SS-NEWS-016: Security planning in Mergers and Acquisitions

Episode 16 June 27, 2021 01:02:35
SS-NEWS-016: Security planning in Mergers and Acquisitions
Security Serengeti
SS-NEWS-016: Security planning in Mergers and Acquisitions

Jun 27 2021 | 01:02:35

/

Show Notes

In this episode we discuss three articles.  First, a brief summary of security planning in mergers and acquisitions.  Second, what's most important during a security incident?  Finally, PROCESS GHOSTING!

 

Article 1 - How to Plan Your M&A Security Strategy

Supporting Articles:

Marriott data breach FAQ: How did it happen and what was the impact?

Why Evaluating Cybersecurity Prior to Mergers and Acquisitions is Necessary

 

Article 2 - Mission Critical: What Really Matters in a Cybersecurity Incident

Supporting Articles:

Malware Archaeology Logging Cheat Sheets

NIST 800-61: Computer Security Incident Handling Guide

Amazon AWS S3 Pricing

 

Article 3 - Researchers Uncover 'Process Ghosting' — A New Malware Evasion Technique

Supporting Articles:

Process Doppelganging: New Malware Evasion Technique Works On All Windows Versions

Herpaderping: Security Risk or Unintended Behavior?

Submitted Github issue to allow ProcessHacker to detect these methods of evasion

As always, please subscribe on your favorite podcast app, and rate and review so that other people will come to know and love us as much as our mothers do

Other Episodes

Episode 2

March 22, 2021 00:45:25
Episode Cover

SS-SUBJ-02 - Certifications

Hosted by David Schwendinger and Matthew Keener, welcome to the Security Serengeti! Rather than look at the news this week, instead we take a...

Listen

Episode 23

August 23, 2021 00:45:45
Episode Cover

SS-NEWS-23: How to stop ransomware? Ban payments?

In this week's episode, we end up spending wayyyyy too long talking about a Lawfare article on banning ransomware payments.  We had some other...

Listen

Episode 40

December 19, 2021 00:49:44
Episode Cover

SS-NEWS-40: No Insurance Payout for State Sponsored Attacks

In this episode, we review Lloyd's recent announcement on not covering state sponsored attacks, an article from Anton Chuvakin on SOC technology fails, and...

Listen