Resilient Cyber
Resilient Cyber
  • 103
  • 62 951
Resilient Cyber w Michael Silva Securing Non Human Identities
In this episode we sit down with Michael Silva of Astrix Security to discuss Securing Non-Human Identities (NHI)'s.
- First off, for those unfamiliar with you can you tell us a bit about your background?
- There is a lot of industry hype right now about "Non-Human Identities" or NHI's as they're called, what exactly are NHI's?
- We know that credentials have long been a primary attack vector due to sources like DBIR and others. Why are NHI's getting so much attention now, and how have they been overlooked before?
- What are some key things organizations need to keep in mind when they're thinking about securing NHI's?
- How do NHI's play into things like software supply chain attacks and/or third party risk?
- For folks looking for tooling to help tackle NHI risks, what are some key capabilities to be looking for?
- How do NHIs open gaps in the current security footprint of companies who are already leveraging tools such as SSPM, CNAPP, IGA, etc.
- This is always a good topic to talk about how many of these platforms are monitored by disparate teams and focus more on external threats specific to their vertical, vs the trusted paths opened by the interconnectivity between SaaS, PaaS, IaaS and on prem environments which is a main use case of why NHIs exist.
- Where can folks learn more about Astrix, and what are you all currently excited about that you're working on?
astrix.security/
Переглядів: 254

Відео

Resilient Cyber Show Software Supply Chain Security w Dan Lorenc
Переглядів 2452 роки тому
Resilient Cyber Show Software Supply Chain Security w Dan Lorenc
Resilient Cyber Show Security vs Compliance w Jacob Horne
Переглядів 2972 роки тому
Resilient Cyber Show Security vs Compliance w Jacob Horne
Resilient Cyber Show Cybersecurity in the Boardroom w Bob Zukis
Переглядів 2002 роки тому
Resilient Cyber Show Cybersecurity in the Boardroom w Bob Zukis

КОМЕНТАРІ

  • @fredscholl5250
    @fredscholl5250 18 днів тому

    I met Daniel at conference last week. This is a very good overview of ADR and how it fits into the cybersecurity architecture.

  • @adamdedelva352
    @adamdedelva352 Місяць тому

    Thanks Chris & Resilient Cyber team for having Omkhar on the channel. Excited to see where openSSF goes with his recent retirement.

  • @DeathDirector
    @DeathDirector 3 місяці тому

    You know why army recruitment is failing? no one wants to work for a woke/dei army. you know why marines aren't failing? because they are tougher/more hard ass and that's what the people want. Get rid of dei/trans ppl in the army/get rid of soft drill sergeants/bring back the shark attack in bootcamp/make a better tougher recruitment ad and I guarantee you you'll have no problem with recruitment

  • @vijayburington3005
    @vijayburington3005 7 місяців тому

    😒 Promo>SM

  • @kolinhodgson286
    @kolinhodgson286 9 місяців тому

    Great session. I hear "Compliance Vs Security" complaints almost daily. Common examples: Requiring Password Complexity Vs MFA and pass-phrases and Requiring FIPS 140-2 ("UL Listed") Encryption Vs Almost any encryption from this decade. The fact is that elements of a prescriptive standard are likely to be out of date the day it's published. So if you know how to re-stack controls to achieve security goals, the compliance can hinder security. So as part of the "1%" I think I and my colleagues are justified in complaining. But I also agree that this is not a reason to abandon standards, nor an argument to not follow them. My hope is that auditors are well-versed enough in the controls that they recognize that the real goal is effective security and not compliance. Compliance is a tool, not a goal. I agree with most of what you said and I learned a lot too! Thanks to you both for getting this "out there". I liked the cooking metaphor except that I think it's OK to make substitutions in cooking, just like you use compensating controls in security. Bomba rice and Saffron might not be available to me, but I think I still deserve Paella every now and then!

  • @goproslowyo
    @goproslowyo Рік тому

    Thanks, interesting conversation!

  • @wrkeith1
    @wrkeith1 Рік тому

    'Next Phase' internet?

  • @yestervue4697
    @yestervue4697 Рік тому

    Wow, a field of expertise I am very experienced with. Who'd a thunk!

  • @littleflowerpatriot8957
    @littleflowerpatriot8957 Рік тому

    I'm listening per recommendation of Ezra.

  • @ezra1064
    @ezra1064 Рік тому

    "PromoSM"

  • @jackiecole6717
    @jackiecole6717 2 роки тому

    😢 ρгό𝔪σŞm