Member Contribution - Weekly CISO Podcast Pick

This Week's Pick by David B. Cross (CISO, Atlassian)

Series curated by the CISO Platform community, sharing practical security leadership resources recommended by experienced CISOs and senior practitioners.

Smashing Security 425: Call of Duty, Legacy Code, and Real-World Risk

David's recommendation this week is episode 425 of Smashing Security, "Call of Duty: From pew-pew to pwned." Graham Cluley and Carole Theriault use two very different stories to make one useful point for security leaders: technical debt, identity abuse, and social engineering do not stay neatly inside technology teams.

The episode opens with reports that Call of Duty: WWII on PC was pulled offline after security issues around online play, then shifts to scams targeting families of recently incarcerated people. For CISOs, the value is in the leadership pattern: old systems, high-trust workflows, and human urgency can combine into risk that moves faster than formal ownership models

 

Source: Smashing Security 425: Call of Duty: From pew-pew to pwned

Focus: legacy software risk, consumer platform exposure, fraud, social engineering, operational ownership

Why this matters to CISOs

  • Legacy code can become a live business risk when old assumptions meet new distribution channels, online services, or user behavior.
  • Security ownership is often unclear when the vulnerable surface spans product, platform, cloud service, game infrastructure, and customer endpoint impact.
  • Fraud schemes work because attackers understand urgency, trust signals, and weak verification workflows. That makes them a security leadership issue, not only a consumer-awareness problem.
  • Public trust is affected by incident response decisions such as taking a service offline, communicating uncertainty, and setting expectations for remediation.

Copy-paste takeaways for your team

  • Review older customer-facing services for assumptions that changed after cloud distribution, online identity, or platform integration expanded.
  • Map who can decide to pause, isolate, or disable a risky feature when exploitation is plausible but root cause is still under investigation.
  • Add abuse-case reviews for workflows where anxious users may be pressured into payments, credential sharing, or unsafe verification shortcuts.
  • Treat social engineering reports as signals about process design, not only as user education failures.
  • Use plain-language incident updates that separate confirmed facts, protective actions, and what users should avoid doing next.

Standout ideas

  • Old software is not automatically dormant risk. It can become urgent again when resurfaced through a new marketplace, subscription service, or integration path.
  • Safety controls should account for the environment where users actually interact with the system, including unmanaged endpoints and consumer-grade devices.
  • Scammers exploit moments when people are least able to slow down. Security programs need escalation paths that make verification easier than panic-driven action.
  • A strong response may start with containment before full attribution. The key is to make the decision rights visible before the incident.

Try this in the next 7 days

  1. Pick one older service or integration and ask whether its threat model still matches how users access it today.
  2. Identify who owns emergency shutdown, customer communication, and recovery decisions for that service.
  3. Run one tabletop question: "What would we do if exploitation reports are credible but incomplete?"
  4. Review one customer-support or identity-verification flow for social engineering pressure points.
  5. Update user-facing guidance so people know the official channel for payment, verification, and urgent account requests.

About David B. Cross

David B. Cross is CISO at Atlassian and a long-time CISO Platform community member. His weekly picks highlight practical conversations that help security leaders sharpen judgment, improve team execution, and stay current on emerging risk.

Share this with your team

Use this pick to start a practical discussion on legacy service ownership, emergency containment decisions, and fraud-resistant user workflows.

Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion