Strategic Human Firewall: Overcoming the Human Blind Spot | Interview with Robert Siciliano
Welcome to Secure and Simple Podcast. In this podcast, we demystify cybersecurity governance compliance with various standards and regulations and other topics that are of interest for consultants, CISOs and other cybersecurity professionals. Hello. I'm Dejan Kosutic, the CEO at Advisera and the host of Secure and Simple Podcast. Today, my guest is Robert Siciliano, and he's the co founder of ProtectNow, a company for security training and certification.
Dejan Kosutic:And he has featured over 500 times as an expert on the today's show, CNN, Fox News, MSNBC, and CNBC. And he's also the author of Strategic Human Firewall framework that teaches that protecting the organization begins with protecting the people themselves. So in today's podcast, you learn what a human blind spot is and how attackers use it for impersonation, social engineering, and other attacks. So welcome to the show, Robert.
Robert Siciliano:Thank you so much. Happy to be here.
Dejan Kosutic:Okay. Great to have you here. So you are using various, I would say, interesting concepts like human blind spot, strategic human firewall, security appreciation, AAA. So can you explain what do all of these mean?
Robert Siciliano:Sure. So I've been providing true security awareness training for over thirty years. Today, when we refer to security awareness training, we're talking about phishing simulation training. Uh-huh.
Robert Siciliano:And that's it. So companies have adopted the phrase, the term, the generic term for security awareness training and placed it on phishing simulation training. And I disagree that, phishing simulation training is in fact security awareness training. I just think it's phishing simulation training. And, what truly is security awareness training is, you know, teaching personal security to the individual, to the consumer, to the user, to the employee.
Robert Siciliano:And personal security is where all security begins. It begins with the individual. And if you flesh out the definition of personal security, it truly is securing the person. And that means from violence and from theft. And back in the day, that meant in the physical world.
Robert Siciliano:And as security evolved, as our culture evolved, as technology evolved, security awareness became more than just in the physical world. It was also in in in today in the virtual world as well. So violence and theft prevention is protecting yourself both physically and digitally. Because as we know, you know, there are plenty of violent crimes that occur over the Internet. You know?
Robert Siciliano:And while they may not initially affect the physical being, they ultimately are, you know, violent crimes. And so when you teach security awareness training as I do, you incorporate the methodology that all security fundamentally is personal, and you present and teach from that perspective, the ultimate learning objectives and the outcomes, when it comes to training that individual are a lot more effective than simply phishing simulation training. Because you're you're providing a holistic training that effect... Effectively, you know, encompasses the person's entire existence when it comes to their security. And so in that time frame, thirty years, I've developed a number of different methodologies that, are designed to effectuate the outcomes.
Robert Siciliano:And one thing that I've come to a solid conclusion on over the course of my career is that we all have, when I say we, meaning humans, we all have what I consider the human blind spot. And the human blind spot is our psychological and biological want and need to trust each other. Human beings are what is considered an interdependent species. And as an interdependent species, that truly means that we are dependent upon each other for our survival. You know?
Robert Siciliano:Like, man needs woman, woman needs man fundamentally to procreate to further the species. And we... And that is based on that we trust each other. You know? In order for procreation to occur, there needs to be some fundamental trust.
Robert Siciliano:Otherwise, it would just be sexual assault. If you don't trust anybody, then it would be forced. So that said, this procreation demands trust. And if that's the basis of the fundamental of our existence, then every day, the people that we correspond with in person, the people that we meet, the person that call us, email us, text us, and ultimately those who we are on a video call like this, we want and need to trust that they don't wanna harm or hurt us, that they have our best interest in mind, and we wanna believe that they are essentially, you know, good with good intentions. Right?
Robert Siciliano:And so the human blind spot essentially is designed to define that, to put it in perspective, to provide an understanding that, you know, you you want as a human to give the benefit of the doubt all day every day. Like, is... You you... When somebody lies to you, you still want to believe them. You truly do, you know, because you wanna give the benefit of doubt.
Robert Siciliano:You don't want to think that somebody is out to hurt you. You want to think and believe that, you know, people are generally good. And in the course of my career, I've come to the conclusion that... And you could do your own research here. I think you'd come to the same results.
Robert Siciliano:They're probably like 97% of all the people that you will ever meet in the course of your life. 97% are good with good intentions. That they don't effectively, like, wake up every day intending on hurting and harming and deceiving. That in their heart that they are actually, you know, worthy of your trust. But about 3% of the world's population, and they say as much as six percent of men and about three percent of women, that they wake up every day with the intentions of deceiving, with the intentions of hurting and harming.
Robert Siciliano:The medical communities would define them as sociopaths and psychopaths. Now not all sociopaths and not all psychopaths intend on hurting or harming or deceiving, but many of them do. And they make a lot of noise and they do a lot of harm. And so when we get the wrong number text messages, when our networks are compromised, when somebody physically accosts or hurt or harms you, we can often consider them a sociopath or a psychopath or at least a hardcore narcissist that, intends on deceiving or hurting or harming. And so when you understand the human blind spot and you understand how you want to engage in trusting people all day every day and that when the phone rings and you get a text message or an email that you biologically and psychologically, like, are compelled to want to believe that person and how they're using that against us truly.
Robert Siciliano:Right? They use that as a methodology to hurt and harm us.
Dejan Kosutic:Can you provide a couple of examples just how this normally works from the attacker's point of view?
Robert Siciliano:Sure. Yeah. So criminals use what we call in most, you know, outbound or inbound communications, what we call manufactured urgency. Right? So if you look at your spam folder or even your inbox these days, because they're becoming more and more effective at getting scammy emails into the inbox, especially when they take over somebody else's account.
Robert Siciliano:Right? A legitimate email that has good demark and so forth. When we receive a communication that involves manufactured urgency, that's designed to get our blood pressure up. It's designed to engage us in such a way where if we don't act or react in a timely fashion to essentially update our account information, change our passcode, pay an invoice, refute an unauthorized charge and so forth. Right?
Robert Siciliano:Manufactured urgency.
Dejan Kosutic:Is this urgency actually connected to a human blind spot? Because urgency is one thing, and basically playing with someone else's trust might be completely another thing. Right?
Robert Siciliano:Yeah. So let's flesh that out. Right? So manufactured urgency is designed to, provide a scenario that ultimately, that scenario is believable. And its believability revolves around scenarios that either have happened to you before or you've seen elsewhere or you've heard about or ultimately just make sense to you.
Robert Siciliano:Right? Like that scenario, like, that you could pay a bill and that bill was authorized and that you would need to call a phone number if you didn't authorize it. Like, that makes sense. Like, you've probably done that before. Yeah.
Robert Siciliano:And so it's based on experience, and it's based on you trusting that PayPal, for example, who is sending you this communication is worthy of your trust because you have a relationship with PayPal. And so you trust PayPal. And the manufactured urgency is PayPal saying, hey, if you didn't authorize this transaction, call us, and we will put that money back into your account. Well, you trust PayPal fundamentally because you've done business with them basically over the course of your adult life over the past twenty years. And so it's that trust in that relationship with PayPal and the urgency based on PayPal saying, hey.
Robert Siciliano:You trust us and we're watching your back. And there's a charge here that if you don't agree with, give us a call.
Dejan Kosutic:Understood. So from your experience, what is the best method or the way to to handle this human blind spot or or this, let's say, that we... Or this notion that we would like to trust everyone?
Robert Siciliano:Well, we engage in what we call the AAA protocol. Right? And the AAA protocol essentially is, well, triple a is is analyze, authenticate, and then act. Right? And the idea behind the triple a protocol essentially is your break the fake playbook.
Robert Siciliano:It's designed to get you to understand and recognize what's happening to you when you receive that communication, that that manufactured urgency, say from PayPal, with the phone number to call. And so this entire motive... The entire motivation of that is is to capitalize and compromise your human blind spot, your trusting nature. And so the idea is that ultimately you engage in the break the fake playbook, the triple a protocol, and number one is you analyze. Recognize manufactured urgency.
Robert Siciliano:What is happening right now? What is happening to me? Right? The moment the request demands that you react now or else or it demands secrecy, it demands immediate action. What you must do immediately is just stop.
Robert Siciliano:Stop what you're doing. Right? Your brain, your body is now moving into emotional reaction, which is what most manufactured urgency type scams are designed to do by compromising your human blind spot. And so the idea is essentially to take a breath and move back into analytical thinking, away from emotion and back into analytical thinking, which is what most scams are designed to do is to get you emotionally charged up. Number two, the second part of the triple a protocol is authenticate.
Robert Siciliano:Identify, say, the scam. Identify the digital mask. Treat every income communication, every inbound communication, every phone call, text, email as a potential vulnerability because they are. Right? Look for the technical and even biological red flag, say, of a deep fake, of that manufactured urgency.
Robert Siciliano:See what's happening in front of your eyes. Text phone... Text, phone calls, emails, pop ups, whatever the case is. Right? And number three, act.
Robert Siciliano:Right? Execute what we call out of band verification. Out of band verification means, like, whatever the phone number is, whatever the text is, whatever the email is, whatever the call is, don't necessarily call or email right back in regards to that inbound communication. Do your own research. Never use the contact information provided in that suspicious message.
Robert Siciliano:Hang up and call the person back at a phone number that you know is legit, a pre validated phone number that might be in your contact manager, a phone number that you can research doing a quick Google search. Right? When you engage in the AAA protocol, what you're doing is you're breaking up the playbook. You're breaking up the momentum of that manufacturer urgency. You're going beyond your human blind spot.
Robert Siciliano:You're not automatically trusting.
Dejan Kosutic:Okay. This definitely makes sense. So let's use this example of that you mentioned for PayPal. So how would it work in this particular case that you mentioned of this impersonation email with PayPal?
Robert Siciliano:So I probably receive 10 emails a week that are scammy emails engaged in manufactured urgency that either end up in my inbox or my spam folder. I investigate every single one of them. And they might be coming from Amazon. They could be coming from Bank of America. They could be coming from any entity saying that your PayPal account has been charged.
Robert Siciliano:And so I know just by looking at it that no, my PayPal account wasn't charged. No, this isn't Bank of America or Amazon. If I really wanna verify it, I would just log in to Bank of America or I would just log in to Amazon or I would just log in to PayPal. I know it's all BS, so I'm not even gonna bother. But when I look at the fundamentals of the scam, it it has the Bank of America logo, it has the Amazon logo, it has the PayPal logo, it might have the Apple logo or the Microsoft logo, companies that I know, I like, I trust, and I do business with.
Robert Siciliano:And so many of the elements of these inbound communications, these scams, they are based on our trusting these companies that we've done business with. And most consumers understand that these companies in general are worthy of our trust because we've been working with them and doing business with them for decades. But they don't necessarily understand manufactured urgency. They don't understand their own human blind spot. They don't understand that the communication they just received is a scam itself.
Robert Siciliano:And the moment you pick up the phone and call the number to refute the charges, they don't understand that the act of picking up the phone, y'all are already going down the rabbit hole. Y'all are already compromised.
Dejan Kosutic:But if you want to apply this methodology of AAA, so basically, okay, the first one is to recognize that this might be a scam. Right? This is the first day. Right? The second day authenticate, how would you authenticate this kind of potentially malicious message?
Robert Siciliano:So like I just mentioned, would suggest first and foremost, log into your Amazon account, log into your Bank of America, log into your PayPal, like look for any messages within your account, outbound messages or in your message server to find out, hey, did Amazon just send me a note? Most people don't know enough to do that to begin with. Most people don't even think that they would even receive a communication like this. Most people are like, well, why would Amazon try to scam me? Why would PayPal try to scam me?
Robert Siciliano:Why would hackers try to hack me? Like most people aren't even thinking like that to begin with. They don't wanna think that bad things can happen to them at all. Most people are security averse, which is why we need to get back to the absolute basics, the absolute fundamentals with our employees. Because when all we're doing is trying to phish them, look for this, hover your mouse over that, do this, don't do that, or else, we're not actually training the employee to recognize risk.
Robert Siciliano:We're training the employee to understand what a phishing email looks like. But we're not actually engaging this employee in security awareness. We're trying to scare them. We're threatening them. And they don't want that.
Dejan Kosutic:Of course. Now, the the... What... For example, let's say that you have this email, let's say, impersonating your CEO. And basically this CEO then says, look, you have to transfer the, I don't know, dollars 100,000 to this account, let's say, within ten minutes, but do not contact anyone else.
Dejan Kosutic:Now, how should then a person use your AAA approach methods actually to deal with this kind of situation?
Robert Siciliano:Yeah, analyze exactly what's happening. You know, that request itself is significant and it revolves finances. And these are the things that we talk about.
Dejan Kosutic:Let's that this is received by someone who is doing the payment in the finance department.
Robert Siciliano:Yeah, which is their job. That's what they do for a living. And they're so accustomed to it. And they're going to be targeted. And they specifically need to understand that, listen, all you've gotta do is pick up the phone and call that person to find out, hey, did you just send me this email?
Robert Siciliano:Is this authorized? I am not going to distrust a digital communication by itself or even go knock...
Dejan Kosutic:But if you don't know the the the, you know, phone number from from your CEO ...
Robert Siciliano:Look it up.
Dejan Kosutic:It is not available.
Robert Siciliano:It's it's always available. It... The the communication is always available. The the person...
Robert Siciliano:Somebody in the in the organization at the switchboard knows how to get in touch with that person. It's guaranteed. And so that's the thing. We we have to go outside of the normal channels of communication, phone calls, emails, text messages, and and not necessarily take at face value that that communication is real or legit, that we need to engage in the triple a protocol, analyze, authenticate, and then act, execute the out of band verification. We can no longer automatically trust.
Robert Siciliano:We can't do that. And once the employee understands how vulnerable they are in regards to the human blind spot, and once they know that that in order for them to really prevent them from losing their job because they got caught up in a scam, which 75% of corporate vulnerabilities or... Are as a result of human error at this point is... Those are the studies that I see. And once that 75% see how vulnerable they actually are, they're going to want to find that phone number.
Dejan Kosutic:Okay. Now what kind of, let's say, reconnaissance or or analysis does does a scanner a scammer do before they actually start with the attack? So what...
Dejan Kosutic:How do they collect the information? What is their intelligence, so to say?
Robert Siciliano:So today, it is said that, and you could do your own research on this, that there are are about 300,000,000,000 of our records out there on the dark web. 300,000,000,000. That's over basically the past two decades. Okay? And so when there are 300,000,000,000 records out there on the dark web that are essentially are being sorted through and indexed and collated, that's usernames and passcodes, That's names, addresses, phone numbers.
Robert Siciliano:Right? That's that's email addresses. That's company names. That's everything about us. That is all the intelligence that a scammer needs on you and I to target us individually.
Robert Siciliano:Because they know what company we work for. They know our email address. They know who our coworkers are. They know where we are in the food chain in that company. And so they use every little bit of that against us, our social media.
Robert Siciliano:So they're able to target us specifically. And that makes the scam that much more effectively. And once they understand that, and once you point that out to them, and once you show them that, they're like, woah. I had no idea that any of this was actually a thing. And once they begin to see simply how vulnerable they actually are and how easy security actually is, then they want to know how to engage in personal protection first.
Robert Siciliano:And then it makes it much easier to send them phishing simulation training where they will be successful in.
Dejan Kosutic:Mhmm. Mhmm. Okay. Now if we switch the the, let's say, lens now and how do actually companies or security officers need to organize a training that actually handles this human blind spot? I mean, said that this efficient training does not work anymore.
Dejan Kosutic:So what does work from your experience?
Robert Siciliano:So the methodology that I've developed over the past thirty years is truly I want every single human who responds to the phone, email, text message, heck, every single human that's walking down the street to become what I call a strategic human firewall. A strategic human firewall essentially is situational awareness. You know? Mhmm. Situational awareness in the physical world is when you're walking down the street, you're looking up ahead to see if anybody's paying any unwanted attention to you.
Robert Siciliano:You're looking to the right, looking to the left, knowing what's going on behind you. You know, head on a swivel. You're you're anticipating and looking for potential risk. Right?
Robert Siciliano:We know that traditional firewalls filter traffic. A human firewall filters intent. What is the intent of this person? What is the intent of the phone call, email, and text message? And a strategic human firewall essentially blocks deception.
Robert Siciliano:It is essentially a proactive governance. It is a mindset that turns employees from passive targets to active detection layers. You are creating a human sensor network. It is the shift from by default because of my human blind spot, I trust what I see Two, I verify everything.
Dejan Kosutic:Does this mean that you develop, I don't know, a series of videos that actually where you display all the potential scenarios or all potential, let's say, types of attacks? Or how does this work in practice?
Robert Siciliano:In practice, this is a conversation like you and I are having. Right? The CISO, the CTO, the CSO, generally, they're not having a dialogue with their employees. Generally, they're not getting in front of all of their coworkers via an all hands event and having a conversation like this. Generally, they're stuffing videos down their throat.
Robert Siciliano:A monologue. They're being... The employees are being told what to do. Employees, when it comes to security, they don't wanna be told what to do. They wanna have a dialogue.
Robert Siciliano:They wanna have a conversation.
Dejan Kosutic:But how do you scale this kind of a conversation throughout the company? I mean, might be possible for, I don't know, a 30 employee company, but for a 3,000 employee company, not so. Right?
Robert Siciliano:No. It's easy to scale. I did a presentation in Silicon Valley, San Jose, California, not too long ago, where I spoke to a company that basically built the five gs network. They provide most of the original chips for cell phones, right? And I spoke in front of 400 people in a room, broadcast to 4,000 people worldwide.
Robert Siciliano:And I had a dialogue with 4,000 people. And how'd I do that? Well, the 400 people represented the 4,000. And the conversation was questions. It was me pointing all of this out.
Robert Siciliano:It was them asking questions. It was us having a conversation about the issues that they face every single day in their personal and professional lives. And by the time the seventy five to ninety minutes was over, like, they exhausted all of their questions. When they begin to ask questions as employees, some of the most absolute basic questions that employees ask are, for example, how do I know what links are okay to click when I do a Google search? Like, that's literally what they wanna know because they've never had an opportunity to ask that question before.
Robert Siciliano:How do I know what links are okay to click in a Google search? Like, if you have been online for twenty years, thirty years like I have, you know the answer. But most people don't. And they've never had an opportunity to ask such a rudimentary question. And it is that dialogue that is required in order to engage that employee, in scaling today is easier than it's ever been.
Dejan Kosutic:But in some cultures, let's say, people are not going to ask these kinds of questions. Will simply be, let's say, afraid or something like that. Might be, let's say, normally.
Robert Siciliano:What's interesting about that is when the hands go up, right, I start, okay, sir, you had a question. He asks that question. And like 10 seats over, another woman had her hand up. And I said, yes, ma'am, you had a question. She goes, oh, he asked the question that I was gonna ask.
Robert Siciliano:The reality is they all have the same questions. They all do. Everybody has the same concerns. We are concerned about our passwords and two factor authentication. We are all concerned about our home security and our children's security.
Robert Siciliano:We're all concerned about our digital footprint, our bank accounts and protecting our money. We're all concerned about the same exact things with the same questions. And once you begin to engage in a dialogue, it's amazing how quickly people raise their hand because they wanna know. There's never been a presentation where we didn't fully exhaust all those questions. And the CISO and the COO and the CIO and the CTO, they can do the exact same thing.
Robert Siciliano:And what's interesting about this is, like, single person has the same concerns, and every single person has family members that have the same vulnerabilities too. And so the CIO and the CSO and the CEO all have a mom that can't stop clicking links. Or a dad that responds to every single pop up and so And employees that are all doing the same things that all have family members with the same vulnerabilities. And so none of that is addressed in a phishing simulation training. All of that is addressed in a dialogue that we have.
Robert Siciliano:And once you engage in this dialogue, it's awesome. Every single presentation that I do, at the end of the program, I've got a line of people that are waiting for me. And and they say to me, you know what? I didn't wanna come here today. I came here because my boss told me I had to be here.
Robert Siciliano:But you know what? I'm so glad I did because this is nothing like I thought it was gonna be. This is about me. You know? And they say, I wish my spouse was here today because he or she would have loved it.
Robert Siciliano:We call that the kitchen table effect. The kitchen table effect is when they take what they learned at work and they bring it home and they teach it to their family. Try that with phishing simulation training. You're not gonna get that.
Dejan Kosutic:Okay. So you mentioned that this dialogue was organized with what, 400 people. So, and for what, ninety minutes, if I understood well? So, how do you actually get companies to organize this kind of an event? I assume this is not easy, right?
Robert Siciliano:Actually, you know, what happens is companies go through, you know, it's cyclical. What happens is over time, while their phishing simulation numbers might actually be proving pretty good, what they're finding is, and these are the phone calls that I get, we just want, while our our metrics are good in regards to our opens and, you know, deletes and such, we just want our employees to care about security. How do you get them to care? And I asked them a very simple question. When you are on an airplane and the flight attendant is providing instruction on the oxygen mask, What does she say to do?
Robert Siciliano:When the oxygen mask comes down, what do you do first? What do you do first?
Dejan Kosutic:Basically to put it on your own mouth, right?
Robert Siciliano:Exactly. You gotta take care of yourself first. And when it comes to security, you have to train the employee to protect themselves first. And once they know how to protect themselves first, then it makes it so much easier for them to protect the company. It's more natural and more normal for them to protect themselves first as a...
Robert Siciliano:Self care is fundamental to being a human being. And once we take care of ourselves first, it's so much easier for them to recognize risk and protect the organization. And that's what I do. I teach them how to protect themselves first to fundamentally appreciate the value that security has in their lives first so that once they're engaged in securing the corporate network, they have a better understanding and appreciation for the value of that process.
Dejan Kosutic:I understand the point, but isn't it very hard, you know, to to make a company really dedicate a part of their workforce for ninety minutes at the same time, at the same place? Isn't it really hard to achieve to get this kind of a general meeting?
Robert Siciliano:Well, in certain situations where you might have, say ten, fifteen, 20,000 employees, the presentations may need to be broken down into like, one to six to eight programs depending on. But once that's accomplished, you have a much higher level of employee engagement when it comes to protecting the corporate network. The return on investment is just astronomical. Smaller companies short, you don't necessarily have to provide as many programs, but we engage in certain forms of employee training all the time. You know, whether it's sales or customer service, like we're constantly engaged in keeping the employee up to speed in regards to all aspects of developing that employee.
Robert Siciliano:So security shouldn't be any different. And while we may only provide security awareness training once a year during, you know, Cybersecurity Awareness Month for compliance or regulatory issues, is that really all we wanna do? Are we just doing that because it's all we have to? Do we only develop the employee regarding other aspects of their job because we have to or because we know it's beneficial to the company's bottom line.
Dejan Kosutic:Okay. So are you saying that actually companies should start to do... Stop doing this, I would say, traditional phishing simulations and and awareness training. So let's say through videos and, let's say, computer based training and introduce this dialogue instead. Is this what you're saying?
Dejan Kosutic:Or should there be a... Some kind of a combination?
Robert Siciliano:Oh, absolutely, a combination. Phishing simulation training is absolutely necessary. But I think what it's doing is it's putting the cart before the horse. I think that what we wanna do is we wanna engage the employee first And then offer phishing simulation training. We're always gonna offer phishing simulation training.
Robert Siciliano:That should never stop. But what we should also be doing is we should actually truly engage them in security awareness training. True security awareness training. Listen, when I get in front of a live audience, my job is to challenge their belief systems in regards to what security is and what security isn't. So I ask them a number of different questions to challenge their belief systems.
Robert Siciliano:One of those questions I might ask them is, you know, how many of you have a home security system? If I get 15% of the room to raise their hand, that's a lot of people, which means 85% don't have a home security system. And why does this matter? Because security begins in the home. And I say to them, okay.
Robert Siciliano:So why don't you have a home security system? And the hands begin to fly up. One of the most common answers that I get is we don't have a home security system because I don't wanna live like that. And I say, well, what does that actually mean? And she says, I don't wanna live in fear.
Robert Siciliano:I don't wanna have to worry. And I say, so so what you're saying is installing a home security system is gonna make you worry? It's gonna make you live in fear? She goes, well, kinda. Yeah.
Robert Siciliano:She goes, I just wanna trust people. And I say, okay. And I go, I'm a guy, and this is true, I'm a guy that has 20 plus security cameras, which is true. Like, in my home, outside, inside my home in total, 20 plus security cameras. I say, so that being said, what might you think is my disposition, my belief system?
Robert Siciliano:Like, I wake up every day with 20 plus security cameras. I must be what? What do you think they say?
Dejan Kosutic:I don't know. Enthusiast, at least. Security enthusiast, at at the very least.
Robert Siciliano:You know what they truly say? They say you're paranoid. That's what they say. You're paranoid. And I say, well, what is paranoia?
Robert Siciliano:Paranoia, and and and I define it for them. Paranoia is the false belief that you are that you are being persecuted by others, unjustifiably persecuted by others. Right? That's what paranoia is. Paranoia is a mental health disease.
Robert Siciliano:And we as a culture, we associate security, putting systems in place, recognizing risk, mitigating risk, and paranoia. I don't wanna live like that. I don't wanna have to worry. I don't wanna live in fear. I don't wanna be paranoid, they say. We think as a culture that security and paranoia are the same thing. And that dichotomy prevents us from recognizing risk. Why would you embrace security if it's about worry and fear and paranoia? That's truly how most people think.
Robert Siciliano:Order to effectively engage an employee in security awareness training, you need to challenge their belief systems. And that's not being done by anyone anywhere. And that needs to take place first.
Dejan Kosutic:Okay. But how do you then balance between paranoia and security? Where is really this this, I would say, thin line where you're being, let's say, security conscious, but not really paranoid?
Robert Siciliano:There is no balancing security and paranoia. There is no thin line.
Robert Siciliano:That statement perpetrates that security and paranoia are actually in the same category, and they're not. Have you ever actually spent any time with somebody who's actually paranoid? People who are paranoid are living on red alert all the time. And that's what most people think security is, is living on red alert. The Strategic Human Firewall is not living on red alert.
Robert Siciliano:The Strategic Human Firewall is recognizing risk. Not because you worry, not because you live in fear, not because you are paranoid, because you understand what risk actually is. Walking down the street, you see on the sidewalk that a tree on the sidewalk has... Its root system has pushed the sidewalk up and caused a tripping hazard. That is recognizing risk.
Robert Siciliano:It's not living in fear. It's not being paranoid. It's seeing something for what it actually is.
Dejan Kosutic:I'm asking this question because very often non security people consider security people as paranoid. Right? But the question here is, you know, how should security people explain exactly what you were explaining, that they're not paranoid? They're they're simply, let's risk averse, that they are viewing the environment around them from the risk perspective and trying to reduce this risk.
Dejan Kosutic:So how to achieve this positive approach to security rather than negative?
Robert Siciliano:That's exactly where the dialogue begins. That's exactly where the dialogue begins. So for example, you are a chief information security officer. You get in front of your people through an all hands event, right? And you say, listen.
Robert Siciliano:You know, my mom, my my dad's been... You know, he he died a few years ago, which might might be a true story, like, it should be a true story. And my mom, like, you know, she's she's kinda lonely, and she's been on all these dating sites. And my mom, like, is vulnerable because, like, she gets these emails and these messages from these guys that, like, pose as, you know, military overseas, And they need my mom to help her... To help him move money from, you know, a house in Afghanistan to The US so they can live happily ever after.
Robert Siciliano:And I've gotta sit down with my mom and I've gotta explain to her mom, like, know you're lonely, but this guy, he's he's trying to scam you. And I guarantee there are employees in the room that have the exact same issues they're facing. And so when the CISO humanizes himself that he's not paranoid, he's got a mom too, just like you who has the same issues, that's where the dialogue begins. And so, you know, it's not about worry. It's not about fear.
Robert Siciliano:It's about, I'm just trying to protect my mom. And when you humanize yourself, you're changing what security actually is to most people. They no longer look at the CISO as being paranoid. He's making me do this. They look at the CISO as he's got a mom like I do, and we're all in this together.
Robert Siciliano:And security is about protecting our mom. It's about managing risk. It's about putting systems in place. It's about having uncomfortable conversations occasionally and doing things a little bit differently and seeing security for what it actually is. It's a good thing.
Dejan Kosutic:Okay. Okay, so when companies start introducing this kind of, let's say, dialogue as a method for security awareness raising, how can they actually measure the progress towards this strategic human firewall, as you were saying? Which kind of KPIs to use?
Robert Siciliano:You'll see it in your metrics in regards to phishing simulation. You'll see an improvement because people will, your employees will begin to recognize what's actually happening. Even the best phishing emails, somebody is gonna fall for occasionally. But once you actually engage the employee in a dialogue, they begin to stop emotionally moving in... To analytical thinking, and they begin to see the fraud and the scams and the manufactured urgency and their biology differently.
Robert Siciliano:And your metrics in regards to phishing simulation are gonna get even better. They might be pretty good now, and there's room for improve... There's always room for improvement.
Dejan Kosutic:Okay. But beyond these phishing metrics, are there any other metrics that are specific, let's say, for for these frameworks that you developed?
Robert Siciliano:I would say that if you're relying solely on a spreadsheet, I would say go right for your phishing simulation training.
Robert Siciliano:And then, you know, all hands on events. For example, right, when I engage a live audience and I see that same audience a year later, I ask a number of questions in the first, you know, the first time around and and hands go up. For example, like, I'll ask, how many of you can honestly say you're using a different passcode across all your critical accounts? If I get 10% of the room to raise their hand that they're using a different passcode, that's a lot. And I say, well, how many of you are using a password manager?
Robert Siciliano:If I get five to 10% of the room to raise their hand, that's a lot. Right? I speak to that same audience a year later. I ask the same questions. I might get 80% of the room to raise their hand that they're using obvious improvement.
Robert Siciliano:Yes. So once you actually engage them in this dialogue, you actually show the value of all these various security tools, these risk management tools, you show them of the 300,000,000,000 records that are compromised, it said that about 25,000,000,000 of them are actually our passwords on the dark web. Hackers aren't hacking, they're logging in. And you show them how it works. You show them the data on the dark web and they're like, woah, I had no idea.
Robert Siciliano:And once you show them how vulnerable they are for using the same passcode across multiple accounts and you actually truly show them examples of it, they're like, woah, I I had no idea. They don't understand why they have to change a passcode. They don't understand why it has to be uppercase, lowercase numbers and characters. They don't understand why. Therefore, they don't care.
Robert Siciliano:They just want it to be easy. And when you say password manager, woah, I'm not using a password manager. Password managers can be hacked. They're engaging in fatalism justify why they don't use a password manager. Because they don't understand that the likelihood of a password manager getting hacked is like slim to none.
Robert Siciliano:It's slim to none. Can they be hacked? Sure. But so can your bank. But you put money in a bank.
Robert Siciliano:And once you engage them in a dialogue that explains all of this, and they ask questions in response to it, and they are literally gonna say, well, why would I... They will literally say, why would I use a password manager if it can be hacked? Which is a perfect question, and it's a perfect opportunity to explain how that all works.
Dejan Kosutic:This definitely makes sense. Okay. So let's up the discussion for today.
Dejan Kosutic:So what are, let's say, top things that you recommend to CISOs to actually avoid this human blind spot in their companies?
Robert Siciliano:Start with an all hands event. Truly start with an all hands event. Start with a dialogue. Start with a dialogue. See where it goes.
Robert Siciliano:Even if it's not the whole company, start with like a small division. Right? Start with HR. Just sit down with HR and have a conversation with them because they're hearing all kinds of questions, right, all the time. And even if it's only, like, five, ten, fifteen, twenty people and see how it goes and watch and see how it plays out.
Robert Siciliano:And I guarantee you, you will make a connection with that room. You will make connections with your employees like you never have in the course of your career because people are literally afraid. They literally are afraid and they don't know what to do. They they have questions and they have no answers. Security is scary to people.
Robert Siciliano:It's It's thieves. It's hackers. It's it's mysterious. And the people that do it, they they... They're they're bad apples and they want to hurt you.
Robert Siciliano:And that's how they see it because it's true. And they don't know what to do. And nobody has ever actually sat them down and said, you know what? We're gonna figure this thing out together. And that's what you can and should do.
Robert Siciliano:And you'd be amazed at the results. It's what I do.
Dejan Kosutic:Great. Thanks for these insights. It's been a pleasure talking to you and I've learned a lot today.
Dejan Kosutic:Then thanks everyone for listening or watching this podcast and see you again in two weeks time in our new episode of Secure and Simple podcast. Thanks for making it this far in today's episode of Secure and Simple podcast. Here's some useful info for consultants and other professionals who do cybersecurity governance and compliance for a living. On Advisera website, can check out various tools that can help your business. For example, Conformio software enables you to streamline and scale ISO 27,001 implementation and maintenance for your clients.
Dejan Kosutic:White label documentation toolkits for NIS 2, DORA, ISO 27,001 and other ISO standards enable you to create all the required documents for your clients. Accredited Lead auditor and Lead implementer courses for various standards and frameworks enable you to show your expertise to potential clients. And a learning management system called Company Training Academy with numerous videos for NIS2, DORA, ISO 27,001 and other frameworks enable you to organize training and awareness programs for your clients workforce. Check out the links in the description below for more information. If you like this podcast, please give it a thumbs up, it helps us with better ranking and I would also appreciate if you share it with your colleagues.
Dejan Kosutic:That's it for today, stay safe.
Creators and Guests
