Paul's Security Weekly - Episode 474 - 6:00PM

Recorded: July 21, 2016

Interview: John Kindervag


With more than 25 years of high tech experience, John is best known for creating the highly influential “Zero Trust” model of information security. He currently advises both public and private sector organizations with the design and building of Zero Trust Networks. He holds, or has held, numerous industry certifications, including QSA, CISSP, CEH, and CCNA. John has a practitioner background, having served as a security consultant, penetration tester, and security architect before joining Forrester. He has particular expertise in the areas of secure network design, wireless security, and voice-over-IP hacking. He has been interviewed and published in numerous publications, including The Wall Street Journal, Forbes, and The New York Times. He has also appeared on television networks such as CNBC, Fox News, PBS, and Bloomberg discussing information security topics. John has spoken at many security conferences and events, including RSA, SXSW, ToorCon, ShmoCon, InfoSec Europe, and InfoSec World.

  1. How did you get your start in information security?
  2. What is the Zero Trust network architecture?
  3. Many people ask me what they can do to secure their Big Data deployments and databases and as for best practices, what is your advice?
  4. The decisions people make about whether or not to put data in the cloud seem split, some say "No Cloud", some "Maybe" and some are all in, what advice do you have for those who say "No cloud"? What is the happy medium? Is all-in cloud too much?
  5. How is hunting vampires (and werewolves) similar to looking for "cyber" threats?
  6. What is the best way to "Know your network", we all say this, but what are the best ways to accomplish this goal?
  7. Are we seeing the convergence of traditional IT and security? What are some of the most exciting trends you see in this area?
  8. What advice do you have for those folks listening in search of the following solutions:
    1. DDoS mitigation
    2. Threat Hunting
    3. User behavior analytics
    4. Vulnerability management
    5. Data Loss Prevention
  1. Three words to describe yourself.
  2. If you were a serial killer, what would be your weapon of choice?
  3. If you wrote a book about yourself, what would the title be?
  4. In the popular game of ass grabby-grabby, do you prefer to go first or second?
  5. Choose two celebrities to be your parents.

