Prowling: Better Penetration Testing, at Converge 2018

Archive for the ‘Videos’ Category

Prowling: Better Penetration Testing, at Converge 2018

Posted by

“But we passed our penetration test,” the person handling the security breach groaned. “How come they missed this?” Since the late 1960s, penetration testing has been about two things: demonstrating that the system can be broken into and finding some vulnerabilities. But, by now? We all know systems can be broken into. The shock and surprise are gone. And we all know there are vulnerabilities. Scores of vulnerabilities. Too many vulnerabilities. In fact, arguably today’s penetration testing doesn’t even identify a fraction of the vulnerabilities. This session will review the state of testing strategies and present predictions on where penetration testing should go in the future.

Watch more videos on my YouTube channel.

Zero to Ninety in Securing DevOps

Posted by

RSA: DevOps Connect, Hosted by Courtney Kissler

As DevOps continues to be adopted across industries, IT security and application security professionals are being asked to secure the workflow and products. And we get asked to evaluate, recommend, and implement security controls well after the DevOps team has been established. Sometimes, months or even years after the team has launched. This talk speaks to that audience, sharing practices on how to start off strong. Approaches for building relationships, creating intuition, and becoming a trusted partner will be discussed and demonstrated. It is imperative we add security without taking away speed and agility, and the first 90-days is a crucial period.

Watch more videos on my YouTube channel.