
Network detection and response (NDR): the value of evidence
mnemonic security podcast
02/06/23
•33m
About
Comments
Featured In
Network detection and response (NDR): the value of evidence
What exactly is NDR, how have these technologies changed over the years, and are they more relevant now than ever?
To help answer these questions, Robby is joined by Jean Schaffer. She’s had, to say the least, an interesting career with more than 33 years of experience from the US Department of Defense. Including managing the network of the NSA, and holding the position of CISO of the Defense Intelligence Agency. Currently she’s the Federal CTO at Corelight, an open-source network detection and response company.
During their conversation, they talk about the differences, limitations and benefits of EDR and NDR, what evidence based detection really is, and President Biden’s Executive Order on Improving the Nation's Cybersecurity.
She also shares some of the most common pain points she’s observed that organisations are looking to solve, as well as go into how the adaption of cloud affects the value of NDR, and her take on the future of NDR.
Previous Episode

ICS in the Cloud
January 23, 2023
•35m
Industrial Control Systems (ICS) in the cloud
Can the cloud fundamentally revolutionise Operational Technology (OT) security?
To help Robby understand some of the nuances of OT security and help connect the dots between IT and OT, we’re joined by Vivek Ponnada from the OT, ICS & IoT security company Nozomi Networks.
Vivek shares from his 24 years of experience working with ICS, and explains how much cloud is and is going to be utilised within OT in the years to come.
He also shares what threats he is seeing in the OT space, as well as some examples of what’s up-and-coming in OT security
Next Episode

Insider threats to ransomware groups
February 20, 2023
•30m
What happens when cyber criminals don’t get what they believe they're owed?
For this episode, Robby is joined by John Fokker, Head of Trellix Threat Intelligence. John shares from his long experience fighting cybercrime, where he among other places has worked for the Dutch National High-Tech Crime Unit (NHTCU), the Dutch National Police unit dedicated to investigate advanced forms of cybercrime. John was also one of the co-founders of the NoMoreRansom Project.
They discuss John’s encounter with an insider in a ransomware group, the valuable information these situations provide the security community, and what we have learned from them.
John also talks about how cybercrime has changed during his career, and how the war in the Ukraine has affected organised cybercrime.
If you like this episode you’ll love
Promoted




