Member Contribution - Weekly CISO Podcast Pick
This Week's Pick by David B. Cross (CISO, Atlassian)
Series curated by the CISO Platform community to surface podcasts, talks, and interviews worth a security leader's attention.
Strange Things Are Happening: To Catch a Thief - North Korea On Our Payroll
David's recommendation this week points to the Season 2 premiere of Strange Things Are Happening, hosted by former New York Times cybersecurity reporter Nicole Perlroth. The episode examines how North Korean state-backed workers are allegedly getting hired into global remote roles, gaining trust, writing code, handling corporate credentials, and reaching sensitive technology environments from inside normal business workflows.
For CISOs, the value is not just the espionage story. It is a reminder that workforce identity, contractor governance, privileged access, and insider-risk controls now sit directly inside the geopolitical threat model.
Focus: workforce identity, remote hiring abuse, insider risk, privileged access, and AI-era supply chain exposure.
Why this matters to CISOs
Remote hiring fraud changes the shape of identity risk. A hostile actor no longer has to break into a system first if they can enter through recruiting, onboarding, payroll, and collaboration tools as an apparently legitimate worker.
The hardest part is that many of the early signals look operational rather than malicious: inconsistent locations, outsourced interviews, unusual work patterns, credential-sharing behavior, and access requests that pass ordinary approval gates.
Copy-paste takeaways for your team
- Treat remote worker identity assurance as a security control, not only an HR process.
- Review privileged access for contractors, vendors, and remote engineers with the same rigor as production access.
- Look for signals that combine identity, device, network, payroll, and code activity rather than relying on one system of record.
- Assume adversaries will target AI, source code, secrets, and internal tooling through legitimate-looking employment paths.
Standout ideas
- Hiring, onboarding, and access provisioning are now part of the attack surface.
- The insider-risk program needs a path for suspicious identity signals that do not yet look like data theft.
- Security teams should help HR, legal, and engineering define what proof of work identity means in distributed teams.
- AI development environments deserve special attention because model work can concentrate code, data, credentials, and strategic IP.
Try this in the next 7 days
- Ask HR, legal, security, and IT to map how remote workers are verified before and after onboarding.
- Sample recent contractor and engineering access grants for least privilege, business justification, and review owner quality.
- Check whether identity, device, VPN, code repository, and payroll anomalies can be correlated during an investigation.
- Define one escalation path for suspected remote-workforce fraud that avoids tipping off the person under review too early.
About David B. Cross
David B. Cross is CISO at Atlassian and a regular contributor to the CISO Platform community. His weekly recommendations highlight practical security leadership lessons from podcasts, talks, and technical conversations worth sharing with peers.
Share this with your team
Forward this pick to the leaders responsible for identity, hiring, contractor access, engineering security, and insider risk. The useful discussion is not whether remote work is risky. It is whether your organization can spot when a trusted workforce path has been turned into an adversary access path.

Comments