<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet href="https://rss.buzzsprout.com/styles.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:psc="http://podlove.org/simple-chapters" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <atom:link href="https://rss.buzzsprout.com/1927024.rss" rel="self" type="application/rss+xml" />
  <atom:link href="https://pubsubhubbub.appspot.com/" rel="hub" xmlns="http://www.w3.org/2005/Atom" />
  <title>Sedara&#39;s Cybersecurity Podcast</title>

  <lastBuildDate>Sun, 17 May 2026 12:02:18 -0400</lastBuildDate>
  <link>https://www.buzzsprout.com/1927024</link>
  <language>en-us</language>
  <copyright>© 2026 Sedara&#39;s Cybersecurity Podcast</copyright>
  <podcast:locked>yes</podcast:locked>
    <podcast:guid>fcccd584-4295-588b-bd47-ffd19634cf59</podcast:guid>
  <itunes:author>Sedara</itunes:author>
  <itunes:type>episodic</itunes:type>
  <itunes:explicit>false</itunes:explicit>
  <description><![CDATA[]]></description>
  <generator>Buzzsprout (https://www.buzzsprout.com)</generator>
  <itunes:owner>
    <itunes:name>Sedara</itunes:name>
  </itunes:owner>
  <image>
     <url>https://storage.buzzsprout.com/3nixwqxfgvjktmlx12b4ldcmkmq7?.jpg</url>
     <title>Sedara&#39;s Cybersecurity Podcast</title>
     <link></link>
  </image>
  <itunes:image href="https://storage.buzzsprout.com/3nixwqxfgvjktmlx12b4ldcmkmq7?.jpg" />
  <itunes:category text="Technology" />
  <item>
    <itunes:title>Introduction to Information Security: What is a CISO? - Sedara Whiteboard Series</itunes:title>
    <title>Introduction to Information Security: What is a CISO? - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[A Chief Information Security Officer (CISO) is the tip of the spear for an organization’s cybersecurity program. CISOs identify threats, manage risk, implement security controls, and increase organizational resiliency. Sedara has several “virtual” CISOs (vCISOs) who split their time serving as CISOs for different organizations. This podcast covers what CISOs do and how they protect your organization’s most valuable assets.  Sedara has vCISOs available to take an organization’s cybersecurity p...]]></itunes:summary>
    <description><![CDATA[<p>A Chief Information Security Officer (CISO) is the tip of the spear for an organization’s cybersecurity program. CISOs identify threats, manage risk, implement security controls, and increase organizational resiliency. Sedara has several “virtual” CISOs (vCISOs) who split their time serving as CISOs for different organizations. This podcast covers what CISOs do and how they protect your organization’s most valuable assets.<br/><br/>Sedara has vCISOs available to take an organization’s cybersecurity program to the next level. They provide ongoing supervision and support and advise about threats, risk, security controls, and resiliency strategies. <a href='https://www.sedarasecurity.com/contact/'>Contact Sedara today</a> to learn how a vCISO can help your organization.</p>]]></description>
    <content:encoded><![CDATA[<p>A Chief Information Security Officer (CISO) is the tip of the spear for an organization’s cybersecurity program. CISOs identify threats, manage risk, implement security controls, and increase organizational resiliency. Sedara has several “virtual” CISOs (vCISOs) who split their time serving as CISOs for different organizations. This podcast covers what CISOs do and how they protect your organization’s most valuable assets.<br/><br/>Sedara has vCISOs available to take an organization’s cybersecurity program to the next level. They provide ongoing supervision and support and advise about threats, risk, security controls, and resiliency strategies. <a href='https://www.sedarasecurity.com/contact/'>Contact Sedara today</a> to learn how a vCISO can help your organization.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/12069395-introduction-to-information-security-what-is-a-ciso-sedara-whiteboard-series.mp3" length="11051361" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/427v20pyiltrq82x9al2x128wddj?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-12069395</guid>
    <pubDate>Wed, 18 Jan 2023 11:00:00 -0500</pubDate>
    <itunes:duration>914</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>10</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Security Awareness - Sedara Whiteboard Series</itunes:title>
    <title>Security Awareness - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[Why is security awareness important when we have all of these appliances and software and hardware to protect us? Well, ultimately, attacks come down to a set of human eyes and a keyboard, and a mouse. And if a user is well educated and if they're trained well and they're astute, they can help prevent a security incident from ever happening or detect it. ]]></itunes:summary>
    <description><![CDATA[<p>Why is security awareness important when we have all of these appliances and software and hardware to protect us? Well, ultimately, attacks come down to a set of human eyes and a keyboard, and a mouse. And if a user is well educated and if they&apos;re trained well and they&apos;re astute, they can help prevent a security incident from ever happening or detect it.</p>]]></description>
    <content:encoded><![CDATA[<p>Why is security awareness important when we have all of these appliances and software and hardware to protect us? Well, ultimately, attacks come down to a set of human eyes and a keyboard, and a mouse. And if a user is well educated and if they&apos;re trained well and they&apos;re astute, they can help prevent a security incident from ever happening or detect it.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/11881030-security-awareness-sedara-whiteboard-series.mp3" length="5374290" type="audio/mpeg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11881030</guid>
    <pubDate>Thu, 15 Dec 2022 17:00:00 -0500</pubDate>
    <itunes:duration>445</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Business Continuity, Disaster Recovery, and Security Incident Response Plan - Sedara Whiteboard Series</itunes:title>
    <title>Business Continuity, Disaster Recovery, and Security Incident Response Plan - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[Incident response is a structured process organizations use to identify and deal with cybersecurity incidents. Response includes several stages, including preparation for incidents, detection and analysis of a security incident, containment, eradication, and full recovery, and post-incident analysis and learning.  What are some tips for making effective plans?  Listen to this episode of Sedara's Whiteboard Series to find out.   Be sure to subscribe to our YouTube channel to get more content. ]]></itunes:summary>
    <description><![CDATA[<p>Incident response is a structured process organizations use to identify and deal with cybersecurity incidents. Response includes several stages, including preparation for incidents, detection and analysis of a security incident, containment, eradication, and full recovery, and post-incident analysis and learning.<br/><br/>What are some tips for making effective plans?<br/><br/>Listen to this episode of Sedara&apos;s Whiteboard Series to find out. <br/><br/>Be sure to <a href='https://www.youtube.com/@sedarasecurity'>subscribe to our YouTube channel</a> to get more content.</p>]]></description>
    <content:encoded><![CDATA[<p>Incident response is a structured process organizations use to identify and deal with cybersecurity incidents. Response includes several stages, including preparation for incidents, detection and analysis of a security incident, containment, eradication, and full recovery, and post-incident analysis and learning.<br/><br/>What are some tips for making effective plans?<br/><br/>Listen to this episode of Sedara&apos;s Whiteboard Series to find out. <br/><br/>Be sure to <a href='https://www.youtube.com/@sedarasecurity'>subscribe to our YouTube channel</a> to get more content.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/11662297-business-continuity-disaster-recovery-and-security-incident-response-plan-sedara-whiteboard-series.mp3" length="5266643" type="audio/mpeg" />
    <link>https://www.sedarasecurity.com/recovery-and-response-plans/</link>
    <itunes:image href="https://storage.buzzsprout.com/cvw19vls5nlql7ck72f3gzl5ll7z?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11662297</guid>
    <pubDate>Wed, 09 Nov 2022 09:00:00 -0500</pubDate>
    <itunes:duration>432</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>9</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>What is Social Engineering? - Sedara Whiteboard Series</itunes:title>
    <title>What is Social Engineering? - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[ Many organizations focus on technological controls to protect their assets. But that’s only part of the story! Smart attackers use social engineering to achieve their goals in compromising networks and data. In a social engineering attack vector, attackers lie or present deceptive fronts to convince people to divulge information or take some action that allows the attackers access.    Sedara offers a phishing assessment, in which we send out communication and assess the rate of “su...]]></itunes:summary>
    <description><![CDATA[<p> Many organizations focus on technological controls to protect their assets. But that’s only part of the story! Smart attackers use social engineering to achieve their goals in compromising networks and data. In a social engineering attack vector, attackers lie or present deceptive fronts to convince people to divulge information or take some action that allows the attackers access. <br/><br/> Sedara offers a <a href='https://www.sedarasecurity.com/services/assessments/'>phishing assessment</a>, in which we send out communication and assess the rate of “success”. We can also include social engineering in our <a href='https://www.sedarasecurity.com/services/penetration-testing/'>penetration testing</a> or security assessments. This service includes a deeper approach, in which we integrate the results of the phishing campaign into our assessment of overall security. <a href='https://www.sedarasecurity.com/contact/'>Please let us know</a> how we can help you! </p>]]></description>
    <content:encoded><![CDATA[<p> Many organizations focus on technological controls to protect their assets. But that’s only part of the story! Smart attackers use social engineering to achieve their goals in compromising networks and data. In a social engineering attack vector, attackers lie or present deceptive fronts to convince people to divulge information or take some action that allows the attackers access. <br/><br/> Sedara offers a <a href='https://www.sedarasecurity.com/services/assessments/'>phishing assessment</a>, in which we send out communication and assess the rate of “success”. We can also include social engineering in our <a href='https://www.sedarasecurity.com/services/penetration-testing/'>penetration testing</a> or security assessments. This service includes a deeper approach, in which we integrate the results of the phishing campaign into our assessment of overall security. <a href='https://www.sedarasecurity.com/contact/'>Please let us know</a> how we can help you! </p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/11542866-what-is-social-engineering-sedara-whiteboard-series.mp3" length="4980724" type="audio/mpeg" />
    <link>https://www.sedarasecurity.com/social-engineering/</link>
    <itunes:image href="https://storage.buzzsprout.com/o0ue867ftyzhuda4dsrt1677hwct?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11542866</guid>
    <pubDate>Fri, 21 Oct 2022 11:00:00 -0400</pubDate>
    <itunes:duration>412</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>8</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>What is the NIST CSF? - Sedara Whiteboard Series </itunes:title>
    <title>What is the NIST CSF? - Sedara Whiteboard Series </title>
    <itunes:summary><![CDATA[Welcome back to the Sedara Whiteboard series. In this episode, we will discuss frequently asked questions about NIST CSF.   The NIST Cybersecurity Framework, developed by the National Institute of Standards and Technology, integrates industry standards and bast practices to help organizations manage their cybersecurity risks. It is widely used across schools, government organizations, and businesses across the globe. Sedara uses the NIST CSF as a basis for testing the posture of an organizati...]]></itunes:summary>
    <description><![CDATA[<p>Welcome back to the Sedara Whiteboard series. In this episode, we will discuss frequently asked questions about NIST CSF. <br/><br/>The NIST Cybersecurity Framework, developed by the National Institute of Standards and Technology, integrates industry standards and bast practices to help organizations manage their cybersecurity risks. It is widely used across schools, government organizations, and businesses across the globe. Sedara uses the NIST CSF as a basis for testing the posture of an organization’s security.<br/><br/>If you found this information helpful, please subscribe to<a href='https://www.youtube.com/channel/UCwY-DEqOX357XVLP3q8xxBA'> our YouTube channel! </a><br/><br/>For more helpful resources, check out <a href='https://www.sedarasecurity.com/resources/'>Sedara Declassified. </a></p>]]></description>
    <content:encoded><![CDATA[<p>Welcome back to the Sedara Whiteboard series. In this episode, we will discuss frequently asked questions about NIST CSF. <br/><br/>The NIST Cybersecurity Framework, developed by the National Institute of Standards and Technology, integrates industry standards and bast practices to help organizations manage their cybersecurity risks. It is widely used across schools, government organizations, and businesses across the globe. Sedara uses the NIST CSF as a basis for testing the posture of an organization’s security.<br/><br/>If you found this information helpful, please subscribe to<a href='https://www.youtube.com/channel/UCwY-DEqOX357XVLP3q8xxBA'> our YouTube channel! </a><br/><br/>For more helpful resources, check out <a href='https://www.sedarasecurity.com/resources/'>Sedara Declassified. </a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/11347250-what-is-the-nist-csf-sedara-whiteboard-series.mp3" length="5059564" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/b0c286g06erwccw4ky5zatvy77jb?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11347250</guid>
    <pubDate>Mon, 19 Sep 2022 16:00:00 -0400</pubDate>
    <itunes:duration>419</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>7</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Identifying a Quality Pentest - Sedara Whiteboard Series</itunes:title>
    <title>Identifying a Quality Pentest - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[In this episode of the Sedara Cybersecurity Whiteboard Series, our Lead Pentester Nick Aures talks about what to look for in a quality pentest. Nick breaks the talk down into 4 key takeaways: A Vulnerability Scan is NOT a PentestHow to identify a qualified vendorWhat you should expect from the engagementWhat you should expect from the reportTake a look, and we hope it's helpful.  If you're finding our content useful, sign up for Sedara Declassified to make sure you get it sent right to you ev...]]></itunes:summary>
    <description><![CDATA[<p>In this episode of the <a href='https://www.sedarasecurity.com/'>Sedara</a> Cybersecurity Whiteboard Series, our Lead Pentester Nick Aures talks about what to look for in a quality pentest. Nick breaks the talk down into 4 key takeaways:</p><ul><li>A Vulnerability Scan is NOT a Pentest</li><li>How to identify a <em>qualified</em> vendor</li><li>What you should expect from the engagement</li><li>What you should expect from the report</li></ul><p>Take a look, and we hope it&apos;s helpful.<br/><br/>If you&apos;re finding our content useful, sign up for <a href='https://www.sedarasecurity.com/resources/'>Sedara Declassified</a> to make sure you get it sent right to you every month, and of course, if we can help you with anything directly, feel free to reach out.</p>]]></description>
    <content:encoded><![CDATA[<p>In this episode of the <a href='https://www.sedarasecurity.com/'>Sedara</a> Cybersecurity Whiteboard Series, our Lead Pentester Nick Aures talks about what to look for in a quality pentest. Nick breaks the talk down into 4 key takeaways:</p><ul><li>A Vulnerability Scan is NOT a Pentest</li><li>How to identify a <em>qualified</em> vendor</li><li>What you should expect from the engagement</li><li>What you should expect from the report</li></ul><p>Take a look, and we hope it&apos;s helpful.<br/><br/>If you&apos;re finding our content useful, sign up for <a href='https://www.sedarasecurity.com/resources/'>Sedara Declassified</a> to make sure you get it sent right to you every month, and of course, if we can help you with anything directly, feel free to reach out.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/11044028-identifying-a-quality-pentest-sedara-whiteboard-series.mp3" length="11068116" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/f1mdb7ikibs0zwuk327uzanvpo93?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-11044028</guid>
    <pubDate>Thu, 28 Jul 2022 14:00:00 -0400</pubDate>
    <podcast:transcript url="https://www.buzzsprout.com/1927024/11044028/transcript" type="text/html" />
    <podcast:transcript url="https://www.buzzsprout.com/1927024/11044028/transcript.json" type="application/json" />
    <podcast:transcript url="https://www.buzzsprout.com/1927024/11044028/transcript.srt" type="application/x-subrip" />
    <podcast:transcript url="https://www.buzzsprout.com/1927024/11044028/transcript.vtt" type="text/vtt" />
    <itunes:duration>919</itunes:duration>
    <itunes:keywords>cybersecurity, business, pen testing </itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>6</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>NIST Compliance Framework - Sedara Whiteboard Series</itunes:title>
    <title>NIST Compliance Framework - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[Why Should I Consider the NIST Cybersecurity Framework(NIST CSF)? The NIST Cybersecurity Framework (NIST CSF) is great for organizations that want to improve their information security maturity. Other organizations may align the framework with other compliance or governance requirements. The NIST CSF has five cyclical functions that cover an organization’s security processes: Identify, Protect, Detect, Respond, and Recover. Regardless of the reason, getting started with the NIST Framework is ...]]></itunes:summary>
    <description><![CDATA[<p><b>Why Should I Consider the NIST Cybersecurity Framework(NIST CSF)?</b></p><p>The NIST Cybersecurity Framework (NIST CSF) is great for organizations that want to improve their information security maturity. Other organizations may align the framework with other compliance or governance requirements. The NIST CSF has five cyclical functions that cover an organization’s security processes: Identify, Protect, Detect, Respond, and Recover.</p><p>Regardless of the reason, getting started with the NIST Framework is often the #1 challenge. Against a complex environment, the framework can seem overwhelming.</p><p><b>Where Do I Start?</b></p><p>Almost all information security frameworks start with asset management. You can’t secure devices you don’t know about! But asset management doesn’t have to be complete or perfect before moving through the framework.</p><p>Start with the assets you already know about and work with, in your daily operations. For most organizations, this means high impact assets with a low volume of devices. Examples include servers, domain controllers, and firewalls. Asset management doesn’t need to be complicated – it can start with a short, written list. In this post, we’ll use firewalls as an example.</p><p><b>Breaking it down</b></p><p>After you’ve inventoried a category of assets, you can move through the framework and pick the tasks that will best secure it. This can be done by asking what-if questions and documenting the answers. Here are some examples:</p><p><em>Identify / Governance</em></p><p>Who manages the firewall? How often do they manage it? What are they allowed to do? What is the approval process for changes?</p><p><em>Protect / Access Control</em></p><p>Who can log into the firewalls? What level of access do they have and what can they do with that data? Is monitoring in place?</p><p><em>Protect / Maintenance</em></p><p>Who checks for and installs updates? Who reviews release notes? How often is maintenance on the firewall performed?</p><p><em>Detect &amp; Response</em></p><p>How are incidents detected? What is the response plan when an incident is detected?</p><p><em>Recovery</em></p><p>How are backups performed? When a firewall goes down, who is notified and what is the process for getting it back online?</p><p><b>Want to know more about NIST CSF?</b></p><p>Check out<a href='https://www.nist.gov/cyberframework'> this resource</a> for more information about the NIST CSF version 1.1 and to access online learning resources!</p><p><b>Summary</b></p><p>It’s easier to start on the NIST CSF by taking small steps, grouping assets into categories, and documenting the operational processes you already have. Starting with the high-impact, low-volume assets will save valuable time, and makes the biggest impact in improving your organization’s security stance.</p><p><b>How Sedara Can Help with the NIST Cybersecurity Framework</b></p><p><a href='https://www.sedarasecurity.com/'>Sedara</a> helps organizations implement the NIST CSF to improve their cybersecurity programs. Our team will take your information security maturity to the next level with proven methods and expertise.</p><p><a href='https://share.hsforms.com/1eQKHSR4UQO2YQVbGGeyEIAuxid?__hstc=194153074.378a07925e7a62e39080c6ed4c8f3318.1624296408637.1653677250503.1654787086463.47&amp;__hssc=194153074.2.1654787086463&amp;__hsfp=760331027'>Subscribe to Sedara Declassified</a> to get timely updates on new and evolving threats – and what to do about them – just like our clients do.<br/><br/><a href='https://youtu.be/Lj5hsoKC5JU'>Watch this episode </a>on Youtube. </p>]]></description>
    <content:encoded><![CDATA[<p><b>Why Should I Consider the NIST Cybersecurity Framework(NIST CSF)?</b></p><p>The NIST Cybersecurity Framework (NIST CSF) is great for organizations that want to improve their information security maturity. Other organizations may align the framework with other compliance or governance requirements. The NIST CSF has five cyclical functions that cover an organization’s security processes: Identify, Protect, Detect, Respond, and Recover.</p><p>Regardless of the reason, getting started with the NIST Framework is often the #1 challenge. Against a complex environment, the framework can seem overwhelming.</p><p><b>Where Do I Start?</b></p><p>Almost all information security frameworks start with asset management. You can’t secure devices you don’t know about! But asset management doesn’t have to be complete or perfect before moving through the framework.</p><p>Start with the assets you already know about and work with, in your daily operations. For most organizations, this means high impact assets with a low volume of devices. Examples include servers, domain controllers, and firewalls. Asset management doesn’t need to be complicated – it can start with a short, written list. In this post, we’ll use firewalls as an example.</p><p><b>Breaking it down</b></p><p>After you’ve inventoried a category of assets, you can move through the framework and pick the tasks that will best secure it. This can be done by asking what-if questions and documenting the answers. Here are some examples:</p><p><em>Identify / Governance</em></p><p>Who manages the firewall? How often do they manage it? What are they allowed to do? What is the approval process for changes?</p><p><em>Protect / Access Control</em></p><p>Who can log into the firewalls? What level of access do they have and what can they do with that data? Is monitoring in place?</p><p><em>Protect / Maintenance</em></p><p>Who checks for and installs updates? Who reviews release notes? How often is maintenance on the firewall performed?</p><p><em>Detect &amp; Response</em></p><p>How are incidents detected? What is the response plan when an incident is detected?</p><p><em>Recovery</em></p><p>How are backups performed? When a firewall goes down, who is notified and what is the process for getting it back online?</p><p><b>Want to know more about NIST CSF?</b></p><p>Check out<a href='https://www.nist.gov/cyberframework'> this resource</a> for more information about the NIST CSF version 1.1 and to access online learning resources!</p><p><b>Summary</b></p><p>It’s easier to start on the NIST CSF by taking small steps, grouping assets into categories, and documenting the operational processes you already have. Starting with the high-impact, low-volume assets will save valuable time, and makes the biggest impact in improving your organization’s security stance.</p><p><b>How Sedara Can Help with the NIST Cybersecurity Framework</b></p><p><a href='https://www.sedarasecurity.com/'>Sedara</a> helps organizations implement the NIST CSF to improve their cybersecurity programs. Our team will take your information security maturity to the next level with proven methods and expertise.</p><p><a href='https://share.hsforms.com/1eQKHSR4UQO2YQVbGGeyEIAuxid?__hstc=194153074.378a07925e7a62e39080c6ed4c8f3318.1624296408637.1653677250503.1654787086463.47&amp;__hssc=194153074.2.1654787086463&amp;__hsfp=760331027'>Subscribe to Sedara Declassified</a> to get timely updates on new and evolving threats – and what to do about them – just like our clients do.<br/><br/><a href='https://youtu.be/Lj5hsoKC5JU'>Watch this episode </a>on Youtube. </p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/10765097-nist-compliance-framework-sedara-whiteboard-series.mp3" length="8527504" type="audio/mpeg" />
    <link>https://www.sedarasecurity.com/nist-cybersecurity-framework/</link>
    <itunes:image href="https://storage.buzzsprout.com/266waqughot431edy7ypcnf93lmx?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10765097</guid>
    <pubDate>Thu, 09 Jun 2022 11:00:00 -0400</pubDate>
    <itunes:duration>707</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>5</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Cybersecurity Framework for EdLaw 2D Explained  - Sedara Whiteboard Series</itunes:title>
    <title>Cybersecurity Framework for EdLaw 2D Explained  - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[What is Education Law 2-d? Education Law 2-d is a new section to NYS Education Law that was added in early 2020. This section covers various aspects of data privacy for school districts in New York State. It identifies data that exists, how it’s handled, what you’re allowed to do with it, and defines additional security requirements. Ed Law 2-d provides a clear description of student data and personally identifiable information (PII). What are the requirements of Ed Law 2-d? Ed Law 2-d create...]]></itunes:summary>
    <description><![CDATA[<p><b>What is Education Law 2-d?</b></p><p>Education Law 2-d is a new section to NYS Education Law that was added in early 2020. This section covers various aspects of data privacy for school districts in New York State.</p><p>It identifies data that exists, how it’s handled, what you’re allowed to do with it, and defines additional security requirements. Ed Law 2-d provides a clear description of student data and personally identifiable information (PII).</p><p><b>What are the requirements of Ed Law 2-d?</b></p><p>Ed Law 2-d creates specific regulations and controls that school districts are required to abide by. According to the New York State Regional Information Centers and the Ed Law 2-d/Part 121 of the Commissioner’s Regulations outline, schools must follow a multi-faceted approach to information governance, including:</p><p>The protection of PII:</p><p>PII for teachers, students, and principals must be protected</p><p>Parent’s Bill of Rights for Data Privacy and Security:</p><p>Districts must develop and share this information on their website with supplemental information regarding every agreement with a third-party contractor involving the disclosure of PII</p><p>Data Security and Privacy Policy:</p><p>Districts are required to adopt a Data Security and Privacy Policy that adheres to the NIST Cybersecurity Framework (NIST CSF)</p><p>Data Protection Officer:</p><p>It is mandatory to appoint a Data Protection Officer to oversee the execution of Ed Law 2-d responsibilities.</p><p>It is also mandatory to have a complaint process, incident reporting/notification process, annual employee training, and most importantly, map everything back to NIST Cybersecurity Framework.</p><p>NIST CSF is a set of controls that governs aspects of the law and is a risk management program that identifies 1) where there are risks within an organization and 2) the ability to respond and prioritize those risks.</p><p>NIST is a comprehensive United States program that Sedara has been implementing in school districts for years.</p><p><b>The Sedara Approach:</b></p><p>Sedara has spent the last couple of years developing the Cybersecurity Development Program (CDP). A CDP encompasses controls such as NIST and is approachable, scalable, and specific for school districts to obtain and maintain compliance while keeping their data safe.</p><p>The method is designed to understand and factor in the needs, resources, and the existing operations of school districts.</p><p>Sedara’s CDP includes technical and non-technical approaches, and is effective in keeping student data safe This can include incident response, data loss and privacy controls, protection against ransomware, and much more.</p><p>CDP is not designed to replace an existing system - it is designed to augment the investments that have already been made and right-size a program that&apos;s appropriate for a particular school district. CDP brings in the resources - both technical and non-technical - to help deliver on an ongoing basis, making it a cost-effective approach.</p><p><b>How Sedara Can Help</b></p><p>Sedara has worked with school districts all over New York State to help them protect the PII of students, teachers, and staff. We’re experienced with Ed Law 2-d and can help make sure school districts are compliant.</p><p>Don’t take our word for it - check out what other school districts had to say about their experience with the program.</p>]]></description>
    <content:encoded><![CDATA[<p><b>What is Education Law 2-d?</b></p><p>Education Law 2-d is a new section to NYS Education Law that was added in early 2020. This section covers various aspects of data privacy for school districts in New York State.</p><p>It identifies data that exists, how it’s handled, what you’re allowed to do with it, and defines additional security requirements. Ed Law 2-d provides a clear description of student data and personally identifiable information (PII).</p><p><b>What are the requirements of Ed Law 2-d?</b></p><p>Ed Law 2-d creates specific regulations and controls that school districts are required to abide by. According to the New York State Regional Information Centers and the Ed Law 2-d/Part 121 of the Commissioner’s Regulations outline, schools must follow a multi-faceted approach to information governance, including:</p><p>The protection of PII:</p><p>PII for teachers, students, and principals must be protected</p><p>Parent’s Bill of Rights for Data Privacy and Security:</p><p>Districts must develop and share this information on their website with supplemental information regarding every agreement with a third-party contractor involving the disclosure of PII</p><p>Data Security and Privacy Policy:</p><p>Districts are required to adopt a Data Security and Privacy Policy that adheres to the NIST Cybersecurity Framework (NIST CSF)</p><p>Data Protection Officer:</p><p>It is mandatory to appoint a Data Protection Officer to oversee the execution of Ed Law 2-d responsibilities.</p><p>It is also mandatory to have a complaint process, incident reporting/notification process, annual employee training, and most importantly, map everything back to NIST Cybersecurity Framework.</p><p>NIST CSF is a set of controls that governs aspects of the law and is a risk management program that identifies 1) where there are risks within an organization and 2) the ability to respond and prioritize those risks.</p><p>NIST is a comprehensive United States program that Sedara has been implementing in school districts for years.</p><p><b>The Sedara Approach:</b></p><p>Sedara has spent the last couple of years developing the Cybersecurity Development Program (CDP). A CDP encompasses controls such as NIST and is approachable, scalable, and specific for school districts to obtain and maintain compliance while keeping their data safe.</p><p>The method is designed to understand and factor in the needs, resources, and the existing operations of school districts.</p><p>Sedara’s CDP includes technical and non-technical approaches, and is effective in keeping student data safe This can include incident response, data loss and privacy controls, protection against ransomware, and much more.</p><p>CDP is not designed to replace an existing system - it is designed to augment the investments that have already been made and right-size a program that&apos;s appropriate for a particular school district. CDP brings in the resources - both technical and non-technical - to help deliver on an ongoing basis, making it a cost-effective approach.</p><p><b>How Sedara Can Help</b></p><p>Sedara has worked with school districts all over New York State to help them protect the PII of students, teachers, and staff. We’re experienced with Ed Law 2-d and can help make sure school districts are compliant.</p><p>Don’t take our word for it - check out what other school districts had to say about their experience with the program.</p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/10499123-cybersecurity-framework-for-edlaw-2d-explained-sedara-whiteboard-series.mp3" length="3905953" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/fjhfattt5a2sqqh81axkd84xjz13?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10499123</guid>
    <pubDate>Mon, 25 Apr 2022 11:00:00 -0400</pubDate>
    <itunes:duration>322</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>4</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>A Crawl Walk Run Approach to Offensive Security Operations - Sedara Whiteboard Series</itunes:title>
    <title>A Crawl Walk Run Approach to Offensive Security Operations - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[A Crawl, Walk, Run Approach to Offensive Cybersecurity  For the next video in our Whiteboard Series, we talk about a Crawl, Walk, Run Approach to introducing offensive cybersecurity operations to your environment.   What are Offensive Security Operations?   Offensive security operations are about replicating the type of tactics and procedures that real-world hackers are using to penetrate networks. Common forms of offensive security include penetration testing and vulnerability scanning.  Wha...]]></itunes:summary>
    <description><![CDATA[<p><b>A Crawl, Walk, Run Approach to Offensive Cybersecurity<br/></b><br/>For the next video in our Whiteboard Series, we talk about a Crawl, Walk, Run Approach to introducing offensive cybersecurity operations to your environment. <br/><br/><b>What are Offensive Security Operations? <br/></b><br/>Offensive security operations are about replicating the type of tactics and procedures that real-world hackers are using to penetrate networks. Common forms of offensive security include penetration testing and vulnerability scanning.<br/><br/><b>What is Crawl, Walk, Run? <br/></b><br/>A Crawl, Walk, Run Approach is an effective method where you lay out the steps for an organization to start out with the basics, and mature their processes over time. <br/><br/>This approach has been found to be extremely effective when it comes to cybersecurity program maturity.<br/><br/><b>The Crawl Stage: <br/></b><br/>During the “crawl” stage, the I.T. team is spending their time ensuring production is running smoothly, ensuring upgrades are complete, hardware is repaired, end-user tickets are resolved, etc. These tasks consume most of their time.<br/><br/>This is where Sedara sees a lot of organizations struggle with going above and beyond to prepare for an advanced attack. It can seem impossible when a majority of your time is spent putting out fires. <br/><br/>So, what can you do? <br/><br/>There are a few simple things, such as asset discovery. Understanding where your business-critical assets are, whether they are internal, external, or cloud-hosted, is one thing to focus on. <br/><br/>The next step would be a vulnerability scan of those assets. This will provide you with any low-hanging fruit that an attacker might find. Low-hanging fruit to an attacker would be something of high value that is easy to attack. <br/><br/>The next thing you want to do is a basic assessment. At this point, you should have an understanding of where your weaknesses are and which of your business assets are critical. You’ll also want to understand what weakness might look like in your organization. Then, you can move to the “walk” phase.  <br/><br/><b>The Walk Phase: <br/></b><br/>The “walk” phase is where you run a penetration test. <br/><br/>A penetration test takes the vulnerability test one step further. Penetration testing is a controlled form of hacking. You take real-world tactics that attackers would use to simulate a hacker trying to get into your network, systems, and applications through the exploitation of vulnerabilities. <br/><br/>Penetration testing will also help you better understand your external assets. Once you have this understanding, you’re ready to move on to the “run” phase.<br/><br/><b>The Run Phase: <br/></b><br/>If you want to continue to improve the cybersecurity maturity of your organization, consider running a red-team engagement. <br/><br/>A Red-team engagement gauges technical vulnerabilities, business logic flaws, and social engineering. With a red-team engagement, you can also perform advanced remediation, which helps you fix deeper issues, often procedure-related, for lasting cybersecurity improvement.  Overall, this type of engagement can take anywhere from 3-6 months. <br/><br/><b>How Sedara Can Help You <br/></b><br/><a href='https://www.sedarasecurity.com/contact/'><b>Reach out to us</b></a> to learn how we can help prepare your organization for when a threat occurs. <br/><br/>Be sure to follow our Whiteboard Series, and check out our video for more information on offensive security operations. <br/><br/></p>]]></description>
    <content:encoded><![CDATA[<p><b>A Crawl, Walk, Run Approach to Offensive Cybersecurity<br/></b><br/>For the next video in our Whiteboard Series, we talk about a Crawl, Walk, Run Approach to introducing offensive cybersecurity operations to your environment. <br/><br/><b>What are Offensive Security Operations? <br/></b><br/>Offensive security operations are about replicating the type of tactics and procedures that real-world hackers are using to penetrate networks. Common forms of offensive security include penetration testing and vulnerability scanning.<br/><br/><b>What is Crawl, Walk, Run? <br/></b><br/>A Crawl, Walk, Run Approach is an effective method where you lay out the steps for an organization to start out with the basics, and mature their processes over time. <br/><br/>This approach has been found to be extremely effective when it comes to cybersecurity program maturity.<br/><br/><b>The Crawl Stage: <br/></b><br/>During the “crawl” stage, the I.T. team is spending their time ensuring production is running smoothly, ensuring upgrades are complete, hardware is repaired, end-user tickets are resolved, etc. These tasks consume most of their time.<br/><br/>This is where Sedara sees a lot of organizations struggle with going above and beyond to prepare for an advanced attack. It can seem impossible when a majority of your time is spent putting out fires. <br/><br/>So, what can you do? <br/><br/>There are a few simple things, such as asset discovery. Understanding where your business-critical assets are, whether they are internal, external, or cloud-hosted, is one thing to focus on. <br/><br/>The next step would be a vulnerability scan of those assets. This will provide you with any low-hanging fruit that an attacker might find. Low-hanging fruit to an attacker would be something of high value that is easy to attack. <br/><br/>The next thing you want to do is a basic assessment. At this point, you should have an understanding of where your weaknesses are and which of your business assets are critical. You’ll also want to understand what weakness might look like in your organization. Then, you can move to the “walk” phase.  <br/><br/><b>The Walk Phase: <br/></b><br/>The “walk” phase is where you run a penetration test. <br/><br/>A penetration test takes the vulnerability test one step further. Penetration testing is a controlled form of hacking. You take real-world tactics that attackers would use to simulate a hacker trying to get into your network, systems, and applications through the exploitation of vulnerabilities. <br/><br/>Penetration testing will also help you better understand your external assets. Once you have this understanding, you’re ready to move on to the “run” phase.<br/><br/><b>The Run Phase: <br/></b><br/>If you want to continue to improve the cybersecurity maturity of your organization, consider running a red-team engagement. <br/><br/>A Red-team engagement gauges technical vulnerabilities, business logic flaws, and social engineering. With a red-team engagement, you can also perform advanced remediation, which helps you fix deeper issues, often procedure-related, for lasting cybersecurity improvement.  Overall, this type of engagement can take anywhere from 3-6 months. <br/><br/><b>How Sedara Can Help You <br/></b><br/><a href='https://www.sedarasecurity.com/contact/'><b>Reach out to us</b></a> to learn how we can help prepare your organization for when a threat occurs. <br/><br/>Be sure to follow our Whiteboard Series, and check out our video for more information on offensive security operations. <br/><br/></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/10341203-a-crawl-walk-run-approach-to-offensive-security-operations-sedara-whiteboard-series.mp3" length="8445380" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/0slxuugibl7cn9n51o4sbh9bny2x?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10341203</guid>
    <pubDate>Tue, 29 Mar 2022 15:00:00 -0400</pubDate>
    <itunes:duration>700</itunes:duration>
    <itunes:keywords></itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>3</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>MDR vs XDR - Sedara Whiteboard Series</itunes:title>
    <title>MDR vs XDR - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[MDR vs XDR - Key Differences  Managed Detection and Response (MDR) and Extended Detection and Response (XDR) are two solutions designed to help security teams with cybersecurity threats. However, these two methods approach threats in different ways.  In the latest video for our Cybersecurity Whiteboard Series, we go over MDR and XDR, their differences, and why they should matter to you.    MDR Defined and Its Purpose:   MDR, or Managed Detection and Response, is a function or a service t...]]></itunes:summary>
    <description><![CDATA[<p><b>MDR vs XDR - Key Differences<br/></b><br/>Managed Detection and Response (MDR) and Extended Detection and Response (XDR) are two solutions designed to help security teams with cybersecurity threats. However, these two methods approach threats in different ways.<br/><br/>In the latest video for our Cybersecurity Whiteboard Series, we go over MDR and XDR, their differences, and why they should matter to you.  <br/><br/><b>MDR Defined and Its Purpose: <br/></b><br/>MDR, or Managed Detection and Response, is a function or a service that cannot be defined by a single technology. Rather, it is defined by what the intended outcome is supposed to be. <br/><br/>MDR focuses on what threats you want to detect and how you respond to them. It is an external service that focuses on data collection and the ability to investigate and respond.  <br/><br/>First, you want to have the ability to analyze what is happening in your environment, followed by a response plan. Typically, you’re looking to block unfamiliar IP addresses on your firewall or inbound and outbound blocking URLs and your spam or content filter - to name a few examples.  <br/><br/>In short, the goal is to identify if an account is compromised and then disable that account. Afterwards, you would begin your incident response plan to understand if further action is required. <br/><br/><b>XDR Defined and Its Purpose: <br/></b><br/>XDR, also known as Extended Detection and Response, is a strategy-driven approach. Essentially, XDR brings MDR to a new level. <br/><br/>XDR is about enhancing your threat detection, reducing your time to respond, and making your response actions more effective. Ultimately, it is about establishing a stronger security program and automated data enrichment. <br/><br/>Automated data enrichment is about thinking of all the data you’re collecting and how you understand it. <br/><br/>One of the most important aspects of XDR is the ability to view what is not changing within your cybersecurity system and understand how it applies to things that are changing constantly. <br/><br/><b>MDR vs XDR: <br/></b><br/>Both MDR and XDR assist security teams around increasing workloads. MDR essentially provides an external Security Operations Center (SOC) that performs a majority of duties necessary to protect your IT assets. <br/><br/>XDR, on the other hand, enhances your threat detection, reduces your time to respond, and makes your response actions more effective. Together, this is an efficient way to manage threats and respond appropriately. <br/><br/><b>How Sedara Can Help You: <br/></b><br/>Sedara was founded on the principle that cybersecurity monitoring must have detection capabilities and response capabilities built into it. We’ve been doing MDR and XDR for over a decade now. <br/><br/>If you’re looking to strengthen your cybersecurity operations, <a href='https://www.sedarasecurity.com/contact/'>contact Sedara today. </a></p>]]></description>
    <content:encoded><![CDATA[<p><b>MDR vs XDR - Key Differences<br/></b><br/>Managed Detection and Response (MDR) and Extended Detection and Response (XDR) are two solutions designed to help security teams with cybersecurity threats. However, these two methods approach threats in different ways.<br/><br/>In the latest video for our Cybersecurity Whiteboard Series, we go over MDR and XDR, their differences, and why they should matter to you.  <br/><br/><b>MDR Defined and Its Purpose: <br/></b><br/>MDR, or Managed Detection and Response, is a function or a service that cannot be defined by a single technology. Rather, it is defined by what the intended outcome is supposed to be. <br/><br/>MDR focuses on what threats you want to detect and how you respond to them. It is an external service that focuses on data collection and the ability to investigate and respond.  <br/><br/>First, you want to have the ability to analyze what is happening in your environment, followed by a response plan. Typically, you’re looking to block unfamiliar IP addresses on your firewall or inbound and outbound blocking URLs and your spam or content filter - to name a few examples.  <br/><br/>In short, the goal is to identify if an account is compromised and then disable that account. Afterwards, you would begin your incident response plan to understand if further action is required. <br/><br/><b>XDR Defined and Its Purpose: <br/></b><br/>XDR, also known as Extended Detection and Response, is a strategy-driven approach. Essentially, XDR brings MDR to a new level. <br/><br/>XDR is about enhancing your threat detection, reducing your time to respond, and making your response actions more effective. Ultimately, it is about establishing a stronger security program and automated data enrichment. <br/><br/>Automated data enrichment is about thinking of all the data you’re collecting and how you understand it. <br/><br/>One of the most important aspects of XDR is the ability to view what is not changing within your cybersecurity system and understand how it applies to things that are changing constantly. <br/><br/><b>MDR vs XDR: <br/></b><br/>Both MDR and XDR assist security teams around increasing workloads. MDR essentially provides an external Security Operations Center (SOC) that performs a majority of duties necessary to protect your IT assets. <br/><br/>XDR, on the other hand, enhances your threat detection, reduces your time to respond, and makes your response actions more effective. Together, this is an efficient way to manage threats and respond appropriately. <br/><br/><b>How Sedara Can Help You: <br/></b><br/>Sedara was founded on the principle that cybersecurity monitoring must have detection capabilities and response capabilities built into it. We’ve been doing MDR and XDR for over a decade now. <br/><br/>If you’re looking to strengthen your cybersecurity operations, <a href='https://www.sedarasecurity.com/contact/'>contact Sedara today. </a></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/10220100-mdr-vs-xdr-sedara-whiteboard-series.mp3" length="9348753" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/rtlwtavuwd5j96b9qigjbb9dsmbt?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-10220100</guid>
    <pubDate>Wed, 09 Mar 2022 15:00:00 -0500</pubDate>
    <itunes:duration>776</itunes:duration>
    <itunes:keywords>cybersecurity, mdr, xdr</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>2</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
  <item>
    <itunes:title>Tiered Approach to Security Maturity: A Crawl Walk Run Approach - Sedara Whiteboard Series</itunes:title>
    <title>Tiered Approach to Security Maturity: A Crawl Walk Run Approach - Sedara Whiteboard Series</title>
    <itunes:summary><![CDATA[Welcome to the first video of Sedara's Whiteboard Series. Our goal for these videos is to educate you about cybersecurity.   In this podcast, Darrick will go over the Tiered Approach to Security Maturity. Darrick Kristich is the Founder and CEO of Sedara.  The SIEM &amp; MDR deployment process can seem overwhelming, especially if your organization lacks experience with this process. There’s a lot to consider, such as understanding exactly what you can expect and the value you will get from th...]]></itunes:summary>
    <description><![CDATA[<p>Welcome to the first video of Sedara&apos;s Whiteboard Series. Our goal for these videos is to educate you about cybersecurity. <br/><br/>In this podcast, Darrick will go over the Tiered Approach to Security Maturity. <a href='https://www.linkedin.com/in/darrickkristich/'>Darrick Kristich</a> is the Founder and CEO of Sedara.<br/><br/>The SIEM &amp; MDR deployment process can seem overwhelming, especially if your organization lacks experience with this process. There’s a lot to consider, such as understanding exactly what you can expect and the value you will get from the process. <br/><br/>In this first podcast of the Sedara Whiteboard Series, we go over a crawl-walk-run methodology to ease into a mature cybersecurity posture. <br/><br/>If you’re looking to get some tangible value out of a system or service, watch this video or read below for some key takeaways.<br/><br/> What is SIEM Technology? <br/><br/>SIEM technology revolves around data collection. It’s about collecting logs, analyzing them, and pulling data through API integrations to understand what is happening in your cybersecurity environment. <br/><br/>The crawl-walk-run-approach:<br/><br/>Crawl <br/><br/>The crawl phase starts with your SIEM ingesting highly critical assets, and sometimes high-value, lower volume assets. What do we mean when we say high-value? We’re referring to the data they are providing. <br/><br/>The primary focus during this stage includes getting visibility into network traffic. This includes firewall logs and directory services. Firewalls and directory services are considered extremely high-value data sources. <br/><br/>In a firewall log, you can expect to get the source, target port, and protocol information. Firewall logs don’t share a lot of information unless it is a unified threat management (UTM) device.  With a UTM device, you can get actual URL destinations and conduct spam filtering.<br/><br/>When examining log sources, it’s crucial to consider:<br/>What data you’re collecting<br/>What intelligence is going to be applied<br/>What are you getting out of it? <br/><br/>One example of a security risk would be if a user adds another domain admin at a time when your employees aren’t usually working. Sedara can detect and respond to this problem by using your SIEM that has collected logs from your domain controllers. <br/><br/>Without putting some sort of intelligence into this, you would not be able to find this significant compromise. <br/><br/><br/>Walk:<br/><br/>The walk phase gets into more complex systems to configure, with higher volumes. <br/><br/>In this phase, workstations are your highest volume assets. The logs from your workstation may not be as important as the logs from your global directory services. However, you can build a significant amount of use cases and alarms from the data. <br/><br/>Obtaining workstation logs can be challenging. However, Sedara has created processes that integrate Windows event forwarding that can be applied in a couple of hours. The volume of data impacts the size SIEM you need.<br/><br/>One reason workstation logs are impactful is because, if an attacker knows you are using a SIEM they will use local accounts to get into your system and stay under the radar from detection.<br/><br/>Starting to isolate and remove devices or killing processes is a great way to start the response process during the walk phase. <br/><br/>As an MDR provider, Sedara can detect and respond to threats on your behalf.<br/><br/>Run: <br/><br/>The run phase can take longer to reach, is typically very high volume, and is fairly sophisticated to implement and manage. The complexity comes into play because you are including robust business applications such as ERP systems, EMR systems, finance systems, and more. <br/><br/></p>]]></description>
    <content:encoded><![CDATA[<p>Welcome to the first video of Sedara&apos;s Whiteboard Series. Our goal for these videos is to educate you about cybersecurity. <br/><br/>In this podcast, Darrick will go over the Tiered Approach to Security Maturity. <a href='https://www.linkedin.com/in/darrickkristich/'>Darrick Kristich</a> is the Founder and CEO of Sedara.<br/><br/>The SIEM &amp; MDR deployment process can seem overwhelming, especially if your organization lacks experience with this process. There’s a lot to consider, such as understanding exactly what you can expect and the value you will get from the process. <br/><br/>In this first podcast of the Sedara Whiteboard Series, we go over a crawl-walk-run methodology to ease into a mature cybersecurity posture. <br/><br/>If you’re looking to get some tangible value out of a system or service, watch this video or read below for some key takeaways.<br/><br/> What is SIEM Technology? <br/><br/>SIEM technology revolves around data collection. It’s about collecting logs, analyzing them, and pulling data through API integrations to understand what is happening in your cybersecurity environment. <br/><br/>The crawl-walk-run-approach:<br/><br/>Crawl <br/><br/>The crawl phase starts with your SIEM ingesting highly critical assets, and sometimes high-value, lower volume assets. What do we mean when we say high-value? We’re referring to the data they are providing. <br/><br/>The primary focus during this stage includes getting visibility into network traffic. This includes firewall logs and directory services. Firewalls and directory services are considered extremely high-value data sources. <br/><br/>In a firewall log, you can expect to get the source, target port, and protocol information. Firewall logs don’t share a lot of information unless it is a unified threat management (UTM) device.  With a UTM device, you can get actual URL destinations and conduct spam filtering.<br/><br/>When examining log sources, it’s crucial to consider:<br/>What data you’re collecting<br/>What intelligence is going to be applied<br/>What are you getting out of it? <br/><br/>One example of a security risk would be if a user adds another domain admin at a time when your employees aren’t usually working. Sedara can detect and respond to this problem by using your SIEM that has collected logs from your domain controllers. <br/><br/>Without putting some sort of intelligence into this, you would not be able to find this significant compromise. <br/><br/><br/>Walk:<br/><br/>The walk phase gets into more complex systems to configure, with higher volumes. <br/><br/>In this phase, workstations are your highest volume assets. The logs from your workstation may not be as important as the logs from your global directory services. However, you can build a significant amount of use cases and alarms from the data. <br/><br/>Obtaining workstation logs can be challenging. However, Sedara has created processes that integrate Windows event forwarding that can be applied in a couple of hours. The volume of data impacts the size SIEM you need.<br/><br/>One reason workstation logs are impactful is because, if an attacker knows you are using a SIEM they will use local accounts to get into your system and stay under the radar from detection.<br/><br/>Starting to isolate and remove devices or killing processes is a great way to start the response process during the walk phase. <br/><br/>As an MDR provider, Sedara can detect and respond to threats on your behalf.<br/><br/>Run: <br/><br/>The run phase can take longer to reach, is typically very high volume, and is fairly sophisticated to implement and manage. The complexity comes into play because you are including robust business applications such as ERP systems, EMR systems, finance systems, and more. <br/><br/></p>]]></content:encoded>
    <enclosure url="https://www.buzzsprout.com/1927024/episodes/9956798-tiered-approach-to-security-maturity-a-crawl-walk-run-approach-sedara-whiteboard-series.mp3" length="11592046" type="audio/mpeg" />
    <itunes:image href="https://storage.buzzsprout.com/bqwc1uqixtzbcrkiwyiok0gjvkq9?.jpg" />
    <itunes:author>Sedara</itunes:author>
    <guid isPermaLink="false">Buzzsprout-9956798</guid>
    <pubDate>Thu, 27 Jan 2022 10:00:00 -0500</pubDate>
    <itunes:duration>963</itunes:duration>
    <itunes:keywords>cybersecurity, security maturity, security, technology</itunes:keywords>
    <itunes:season>1</itunes:season>
    <itunes:episode>1</itunes:episode>
    <itunes:episodeType>full</itunes:episodeType>
    <itunes:explicit>false</itunes:explicit>
  </item>
</channel>
</rss>
