Illuminating Data Blind Spots, Topic, Enterprise News - Tony Kelly - ESW #437
Get every episode summarized
Each time Enterprise Security Weekly (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
Interview Segment: Tony Kelly
Illuminating Data Blind Spots
As data sprawls across clouds and collaboration tools, shadow data and fragmented controls have become some of the biggest blind spots in enterprise security. In this segment, we'll unpack how Data Security Posture Management (DSPM) helps organizations regain visibility and control over their most sensitive assets.
Our guest will break down how DSPM differs from adjacent technologies like DLP, CSPM, and DSP, and how it integrates into broader Zero Trust and cloud security strategies. We'll also explore how compliance and regulatory pressures are shaping the next evolution of the DSPM market—and what security leaders should be doing now to prepare.
Segment Resources:
https://static.fortra.com/corporate/pdfs/brochure/fta-corp-fortra-dspm-br.pdf
This segment is sponsored by Fortra. Visit https://securityweekly.com/fortra to learn more about them!
Topic Segment: We've got passkeys, now what?
Over this year on this podcast, we've talked a lot about infostealers. Passkeys are a clear solution to implementing phishing and theft-resistant authentication, but what about all these infostealers stealing OAuth keys and refresh tokens? As long as session hijacking is as simple as moving a cookie from one machine to another, securing authentication seems like solving only half the problem. Locking the front door, but leaving a side door unlocked.
After doing some research, it appears that there has been some work on this front, including a few standards that have been introduced:
- DBSC (Device Bound Session Credentials) for browsers
- DPoP (Demonstrating Proof of Possession) for OAuth applications
We'll address a few key questions in this segment: 1. how do these new standards help stop token theft? 2. how broadly have they been adopted?
Segment Resources:
- FIDO Alliance White Paper: DBSC/DPOP as Complementary Technologies to FIDO Authentication
News Segment
Show Notes: https://securityweekly.com/esw-437
Get every episode summarized
Each time Enterprise Security Weekly (Video) publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Enterprise Security Weekly (Video)
State of the AI SOC, regulating AI, and can AI agents feel pain? - Aqsa Taylor -...
Enterprise Security Weekly (Video)
Measuring the Value of SecOps; BH Interviews with Fortra, Helmet, Above, & Keepe...
Enterprise Security Weekly (Video)
Cyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob S...
Enterprise Security Weekly (Video)
Safely exploiting vulnerabilities at scale, TVs attack privacy, and the news. -...
Enterprise Security Weekly (Video)