ABOUT THIS EPISODE
Discover the unexpected synergies between spy craft and cybersecurity as Shawnee Delaney, ex-intelligence operative and CEO of Vaillance Group, shares her thrilling escapades and invaluable insights. Her experience, including a thwarted attempt to help capture Osama bin Laden due to miscommunication, offers a unique lens through which we examine the human elements essential to protecting national and organizational assets. Shawnee's anecdotes not only captivate but also elucidate the critical role empathy and understanding motivations play in managing insider risks.
Tackling the underestimated threat of insider risks, our conversation with Shawnee reveals the foundational pillars of creating a culture of cybersecurity awareness. We expose the vulnerabilities that lie within organizations, often overshadowed by the focus on external threats. Shawnee, drawing from her extensive background, advises on the establishment of an insider risk program, highlighting the importance of a dedicated manager and the strategic communication necessary to engage employees without invoking fears of intrusive surveillance.
As we shift our attention to the cultivation of future cybersecurity talent, Shawnee imparts wisdom for those embarking on or exploring a career in this dynamic field. She stresses the vast opportunities that look beyond technical expertise, weaving in the significance of human psychology and intelligence. Moreover, in a surprising twist, we pull back the curtain on a former Disney performer's journey, exploring the art of preserving Disney's magic, the power of networking, and the cultivation of professional relationships that can unlock doors in ways you never imagined.
🔗 Connect with Us & Get in Touch
Tune in to Simplifying Cyber wherever you get your podcasts, or watch exclusive video content right here on the channel. Subscribe for hot takes on emerging technologies, tips and tricks for everyone looking to stay secure, and in-depth conversations about complex cybersecurity topics.
No gatekeeping and no BS. We’re here to simplify.
Official Website: www.revealrisk.com
LinkedIn: https://www.linkedin.com/company/reveal-risk
🤘 Stay Secure with Us
If this content helped you understand cybersecurity better, please give it a thumbs up, subscribe to our channel for more expert insights, and hit the notification bell so you don't miss our latest updates.
Reveal Risk delivers cybersecurity results, not just reports.
IN THIS EPISODE
SHOW NOTES 🔗
TRANSCRIPT 🔗
00:00:10.071 --> 00:00:10.371
All right.
00:00:10.371 --> 00:00:12.675
Thanks for tuning in to Simply Solving Cyber.
00:00:12.675 --> 00:00:21.612
I'm Aaron Prince and I'm Cody Rivers, and today we're here with Shawnee Delaney, CEO from Viance Group, which means courage and bravery.
00:00:21.612 --> 00:00:23.146
I just learned that in French.
00:00:23.146 --> 00:00:24.132
I'm very impressed.
00:00:24.132 --> 00:00:24.655
How's?
00:00:24.655 --> 00:00:26.844
It going Shawnee.
00:00:26.844 --> 00:00:27.466
How are you doing?
00:00:27.507 --> 00:00:28.690
today.
00:00:28.690 --> 00:00:29.812
I'm good Thanks for having me.
00:00:30.195 --> 00:00:32.020
Good, Well, we're excited to hear your story.
00:00:32.020 --> 00:00:37.832
I know Cody and I got a preview at the HISAC in the fall I guess it was late November.
00:00:37.832 --> 00:00:47.570
But I don't want to steal any of your thunder, so I'm just going to go right into the first question, which is give us your story and I know it's an interesting story into cyber and take it away.
00:00:47.719 --> 00:00:52.832
Yeah, I probably have a little bit of an unusual background getting into cyber.
00:00:52.832 --> 00:01:01.246
So I was the black sheep of my family and I decided at a very young age that I was going to be a spy when I grew up.
00:01:01.246 --> 00:01:04.289
So I doggedly pursued this dream.
00:01:04.289 --> 00:01:07.228
I ended up working for the Defense Intelligence Agency.
00:01:07.228 --> 00:01:10.060
I was CIA trained down at the farm.
00:01:10.060 --> 00:01:12.087
If you watch the movies, you know what the farm is.
00:01:12.620 --> 00:01:16.450
But yeah, so I did that for about eight and a half years and I liked to joke.
00:01:16.450 --> 00:01:23.948
You guys saw my keynote, but I liked to joke that I used to steal secrets for a living and now I help people protect their secrets, which is actually very, very true.
00:01:23.948 --> 00:01:25.171
So I did that.
00:01:25.171 --> 00:01:29.671
I stood up inside our threat programs for major Fortune 500 companies.
00:01:29.671 --> 00:01:34.731
I had left government, went into private sector and then I missed government, I missed the mission.
00:01:34.731 --> 00:01:45.105
So I went back and I worked for Homeland Security for a while in their industrial control systems Cyber Emergency Response Team, which I don't know if it was the name or what, but that program didn't last very long.
00:01:45.599 --> 00:02:00.909
So I did that for a while, went back into private sector and then, about I don't know five years ago, stood up my own consulting firm, All right, let's start with how does one at a young age become a spy, or what do you put on your youth development plan to go in that direction?
00:02:01.480 --> 00:02:02.927
Yeah, I think I probably put actor.
00:02:04.424 --> 00:02:05.707
What is probably some good traits.
00:02:06.361 --> 00:02:07.427
Well, yeah, I did.
00:02:07.427 --> 00:02:10.188
Actually, when I was younger, I did theater very begrudgingly.
00:02:10.188 --> 00:02:19.967
I got dragged into it because I was a really shy kid, but those are skills that you use when you are conducting clandestine operations Because you are living a cover right.
00:02:19.967 --> 00:02:25.228
I was an alias when I was meeting with sources and assets, so all of that acting actually really came in handy.
00:02:25.741 --> 00:02:26.844
Yeah, no, that's true.
00:02:26.844 --> 00:02:33.513
So I know we heard a fantastic story of kind of one of your cool missions at the HISAC.
00:02:33.513 --> 00:02:46.163
But before we pivot into cyber, give us one of your best stories as a spy and maybe draw some correlations to how those tactics were useful in the cyber side or the corporate side of your life.
00:02:46.939 --> 00:02:50.467
If you know me, you know I have more stories than anyone you've ever met in your life.
00:02:51.329 --> 00:02:51.629
Hard.
00:02:51.629 --> 00:02:52.570
Right, You've got to pick yeah.
00:02:53.800 --> 00:02:57.491
I think probably the most well-known one is I was very, very close.
00:02:57.491 --> 00:03:05.090
I had an incredible asset who was close with Osama bin Laden and I was very close to being the one to say this is where he is.
00:03:05.090 --> 00:03:33.788
There was some major miscommunication going on between the intelligence organizations I was working with, between my source and between my interpreter, and I kind of joke that this is like my biggest success because I recruited this guy who, I mean, how many white Western chicks can say they recruited like the right hand man to Osama bin Laden, but they misunderstood where he was saying Osama was, and so I woke up a few weeks later, probably three weeks later.
00:03:33.788 --> 00:03:41.067
I woke up and on CNN and said, you know, osama's caught in a bot-a-bot and I was like, oh my God, that's what he was saying.
00:03:41.067 --> 00:03:44.725
Wow, I was like, oh, close, but no cigar.
00:03:45.146 --> 00:04:08.229
Yeah, in any parallels, like I'm just reflecting on that point of like human communication and translation, I worked at international companies and tried to get awareness messages out and like just silly accidental translation company mistakes, that one thing that you think would translate fairly easy turns into something that's accidentally offensive or not funny.
00:04:08.229 --> 00:04:10.019
What are your thoughts on kind of?
00:04:10.019 --> 00:04:15.763
I mean that probably happened all throughout the spy game, but how do you drop those learnings from what you experienced in the field?
00:04:16.495 --> 00:04:23.968
I think really the bottom line is and this is for any company that employs humans, which is all of you right- Link, link yeah.
00:04:24.154 --> 00:04:27.843
Every person is different and every situation is different.
00:04:27.843 --> 00:04:29.807
Every investigation is different.
00:04:29.807 --> 00:04:40.100
So every time I was running a clandestine asset or trying to work with a developmental source to recruit them, you had to figure out their motivations and vulnerabilities.
00:04:40.100 --> 00:04:59.574
And really it's the same thing in your companies your employees all have unique motivations and vulnerabilities and you have to figure out what those are and you have to encourage those as well and you have to push people along and you do need that positive deterrence as well as the negative deterrence.
00:04:59.574 --> 00:05:00.978
But it's finding that balance.
00:05:01.559 --> 00:05:11.062
So, with that said kind of looking at your organization, culture is so, so critical and it is the same thing in espionage.
00:05:11.062 --> 00:05:19.226
In that arena too, culture matters, understanding people matters and I'll add, above all else, empathy matters.
00:05:19.226 --> 00:05:22.636
I mean, like the story I just told you, and I told you a tiny, tiny nutshell.
00:05:22.636 --> 00:05:25.461
There's a podcast out there somewhere where I tell the whole story.
00:05:25.461 --> 00:05:47.911
But having empathy is critical, right, you have to empathize with what people are going through, no matter what it is in their life, and I think that a lot of C-suite sit up there and they look down and people are numbers and you can't do that and that's where that human factor comes in and when people need to realize that that is I mean insider risk is your biggest risk.
00:05:47.911 --> 00:05:52.125
You have all these people with access, all these trusted business partners, all these vendors.
00:05:52.125 --> 00:05:53.750
So what are their motivations?
00:05:53.750 --> 00:05:54.617
What are their vulnerabilities?
00:05:54.617 --> 00:05:55.398
Are those changing?
00:05:55.398 --> 00:05:58.826
Yes, they're changing every day, depending on their personal situations.
00:05:59.206 --> 00:05:59.728
Yeah, yeah.
00:05:59.728 --> 00:06:12.627
What do you say to the I would say stereotypically, the more technical cyber leaders that you know, I've heard you know fairly senior leaders say we're never going to fix the human, like humans are going to always make mistakes.
00:06:12.627 --> 00:06:18.531
I'm not going to fund awareness, we're going to just get as many tools to take the thought pattern out of it.
00:06:18.531 --> 00:06:22.245
What would your counterpoint to them be, based upon what you were just saying?
00:06:22.875 --> 00:06:27.584
Yeah, I think that's BS really when you're talking about humans, right?
00:06:27.584 --> 00:06:28.726
Like I just said, everyone.
00:06:28.726 --> 00:06:30.958
Every day, our priorities are changing.
00:06:30.958 --> 00:06:32.581
Maybe you have a sick loved one all of a sudden.
00:06:32.581 --> 00:06:35.355
I have a dear friend whose mom just died two days ago.
00:06:35.355 --> 00:06:38.122
Right, you don't know what's going to happen today.
00:06:38.122 --> 00:06:39.505
You don't know what's going to happen tomorrow.
00:06:39.505 --> 00:06:43.802
So the thing is, with training and awareness, you are building the foundation.
00:06:43.802 --> 00:06:48.281
If we're building a house, that is the foundation for everything you are building above it.
00:06:48.281 --> 00:07:01.129
If you don't have enterprise wide awareness as to what the threats are and how us as employees could actually contribute or make it worse, you're going to have a problem.
00:07:01.129 --> 00:07:15.588
You can have all the tools in the world, but if you don't have people saying, oh shoot, I'm recognizing that someone over there on my team is acting different and I understand now that that could be a red flag for something nefarious.
00:07:15.588 --> 00:07:26.105
And I need to report that if you don't instill those behaviors of that good muscle memory and that good cyber hygiene, those tools are going to do you no good, really.
00:07:27.394 --> 00:07:29.098
Yeah, and you get some great points there.
00:07:29.098 --> 00:08:02.509
So, going back a little bit to the transfer from clandestine operative recruiting high level intelligence agents in other countries and what you're doing now with inside a risk air nigh and reveal risk as a whole, two are very strong on the pillar of people in process and so I think inside a risk party your presentation we saw was about like don't wait until something bad happens to start building a program, and so I think, kind of talk through us about what you're seeing as far as a good strategy, because a lot of times I talk to folks about awareness programs and there's like I don't know where to start.
00:08:02.509 --> 00:08:05.699
I don't know how much it's going to cost out of the people for it.
00:08:05.699 --> 00:08:10.961
Or I came in with leadership to Aaron's point earlier that this is an important thing to even invest in.
00:08:10.961 --> 00:08:13.894
So what are you seeing right now with your clients in the market?
00:08:14.817 --> 00:08:30.744
Yeah, the same, really, when you think about it, and I think Ponaman just came out with their report for 2023, and they found in their report I think it was like almost 92% of organizations, they're investing their security budget in external threats.
00:08:30.744 --> 00:08:40.965
But the thing is, over half of these organizations recognize that social engineering and other attempts like that are actually the leading cause of all of those outside attacks.
00:08:40.965 --> 00:08:42.698
Right, so they know it.
00:08:42.698 --> 00:08:49.782
I talk to people every day in my business who know they need an insider risk program or insider threat program, whatever you want to call it.
00:08:49.782 --> 00:09:04.038
But, like you said, they don't know where to start, and I think what a lot of people don't realize is that you probably have good bones already and you probably have tools and processes and people that you could pull from and not have to reinvent the wheel.
00:09:04.038 --> 00:09:09.466
Now I really really think that you need a program manager for that program.
00:09:09.466 --> 00:09:13.966
I really really believe that you need to make this a transparent program.
00:09:14.514 --> 00:09:23.784
I really believe in marketing and branding of this program and the mission of the program the right way, so that people don't think big brother's spying on me.
00:09:23.784 --> 00:09:25.520
They're watching me all the time.
00:09:25.520 --> 00:09:27.481
Instead, it's we're here to help you.
00:09:27.481 --> 00:09:29.741
We want to keep you and your family safe.
00:09:29.741 --> 00:09:34.265
It's all in how you sell it to your employees to get that buy in.
00:09:34.265 --> 00:09:41.403
And then also creating a working group, creating a steering committee above that, where you have people from every single stakeholder.
00:09:41.403 --> 00:09:48.162
That's kind of what I like about it is you're working with everyone across the company, right, and so you're building those relationships.
00:09:48.162 --> 00:09:51.302
You're teaching all of these groups that gosh.
00:09:51.302 --> 00:10:02.399
When something interesting happens in an HR or someone's put on a performance review or a PIP or something, maybe they should let the investigations team know and the insider threat team know, or maybe they should be monitoring with the IT security team.
00:10:02.399 --> 00:10:06.802
So bringing all those people together, sometimes it's a hurdle, but it's doable.
00:10:06.802 --> 00:10:09.227
I've done it, I've seen it, I've seen it all the time.
00:10:09.975 --> 00:10:15.748
Well, and the thing I do I see a lot too is even looking back at what is insider risk and insider threat.
00:10:15.748 --> 00:10:21.059
I think a lot of folks right away think that, well, it's a spy or my company or someone's you know, corporate espionage.
00:10:21.059 --> 00:10:31.881
So we don't have I trust everybody, we're a small company, we have a good culture, so we don't have anyone trying to spy on our company and exfiltrate IP or secrets, which is a real thing and there is a lot of cases that go on.
00:10:31.881 --> 00:10:36.139
But give us a little insight too about the different kinds of insider threat and risk.
00:10:36.481 --> 00:10:43.143
Yeah, that's a great question because that, to your point, that's what a lot of people think theft of IP or espionage, and that's it.
00:10:43.143 --> 00:10:50.323
I've had cases where, like I still feel bad for this manager, there was a manager, her employees who she was very close with.
00:10:50.323 --> 00:10:51.106
They were friends.
00:10:51.106 --> 00:10:59.625
Two of her employees were committing fraud I mean massive amounts of fraud and when she found out she was crying on my shoulder saying but how could they do this to me?
00:10:59.625 --> 00:11:03.379
And I said they weren't doing it to you, they were trying to survive.
00:11:03.379 --> 00:11:05.042
Right, this is right.
00:11:05.042 --> 00:11:13.059
Before COVID they didn't make any money, they were external employees, they weren't full-time employees, so they didn't have that loyalty.
00:11:13.059 --> 00:11:15.543
So there are a lot of things that happen in people's lives.
00:11:15.543 --> 00:11:16.779
They're not doing it to the company.
00:11:17.375 --> 00:11:32.057
I think one thing you also mentioned too, like the difference from unintentional and intentional and the power of the awareness programs and building the education, and like strengthening your unintentional insider risk which then drives security and builds maturity to the intentional insider risk.
00:11:32.097 --> 00:11:37.924
Yes, yeah, and I think basically I like to put it in a pyramid, if you have that graphic.
00:11:37.924 --> 00:11:41.625
So at the bottom of that pyramid is the unintentional, the negligent.
00:11:41.625 --> 00:11:45.645
That could be someone who makes a mistake, which is the vast majority of cases.
00:11:45.645 --> 00:11:52.184
That could be someone who thinks well, I'm not doing anything bad and I know I'm not supposed to do that according to policy, but I'm going to do it anyway.
00:11:52.184 --> 00:11:54.783
You know, a lot of people are doing things just to do their job.
00:11:54.783 --> 00:11:56.080
They're trying to find a workaround.
00:11:56.080 --> 00:11:59.542
They're not trying to be malicious, but that's compromising.
00:11:59.542 --> 00:12:02.347
Whatever you know, ip, whatever.
00:12:02.347 --> 00:12:03.399
There's a whole bunch of options.
00:12:03.399 --> 00:12:07.004
The next category is the compromised insider.
00:12:07.004 --> 00:12:14.422
Those are basically the malicious actors who are feeding off of those negligent employees and stealing credentials and things like that.
00:12:14.422 --> 00:12:17.644
The next category, the top of that pyramid, would be the malicious actors.
00:12:17.644 --> 00:12:19.422
Luckily that's the smallest category.
00:12:19.995 --> 00:12:30.857
Now the thing is, when we talk about training and awareness and investment, you can train away heavily that negligent and that compromise those two categories, the big base of that pyramid.
00:12:30.857 --> 00:12:37.359
You can bring awareness, where people stop doing dumb things because now they know, oh shoot, I shouldn't do that.
00:12:37.359 --> 00:12:43.302
But people are going to argue and this is totally true, you're never going to train away malicious insiders.
00:12:43.302 --> 00:12:47.666
If I am set on stealing IP or committing workplace violence, I'm going to do it.
00:12:47.666 --> 00:13:03.066
My training is not going to matter, but by training everybody else, you now have eyes and ears everywhere where they understand the importance of reporting, they understand what red flag indicators there are, they understand when someone's pattern of behavior has changed and they know how to report.
00:13:03.615 --> 00:13:07.461
Yeah, they see something, say something, like if people don't know that that's part of their job.
00:13:07.481 --> 00:13:08.325
They're not going to do it.
00:13:08.325 --> 00:13:12.004
So we've talked a little bit about awareness and the connection to Insider.
00:13:12.004 --> 00:13:19.238
Talk to us and I know we actually both had some experiences in pharmaceuticals and Insider threat experiences and programs.
00:13:19.238 --> 00:13:20.899
Where do you get started?
00:13:20.899 --> 00:13:32.509
Like when you're coming into a new company, talk about how you help them get over the hump of, as Cody mentioned, we don't know if we need it, and then two to start building the building blocks of the program.
00:13:32.509 --> 00:13:33.312
What do you do first?
00:13:33.312 --> 00:13:35.562
How do you evaluate what the needs are?
00:13:35.581 --> 00:13:35.861
Yeah.
00:13:35.861 --> 00:13:40.110
So the first thing I say to people is well, do you employ humans?
00:13:40.110 --> 00:13:43.224
The answer is yes, then you have insider risk.
00:13:43.224 --> 00:13:47.232
100% of your employees are your insider risk.
00:13:47.232 --> 00:13:52.307
That's the risk of someone making a mistake, of someone being human.
00:13:52.307 --> 00:13:57.888
The insider threat is when someone that's right of boom instead of risk is left of boom, as we say.
00:13:58.571 --> 00:14:04.032
So what we do when we come in and I really like this process is I've basically broke it down into four phases.
00:14:04.032 --> 00:14:25.792
The first phase is doing an insider threat vulnerability assessment I like to call it a human risk assessment and in that you can look at what is the ground truth of that organization, because you could think your culture is great, you could think you've got all the governance and all the tools, but really when interviewing every stakeholder it could be an absolute nightmare and I've seen that.
00:14:25.792 --> 00:14:33.660
The thing with that also is important is it's looking at morale, it's looking at culture and it's looking at what you're doing right.
00:14:33.660 --> 00:14:47.207
So when you take that report, then you can build off your program from that report and you can understand what you need to really focus on, what you need to improve, especially related to like process or governance, and then kind of how to take it.
00:14:47.207 --> 00:14:49.131
So those are the first two.
00:14:49.131 --> 00:14:58.121
You know, the human risk assessment, the governance building the program, and the first phase is everyone's favorite trading and awareness, because again, you need that foundation Right.
00:14:58.522 --> 00:15:14.923
What would you say and I've had this in many different companies to an executive could be a CIO or a CEO that said we're manufacturing but we don't really have IP, we don't have the crown jewels, we're not an R&D focused company, we're a manufacturing delivery company.
00:15:14.923 --> 00:15:17.390
What would your comments be to that?
00:15:18.240 --> 00:15:26.708
Yeah, actually there is a major tech company and the CEO made an announcement to everyone in a huge meeting and this lasted for years, like the morale effect.
00:15:26.708 --> 00:15:34.605
It affected morale for years, where he said we have no IP, we have no trade secrets, we have nothing to protect and he was absolutely incorrect, by the way.
00:15:34.605 --> 00:15:46.945
So my comeback to that would be do you have anything within your business, within your data sets, within your emails, within your knowledge base, that would help a competitor?
00:15:46.945 --> 00:15:51.562
Because if the answer is yes, then you have intellectual property, you have trade secrets.
00:15:51.562 --> 00:15:54.730
Do you have processes that are special and unique to you?
00:15:54.730 --> 00:15:56.205
Yeah, probably.
00:15:56.205 --> 00:15:58.419
Then you might want to protect those things.
00:15:59.501 --> 00:16:04.312
One thing I see, too is to your point of supply chain right, are you a door to a bigger fish?
00:16:04.312 --> 00:16:11.746
So why I may not be interested in what you house I mentioned in the keys that you have to other companies and to back doors.
00:16:11.787 --> 00:16:25.009
That's why we see a lot of things on third party risk, which is a different topic for a different day, but a lot of times I think, when you're looking at what are people interested in from the outside to then solicit my employees to get access to, I think that is often undervalued or underestimated.
00:16:25.351 --> 00:16:25.774
Absolutely.
00:16:25.774 --> 00:16:28.201
Do you want to be on the front page of the New York Times?
00:16:28.201 --> 00:16:29.524
Probably not.
00:16:30.105 --> 00:16:31.128
Reputational risk.
00:16:31.128 --> 00:16:46.172
I think Aaron says it's great when the four options for risk and one's transfer and Aaron always says you can share the risk, you can't transfer the risk because, yes, you can probably offset some of the financial damage, but reputational damage is reputational damage, so you can't transfer that risk.
00:16:46.172 --> 00:16:48.450
Aaron, do you want to take your thunder there?
00:16:48.450 --> 00:16:58.961
But I love that you say that on certain calls and I think it's very valid because I think some of the tech focused people think I'm good, I got this, I'll get some cyber insurance and then I'm good, risk transfer and they'll look around my plate.
00:16:59.162 --> 00:17:03.472
Yeah, and I think also like throw in social media in the court of public opinion.
00:17:03.472 --> 00:17:14.490
That could be pretty nasty and even if the direction and the opinion is completely off base, it's really hard to change that narrative when social media is just fueling it.
00:17:15.780 --> 00:17:16.704
I think all three of us.
00:17:16.704 --> 00:17:19.317
It's fair to say that we all love coaching people.
00:17:19.317 --> 00:17:26.173
Obviously, we wouldn't be in consulting if we weren't but Shawnee talk about coaching new talent into cyber.
00:17:26.173 --> 00:17:32.442
What advice would you have for listeners that are maybe just getting into the field or thinking about getting into the field?
00:17:32.442 --> 00:17:36.413
What's your advice for them, knowing what you know, this far into your career?
00:17:36.855 --> 00:17:37.778
Yeah, just do it.
00:17:37.778 --> 00:17:39.124
Go ahead, Cody.
00:17:39.335 --> 00:17:41.099
Actually added that too, because I have.
00:17:41.099 --> 00:17:48.739
I've been to a lot of entry level people and cyber and they always ask me I'm not in the tech and tools by life cyber, what else is out there?
00:17:48.739 --> 00:17:50.305
So that's what just Aaron said.
00:17:50.305 --> 00:17:55.061
I think that'd be super valuable, for hopefully my mentees are listening to this podcast, but I think they'd be very grateful to hear.
00:17:55.415 --> 00:18:01.720
Yeah say, I do a ton of mentoring as well and I am constantly pitching out insider threat and here's why.
00:18:01.720 --> 00:18:08.846
So, first of all, this is a field that is in cybersecurity, but it's really that human factor overlying.
00:18:08.846 --> 00:18:14.038
If you think about all the phishing emails, it takes someone's finger to click that link right.
00:18:14.038 --> 00:18:14.960
That's the human angle.
00:18:14.960 --> 00:18:18.700
So when you're looking at this realm, I am not techie.
00:18:18.700 --> 00:18:20.424
I have a master's in cybersecurity.
00:18:20.424 --> 00:18:25.007
I hated doing my labs, I hated cracking passwords, right.
00:18:25.855 --> 00:18:27.819
But you can do psychology.
00:18:27.819 --> 00:18:33.625
You can do industrial, organizational psychology, behavioral psychology, forensic psychology all this applies.
00:18:33.625 --> 00:18:36.142
You can have a law enforcement background, like me.
00:18:36.142 --> 00:18:37.916
You can have an intelligence background.
00:18:37.916 --> 00:18:39.442
You know I used to steal your secrets.
00:18:39.442 --> 00:18:40.535
Now I can help you protect them.
00:18:40.535 --> 00:18:42.940
Right, cyber IT.
00:18:42.940 --> 00:18:46.667
The cool thing about this is there's so much in this realm.
00:18:46.667 --> 00:18:52.416
Understanding people's motivations, understanding why people do things, is really key.
00:18:52.416 --> 00:18:53.980
Digital forensics like they're.
00:18:53.980 --> 00:19:01.498
Really I could tick a ton of boxes and, like I said earlier, every case is different and that's the fun thing is figuring out why.
00:19:01.498 --> 00:19:02.540
Why did they do it?
00:19:02.540 --> 00:19:03.502
How did they do it?
00:19:03.502 --> 00:19:10.999
You know for the people out there that, like all the drama crime shows and CSI, whatever it's this kind of stuff and it's a lot, a lot of fun.
00:19:11.500 --> 00:19:16.336
I'll also add network your ass off, like seriously.
00:19:16.336 --> 00:19:19.565
Leverage LinkedIn, leverage people you know.
00:19:19.565 --> 00:19:20.675
Ask them who they know.
00:19:20.675 --> 00:19:24.276
Ask them if there's anyone you could meet or be introduced to in the field.
00:19:24.276 --> 00:19:26.901
Find a way to get to.
00:19:26.901 --> 00:19:38.444
Yes, a lot of times people are applying to roles as newbies, as being green, and they're struggling to get in, even though we've got a deficit of hundreds of thousands of positions just in the US.
00:19:38.444 --> 00:19:40.357
Keep pushing.
00:19:40.357 --> 00:19:41.884
Don't take no for an answer.
00:19:41.884 --> 00:19:43.230
Find a workaround.
00:19:43.230 --> 00:19:50.159
Take a different role in a company you really really find appealing or whatever, and then learn constantly.
00:19:50.159 --> 00:19:50.842
Learn.
00:19:50.842 --> 00:19:56.781
Take every class you can and inside our threat, there's a ton of free training available through the government.
00:19:56.781 --> 00:20:01.231
There's paid training also, and all of them are very, very interesting.
00:20:01.231 --> 00:20:01.472
Each one.
00:20:01.472 --> 00:20:10.684
You're going to learn something different, but work every case you can, at any level you can, just to learn all the different processes around these things.
00:20:11.215 --> 00:20:27.203
Cool, yeah, I went through the FBI Citizens Academy this last fall and I'd seen them before, but some of the videos that they put together dramatically reenacted but all about corporate espionage and insider threat and some ways that you wouldn't think that it would have happened in industries that you wouldn't think that they were targeted.
00:20:27.203 --> 00:20:28.426
But yeah cool stuff.
00:20:28.895 --> 00:20:29.740
Yeah, absolutely.
00:20:29.740 --> 00:20:35.401
And I think like to one of your earlier questions too, when we were talking about what is insider risk and insider threat.
00:20:35.401 --> 00:20:41.231
People need to really recognize that it's such a wide scope of what it entails.
00:20:41.231 --> 00:20:43.381
Right, it can be workplace violence.
00:20:43.381 --> 00:20:45.854
It can be an interoffice relationship gone bad.
00:20:45.854 --> 00:20:49.530
It can be bad publicity on social media or media leaks.
00:20:49.530 --> 00:20:51.921
There's a lot of different stuff under that umbrella.
00:20:52.895 --> 00:20:55.686
Yeah, I think to cap on that as well too.
00:20:55.686 --> 00:21:01.837
Looking at new professionals, a lot of my mentees say, well, I don't have three or five years of experience in this or in that.
00:21:01.837 --> 00:21:03.182
I'm like do you have problem solving?
00:21:03.182 --> 00:21:05.662
Do you have people, do you have leading projects?
00:21:05.662 --> 00:21:06.990
Do you manage a budget?
00:21:06.990 --> 00:21:11.071
Those are things that are very, very tied to cyber related, that aren't so technical.
00:21:11.071 --> 00:21:15.294
But I say work on the story and I think to your point, learning what insider risk is.
00:21:15.294 --> 00:21:21.162
I get it and an idea of what that is and then take your skill sets, match those and kind of put that in your resume as you reach out to people.
00:21:21.462 --> 00:21:21.884
Exactly.
00:21:22.275 --> 00:21:35.226
We just started working with a new client that has almost every tool that you could want to have, no dedicated cyber talent, all run by infrastructure, and they're just turning stuff on and we're like let's take a step back here.
00:21:35.226 --> 00:21:38.661
We need to think about people process, what you're going to do with the results.
00:21:38.661 --> 00:21:47.097
Yeah, yeah, the tool active doesn't mean that you are capable of taking the intelligence or whatever it's spitting out and turning that into a risk reduction.
00:21:47.097 --> 00:21:54.130
So I think, cody, to your point, there's plenty of roles beyond running the tech that are so needed and, in my opinion, more needed.
00:21:54.130 --> 00:21:56.656
That's more of a deficit in the market.
00:21:58.308 --> 00:22:00.454
Yeah, so, aaron, and in that same vein, this is great.
00:22:00.454 --> 00:22:01.416
It's almost like this is scripted.
00:22:01.416 --> 00:22:13.857
So technology and cyber is always critical, but, chania, I'd love if you can give us a story about a project or initiative within your corporate that only exceeded through people and process focus.
00:22:14.565 --> 00:22:14.885
Yeah.
00:22:14.885 --> 00:22:32.450
So an organization that I was working with standing up a program I won't name the company, but is a major, major company they had no tools, no tech, nothing, and we're talking about tens and tens of thousands of employees globally.
00:22:32.450 --> 00:22:45.834
So the program the only thing we had to stand up this program and to get any buy-in was through the processes and through the relationships that we built with all the stakeholders, kind of like what I was alluding to earlier.
00:22:45.834 --> 00:22:49.608
What we did was leveraging training and awareness.
00:22:49.608 --> 00:22:57.173
We made very short, like 30-second Hollywood style videos just showing reenactments of cool cases, trying to get people.
00:22:57.173 --> 00:23:01.895
I mean, look, we're like a Netflix nation now, right, we need to be entertained.
00:23:01.895 --> 00:23:05.126
Everyone has the attention span shorter than a Goldfish, by the way.
00:23:05.749 --> 00:23:09.336
So we really focused on making things interactive and engaging.
00:23:09.336 --> 00:23:16.247
We leveraged pop culture and what was going on in the world the Oscars and the Emmys and the awards season movies.
00:23:16.247 --> 00:23:26.280
We made things fun and we got so much engagement and we actually got people constantly emailing the insider threat team saying thank you so much for doing this.
00:23:26.280 --> 00:23:37.217
We brought in keynote speakers to talk about how to protect your family at home, how do you lock down your weird Alexes and series and all the things, your refrigerator and your oven everything's connected.
00:23:37.217 --> 00:23:38.951
Now, how do you keep your family safe?
00:23:38.951 --> 00:23:49.472
Yeah, so by doing all of that, not only did we get buy-in and support from the employees, like, oh wow, the company really cares about us, but all the stakeholders were like, oh wow, you're not trying to step on our toes, you're actually here to help.
00:23:49.472 --> 00:23:56.617
And it worked and culture started shifting and we had a really successful program, even without the tools.
00:23:57.486 --> 00:23:59.938
Yeah, I think your point earlier about culture is important.
00:23:59.938 --> 00:24:00.962
Two things in that is.
00:24:00.962 --> 00:24:11.301
I think that one a culture of fear or trouble if something is reported or something is seen is that we've seen that go well because they make a mistake, they pick on a fish.
00:24:11.301 --> 00:24:12.003
They have two options.
00:24:12.003 --> 00:24:21.277
I can report myself and maybe probably get in trouble or get some kind of reprimand, or I can not say anything and hope it goes under the rug and it goes away.
00:24:21.277 --> 00:24:26.558
One option is leads to a longer time of something you ever be discovered or a breach going on.
00:24:26.558 --> 00:24:27.644
The other one is hey, we found it.
00:24:27.644 --> 00:24:29.951
Let's focus on training and let's educate.
00:24:29.972 --> 00:24:36.176
I think people have a intrinsic drive to learn and to educate or to learn about this Because it is interesting.
00:24:36.176 --> 00:24:39.151
What we've seen is, to your point, it's a hearts and minds campaign.
00:24:39.151 --> 00:24:43.126
It's like why is this not just important to you as an employee of company X?
00:24:43.126 --> 00:24:50.538
This is important to you for your kids, your parents, your grandparents, your cousins, because it happens to folks in personal and work environments.
00:24:50.538 --> 00:25:05.721
So once you can start correlating that this knowledge is transferable to another job, to a family, I think you drive that and then the only challenge is just saying let's just come up with relevant content and like relevant messaging, so we're not sending out 30 minute videos of old school.
00:25:05.821 --> 00:25:09.814
Onboarding of policies and procedures are very important, but it's like how do I make this real?
00:25:09.814 --> 00:25:10.636
And distill it down.
00:25:10.636 --> 00:25:23.353
And in the hearts and minds campaign we do a lot of programs for companies, small and large, and we have some live action, some characters, some branding, but just some limited branding on some like items and making it real.
00:25:23.353 --> 00:25:25.804
You get people to educate, you want to learn about it.
00:25:25.804 --> 00:25:28.095
And then to your point, now they're asking questions.
00:25:28.095 --> 00:25:29.964
They're coming to you saying, hey, what about this idea?
00:25:29.964 --> 00:25:30.949
They're cross functional.
00:25:30.949 --> 00:25:33.662
So these are marketing folks or HR or finance.
00:25:33.662 --> 00:25:36.192
This is not like your info, your info sector, your technology people.
00:25:36.836 --> 00:25:39.768
Yeah, to put an espionage spin on it, because that's what I do.
00:25:39.768 --> 00:25:46.752
When you are trying to recruit someone and you're developing that relationship with them, you have to.
00:25:46.752 --> 00:25:50.188
I mean, these people are putting their lives on the line right, or their family's lives on the line.
00:25:50.188 --> 00:25:54.342
What's in it for me is going to be question number one.
00:25:54.342 --> 00:26:06.698
So when organizations look at it that way and you put the benefits upfront to those employees, they are much more likely to be engaged and to learn than they are if you say do it because we told you so.
00:26:07.984 --> 00:26:08.145
Kevin.
00:26:08.145 --> 00:26:11.516
All right, I've got a couple more questions to close us out here.
00:26:11.516 --> 00:26:17.097
Sean, what's your top takeaway If you were, if speaking to all the leaders that are on calls?
00:26:17.097 --> 00:26:24.471
Top takeaway for insider threat if they're to do one thing, go back to their company or their job, and maybe they have an insider threat program.
00:26:24.471 --> 00:26:27.907
Maybe they are just getting started, maybe they don't have one.
00:26:27.907 --> 00:26:31.317
What's like the number one thing that you want to leave with the listeners?
00:26:33.365 --> 00:26:38.657
Really, the first thing that comes to mind is it will happen to you Period.
00:26:38.657 --> 00:26:40.226
Yeah.
00:26:40.226 --> 00:26:43.717
And like I said earlier to getting into cyber, just do it.
00:26:43.717 --> 00:26:45.864
Stand up a program.
00:26:45.864 --> 00:26:57.586
You might not have a budget, you can do it with little to nothing, but stand up a program, have people understand what it is and start engaging with your employees, like everything we were just talking about.
00:26:57.586 --> 00:27:00.692
It's like brand recognition, right.
00:27:00.692 --> 00:27:02.616
Oh, there's that cool insider threat thing.
00:27:02.616 --> 00:27:14.376
I think sharing case studies is really important because if you hear these real world stories which you guys heard when I was on stage I share stories when you hear these stories, you're like, oh crap, that is real, it happened here.
00:27:14.376 --> 00:27:16.345
It's really impactful.
00:27:17.669 --> 00:27:19.154
Awesome, Great segue again.
00:27:19.154 --> 00:27:20.980
Storytelling Super important.
00:27:20.980 --> 00:27:23.111
We've talked a lot about that throughout this episode.
00:27:23.111 --> 00:27:24.779
Let's end on a personal note.
00:27:24.779 --> 00:27:29.075
Give us a story that maybe not a lot of people that know you know about.
00:27:29.075 --> 00:27:35.976
I know you have a ton of stories, both personal and professional, but what's your favorite story to put yourself out there and entertain the group?
00:27:37.445 --> 00:27:38.731
God, that's a tough one.
00:27:39.944 --> 00:27:42.994
I should have prepped you more, but it's not well thought out.
00:27:43.805 --> 00:27:49.310
Something that tickles people a lot is that you know, yes, I used to be a spy, but I used to work at Disneyland.
00:27:51.467 --> 00:27:52.984
Disneyland or Disney World.
00:27:52.984 --> 00:27:57.987
Disneyland the original yes, all right, yes, yeah, that was.
00:27:58.409 --> 00:28:01.082
I always tell people that was probably the best job I ever had.
00:28:01.082 --> 00:28:03.724
Yeah, because you and I use those skills.
00:28:03.724 --> 00:28:06.744
I went through Disney University twice because I changed jobs.
00:28:06.744 --> 00:28:12.105
I went from the character department to an actress and, um, yeah, so you got to give us your roles.
00:28:12.326 --> 00:28:14.713
What roles did you play or what jobs did you have?
00:28:15.065 --> 00:28:16.750
I'm going to ruin the magic for people.
00:28:16.750 --> 00:28:17.534
Yeah, you can't.
00:28:17.534 --> 00:28:18.438
So, aaron, this.
00:28:18.479 --> 00:28:19.549
I do know you can't say.
00:28:19.549 --> 00:28:24.444
You can say I was friends with someone, yeah, but part of the thing is, when you leave you can never say who you are.
00:28:24.444 --> 00:28:25.106
It's like hey.
00:28:25.106 --> 00:28:26.192
I'm friends with so-and-so.
00:28:26.412 --> 00:28:29.121
Yeah, I knew Pluto, and you are really well though, okay.
00:28:29.181 --> 00:28:37.676
Okay, yeah, I was going to ask if you were a princess, a character with a big head or a, you know, big, big character.
00:28:37.676 --> 00:28:38.303
Okay, all right.
00:28:38.324 --> 00:28:41.314
Yeah, she was good friends, good friends with them.
00:28:41.453 --> 00:28:42.657
Good friends, very good friends.
00:28:42.718 --> 00:28:43.780
Very good, awesome Hug along.
00:28:44.951 --> 00:28:46.904
I really appreciate you coming on the show.
00:28:46.904 --> 00:28:49.133
This has been a great conversation, as always.
00:28:49.133 --> 00:29:01.963
Best of luck in your business and really reaching your audience and really helping to get the message out there around insider, because you are right, just doing it and starting and acknowledging hey, yes, we have a problem, let's figure it out.
00:29:01.963 --> 00:29:04.000
Yes, that's really where everyone needs to be.
00:29:04.000 --> 00:29:04.443
Yeah, yeah.
00:29:05.430 --> 00:29:13.240
And one thing too is that, to your point earlier, shawnee, just reach out and like networks I know I heard you speak and you walked us like, hey, hold on for a second.
00:29:13.240 --> 00:29:16.413
We had a brief conversation, it was like five minutes in San Antonio, texas.
00:29:16.413 --> 00:29:17.377
And here we are now.
00:29:17.377 --> 00:29:23.865
As we've met, we have some partnerships working up and everything, but be bold and just ask folks to talk about it because no one has it all figured out.
00:29:23.865 --> 00:29:26.334
So I think everyone in the industry likes to talk about things.
00:29:26.354 --> 00:29:29.131
So and for that networking another tip.
00:29:29.131 --> 00:29:30.634
Here's another espionage tidbit for you.
00:29:30.634 --> 00:29:32.811
People love talking about themselves.
00:29:32.811 --> 00:29:39.919
So when you are nervous or like I don't know if I should approach, ask someone about themselves and you will open a big old door.
00:29:40.742 --> 00:29:41.686
Love it On that.
00:29:41.686 --> 00:29:42.790
Go forth and prosper.
00:29:42.790 --> 00:29:45.839
Everyone, Ask somebody about themselves and make it happen.
00:29:45.839 --> 00:29:47.546
Thanks so much You're having me.