachelor of Computer and Information Science (Software Development) from the Auckland University of Technology, where he was awarded the New Zealand Computer Society Cup for the top Computer and Information Science Graduate.
Generative AI, particularly ChatGPT, is transforming service delivery for clients and end-users, prompting businesses to actively integrate this technology for operational refinement. Grant shares anecdotes, such as using ChatGPT to craft children's bedtime stories.
Acknowledging glimpses of success in applying generative AI to customer interactions, Grant highlights the challenges of scaling these applications. Ongoing efforts focus on optimizing technology for widespread use, particularly in customer service scenarios.
In the realm of Gen AI transforming information into intelligence, Grant provides statistical insights into the platform's extensive reach, encompassing millions of candidate profiles, billions of interactions, and a substantial volume of job applications. Gen AI's value lies in extracting insights from traditionally unstructured data like job ads and CVs, summarizing and distilling it for actionable intelligence.
Anticipating a transformative shift in user experience, Grant envisions users communicating with AI more naturally. This evolution, inclusive of voice interfaces, promises new avenues for interaction, moving away from adapting to machine language.
Delving into responsibility in AI implementation, Grant underscores the importance of responsibly handling data and biases to prevent reinforcing discriminatory outcomes through AI. Emphasizing the necessity to understand the risks associated with training data and be mindful of potential impacts on individuals affected by AI-generated decisions.
Exploring the challenges and realities of AI impact on jobs, Grant highlights the disparity between the hype around AI's impact on jobs and tangible transformations in the job market. A balanced perspective is crucial to avoid overestimating or underestimating AI's immediate effects. Jobs are perceived as bundles of tasks, and Grant emphasizes the complexity of job market transformations. While some tasks may automate, others evolve or experience increased demand. For instance, the transition from last-mile delivery to drone-based delivery illustrates how job demands can shift within industries.
In preparing for change and AI adoption, Grant advises individuals, employers, and business owners to embrace adaptability in the face of evolving technological landscapes. Individuals are encouraged to explore and experiment with AI tools in their daily lives. Employers should focus on evolving skill requirements rather than rigidly adhering to traditional hiring practices. Additionally, caution is advised in AI adoption, especially in building internal capabilities. It involves asking the right questions about underlying AI capabilities, understanding potential risks.
Recorded on 29th February 2024, 6pm, SEEK office (Wallich Street, Singapore).
Sharat has over 15 years of experience assisting organisations in the areas of security architecture, threat detection and threat hunting. He has a strong focus on leading security engineering, security architecture, and the sales engineering team across APJ.
The global cybersecurity landscape is witnessing a concerning surge in threats, and is particularly pronounced in the Asia-Pacific region. With the imminent impact of AI-boosted cyberattacks, cybercriminal tactics like phishing and social engineering are evolving in sophistication. Moreover, the recent uptick in high-severity cyber incidents underscores the urgent need for organisations to bolster their defence strategies. The implementation of comprehensive cybersecurity protocols is paramount for businesses and organisations to effectively mitigate these evolving threats.
Vectra AI, Inc. is the leader in hybrid attack detection, investigation and response. The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Vectra AI’s patented Attack Signal Intelligence empowers security teams to rapidly detect, prioritize, investigate and stop the most advanced hybrid cyber-attacks. With 35 patents in AI-driven detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI Platform and MDR services to move at the speed and scale of hybrid attackers.
Visit Booth 1810 at Milipol APAC 2024, 3 - 5 April at the Sands Expo & Convention Centre, Singapore.
#milipol #vectra #mysecuritytv
CyberArk has advanced capabilities for securing access to cloud services and modern infrastructure for all users, based on the company’s risk-based intelligent privilege controls.
The CyberArk Secure Cloud Access solution provides just-in-time access with zero standing privileges to cloud management consoles and services running in multi-cloud environments. These security controls enable secure access to every layer of cloud environments, while causing no disruption or change to the way developers and other users access cloud services.
Charles will be in Sydney & Melbourne - 18-22 March, 2024.
For a demo visit cyberark.com/request-demo or find out more at cyberark.com/contact
#mysecuritytv #cyberark #iam #identitysecurity #cloudsecurity #pam
Shamane is a huge advocate and business champion for cyber risk professionals and actively encourages people to look for new ways to take a step forward.
To read more visit
linkedin.com/in/shamane
#cyberriskmeetup #mysecuritytv #sheleadstech #shamanetan
Recorded in Singapore, 7 March 2024
Guest-of-Honour, Puay Li Phua, Senior Director (Policy and Corporate Development) of the Cyber Security Agency of Singapore (CSA) and Jenny Tan, President of the ISACA Singapore Chapter shared the futuristic mission that SheLeadsTech hopes to achieve in the next 5 years.
We speak with ISACA Singapore Chapter President Jenny Tan and SheLeadsTech champion on the highlights of the last five years and the outlook for the next five years.
#sheleadstech #mysecuritytv #singapore #isaca
Recorded 7 March 2024
Read more - aseantechsec.com/singapores-sheleadstech-conference-celebrates-5-years
The additional capital enables Bugcrowd to accelerate growth across EMEA, APAC, and the United States, fund continued innovation into the Bugcrowd Platform, and leverage opportunities for strategic M&A, providing added value to clients, partners, and the hacker community.
For Australian founder and now Chief Strategy Officer, Casey Ellis, this is an exciting time. Casey told MySecurity Media, “It’s a constant series of moments where I’m pinching myself. I get to work with this team, seeing all this play out, getting to have the kind of impact and influence that we’ve had. As an organisation it’s a thrill, frankly. That’s a lot of the reason why I’m still here. There’s still so much to achieve. This is a fantastic team for me to partner with, even as someone who’s more classically, an early stage guy, it’s just been phenomenal being able to partner on that and see them execute.”
As a part of this investment, Mark Crane, Partner at General Catalyst and Paul Sagan, Senior Advisor at General Catalyst, will join the Bugcrowd Board of Directors. Sagan will also step into the Board Chair role. Jeff Simon, Chief Security Officer at T-Mobile and Prabhath Karanth, Vice President and Global Head of Security and Trust at Navan, join the advisory board to serve alongside David Fairman, CIO & CSO – APAC at Netskope.
Interview conducted in Sydney, 26 March 2024.
Further reading visit https://australiancybersecuritymagazine.com.au/bugcrowd-secures-us102-million-to-scale-crowdsourced-security-platform/
#bugcrowd #hacking #mysecuritytv #caseyellis #capitalraising
We speak with Yuri Miloslavsky, CEO and founder of SharePass as the partner bringing Australian cybersecurity companies to the 2024 edition of #GISECGlobal.
🗓 23 - 25 April 2024
📍 Halls 2 - 8, Dubai World Trade Centre
🔗 Register your interest: https://gisec.ae/book-a-stand.html
🔗 Register as a delegate visit: mysecuritymarketplace.com/event/gisec-global-2024
A super connector event for the global cybersecurity community, GISEC delivers on two fronts.
Firstly, it provides vendors and companies from around the world with access to truly lucrative opportunities within one of the world’s booming markets. For example, driven by its growing spending on securing digital infrastructure, the Middle East cybersecurity market alone is expected to be valued at $31bn by 2030, according to recent data from Frost & Sullivan. Within this commercial context, GISEC stands as the indisputable platform for the public-private partnerships that drive many of its biggest opportunities and projects.
Secondly, GISEC is also a forum for furthering the key discussions that are helping to define cyber resilience across multiple sectors.
For 2024, the forum has been arranged around five key areas. These include the Government stage, healthcare and finance tracks, plus the CISO Circle for Chief Information Security Officers – that will explore the risks posed by state-sponsored hackers, organised hacking groups and insider threats – and the Critical Information Dome, where attendees can gain insights into advanced ways to identify, respond to and mitigate cyber risks to essential services, such as communication, aviation, transportation and energy.
#mysecuritytv #cybersecurity
In this interview, Ivo shared insights in 6 topics:
1. Information sharing challenges: Addressing conflicts between private sectors and law enforcement priorities, particularly in cases like ransomware, where the need to restore operations clashes with preserving evidence.
2. Data Processing Regulations: Exploring Interpol's regulations for data processing and exchange, considering cultural barriers, language differences, and data sovereignty concerns when sharing information among different countries.
3. Project Gateway Initiative: Understanding the process and significance of Project Gateway, a collaboration framework between Interpol and private entities, including the steps for private organizations to join this initiative.
4. AI's Impact on Cybersecurity: Recognizing AI as a productivity enhancer, both for defenders and attackers, and the importance of balancing technological advancements with legal frameworks in the evolving cybercrime landscape.
5. Training and Collaboration: Emphasizing the need for regular training sessions and exercises to foster a common understanding and language among global law enforcement agencies, crucial for effective collaboration during global cybercrime operations.
6. Skill Set for Investigators: Discussing the essential skills for law enforcement investigators, including self-driven motivation, the importance of work-life balance, and the role of teamwork, personal interests, and joy in maintaining stamina and perseverance in the field of cybersecurity.
Recorded 7th December, ISC2 Secure Asia Pacific 2023, 10.30am.
#interpol #mysecuritytv #cybersecurity
The startup is trialing its wireless brain-computer interface to evaluate the safety and functionality of the implant and surgical robot.
We speak with Dr Allan McCay, Deputy Director, Sydney Institute of Criminology, Sydney Law School on the range of applications, Australian and international frameworks and the ethical issues related to emerging neurotechnologies.
#bci #mysecuritytv #neurotechnology
Note: apologies for inconsistent audio
NEC, a globally renowned Fortune 500 company, engages in various sectors, including submarine cables, facial recognition, managed services, and more. In Australia, the focus lies on managed services, smart transport, biometrics, facial recognition, wireless display screens, and unified communications.
"As an organization, NEC is 125 years old and has completely reinvented itself several times. We need to constantly make sure that we're looking for new opportunities," said Price. He highlighted the importance of exploring new avenues and opportunities as the industry experiences rapid changes.
Price also acknowledges the central theme around cybersecurity in contemporary discussions. He noted that cybersecurity has transcended IT departments and become a crucial business decision, with boards taking responsibility for breaches. Price emphasized the importance of staying on top of security measures and ensuring the organization possesses the necessary skills to provide comprehensive solutions to clients.
For further reading visit chiefit.me/tech-industry-faces-unprecedented-challenges-and-transformation
#mysecuritytv #canalys #canalyforums2023 #cybersecurity
Thomas provides insight into his business and its focus on external threat visibility in the realm of cybersecurity. While many companies excel in internal security, there remains a significant risk outside the network. Cyber Sentience aims to address this visibility gap by providing solutions that focus on threats originating from external sources, including data outside the network and potential exploitation of staff credentials.
Attending Canalys as a channel partner, was the importance of future-proofing his business by gaining insights into the industry's needs, particularly with the rising influence of artificial intelligence (AI) and its impact on the cybersecurity landscape.
While cybersecurity is not the sole focal point of the Channel Forum, it is an integral part of a broader IT ecosystem. Crisp highlighted the importance of considering cybersecurity as a wrapper for protecting systems within the larger context of IT.
For further reading visit chiefit.me/tech-industry-faces-unprecedented-challenges-and-transformation
For Cyber Sentience visit cybersentience.co.nz
#mysecuritytv #canalys #canalyforums2023 #cybersecurity
As a global IT organization, NTT boasts a full-stack approach, covering network infrastructure, data centers, system integration, and managed services. Pranay emphasized the company's commitment to solving client problems and highlighted his role, which includes driving innovation, leading architectural initiatives, and overseeing go-to-market functions.
"I have one of the best jobs," said Pranay, emphasizing his focus on solving client problems from an outside-in perspective and linking innovation back to the organization's capabilities.
Pranay expressed optimism about the opportunities presented by artificial intelligence (AI) in the coming years. He highlighted the transformative power of AI in processing vast amounts of data quickly, enabling organizations to tackle a range of challenges. NTT's innovation-first approach involves validating solutions, testing them with clients, and scaling successful initiatives.
For further reading visit chiefit.me/tech-industry-faces-unprecedented-challenges-and-transformation
#mysecuritytv #canalys #canalyforums2023 #cybersecurity
Prior to Eclypsium, Yuriy was Chief Threat Researcher and led the Microprocessor Security Analysis team at Intel Corporation, as well as the Advanced Threat Research team at Intel Security.
He is also the creator of CHIPSEC, the popular open-source firmware and hardware supply chain security assessment framework.
When enterprises started using CHIPSEC to find vulnerabilities, discover compromised firmware, or just poke around hardware systems, Yuriy founded Eclypsium with Alex Bazhaniuk.
Since then Eclypsium has been on a mission to protect devices from supply chain risks.
In this interview, Yuriy highlights the potential vulnerabilities in the firmware (software running the hardware) in today’s digital devices, and the risk posed by threat actors.
Using a typical PC as an example, which involves contributions from over 265 suppliers, each with its components and code, he notes the ubiquity of software, and liken the supply chain of such a device to a “Wild West”:
“at any point in the supply chain, at any of those links in the supply chain, a compromise may happen”, and “ all of these components and all the code that is developed by those suppliers and vendors has vulnerabilities.”
He elaborated that “even if it's OK now … 3 months from now, it can be compromised because of those vulnerabilities.”
To give an example, he referenced the recently discovered threat in the wild – “BlackLotus”, an evolution of threats based on open-source frameworks – e.g. Lojax, MosaicRegressor, Moon bounce - discovered in the past 3 to 4 years.
He highlighted the characteristics of such threats:
• These UEFI compromises allow attackers to compromise equipment remotely, for access or persistent malware installation.
• They cannot be removed by reinstalling operating system or reimaging or even replacing the hard drive.
• BlackLotus exploitation of the UEFI system vulnerabilities, particularly the Secure Boot - a fundamental security feature adopted by modern operating systems - sets it apart as an advanced threat, marking the first instance of such threats discovered "in the wild."
He explained that compromising firmware is attractive for threat actors for many reasons:
• Stay hidden: Detection and protection controls operate at the software application level and above, but there is no equivalent for firmware.
• Achieve "Persistence" - where traditional mitigation measures cannot remove the malware/threats.
• Simplicity – for example, exploiting firmware vulnerabilities to gain access is much simpler than developing a very complicated exploit chain.
• Gain high privileges – Remain hidden and persistent while gaining high level of privileges.
To mitigate against malicious firmware implants, Yuriy suggested,
(a) assess the supply chain risks (e.g. potential vulnerabilities and threats introduced during procurement and deployment),
(b) continuous monitoring of system integrity,
(c) implement specialized technologies designed for malicious firmware detection.
Recorded at Singapore International Cyber Week / Govware 2023 – 18th October 2023, 3pm.
#mysecuritytv #govware #sicw
The relaunched 2023-2030 Australian Cyber Security Strategy will be a “game-changing strategy,” according to O’Neil. She says cybersecurity is Australia’s fastest-growing national security challenge. The updated strategy will see the government invest another AUD600 million into fighting cybercrime, based on the six cyber shields or pillars O’Neil articulated at a cybersecurity conference in Sydney in September.
Professor Phair said, "The Strategy highlights the need for a skilled workforce to solve the cyber security problems of the future. The higher education sector is well placed and stands ready to support the government in this aim.
"Partnerships between academia, business and government will be critical to meeting the goals of the Strategy. A joined-up approach where all three sectors work together is efficient and effective."
Professor Carsten Rudolph, Department of Software Systems and Cybersecurity, Faculty of Information Technology at Monash University has added, "Support for countries with cyber security incidents is definitely useful and highly welcome. However, in the long-term it will be necessary to support countries in the Pacific region to establish their own sovereign cyber security capabilities.
“A 'we need to do it for them’ approach will provide support, but also create new dependencies and the clear message from the October 2023 P4C conference in Fiji was that Pacific countries require longer-term commitments that build resilience in a strategic and holistic manner.
“Many countries have gone through comprehensive cyber security reviews, such as the ones delivered by the Oceania Cyber Security Centre OCSC in Melbourne and these countries have developed roadmaps to improve their cyber security maturity.
“Incident response support should be complemented by funding that builds on existing initiatives, reports and should consider the countries' own roadmaps. Building up capabilities and teams in Pacific countries, for example in collaboration with their national universities, can be one way to establish resources and create local talent. These local experts can then also have perspectives for careers in cyber security in their home countries.”
Further reading
https://australiancybersecuritymagazine.com.au/cyber-security-minister-eyes-blanket-ransomware-ban-in-two-years/
Link to strategy: mysecuritymarketplace.com/reports/australian-cyber-security-strategy
#mysecuritytv #cybersecurity #monashuniversity
Prior to joining ISC2, Clar served as the executive vice president, engagement and learning innovation for the Association of International Certified Professional Accountants (AICPA) where she led the development and execution of strategy to support global competency development and lifelong learning for the finance and accounting profession.
Previously, Clar worked as the Chief Operating Officer of the California Society of CPAs (CalCPA) and the CalCPA Education Foundation where she drove membership growth of more than 30 percent and developed and executed a strategic vision to transition the Education Foundation to a digitally focused business model. Prior to CalCPA, Clar worked as an educator, magazine writer and sports reporter. Clar holds a bachelor’s degree in rhetoric and communications from the University of California, Davis and a master’s degree in special education from San Francisco State University.
In this interview, Clar shares her perspectives on cybersecurity skills and the workforce, and how ISC2, a 34-year-old organization, aims to plug the gap with certifications ranging from entry-level to advanced, including the renowned CISSP.
Key cybersecurity skills
• While highlighting technical skills that are in high demand - cloud security, zero trust implementation, and expertise in cyber operations and threat analysis, Clar also notes the importance of soft skills - communication, problem-solving, critical thinking, and a passion for lifelong learning.
• Drawing on her personal experience throughout her career, Clar also offers skills that she developed outside of the cybersecurity industry - such as risk management skills and hands-on experience with technology projects – have given her valuable insights into cybersecurity.
Ecosystem and inter-governmental Initiatives
• To cultivate cybersecurity capabilities amongst the youth, Clar shares that ISC2 charitable nonprofit, “Center for Cyber Safety and Education” sends volunteers to schools to teach "Safe and Secure Online", with the aim to build awareness of digital safety and cybersecurity principles from an early age.
• ISC2 also recently embarked on a "Certified in Cybersecurity" partnership with CSA (Cyber Security Agency of Singapore) to offer free education and exams to boost cyber literacy and address the skills gap, targeting 10,000 individuals in Singapore for potential cybersecurity careers.
Impact of AI on cybersecurity
• On how AI will transform the cybersecurity, Clar acknowledged that there are various aspects to consider.
• One key area in training is optimising the learning process. As an example, she points to how ISC2 is introducing adaptive learning using machine learning in their certification programs, which helps personalize the learning experience and save time.
• When it comes to related security risks, she highlights the importance of adopting existing security principles to the AI use case, to secure the technology underpinning AI systems.
• Another dimension is AI’s role in decision-making, and the need for us to evaluate the potential risks and validity of its recommendations. She points out this is where non-technical skills like analytical thinking and critical problem-solving become invaluable.
• Another risk is the potential compromise of AI by threat actors
Wrap-up
• Wrapping up the interview, Clar offers that while AI may change the nature of some roles, it will not replace human cybersecurity professionals – and the key is to keep learning and staying prepared for the technological evolutions.
Recorded 17th October, 5.30pm, Singapore International Cyber Week 2023/ Govware 2023
#mysecuritytv #ISC2
Prior to joining Keppel T&T, Mr Wong was Vice President of BT Advise BT Global Services across Asia Pacific, Middle East, Africa and Turkey (AMEA) where he managed the company's practices in business consulting, systems integration, software development, networking, mobility, collaboration and security. He was also CEO of the BT Frontline group of companies where he played a critical role in the integration of BT Frontline into BT Global Services.
Mr Wong now serves as Chair of SGTech Council, Member of the Council and Chair of Digitalisation Committee in Singapore Business Federation, and is active on various industry panels and committees.
In November 2022, he won the Top Business Leaders accolade at the Asia-Pacific Cloud & Datacentre Awards
More recently in August 2023, he was named by the Singapore Computer Society as Tech Leader of the Year 2023.
In this interview, Mr Wong shared his insights on the evolution of data centres over the last two decades, from the early computing days to today’s AI and Web3 eras, highlighting the pivotal role of connectivity in transforming how “we consume technology today”.
Noting how the shift bring to realisation of a “computer” in our palms and concepts such as “software as a service”, he said these transformations contribute to a trend from on-premises solutions to cloud-based applications. These changes in turn have driven demands for centralisation of services in the cloud, leading to the growth of data centres, and the rise of hyperscalers.
Other topics discussed include:
1. The impact of AI on the tech industry, and the significance of AI in the context of AI vs. AI scenarios.
2. Location considerations for data centres (factors such as power availability, water supply for cooling, and connectivity infrastructure being key considerations); sustainability in data centres (including energy efficiency and the use of renewable energy sources).
3. Cybersecurity as a holistic approach to digital trust, which goes beyond just technology and involves governance, data management, and privacy considerations.
Mr Wong wrapped up the interview by sharing how the tech industry's perpetual evolution change keep him passionately engaged throughout his career – and the promise of groundbreaking change, making each day a thrilling journey of discovery.
Recorded at Tech Week 2023, 12th October 2023, 4pm, Singapore Marina Bay Sands.
#mysecuritytv
Zee Kin is an internationally recognized expert on AI ethics. He spearheaded the development of Singapore’s Model AI Governance Framework, which won the UNITU WSIS Prize in 2019. He is currently a member of the OECD Network of Experts on AI (ONE AI). In 2019, he was a member of the AI Group of Experts at the OECD (AIGO), which developed the OECD Principles on AI. These principles have been endorsed by the G20 in 2019. He was also an observer participant at the European Commission’s High-Level Expert Group on AI, which fulfilled its mandate in June 2020
Zee Kin is also a well-regarded expert on data privacy issues. He has contributed to publications on legal issues relating to data privacy and has spoken at many well-recognised international and domestic platforms on this topic.
--
In this interview, Zee Kin shares his insights on the legal challenges in the Era of Advanced AI
Zee Kin highlighted that with the latest AI innovations, the responsibility and legal issues remain largely consistent, but the tools and technology introduce different challenges.
For instance, he shared that such concerns around content, child protection, intermediary behavior, data security, data protection, and cybercrime remain, while challenges such as detection of fake content has intensified due to increased tool accessibility and the scalability of threats.
Referring to the "Getty vs. Stability AI" case, he shared that the interesting question is the use of copyrighted data to train AI models – which is not new, and the key is to establish a proper legal basis for using such data. Data lineage and the provenance of data have always been important in legal contexts.
He also noted that these concerns have also surfaced during the recent governmental responses around the world to the latest AI innovations.
Zee Kin also highlighted the challenges with defining terms such as "fairness," "transparency," and "repeatability" – varies by context, where expectations and priorities for AI differ based on its use, such as safety and predictability in medicine, and bias and fairness in personal data applications.
Repeatability poses an additional challenge in Generative AI because every iteration of an image or summary will vary (**owing to Generative AI's statistical predictive nature).
Zee Kin also shares his views of AI's impact on job security, nothing that there will be emerging opportunities for lawyers to use AI tools for efficiency and error reduction.
Recorded at TechLaw Fest 2023, 21st Sept 2023, 3.30pm, Marina Bay Sands, Singapore.
#mysecuritytv #cybersecurity #ai #law #ailawyer
With over 19 years in the IT industry, Ben Verschaeren is a seasoned professional based in Melbourne. He leads global strategic initiatives, educates on threat landscapes, and develops training tools focusing on real-world exploits.
Ben also directs a global sales engineering team responding to RFPs, and a software engineering team creating high-quality products for various uses. His prior roles include serving as a Solution Architect at JB HiFi, Australia's largest retailer, and at Thiess, the leading mining and construction company in Australia.
Ben’s unique blend of sales and engineering experience across diverse sectors enables him to drive tech-forward initiatives with an innovative approach, affirming his position as a key asset in the industry.
In this interview, Ben kicked off the interview by sharing his insights on drivers into the wide-spread popularity of the latest AI technology – “generative AI”.
On discussing how generative AI could transform the cybersecurity landscape, Ben acknowledged that it could help increase the productivity of cyber defenders, as an “AI” personal assistant – such as “help you write code” or “help you write query”.
However, he also cautioned that the technology also introduces new threats.
Elaborating on some of the emerging threats, he said that contrary to expectations, malware generated by LLM can be more easily detected than phishing emails and synthetic voice.
To mitigate against such threats, he suggested enhancing business processes and controls (for example, robust fund transfer authorisation, to mitigate phishing risk). He also recommended conducting user awareness training regularly to align with the fast-evolving landscape of phishing tactics, emphasising the importance of understanding the "why."
Another threat is the potential of generative AI to “hallucinate” when making recommendations for software libraries. He pointed out this issue underscores the need to maintain a SBOM (software bill of materials), and implementing quality controls throughout the software development process.
Ben also recommended that organisations looking to embrace AI, develop an “AI policy”, providing guidance in areas such as the types of data or models that to be used during training and deployment. He also shared that middleware solutions are available to anonymise the data entered in the prompt, and check that no personally identifiable information (PII) is included.
Wrapping up, Ben notes that rapid pace of generative AI development and “the landscape is changing everyday”, and advises cyber defenders to “stay on top”, “don’t be complacent”, and it is “another area where and different threats are emerging every day”.
Recorded at Cloud Expo Asia, Singapore Marina Bay Sands, 12th October 2023.
#mysecuritytv #sophos #generativeai #cybersecurity
While being interested in physical security and lockpicking, he enjoys applied research and reverse engineering malware and all kinds of devices.
His most known projects are the documentation and hacking of various vacuum robots. His current vacuum robot army consists of over 49 different models from various vendors.
Recorded on 18 October, 2023 at The Australian Cyber Conference 2023 - Melbourne with the Australian Information Security Association. #cybercon #IoTsecurity #mysecuritytv
In this interview, Brendan shared his perspectives on cybersecurity skills, threats and budgets.
Reflecting on his career at the NSA from 2002 to 2013 and essential cybersecurity skills, Brendan emphasized the importance of curiosity, analytical thinking, and adaptability, which he believes are still relevant in today's cybersecurity landscape.
When it comes to the question of whether cyber threat actors possess greater expertise than cyber defenders, Brendan suggested that they strive to utilize their resources as effectively as possible to breach networks. From this standpoint, they share similarities with other criminals who possess the necessary skills to perpetuate their criminal activities.
For cyber defenders also seeking to optimise the return on investments, he noted the challenge of quantifying cybersecurity investments and the need to tailor metrics for different companies and industries.
On the topical theme of AI in cybersecurity, Brendan highlighted the potential of AI, particularly in threat intelligence characterization and customer engagement. He also mentioned the challenges of AI models and their potential use by threat actors.
He also shared his experiences starting a company and raising funds, and the value of Information Sharing and Analysis Centers (ISACs) and various industry-specific information-sharing groups.
Recorded 26th Sept 2023, 5.30pm, Asia Square Singapore.
#mysecuritytv #cybersecurity #isac


