WEBVTT
00:00:01.199 --> 00:00:06.240
Welcome to Cyberminded, where cybersecurity, behavior, and leadership meet.
00:00:06.400 --> 00:00:06.959
I'm Dr.
00:00:07.120 --> 00:00:14.960
Dustin Sachs, and this podcast, co-sponsored by CyberCog Labs and Cybersec Media, asks a simple question.
00:00:15.119 --> 00:00:21.120
What if the biggest risks in cybersecurity start with how we think, decide, and respond?
00:00:21.440 --> 00:00:27.199
Each episode is a chance to pause, reflect, and see security through a more human lens.
00:00:27.359 --> 00:00:33.280
Let's take some time and look beyond the controls to the human side of cybersecurity.
00:00:34.159 --> 00:00:35.840
Hello, Cyberminders.
00:00:36.000 --> 00:00:36.320
Dr.
00:00:36.479 --> 00:00:42.320
Dustin Sachs here, host of Cyberminded and founder and CEO of Cybercog Labs.
00:00:42.880 --> 00:00:46.560
And for today, I wanted to do a very special episode.
00:00:46.799 --> 00:00:57.119
I wanted to reflect on what we learned out at Hacker Summer Camp, out at Black Hat, DEF CON, B-sides.
00:00:57.679 --> 00:01:09.680
And the way we wanted to do that is by sharing some clips from a couple of individuals who we spoke with out at um Hacker Summer Camp out in Vegas.
00:01:10.000 --> 00:01:15.280
We spoke with Rock Lambrose, who is an AI expert.
00:01:15.439 --> 00:01:30.079
We spoke with Mel Reyes, multi-time CISO, Andres Sendreyu, author in multi-time CISO, and Mark Alba, who is part of Cyberminds and the Mesh Commons organization.
00:01:30.319 --> 00:01:42.319
We also wanted to share clips of existing guests that you've already met and some of the guests that you're going to see in the remainder of season one of Cyberminded.
00:01:42.799 --> 00:01:47.519
And really, we wanted to focus on the key question we ask at the beginning of every episode.
00:01:48.719 --> 00:01:54.400
When you hear the phrase the human side of cybersecurity, what does that mean to you?
00:01:54.480 --> 00:01:58.159
And where do you think organizations misunderstand that?
00:01:58.959 --> 00:02:23.919
You know, early in the uh season, we spoke with Calvin Nobles, who mentioned that he had done some research on this topic and that he found that uh for every person that answered uh the question about what does human factors or human side of cybersecurity mean to you, um there were about 17 answers that came out.
00:02:24.319 --> 00:02:28.240
Um, and we're really seeing that play out in every episode.
00:02:28.560 --> 00:02:42.400
So really excited to share the clips that we got both out at Black Hat and some of the clips that you have seen already, or uh maybe want to go back and watch previous episodes.
00:02:42.560 --> 00:02:48.319
Also, you'll get to see some of the clips of some of the uh guests that we've got still to come for you.
00:02:48.479 --> 00:02:53.360
Uh, we look forward to seeing everybody on the next episode.
00:02:53.520 --> 00:02:56.400
Thank you so much for your support to date.
00:02:56.639 --> 00:02:58.560
This has been a really awesome experience.
00:02:58.639 --> 00:03:01.039
We look forward to so many more episodes.
00:03:01.199 --> 00:03:05.840
We've got a bunch of really cool guests that we're already scheduling.
00:03:06.080 --> 00:03:22.960
And uh, we encourage you to like, subscribe, follow us, uh check out Cybercog Labs, check out the uh cybersec community, and uh we look forward to seeing you real soon.
00:03:23.439 --> 00:03:28.319
Before we go further, this episode is supported by Cybercog Labs.
00:03:28.639 --> 00:03:38.719
At Cybercog Labs, we help cybersecurity and risk leaders look beyond control design to understand where human behavior is shaping cyber risk.
00:03:39.039 --> 00:03:52.719
Because the issue is not that a control does not exist, it's that the control breaks down when real people encounter pressure, ambiguity, competing priorities, unclear incentives, or decision fatigue.
00:03:53.120 --> 00:04:01.840
Cybercog Labs helps leaders identify those breakdowns and turn behavioral cyber risk into practical, board-relevant insight.
00:04:02.080 --> 00:04:04.639
Visit us at cybercog.com.
00:04:04.960 --> 00:04:10.240
That's P-S Y B-E-R-C-O-G.com.
00:04:10.560 --> 00:04:14.960
Now, with that in mind, let's get into the problem beneath the problem.
00:04:27.439 --> 00:04:34.639
But the flip side of that is the human impact on cybersecurity events, consumers and families and everything else.
00:04:35.040 --> 00:04:43.120
Uh it's all stressors, all key stressors that have a massive impact on financials, emotionals, and relationships.
00:04:43.519 --> 00:04:46.000
Human side of cybersecurity and what does it mean to me?
00:04:46.079 --> 00:04:59.759
So I've sat in the side for uh better part of my career, uh, and I think when people think about the human side, the empathetic CISOs, the empathetic leaders, understand that human side means understanding personal.
00:05:00.079 --> 00:05:04.480
It means understanding the workload in the aimless sense.
00:05:04.959 --> 00:05:12.399
Uh the reverse side of it is unfortunately very prevalent within uh a lot of cybersecurity, which is the hero mentality.
00:05:12.480 --> 00:05:18.240
Um you always have to be on, you always have to be fighting something, you always have to have a huge amount of workload.
00:05:18.399 --> 00:05:31.199
Um, which, while uh, you know, maybe satisfying from a hero perspective, uh ends up causing more of a potential mess within your organization because your humanists are not performing.
00:05:31.360 --> 00:05:36.959
Um human side is focus on the technology but understand that humans have to operate that technology.
00:05:38.079 --> 00:05:40.240
The human side of cybersecurity.
00:05:43.040 --> 00:05:46.240
I mean, it's honestly the burnout I think that people aren't accounting for.
00:05:46.560 --> 00:05:49.680
And I think that is where organizations are also giving it wrong.
00:05:50.240 --> 00:06:01.360
Uh throwing more tools, even more UA people without understanding how to leverage it to reduce the cognitive workload on the people that it's affecting.
00:06:01.519 --> 00:06:03.120
Um burnout is real.
00:06:03.360 --> 00:06:04.319
The burnout is real.
00:06:04.480 --> 00:06:08.079
I've suffered it every I used to let a global knocks out.
00:06:08.560 --> 00:06:13.120
Um every animal is not knocked out was burnout through just alert fatigue.
00:06:13.279 --> 00:06:25.279
And now we're seeing it a hundredfold by asking people to be the human in the loop for VI and Angentique AI, um, where now we just turn people into a bunch of rubber samples.
00:06:25.600 --> 00:06:29.120
Yeah, and that copy of dissidents just continues to increase.
00:06:29.920 --> 00:06:32.319
So I think there's a two-fold answer here.
00:06:32.560 --> 00:06:41.279
On the one hand, you have users and the psychology that comes with users, which is predominantly centered around functionality and not security.
00:06:41.439 --> 00:06:44.560
And then you have the adversarial mindset on the other side.
00:06:44.879 --> 00:06:58.240
In the middle is the enterprise reality where you're trying to protect from the adversary, and then you're trying to protect users from themselves, really, because they're the ones that generally make mistakes that are done in unfortunate situations.
00:06:58.879 --> 00:07:13.040
To me, you know, as a marketer and a person who loves psychology and connecting with people, the human side is understanding those connections and how to further and strengthen them through the words that we use.
00:07:14.560 --> 00:07:38.720
The human side of cybersecurity are the people in the trenches, the threat hunters, the security architects and engineers, the um governance, risk, and compliance practitioners, um, everybody who's responsible for a business's security.
00:07:39.120 --> 00:07:53.680
And, you know, um we often talk when we're talking about cybersecurity, as you pointed out at the beginning, you know, we we talk a lot about the technology.
00:07:54.639 --> 00:08:05.360
And we don't talk nearly enough about the environmental conditions for the people who are working the technology.
00:08:06.079 --> 00:08:17.040
And um, but over the last year it's really become a front burner topic, which I've been glad to see.
00:08:17.279 --> 00:08:37.120
But what it means to me is um everything to do with making sure that the human behind the technologies and behind the policies um have the can the conditions and environment that they need to do their work consistently.
00:08:37.360 --> 00:08:53.440
And you can't do your work consistently if you're in a stressful environment, if your um basic needs for how one should take care of themselves aren't being met.
00:08:54.000 --> 00:08:55.039
That's a great question.
00:08:55.279 --> 00:08:59.919
Um, to me, the human side is really all of it.
00:09:00.240 --> 00:09:04.080
It's not just the people, it's the process and the technology as well.
00:09:04.399 --> 00:09:17.200
Because you need people, of course, but your processes will not work if you don't have the people in place to establish the processes to ensure that they're being maintained and to update them as things change.
00:09:17.360 --> 00:09:33.200
And then from a technology perspective, you know, especially in this age of AI, where you have to be verifying or validating inputs and outputs, like the human element is key to the success of an entire cybersecurity program to every organization.
00:09:33.519 --> 00:09:46.720
Um, and when we start to over work and burn out these resources, not just in security, but across the board, um, that's when you start to see mistakes happen and incidents occur.
00:09:46.799 --> 00:09:48.480
And it is, it's all tied together.
00:09:48.559 --> 00:09:52.799
And the in the human element piece, um, you know, it's like a car.
00:09:53.200 --> 00:09:56.480
I think we use car analogies and and security all the time, right?
00:09:56.639 --> 00:10:05.759
But you know, if you're if you're running your engine at the max revs constantly, you're gonna run out of gas sooner and things are gonna start to break.
00:10:06.000 --> 00:10:22.559
So you have to treat, I guess, treat yourself like a car and slow down a little bit, use your brakes, you know, check your mirrors, see what's going on around you, make sure that you're recognizing the signs in yourself and your teammates, and if you're a leader in your team, um, and you know, send yourself in for a tune-up every now and again.
00:10:22.799 --> 00:10:32.240
I think we have to understand that I can write a cybersecurity policy that says you shall patch in one day, and it's gonna fail miserably.
00:10:32.559 --> 00:10:40.559
Because I need to actually go beyond anything in policy to say what's the process and what's just how people work.
00:10:40.720 --> 00:10:45.200
How do I make cyber really, really easy for them to do the right thing?
00:10:45.440 --> 00:10:59.679
Because it doesn't matter what's on paper, it doesn't matter what tool does something, it matters how the people implement the tool, what is the daily practice of things, what is the tradecraft of the organization because that is where the rubber meets the the road.
00:11:00.080 --> 00:11:07.679
We all have been in a fishing training simulation, we know not to click the fish, but someone's gonna click a fish.
00:11:08.000 --> 00:11:14.399
And how do we make sure we're we're a good organization despite knowing we're gonna have human failures?
00:11:14.639 --> 00:11:23.759
Well, there that's it's funny because when you say the human side of cybersecurity, a lot of people sit there and say, oh, it's immediately identity and access management, right?
00:11:23.840 --> 00:11:29.039
They instantly think of user IDs and passwords, but it's so much more than that, right?
00:11:29.279 --> 00:11:48.000
It's it's the ability to make trustworthy decision making, it's the ability to be able to understand um how we interact, not just professionally, but how we interact uh with other portions of our organization when we're assessing risk, which is a whole nother problem, right?
00:11:48.240 --> 00:11:52.879
And then there's the human side, which is also there's a piece of identity, right?
00:11:53.120 --> 00:11:58.480
But um it encompasses so much more than what the average person would think of.
00:11:58.720 --> 00:11:58.960
Absolutely.
00:11:59.039 --> 00:12:00.240
This is a fantastic question.
00:12:00.320 --> 00:12:13.519
So when I heard that phrase, the human side of cybersecurity, to me, it is the it is the most salent aspect of cyber of it's the most salent point of cybersecurity.
00:12:13.759 --> 00:12:18.639
Because without the human aspect of cybersecurity, you can't advance cybersecurity at all.
00:12:18.879 --> 00:12:25.759
Because ultimately, in cybersecurity, the humans are responsible for everything about cybersecurity.
00:12:26.240 --> 00:12:38.639
And for me, when when I see the advances that were made in cybersecurity, I see a lot of it around the technological aspect, and I see very little around really trying to understand the human behavior.
00:12:38.720 --> 00:13:07.840
And I make one critical point here, and that is if you look at most cybersecurity teams today, and they look at their most of their operations, very few, if any, have a dedicated staff uh expert who understands human behavior, human factors, cognitive psychology, or anything of neuroscience to help them understand human behavior and how people are going to perform within the ecosystem that they built.
00:13:08.159 --> 00:13:10.159
And so it's always a red flag for me.
00:13:10.240 --> 00:13:13.360
But at the same time, Dustin, I will say this.
00:13:15.759 --> 00:13:28.799
The way so the way human the way cybersecurity has morphed into what it is today, uh, one of the things that I could that I say is that the problem that we face today with the human element and cybersecurity is not an industry problem alone.
00:13:29.120 --> 00:13:33.840
It's a government problem, it's an academia problem, and it's definitely an industry problem.
00:13:34.080 --> 00:13:40.879
And we need to work in that threesome in that threesome there to fix and address the human element in cybersecurity.
00:13:41.279 --> 00:13:42.159
That is a fun question.
00:13:42.320 --> 00:13:51.279
So I think actually that a lot of cybersecurity resides in the human side and that it gets overlooked a lot.
00:13:51.919 --> 00:13:54.320
Um, you called it squishy, I love that.
00:13:54.559 --> 00:14:13.279
Um there's a temptation to skip the squishy, uh, and to want to like not deal, skipping the sort of obvious information that like people have been perpetuating fraud on each other for a long time, and that basically entirely lives in the space of people being squishy.
00:14:13.600 --> 00:14:30.799
This episode is brought to you in part by Cybersec Media, a cybersecurity media and community platform built for practitioners, leaders, and innovators who want sharper conversations about the human, technical, and operational realities of security.
00:14:31.120 --> 00:14:42.080
And if you want to be part of that community in person, get your tickets now for CybersecCon, happening September 15th and 16th, 2026 in Houston, Texas.
00:14:42.480 --> 00:14:51.759
Join cybersecurity leaders, practitioners, researchers, and innovators for two days of insight, a connection, and actionable strategies.
00:14:52.159 --> 00:14:56.000
Secure your spot today at cyberseccon.com.
00:14:56.399 --> 00:15:02.960
That's cyber without the e at S E C C O N dot com.
00:15:03.360 --> 00:15:18.159
We hope you enjoyed this uh special episode of Cyberminded as we uh kind of look back and uh take a pause uh in the aftermath of all of the hacker summer camp activities out in Vegas.
00:15:18.480 --> 00:15:30.639
If you attended B Sides, if you attended Black Hat, DEF CON, any of the uh other activities that were happening in Las Vegas, hope that you made it home safe, hope that you had a great time.
00:15:30.960 --> 00:15:46.960
I hope that you really enjoyed hearing from not only current future guests, but also some uh key followers and key uh individuals that we met out at uh out at Black Hat.
00:15:47.279 --> 00:15:57.279
And as we always say, you know, it's really important that you look beyond the controls and pay attention to the human side of cybersecurity.
00:15:57.440 --> 00:15:59.840
We'll see you again on the next episode.
00:16:03.039 --> 00:16:09.440
This has been a cybersec media production recorded in partnership with CyberCog Labs.
00:16:09.919 --> 00:16:12.080
Cyberminded is hosted by Dr.
00:16:12.159 --> 00:16:13.279
Dustin Sachs.
00:16:13.600 --> 00:16:19.759
It's directed by Bill Brenner, produced by Lauren Andris, and edited by Ivan Basconcillo.
00:16:19.840 --> 00:16:28.799
The views and opinions expressed in this show are those of the speakers and do not necessarily reflect the views or positions of any entities they represent.
00:16:28.960 --> 00:16:35.919
This show is for informational purposes only and does not render or offer to render personalized advice.
00:16:36.159 --> 00:16:38.960
Subscribe now so you never miss an episode.
00:16:39.120 --> 00:16:45.600
You can find all our podcasts, articles, blogs, and conference talks on cybersecmedia.com.
00:16:45.679 --> 00:16:47.519
That's cyberwithout the e.
00:16:47.840 --> 00:16:54.639
And follow cybersec Media on LinkedIn, X, Instagram, Facebook, TikTok, and YouTube.
00:16:55.039 --> 00:17:02.799
You can keep up with our conferences by following us on LinkedIn, X, Instagram, and Facebook at Cybersec Events.
00:17:02.879 --> 00:17:11.839
And you can learn more about our events or buy tickets at cybersec.community slash cyberseconds.
00:00:01.199 --> 00:00:06.240
Welcome to Cyberminded, where cybersecurity, behavior, and leadership meet.
00:00:06.400 --> 00:00:06.959
I'm Dr.
00:00:07.120 --> 00:00:14.960
Dustin Sachs, and this podcast, co-sponsored by CyberCog Labs and Cybersec Media, asks a simple question.
00:00:15.119 --> 00:00:21.120
What if the biggest risks in cybersecurity start with how we think, decide, and respond?
00:00:21.440 --> 00:00:27.199
Each episode is a chance to pause, reflect, and see security through a more human lens.
00:00:27.359 --> 00:00:33.280
Let's take some time and look beyond the controls to the human side of cybersecurity.
00:00:34.159 --> 00:00:35.840
Hello, Cyberminders.
00:00:36.000 --> 00:00:36.320
Dr.
00:00:36.479 --> 00:00:42.320
Dustin Sachs here, host of Cyberminded and founder and CEO of Cybercog Labs.
00:00:42.880 --> 00:00:46.560
And for today, I wanted to do a very special episode.
00:00:46.799 --> 00:00:57.119
I wanted to reflect on what we learned out at Hacker Summer Camp, out at Black Hat, DEF CON, B-sides.
00:00:57.679 --> 00:01:09.680
And the way we wanted to do that is by sharing some clips from a couple of individuals who we spoke with out at um Hacker Summer Camp out in Vegas.
00:01:10.000 --> 00:01:15.280
We spoke with Rock Lambrose, who is an AI expert.
00:01:15.439 --> 00:01:30.079
We spoke with Mel Reyes, multi-time CISO, Andres Sendreyu, author in multi-time CISO, and Mark Alba, who is part of Cyberminds and the Mesh Commons organization.
00:01:30.319 --> 00:01:42.319
We also wanted to share clips of existing guests that you've already met and some of the guests that you're going to see in the remainder of season one of Cyberminded.
00:01:42.799 --> 00:01:47.519
And really, we wanted to focus on the key question we ask at the beginning of every episode.
00:01:48.719 --> 00:01:54.400
When you hear the phrase the human side of cybersecurity, what does that mean to you?
00:01:54.480 --> 00:01:58.159
And where do you think organizations misunderstand that?
00:01:58.959 --> 00:02:23.919
You know, early in the uh season, we spoke with Calvin Nobles, who mentioned that he had done some research on this topic and that he found that uh for every person that answered uh the question about what does human factors or human side of cybersecurity mean to you, um there were about 17 answers that came out.
00:02:24.319 --> 00:02:28.240
Um, and we're really seeing that play out in every episode.
00:02:28.560 --> 00:02:42.400
So really excited to share the clips that we got both out at Black Hat and some of the clips that you have seen already, or uh maybe want to go back and watch previous episodes.
00:02:42.560 --> 00:02:48.319
Also, you'll get to see some of the clips of some of the uh guests that we've got still to come for you.
00:02:48.479 --> 00:02:53.360
Uh, we look forward to seeing everybody on the next episode.
00:02:53.520 --> 00:02:56.400
Thank you so much for your support to date.
00:02:56.639 --> 00:02:58.560
This has been a really awesome experience.
00:02:58.639 --> 00:03:01.039
We look forward to so many more episodes.
00:03:01.199 --> 00:03:05.840
We've got a bunch of really cool guests that we're already scheduling.
00:03:06.080 --> 00:03:22.960
And uh, we encourage you to like, subscribe, follow us, uh check out Cybercog Labs, check out the uh cybersec community, and uh we look forward to seeing you real soon.
00:03:23.439 --> 00:03:28.319
Before we go further, this episode is supported by Cybercog Labs.
00:03:28.639 --> 00:03:38.719
At Cybercog Labs, we help cybersecurity and risk leaders look beyond control design to understand where human behavior is shaping cyber risk.
00:03:39.039 --> 00:03:52.719
Because the issue is not that a control does not exist, it's that the control breaks down when real people encounter pressure, ambiguity, competing priorities, unclear incentives, or decision fatigue.
00:03:53.120 --> 00:04:01.840
Cybercog Labs helps leaders identify those breakdowns and turn behavioral cyber risk into practical, board-relevant insight.
00:04:02.080 --> 00:04:04.639
Visit us at cybercog.com.
00:04:04.960 --> 00:04:10.240
That's P-S Y B-E-R-C-O-G.com.
00:04:10.560 --> 00:04:14.960
Now, with that in mind, let's get into the problem beneath the problem.
00:04:27.439 --> 00:04:34.639
But the flip side of that is the human impact on cybersecurity events, consumers and families and everything else.
00:04:35.040 --> 00:04:43.120
Uh it's all stressors, all key stressors that have a massive impact on financials, emotionals, and relationships.
00:04:43.519 --> 00:04:46.000
Human side of cybersecurity and what does it mean to me?
00:04:46.079 --> 00:04:59.759
So I've sat in the side for uh better part of my career, uh, and I think when people think about the human side, the empathetic CISOs, the empathetic leaders, understand that human side means understanding personal.
00:05:00.079 --> 00:05:04.480
It means understanding the workload in the aimless sense.
00:05:04.959 --> 00:05:12.399
Uh the reverse side of it is unfortunately very prevalent within uh a lot of cybersecurity, which is the hero mentality.
00:05:12.480 --> 00:05:18.240
Um you always have to be on, you always have to be fighting something, you always have to have a huge amount of workload.
00:05:18.399 --> 00:05:31.199
Um, which, while uh, you know, maybe satisfying from a hero perspective, uh ends up causing more of a potential mess within your organization because your humanists are not performing.
00:05:31.360 --> 00:05:36.959
Um human side is focus on the technology but understand that humans have to operate that technology.
00:05:38.079 --> 00:05:40.240
The human side of cybersecurity.
00:05:43.040 --> 00:05:46.240
I mean, it's honestly the burnout I think that people aren't accounting for.
00:05:46.560 --> 00:05:49.680
And I think that is where organizations are also giving it wrong.
00:05:50.240 --> 00:06:01.360
Uh throwing more tools, even more UA people without understanding how to leverage it to reduce the cognitive workload on the people that it's affecting.
00:06:01.519 --> 00:06:03.120
Um burnout is real.
00:06:03.360 --> 00:06:04.319
The burnout is real.
00:06:04.480 --> 00:06:08.079
I've suffered it every I used to let a global knocks out.
00:06:08.560 --> 00:06:13.120
Um every animal is not knocked out was burnout through just alert fatigue.
00:06:13.279 --> 00:06:25.279
And now we're seeing it a hundredfold by asking people to be the human in the loop for VI and Angentique AI, um, where now we just turn people into a bunch of rubber samples.
00:06:25.600 --> 00:06:29.120
Yeah, and that copy of dissidents just continues to increase.
00:06:29.920 --> 00:06:32.319
So I think there's a two-fold answer here.
00:06:32.560 --> 00:06:41.279
On the one hand, you have users and the psychology that comes with users, which is predominantly centered around functionality and not security.
00:06:41.439 --> 00:06:44.560
And then you have the adversarial mindset on the other side.
00:06:44.879 --> 00:06:58.240
In the middle is the enterprise reality where you're trying to protect from the adversary, and then you're trying to protect users from themselves, really, because they're the ones that generally make mistakes that are done in unfortunate situations.
00:06:58.879 --> 00:07:13.040
To me, you know, as a marketer and a person who loves psychology and connecting with people, the human side is understanding those connections and how to further and strengthen them through the words that we use.
00:07:14.560 --> 00:07:38.720
The human side of cybersecurity are the people in the trenches, the threat hunters, the security architects and engineers, the um governance, risk, and compliance practitioners, um, everybody who's responsible for a business's security.
00:07:39.120 --> 00:07:53.680
And, you know, um we often talk when we're talking about cybersecurity, as you pointed out at the beginning, you know, we we talk a lot about the technology.
00:07:54.639 --> 00:08:05.360
And we don't talk nearly enough about the environmental conditions for the people who are working the technology.
00:08:06.079 --> 00:08:17.040
And um, but over the last year it's really become a front burner topic, which I've been glad to see.
00:08:17.279 --> 00:08:37.120
But what it means to me is um everything to do with making sure that the human behind the technologies and behind the policies um have the can the conditions and environment that they need to do their work consistently.
00:08:37.360 --> 00:08:53.440
And you can't do your work consistently if you're in a stressful environment, if your um basic needs for how one should take care of themselves aren't being met.
00:08:54.000 --> 00:08:55.039
That's a great question.
00:08:55.279 --> 00:08:59.919
Um, to me, the human side is really all of it.
00:09:00.240 --> 00:09:04.080
It's not just the people, it's the process and the technology as well.
00:09:04.399 --> 00:09:17.200
Because you need people, of course, but your processes will not work if you don't have the people in place to establish the processes to ensure that they're being maintained and to update them as things change.
00:09:17.360 --> 00:09:33.200
And then from a technology perspective, you know, especially in this age of AI, where you have to be verifying or validating inputs and outputs, like the human element is key to the success of an entire cybersecurity program to every organization.
00:09:33.519 --> 00:09:46.720
Um, and when we start to over work and burn out these resources, not just in security, but across the board, um, that's when you start to see mistakes happen and incidents occur.
00:09:46.799 --> 00:09:48.480
And it is, it's all tied together.
00:09:48.559 --> 00:09:52.799
And the in the human element piece, um, you know, it's like a car.
00:09:53.200 --> 00:09:56.480
I think we use car analogies and and security all the time, right?
00:09:56.639 --> 00:10:05.759
But you know, if you're if you're running your engine at the max revs constantly, you're gonna run out of gas sooner and things are gonna start to break.
00:10:06.000 --> 00:10:22.559
So you have to treat, I guess, treat yourself like a car and slow down a little bit, use your brakes, you know, check your mirrors, see what's going on around you, make sure that you're recognizing the signs in yourself and your teammates, and if you're a leader in your team, um, and you know, send yourself in for a tune-up every now and again.
00:10:22.799 --> 00:10:32.240
I think we have to understand that I can write a cybersecurity policy that says you shall patch in one day, and it's gonna fail miserably.
00:10:32.559 --> 00:10:40.559
Because I need to actually go beyond anything in policy to say what's the process and what's just how people work.
00:10:40.720 --> 00:10:45.200
How do I make cyber really, really easy for them to do the right thing?
00:10:45.440 --> 00:10:59.679
Because it doesn't matter what's on paper, it doesn't matter what tool does something, it matters how the people implement the tool, what is the daily practice of things, what is the tradecraft of the organization because that is where the rubber meets the the road.
00:11:00.080 --> 00:11:07.679
We all have been in a fishing training simulation, we know not to click the fish, but someone's gonna click a fish.
00:11:08.000 --> 00:11:14.399
And how do we make sure we're we're a good organization despite knowing we're gonna have human failures?
00:11:14.639 --> 00:11:23.759
Well, there that's it's funny because when you say the human side of cybersecurity, a lot of people sit there and say, oh, it's immediately identity and access management, right?
00:11:23.840 --> 00:11:29.039
They instantly think of user IDs and passwords, but it's so much more than that, right?
00:11:29.279 --> 00:11:48.000
It's it's the ability to make trustworthy decision making, it's the ability to be able to understand um how we interact, not just professionally, but how we interact uh with other portions of our organization when we're assessing risk, which is a whole nother problem, right?
00:11:48.240 --> 00:11:52.879
And then there's the human side, which is also there's a piece of identity, right?
00:11:53.120 --> 00:11:58.480
But um it encompasses so much more than what the average person would think of.
00:11:58.720 --> 00:11:58.960
Absolutely.
00:11:59.039 --> 00:12:00.240
This is a fantastic question.
00:12:00.320 --> 00:12:13.519
So when I heard that phrase, the human side of cybersecurity, to me, it is the it is the most salent aspect of cyber of it's the most salent point of cybersecurity.
00:12:13.759 --> 00:12:18.639
Because without the human aspect of cybersecurity, you can't advance cybersecurity at all.
00:12:18.879 --> 00:12:25.759
Because ultimately, in cybersecurity, the humans are responsible for everything about cybersecurity.
00:12:26.240 --> 00:12:38.639
And for me, when when I see the advances that were made in cybersecurity, I see a lot of it around the technological aspect, and I see very little around really trying to understand the human behavior.
00:12:38.720 --> 00:13:07.840
And I make one critical point here, and that is if you look at most cybersecurity teams today, and they look at their most of their operations, very few, if any, have a dedicated staff uh expert who understands human behavior, human factors, cognitive psychology, or anything of neuroscience to help them understand human behavior and how people are going to perform within the ecosystem that they built.
00:13:08.159 --> 00:13:10.159
And so it's always a red flag for me.
00:13:10.240 --> 00:13:13.360
But at the same time, Dustin, I will say this.
00:13:15.759 --> 00:13:28.799
The way so the way human the way cybersecurity has morphed into what it is today, uh, one of the things that I could that I say is that the problem that we face today with the human element and cybersecurity is not an industry problem alone.
00:13:29.120 --> 00:13:33.840
It's a government problem, it's an academia problem, and it's definitely an industry problem.
00:13:34.080 --> 00:13:40.879
And we need to work in that threesome in that threesome there to fix and address the human element in cybersecurity.
00:13:41.279 --> 00:13:42.159
That is a fun question.
00:13:42.320 --> 00:13:51.279
So I think actually that a lot of cybersecurity resides in the human side and that it gets overlooked a lot.
00:13:51.919 --> 00:13:54.320
Um, you called it squishy, I love that.
00:13:54.559 --> 00:14:13.279
Um there's a temptation to skip the squishy, uh, and to want to like not deal, skipping the sort of obvious information that like people have been perpetuating fraud on each other for a long time, and that basically entirely lives in the space of people being squishy.
00:14:13.600 --> 00:14:30.799
This episode is brought to you in part by Cybersec Media, a cybersecurity media and community platform built for practitioners, leaders, and innovators who want sharper conversations about the human, technical, and operational realities of security.
00:14:31.120 --> 00:14:42.080
And if you want to be part of that community in person, get your tickets now for CybersecCon, happening September 15th and 16th, 2026 in Houston, Texas.
00:14:42.480 --> 00:14:51.759
Join cybersecurity leaders, practitioners, researchers, and innovators for two days of insight, a connection, and actionable strategies.
00:14:52.159 --> 00:14:56.000
Secure your spot today at cyberseccon.com.
00:14:56.399 --> 00:15:02.960
That's cyber without the e at S E C C O N dot com.
00:15:03.360 --> 00:15:18.159
We hope you enjoyed this uh special episode of Cyberminded as we uh kind of look back and uh take a pause uh in the aftermath of all of the hacker summer camp activities out in Vegas.
00:15:18.480 --> 00:15:30.639
If you attended B Sides, if you attended Black Hat, DEF CON, any of the uh other activities that were happening in Las Vegas, hope that you made it home safe, hope that you had a great time.
00:15:30.960 --> 00:15:46.960
I hope that you really enjoyed hearing from not only current future guests, but also some uh key followers and key uh individuals that we met out at uh out at Black Hat.
00:15:47.279 --> 00:15:57.279
And as we always say, you know, it's really important that you look beyond the controls and pay attention to the human side of cybersecurity.
00:15:57.440 --> 00:15:59.840
We'll see you again on the next episode.
00:16:03.039 --> 00:16:09.440
This has been a cybersec media production recorded in partnership with CyberCog Labs.
00:16:09.919 --> 00:16:12.080
Cyberminded is hosted by Dr.
00:16:12.159 --> 00:16:13.279
Dustin Sachs.
00:16:13.600 --> 00:16:19.759
It's directed by Bill Brenner, produced by Lauren Andris, and edited by Ivan Basconcillo.
00:16:19.840 --> 00:16:28.799
The views and opinions expressed in this show are those of the speakers and do not necessarily reflect the views or positions of any entities they represent.
00:16:28.960 --> 00:16:35.919
This show is for informational purposes only and does not render or offer to render personalized advice.
00:16:36.159 --> 00:16:38.960
Subscribe now so you never miss an episode.
00:16:39.120 --> 00:16:45.600
You can find all our podcasts, articles, blogs, and conference talks on cybersecmedia.com.
00:16:45.679 --> 00:16:47.519
That's cyberwithout the e.
00:16:47.840 --> 00:16:54.639
And follow cybersec Media on LinkedIn, X, Instagram, Facebook, TikTok, and YouTube.
00:16:55.039 --> 00:17:02.799
You can keep up with our conferences by following us on LinkedIn, X, Instagram, and Facebook at Cybersec Events.
00:17:02.879 --> 00:17:11.839
And you can learn more about our events or buy tickets at cybersec.community slash cyberseconds.