What happens when cybercriminals don't even bother encrypting your files, but still demand $5 million?
In Episode 49 of DTF Cyber, Damian, Troy, and Fern sit down with former 3x Financial CISO Brian Rosario to break down a terrifying shift in the threat landscape: Extortion Without Encryption. We analyze recent breach news (like Abbott Laboratories) to reveal how bad actors quietly exfiltrate crown jewel data, bypass traditional backup recovery options, and hold reputational/SEC clocks over your head. Plus, we dive into the risks of "Vibe Coding" with AI, unmonitored OAuth tokens, and how to build a security culture without ego.
----------------------------------------------------------------
📌 TIMESTAMPS:
00:00 - Cold Open: $5M Ransom, Zero Encrypted Files
00:49 - Guest Intro: 20-Year CISO Veteran Brian Rosario
01:50 - Abbott Labs Incident: The Shift Away From Encryption
03:55 - Why Bad Actors Pre-2020 Pivot To Pure Data Exfiltration
06:32 - Why Cloud Snapshots & Backups Aren't Stopping Extortion
08:28 - Supply Chain Threats: Codebases & Hardcoded Secrets
10:30 - The SolarWinds & NotPetya Effect
11:47 - Email Protection & Siphoning CEO Mailboxes via OAuth
14:35 - "Vibe Coding" & Unmonitored Citizen Developers
18:30 - The Explosive Rise of AI Governance Platforms
20:26 - "Is It Better To Not Know?" The CISO Visibility Dilemma
23:27 - Getting Ego Out of Security Leadership
28:20 - Analyzing the Kill Chain: Vishing, Smishing & DefCon Lessons
36:06 - SEC Disclosures & Data Layer Visibility
42:30 - Data at Rest Encryption: Is AI The Solution?