Why CISOs Should Care About Cyber Threat Intelligence with Joe Cozzupoli
Everyone wants the CISO to care about their corner of the security landscape, so why is Threat Intelligence any different? Cosive Field CISO Joe Cozzupoli argues that CTI can help CISOs prioritise investments of time and budget, and avoid rabbit-holes that waste time defending against irrelevant threats.
Becoming a FIRST.org Member with Terry MacDonald
Security teams often aspire to become FIRST members, but it can be a long and winding road to get there. In this interview, Terry MacDonald breaks down each stage of the journey and charts a path forward. He says that contrary to what many people think, you don't need to be a rockstar organisation to join FIRST.
CTI-CMM: Improving Cyber Threat Intel Maturity with Colin Connor, Terry MacDonald & Prescott Pym
In this episode of the Cosive podcast, Terry MacDonald and Prescott Pym are joined by CTI-CMM framework co-lead Colin Connor to dive into what the CTI-CMM framework is, why it exists, and how to use it.
Episode #009 - Threat Sharing Communities with Prescott Pym
Cosive Principal Consultant and CTI expert Prescott Pym discusses the how and why of threat sharing communities, including CTIS, the Australian Signals Directorate's national threat sharing program. You'll learn how to get involved in your first threat sharing community, and why you might consider joining a national threat sharing program like CTIS.
Episode #008: Getting Started with Cyber Threat Intelligence (CTI) with Chris Horsley
Can one analyst with zero budget start a Cyber Threat Intelligence (CTI) program?Yes! In fact, you may already have started a small threat intelligence program without even realising it.In this interview with Cosive CTO and renowned CTI expert Chris Horsley we delve into the following questions on how analysts and teams can start a threat intelligence practice with limited resources.
Episode #007: How the NZITF Improves New Zealand's Security Posture with Terry MacDonald
New Zealand Internet Taskforce (NZITF) chairman and Cosive COO Terry MacDonald speaks on all things NZITF, including what the NZITF does, why it was created, and how to get involved. You can see Terry in-person at the NZITF conference on the 13th and 14th of November, 2023.
Episode #006: Securing Medical Devices with Emily Etchell
Ever wondered how medical devices like pacemakers, ventilators, and cochlear implants are protected from threat actors? Emily Etchell is a Security Consultant at Cosive. Previously, Emily worked for Australia's Therapeutic Goods Administration (TGA), focusing on how medical devices can be kept safe from malicious actors. Emily shares her experiences in this podcast, explaining some of the challenges involved with securing medical devices, and how they're currently being overcome.
Episode #005: Security-focused Code Review for Software Developers with Sid Odgers
Cosive's Software Development Lead, Sid Odgers, is a cybersecurity expert who spends his days building secure software. In this podcast you'll learn how Sid approaches code review to make sure that all code shipped to production is secure as well as high-quality. The checklist and tips shared here are language agnostic and will be of use to any software developer who wants to get better at security.
Episode #004: How ChatGPT Could Transform the CTI Analyst Role with Chris Horsley
Cosive CTO Chris Horsley conducted early experiments using ChatGPT to help assign ATT&CK IDs to threat intelligence reports. While the tool won’t replace an experienced analyst as of today, it will likely change the way we do this kind of work.
Episode #003: Securing REST API Endpoints (or How to Avoid Another Optus) with James Cooper
Unless you have been living in a cave on Mars with your eyes shut and your fingers in your ears for the past few weeks, you have probably heard something about a data breach at Australian telecommunications giant Optus.As security mistakes go, the vulnerability reported to have enabled the attack leans toward the more embarrassing side of the scale. If reports are true, Optus has effectively exposed customer data on an endpoint available to the entire internet.While it is plausible that a developer will forget to (re)secure an endpoint once they finish their development work, there are multiple practical steps you can take to catch or mitigate the problem.





