Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Megan Samford

πŸ‘€ Speaker
157 total appearances
Voice ID

Voice Profile Active

This person's voice can be automatically recognized across podcast episodes using AI voice matching.

Voice samples: 1
Confidence: Medium

Appearances Over Time

Podcast Appearances

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Figure out if you need to formally declare an incident that would need to be investigated, the level of that incident.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

For the mobile app, where people are responding to text messages, could be phishing, not quite sure, not sure how many people, all of that.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

That's why you stand up incidents to kind of get the full scope of what's going on and you begin to tackle it.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And I would say, depending on the nature of the phish or how sophisticated you think the phishing attack was,

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Just start an incident when you're in doubt.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Just declare an incident and begin to investigate it.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And you can always de-escalate the incident and say, OK, well, this wasn't as big of a deal as we thought it was going to be.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

But you can huddle over all the teams together that would be responsible for providing some immediate stopgaps and then longer term things like more education and things like that for your employees.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

So that's how I think about that.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Probably the mobile one in the immediate until you get your arms around the scenario, because the first scenario, the way you described it to me, I mean, if people aren't doing this stuff every day, what are they doing?

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Identifying risk and dispositioning risk, right?

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Because the whole scenario is, hey, we've uncovered some risk.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

We're aware of it.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

We're not sure what we're going to do about it.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Yes.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Yeah, I took number two, but I mean, I don't.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

That's exactly right.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And with things like NIST 2 and CRA and global regulation, you better build some muscle memory in to where if you know that there is a potential for greater risk in your company and you know that a select population has been spearfished on the mobile and there's a good potential that there could be something on your network or that risk is moving laterally.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Yeah, absolutely.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

You need to declare an incident to huddle around that so that you can understand if you have any reporting obligations.