Episode 438: Andy Powell on Lessons Learned from a Major Cyber Attack

Topics covered
Popular Clips
Episode Highlights
Risk Management
Andy Powell, the CISO of AP Moller Maersk, outlines essential principles for managing cybersecurity risks. He emphasizes the importance of understanding risks and vulnerabilities, highlighting the need for visibility to identify where these risks lie. Powell explains that companies must develop operational capabilities to proactively and reactively handle events, likening a security operations center to a "goalkeeper" that ensures processes can continue during disruptions 1.
You need a goalkeeper who can operate the processes and ensure things can work if they were disrupted.
---
Additionally, he stresses the significance of a "secure by design" approach, which, when balanced with risk and operational capabilities, positions a company well against cyber threats 2.
Preparedness
Preparedness for cyber attacks is crucial, as Andy Powell notes that it's only a matter of time before any company faces such a threat. He advises companies to focus on three key areas: understanding the inevitability of attacks, building robust defenses, and learning from past incidents to improve future responses 3.
It's only a matter of time before you get hit by any major company or small startup could get hit by a cyber attack.
---
Priyanka Raghavan reflects on the value of case studies in understanding cyber threats, emphasizing that learning from real-world examples can significantly enhance a company's preparedness 4.
Related Episodes


SE Radio 648: Matthew Adams on AI Threat Modeling and Stride GPT
Answers 383 questions

Episode 535: Dan Lorenc on Supply Chain Attacks
Answers 383 questions

Episode 395: Katharine Jarmul on Security and Privacy in Machine Learning
Answers 383 questions

Episode 385: Evan Gilman and Doug Barth on Zero-Trust Networks
Answers 383 questions

416: Adam Shostack on Threat Modeling
Answers 383 questions

Episode 378: Joshua Davies on Attacking and Securing PKI
Answers 383 questions

Episode 541: Jordan Harband and Donald Fisher on Securing the Supply Chain
Answers 383 questions

Episode 457: Jeffery D Smith on DevOps Anti Patterns
Answers 383 questions

Episode 134: Release It with Michael Nygard
Answers 383 questions

SE-Radio Episode 314: Scott Piper on Cloud Security
Answers 383 questions

SE-Radio Episode 247: Andrew Phillips on DevOps
Answers 383 questions

Episode 514: Vandana Verma on the Owasp Top 10
Answers 383 questions

SE-Radio-Episode-309-Zane-Lackey-on-Application-Security
Answers 383 questions
Episode 122: Interview Janos Sztipanovits
Answers 383 questions

Episode 526: Brian Campbell on Proof of Possession Defenses
Answers 383 questions














