TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    Technology

    Embracing Digital Transformation

    Dr. Darren Pulsipher, Chief Enterprise Architect for Public Sector, author and professor, investigates effective change leveraging people, process, and technology. Which digital trends are a flash in the pan—and which will form the foundations of lasting change? With in-depth discussion and expert interviews, Embracing Digital Transformation finds the signal in the noise of the digital revolution.

    People
    Workers are at the heart of many of today’s biggest digital transformation projects. Learn how to transform public sector work in an era of rapid disruption, including overcoming the security and scalability challenges of the remote work explosion.

    Processes
    Building an innovative IT organization in the public sector starts with developing the right processes to evolve your information management capabilities. Find out how to boost your organization to the next level of data-driven innovation.

    Technologies
    From the data center to the cloud, transforming public sector IT infrastructure depends on having the right technology solutions in place. Sift through confusing messages and conflicting technologies to find the true lasting drivers of value for IT organizations.

    Advertise

    Copyright: © Paidar Productions

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    #183 Data Management in Material Science and Manufacturing Industries Jan 25, 2024
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    In a rapidly evolving technological landscape, leaders from diverse sectors apply data analytics, machine learning, and artificial intelligence to their operations. Today, look deeper at a company driving digital transformation in the manufacturing industry – Ori Yudilevich, the CTO of Materials Zone.

    Bridging the Gap between Physical and Digital in R&D


    Materials Zone is focused on the niche yet significant aspect of material science, specifically in the manufacturing industry. Given the considerable role of materials in product development, effectively managing data becomes crucial. Analogous to a cooking recipe, material science involves a nuanced integration of ingredients (materials) passed through a process to produce the final product.


    However, this area has historically been ad hoc, relying on trial, error, and intuition. Consequently, the knowledge acquired during this process often gets lost due to insufficient documentation or employee attrition. In our modern, interconnected world, where product development processes often span multiple locations, even countries, establishing structured methodologies to prevent knowledge loss is critical.


    One of the techniques highlighted by Yudilevich is addressing the "trucking factor," which suggests that if the only person who knows how to do a particular task got hit by a truck, it could potentially derail the entire project. Hence, having at least one other person aside from the primary individual who can perform the task could lower the team's vulnerability.


    Capturing Complexities of Material Science Data


    The field of material science generates complex data, often unstructured and difficult to capture using traditional data tables and databases sufficiently. To visualize this, consider data as a graph where raw materials turn into end products. The innumerable interactions between the various constituents give rise to multiple unique dimensions within the data.


    Moreover, a seamless translation exists within the manufacturing realm – From the explorative research to the production phase, which demands stabilization and consistency. Collating data from these phases into a unified repository can enhance the R&D process by centralizing information, aiding inter-phase learning, and accelerating new product development.


    Integrating Data Science into Manufacturing


    While data science has permeated many industries, companies focused mainly on product development in the physical world often find setting up dedicated data departments or integrating analytical tools inefficient and costly. This is where Materials Zone's solution comes into play, making data science, machine learning, and statistical tools accessible to businesses unfamiliar with these areas.


    They offer out-of-the-box tools accompanied by webinars and training sessions for easy adoption, thus reducing the barriers to integrating data science into manufacturing practices. Surprisingly, even Fortune 500 companies who lack the necessary digital skills can benefit significantly from such solutions.


    As We Step Forward


    As the product development process becomes more complex and global, the critical nature of systematic data management combined with technological innovation is coming to the fore. Companies like Materials Zone are paving the path, guiding businesses to bridge their physical-digital knowledge gap, bolster their manufacturing practices, and ensure future success.


    For more information, check out https://materials.zone.


    #182 Zero Trust Data Assurance Jan 22, 2024
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    The need for robust data security strategies has grown exponentially in the digital age, becoming a top priority for businesses around the world. Cybersecurity expert and CTO of Walacor, Walter Hancock, offers keen insight into the importance of data integrity and a zero trust approach in current cybersecurity regimes.

    Unmasking Assumptions About Data Security


    In the past, people have had implicit trust that their data is secure and their privacy is protected. However, this trust is often based on an outdated model that no longer aligns with the current technological landscape. The increasing number of data breaches and cyber attacks has made it evident that data security is more critical than ever, and the precautions that were considered adequate in the past may no longer be sufficient.


    Today, data is vulnerable to threats not only from external hackers but also from within organizations. It is essential to understand that a data breach can have significant implications, ranging from financial losses to reputational damage. Therefore, it is crucial to implement a zero-trust approach to data management, which means that every request for access to data must be verified before access is granted. Reliable data audits are also necessary to ensure that the data input matches the output and that there is no unauthorized access to sensitive information.


    Implementing a New Age of Data Security with Walacor


    Walacor provides a unique solution to improve our understanding of data security. They offer an automatic and full-proof audit log that is immutable, meaning that once data is entered, it can never be altered or deleted without being detected. This feature makes it incredibly easy to track every change made to the system, which is critical in maintaining a secure environment.


    By providing transparency and traceability, Walacor's solution helps organizations to meet legal compliance requirements and mitigate risks. For instance, in a legal dispute, an immutable audit log can serve as a reliable source of evidence, as it cannot be tampered with. Furthermore, in the event of a data breach, an immutable audit log can help identify the source of the breach and the extent of damage caused.


    Overall, Walacor's innovative approach to data security, with its 100% immutable audit log, offers a promising solution for organizations looking to enhance their cybersecurity posture.


    Shaping the Future of Data Intelligence


    The increasing risk of data breaches means that we need to move away from using multiple layers of data security to a more integrated data protection solution. This type of solution lays the foundation for a Zero Trust environment, which significantly reduces the risk of cyber threats and vulnerabilities. By adopting this approach, we can streamline our data protection methods and ensure better data integrity.


    The development of data intelligence in the form of data integrity and security opens up new possibilities for digital businesses. Improved data protection methods, better data integrity, and a reduction in potential cyber threats are just a few of the benefits that are set to transform the digital landscape. Among these, the talk of the town is Walacor's unique approach to data integrity and zero trust, which marks a significant milestone in how we approach data security now and in the future.


    Check out more information from (https://walacor.com)https://walacor.com]


    #181 Zero Trust in 5G Jan 16, 2024
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    In the midst of the growing adoption of 5G technologies worldwide, the experts in the recent episode of Embracing Digital Transformation podcast delved into the integral topic of Zero Trust in 5G security. Host Darren Pulsipher welcomed 5G advanced communications expert Leland Brown, VP of Marketing at Trenton Systems Yazz Krdzalic, and Ken Urquhart, a physicist turned cybersecurity professional from Zscaler, to discuss the integration and advancement of 5G technology, along with its challenges and breakthroughs.

    The Expansive 5G Landscape and The Lonely Island Approach


    The world of 5G technology is rapidly evolving, and as a result, there are a lot of insightful discussions taking place around merging Operational Technology (OT) and Information Technology (IT). Yazz Krdzalic describes the concept of the "Lonely Island approach." This approach refers to the tendency of different entities to focus too heavily on solving their individual problems, which has often led to the stalling of growth in custom hardware in telecom infrastructure.


    The need to break away from this individualistic approach and re-establish a collective architectural framework that can scale and flex with different use cases is becoming increasingly apparent. With the emergence of 5G technology, there is a need for a collaborative approach that can accommodate the various requirements of different entities. The collective approach will help to ensure that the infrastructure is flexible and scalable, making it easier for entities to integrate their technologies and applications into the network.


    The discussions around merging OT and IT are also gaining momentum, and it is becoming clear that the collaboration between these two domains is essential for the success of 5G technology. As the technology continues to evolve, it is expected that there will be more debates and discussions around how to take advantage of the opportunities presented by 5G, while also addressing the challenges posed by the emerging technology. Overall, the future of 5G technology looks bright, and the collaboration between different entities will play a critical role in its success.


    Transitioning to Zero Trust Security


    As technology continues to evolve, security concerns have become a growing issue for individuals and organizations alike. In order to address these concerns and ensure a safe and secure environment, a collective architectural framework is needed. This framework includes the implementation of advanced security models, such as Zero Trust Security. However, transitioning to these models is not always easy. It requires letting go of older methods of operating and ensuring that all technological modules are synchronized and functioning properly. In the past, it was the customers who were burdened with the responsibility of integrating all the pieces. Fortunately, with the adoption of a more evolved approach, the onus of integration has been considerably reduced for the customers, making the implementation of Zero Trust Security and other advanced security models a much smoother process.


    Finding The Common Ground In 5G Usage


    The development of 5G technology has been a game-changer in both commercial and military sectors. However, there are specific requirements that differentiate the commercial and military usage of 5G. Commercial deployments of private 5G networks are largely static, whereas military deployments need to be mobile.


    Leland Brown, a prominent expert in the field, has discussed the complexities of finding a common architecture that could cater to both these needs. The challenge was to create a final solution that elegantly fulfilled these requirements. It was important to ensure that the solution was efficient and effective for both commercial and military use cases.


    The development of such solutions is crucial to ensure that 5G technology is utilized to its fullest potential and can cater to the diverse needs of different industries.


    Wrapping up


    The world of technology is constantly evolving and improving, and the advent of 5G technology and Zero Trust security is a testament to this. However, implementing these advancements can be challenging due to technical and cultural obstacles. Thankfully, experts like Leland Brown, Ken Urquhart, and Yaz Krdzalic are working to streamline the integration of 5G technology and Zero Trust security, making the journey towards a safer and more efficient technological future a little easier for everyone. Their insights and expertise are shedding light on the continuous journey of evolution and improvement in the world of technology.


    #180 Generative AI in Higher Education (Revisited) Jan 11, 2024
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    In this week's episode of Embracing Digital Transformation, Darren Pulsipher interviews guest speaker Laura Newey about her fascinating journey through the critically emerging world of Generative AI, particularly in the education sector. Covering the transformation of her teaching experience and enriching her students' learning outcomes through AI, she extensively analyzed adapting to modern education dynamics.

    How Generative A.I. Enhances the Classroom Experience


    Generative AI is rapidly weaving into educational curriculums, impacting how educators approach teaching and fundamentally enhancing the learning experience. According to Newey, this much-debated technology is not merely a form of plagiarism but a brilliant tool that augments and revitalizes educational methodologies. Encouraging students to use A.I. in thinking tasks, she emphasizes fostering and harvesting critical thinking skills in our breakneck digitizing society.


    Rather than lingering as passive participants, she advocates for students to become active players, analyzing the results generated by AI and considering the quality and substance of their input information. The shift underlines the importance of understanding, research, and analysis over mere result generation.


    Transition From Traditional Teaching


    Newey's progressive approach dramatically diverges from the conventional methods that most educators cling onto, especially considering general resistance towards integrating Generative A.I. in educational settings. However, she emphasizes the inevitability and necessity of adopting digitalization for the overall advantage of students.


    Comparing this transition with the initial resistance to utilizing the internet as a teaching tool indicates where we stand today. Generative AI, like any other evolving technology, necessitates incorporation within the curriculum and demands regular updates for relevance in this fast-paced digital landscape.


    Balancing Innovation and Ethics


    With progression and innovation, Newey also addresses the ethical considerations inherent to this change. She shares several instances where students, unknowingly or subtly, submitted AI-generated essays. Thus, she emphasizes educators' need to vigilantly balance technological embracement and ethical usage.


    She firmly believes that students can use A.I. as a productive tool, but the responsibility also falls upon educators to guide them toward maintaining academic integrity simultaneously.


    Conclusion: Paving the Way Towards an A.I. Enhanced Education System


    The incorporation of Generative AI in education, while met with resistance, is a profound indication of the shifting educational landscape. As Newey illustrates, successful integration of AI in education can significantly enhance learning experiences and the development of essential skills, securing our students' readiness for a future shaped by digital transformation.


    #179 Leveraging Generative AI in College Jan 04, 2024
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    In this episode, Darren interviews his daughter who recently completed her first semester in college about her experience using generative AI technology in her academic studies. She describes the challenges and successes associated with utilizing this transformational tool.

    Navigating the Intricacies of Academic Integration with Generative AI


    In the fast-paced world defined by the rapid digital transformation, it is increasingly noticeable how AI constructs are becoming inextricable parts of everyday life. One captivating area where their impact can be felt is in the field of academics. This blog post intends to delve into the potential of generative AI with firsthand experiences from a student, Madeline Pulsipher, at BYU Idaho.


    Applying generative AI assistance such as ChatGPT in academic work reveals exciting possibilities. When utilized responsibly, this powerful tool can provide a digital advantage in brainstorming ideas, generating essay outlines, and self-assessing your work against grading rubrics.


    Generative AI - Tool or Trick?


    The question of whether or not utilizing AI for academic tasks happens to be cheating presents an intriguing aspect. Madeline rightly points out that using AI to facilitate a process or guide along should not be equated with cheating. Cheating would imply composing an essay solely by the AI and taking credit for the unaided work.


    However, we must create distinguishing guidelines as we broach newer technological methods. Defining what constitutes responsible use versus cheating when incorporating AI in academics is an essential task that educational institutions must work on and set formally and strenuously.


    The Efficiency of AI in Self-assessment


    An intriguing usage of AI has stopped everyone in their tracks - self-grading her work based on the established marking rubric before submission. Madeline's experiments with this approach bore fruitful results, with her securing As in all her AI-assisted essays. This signifies the newfound potential of AI to assist not just in mechanical tasks but also in the qualitative improvement of work.


    Prospects and Ongoing Debates


    The use of AI in academic contexts has been debated for quite some time. While it can be a valuable tool for enhancing learning outcomes and improving productivity, it's important to remember that AI cannot replace the human intellect. Every new technology has benefits and drawbacks, and AI is no different.


    Although generative AI can produce content, it lacks the human touch that is essential in communication. It cannot replace human teachers in explaining complex concepts, as it needs the ability to understand the nuances of human conversation. Therefore, while AI can be a valuable asset in certain areas, it must maintain the value of human interaction and expertise.


    Improving Social Interactions


    The COVID-19 pandemic has disrupted the lives of many students beginning their freshman year in college this year. The negative dating trend among teenagers has been further exacerbated during the pandemic. Due to the lack of social interactions, the current generation misses many critical experiences, such as breaking up, first kissing, or asking for another date.


    Madeline sought advice from her friends on how to let down a guy who wanted another date but received conflicting advice. Then, she turned to ChapGPT, an impartial and unemotional AI-powered assistant, for advice. She used ChapGPT's suggestions as a guide to develop her approach.


    This ability to use Generative AI as an advisor rather than a definitive authority will be crucial for the next generation to leverage the power of AI in academic and social situations.


    The Future of AI in Academics


    Various concerns continue to hover around integrating AI into academics - worries about cheating, the lack of established institutional policies, and the possibility of fostering a short-cut culture. However, it is undeniable that generative AI is a tool many students are resorting to, and its full potential within academia still needs to be thoroughly explored.


    Clearly, the stringent line between cheating and appropriate use needs to be carefully charted. But once this line has been established, the success of AI as a tool in academic paradigms looks promising. If wielded correctly, it can become a substantial part of an educational toolkit - shaping competent individuals well-equipped to handle AI in their professional habitats.


    #178 Zero Trust networking with OpenZiti Dec 28, 2023
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    On this episode, Darren interviews Phillip Griffith, a community leader of the open-source project OpenZiti. They discuss the importance of Zero Trust networking in modern IT networks.

    # Unveiling the Dynamics of Zero Trust Networking and Overlay Networks


    As the digital age progresses, the conversation around network security takes a frontline position. In a rapidly evolving digital landscape, Zero-trust networking and Overlay networks are critical strategies for tackling current security challenges. Here, we delve into these concepts, how they shape our digital systems and provide an understanding of their potential benefits and applications.


    A Closer Look at Zero Trust Networking


    Zero-trust networking is a mindset that places security as a prime concern in designing and operating digital systems. Its critical aspect is the presumption of potential threats from every part of the network, irrespective of how secure they may appear. This approach moves away from the traditional fortress-style concept in security and leads to more robust networks that do not rely solely on a single firewall's protection.


    Firstly, the beauty of zero-trust networks lies in their capacity to work effectively and securely, presenting an advantage for software developers and engineers. Security becomes an enabler rather than a hindrance to the software development process. With zero-trust networking, developers can focus on feature development without worrying about blocked ports or consulting network teams—a significant step towards faster market releases.


    Nevertheless, zero-trust networking doesn’t eliminate the need for perimeter defenses or firewalls. The zero trust strategy assumes a possible network compromise; therefore, it calls for defense layering instead of solely relying on elementary perimeter defense.


    The Rise of Overlay Networks


    Amid the rising security threats and data breaches, overlay networks are emerging as an invaluable tool. These software-defined virtual networks provide an extra layer of security compared to underlay networks such as routers or firewalls.


    Overlay networks like VPN and Wireguard allow secure communication between resources even when the underlying network has been compromised. They offer attractive features, like self-reorganization based on conditions, giving them temporary characteristics. These networks also come with options for secure in-application or data system communication—additionally, a clientless endpoint option bolsters user connectivity, requiring no software installation on individual devices.


    Overlay networks provide flexibility concerning deployment. There’s no need to rewrite your application code, as the code for the overlay network can be embedded directly into the application code. Alternatively, a virtual appliance can be deployed instead if you want to avoid altering your application. This convenience, combined with added security, sets overlay networks up as future-proof solutions to network security.


    The Power of ZTN and OpenZiti Solutions


    Zero Trust networking (ZTN) offerings, like Open Zero Trust (Open Ziti), provide competent solutions in zero trust and overlay networking. They deliver robust Zero Trust principles into the field of overlay network solutions.


    ZTN, for instance, brings its identity system to the table, perfect for edge IoT devices unable to access typical identity services. It offers secure data transmission through mutual tunneling and an intelligent routing fabric that determines the most efficient path from point A to point B. On the other hand, Open Ziti facilitates multiple use cases, managing east-west and north-south connections smoothly and securely. It integrates well with service meshes to provide high-level security.


    Thus, adopting such holistic security measures becomes necessary as we step into the digital era. ZTN and OpenZiti present practical solutions for those embracing the Zero Trust model, with advantageous features ranging from identity management to secure connectivity. No doubt, these innovations are setting the benchmarks for network security.


    #177 Zero Trust Data with SafeLiShare Dec 14, 2023
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    During this episode, Darren and SafeLishare CEO Shamim Naqvi discuss how confidential computing can be employed to create managed data-sharing collaborative environments in the cloud.

    The SafelyShare Revolution in Data Sharing and Confidentiality


    Data sharing has always been a key issue when dealing with sensitive and confidential business information. The advanced technological solutions including SafelyShare have been tackling this problem, offering a controlled system for data access without violating data protection. The fundamental basis of this system is "Zero Trust", a unique strategy that doesn't assume trust for anyone and keeps control and monitoring at its core.


    Harnessing the Power of Secure Enclaves


    A critical aspect of SafelyShare's approach is the use of secure enclaves, or trusted execution environments, ensuring a safe space for data sharing, authentication, and management. These enclaves are created with the help of specific confidential computing chipsets that fully enclose the shared data. With encryption practices implemented outside of these enclaves, data can only be decrypted once it enters the enclave, thereby providing an end-to-end encryption policy. The output exiting the enclave is also encrypted, adding another layer of security to protect the data.


    But challenges exist within this process. Not all online services incorporate a secure enclave in their operation, leading to a high demand for a more flexible, effective solution to confidential computing.


    The Hybrid Approach of Confidential Computing


    To address this issue, SafelyShare offers an approach that is best described as a hybrid model of confidential computing. To compensate for services that don't operate within secure enclaves, this methodology introduces the idea of 'witness execution.' In this scenario, the user places trust in the providers' guarantee of their competency and safe data handling. It's a kind of tacit agreement between the user and the remote service provider, making the confidential computing more feasible in the real world scenarios.


    This hybrid approach redefines the secure sharing paradigm in a world that's continuously evolving. With its elastic foundation, SafelyShare incorporates a profound understanding of the changing security parameters, making confidential computing adaptable and responsive to changing demands and realities.


    Conclusion: Revolutionizing Secure Data Sharing


    In essence, SafelyShare is the leading forerunner in the journey to making sensitive data sharing secure, efficient, and feasible. Navigating around traditional hurdles, it integrates hybrid confidential computing into its framework, achieving a unique blend of trust and practicality. The innovative approach of integrating witnessed computing into the process blurs the lines between full and partial trust, making data security more achievable and delivering a promising narrative for the future of data sharing and security.


    #176 Zero Trust Shared Data Dec 07, 2023
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    In this episode, Darren interviews Shammim Naqvi, the CEO and founder of SafelyShare, about managing and securing data in shared and collaborative environments using the zero-trust data model.

    # Shamim Naqvi: Pioneering Data Privacy in the Age of Zero Trust Security


    In the ever-evolving world of computer science, addressing the issue of data privacy forms a daunting yet essential task. As digital transformations engulf every sphere of life, an increasing onus lies on preserving and protecting the user's data. One expert battling this computational challenge head-on is Shamim Naqvi, a veteran technologist and the driving force behind the innovative startup, Safely Shared.


    Prioritizing User Control in Data Privacy


    In a universe swarming with security measures focusing mainly on encrypting network data or safeguarding ports, Naqvi’s approach stands out as he prioritizes how data is utilized during computation. It's seldom about erecting impregnable walls, but aligning more towards enabling the users to dictate the use of their data.


    Naqvi's trailblazing approach seeks to solve a previously unsolved conundrum: stopping unauthorized usage of user data. This issue is often a surreptitious byproduct of the trade between users and service providers—exchange of data for services. Over time, however, this data tends to stray into territories not intended by the users, triggering severe privacy concerns.


    Zero-Knowledge Proofs: A Gamechanger for Data Privacy


    In his quest for achieving data privacy, Naqvi gives special attention to a mathematical concept—zero-knowledge proofs—that promotes data verification without acquiring any excess knowledge from the verification process. Despite offering an impeccable solution, the multifaceted mathematics behind zero-knowledge proofs pose a significant challenge for their efficient implementation in real-world applications.


    Data Security in Naqvi's Startup Project: Safely Shared


    Naqvi's cutting-edge firm, Safely Shared, is making giant strides in striking a balance between user convenience and data privacy. Its motto, “share but not lose control,” is a testament to its mission to foster a secure computing environment that leaves no data unprotected.


    Valuing Data Privacy in A Zero Trust Security Age


    In this modern era, where trust and secrecy are paramount, the idea of user's control over their data is widely welcomed. It's a thrilling challenge—making data privacy more accessible—and at the helm of Safely Shared, Shamim Naqvi is breaking new grounds with his innovative approaches to secure this privacy.


    #175 Zero Trust with Operational Technology Nov 30, 2023
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    In this episode Darren interviews the CEO of Founder of Veridify Louis Parks. They discuss the unique problems with Operational technology networks that control critical infrastructure, due to legacy complexity, accessibility vulnerabilities, and lack of visibility.

    Introduction


    Operational technology (OT) networks power our critical infrastructure like energy, transportation, and manufacturing systems. These OT networks were designed for safety and reliability without much thought about cybersecurity. However, with increased connectivity, OT networks face growing threats that could have major impacts on our physical world. This article discusses some of the unique challenges and solutions for securing OT environments.


    Legacy Complexity


    OT networks accumulate technologies over decades of operations, leading to complex environments with older unsupported devices and proprietary protocols. Trying to retrofit security is difficult without impacting critical functions. Solutions focus on non-intrusive monitoring of network traffic and encrypting data streams while maintaining existing systems. The priority is keeping systems running safely rather than taking systems offline to investigate threats.


    In addition, OT networks often have a mix of legacy devices using older proprietary protocols that predate common IT technologies like TCP/IP networking. Securing these heterogeneous environments requires protecting both modern IP-connected devices as well as older technology using obscure protocols. Emerging solutions aim to encrypt network traffic at the packet level, creating encrypted tunnels even over non-IP networks to block tampering.


    Physical Access Vulnerabilities


    Many OT devices are distributed in publicly accessible areas like smart city infrastructure or manufacturing plants. This makes them vulnerable to physical tampering by malicious actors trying to access networks. Solutions aim to encrypt network traffic from end to end, blocking man-in-the-middle attacks even if someone gains physical access to infrastructure.


    Demonstrating these physical access threats, solutions show how devices secretly plugged into infrastructure switches are unable to control other devices or decrypt meaningful data from the network when encryption is enabled. This foils common attacks by insiders with physical access trying to spy on or disrupt operations.


    Lack of Visibility


    OT networks often lack visibility into assets, vulnerabilities, and threats compared to IT environments. Simply gaining an accurate asset inventory and monitoring network activity can improve security postures. Emerging solutions apply IT security best practices like zero trust segmentation to OT environments through centralized policy management rather than trying to secure each individual asset.


    In addition to lack of visibility, OT networks transmit data without protections common in IT environments like encryption. Unencrypted plain text protocols allow anyone with network access to spy on sensitive operational data. New solutions not only selectively encrypt sensitive data streams but also establish secure tunnels between authorized devices rather than openly transmitting data.


    Conclusion


    Securing OT environments raises unique challenges but solutions are emerging to balance improved cybersecurity with operational reliability. Non-intrusive monitoring, data encryption, and centralized policy enforcement allow incremental hardening of OT networks against escalating threats. There is still a long way to go but progress is being made.


    #174 Zero Trust Application with Confidential Computing Nov 16, 2023
    Show notes

    Check out my new book AI Augmented Teams on Amazon or on my website paidar.ai/books.


    In this episode Darren interviews Patrick Conte from Fortanix about leveraging confidential computing in securiting applications in zero trust architectures.

    The Evolution of Confidential Computing



    Confidential computing allows encrypting data not just at rest and in transit, but also while it is actively in use. This protects against attacks even if an attacker gains root access, since memory dumps will just show useless encrypted data. Intel's Software Guard Extensions (SGX) technology provides a hardware-based foundation for confidential computing. Fortanix builds on top of SGX and related Intel advancements to make confidential computing accessible and easy to use.



    A core Fortanix offering is their Data Security Manager platform. This replaces purpose-built hardware encryption solutions with software encryption powered by SGX enclaves. Data Security Manager enables advanced crypto functions like global key management for millions of encryption keys all from a unified console. It can also handle database encryption, certificate management, and other critical data protection needs. This software-defined approach represents the future of data security.



    Enabling True Zero Trust Applications



    Confidential computing has implications beyond just data security. It also allows attaching security profiles directly to applications themselves, so the security travels with the application regardless of where it runs. Fortanix analyzes applications to assess if they can run seamlessly in SGX enclaves. If modifications are needed, they provide guidance on rewriting portions in enclave-friendly languages like Python.



    Fortanix's Confidential Computing Manager solution orchestrates encrypted applications across different environments like on-prem, private cloud, and public cloud. This orchestration engine achieved zero trust not just for sensitive data, but also for mission-critical applications. Workloads can be dynamically shifted to different SGX-enabled environments as needed while maintaining end-to-end security.



    The Future of Confidential Computing



    There are many exciting potential use cases for confidential computing, like running distributed analytics collaboratively within isolated secure enclaves. While there used to be substantial performance penalties, improvements by Intel and Fortanix have now reduced overhead to single digit percentages in most cases. Adoption is rapidly growing in healthcare, government, finance, and other industries to protect valuable algorithms and regulated workloads. As confidential computing becomes more ubiquitous and accessible, it will form a foundational pillar of modern zero trust architectures.



    Conclusion



    This insightful podcast provides a thought-provoking overview of how confidential computing can enable true zero trust applications. The ability to encrypt data in use and attach security profiles to applications opens up intriguing new possibilities for end-to-end data protection and application security across dynamic environments. As threats become more sophisticated, confidential computing will only increase in strategic importance.


    Previous 1 19 20 21 22 23 38 Next

    Related Podcasts

    Reply All

    1

    Reply All Games & Hobbies
    Inside VR & AR

    2

    Inside VR & AR Gadgets
    Note to Self

    3

    Note to Self News
    BrainStuff

    4

    BrainStuff Natural Sciences
    This Week in Tech (Audio)

    5

    This Week in Tech (Audio) News
    Hands-On Tech (Audio)

    6

    Hands-On Tech (Audio) Technology
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights