Explorez tous les épisodes du podcast Cyber Security Agony Uncles
| Titre | Date | Durée | |
|---|---|---|---|
| 7th May 2025 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 08 mai 2025 | 00:29:34 | |
In today's episode, experts Stephen and Rich discuss a real Agony Uncles challenge with another of their listeners' questions. I work for a decent-sized retail company. We have a few hundred stores selling all sorts of products. I am fairly senior in the cyber security team, and I'm absolutely petrified by the attacks on M&S, Coop and Harrods. I'm genuinely concerned that we could be next. The thing is, security is the one area where the board have been underinvesting for years, and whilst we have nice shiny shops on the high street, the rest of our operations are held together by duct tape and string. I've been screaming into the void about our lack of tools, processes and manpower on the security front for nearly a year, nothing's improved. Now that we're at dire risk of a cyber attack, how do I tell the business that it's now or never in terms of getting secure? | |||
| 2nd April 2025 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 13 avr. 2025 | 00:31:04 | |
In today's episode, experts Stephen and Rich discuss a real Agony Uncles challenge with another of their listener's questions. I'm a security analyst with 4 years experience. Prior to that I worked in IT infrastructure for 3 years after years of help desk roles . I'm in my early 30's. Now, I'm not getting any younger and feel the need to move into leadership roles, with a view to climbing the corporate ladder in the next couple of years. I've been keeping an eye on LinkedIn and the job boards, to see what my potential career path may look like. Ultimately, I would like to reach a board level role, maybe a CESO or CIO in the next 10 years or so, but what I'm seeing is that the CESO and CIO roles are few and far between, and CESO roles don't seem to either pay well or be very genuine senior roles. What's going on? How does the role have a C-level job title but then often report to IT, CTO's or CFO's? Is the hierarchy in cyber security broken? Do I have a long-term future in cyber? | |||
| 5th March 2025 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 05 mars 2025 | 00:23:16 | |
In this episode of Cyber Security Agony Uncles, Stephen and Rich work through an issue facing one of our listeners. They wrote: "I work as a security engineer for a company that has put out a massive RFP for cybersecurity services. On the surface, it looks like an open competition, and several businesses have been invited to submit proposals. But behind the scenes, the higher-ups have already chosen who’s getting the contract—so much so that the winning vendor actually wrote the RFP themselves, and we even paid them consulting fees to do it. I can’t shake the feeling that the other businesses are wasting their time and resources bidding on something they have no chance of winning. Is it unethical to let them believe they have a shot? Should I find a way to discreetly warn them, or is that just asking for trouble?" Listen in to catch Stephen and Rich offering some guidance on this issue. | |||
| 5th February 2025 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 10 févr. 2025 | 00:31:33 | |
In this episode, Stephen and Rich discuss the following listeners cyber work issue: "I'm the Head of IT in a reasonably large company in Birmingham. The execs hired a cyber security team last summer and they're making my life miserable! They seem to be the department that always says "no!". I get that we need to be secure, but they're demanding so many changes that we can't get through any of our BAU work. They want us to rip out the tools that took forever to implement and now seem to be set on their own agenda. They're not aware of the change and disruption we went through to get where we are, they're just hell-bent on having things their way. It's making my team miserable and we just seem to be constantly clashing with the cyber team. How can we coexist with them? Things seemed to be so much easier before...." | |||
| 15th January 2025 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 21 janv. 2025 | 00:23:44 | |
Stephen and Rich dive into listeners' concerns, offering expert guidance and insights into the world of cybersecurity. This week, they're tackling a tough topic: the challenges of becoming unemployed in this industry. They share tips on how to approach your job search and where to start when looking to re-enter the cybersecurity field. | |||
| 18th December 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 08 janv. 2025 | 00:31:35 | |
Stephen and Rich dive into listeners' concerns, offering expert guidance and insights into the world of cybersecurity. This week, they're tackling a tough topic: the challenges of becoming unemployed in this industry. They share tips on how to approach your job search and where to start when looking to re-enter the cybersecurity field. | |||
| 5th November 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 05 nov. 2024 | 00:31:01 | |
Stephen and Rich answer our viewers' questions. This month... "I'm Head of Security Operations at a retailer. I'm absolutely shitting myself all the time. I don't have incontinence issues, not literally crapping my pants but basically I can't take the stress. We're bombarded from all directions every day. I have no clue if our defences work. I'm crossing my fingers every day. The SOC are mediocre on a good day, mainly because we're a retailer not GCHQ. I'm constantly being tasked with driving down costs to the point where we're under staffed and I'm loosing sleep thinking what the heck do I do, if and when something happens. I can't sleep. I've aged 50 years in 5 years. I guess I'm not cut out for this job but at the same time I worked hard to get to this point and my wife likes to spend money like you'd not believe. She'd probably leave me if I ditched my job or took a demotion. There isn't really a question here. Other than.." Question: Who can cope with this? Please don't tell me it's just me. | |||
| 1st October 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 01 oct. 2024 | 00:26:45 | |
Stephen and Rich answer our viewers' questions. This month... "I'm responsible for budget at one of your competitors, hush, hush. I'm responsible for allocating security practitioners onto projects for our customers. I'm also a senior securities VCSO myself, so not only am I delivering billable work, I oversee the other FTE consultants and make sure they are doing billable work correctly. So many of them aren't good. The business has hired graduates with absolutely no work ethic and I find it hard to resist parachuting in and doing the work myself to fix the problems they're creating. I'm absolutely exhausted. When I go to the business to discuss this, they make out it's a problem with my leadership style but trying to get work out of these grads is like trying to get blood out of a brick. My I also clarify that customers do not know that these are grads, they think that they are senior security practitioners. I'm the only senior and I feel like I'm the proxy for everyones knowledge." Question: What do I do? | |||
| 3rd September 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 03 sept. 2024 | 00:28:59 | |
Stephen and Rich answer our viewers' questions. This month... Question: How can someone with decades of tech industry experience as a software developer, engineering manager, advisor etc., transition into Cyber Security? How can that wealth of experience be applied to a Cyber Security company, to be the most effective and utilised? | |||
| 6th August 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 06 août 2024 | 00:21:46 | |
Agony Aunts Special! Eliza and Rosie answer our viewers' questions. This month... "I'm the Head of IT for a tech company in the UK and I've been tasked with getting everyone back in the office for 4 to 5 days a week. This is not going to go down well with the team." Question: How on earth do I manage this situation? | |||
| 2nd July 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 02 juil. 2024 | 00:21:09 | |
Stephen and Rich answer our viewers' questions. This month... "As the head of our IT department, I'm constantly getting pushed back from the development team about our security protocols being too restrictive." Question: How can we find middle ground that keeps our system secure without stifling innovation and making our developers jobs harder? | |||
| 4th June 2024 - Cyber Security Agony Uncles | th4ts3curity.company | 04 juin 2024 | 00:23:02 | |
Stephen and Rich answer our viewers' questions. This month... "I'm a consultant working in various vCSO roles for multiple companies. Recently, I've noticed a troubling trend. Vendors are blatantly lying to SME's that lack cyber representatives and they're getting away with it. One of my customers recently reduced my hours to just a couple per month because the provider of a prominent tool assured them that they had eradicated all cyber risk. When I tried to explain that this was nonsense, they dismissed it as me trying to hold on to my hours. It feels like Cyber Security is the Wild West. Companies can't use fake eyelashes and mascara ads but in Cyber Security anything seem to go. I'm embarrassed and frustrated." Question: What is happening and how can I address this without looking jealous or like I'm trying to upsell things for myself? | |||
| 7th May 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 07 mai 2024 | 00:28:19 | |
Stephen and Rich answer our viewers' questions. This month... "I work in incidence response, I'm absolutely burnt out, have lost all interest in keeping abreast of the latest security knowledge and I just don't care about cyber anymore. I'm incredibly tempted to just quit and go and do training and awareness or GRC. Something none technical that requires less research and investment. The thing that's stopping me is that I'm a woman and it's such a cliche that women in cyber aren't technical and I don't want to add to those appalling stats but I'm just so tired of this shit. It's so hard and i can't be bothered. From burnt out Becky." Question: What should I do about it? | |||
| 2nd April 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 02 avr. 2024 | 00:33:48 | |
Stephen and Rich answer our viewers' questions. This month... Question: Does a CSO need to be technical to be successful? | |||
| 5th March 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 05 mars 2024 | 00:24:15 | |
Stephen and Rich answer our viewers' questions. This month... "I'm a SESO across the pond in the States. I have a relatively high profile, a ton of followers on LinkedIn. I'm invited to speak at conferences and I've got a great job. However, I cannot shake this feeling that I don't know what I'm doing. I know people talk about imposter syndrome a lot in Cyber Security and I don't think it's that. I genuinely think, no, I know that I'm not very good at my job. My knowledge is superficially deep but my employer keeps me around because of my reasonably high profile. I'm far too into my career to start back at basics with certifications. Also, my employer isn't going to fund certs that somebody new to the industry would be doing, not to mention that would give the game away. I'm just not good at this and nobody has seemed to notice yet!" Question: What do I do? Where do I start? | |||
| 6th February 2024 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 06 févr. 2024 | 00:29:29 | |
Stephen and Rich answer our viewers' questions. This month... "I have recently started working in Cyber Security and while I love the challenge and the constant learning, I can't help but feel the constant pressure to keep up with rapidly advancing technology. It seems like every day there's a new vulnerability or a tac vector to worry about." Question: How do I maintain a healthy work-life balance to prevent burnout in an industry where the stakes are so high and the pace is relentless? | |||
| 5th December 2023 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 05 déc. 2023 | 00:32:01 | |
Stephen and Rich answer our viewers' questions. This month... "I am the Head of Information Security at a company that supplies to the public sector. It is large enough that people should know who we are but dull enough that nobody does. We aren't public sector though. I listen to this podcast and you guys seem pretty switched on. So I hope that you'd think of something that I hadn't yet. I've got a wretched relationship with our CFO. It's safe to say he hates me and this feeling is very much mutual. He is able to squash every aspect of my security strategy. None of which is necessary by the way. In fact a lot of it is basic funding for cyber hygiene. It's baffling how we get the contracts we get. When we literally don't even enforce 2FA. I completely understand that CFO seek to strike a balance between investing enough in Cyber Security to mitigate risks and ensuring cost effectiveness. They often want to understand the justification for Cyber Security budgets and how the organisation can measure the ROI on Cyber Security investments. I get it. I empathise. But he's just being difficult, it's 100% personal but there's no point in me saying this because I have no evidence of it. My entire strategy was denied the same day I had submitted it. Normally it takes 2 or so weeks. I escalated it, was told the ROI wasn't clear, so I resubmitted it and again it was denied. There's a guy in HR who has got funding for in office standing desks and we all work from home! Can you see my frustration! I am actually desperate." Question: Would either of you confront this person? Or is there avenue around this that I could be exploiting but aren't. | |||
| 7th November 2023 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 07 nov. 2023 | 00:27:06 | |
Stephen and Rich answer our viewers' questions. This month... "I'm the Head of Information Security. It's a title in name only because quite frankly I don't have any authority. I'm just the person people point at when things go wrong or when something scary or unrelated crops up int the news. I love my job though but I do find I have a repeat issue, in that I don't seem to get a sign off for any budget ever. I know other none security departments have managed to, so it's not like the company doesn't have the funds or the inclination to spend money. I spoke to your CEO Eliza at a conference about this and she gave me great advice about approaching a topic of budgets in the language of finance and business risk rather than security. I tried this and I still can't get sign off. I'm one of three people in the security team and the burden of responsibility is on my shoulders but I can't get any tooling, can't get more people and it feels kind of pointless. It's almost like I've been in this role to impress our investors because nothing I do seems to work. I'm not asking for the earth, I'm literally asking for vulnerability management of key assets and login and monitoring of key assets first." Question: How can I relay the new fees basic measures in a way that gets me somewhere? | |||
| 5th September 2023 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 05 sept. 2023 | 00:35:00 | |
Eliza and Rich answer our viewers' questions. This month... "I've been in the IT field for 8 years and 2 years ago I transitioned into a Cyber Security consultant role at one of the big four consultancy firms. Whilst I acknowledge that I am not the most experienced, I've been continuously improving and hold a CISSP certification. So here's the dilemma. I was given a small team of direct reports all with the same job title but in a lower pay band than me, or so I thought. During the interview process for a new team member, we agreed on a woman with one years experience in compliance who came through from a training bootcamp. Surprisingly she's being paid the same as me, despite being my direct report and she's earning 15K more than her male colleague with more experience than her. I don't want to jump to conclusions and assume this pay gap is solely because of her gender but it's hard to ignore the possibility. We have ambitious quotas to meet and this situation is causing me a lot of frustration. On one hand I understand that she may need time to gain experience but her pay grade implies a certain level of expertise. I can't help but feel a tinge of jealousy because I worked hard to reach my salary, while it seems she was handed hers. I want to support the women in cyber movement but incidents like this make it challenging. I've considered sharing my thoughts on LinkedIn but I'm worried it might harm my career. I'm so angry and I'm starting to dislike her even though it's not her fault. I've genuinely considered leaving because it feels so unfair." Question: What should I do to handle this situations without driving myself mad with jealousy and how do I stop myself disliking her so much? | |||
| 1st August 2023 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 01 août 2023 | 00:33:15 | |
Stephen and Rich answer our viewers' questions. This month... "I'm new to a company as the Head of IT, it's my second head of IT role but it's the first time I've had Cyber Security in my remit. This is great, and it's one of the reasons I took the role because I'd really like to move into Cyber Security. Some decisions were made prior to me starting, for example their AV & MDR, their not critical national infrastructure. I think that it's overkill, as they both perform similar functions and AV would have been fine. There is no SIEM but there are a bunch of SAS products but there is no security alerting on that. The previous guy put out a tender for a SIEM provider, he selected one but the contract wasn't signed. Needless to say everyone here was onboard with it and I've come in and I'm questioning things. I think if we have a SIEM, great. But who has time to monitor it? Not me. There been a lot of buying here and no use made of those purchases. I've come in and I look like I'm being difficult for the sake of it. I feel I need to take a breath and actually look at the problems before blowing my small budget that was given to the previous trigger happy guy." Questions: Do we kill off the login we currently have? What should I do here? Move forward with SIEM to keep my position politically not literally or trample on it and start again knowing that I'm going to piss off a whole bunch of people? | |||
| 4th July 2023 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 04 juil. 2023 | 00:27:53 | |
Stephen and Rich answer our viewers' questions. This month... "I am the Head of IT in a small organisation and am responsible for all cyber and data protection-related issues, whilst working mainly alone. I have applied for some senior roles in Cyber Security, with no success." Questions: Do I need to go into Cyber Security in a junior role and start at the bottom? Or is there something I could be doing in my current role to evidence my worth to employers for senior roles, such as Head of Cyber or CESO? | |||
| 6th June 2023 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 06 juin 2023 | 00:19:57 | |
Stephen and Rich answer our viewers' questions. This month... "I'm the Head of the new Cyber Security department, and I'm reporting to Head of IT, who's not a problem but some members of his team are quite abrasive. The structure means I find it difficult to hold the IT team accountable, which I consider to be my job." Questions: Is this operating model advisable? Is there a better model? Is it a good idea for Cyber Security to report to IT? If so, why? | |||
| 2nd May 2023 - Cyber Security Agony Uncles | th4ts3cur1ty.company | 02 mai 2023 | 00:24:26 | |
Stephen and Rich answer our viewers' questions. This month... "I'm working at a company that has just been bought by a larger company. I'm staying on and I'm part of the technical M&A project but the buying company is insanely disorganised." Questions: What suggestions do you have to help us to address these problems? | |||