Cybersecurity Today TV - Ep 64 - Real-Time Ransomware Defense: Lessons from a Field CISO

Cybersecurity Today TV - Ep 64 - Real-Time Ransomware Defense: Lessons from a Field CISO

🎙 CybersecurityToday 👥 492 📅 October 21, 2025 ⏱ 29 min 👁 38 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

ransomwaredefenseCISOincident responsebackups

Summary

In this episode of Cybersecurity Today, host Jim Wiggins interviews Gregory Crabb, a former CISO of the US Postal Service and current Field CISO at Mimic, about real-time ransomware defense. The show begins with a news segment covering recent vulnerabilities: Oracle’s critical patch update addressing 309 flaws, Google’s Chrome 138 patch for an exploited zero-day, and CISA’s warning about Citrix Bleed 2. The main interview focuses on ransomware fundamentals, using the Colonial Pipeline attack as a case study. Crabb explains how ransomware works, the evolution of attacks from WannaCry to more targeted and automated threats, and the growing involvement of Chinese state-sponsored groups. He emphasizes the importance of having a premeditated ransomware playbook, involving law enforcement early, and prioritizing high-value applications. The discussion covers the role of backups, noting that restoration must be practiced and that paying the ransom does not guarantee data recovery. Crabb recommends testing backups at least quarterly, with more frequent testing for critical systems. He also predicts future trends, including increased use of AI by attackers and potential destructive attacks by nation-states. The episode concludes with advice on how to contact Crabb via LinkedIn or email.

190 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights from a seasoned CISO, offering practical advice on ransomware preparedness and response. The argumentation is based on real-world experience and references authoritative sources like CISA’s StopRansomware guide. However, the discussion remains at a high level, lacking deep technical details or concrete case studies beyond well-known incidents. The value lies in the strategic perspective and emphasis on organizational readiness rather than technical specifics.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates a reasonable level of scientific rigor, with the guest referencing credible sources such as CISA and the FBI. The title accurately reflects the content, focusing on real-time ransomware defense lessons. However, the show has a promotional aspect, as the guest is affiliated with Mimic, which may introduce bias. The news segment provides current information but lacks in-depth analysis. Overall, the sources cited are reliable, but the discussion is more anecdotal than evidence-based.

157 words

Title / Content Match

The title accurately reflects the content: a discussion on real-time ransomware defense with a field CISO.

Quality & Reliability

7/10

The video features an experienced CISO with 25+ years in the field, providing practical insights and referencing authoritative sources like CISA and FBI. However, the discussion is largely anecdotal and lacks detailed technical depth or verifiable data, and the promotional nature of the segment (Mimic) may introduce bias.

Key Moments

Cited Sources

Concurring Sources

  • CISA StopRansomware Guide — The video's advice aligns with CISA's recommendations.
  • FBI Internet Crime Complaint Center (IC3) — The video encourages reporting to law enforcement, consistent with IC3's role.

Contribution & Novelties

The video offers a practical perspective from a field CISO, emphasizing the importance of organizational preparedness and the need for a ransomware playbook. It highlights the evolving threat landscape, including the rise of AI-driven attacks and the involvement of Chinese state-sponsored groups. The discussion on backup testing frequency provides actionable advice. However, the content is not highly novel, as similar guidance is available from CISA and other sources.

Pour aller plus loin :

  • CISA StopRansomware Guide — Official guidance on ransomware defense.
  • NIST Cybersecurity Framework — Framework for improving critical infrastructure cybersecurity.
  • MITRE ATT&CK — Knowledge base of adversary tactics and techniques.

102 words

Radar Profile

The radar profile shows moderate scores across all dimensions, with slightly higher scores in information quantity and reliability, reflecting the guest's experience and the practical advice provided. The lower technical depth score indicates the content is accessible to a broad audience but lacks advanced technical details.

Reliability 7/10