Everything David D'Amato said on any show that made the record, most notable first. Each card names its show and opens the statement there.
D'Amato: Corporate board focus on China and Russia is a distraction
“They're simply really interested in things that are in the news. So if you look at things like China and Russia that don't impact most organizations, they want to know who's attacking and where they're from, what they're doing. And to be honest with you, that'…”
D'Amato: Cyber attack attribution does not matter for private corporations
“And for most organizations, the attribution doesn't matter. For the government, it absolutely matters. But as a corporation, what will you be able to do? You're not going to be able to hack back that, that country.”
D'Amato: Cyber attackers often understand target networks better than defenders
“Most organizations don't really understand their own organization, their environment, and that in many cases, attackers understand the environment much better than the defenders do.”
D'Amato: Chief Security Officers commonly do not know their endpoint count
“When I asked them how many systems they had in their organization, how many endpoints they had, computers and servers and things like that, They had no idea. So that's pretty common.”
D'Amato: Penetration testers breached top secure facilities in under two hours
“I'll be honest with you, I was not very good, but within about a week or less, I think my best was about two hours, we were able to break into some of the most secure locations in the world. Physically and Based on information technology.”
D'Amato: Integrity attacks are most devastating because they go undetected
“And integrity tends to be one of the most devastating attacks, because you typically don't know what's happened.”
D'Amato: Google was the first company to publicly disclose Chinese cyberattacks
“If you walk through the timeline, you go back and start with Google in 2010, when they're the first company to come out and actually talk about Chinese state-sponsored actors. This is something the government and a lot of people knew about at the time. And it'…”
D'Amato: Most steps in a cyberattack reuse familiar tactics
“An attack isn't made up of one action. It's usually made up of multiple actions. And so what you may see is one different action in that attack, and probably multiple, maybe 10 or 12 of the steps that you've seen in previous attacks. So in most cases, you're l…”
D'Amato: Cyber attackers face no accountability, enabling endless retries
“As an attacker, I can keep trying my attack as many times as I want. So every time you catch me, I simply restart my attack because there is no accountability.”
D'Amato: No standardized cybersecurity reporting framework exists for corporate boards
“There should be, and the challenge is right now there's no standardized way to report information to the board.”
D'Amato: Non-state criminals stole $10 million from a bank overnight in 2010
“One of the first cases I ever worked on back in 2010 was a bank that lost about ten million dollars overnight. It's a gang of criminals who were loosely affiliated with each other, who had a reasonable set of skills from their computer science degrees, from th…”