Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andy Ellis

πŸ‘€ Speaker
414 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Ross mentioned IAM hygiene, but it goes more than just the MFA and all the controls.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

We talked about cleanup.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So is it worse?

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You've got potentially tens of thousands of stale accounts.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You've got service accounts you don't know what they are.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You've got overprivileged accounts that you should be running Bloodhound on.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

These are all, to me, all the hygiene basics and things, especially as a CISO coming new into a company.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You need to be finding all these skeletons, all these end of life.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Where's the end of life?

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And my favorite thing to do on that example, and I'm wondering if Andy has done this, find all of your end of life and your legacy and don't steal that budget.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Get the budget for IT for them to go replace those and upgrade those.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

That is the best security budget you can spend is reducing risk when it's not part of your budget.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Oh, absolutely.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

All right.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

David, your take.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Well said, Andy.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You've got a decent amount of experience in this space.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

I think what you said about everybody is now a basic developer, I absolutely love that because I've definitely seen that being the case where it increases the speed to MVP.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So it has the classic, back in the day, we wanted IT or the development or product teams to build this new thing for me, and I didn't have enough time or it wasn't prioritized.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

This at least allows non-development teams to prototype and prove a concept before they then have to scale it, etc.