Security Confidential S6 E3 Tim Chase

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Tim Chase. Tim is a Field CISO, Professional Speaker, Author, Ethical Hacker, Certified Application Security Engineer, etc. He is also a LinkedIn Learning Instructor who writes training modules about DevOps and DevSecOp. Tim is an expert at resolving challenging security incidents with a short turnaround time. He is a graduate of Tennessee Tech and the University of Phoenix.

00:00 Introduction

01:13 The problem of Ransomware, how do you see it evolving over in the near future?

05:17 Third-Party Risk

06:21 Applications built on open source code and how to ensure their security?

11:45 What do you see as the Top 3 root causes of security incidents?

14:40 Deep Provisioning

22:22 Step-by-step on how to build a cybersecurity program for SMB

32:05 How to make Cybersecurity logical when coaching a young cybersecurity team. What foundational elements do you emphasize?

37:30 Companies use Cybersecurity as a revenue

40:48 Outro

Transcripts

Manoj Tandon:
Hello everyone, welcome to another episode of Dark Rhino Security: Security Confidential. I’m your host, Manoj Tandon, and today we are honored to have a great guest joining us—Tim Chase. Tim is a Field CISO, a professional speaker, an author, and an ethical hacker. He’s a certified application security engineer and a LinkedIn Learning instructor who creates training modules on DevOps and DevSecOps. Tim is an expert at resolving complex security incidents with rapid turnaround times and is a graduate of Tennessee Tech and the University of Phoenix. Tim, welcome to the show. Thank you for being here.

Tim Chase:
Thanks, Manoj. I appreciate it.

Manoj Tandon:
Tim, you’ve got quite an extensive background, and there are a lot of topics we want to cover today. I’m not sure we’ll get through everything, but let’s start with something that’s constantly in the news—ransomware. It’s everywhere, and unfortunately, many of our listeners have had direct experience with it. Specifically, ransomware-as-a-service—can you break that down for us? Where is ransomware heading, how is it evolving, and who is being impacted?

Tim Chase:
You actually touched on it in your question. If I think back to when ransomware first started, it was very targeted. Attackers would go after specific organizations—companies they knew had money or valuable data—and plan those attacks carefully. What we’re seeing now is a shift to ransomware-as-a-service. You have developers who create the ransomware and then essentially lease it out to other groups for a percentage of the profits.

Because it’s become so easy to access, it’s moving downstream—not just large enterprises anymore, but mid-sized and small businesses as well. A big driver of this is how digital everything has become. Even smaller organizations are heavily reliant on cloud services and online systems.

What we’re seeing now is less targeted attacks and more opportunistic ones. Attackers scan for open ports, exposed servers, or compromised credentials and then go after whatever they find. It’s less about picking a specific company and more about finding easy entry points.

Manoj Tandon:
That makes a lot of sense. When we think about exposure, especially in the context of supply chains, there’s another layer here. We’ve seen breaches like Target that originated from an HVAC contractor, and more recently, incidents involving pipelines through third-party vendors. Doesn’t where a company sits in the supply chain also make them a target?

Tim Chase:
Absolutely. That’s where third-party risk comes into play. There are still attackers who target specific organizations to make a bigger impact, but many will go after weaker links in the supply chain. Smaller vendors often don’t have the same level of security as larger enterprises, making them easier entry points.

We’ll continue to see attackers exploit those relationships—whether it’s HVAC contractors, service providers, or other third parties. It’s a very effective way to get into larger organizations indirectly.

Manoj Tandon:
That’s a really important takeaway for our audience. Even if you’re a small business and don’t think you’re a target, you need to consider your clients and where you fit into their ecosystem. That alone could make you a target. Third-party risk is a massive topic, and we’re seeing it more and more—not just with ransomware, but as a primary entry point into organizations.

Let’s shift gears a bit. Many organizations are building their own applications and platforms, often using open-source code. How can they ensure those applications are secure?

Tim Chase:
It’s definitely a challenge because open source means anyone can contribute. Most projects do a good job with community reviews and built-in security practices, but there are a few key things I always recommend.

First, keep everything updated. It sounds simple, but it’s one of the most common failures. People install something and never revisit it. You need to make sure the project is actively maintained and that you’re applying updates regularly—especially when vulnerabilities like Log4j emerge.

Second, don’t trust anything by default. Go back to the basics—defense in depth. Make sure you have proper logging, monitoring, antivirus or EDR where possible, and correct permissions. Limit what the application can access. Use segmentation and network controls instead of giving it broad access across your environment.

Manoj Tandon:
So essentially, instrument it as much as possible. Even if smaller organizations don’t have enterprise-grade tools, they can still implement logging, access controls, and process-based security measures. And of course, things like changing default passwords—because we still see systems running with factory credentials.

Tim Chase:
Exactly. Defaults are widely known and easily exploited. Even in larger organizations, you’d be surprised how often people rely on them. And to your point about smaller businesses—not everything needs to be high-end or expensive. Tools like Microsoft Defender and other built-in security capabilities in platforms like Microsoft 365 are actually quite strong and accessible.

Manoj Tandon:
That’s a great point. A lot of security gaps aren’t due to lack of tools—they’re due to misconfiguration or simply not implementing what’s already available. Let me ask you this: from your experience, what are the top three causes of security incidents?

Tim Chase:
The first one is still phishing. It may sound overused, but it’s still incredibly effective. Whether it’s simple scams like gift card fraud or more advanced targeted phishing using LinkedIn reconnaissance, it remains one of the easiest ways to gain access. Once attackers get in, they can often move laterally because segmentation isn’t always strong.

The second is access control. Over-permissioning is a huge issue, especially in smaller organizations where people wear multiple hats. Access isn’t always reviewed or removed when roles change. De-provisioning is also a major problem—people leave, and their access remains.

I’ve seen cases where former employees still had access to cloud environments and caused significant damage, whether intentional or not. That’s why identity management and lifecycle controls are so important.

The third is application security. Even after 20 years in AppSec, we’re still seeing issues like SQL injection. While languages have improved, the heavy reliance on open-source code introduces new risks. You may secure your own code, but vulnerabilities in third-party libraries can still expose you.

Manoj Tandon:
That’s a great breakdown. And it really highlights how some of these problems haven’t changed—they’ve just evolved. Let’s talk about budgets, especially for small and mid-sized businesses. There’s often fear around the cost of building a proper cybersecurity program. What’s your advice?

Tim Chase:
Start small and be pragmatic. You don’t need to boil the ocean. A great starting point is an open framework like the NIST Cybersecurity Framework. It’s free, and you can use it to assess where you currently stand.

You’re likely not starting from zero—your teams probably already have some security measures in place. Once you understand your gaps, focus on your biggest risks. If you’re handling sensitive data, prioritize securing that. If you’re cloud-based, start with cloud security.

You don’t need expensive enterprise tools right away. Focus on people and processes first, then layer in technology. There are plenty of strong open-source tools—SonarQube, FindSecBugs, Cloud Custodian—that can help without massive costs.

Manoj Tandon:
That’s excellent advice. Not every organization can afford enterprise solutions, and open-source tools combined with strong processes can go a long way.

I want to come back to something you said—people first. I’ve always believed that people are the most underutilized security asset in any organization. If we educate users and help them understand the “why,” we can close a lot of gaps. How do we make cybersecurity more relatable to end users?

Tim Chase:
It starts with buy-in. Cybersecurity can’t function effectively without it. Whenever I implement policies or tools, I involve the people who will be impacted. I explain why we’re making changes and get their input.

I also try to meet people where they are. If developers are working in Visual Studio, I integrate security tools into that environment instead of forcing them to use something new. The goal is to make security part of their workflow, not an added burden.

Training is also critical. Everyone should receive security training relevant to their role. Developers need AppSec training, system admins need infrastructure security training, and so on. Security is everyone’s responsibility, not just the security team’s.

Manoj Tandon:
That makes a lot of sense—making security accessible, integrated, and understandable. Before we wrap up, let’s talk about cybersecurity as a business driver. Have you seen it used as a revenue enabler?

Tim Chase:
Directly, it’s more challenging—especially in smaller organizations. But I have seen it enable revenue indirectly. For example, achieving compliance—like NIST or HIPAA—can open doors to new business opportunities. Organizations can pursue government contracts or healthcare clients they otherwise couldn’t.

So while cybersecurity might not generate revenue directly, it absolutely enables growth by reducing risk and unlocking new markets.

Manoj Tandon:
That’s a great perspective. Tim, we’re just about at time. Is there anything you’d like to share with our audience?

Tim Chase:
I appreciate the opportunity. If you’re interested, check out my courses on LinkedIn Learning. I have a DevSecOps course that introduces the concept and how to integrate security into development workflows, and another on Continuous Application Security that focuses on automating security within DevOps pipelines.

Manoj Tandon:
And who are those courses best suited for?

Tim Chase:
The DevSecOps course is great for anyone looking to understand the basics. The application security course is a bit more advanced—you should have some foundational knowledge, but not years of experience.

Manoj Tandon:
Fantastic. Tim, thank you again for joining us. It’s been a great conversation, and we’d love to have you back in the future.

Tim Chase:
Thank you, Manoj. I appreciate the time.

Manoj Tandon:
Thank you. Take care.

To learn more about Tim on his Linkedin

Check out the other episodes in Season 6:

Ep. 0 Bonus: Why do People Get Hacked?

Ep. 1 Brian Stoner – VP of StellarCyber

Ep. 2 Dr. Joseph – Russia, Ukraine, and Cybersecurity

Ep. 3 Tim Chase – Ethical Hacker, CISO

Ep. 4 Brian Haugli – CEO of SideChannel

Ep. 5 Nat Schere – Cybersecurity as a revenue

Ep. 6 Endre Walls – Starting in Cyber, Vendors, and Diversity

Ep. 7 Erika Carrara – Veteran, Mentor, C-suite executive

Ep. 8 Eddie Thomason – Podcast Host, Author, and Entrepreneur

Ep. 9 Greg Schaffer – vCISO, Author, and Podcast Host

Ep. 10 Jake Belcher – Sr. Director of Security Strategy

Tim Chase's profile picture for Dark Rhiino Security's Security Confidential podcast

Tim is a Field CISO, Professional Speaker, Author, Ethical Hacker, Certified Application Security Engineer, etc.

He is also a LinkedIn Learning Instructor who writes training modules about DevOps and DevSecOp.

Tim is an expert at resolving challenging security incidents with a short turnaround time.

He is a graduate of Tennessee Tech and the University of Phoenix.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top