Security Confidential S3 E3 Karla Reffold

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Karla Reffold. Karla is an experienced business owner and business leader. She has a large international network in cybersecurity and is well versed in the many topics relevant to the industry. She founded the international recruitment business, BeecherMadden in 2010 before overseeing the acquisition by Nicoll Curtin. In 2020 she joined Orpheus Cyber as the Chief Operating Officer (COO). Orpheus is a threat intelligence company with a SAAS platform that helps organizations manage their own risk, and that of their third parties, with an easy to understand cyber risk score. Karla is the host of industry interviews on the Cyber Talks media platform and the Zero Hour Podcast. She was included in SC Magazine’s Top 50 Women in Security in 2019. Karla discusses her transition from a recruiting firm to COO of Orpheus. She discusses gender differences in male-dominated cybersecurity and why women in cybersecurity make 30% more money than men, in the field.

00:00 Introduction

01:22 Journey from Recruiting to COO

02:52 Advice to startup companies

04:45 Gender differences in cybersecurity and how to overcome them

06:40 Why women get paid more in cybersecurity?

10:00 Assessing and managing risk in cybersecurity

17:13 The role of threat intelligence

18:51 Heavy reliance on cybersecurity tools vs. processes

20:25 The pyramid of pain and threat hunting

22:40 The Solarwinds breach

24:36 Changes resulting from the Covid Pandemic

25:49 Zero trust

27:21 Quantifying risk on cloud platforms

27:57 European vs North American differences on cybersecurity and GDPR

29:38 IT Hygiene, why cybersecurity is hard

30:52 Parting thoughts

Transcript

Manoj Tandon: Hello everyone, welcome to another episode of Dark Rhino Security Confidential. Today we are honored to have Karla Reffold join us. Karla is an experienced business owner. She founded the international recruitment business Beecher Madden in 2010 before overseeing the acquisition by Nicoll Curtin. In 2020, she joined Orpheus Cyber as the Chief Operating Officer. Orpheus is a threat intelligence company with a SaaS platform that helps organizations manage their own risk and that of their third parties with an easy-to-understand cyber risk score. She is the host of industry interviews on the Cyber Talks media platform and the Zero Hour podcast. Karla was included in SC Magazine’s top 50 women in security in 2019. Welcome to the show, Karla. Thank you for being with us.

Karla Reffold: I’m really glad to come on.

Manoj Tandon: I know we imposed at the last minute and you really graced us, so thank you very much for that. But I’ve got to ask you: looking at your background, it’s very interesting. You started off in recruiting, and now you’re the COO of a cybersecurity firm. What’s that journey like? How did that take place, from recruiting to cyber?

Karla Reffold: You know what, you’re the second person to ask me this today, because to me it just seems really natural, but I guess it isn’t. So, yeah, I started off in recruiting and then around 2010, people were saying, “You’ve got to focus more on this cyber thing.” Cyber was big, and all our clients wanted to talk to us about cyber; they didn’t want to talk to us about resilience or crisis management anymore. And it really just exploded from there because we were one of the first recruitment companies to just focus on cybersecurity. And then my network has kind of grown as the industry’s grown, so I’ve been fortunate enough to meet and interview a huge number of CISOs and CEOs across the industry. Running your own recruitment firm, we grew that to a reasonable amount of people before it sold. I wasn’t really a recruiter; I think I did two placements in five years or something. I’m really a business leader. My skills are in developing people, developing talent, in marketing, in running operations, and running sales teams. So moving into Orpheus was just a really natural step.

Manoj Tandon: Tell me if this is a hard question: what is one mistake that younger companies universally make as a startup that challenges their own success? Is there a single piece of advice or challenge you’ve seen in your own experience?

Karla Reffold: I’m not sure if it’s universal; maybe it is, because I’ve seen a few. My biggest mistake was thinking I could do everything. We reached this tipping point, and I didn’t want to bring in more people because I thought I could do it best. I think if we’d have brought in some more people at that point, we probably could have accelerated our growth. I don’t know if that’s a challenge everyone has, but I think I see it in cyber: “When do I take funding?” “When do I bring in a CEO or a CTO?” whatever it is. When do I expand that out? So, that’s what I see.

Manoj Tandon: Well, I would concur. We saw that in our own firm: recognizing that you need to delegate to other folks and bring in other experts. You really have to, instead of doing it all yourself. It is something that can be limiting, and it has to do with who knows the story better than the founders and the partners of the company. It takes some time on everyone’s part to enable the rest of the team to understand those things so that they can become articulate in it.

Karla Reffold: You know, I was quite young when I started that company, and I can look back now and say I think there was some—there definitely was some inexperience in some areas. I didn’t necessarily have the confidence in enforcing my boundaries, which would have enabled other people to really take my vision and deliver my vision. So, I think that’s something I learned, anyway.

Manoj Tandon: That’s a great bit of advice. Now, let me ask you: as a very successful woman in cybersecurity and in business, can you point to some gender differences—challenges that come about as a result of gender differences, whether that be in cybersecurity or recruiting, that you’ve experienced and how do you overcome them?

Karla Reffold: I’ve got some great research and insights that I think we’re going to get to with women in cyber. But I think the big challenge—and it’s one women have everywhere—is perception. You are constantly battling the perception that other people have of you because of your gender or because of your age. Even if that other person doesn’t have it, you’ve experienced it so many times that you feel it in every situation, or at least I certainly do. The amount of people that sat across the table from me and literally said to my face, “You’re very young to be doing this,” and really what they meant is: “You’re a girl, and I’m going to talk to the man next to you because I think that man will give me the answers I want.” And that’s the perception we have. We know we’re discriminated against; we know we face these challenges. We see that in all walks of life and all careers. That’s the big challenge, I think.

Manoj Tandon: I think in cyber there would be a lot less of that given the imbalance in supply and demand of people. At Dark Rhino, we’ve had a lot of women in the business, and our lead threat hunter is a brilliant young lady. We’re just glad to have great people. We look at it a little differently; maybe we’re from Ohio, so we don’t know any better.

Karla Reffold: Well, one thing I would say is it’s changing. It’s definitely changing. Companies really want women in their cyber teams. And what I was seeing in the recruitment world was that women were actually getting job offers which were paying them up to 30% more. You think women are being paid less, but they’re not. But again, it comes back to perception: because we feel like we’re being paid less, we feel like we’re being penalized.

Manoj Tandon: Perception is reality. But 30% more than males—that’s actually… I did not know that. I learned something new today.

Karla Reffold: Well, I think two things: the really easy thing to say is companies want women, so they’re paying them more just to get them. And I think that’s true when it comes to how many job offers women get, because we would see women get more job offers and we would see them get them quicker. So, I think you can put that down to supply and demand. But what we found with the women getting these offers is they had a very broad background compared to men. They were maybe coming from risk management or project management, and they had different skills. I think it was the breadth of skill sets that they’re bringing.

Manoj Tandon: So then that’s merit-based, which is the right thing to take place. I mean, if you have more skills, then you should get paid accordingly.

Karla Reffold: Yeah, absolutely. And my real fear with this research was everyone’s just going to think we’re chucking money at women and they don’t really deserve it. So it was really heartwarming when I went through it and thought, “I don’t think that’s the reason. I think these women genuinely deserve this money.”

Manoj Tandon: Do you think that maybe women feel that they need to have a better leg up, so they’re spending a lot more time and investment in broadening their skill set, or are there other reasons why they’re carrying such a broad skill set?

Karla Reffold: In cyber, women work 10 times harder than the men. I have to say it. I’ve interviewed a lot of them. It’s always the women that have done their research and want to be on point with what they’re saying when you talk to them. I see this in the interviews and in my role as a judge on some of the awards as well. The women are out there in the schools; they’re speaking to children about getting them into cyber; they’re doing extra projects and extra training, whereas the guys—and there’s some lovely ones—they kind of show up and go, “I do my job and I do it really well,” and that’s it. But yeah, if you’re going to generalize, women often are more personable and they do have more empathy, and then they have learned to communicate that to the business in a different way, which is a skill that we see really underrepresented in security: “How can I actually communicate this to the business in a way they understand?” And I do think that, on the whole, women are able to do that really well.

Manoj Tandon: That’s a very good observation. I think all our listeners out there should pay note to that. If you’re looking to change careers into cyber and you’re a woman who’s looking to make the switch, this might be a great time to do it. I know we have a lot of training programs that help people come along because there’s such a huge demand for things that we’re doing right now, and good people are good people.

Karla Reffold: They are. There’s so much demand; it’s a great time to get into cyber, especially if you’re female.

Manoj Tandon: You talked about risk—you mentioned it very briefly—and this is a topic that’s often talked about in cybersecurity circles. Give us your view, and maybe Orpheus’s view, of what risk is, and how you should assess it and manage it. Give us some insights here.

Karla Reffold: So at Orpheus, we take the approach that your risk is your threat and your vulnerability, and then you couple that with your impact. That’s your risk. We can then look at not necessarily your impact, as that’s quite internal, but we can look at your threat and your vulnerability for you. I think it’s really around that piece: “What is your impact?” And I think that’s where, as a profession, we need to start talking more: “What’s the impact to the business, to the bottom line? What does this cost if we do it or don’t do it?” Put that in a way then that the board can understand and other people in the business understand. They are used to talking about risk that isn’t cyber risk; they are used to talking about the whole range of risks in the business.

Manoj Tandon: A couple of episodes back, we had a gentleman by the name of Warner Moore on the show. He made a really interesting observation that we would agree with, based on our own personal experience: a lot of times risk is talked about, but it’s not really addressed well. We see this time and time again: we go into an organization and really ask them, “What are your crown jewels? What is worth protecting?” Whether that be data, intellectual property, or a product—what is that crown jewel set? Who has access to it, and what’s the likelihood it would be impacted by a cyber incident? We don’t usually get a straightforward answer.

Karla Reffold: Yeah, and I think there’s two things in there. One is: who is really educating cyber professionals and CISOs on how to communicate risk? If we come up through the technical route, we’re not getting access to the CFO, who might talk to us about how they see risk and how they measure risk. And then I think the other thing is it’s really complex. It’s really easy to say, “Well, you should know where your stuff is, and you should know who has access to it.” But if you’re in a company of a couple hundred thousand people with however many systems—some of them are old, and there’s all sorts of processes and people jumping up and down—that’s hard. It’s really hard to put in those sort of programs. I’ve worked with quite a few organizations putting in their IDAM programs, and it’s hard. It takes them a long time, a lot of money, and really specialist people to get a handle on it. It’s not easy stuff.

Manoj Tandon: So how would you suggest a company begin? The company I’d like you to think about is one with 2,000 employees and below, because we know in much larger organizations there is a focus on risk and there are usually teams set up to look at this. But in that mid-range of company, are there some tips and pointers you would provide as a guiding light if they wanted to really look at examining risk?

Karla Reffold: I think you have to put people in charge of the right thing and put specialists in charge of what you need. Putting everything under the CISO, or even everything between a CISO and a data protection officer—you’re not really solving your problem because they have so many fires to fight. So, if working out who has access to what is really a priority, put in an IDAM person. Put them on a contract if it’s not going to be forever, but put someone in charge of just doing that. I think even at 2,000 people, that’s still quite big; you’re going to need it, and you can make one person responsible for that. That, I think, is where you need to start.

Manoj Tandon: Do you think there is a recognition by executive leadership in companies that risk is a business problem? That cyber risk is a business problem and not an IT problem?

Karla Reffold: I’m not sure yet. I think we’re getting there. I think we’re saying the right things, and I think as an industry, generally we’re being listened to. It’s taking a while, but I think boards and companies really are understanding now how important cyber is. So I think we’re getting there; I’m not sure we’re there yet—not in all companies, for sure.

Manoj Tandon: Yeah, we tend to agree. We’ve seen a similar thing. I think the conversation really does need to be brought up to the board level in dollars and cents terms and then probability of loss. At Orpheus, you’re doing this in an automated fashion. Is your technology looking at the environment and evaluating it? What’s the process, if I might ask?

Karla Reffold: So we look at a couple of things. We’ve got this amazing team of threat analysts that are doing very high-quality threat intelligence work, and that feeds into our platform. Then we have some quite exciting machine learning looking at vulnerabilities. We’re looking at the severity of the vulnerabilities in a company’s environment, but also what vulnerabilities could be exploited or what we think are likely to be exploited in the future. You all know not every vulnerability we see gets actually used. I think several hundred a day get discovered, but actually not that many of them go on to be exploited. Our machine learning can predict which ones will be exploited in the future. It’s over 90% accurate, so it helps companies really prioritize which ones they go after based on whether they are being exploited, if they will be exploited, and how severe they are. Then they can apply those two things to themselves or to their supply chain. That’s where it gets really powerful. We can then start looking at a supply chain for a company and help them work out where the risk is.

Manoj Tandon: So you’re building a business-specific custom model for each client essentially with the technology.

Karla Reffold: Exactly. And then they can drill down on it. The right people in the right teams can go drill down on that. If you care about what your threat profile is, that’s in there. If you care about what vulnerabilities there are, that’s in there. And if you want to work with your third parties and say, “This is a problem, you need to go fix it,” then we have all the data that tells you exactly what you need to go fix.

Manoj Tandon: What’s the role of threat intelligence in this?

Karla Reffold: For us, you can’t just say, “Here are your vulnerabilities.” If nobody cares about them or cares about you, then the threat to you is pretty low, right? You can’t go and fix everything; as we’ve been saying, it’s complex. You need to really understand your threat profile to be able to work out where to start. For us—and for me, learning so much about it—threat intelligence is just so crucial. I don’t understand how anyone does anything in security without it.

Manoj Tandon: One of the complaints we hear quite a bit from security professionals and practitioners is that there’s a lot of threat intelligence, but it needs to be made actionable. That’s an arduous task. Any commentary on that?

Karla Reffold: I would say if you have so much threat intelligence that you need to do something with it, that’s not intelligence—that’s information; it’s data. You can get hundreds of alerts and feeds, and then you’re going to need a team of people to pick through it. That’s not intelligence. Intelligence, for us, is something that tells you: this is a problem, this is where it is, and this is what you need to do about it.

Manoj Tandon: Yeah, and that’s a little bit of a complex process, I would imagine, unless you have put some thought into the automation of it or looked at the vulnerabilities, as you’re saying, and said, “What particular threats do I really need to examine and which can I just disregard?”

Karla Reffold: Yeah, exactly. That’s why we have a team who are doing that and then supporting our clients with it. We’re saying, “Are nation-states really a problem to you? Maybe not.” Maybe they’re not someone you need to worry about. But what you do need to worry about are these people with a social justice agenda that keep talking about you and who want to target you because they don’t like what you’re doing. That’s what we’re doing for our clients.

Manoj Tandon: Now, do you think that maybe there is a heavier reliance on tools by companies than there should be? And not as much focus on processes and procedures as it relates to cyber?

Karla Reffold: Perhaps. I mean, I think if we talk about people, process, and technology, I’ve been hearing for a long while that it’s about the people, not about the technology. I don’t know—maybe this isn’t necessarily my area, but I definitely feel there’s a lot of confusion in the market. There’s a lot of confusion about what tools are good, and confusion on how we balance getting innovative solutions in from newer companies while balancing that with, “Hey, we’re going to go with the big guys because we trust you,” and that feels safe, whether or not you’re the best. And how are we really analyzing the ROI on these tools? Budgets in cyber keep going up and up; that can’t happen forever. So, we really do need to start analyzing: is this working for us? Is it necessary? Is there a better, cheaper, more innovative solution that we could be deploying? I know everyone has a different strategy: some people want everything from the same vendor because it’s simple; some people don’t want to rely on the same vendor because that feels risky. So, I don’t know if we have too big a reliance on tools, but I think we could definitely use them better and use the industry better.

Manoj Tandon: All right, let me frame it. I think a lot of our listeners might be familiar with the Pyramid of Pain. In cyber, a lot of folks know about it. We know how to handle the base—those known knowns we know how to deal with. The unknown knowns we can address to a very large degree. At the very top of that thing are refined or new techniques, tactics, and procedures—new TTPs. And that’s not the domain of a vendor; that’s really the domain of human consciousness. A tool is not going to solve it, like the SolarWinds hack. I don’t know if there’s a single platform or any technology that was capable of detecting, solving, or finding any of those things. It took human intelligence to do it. When you see things like that, it just brings the question: is there an over-reliance there? And maybe should we be giving the people a lot more of a stake in the process, rather than just relying on a SOC showing potential threats and the analyst only acting when they see something change on their screen? Why not go find it first?

Karla Reffold: Yeah, right. And I’m seeing a lot more companies put people in to do roles like that—to do that kind of threat hunting and threat detection piece. And I’m sure everyone listening will know all the stats around the SOCs: how many false positives. I think analysts get less than 10 minutes to triage something and make a decision. That’s really hard. Either you need to change what the tools do—make them more effective—or you need to back it up with more intelligence, like proper intelligence, so you know what you need to be looking for. Or you need more people, or we need more education as well. How many businesses are really invested in cyber awareness to educate the employees in the business on what they need to be looking out for? You can’t stop every phishing email, so you want to have people that have an awareness when something doesn’t look right.

Manoj Tandon: Do you think the SolarWinds hack is going to affect that positively, maybe raise awareness on exactly what you just said—raising people’s awareness?

Karla Reffold: I think so. Every time there’s something this big, you see a little bit more awareness in the public consciousness. And I think what’s positive about this one is it’s really brought to the forefront that third-party attacks are the big risk. But I also wonder—and I don’t have the answer to this—when you have an attack like this where I don’t think anyone could have stopped it, right? It was so sophisticated, and I think we’re all aware that very sophisticated attacks will happen and will get through. So if you’re a business, do you turn around and say, “Well, if we can’t be secure, why do we bother? Why are we spending all this money? Let’s spend a bit less and accept a higher level of risk.” I’m not sure. I think it just makes it harder when you as an industry say no one could have stopped this, and then ask for more investment to stop those attacks.

Manoj Tandon: Well, I think it gets… if you know what your crown jewels are and what you’re really defending, you really mitigate against those, right? And you do the best possible job. Then I think that’s the best that you can get. I mean, beyond that, being in business is a risk; there is a degree of risk there, as we all know.

Karla Reffold: It is. And you know, what I really thought was positive about this particular breach is how the community came together to back everyone up. Lots of stuff around, “Well, let’s not jump to conclusions; let’s not criticize.” This hurts everyone, and I thought that was really great to see as an industry.

Manoj Tandon: Now, what do you think are going to be some changes that the COVID pandemic has brought upon our industry? How do you think that’s going to affect the cybersecurity space long-term?

Karla Reffold: It’s going to be so interesting, right? I don’t know that there’s one answer. I think some companies are going to go fully remote, and some companies are going to be desperate to rush back to the office, and most companies will go somewhere in between. I have this feeling that companies will come more back to the office than they will stay remote. I keep likening it to the Friends episode where Rachel takes up smoking because everyone’s going outside and making all the decisions on their cigarette breaks. That’s going to happen when some people are in the office and some people aren’t. It’s going to be hard to keep that going. I do feel like we might end up more physically back in the office than we think. But if we’re going more remote and we’re having to put in more cloud-based solutions, and we’re going to change our infrastructure, then we’re going to have to change the security that goes with that infrastructure and how that’s managed, which I think will be quite interesting. And we were talking a little bit earlier: why haven’t we fixed some of these problems earlier? Part of that is that companies have old legacy systems that make it really hard to do that. So actually, if we’re going to go through this period where organizations really change and IT changes come off that, I think that’s going to change how we secure them and change how we think about security.

Manoj Tandon: Zero trust—how much of a play do you think that’s going to have going forward?

Karla Reffold: I do think that the moving to the cloud piece that you mentioned is really interesting, because we’re certainly seeing the regulators start to take note of that. They’re saying that you can’t just outsource your security for that and just assume it’s secure because that’s what you’ve been told. There’s a lot of interest in actually how we secure that.

Manoj Tandon: You bring up an interesting point. I would advise everyone that’s listening and is using AWS, the Microsoft environment, or Google to really read the fine print of their contract. Because when you read that fine print, they don’t say that they take care of everything. There is a big responsibility on the part of the user of those systems for their security.

Karla Reffold: Yeah, and I think that’s going to be a big area. We’ve certainly seen that in the amount of cloud security jobs that are available; it’s clear the industry thinks that is a big problem.

Manoj Tandon: How do you quantify risk on that? The end user doesn’t control AWS; they don’t have control over Google’s environment or Microsoft’s environment, for that matter. But they are absolutely carrying a degree of risk from those organizations onto themselves.

Karla Reffold: Yeah, they are, and it’s really challenging. How can you manage that risk? It’s an area where—maybe this isn’t the right answer—but for me at the moment, you just have to accept a level of risk.

Manoj Tandon: Do you see differences between Europe and North America in their views on cybersecurity?

Karla Reffold: I see a big difference in attitude. I’m not sure if I see a big difference in how we’re really approaching it. I think the attitude in America in general is just very positive: “Great, how can we get involved? How can we help? How can we fix it?” Whereas in Europe, maybe it’s a little bit more cautious; things take longer to do. We’re slightly more cautious on what we implement. I think there’s a view that America is far further ahead on their security than Europe, and I’m not convinced that’s true. I think there are areas where that’s not true—maybe some where it is. Incident response, I think, is all being driven out of America. But yes, there are some differences.

Manoj Tandon: GDPR: a good thing or a bad thing for cyber?

Karla Reffold: I think it’s a good thing. I think what it did for the industry that was really positive is companies had to notice it. Those fines are too big to ignore, and so I think we saw a lot of investment coming off the back of that. I think that that’s a really good thing. I’m sure there are areas in companies where we’re not quite complying, and there’s definitely a bit of boredom from the public on certain things. It gets waved as a tool often in not quite the right ways, but I think overall, yeah, it’s a good one.

Manoj Tandon: One last thing that I wanted to touch base on—I know we’re getting close here—is this whole topic of IT hygiene. You mentioned it’s hard. When we were talking about processes, you said it was hard. Is that the reason why you think IT hygiene is difficult to follow in the cybersecurity space? We see that a lot of failures in hygiene result in breaches.

Karla Reffold: Yeah, and I’ve spoken to people on both sides of this. People that are like, “Look, we’ve known these are problems for long enough; why can’t we just build it in a different way and stop? Just build it securely. It’s not hard.” And then I speak to people in really large organizations and, like I said, there are legacy systems, lots of people, and lots of priorities. And then I start to understand: okay, this is actually really, really hard. It’s not as easy as saying, “Just patch everything,” or “patch the most important things,” or “you should have known about this, why haven’t you done that?” It’s hard to do. It’s hard to get the time and the downtime. It’s hard to know what to prioritize sometimes if you don’t have the right intelligence to help you. So, yeah. In my opinion, I’ve seen enough people explain to me why it’s hard to go, “I get it, it’s hard.”

Manoj Tandon: Karla, we’re coming up on the hour here and I wanted to let you get the last word in. Is there anything you’d like to plug—a book, a show, any upcoming events, anything you would like everyone to look out for?

Karla Reffold: Well, I’ve only recently joined Orpheus, so I’m going through my own journey of learning more about the threat intel world and third-party risk. But I’m really excited by what we’re doing. The more I learn, the more I look at our competitors and the more I look at what we’re doing, the more excited I am about what we have to offer. So, go and check out Orpheus. You can get there through my LinkedIn, or a quick Google.

Manoj Tandon: We’ll put the links in the show notes so people can connect. Well, thank you, Karla, for joining us. It’s been a pleasure.

Karla Reffold: Thank you, bye.

To learn more about Karla Reffold please visit her LinkedIn

To learn more about Orpheus please visit their Website

Check out the other episodes in Season 3:

Ep. 0 Tyler Smith – Cyber Basics: Training the End-User

Ep. 1 Manoj Tandon – Was it worth it? Lessons Learned

Ep. 2 Chenoa Moss – Healthcare IT: Innovation at the Speed of Life

Ep. 3 Karla Reffold – Do Women make more Money in Cyber?

Ep. 4 Nick York – How the OITA is helping Tech in Ohio

Ep. 5 Dr. Calvin Nobles – How Human Factors Can Impact Cybersecurity

Ep. 6 Karl Sharman – How to Hire and Retain Cybersecurity Personnel

Ep. 7 James Azar –  How Secure is Your Organization?

Ep. 8 Jordan Graham – Business Lessons from a Bowhunter

Ep. 9 Chris Auger – Why Microsoft 365 is difficult

Ep. 10 Jeff Manhardt – The Power of Why

Karla Reffold's profile picture for Dark Rhiino Security's Security Confidential podcast

Karla is an experienced business owner and business leader. She has a large international network in cybersecurity and is well versed in the many topics relevant to the industry. She founded the international recruitment business, BeecherMadden in 2010 before overseeing the acquisition by Nicoll Curtin. In 2020 she joined Orpheus Cyber as the Chief Operating Officer (COO). Orpheus is a threat intelligence company with a SAAS platform that helps organizations manage their own risk, and that of their third parties, with an easy to understand cyber risk score. Karla is the host of industry interviews on the Cyber Talks media platform and the Zero Hour Podcast. She was included in SC Magazine’s Top 50 Women in Security in 2019.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top