DiscoverFIRST Impressions Podcast
FIRST Impressions Podcast
Claim Ownership

FIRST Impressions Podcast

Author: FIRST.Org

Subscribed: 4Played: 25
Share

Description

The FIRST Impressions podcast brings you regularly scheduled content focused on discussions from across the incident response and security spectrum. Hosted by Chris John Riley and Martin McKeay, new episodes released first Friday of the month!
62 Episodes
Reverse
Recorded live at FIRSTCON26 in Denver, Colorado, this episode of FIRST Impressions features an interview with John Hollenberger of Fortinet to discuss his FIRSTCON26 presentation on ChaosStack, a fresh approach to tabletop exercises designed to better prepare incident response teams for real-world crises. Rather than following a traditional step-by-step scenario, John explains how ChaosStack intentionally overwhelms participants with multiple competing events at the outset, mirroring the uncertainty, pressure, and decision fatigue that security teams face during actual incidents. Topics discussed include: why traditional tabletop exercises often fail to recreate the realities of incident response; how the ChaosStack methodology introduces multiple simultaneous "injects" to simulate competing priorities and high-pressure decision making; the importance of helping teams learn how they collaborate under stress, and more! The conversation highlights an important takeaway: incident response isn't just about technical expertise, it's about how people communicate, collaborate, and make decisions when the pressure is at its highest.
Recorded live at FIRSTCON26 in Denver, Colorado, this episode of FIRST Impressions, interviews Tim Brown, CISO-in-Residence at Team8 and former CISO of SolarWinds, following his opening keynote at the conference. Drawing on his firsthand experience leading SolarWinds through one of the most significant cyber incidents in recent history, Tim offers an honest and deeply personal conversation about what happens after the headlines fade. Topics discussed include: How Team8 partners with a global community of CISOs to identify security challenges and launch innovative cybersecurity startups; the realities of leading an organization through the SolarWinds incident, from the initial crisis response to years of recovery; the often-overlooked human impact of major cyber incidents, including prolonged stress, burnout, and the emotional toll on security teams; lessons learned and more! Tim closes with an encouraging message for incident responders: while crises are never easy, they are also opportunities for growth. The experiences gained through responding to difficult incidents can shape stronger leaders, stronger teams, and ultimately a stronger cybersecurity community.
Recorded live at FIRSTCON26 in Denver, Colorado, this episode of FIRST Impressions, features an interview with Chris Butera, acting Executive Assistant Director for Cybersecurity at CISA (Cybersecurity and Infrastructure Security Agency), the local host of the conference. Chris shares how CISA serves as America’s cyber defense agency, protecting federal, state, local, tribal, and territorial government systems while working closely with industry partners across the cybersecurity ecosystem. The conversation explores the rapidly evolving vulnerability landscape, including, the growth of the CVE Program from 26 CVE Numbering Authorities to more than 500 worldwide; why CVEs remain the authoritative global system for identifying and tracking software vulnerabilities; the role of Software Bills of Materials (SBOMs) in managing software supply chain risk; new efforts to create AI-specific SBOM standards through the G7 AI SBOM Minimum Elements initiative, and more! Take a practical look at how vulnerability management, supply chain security, AI governance, and workforce development are becoming increasingly interconnected, and why these initiatives matter to every organization operating in today’s threat environment.
Rapidly approaching, the EU Cyber Resilience Act (CRA) is set to reshape how manufacturers develop, secure, and support digital products. In this episode of the First Impressions Podcast, Mars Cheng of TXOne Networks breaks down what the CRA means for organizations that want to sell products in the European market and why the regulation is being called one of the most significant cybersecurity compliance initiatives in years. Previewing his FIRSTCON26 talk, the discussion covers practical steps companies can take today, including stakeholder alignment, tabletop exercises, internal reporting processes, and compliance planning.
In this episode of First Impressions, Julie Agnes Sparks and Greg Foss of Datadog discuss the growing wave of SaaS-focused attacks, from credential theft and supply chain compromises to large-scale data exfiltration campaigns targeting platforms like Salesforce, GitHub, and other cloud services. They explore the visibility gaps that make these incidents difficult to detect, the challenges of monitoring non-human identities and API-driven access, and why many organizations are overlooking some of their most valuable security telemetry.
loading
Comments