All Episodes

May 13, 2024 27 mins

In this episode of CyberOXtales Podcast, host Neatsun Ziv, CEO of OX Security, interviews Amy Chaney, a financial services senior risk executive, about her experience handling the Log4j vulnerability event while working at JPMorgan Chase and Company. Amy provides insights into the environment she worked in at the time and explains the severity and impact of Log4j. She discusses the steps taken to handle the event, including inventorying systems, creating a centralized war room, and disseminating information to various teams. Amy emphasizes the importance of modernization, automation, and agility in preparing for and responding to such events. She also highlights the need for a strong security posture and collaboration across teams to effectively manage and mitigate risks.

About Our Guest:

Amy Chaney is a financial services senior risk executive with over 25 years of experience in the industry. She has served in leadership roles across multiple domains and has worked at JPMorgan Chase and Company, a large and complex financial services firm. Amy has a strong background in risk management and has expertise in navigating complex environments and managing critical vulnerabilities.


Key Takeaways:

  • The Log4j vulnerability, also known as Log4Shell, was a critical vulnerability discovered in the logging mechanism from Apache. It had widespread use and was easy to exploit, requiring no authentication. The severity of the vulnerability prompted immediate action from organizations globally.
  • Building a centralized war room and establishing a drumbeat of communication and coordination is crucial in managing and responding to a large-scale event like the Log4j vulnerability. This ensures that the right information is disseminated, actions are prioritized, and progress is tracked.
  • Having an accurate inventory of systems and applications is essential for understanding the scope of the vulnerability and prioritizing remediation efforts. This includes not only internal systems but also third-party and vendor networks.
  • Modernization and automation play a significant role in effectively responding to vulnerabilities. By automating upgrades and patches, organizations can reduce the reliance on manual processes and minimize the risk of human error.
  • Collaboration and teamwork are key in managing and mitigating risks. By bringing together different teams, including security, risk, legal, and business units, organizations can leverage diverse expertise and ensure a coordinated response.


Mark as Played

Advertise With Us

Popular Podcasts

Crime Junkie

Crime Junkie

Does hearing about a true crime case always leave you scouring the internet for the truth behind the story? Dive into your next mystery with Crime Junkie. Every Monday, join your host Ashley Flowers as she unravels all the details of infamous and underreported true crime cases with her best friend Brit Prawat. From cold cases to missing persons and heroes in our community who seek justice, Crime Junkie is your destination for theories and stories you won’t hear anywhere else. Whether you're a seasoned true crime enthusiast or new to the genre, you'll find yourself on the edge of your seat awaiting a new episode every Monday. If you can never get enough true crime... Congratulations, you’ve found your people. Follow to join a community of Crime Junkies! Crime Junkie is presented by audiochuck Media Company.

24/7 News: The Latest

24/7 News: The Latest

The latest news in 4 minutes updated every hour, every day.

Stuff You Should Know

Stuff You Should Know

If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.