

The ITSPmagazine Podcast
ITSPmagazine, Sean Martin, Marco Ciappelli
Founded in 2015, ITSPmagazine began as a vision for a publication positioned at the critical intersection of technology, cybersecurity, and society. What started as a written publication has evolved into a comprehensive repository for all their content—podcasts, articles, event coverage, interviews, videos, panels, and everything they create.
This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience.
This is where you'll find it all.
This is where Sean Martin and Marco Ciappelli talk about cybersecurity, technology, society, music, storytelling, branding, conference coverage, and whatever else catches their attention. Over a decade of conversations exploring how these worlds collide, influence each other, and shape the human experience.
This is where you'll find it all.
Episodes
Mentioned books

Jul 10, 2024 • 38min
Punch Cards, Steam Engines, 48 Volt Batteries, Platform Engineering, and the AI Revolution: The Ongoing Evolution of Language-Based Software Development | An OWASP AppSec Global Lisbon 2024 Conversation with Oleg Shanyuk | On Location Coverage
Guest: Oleg Shanyuk, Platform Security, Delivery Hero [@deliveryherocom]On LinkedIn | https://www.linkedin.com/in/oleg-shanyuk/____________________________Hosts: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinMarco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________Episode NotesIn this On Location episode, Sean Martin discusses the complexities of application security (AppSec) and the challenges surrounding the integration of artificial intelligence (AI) with Oleg Shanyuk at the OWASP Global AppSec Global conference in Lisbon. The conversation delves into various aspects of AppSec, DevSecOps, and the broader scope of securing both web and mobile applications, as well as the cloud and container environments that underpin them.One of the core topics Martin and Shanyuk explore is the pervasive influence of AI across different sectors. AI's application in coding, for instance, can significantly expedite the development process. However, as Sean Martin highlights, AI-generated code may lack the human intuition and contextual understanding crucial for error mitigation. This necessitates deeper and more intricate code reviews by human developers, reinforcing the symbiotic relationship between human expertise and AI efficiency.Shanyuk shares insightful anecdotes about the history and evolution of programming languages and how AI's rise is reminiscent of past technological shifts. He references the advancement from physical punch cards to assembly languages and human-readable code, drawing parallels to the current AI boom. Shanyuk stresses the importance of learning from past technological evolutions to better understand and leverage AI's full potential in modern development environments.The conversation also explores the practical applications of AI in fields beyond straightforward coding. Shanyuk discusses the evolution of automotive batteries from 12 volts to 48 volts, paralleling this shift with how AI can optimize various processes in different industries. This evolution demonstrates the potential of technology to drive efficiencies and reduce costs, emphasizing the need for ongoing innovation and adaptation.Martin further navigates the discussion towards platform engineering, contrasting its benefits of consistency and control with the precision and customization needed for specific tasks. The ongoing debate encapsulates the broader dialogue within the tech community about finding the right balance between standardization and flexibility. Shanyuk's perspective offers valuable insights into how industries can leverage AI and platform engineering principles to achieve both operational efficiency and specialized functionality.The episode concludes with forward-looking reflections on the future of AI-driven models and their potential to transcend the limitations of human language and traditional coding paradigms. The thoughtful dialogue between Martin and Shanyuk leaves listeners with a deeper appreciation of the challenges and opportunities within the realm of AI and AppSec, encouraging continued exploration and discourse in these rapidly evolving fields.Be sure to follow our Coverage Journey and subscribe to our podcasts!____________________________Follow our OWASP AppSec Global Lisbon 2024 coverage: https://www.itspmagazine.com/owasp-global-2024-lisbon-application-security-event-coverage-in-portugalOn YouTube: 📺 https://www.youtube.com/playlist?list=PLnYu0psdcllTzdBL4GGWZ_x-B1ifPIIBVBe sure to share and subscribe!____________________________ResourcesBret Victor: https://worrydream.com/Learn more about OWASP AppSec Global Lisbon 2024: https://lisbon.globalappsec.org/____________________________Catch all of our event coverage: https://www.itspmagazine.com/technology-cybersecurity-society-humanity-conference-and-event-coverageTo see and hear more Redefining CyberSecurity content on ITSPmagazine, visit: https://www.itspmagazine.com/redefining-cybersecurity-podcastTo see and hear more Redefining Society stories on ITSPmagazine, visit:https://www.itspmagazine.com/redefining-society-podcastAre you interested in sponsoring our event coverage with an ad placement in the podcast?Learn More 👉 https://itspm.ag/podadplcWant to tell your Brand Story as part of our event coverage?Learn More 👉 https://itspm.ag/evtcovbrf Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Jul 9, 2024 • 30min
Cybersecurity Leadership: AL, Burnout, and Success Strategies | A Conversation with Jack Leidecker | The Soulful CXO Podcast with Dr. Rebecca Wynn
Guest: Jack Leidecker, Chief Information Security Officer, GongLinkedIn: https://www.linkedin.com/in/leideckerHost: Dr. Rebecca WynnOn ITSPmagazine 👉 https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/rebecca-wynn________________________________This Episode’s SponsorsAre you interested in sponsoring an ITSPmagazine Channel?👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network________________________________Episode DescriptionIn this episode of the Soulful CXO, host Dr. Rebecca Wynn welcomes Jack Leidecker, the Chief Information Security Officer at Gong. Jack shares insights into his journey into cybersecurity, starting from pentesting and advancing to building robust security and compliance programs in the technology and financial sectors. Additionally, they discuss the importance of attending conferences like DEF CON for cybersecurity professionals, the importance of a responsible approach when using AI in cybersecurity, the need to validate outputs generated by AI systems to ensure accuracy and reliability. This validation process is crucial as it helps in verifying the results and identifying any potential errors or biases in the AI-generated outputs, legal liabilities, and more. Tune in to learn from these top world-class cybersecurity professionals.________________________________ResourcesBalancing Critical Thinking with Professionalism: A Guide to Constructive Feedbackhttps://medium.com/@soulfulcxo/balancing-critical-thinking-with-professionalism-a-guide-to-constructive-feedback-8888542a507fEnhancing Professional Communication: Strategies for Effective Feedback and Collaborationhttps://medium.com/@soulfulcxo/enhancing-professional-communication-strategies-for-effective-feedback-and-collaboration-2f3f3b5f9c38NIST AI Risk Management Frameworkhttps://www.nist.gov/itl/ai-risk-management-frameworkShields Up: Guidance for Corporate Leaders and CEOshttps://www.cisa.gov/shields-guidance-corporate-leaders-and-ceos________________________________Support:Buy Me a Coffee: https://www.buymeacoffee.com/soulfulcxo________________________________For more podcast stories from The Soulful CXO Podcast With Rebecca Wynn: https://www.itspmagazine.com/the-soulful-cxo-podcastITSPMagazine YouTube Channel:📺 https://www.youtube.com/@itspmagazineBe sure to share and subscribe! Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jul 8, 2024 • 1h 9min
Syracuse Grad's Balancing Act: Juggling Multiple Hats from Academia to Entrepreneurship | A Conversation with Gaurav Sarraf | Off the Record with Saman — Student Abroad Podcast
Guest: Gaurav Sarraf, Security Software Engineer II, Lumen TechnologiesOn LinkedIn | https://www.linkedin.com/in/sarrafgsarraf/On Medium | https://sarrafgsarraf.medium.com/________________________________Host: Saman FatimaOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/saman-fatima________________________________This Episode’s SponsorsAre you interested in sponsoring an ITSPmagazine Channel?👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network________________________________Episode DescriptionAre you from India? Wishing to come to the USA for your studies? Is your dream university - Syracuse University? If yes, grab a pen, paper, and water, and you are all good to know everything. From researching the dream university to getting selected and beating the elephant in the room (i.e. the VISA process) to settling up - you need to know EVERYTHING because, at the end of the day, it is a foreign land with a lot of newness, loneliness, and self-dependency.________________________________ResourcesJoin the BBWIC Foundation Community: https://www.bbwic.com/________________________________For more podcast stories from Off The Record With Saman: https://www.itspmagazine.com/off-the-record-with-saman-student-abroad-podcastWatch the video version on-demand on YouTube: https://www.youtube.com/watch?v=0954PDs3hFI&list=PLnYu0psdcllS96iavkI5nQsErJ3795ow6 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jul 6, 2024 • 28min
The Future of Tech and Society at Viva Tech 2024 | An On Location VIVA TECH Conference 2024 Coverage Conversation with François Bitouzet
Guest: François Bitouzet, Managing Director at Viva Technology [@VivaTech]On LinkedIn | https://www.linkedin.com/in/fran%C3%A7ois-bitouzet-180a89/____________________________Host: Marco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________Episode NotesEvent Recap and HighlightsMarco Ciappelli opens the discussion with a warm greeting, reflecting on his recent travel experiences and upcoming conferences. François Bitouzet, the guest of honor, then dives straight into the heart of the Viva Tech 2024 event, providing detailed insights into its scope, significance, and impact.An Overview of Viva TechFrançois explains that Viva Tech is a four-day event held annually in Paris, focusing on bringing together stakeholders in the innovation sphere. This year’s event saw the participation of 155,000 attendees from 120 countries, showcasing thousands of startups, tech leaders from companies like Google and Meta, corporate giants such as Audi and LVMH, as well as public sector representatives.The Unique Format and InitiativesOne of the most distinctive features of Viva Tech 2024 was its two-fold format. For the first three days, the event catered to the B2B audience, allowing startups and investors to network and collaborate. On the final day, it opened its doors to the general public. This approach aimed to make technology accessible to everyone, regardless of their professional background.François highlighted various initiatives like the “100+100” program, where 100 successful business women in tech spent a day mentoring young girls. This not only promoted diversity and inclusion but also inspired the next generation to pursue careers in technology.Focus on AI and Other InnovationsWhile Artificial Intelligence (AI) was a major talking point, François emphasized that the event delved deeper into how AI is shaping different business sectors rather than just focusing on the technology itself. By bringing in sector-specific insights, the event sought to provide a realistic perspective on the current impact and future potential of AI.Memorable Moments and CreativityFrançois shared several memorable moments from the event, including a live Q&A session with Elon Musk, who joined virtually to answer unfiltered questions from the audience. This showcased the raw and authentic engagement the event aims to foster.Another highlight was the collaboration with the European retailer FNAC, which set up a kiosk where speakers could sign books for the attendees. This initiative bridged the gap between traditional formats and modern technology, exemplifying how the old and the new can coexist harmoniously.Looking AheadAs the conversation winded down, Marco and François discussed the future of Viva Tech, hinting at more surprises and creative content for next year. François emphasized the importance of injecting poetry and romance—metaphorically speaking—into the world of tech to retain its human touch and inspirational value.Call to ActionFinally, Marco encouraged listeners to make plans to attend Viva Tech 2025, expressing his excitement about potentially meeting his audience in person. François echoed this sentiment, inviting everyone to experience the blend of innovation, business, and meaningful impact that Viva Tech promises.ConclusionThe episode concluded with both Marco and François expressing their shared optimism for the future of technology and its potential to not only transform industries but also enhance our quality of life. They agreed that events like Viva Tech are crucial in driving this change by making technology accessible, inclusive, and genuinely impactful.____________________________Catch all of our event coverage: https://www.itspmagazine.com/technology-cybersecurity-society-humanity-conference-and-event-coverage____________________________ResourcesLearn more about VIVA TECH 2024: https://vivatechnology.com/____________________________To see and hear more Redefining Society stories on ITSPmagazine, visit:https://www.itspmagazine.com/redefining-society-podcastAre you interested in sponsoring our event coverage with an ad placement in the podcast?Learn More 👉 https://itspm.ag/podadplcWant to tell your Brand Story as part of our event coverage?Learn More 👉 https://itspm.ag/evtcovbrf Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jul 4, 2024 • 4min
Young Frankenstein (or is it Frankenstream or Frankenscheme?) and the AI Revolution | A Musing On the Future of Cybersecurity and Humanity with Sean Martin and TAPE3 | Read by TAPE3
In the hilarious yet insightful tale, join the eccentric Dr. Frankenstream and his quirky assistant Igor, as they bring an AI system to life, only to face unexpected challenges and hilarious missteps. Discover how they, along with cybersecurity expert Inga, navigate the perils of modern technology, reminding us of the crucial balance between innovation and responsibility.________This fictional story represents the results of an interactive collaboration between Human Cognition and Artificial Intelligence.Enjoy, think, share with others, and subscribe to "The Future of Cybersecurity" newsletter on LinkedIn.Sincerely, Sean Martin and TAPE3________Sean Martin is the host of the Redefining CyberSecurity Podcast, part of the ITSPmagazine Podcast Network—which he co-founded with his good friend Marco Ciappelli—where you may just find some of these topics being discussed. Visit Sean on his personal website.TAPE3 is the Artificial Intelligence for ITSPmagazine, created to function as a guide, writing assistant, researcher, and brainstorming partner to those who adventure at and beyond the Intersection Of Technology, Cybersecurity, And Society. Visit TAPE3 on ITSPmagazine. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jul 4, 2024 • 1h 9min
Everyone is Living in Different Parts of the World, but There's Something That Attached Us All together | A conversation with Dalia Najjar | What If Instead? Podcast with Alejandro Juárez Crawford and Miriam Plavin-Masterman
Guest: Dalia Najjar, General Manager at Farouk Systems and Social Entrepreneurship Faculty Leader at Al-Quds Bard College for Arts and SciencesOn LinkedIn | https://www.linkedin.com/in/dalia-najjar-ab212643/On YouTube | https://youtu.be/KBwjaHq3G3c?si=uvUt0EkoSGvnF7Y5Hosts: Alejandro Juárez CrawfordOn ITSPmagazine 👉 https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/alejandro-juarez-crawfordMiriam Plavin-MastermanOn ITSPmagazine 👉 https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/miriam-plavin-masterman______________________Episode IntroductionDalia discusses her experiences in teaching social entrepreneurship and the impact it has on students. She emphasizes the need to identify problems and find solutions that meet the needs of the people we serve. The conversation also touches on the global collaboration and the power of humor in developing connections and innovation. The conversation explores the dynamic nature of truth and the power of constantly re-deriving old truths in new contexts. The conversation also touches on the challenges faced by students in Palestine and the impact of the political situation on their projects. The concept of solidarity and the sense of community that arises from working together to create change is discussed.______________________ResourcesHow to Launch Your Own Social Enterprise – Love the People You Serve: https://youtu.be/CRVtKfnKkfs?si=WBzERS8u7TNxT_Lq______________________Episode SponsorsAre you interested in sponsoring an ITSPmagazine Channel?👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network______________________For more podcast stories from What If Instead? Podcast with Alejandro Juárez Crawford and Miriam Plavin-Masterman, visit: https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/alejandro-juarez-crawford and https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/miriam-plavin-masterman Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jul 4, 2024 • 45min
Elections and Political Stability | Cyber Cognition Podcast with Hutch and Len Noe
Hosts: HutchOn ITSPmagazine 👉 https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/hutchLen Noe, Technical Evangelist / Whitehat Hacker at CyberArk [@CyberArk]On Twitter | https://twitter.com/hacker_213On LinkedIn | https://www.linkedin.com/in/len-noe/______________________Episode SponsorsAre you interested in sponsoring an ITSPmagazine Channel?👉 https://www.itspmagazine.com/sponsor-the-itspmagazine-podcast-network______________________Episode IntroductionIn this episode, Hutch and Len address the growing challenges that increasingly advanced technology poses to the integrity of elections and political stability.______________________ResourcesScarlett Johansson considers legal action against OpenAIhttps://www.wired.com/story/scarlett-johansson-v-openai-could-look-like-in-court/First AI Beauty Pageanthttps://www.wired.com/story/ai-beauty-pageant-world-ai-creator-awards/Microsoft recalls Recall featurehttps://www.zdnet.com/article/microsoft-delays-recall-after-security-concerns-and-asks-windows-insiders-for-help/Fake head transplant websitehttps://www.technologyreview.com/2024/05/23/1092848/that-viral-video-showing-a-head-transplant-is-a-fake-but-it-might-be-real-someday/Doppel fights candidate impersonation for 2024 electionhttps://www.doppel.com/blog/election-security______________________For more podcast stories from Cyber Cognition Podcast with Hutch, visit: https://www.itspmagazine.com/cyber-cognition-podcastWatch the video podcast version on-demand on YouTube: https://www.youtube.com/playlist?list=PLnYu0psdcllS12r9wDntQNB-ykHQ1UC9U Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jul 3, 2024 • 8min
Pedaling Towards The Stars (Read In English) | Stories Sotto Le Stelle Podcast | Short Stories For Children And The Young At Heart
PEDALING TOWARDS THE STARSOne fine day, in the squares of the city of Ciclopoli, large billboards appeared advertising a bicycle race; everyone could participate, from zero years and up. There wasn’t much information, but it suggested that those interested should contact the Association of Bicycles with Wheels, located at Via dei Manubri Number Eight, behind the playground. The citizens got informed. The start was scheduled for the first Saturday of June from the Piazzale of the Astronomical Observatory, next to the Municipal Library. The finish line was at the top of the Hill of Dreams, and the prize was a star for everyone who crossed the finish line. Registrations had already started and, of course, were free for everyone. Many requests for participation were received.There was a lot of talk about the event, and all the inhabitants of Ciclopoli, including animals, wanted to lend a hand. Volunteers were certainly not lacking. Finally, the day of departure arrived, and the city turned into a great festival. There was a lot of chatter from the balconies of the houses and even from the dome of the Astronomical Observatory, where some inhabitants had climbed to watch the start. Spectators from everywhere cheered on the race participants.Kites in bright colors were tied to the tricycles to keep an eye on the kids. In the playground, where the city's permanent puppet theater was located, the puppets peeked out to watch the show themselves; the strings moved, and a round of applause filled the air. The church bells rang in celebration. All the participants were ready at the start with bikes, unicycles, and tricycles, and all together they formed a varied and numerous group.The start took place despite the great confusion. Fortunately, some fawns were on duty along the race route. They had a megaphone and wore special headphones, which worked with voice transmission to communicate with each other. Little clouds in the clear sky acted as flying race assistants, drawing arrows to indicate the path to the runners at each intersection.Shortly after the start, a fawn took the megaphone: “Attention, attention, the grandfather with the green jacket has a flat tire.” Everyone stopped to wait for the tire to be repaired. Shortly after, a second fawn: “Everyone stop! The kid in the yellow shorts needs to pee.” Another brief stop and a little further ahead, the first refreshment stop. Sandwiches, sweets, and fruit were already ready to be distributed, and everyone lined up to refresh themselves. Tall-stemmed flowers wearing multicolored aprons served the cyclists as they arrived. After a great feast, they set off at full speed again. A small hare was running among the bushes at the edge of the road, and a boy in a purple shirt, curious as he was, left the race course to chase it. The nearby fawn took his megaphone: “New communication! Stop, everyone, a cyclist has gone off course,” he hurried to reach him and brought him back to the road. Everyone back on the saddle.Pedaling, pedaling, they reached the great Field of Happiness full of flowers where the grandparents got lost chasing butterflies and the children lay down to rest. Time was passing. “Let's hurry, let's hurry, the top is still far away,” said the grandparents. Owls, marmots, squirrels, and martens began to follow the runners, cheering them on. Meanwhile, the fawn on the lookout: “Help, the grandmother with the pink skirt has fallen,” but fortunately nothing was broken, and the race resumed quickly.The fastest cyclists happily reached the top of the Hill of Dreams in the early afternoon. The rest of the group arrived at sunset when it was already dark. It was later than expected, and at that point, they couldn't return to the city. How could they spend the night up there? They had no supplies, let alone blankets and sleeping bags. The animals following them understood the problem, and from the nearest farmhouse, they procured milk and cheese for everyone. They ate abundantly and, tired, lay down on the grass around the top after parking their bicycles. It was a bit chilly. In the night air, there was a great buzz. The stars were deciding what to do. They held hands and transformed the sky into a great blanket. How wonderful, a great warmth enveloped all the cyclists who fell asleep.Suddenly, while everything seemed calm, first a flash, then a thunder, and a powerful breath as if caused by the breath of a giant from the top of the hill. No fear, it was just the automatic anti-theft alarm to wake the sleeping cyclists. Awake and with their ears well-tuned to listen, they heard a strange tinkling coming from the free parking lot around the curve. This caused a commotion among the race participants, who jumped to their feet and ran towards the parking lot just in time to see some magpies, some real thieves: bicycle thieves. They had just stolen many parts: bolts, bells, chains, handlebars, rims, and spokes, carrying them away in flight. “What a disaster! And now what do we do?” The fawns did not lose heart and with their powerful means available, they sent an S.O.S. to an elderly carpenter, who was also a blacksmith in the nearby village. Received the signal, he didn't hesitate for a moment and left for the rescue with the siren on his work van. Before dawn, all the bicycles, unicycles, and tricycles of every kind had been skillfully and quickly repaired — as best as the situation allowed. But the fact is that from the first to the last, the cyclists were able to set off again towards Ciclopoli. Their means fixed as much as possible, hopping and limping here and there, they went down the descent, and everyone was laughing their heads off.What great fun! Each one carried with them the promised prize in memory of the cycling race on the Hill of Dreams: a shining star and even a piece of the blanket made of the sky from the previous night.And the Magpies?Well, they had been working for years on building their bicycles, and the race with an overnight stay on the hill offered them an opportunity not to be missed. Their bikes were completed, and that very evening, they were seen pedaling towards the sunset and disappearing on the horizon.The End_____________________Each story is currently written and narrated in both Italian (On The Website https://www.storiesottolestelle.com/) and English.The translation from Italian (the original language) to English and the reading of the stories are performed using Generative Artificial Intelligence — which perhaps has a touch of magic... We hope it has done a good job!If you like it, make sure to tell your friends, family, and teachers, and subscribe to this podcast to stay updated. You’ll be able to read or listen to new stories as soon as they become available. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jun 28, 2024 • 10min
The Implications of Generative AI on Digital Identity, Brand Protection, and Content Marketing: A Philosophical and Sociological Reflection | A Musing On Society & Technology with Marco Ciappelli and TAPE3 | Read by TAPE3
This story represents the results of an interactive collaboration between Human Cognition and Artificial Intelligence.Enjoy, think, share with others, and subscribe to the "Musing On Society & Technology" newsletter on LinkedIn.Sincerely, Marco Ciappelli and TAPE3________Marco Ciappelli is the host of the Redefining Society Podcast, part of the ITSPmagazine Podcast Network—which he co-founded with his good friend Sean Martin—where you may just find some of these topics being discussed. Visit Marco on his personal website.TAPE3 is the Artificial Intelligence for ITSPmagazine, created to function as a guide, writing assistant, researcher, and brainstorming partner to those who adventure at and beyond the Intersection Of Technology, Cybersecurity, And Society. Visit TAPE3 on ITSPmagazine. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Jun 28, 2024 • 33min
From Theory to Process to Practice: Cracking Mobile and IoT Security and Vulnerability Management | An OWASP AppSec Global Lisbon 2024 Conversation with Abraham Aranguren | On Location Coverage with Sean Martin and Marco Ciappelli
Guest: Abraham Aranguren, Managing Director at 7ASecurity [@7aSecurity]On LinkedIn | https://www.linkedin.com/in/abrahamaranguren/____________________________Hosts: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinMarco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________Episode NotesIn this On Location episode recorded in Lisbon at the OWASP AppSec Global event, Sean Martin engages in a comprehensive discussion with Abraham Aranguren, a cybersecurity trainer skilled at hacking IoT, iOS, and Android devices. The conversation delves into the intricacies of mobile application security, touching on both the technical and procedural aspects that organizations must consider to build and maintain secure apps.Abraham Aranguren, known for his expertise in cybersecurity training, shares compelling insights into identifying IoT vulnerabilities without physically having the device. By reverse engineering applications, one can uncover potential security flaws and understand how apps communicate with their IoT counterparts. For instance, Aranguren describes exercises where students analyze mobile apps to reveal hardcoded passwords and unsecured Wi-Fi connections used to manage devices like drones.A significant portion of the discussion revolves around real-world examples of security lapses in mobile applications. Aranguren details an incident involving a Chinese government app that harvests personal data from users' phones, highlighting the serious privacy implications of such vulnerabilities. Another poignant example is Hong Kong's COVID-19 contact-tracing app, which stored sensitive user information insecurely, revealing how even high-budget applications can suffer from critical security flaws if not properly tested.Sean Martin, drawing from his background in software quality assurance, emphasizes the importance of establishing clear, repeatable processes and workflows to ensure security measures are consistently applied throughout the development and deployment phases. He and Aranguren agree that while developers need to be educated in secure coding practices, organizations must also implement robust processes, including code reviews, automated tools for static analysis, and third-party audits to identify and rectify potential vulnerabilities.Aranguren stresses the value of pentests, noting that organizations often show significant improvement over multiple tests. He shares experiences of clients who, after several engagements, greatly reduced the number of exploitable vulnerabilities. Regular, comprehensive testing, combined with a proactive approach to fixing identified issues, helps create a robust security posture, ultimately making applications harder to exploit and dissuading potential attackers.For businesses developing apps, this episode underscores the necessity of integrating security from the ground up, continuously educating developers, enforcing centralized security controls, and utilizing pentests as a tool for both validation and education. The ultimate goal is to make applications resilient enough to deter attackers, ensuring both the business and its users are protected.Be sure to follow our Coverage Journey and subscribe to our podcasts!____________________________Follow our OWASP AppSec Global Lisbon 2024 coverage: https://www.itspmagazine.com/owasp-global-2024-lisbon-application-security-event-coverage-in-portugalOn YouTube: 📺 https://www.youtube.com/playlist?list=PLnYu0psdcllTzdBL4GGWZ_x-B1ifPIIBVBe sure to share and subscribe!____________________________ResourcesLeaveHomeSafe Pentest Report: https://7asecurity.com/reports/pentest-report-leavehomesafe.pdfCoverDrop Pentest Report: https://7asecurity.com/reports/pentest-report-coverdrop.pdfWhy You Need a Pentest: https://www.youtube.com/watch?v=oBVTlKrLw-kLearn more about OWASP AppSec Global Lisbon 2024: https://lisbon.globalappsec.org/____________________________Catch all of our event coverage: https://www.itspmagazine.com/technology-cybersecurity-society-humanity-conference-and-event-coverageTo see and hear more Redefining CyberSecurity content on ITSPmagazine, visit: https://www.itspmagazine.com/redefining-cybersecurity-podcastTo see and hear more Redefining Society stories on ITSPmagazine, visit:https://www.itspmagazine.com/redefining-society-podcastAre you interested in sponsoring our event coverage with an ad placement in the podcast?Learn More 👉 https://itspm.ag/podadplcWant to tell your Brand Story as part of our event coverage?Learn More 👉 https://itspm.ag/evtcovbrf Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.


