355: Eric O'Neill – Hackers Don't Break In, They Log In: Trust as the New Perimeter
Information Security Forum
0:00 / 0:00
355: Eric O'Neill – Hackers Don't Break In, They Log In: Trust as the New Perimeter
34 просмотра · 8 дней назад
Information Security Forum
939 подписчиков
34 просмотра · 8 дней назад
Dark web cybercrime is now estimated at over $12 trillion, larger than most national economies, yet most organisations still have not budgeted to defend against it.
In this episode, former FBI counterintelligence operative Eric O'Neill joins Steve Durbin to explore why every major breach still comes down to a human decision, not a technical one.
You'll learn:
• Why dark web cybercrime now outstrips most national economies
• Why the same three recruitment methods used on Cold War spies still work today
• How North Korea has used fabricated remote employees to infiltrate organisations
• Why attackers increasingly log in rather than break in
Timestamps:
06:03–07:08 Vulnerability assessments and dividing data into compartments
12:46–13:31 Why MFA is still the simplest defence against compromised credentials
13:47–15:36 Vetting high-access hires, including North Korea's fabricated remote employees
21:52–22:44 The PAID methodology: prepare, assess, investigate, decide
22:45–23:33 Trusting your instincts and verifying urgent requests through separate channels
27:53–28:26 Applying PAID to a live incident
29:29–29:44 Revisiting data segmentation as a containment strategy
LEARN MORE ABOUT ISF
The ISF is a leading authority on cyber security and information risk management.
Our research, practical tools and guidance are used by security professionals to help them overcome the wide-ranging security challenges that impact their business today.
🌐 Website: https://isf.securityforum.org/l/65455...
💼 LinkedIn: https://isf.securityforum.org/l/65455...
🤝 Membership: https://isf.securityforum.org/l/65455...
🛠️ Research, tools & services: https://isf.securityforum.org/l/65455...
🎙️ Podcast: https://isf.securityforum.org/l/65455...
#ISF #InformationSecurityForum #CyberSecurity #InsiderThreat #SocialEngineering #Espionage #Cybercrime