Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Andy Ellis

๐Ÿ‘ค Speaker
182 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Right.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And so we talk about some of the things that companies get wrong.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You have to be continual on your patching.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You have to be wholesome.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You can't have these these scatomas and these dark areas that you just say, oh, those are the systems we don't patch.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Right.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Or those are the production systems we're scared of touching.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Ross mentioned IAM hygiene, but it goes more than just the MFA and all the controls.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

We talked about cleanup.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So is it worse?

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You've got potentially tens of thousands of stale accounts.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You've got service accounts you don't know what they are.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You've got overprivileged accounts that you should be running Bloodhound on.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

These are all, to me, all the hygiene basics and things, especially as a CISO coming new into a company.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

You need to be finding all these skeletons, all these end of life.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Where's the end of life?

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And my favorite thing to do on that example, and I'm wondering if Andy has done this, find all of your end of life and your legacy and don't steal that budget.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Get the budget for IT for them to go replace those and upgrade those.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

That is the best security budget you can spend is reducing risk when it's not part of your budget.