Making vulnerability management and incident response actually work. Also, the News! - Ryan Fried, Beck Norris, José Toledo - ESW #442
About this episode
Segment 1 with Beck Norris - Making vulnerability management actually work
Vulnerability management is often treated as a tooling or patching problem, yet many organizations struggle to reduce real cyber risk despite heavy investment. In this episode, Beck Norris explains why effective vulnerability management starts with governance and risk context, depends on multiple interconnected security disciplines, and ultimately succeeds or fails based on accountability, metrics, and operational maturity.
Drawing from the aviation industry—one of the most regulated and safety-critical environments—Beck translates lessons that apply broadly across regulated and large-scale enterprises, including healthcare, financial services, and critical infrastructure.
Segment 2 with Ryan Fried and Jose Toledo - Making incident response actually work
Organizations statistically have decent to excellent spending on cybersecurity: they have what should be sufficient staff and some good tools. When they get hit with an attack, however, the response is often an unorganized, poorly communicated mess! What's going on here, why does this happen???
Not to worry. Ryan and José join us in this segment to offer some insight into why this happens and how to ensure it never happens again!
Segment Resources:
- [Mandiant - Best practices for incident response planning]
Segment 3 - Weekly Enterprise News
Finally, in the enterprise security news,
- Almost no funding…
- Oops, all acquisitions!
- Changes in how the US handles financial crimes and international hacking
- Mass scans looking for exposed LLMs
- The state of Prompt injection
- be careful with Chrome extensions
- and home electronics from unknown brands
- Is China done with the West?
All that and more, on this episode of Enterprise Security Weekly.
Visit https://www.securityweekly.com/esw for all the latest episodes!
Show Notes: https://securityweekly.com/esw-442
Get every episode summarized
Each time Enterprise Security Weekly (Audio) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Enterprise Security Weekly (Audio)
Shadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, &...
Enterprise Security Weekly (Audio)
Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interview...
Enterprise Security Weekly (Audio)
Can employees safely use AI agents? AI pentesting agent liabilities, and the new...
Enterprise Security Weekly (Audio)
Sandbox Escapes with Rubrik's Zero Labs, AI recorders eroding privacy, and the n...
Enterprise Security Weekly (Audio)