[00:01.300 --> 00:02.400] Hello, New York! [00:02.640 --> 00:03.040] Whoo! [00:04.780 --> 00:06.760] I am so delighted to be here today. [00:06.960 --> 00:08.800] I've always heard about HOPE, never got to go. [00:09.060 --> 00:12.360] Wish I had seen it when it was in the pen, but what can you do, right? [00:12.980 --> 00:15.080] But thank you very much for having me up. [00:15.460 --> 00:16.940] My name is Robert Wagner. [00:17.620 --> 00:19.640] Just to give you a quick little background. [00:20.360 --> 00:22.820] So I am on Twitter, kind of. [00:23.000 --> 00:25.260] I mean, it's a dumpster fire, so I'm not there much. [00:25.400 --> 00:29.220] But as well as some other things, I'm an advisory CISO. [00:29.220 --> 00:32.200] I'm also heavy into helping build communities. [00:32.460 --> 00:34.740] So I helped co-found Hack for Kids. [00:34.920 --> 00:35.800] Is David out there? [00:35.900 --> 00:36.500] Yay, David! [00:36.640 --> 00:37.340] That's our president. [00:37.800 --> 00:40.180] We run a day-long hacker con for kids in Chicago. [00:40.380 --> 00:43.880] We will also help other cons run their own kids track at their cons. [00:44.100 --> 00:47.800] So if you ever want to do a kids track in your own neck of the woods, come talk to us. [00:48.260 --> 00:49.140] I'm on the ISSA. [00:49.280 --> 00:50.560] I'm on the Chicago CISO of the Year. [00:51.080 --> 00:58.360] I'm a co-organizer of BurbSec, another great community in Chicago, and I help run a new B-Sides in Chicago called B-Sides 312. [00:58.820 --> 01:00.960] I also suck at social media. [01:01.180 --> 01:05.580] So if you see stuff and you want to take pictures and post, by all means, go right ahead. [01:05.680 --> 01:07.200] Because you're doing me a favor if you do. [01:08.320 --> 01:11.900] I'm also a big fan of all things dogs, motorcycle, and scuba. [01:12.160 --> 01:15.040] And that was the marriage of two of my favorite hobbies together. [01:15.320 --> 01:15.940] This is Rocket. [01:16.080 --> 01:17.480] He rode with me for 14 years. [01:17.940 --> 01:19.520] It was just an amazing dog. [01:20.080 --> 01:23.680] And I just always like putting a picture of him up to remember him by. [01:23.680 --> 01:28.480] Anyway, so I wrote... Can everybody see me if I walk down here? [01:28.560 --> 01:31.800] Because I cannot stand in just one tiny little space. [01:32.320 --> 01:46.960] So I've started off my career as like a third shift stock analyst, moved up through engineer and architect, worked for some rather large financial corporations, and then started being an advisor to all sorts of orgs, including small ones. [01:46.960 --> 01:56.480] And I wrote this talk because small businesses right now are making the same damn mistakes I saw us making 20 years ago. [01:56.620 --> 01:58.900] It's like we've learned nothing, right? [01:59.120 --> 02:05.920] They're all trying to do exactly... Trying to do security, and in trying to do it, they're doing the same stupid things we did. [02:05.920 --> 02:11.820] So I thought I'd put together a deck on how to avoid the stupid things we were doing 20 years ago. [02:13.600 --> 02:16.840] So I love this quote. [02:17.040 --> 02:21.580] It is, there is a better way to do everything, find it, by Thomas Edison. [02:21.940 --> 02:27.820] For those of you that know Thomas Edison's history, you know he stole almost everything that he used. [02:27.960 --> 02:31.720] So by all means, steal from me as much as possible during this talk. [02:33.720 --> 02:41.280] And so I based this on something that Wendy Nather came up with that she coined back in 20... [02:41.280 --> 02:42.960] Who here follows Wendy, by the way? [02:43.100 --> 02:45.640] She's just, yeah, she's just frickin' amazing. [02:46.360 --> 02:50.000] Catch her posts, catch her wherever she's posting on social now. [02:50.620 --> 02:57.800] But the cybersecurity poverty line was a concept that she came up with in 2010, like 15 years ago. [02:57.800 --> 03:03.800] That basically just, she identified as the line below which organizations cannot be effective. [03:04.760 --> 03:08.480] Least of all, meet even just the basic hygiene of security. [03:08.740 --> 03:11.500] How many folks have worked at a company like that? [03:11.620 --> 03:12.300] Yeah, right? [03:13.480 --> 03:30.060] So it's, if you look at the kind of the curve of Fortune X's that are above and below that poverty line, somewhere right in between Fortune 2000, Fortune 4000 is when companies start dropping below that line and don't even have enough budget to be effective. [03:30.320 --> 03:34.660] So some of the things I'm going to be telling you is, you know, how to overcome some of those budget hindrances. [03:34.940 --> 03:39.760] Some of the things I'm going to tell you are how to get more budget, too, in a hackery kind of way. [03:39.760 --> 03:45.100] So the primary hurdles that she identified for this was money. [03:45.260 --> 03:46.180] We all get that, right? [03:46.800 --> 03:47.280] Expertise. [03:47.480 --> 03:50.380] Maybe not having the talent to do the things you want to do. [03:50.780 --> 03:51.260] Capability. [03:51.540 --> 03:55.480] So the ability to take that expertise and put it into production effectively. [03:56.060 --> 04:00.160] And then the last one was one I had not thought about, but she was dead on. [04:00.420 --> 04:01.700] And that was influence. [04:02.020 --> 04:05.600] The ability for the CISO or whoever the security leader is, right? [04:05.600 --> 04:08.520] Because at some of our smaller SMBs, we don't have a CISO. [04:08.600 --> 04:19.480] We just have director of security or maybe director of IT that also has to do security or like that IT person that has to do security, right? [04:19.580 --> 04:20.760] And they're wearing multiple hats. [04:20.960 --> 04:21.580] It's tough. [04:21.800 --> 04:25.880] How many folks work at an organization with more than 100 people on security staff? [04:26.920 --> 04:27.440] Okay. [04:27.440 --> 04:27.800] Wow. [04:27.920 --> 04:28.960] And that's a luxury. [04:29.240 --> 04:30.500] How many people less than 50? [04:31.720 --> 04:32.240] Okay. [04:32.460 --> 04:33.480] Less than 10? [04:34.580 --> 04:35.380] Oh, man. [04:35.380 --> 04:36.420] Less than two. [04:37.220 --> 04:38.260] Oh, my God. [04:38.440 --> 04:38.840] All right. [04:39.140 --> 04:41.120] So hopefully this will help you guys out. [04:42.680 --> 04:44.960] So influence is a big thing. [04:45.020 --> 04:48.220] And we're geeks and we don't always know how to influence, right? [04:48.420 --> 04:52.460] One of the most amazing CISOs that I know, his name's Jason Witte. [04:52.680 --> 04:54.240] I think he's here in New York these days. [04:54.620 --> 04:59.660] Anyway, on staff, he always has a person who is a PowerPoint master. [04:59.880 --> 05:01.760] They don't know jack shit about security. [05:02.000 --> 05:02.560] Can I swear here? [05:03.240 --> 05:03.660] Yeah. [05:03.760 --> 05:04.100] Okay, good. [05:04.100 --> 05:09.740] So they don't know about security as much as they know how to make really good PowerPoint. [05:10.040 --> 05:14.920] So he gets the right information to them, but they make it digestible to the board. [05:15.700 --> 05:16.720] Brilliant, right? [05:17.500 --> 05:20.000] So that's the kind of things we're talking about with influence. [05:21.200 --> 05:25.740] But what is the impact of all of this on small business in the first place? [05:25.840 --> 05:27.220] What are we really talking about here? [05:27.380 --> 05:31.800] How does not being able to achieve even basic hygiene affect small businesses? [05:31.800 --> 05:40.400] So some of these stats are a couple years old now, but attacks targeting small to medium businesses back in 21 was 40% of all attacks. [05:40.540 --> 05:42.040] And I know it's gone up since then, right? [05:42.200 --> 05:44.940] They're a much richer target, much easier to get at. [05:45.720 --> 05:53.540] And cyber attacks cost these SMEs about $200,000 per firm, per event. [05:54.140 --> 05:55.960] And that doesn't sound like much, right? [05:55.960 --> 05:59.840] For like a big bank or a big insurance company. [06:00.020 --> 06:00.960] That's a rounding error. [06:01.200 --> 06:11.220] But to the small, medium businesses, this meant 60% of them went out of business within six months of losing $200,000, right? [06:11.360 --> 06:13.200] From something like ransomware or something like that. [06:13.300 --> 06:17.180] It sucks to be a small company and get hit by an attacker. [06:18.720 --> 06:20.080] So where do we start? [06:20.180 --> 06:20.960] How do we start rounding up? [06:21.020 --> 06:22.620] Who hates this Venn diagram, by the way? [06:22.780 --> 06:25.160] Yeah, this Venn diagram sucks for a couple of reasons. [06:25.160 --> 06:31.520] One, it's like every person that's a salesperson that's new in security goes, I'm going to show you this Venn diagram because everybody... [06:31.520 --> 06:31.780] Right? [06:31.900 --> 06:33.580] They think they've just discovered something new. [06:33.720 --> 06:37.500] But I also hate it because it never, ever looks like this, right? [06:37.520 --> 06:41.880] We never get this really nice whole balance of people, processing technology. [06:42.180 --> 06:44.720] In fact, in small businesses, where do they go right to? [06:45.140 --> 06:50.400] Yeah, they try to solve all the problems with technology and they forget about process and fuck all on the people. [06:51.300 --> 06:52.700] But that's a problem. [06:52.780 --> 07:00.480] Because if we're not being holistic, if we just focus on technology and get tech heavy, what does our security program look like? [07:00.600 --> 07:01.620] It looks like this. [07:01.760 --> 07:05.760] And this is not the way I want to describe my security program. [07:06.600 --> 07:08.040] So, what can we do? [07:08.200 --> 07:09.160] Where do we start? [07:09.400 --> 07:11.820] Let's start with the most important tool. [07:11.960 --> 07:13.820] It's a tool every company has, right? [07:14.000 --> 07:14.840] And that's people. [07:15.060 --> 07:19.160] Not that I'm calling you all tools, but this is where we want to actually get some traction. [07:19.480 --> 07:20.640] So, people. [07:21.560 --> 07:22.820] I hear this all the time. [07:23.060 --> 07:24.500] Talent is hard to find, right? [07:24.820 --> 07:26.320] But is it really though? [07:27.100 --> 07:31.760] One of the things that small companies are trying to do is they're trying to hire big companies. [07:32.180 --> 07:33.420] That's not going to work. [07:33.540 --> 07:34.320] Not at this level. [07:35.560 --> 07:44.500] So, first thing is, especially now with some new mandates and compliance reasons, companies are being forced to get a CISO. [07:44.500 --> 07:47.540] And a V-CISO is sometimes a solution, right? [07:47.640 --> 07:55.880] Maybe a CISO that you only pay like a couple hours a month or a couple hours a week, depending on how big you are, to do some of the basic security stuff. [07:56.060 --> 08:01.160] The problem I'm seeing is small companies have no idea what the fuck that means to get a V-CISO, right? [08:01.320 --> 08:06.680] One of my friends who's a CISO was interviewing for a full-time CISO role for a smaller organization. [08:07.160 --> 08:09.200] And they're like, wow, this is really great. [08:09.200 --> 08:10.580] You've got a fantastic background. [08:11.220 --> 08:13.280] What kind of firewalls do you know how to configure? [08:14.880 --> 08:15.320] Yes. [08:15.640 --> 08:17.840] To the guy interviewing to be a CISO, right? [08:18.040 --> 08:21.600] So, yeah, I'm pretty sure he ran away screaming from that job. [08:21.720 --> 08:23.740] But that's the problem in a nutshell. [08:23.980 --> 08:27.240] They're like, the CISO does the security stuff, right? [08:28.000 --> 08:32.740] So, what you really want to do if you're interviewing a V-CISO is look for someone that speaks in business terms. [08:32.900 --> 08:38.020] Right off the bat, that is the most important vocabulary that they can have. [08:38.200 --> 08:44.280] They should have some experience in incident response, because you're probably going to need to move fast on that when something happens. [08:44.980 --> 08:47.880] They should understand, of course, the compliance of your industry. [08:48.200 --> 08:52.200] And then, actually create realistic objectives, right? [08:52.440 --> 08:53.640] It's even more important. [08:54.000 --> 08:56.800] How many people have fully patched their systems, right? [08:57.060 --> 08:57.900] Doesn't happen. [08:57.900 --> 08:58.300] Yeah. [08:58.740 --> 09:07.660] Well, he or she needs to be more realistic when it comes to what you're going to approach in vulnerability in a small org, because you only have so much time and so many resources. [09:08.260 --> 09:12.640] So, being able to set some very succinct ones is super important for a VC. [09:12.640 --> 09:20.800] So, now, when we talk about hiring the actual security staff, stop chasing unicorns. [09:20.920 --> 09:23.600] How many of you all know, like, some security unicorns? [09:23.640 --> 09:24.600] Like, they are amazing. [09:24.740 --> 09:26.240] They can do all the things, right? [09:26.420 --> 09:28.380] They're usually pretty fantastic. [09:28.940 --> 09:32.580] A lot of them, not all of them, but a lot of them are assholes, right? [09:32.580 --> 09:34.540] They don't work well in a team. [09:34.700 --> 09:43.620] They work well if you stick them in a dark room where you're also growing the mushrooms, and they can, like, you know, white coat and whistle down, whistle modem tones down the wire. [09:43.980 --> 09:47.180] But they're not always the greatest team player. [09:47.340 --> 09:49.340] And in a big company, I love having them. [09:49.620 --> 09:52.780] You can just wind them up, let them go, and they do the stuff. [09:52.940 --> 09:57.640] When you're on a team of three, assholes don't have a place on a team of three. [09:57.760 --> 09:58.620] Not as much. [09:59.560 --> 10:07.080] So instead, hire, depending on the size of your company, one, maybe a couple strategic leads, depending on how big you are. [10:07.720 --> 10:09.940] And then I want you to start... [10:09.940 --> 10:13.340] Well, those folks should really have empathy, really down, right? [10:13.440 --> 10:18.760] Know how to be good, empathetic leaders, high EQ, folks that can lead by example. [10:19.400 --> 10:22.320] Not just do what I say, but do what I'm doing. [10:23.200 --> 10:26.940] And they also need to run interference for those business politics. [10:27.600 --> 10:29.900] Geeks are horrible at office politics. [10:30.100 --> 10:31.060] We suck at it. [10:31.320 --> 10:37.520] Like, the first time I wanted to go to training, when I was a third shift stock analyst, I wanted to go to DEFCON. [10:37.700 --> 10:40.220] Because people were like, oh, DEFCON's cool, you gotta go to DEFCON. [10:40.400 --> 10:42.680] And I'm like, okay, boss, can I go to DEFCON? [10:42.780 --> 10:44.340] And my boss says, what's that? [10:45.420 --> 10:45.780] Yeah. [10:46.020 --> 10:49.260] And I'm like, oh, it's this really cool hacker conference in Las Vegas. [10:50.420 --> 10:50.780] Denied. [10:51.080 --> 10:51.420] Right away. [10:51.420 --> 10:53.560] He's like, no, no, no, no, no. [10:54.040 --> 10:57.160] So, a couple of months later, someone told me about another con in D.C. [10:57.320 --> 10:58.720] They're like, you should go to ShmooCon. [10:59.000 --> 11:00.640] And I'm like, boss, can I go to ShmooCon? [11:00.760 --> 11:03.880] And he gave me an even weirder look and said, what is that? [11:04.100 --> 11:11.920] And I said, it is a information security conference in Washington, D.C., highly attended by three-letter agencies. [11:12.140 --> 11:12.900] Boom, approved. [11:12.900 --> 11:14.340] No problem at all. [11:14.440 --> 11:14.680] It did not. [11:15.080 --> 11:19.180] And so, but he knew the politics of what would get approved and what wouldn't, right? [11:19.320 --> 11:20.340] And that's the point I'm making. [11:21.120 --> 11:25.160] Then the leader or leaders are gonna create a low-cost army. [11:25.500 --> 11:32.620] Some interns, some temp-to-hires, entry-level hires, anybody that they can get their hands on to start filling some of those roles. [11:33.040 --> 11:36.540] Again, with maybe one or two seniors to usher those interns. [11:37.140 --> 11:38.840] And start nurturing that talent. [11:39.060 --> 11:41.780] Now, there's a lot of things people say about that, right? [11:42.920 --> 11:44.620] They're like, oh, well, what if they quit? [11:44.880 --> 11:49.260] So, this is some really good ways to think about how we're gonna use those interns. [11:49.740 --> 11:53.060] We need to create a culture of mutual mentorship and sharing. [11:53.740 --> 12:03.780] I knew a team of six security guys, men and women, actually, that were all working for an office supply store. [12:03.920 --> 12:10.320] And they merged with another office supply store that was based out of Florida that had like 25, 30 folks. [12:10.320 --> 12:18.800] The team of five or six outperformed the team of 30 every frickin' day because they taught each other how to do shit. [12:19.020 --> 12:22.260] They were just like, oh, man, I'm trying to do this. [12:22.440 --> 12:24.380] And everybody would be like, oh, yeah, that's cool. [12:24.440 --> 12:25.280] Let's try and do that. [12:25.400 --> 12:26.820] Maybe I can expand upon it. [12:27.020 --> 12:28.760] They were constantly sharpening each other. [12:28.860 --> 12:30.060] They were mentoring each other. [12:30.800 --> 12:37.560] The most important thing I got from one of my mentors was train them so well that they could leave because they're gonna. [12:37.840 --> 12:38.620] Some of them are gonna. [12:38.800 --> 12:40.060] And you just have to accept that. [12:40.320 --> 12:43.760] Train them so well they could leave, but treat them so well that they stay. [12:43.960 --> 12:44.900] Or at least some of them stay. [12:45.100 --> 12:50.240] So some of those people that are bubbling up, they're like, eh, maybe I want to mentor the next group that comes through, right? [12:50.500 --> 12:52.160] And you've treated them really well. [12:52.160 --> 12:53.380] You're creating this great culture. [12:53.960 --> 12:57.860] Depending on how much money you have, you still may lose them, but you're just gonna have to do that. [12:57.980 --> 12:59.120] So keep turning them through. [12:59.300 --> 13:09.280] I've even seen some smaller companies partner with larger companies to train up interns and get a little money back from the larger company as a feeder. [13:09.460 --> 13:12.520] Just like, you know, amateur baseball, into pro baseball, right? [13:12.760 --> 13:13.940] We'll be the feeder farm. [13:14.160 --> 13:17.620] We'll get some folks with some experience just coming out of college. [13:17.760 --> 13:18.960] They can make mistakes here. [13:18.960 --> 13:24.740] And then if you help us a little bit with their education, we'll feed them up to you and into the larger organization. [13:24.840 --> 13:25.560] It's a great idea. [13:25.720 --> 13:27.400] Not too many are doing it, but I have seen it happen. [13:28.940 --> 13:34.580] I also highly recommend allowing them to interact and participate in the InfoSec community. [13:34.920 --> 13:41.620] I don't know how many junior folks I've met that I've said, hey, why don't you come to ISSA or some of these other things. [13:41.720 --> 13:45.580] They're like, well, my boss won't let me leave halfway through the day or at 3 p.m. [13:45.680 --> 13:45.980] or whatever. [13:45.980 --> 13:47.660] I'm like, what the fuck? [13:47.820 --> 13:49.020] Let me talk to your boss. [13:49.220 --> 13:51.460] Because that's professional development. [13:51.700 --> 13:56.300] They should be encouraging the hell out of you going out and trying to learn from your peers. [13:56.780 --> 14:05.100] I've learned so much just from hanging out at BurbSec with a lot of red teamers, quite honestly, about blue teaming for the price of a beer. [14:05.240 --> 14:07.860] Just sitting down and talking with my peers in the industry. [14:08.520 --> 14:11.660] And then look for talent in existing employees. [14:11.940 --> 14:18.520] I mean, how many awesome security people were Linux admins before they became security people, right? [14:18.640 --> 14:19.780] They've got the chops. [14:20.020 --> 14:22.520] All you've got to do is show them this slightly different thing. [14:22.560 --> 14:23.820] And they usually run with it. [14:25.960 --> 14:32.680] So, in addition, one of the things that we suck at in this industry is good diversity hiring, right? [14:32.680 --> 14:40.100] And what we don't realize a lot of times is it's our own language in the job wrecks themselves that are stopping it. [14:40.260 --> 14:47.740] As I was doing my research for this, I was surprised to find out that words like self-reliant or lead are basically coded for masculinity. [14:47.980 --> 14:49.760] They're like, oh, we need a dude in here, right? [14:50.060 --> 14:51.540] And you may not know that. [14:51.680 --> 14:53.560] It sounds like a good thing. [14:53.660 --> 14:54.580] Oh, you're self-reliant, right? [14:54.760 --> 14:58.200] But instead, what we're doing is we're signaling to people that we want a dude. [14:58.860 --> 15:02.120] The word energetic can deter older candidates. [15:02.240 --> 15:03.720] Well, I've told now I'm not one of them. [15:04.440 --> 15:07.400] So, but yeah, it's basically you put energetic. [15:07.400 --> 15:09.620] It sounds like a good thing to put in a job wreck. [15:09.760 --> 15:16.960] But you're basically telling, you know, folks above, I don't know, 30, whatever you'd consider old, to not sign up. [15:18.540 --> 15:25.440] In addition, there is better and better AI now that will check your job descriptions literally for inclusivity. [15:25.440 --> 15:27.260] So you don't even have to worry about yourself. [15:27.460 --> 15:29.120] Just run it through one of these things. [15:29.260 --> 15:35.460] And then get rid of the fucking nice-to-haves that are this laundry list of job descriptions that we get, right? [15:36.140 --> 15:45.300] I don't know how many guys know, I think all the women know here, that most women will not apply for a job unless they meet 100% of everything on that list. [15:45.480 --> 15:47.680] Whereas guys are like, hey, 60%. [15:47.680 --> 15:48.840] Yeah, 60% is good. [15:48.860 --> 15:49.440] I can do that. [15:49.660 --> 15:49.860] Right? [15:50.060 --> 15:51.180] And they'll apply. [15:51.180 --> 15:53.780] So we need to get rid of the nice-to-haves. [15:53.940 --> 15:57.540] Start changing job wrecks to talk about what you'll be doing, right? [15:58.200 --> 16:06.100] That's a lot more important than you need to know all these things, including, like, 10 years in a technology that only came out two years ago. [16:06.300 --> 16:07.000] Shit like that. [16:08.400 --> 16:23.840] So there's also some pretty cheap hiring bias training that's out there, available online, just to, like, help people get over some of their confirmation bias and other biases as they're trying to interview. [16:23.840 --> 16:31.440] I also see a huge problem in a lot of people trying to take people on staff and just make them interviewers. [16:31.580 --> 16:34.760] Like, oh, hey, you know, we got some new hires coming in, I want you to interview them. [16:34.860 --> 16:41.260] And they give them no framework, no training at all on how to interview someone. [16:41.600 --> 16:43.820] How effective can that possibly be? [16:43.820 --> 16:53.620] Take, you know, an hour's worth of maybe some training on how to interview someone, and definitely have things like a structured interview with scorecards. [16:53.740 --> 16:57.880] So people aren't just asking, like, stupid rando questions that pop into their head. [16:57.980 --> 17:00.340] Like, name all TCP flags or something like that. [17:00.420 --> 17:02.380] I got asked that once in an interview. [17:02.580 --> 17:03.820] Name all the TCP flags. [17:03.940 --> 17:04.460] Right, yeah. [17:05.100 --> 17:07.300] I got most of them, but damn it, right? [17:07.480 --> 17:08.680] You know, you're under pressure. [17:10.040 --> 17:12.000] I even got ECN, which surprised them. [17:12.080 --> 17:13.280] They're like, no one ever gets ECN. [17:13.280 --> 17:15.580] But in any event, so... [17:15.580 --> 17:18.480] And then, non-traditional backgrounds are amazing. [17:18.760 --> 17:23.020] I know tons of musicians that make for great analysts. [17:23.260 --> 17:23.680] And why? [17:23.900 --> 17:25.780] Music is math and patterns. [17:26.100 --> 17:28.440] They make fantastic analysts. [17:28.800 --> 17:33.640] One of the best hackers I know was a nanny before she got into the industry. [17:33.960 --> 17:46.100] So these surprising backgrounds, it's all about their creativity, their persistence, their ability to dig into things that you're really looking for, not what their degree was in. [17:47.780 --> 17:52.340] So, and the payoff for getting diverse is huge, right? [17:53.000 --> 17:55.740] Nineteen percent higher innovation revenues. [17:55.940 --> 17:58.340] And that's for, you know, companies that are trying to sell something. [17:58.660 --> 18:05.180] Think about how much a bump in just innovation in the way you approach security could be for your team. [18:05.180 --> 18:13.980] Getting people to think differently than you is so good for an effective, productive team and raising your ability to do things and do them faster. [18:15.600 --> 18:26.860] And then, so in addition to the training for our team, security awareness training is, first of all, it's usually hideous, right? [18:26.960 --> 18:30.940] I mean, I'd rather rub glass in my eyes than go through most security awareness training. [18:31.040 --> 18:33.120] But you've got to do it because it's a compliance thing. [18:33.120 --> 18:35.340] Well, there's multiple... [18:36.020 --> 18:36.460] Wait. [18:36.740 --> 18:36.880] Oops. [18:37.000 --> 18:37.140] Sorry. [18:37.320 --> 18:38.880] This is training for our team. [18:39.180 --> 18:39.760] Damn it. [18:40.040 --> 18:45.160] So for the team, there's free training, including Cyber Readiness Institute, CISA's toolkits. [18:45.500 --> 18:47.640] I don't know if you guys can see behind the podium. [18:48.420 --> 18:49.940] Even, well, security b-sides. [18:50.020 --> 18:53.100] Many security b-sides are offering free training these days. [18:53.320 --> 18:54.620] I know there's workshops here. [18:54.700 --> 18:55.200] Were they free? [18:55.320 --> 18:56.740] I didn't see if they were free or not. [18:56.880 --> 18:59.040] Anybody know if the workshops here were free? [18:59.900 --> 19:00.260] Yeah. [19:00.380 --> 19:00.680] Awesome. [19:00.840 --> 19:01.020] See? [19:01.020 --> 19:02.140] Yeah, that kind of stuff. [19:02.380 --> 19:06.540] And again, this is the community and the value of the community giving into it. [19:08.140 --> 19:08.580] So... [19:08.580 --> 19:13.200] And then, a lot of times, you don't have the luxury of a tiered SOC, right? [19:13.300 --> 19:14.420] Tier one, tier two, two, three. [19:14.540 --> 19:15.480] You've got a couple people. [19:15.960 --> 19:22.260] Think instead about forming it as a fusion SOC, where you each... [19:22.260 --> 19:34.880] You have each one of the people kind of focusing on something for a couple months, whether it's reading the logs, analyzing alerts, doing reversing, if you can get to that point of some malware and see what it's actually trying to do. [19:35.020 --> 19:36.100] But then you rotate. [19:36.420 --> 19:43.180] And each person that learned the previous thing has to teach the person filling their role how to do it. [19:43.440 --> 19:47.260] Because you learn so much faster when you have to teach someone else, right? [19:47.380 --> 19:49.220] It's a great tactic. [19:49.760 --> 19:54.340] And each time you make these rotations, people are just going to get better and better at what they do. [19:54.520 --> 19:57.620] So, wash, rinse, and repeat on that approach. [19:58.620 --> 20:01.480] And your team will start sharpening each other. [20:02.840 --> 20:05.780] So, now we talk about employee security awareness. [20:06.560 --> 20:15.080] So, sadly, 45% of employees, especially at the SMB, SME level, receive no security training at all. [20:15.200 --> 20:23.400] And 62% do not provide any security awareness that gives any benefits, which is those videos that we'd rather rub glass in our eyes to watch. [20:23.600 --> 20:25.660] So, how can we improve upon this? [20:26.560 --> 20:31.640] So, Amazon, by the way, puts out for free on Prime. [20:31.640 --> 20:38.380] You can go to Amazon Prime, and the same training that they give their own employees is available to free to anybody. [20:39.060 --> 20:41.420] And security awareness training can be expensive. [20:41.700 --> 20:43.620] So, going to them, getting theirs. [20:44.020 --> 20:45.480] There's a Google course. [20:45.620 --> 20:46.400] This EdApp. [20:46.620 --> 21:02.120] So, any of you that are all in manufacturing or other places where maybe not everybody has a laptop to take security awareness training, EdApp is the first module, which is like cybersecurity awareness basics, is free and can be done on a phone. [21:02.340 --> 21:07.120] So, if you have a force that's out in the field and they're like, oh, we can't do security awareness because we don't have a... [21:07.120 --> 21:07.320] Yeah. [21:07.520 --> 21:08.240] No, it's right there. [21:08.340 --> 21:08.860] You can do it. [21:09.360 --> 21:14.400] Backdoors and Breaches, which is a free tabletop exercise constructed as a... [21:14.400 --> 21:15.360] Some of you are nodding. [21:15.500 --> 21:15.580] Yep. [21:15.640 --> 21:16.660] It's a lot of fun. [21:16.800 --> 21:20.280] It's like Dungeons and Dragons and Pokemon together, but around breaches. [21:22.200 --> 21:23.360] NIST has some stuff. [21:23.500 --> 21:25.180] Wizzer has some free training as well. [21:25.380 --> 21:29.200] And then, I got this idea from Ben 10. [21:29.400 --> 21:30.960] I don't know if any of you know Ben 10. [21:31.200 --> 21:31.740] He did a... [21:31.740 --> 21:33.220] Yeah, Ben's fantastic. [21:33.740 --> 21:39.420] He did a talk about this back in DerbyCon, like 2012, somewhere around there. [21:40.580 --> 21:41.900] Stupid, simple idea. [21:42.220 --> 21:53.760] All he said to his company, he made an announcement and said, hey, all that stuff you've been learning in your cybersecurity awareness training, you're gonna start seeing some of those things around the office. [21:54.060 --> 22:04.400] Anybody that reports, you know, something that seems like it's a security awareness flaw or whatever, the first person to report it will get like, I don't know, a $5 gift card. [22:04.600 --> 22:05.960] He's gonna keep tabs. [22:06.160 --> 22:11.520] And at the end of the week, whoever racks up the most points is gonna get a $200 gift card. [22:11.880 --> 22:16.340] And that's all it took to turn his people into rabid security people. [22:16.340 --> 22:19.600] They're like, you're going down, I'm gonna get more points than you. [22:19.760 --> 22:26.020] They started doing things like reporting the CFO for walking through the office without their badge on, because we all have to have our badges on at all times, right? [22:26.300 --> 22:30.560] They reported a black box sitting outside one of the side entrances. [22:30.820 --> 22:32.820] And it turned out it was a rodent control box. [22:32.980 --> 22:34.520] But they were still paying attention. [22:34.900 --> 22:40.820] He had basically turned his people into carbon-based intrusion detection systems, and it was working gloriously. [22:41.260 --> 22:47.080] So gloriously that 15 minutes after he announced the competition, one woman called him up very excited. [22:47.220 --> 22:49.240] She's like, Ben, Ben, I found one of your things. [22:49.520 --> 22:52.100] And he's like, we haven't started yet? [22:52.320 --> 22:53.920] One of what things? [22:54.060 --> 22:56.740] And she's like, that's stuff you said we'd see with the security. [22:56.940 --> 22:59.220] And he's like, oh my God, what are you seeing? [22:59.400 --> 23:04.980] And she's like, well, every once in a while, this little dialogue box pops up and says, you know, click here to authorize access or something. [23:05.180 --> 23:05.460] Like, yeah. [23:06.020 --> 23:09.580] They had a real incident 15 minutes into the competition. [23:10.600 --> 23:14.780] Now, I will warn you, I've had people come up to me and say, yeah, we tried it too, and it was working great. [23:14.940 --> 23:22.060] But people wanted so badly to win that they started downloading Nessus to look for vulnerabilities, right? [23:22.740 --> 23:25.400] Which means you've got a whole other problem, right? [23:25.500 --> 23:27.360] And they shouldn't be able to do that in the first place. [23:27.460 --> 23:29.260] So maybe that was good anyway. [23:29.800 --> 23:34.720] But yeah, there have been some companies that people just got so competitive that they started doing things like that. [23:35.500 --> 23:41.400] But highly effective, I think out on Ben's GitHub, he even has the scoring software still out there. [23:41.560 --> 23:44.240] And that's Ben 0XA for Ben 10. [23:46.800 --> 23:54.280] So then as we're building this out, as we're doing security awareness, building the right culture around this is critical. [23:54.580 --> 24:06.220] I don't know how many times I've been at small companies where everybody has to do multi-factor except for the boss and the guy under the boss and somebody in HR and whatever. [24:07.080 --> 24:09.220] It has to be across the board. [24:09.400 --> 24:13.140] The leaders need to be taking up the reins and modeling this behavior. [24:13.300 --> 24:19.040] You can't get people to actually do the right security stuff if the bosses themselves are not doing the work. [24:21.540 --> 24:23.020] So regular training. [24:23.120 --> 24:32.620] In fact, I like the concept of trickle training and some of the security awareness tools out there are doing it where they just, you know, give you a little thing every week instead of like five hours of videos. [24:35.240 --> 24:38.380] Make sure that employees are actually encouraged to ask why. [24:38.520 --> 24:50.260] If you're gonna force two-factor on them and they have no idea what the fuck it is or why you're doing it, take that, especially at a small company, take 15 minutes and go, this is what this does and why it's important. [24:50.460 --> 24:52.000] Tell them about credential stuffing. [24:52.180 --> 25:06.780] Tell them about the fact that they used their password that they use for their corporate ID also on their Home Depot account, right, because it was really easy to remember, is something that we're gonna use two-factor to try and defeat because we know they can't memorize 10,000 [25:06.780 --> 25:07.180] passwords. [25:07.400 --> 25:12.300] And I don't know how many people have had like relatives that just cannot get a password vault figured out. [25:12.460 --> 25:13.660] Like, yeah, right? [25:14.160 --> 25:15.820] I'm like, try and teach them, try and teach them. [25:15.840 --> 25:17.020] It doesn't work all the time. [25:18.000 --> 25:19.200] Make it fun and personal. [25:19.360 --> 25:20.300] Do things like the games. [25:20.460 --> 25:26.900] Maybe even have just like little lunch and learns where you teach people how to change the default password on their modems at home. [25:27.120 --> 25:27.980] Stuff like that. [25:28.380 --> 25:31.880] Just little tiny things that make it helpful to them as well. [25:32.460 --> 25:35.200] And then, yeah, holding everybody to the same standards. [25:37.300 --> 25:38.660] So insider threat. [25:38.920 --> 25:39.840] Now this is interesting. [25:40.060 --> 25:45.040] Small orgs actually have a bit of a leg up when it comes to insider threat. [25:45.200 --> 25:48.760] Because in many organizations, everybody knows each other. [25:48.760 --> 25:57.700] So if you start seeing those, and there's some free training out there to look for the signs of risk before it comes a threat. [25:57.940 --> 26:06.000] But changes in behavior, whether it's from depression or people acting like people sometimes do when they've stolen a lot of money. [26:06.160 --> 26:10.240] Things like that are much easier to identify in a small org. [26:11.640 --> 26:14.240] You can teach your people how to look for it. [26:14.940 --> 26:20.620] But the inverse of this is you got to watch out for people that use things like this as retaliation too. [26:20.840 --> 26:23.160] Small office politics are brutal sometimes. [26:23.500 --> 26:28.560] And people will go, oh, you know, Joe's acting a little weird lately. [26:28.780 --> 26:30.300] And Joe's not acting weird at all. [26:30.400 --> 26:34.720] But someone got pissed at Joe for taking their yogurt out of the fridge last week. [26:34.820 --> 26:35.740] Something like that, right? [26:36.360 --> 26:38.660] So you got to watch out for a little bit of that. [26:38.660 --> 26:40.380] But this can be super effective. [26:41.200 --> 26:46.440] And the best is to get the indicators before they actually become a threat. [26:46.440 --> 26:54.680] When they're starting to be a little disgruntled, when they're starting to act like they might do something like steal data and then quit or something like that. [26:54.920 --> 26:59.120] If you can get it and nip it in the bud before they become a full-on risk, that's awesome. [27:00.060 --> 27:00.580] Process. [27:00.580 --> 27:02.880] So we've talked about improving people. [27:03.080 --> 27:05.120] Some easy ways to improve process. [27:05.460 --> 27:09.800] So who remembers when this was the SANS 20 critical controls? [27:09.940 --> 27:10.160] Yeah. [27:10.700 --> 27:11.560] Great stuff. [27:11.860 --> 27:12.980] But now there's more. [27:13.160 --> 27:13.800] It's only 18. [27:14.320 --> 27:15.820] And it's not SANS anymore. [27:16.060 --> 27:20.460] But the implementation groups just came out, I think, last year. [27:20.600 --> 27:23.060] And they are brilliant for small organizations. [27:23.060 --> 27:33.920] So what they did with the implementation groups is they took all of the controls, which almost nobody can absolutely implement, and break it down to the first barrier of entry. [27:34.080 --> 27:39.440] So implementation group one for assets is just these first two. [27:40.320 --> 27:46.140] CIS is just saying, dude, if you can just do these first two, man, that'd be awesome, right? [27:46.340 --> 27:49.520] And we all know how hard the asset control stuff is. [27:49.680 --> 27:51.460] I mean, nobody's got a perfect... [27:51.460 --> 27:56.560] I've never seen a company that had perfect grip and inventory of their assets. [27:56.560 --> 28:00.560] But you can start moving in that direction by at least trying to hit the first two. [28:00.640 --> 28:01.340] And guess what? [28:02.080 --> 28:03.560] You don't even need to start... [28:03.560 --> 28:09.920] We all know that control one is the great one to start with because you can't protect what you don't know. [28:10.000 --> 28:10.980] But fuck it. [28:11.240 --> 28:13.620] Sometimes you're at a small company, you can't. [28:13.880 --> 28:17.720] Maybe if you're at a small company, the first thing you want to do is maybe target nine and ten. [28:18.080 --> 28:20.120] Just some malware defenses and protecting that email. [28:20.760 --> 28:25.800] If you can get those two done at a small org, you're probably ahead of the game. [28:25.800 --> 28:30.280] You'll want to get the assets under control if you can. [28:30.840 --> 28:31.560] But these are... [28:31.560 --> 28:34.740] You know, nine to ten is probably where most companies are getting hit. [28:35.180 --> 28:37.640] Why not get your best bang for your buck right out of the gates? [28:37.800 --> 28:39.140] You don't have to do them in order. [28:41.340 --> 28:48.340] So, as we're starting to mature now, we've got to start reporting to the board or the president or the owner. [28:48.540 --> 28:50.020] I don't know of the small company you're at. [28:52.160 --> 28:53.940] And defining risk... [28:54.860 --> 28:57.640] We suck at measuring risk, right? [28:57.760 --> 28:58.580] It's just terrible. [28:58.580 --> 29:06.820] A lot of the frameworks that we've come out with for trying to describe risk to the people that give us the money are just god-awful. [29:06.920 --> 29:07.680] And we do. [29:07.780 --> 29:09.960] We end up looking like this every time we try and describe it. [29:11.120 --> 29:11.600] So... [29:11.600 --> 29:13.440] And this is from Forrester's lovely. [29:14.120 --> 29:18.120] They are improvising risk management, which means they're making shit up. [29:18.300 --> 29:19.560] That's what that line means. [29:19.580 --> 29:21.820] They're just like, I think this is a high. [29:21.820 --> 29:23.260] I think, yeah, right? [29:23.360 --> 29:26.600] We're just, you know, calling an audible and guessing. [29:28.420 --> 29:30.740] This, in fact, further illustrates it. [29:31.160 --> 29:33.660] So, risk matrices can be worse than useless. [29:33.920 --> 29:37.880] Should not be used for any decision of consequence. [29:38.560 --> 29:41.060] This matrix, this is absolute horseshit. [29:41.200 --> 29:42.320] This is the worst thing in the world. [29:42.520 --> 29:49.400] Not only does it tell us nothing, but even worse, it gives us the illusion that we've actually measured the risk. [29:49.400 --> 29:50.000] Oh, yeah. [29:50.300 --> 29:51.580] Yeah, we know what the risk is, right? [29:51.680 --> 29:52.120] It's red. [29:52.300 --> 29:53.100] The risk is red. [29:53.600 --> 29:56.140] Risk is red doesn't tell anybody jack shit. [29:56.500 --> 29:57.620] What I like... [29:57.620 --> 30:00.640] And it's starting to be incorporated in FAIR as well, but... [30:00.640 --> 30:05.020] Anybody ever hear of or read Douglas Hubbard, How to Measure Anything in Cybersecurity Risk? [30:06.220 --> 30:09.300] Brilliant, brilliant book and methodology. [30:09.760 --> 30:17.020] What he does is he uses Monte Carlo simulations and has teams start to give estimates. [30:17.020 --> 30:20.620] And by the way, one of the things he says we suck at is estimating risk. [30:20.780 --> 30:27.620] But he also proves that people can become better risk estimators in half a day with just a little simple training. [30:28.740 --> 30:33.220] But he takes these things over here and starts putting them into probabilities. [30:33.500 --> 30:36.100] What is the probability of us having a ransomware attack? [30:36.240 --> 30:38.920] What is the probability of us having data leakage? [30:39.220 --> 30:39.940] Things like this. [30:39.940 --> 30:49.400] And then you also go to the board and you're like, hey, what percentage of probability would you accept for us to lose $2,000 this year? [30:49.580 --> 30:51.660] And a lot of companies might be like, yeah, 90%. [30:51.660 --> 30:52.620] No problem. [30:53.140 --> 30:54.660] How about $2 million? [30:55.140 --> 30:56.960] Yeah, that better be lower than 5%. [30:56.960 --> 31:04.540] So now you've got what your estimated potential risk is and you've got what the board is willing to pay for out of their pocket. [31:04.540 --> 31:08.100] And all of a sudden, you get graphs like this. [31:08.140 --> 31:10.460] And this is something your board will, you know, understand. [31:10.720 --> 31:15.040] You said you will accept this much probability of us losing this much money. [31:15.180 --> 31:15.960] And guess what? [31:16.080 --> 31:17.520] Our risk is higher than that. [31:17.640 --> 31:23.720] So please give us enough money to bring that risk down below the actual inherent risk. [31:25.160 --> 31:26.380] It takes some tweaking. [31:26.540 --> 31:29.940] It'll never be perfect, but it's a hell of a lot better than those risk matrixes. [31:31.040 --> 31:34.560] So then just some basic hygiene for small orgs, right? [31:34.780 --> 31:36.680] Well, I pointed out, CISA has... [31:36.680 --> 31:40.480] Well, God, for a moment there, I was worried that CISA was not going to have anything for us. [31:41.380 --> 31:43.260] But they still are in existence. [31:43.720 --> 31:47.640] And they've got some awesome, awesome services for small and medium businesses. [31:47.900 --> 31:50.020] They'll scan your web apps for free. [31:50.240 --> 31:52.060] They'll scan your vulns for free. [31:52.200 --> 31:53.640] Is it a full-on pen test? [31:53.820 --> 31:54.120] No. [31:54.340 --> 31:58.940] But if you're not doing anything right now, oh my God, this is a fantastic service. [31:58.940 --> 32:01.960] They'll do an instant management review with you. [32:02.180 --> 32:02.780] They'll come in. [32:02.880 --> 32:04.080] They'll even do some tabletops. [32:04.220 --> 32:05.200] All for free. [32:05.620 --> 32:09.120] And they're particularly targeting the small to medium enterprises. [32:12.100 --> 32:13.140] So then... [32:13.140 --> 32:16.360] So I talked about using stuff to get you a better budget. [32:16.560 --> 32:28.940] So many companies that are required to do security assessments approach it like a checkbox exercise instead of, I need more fucking money exercise, which is what it should be. [32:29.120 --> 32:34.500] If you actually have to get a pen tester in, you pull that pen tester aside and you go, you know what? [32:34.640 --> 32:36.200] We're really screwed over here. [32:36.400 --> 32:41.200] I want you to make sure you hit that and get it into the report. [32:41.480 --> 32:45.720] Because the bosses are going to lose their shit and go, wait, you did what? [32:45.720 --> 32:46.400] Yeah, yeah. [32:46.560 --> 32:47.680] We got your password. [32:47.880 --> 32:48.300] Brilliant. [32:48.580 --> 32:48.780] Yes. [32:48.980 --> 32:50.240] More money coming down the pipe. [32:52.520 --> 32:53.400] So, yeah. [32:53.540 --> 32:54.960] Tailor those to your goals. [32:55.180 --> 32:56.480] Don't just do a checkbox. [32:58.440 --> 33:06.700] And if you have security team inside and you're not just having to hire the checkbox people, make sure that every assessment is purple team. [33:06.700 --> 33:11.800] The testers should be sitting, at least on the first couple goes, right, out of the box. [33:11.980 --> 33:15.380] You don't want the pen testers, like, doing stuff off on the side. [33:15.380 --> 33:18.620] You actually want them hitting your boxes and go, did you see that? [33:18.900 --> 33:23.740] Because if the answer is no, you know you've got some holes to shore up. [33:25.060 --> 33:30.520] Also, create high... a lot of companies don't even know how to create highly detailed scoping docs. [33:30.520 --> 33:38.500] And you know what happens if you engage one of the auditing firms or basically any pen testing firm, and you don't tell them what you want. [33:38.980 --> 33:45.660] They stick a kid just out of college with Nessus on your perimeter and go, hey, we did a pen test. [33:45.940 --> 33:46.220] Yeah. [33:46.420 --> 33:48.540] And they... because they know you won't know any better. [33:48.780 --> 33:52.000] So, talk to people in the industry, get some help with scope. [33:52.340 --> 33:55.980] Shit, you can probably ChatGPT this at this point and get a good scoping doc. [33:56.980 --> 34:03.920] And then, insist on quality output, which means don't just tell us what's broken, tell us how to frickin' fix it. [34:04.480 --> 34:06.580] And a lot... I've seen a lot of pen testing companies. [34:06.760 --> 34:09.320] They'll give you the readout, but they won't tell you how to fix it. [34:11.100 --> 34:15.980] And then... then the other mistake a lot of small companies go is they're like, oh, we're gonna have a pen test. [34:16.120 --> 34:18.380] We're not gonna tell you shit about our network. [34:18.520 --> 34:19.720] We're you... you gotta get in there. [34:19.840 --> 34:22.400] All you're doing is testing how good the pen tester is. [34:22.520 --> 34:24.020] And oh, by the way, they always get in. [34:24.020 --> 34:27.060] Always, every fucking time, and what's the usual way? [34:27.120 --> 34:33.440] If it's not web apps, it's always phishing, especially at a small org that hasn't had any security, we're in a straining anyway. [34:33.660 --> 34:35.640] They will phish the fuck into your network. [34:36.100 --> 34:38.100] Don't even do the black box for a sign. [34:38.220 --> 34:43.300] Maybe as you mature, that could be interesting, but give them a foothold inside, right away. [34:43.600 --> 34:45.680] Give them a box, give them credentials, whatever it takes. [34:46.040 --> 34:52.120] Most pen testing companies will send a little, you know, Windows nook or whatever for you to just plop onto the network. [34:52.120 --> 34:56.560] What you want to test is how much damage they can do once they've got a foothold. [34:56.840 --> 35:01.740] That's the important thing if you're a small org and you only have so many thousand dollars to do this pen test. [35:02.600 --> 35:14.060] And then as you mature, a translucent box, where you give them a little bit of information, you try to get it closer to a real-world scenario, that would be the next level of maturity, but that transparent box is the way to go to start. [35:15.340 --> 35:20.560] All right, who here has a vendor trying to sell them a zero-trust tool in the last couple of years? [35:21.020 --> 35:23.140] Yeah, we have the zero-trust. [35:23.200 --> 35:24.360] Zero-trust is not a tool. [35:24.640 --> 35:25.760] It's a process. [35:26.160 --> 35:28.260] There are some tools that can help you with it. [35:29.120 --> 35:34.060] But there are some very, very easy ways to get zero-trust going in your organization. [35:34.600 --> 35:37.460] And we should all be heading down this path anyway. [35:37.960 --> 35:42.900] But yeah, MFA for everyone, it's the everyone that most orgs make the mistake. [35:43.020 --> 35:46.640] Oh, we'll just give it to the admins because they're the only one with creds to the important. [35:46.720 --> 35:47.180] Yeah, no. [35:47.340 --> 35:56.620] It's got to be everyone, including your partners, including third-party partners, literally anyone that touches any aspect of your systems or connects to them. [35:58.100 --> 36:04.000] Then just logging some simple privileged activity goes a long way to zero-trust. [36:04.060 --> 36:07.420] I don't know if anybody can see that down there, but secure remote access. [36:07.600 --> 36:10.040] Jump boxes are a great way to get zero-trust. [36:10.180 --> 36:13.900] I mean, jump boxes at this point, the concept's like, what, 20 years old? [36:14.060 --> 36:25.660] And they're still an effective way to create a choke point so that they have to go through that box to get to anything, and then you can log that if, of course, they don't delete the logs before you can get to them. [36:27.300 --> 36:36.360] And then just by then logging privileged activity and doing some other stuff, you've got the groundwork for zero-trust. [36:36.500 --> 36:42.820] This will take you really far as far as leveraging that concept with your org, and you've bought almost nothing, right? [36:42.920 --> 36:44.920] A lot of these things are things you might already have. [36:45.280 --> 36:52.520] The 2FA is probably going to be the most expensive thing here, unless you're not logging and you buy Splunk, because then that'll be... I used to work for Splunk. [36:54.040 --> 36:55.920] So that'll be the most expensive thing. [36:57.600 --> 37:00.060] And then find ways to automate everything. [37:00.220 --> 37:16.000] Now that all of a sudden everybody can start coding automation with LLMs, I'm seeing more of this, but I have someone who is actually an automation engineer that I know, and she's like, if you have to do anything in the org more than twice, automate that shit. [37:16.160 --> 37:19.220] And they don't have to be just an automation engineer for security. [37:19.400 --> 37:27.140] When they're not doing stuff for the security team, you should have them on staff automating as many possible things that they can. [37:27.520 --> 37:31.940] It will pay off in dividends, and it'll make your lives a hell of a lot easier. [37:32.260 --> 37:40.560] And especially, you know, if you've got young interns that maybe haven't scripted a whole lot, this is a great resource for them to depend on as well. [37:41.000 --> 37:44.000] Again, maybe LLM can start doing a lot of this for you too. [37:44.660 --> 37:49.880] And now we can talk a little bit about the technology that can help SMBs. [37:49.880 --> 37:56.380] So I don't see most SMBs harnessing the full power of what they get when they go to the cloud, right? [37:57.560 --> 38:00.920] Doing frequent immutable backups now is a freaking... [38:01.420 --> 38:03.020] Who had to do the tapes? [38:03.420 --> 38:05.980] Who had to be on tape duty for backups? [38:06.220 --> 38:09.000] How many times did they fail on you and you didn't know it? [38:09.280 --> 38:09.560] Right? [38:09.740 --> 38:11.460] It seems to be every other month. [38:11.560 --> 38:13.660] You go down there and you're like, I've got to switch the tapes out. [38:13.960 --> 38:16.060] Oh yeah, the tape doesn't have anything on it. [38:16.180 --> 38:17.100] Back to the drawing board. [38:17.300 --> 38:18.240] Make a full backup. [38:18.240 --> 38:20.080] Start the incrementals next week. [38:21.140 --> 38:21.580] So... [38:21.580 --> 38:24.940] But you can push a button now and make sure that you've got backups. [38:25.140 --> 38:29.120] And then just making them immutable would be the second thing. [38:29.260 --> 38:30.360] And you can do that. [38:31.320 --> 38:35.780] Putting the password in your fire call service would be a perfect way to start with that. [38:37.180 --> 38:41.960] A lot of companies, again, moving to the cloud, but they're not leveraging anything... [38:41.960 --> 38:45.660] Any of the protective devices like AWS's WAF or Google Cloud's Armor. [38:46.820 --> 38:54.720] And then just having clean images that are regularly reloaded will stop a lot of persistence with the organization. [38:55.260 --> 38:59.840] Most small companies don't even have a golden image, which is part of their problem. [39:00.000 --> 39:09.960] But just reloading a new golden image every so often to make sure that there's nothing persisting in the code, assuming they haven't made it to your golden image, really helpful. [39:10.500 --> 39:11.040] And then... [39:11.040 --> 39:13.240] So who here has heard of chaos engineering? [39:13.380 --> 39:14.680] Netflix was really big on it. [39:14.780 --> 39:14.920] Yeah. [39:14.920 --> 39:21.260] So Netflix's idea with chaos engineering was to just break stuff regularly and make sure that you were resilient. [39:22.860 --> 39:28.860] Kennedy Takura from IEEE came up with a concept of chaos security engineering. [39:29.000 --> 39:35.740] So what he recommended was that you put flaws, like drop a password in an S3 bucket. [39:36.060 --> 39:38.200] I mean, these days Amazon will tell you almost immediately. [39:38.380 --> 39:41.660] But that's a good example of the kind of flaw you might want to put out there. [39:41.660 --> 39:46.320] And then see what kind of access you can get by creating a flaw. [39:46.600 --> 39:49.380] Someone who's got the wrong, you know, amount of access rights. [39:49.560 --> 39:50.440] Other things like that. [39:52.180 --> 39:53.180] How am I doing on time? [39:55.280 --> 39:55.680] Yep. [39:55.860 --> 39:56.200] We're good? [39:56.280 --> 39:56.380] Yeah. [39:57.580 --> 39:58.160] I'm done. [39:58.480 --> 39:59.200] Oh, all right. [39:59.280 --> 39:59.420] Quick. [39:59.620 --> 39:59.940] All right. [40:00.200 --> 40:01.340] Two quick, quick steps. [40:01.540 --> 40:04.720] Get rid of fucking Active Directory you don't need in a small org. [40:05.320 --> 40:06.640] Switch to Chromebooks. [40:08.060 --> 40:13.480] Deception tactics will get you a lot of money because if you hit on any of these things, you will get money. [40:13.680 --> 40:18.260] And these are stupid easy user tricks to try and get attackers to reveal themselves. [40:19.820 --> 40:21.140] Yeah, you don't need that. [40:21.280 --> 40:21.840] And there we go. [40:22.800 --> 40:23.400] Thank you. [40:23.760 --> 40:26.320] Are we up for up or up for questions up? [40:26.780 --> 40:27.640] Oh, wait, wait. [40:27.900 --> 40:29.120] So let me go to the... [40:29.120 --> 40:31.140] So do most of you know these deception tactics? [40:32.340 --> 40:32.740] Okay. [40:33.000 --> 40:34.760] Because some of this shit is really easy. [40:34.760 --> 40:45.940] You get together with the IT team and you put a file on every system in all those golden images that says, passwords, and then just alert if someone touches that file. [40:46.200 --> 40:49.880] That is such a fantastic way to get an attacker to reveal... [40:49.880 --> 40:51.880] What attacker is going to resist that? [40:52.040 --> 40:54.420] What attacker is not going to open that file? [40:54.420 --> 40:56.040] And then you can get more advanced. [40:56.200 --> 41:04.020] You can like have fake domain accounts alert just if anybody tries to log into that account, but to have it set up that no one can log into that account. [41:04.860 --> 41:07.900] For your databases, honey tables are great. [41:08.120 --> 41:10.360] Put a table in there that says credit cards. [41:10.480 --> 41:11.780] Only you and the DBA know it. [41:11.780 --> 41:26.640] Anybody hits that table, you've either got an attacker or you've got some database admin that needs to go back to training because they just did select star from everything and that's why they hit that. [41:27.060 --> 41:28.720] Even making honey people. [41:29.040 --> 41:38.620] Putting people out on LinkedIn that are your accounts receivable people and see if someone's trying to catfish them, trying to get information out of them, another great way. [41:38.620 --> 41:44.080] And if you get hits on any of these things, you get to go to your boss and say, I told you. [41:44.340 --> 41:47.320] Now, had this been a real attacker, we'd be screwed. [41:47.320 --> 41:53.320] So can we please get the money I asked you for to put in the 2FA or whatever it needs to protect yourself? [41:55.200 --> 41:56.420] A hundred percent, yes. [41:56.600 --> 42:00.560] There's a free open-source tool called Canary Tokens that can help you deploy a lot of this. [42:01.100 --> 42:01.500] Fantastic. [42:02.120 --> 42:03.920] There's some commercial ones as well. [42:04.760 --> 42:06.400] But this is really... [42:06.400 --> 42:07.420] Oh, this one over here. [42:07.480 --> 42:08.540] This one's great. [42:08.800 --> 42:09.920] It puts a... [42:10.840 --> 42:12.280] It's called Invoke Run As. [42:12.380 --> 42:14.720] It puts fake admin account in memory. [42:15.060 --> 42:20.140] So if you actually get someone who's trying to scrape creds out of memory, you can trigger on that too. [42:20.260 --> 42:21.600] And it's creds to nothing. [42:21.900 --> 42:23.600] So that's a beautiful one. [42:24.220 --> 42:25.840] And okay, now we can take questions. [42:29.100 --> 42:30.200] Everybody, let's hear it for Robert. [42:31.720 --> 42:32.120] Thank you. [42:37.390 --> 42:42.070] So if you are on the Matrix, I'll take your questions there. [42:42.210 --> 42:47.990] We'll go Matrix, human, Matrix, human, and present if we have questions in Matrix. [42:48.590 --> 42:50.150] We don't have any questions in Matrix. [42:51.670 --> 42:54.450] If folks would like, I can come around to a mic or you can come up here. [43:15.370 --> 43:20.350] It's only been recently that CrowdStrike started selling like a five-person license. [43:20.570 --> 43:20.650] Right? [43:20.970 --> 43:23.990] There's some really good asset management and threat intelligence. [43:24.590 --> 43:27.750] Snipe IT or Snipe IT by Snipehead. [43:27.950 --> 43:33.010] Great free open-source asset management tool that you can get. [43:33.830 --> 43:35.930] There's some good password vaults out there. [43:36.230 --> 43:37.410] So a lot of... [43:37.410 --> 43:38.570] It's a free version also. [43:38.930 --> 43:39.370] Duo has a free version. [43:39.490 --> 43:39.630] Duo. [43:39.930 --> 43:40.330] Yeah, Duo. [43:40.650 --> 43:41.130] Fantastic. [43:41.330 --> 43:43.690] Duo has a free version of Duo for small organizations. [43:44.090 --> 43:44.290] Yes? [43:44.550 --> 43:56.190] So my main question was mainly with all the vibe coding that has come out with AIs and LLMs, what's like the best advice to stop like, you know, insane leaks or anything like for basic web developers or app developers? [43:56.510 --> 43:57.350] For stopping what? [43:57.550 --> 44:02.790] Like just getting attacked or getting like, you know, access to your system through like a web app or... [44:02.790 --> 44:03.370] Oh, yeah. [44:04.110 --> 44:05.390] Especially with vibe coding and AI. [44:05.410 --> 44:05.830] Yeah. [44:06.450 --> 44:14.190] You know, I have a friend who's actually released his own LLM called Hacker Sidekick that will actually help you write attack code as well. [44:15.350 --> 44:17.510] Again, the best advice is hygiene. [44:18.050 --> 44:25.450] But in, you know, the opposite of that, you can start doing your own code review with LLMs as well, right? [44:25.590 --> 44:27.250] And start seeing if there's stuff out there. [44:28.030 --> 44:29.110] It's not great. [44:29.390 --> 44:30.830] I mean, it gets a lot wrong. [44:31.470 --> 44:36.270] But about the only thing you can do is, you know, continue to patch, continue to check your code. [44:36.550 --> 44:42.850] I see a lot of tools that are coming out that are going to be doing a lot of SAST and DAST to make sure that you haven't injected those flaws. [44:42.850 --> 44:56.970] And I think over time, as LLMs do a lot of our coding for us, just like we have secure libraries now, which has always been a good practice, I think we can start having LLMs make sure that they are also using secure libraries and things like that. [44:56.970 --> 44:57.630] Thank you. [44:57.790 --> 44:57.970] Yeah. [45:04.350 --> 45:11.730] For those online, there's a product called, one of the audience said there's a product called Cursor that'll check all your lines of code for vulnerabilities as well. [45:13.010 --> 45:13.970] Do we have any other questions? [45:19.260 --> 45:20.040] Yeah, you're good. [45:20.280 --> 45:21.120] That was a good tip. [45:21.460 --> 45:21.520] Yeah. [45:22.720 --> 45:24.000] First of all, thanks for this talk. [45:24.440 --> 45:26.280] I just have a couple of recommendations. [45:26.680 --> 45:26.860] Yeah. [45:27.020 --> 45:29.100] Especially for people who are local to New York. [45:29.220 --> 45:29.620] Oh, wow. [45:30.020 --> 45:30.420] Fantastic. [45:30.420 --> 45:45.700] For recruiting, like, entry-level staff members in IT and security, BMCC, the Borough Manhattan Community College and Kingsborough Community College in Brooklyn, have, like, they have IT academic programs. [45:45.920 --> 45:54.680] So, recent graduates, students who are just about to graduate, excellent source of talent and labor for your organizations. [45:55.820 --> 45:56.540] Fantastic. [45:56.820 --> 45:57.540] Great tip. [45:57.680 --> 45:57.800] Yeah. [45:58.280 --> 46:09.400] Another thing for those local in the city, if you have a New York Public Library card, Brooklyn Public Library card, Queen's Public Library card, you can access LinkedIn Learning for free through the library's website. [46:09.880 --> 46:19.060] And you can get it on your phone, you can get it in an app, and they have, like, a vast library of security and IT training videos and courses you can get into. [46:19.220 --> 46:21.040] See, your mom told you to get a library card. [46:21.160 --> 46:21.660] Did you listen? [46:22.920 --> 46:23.580] Thanks again. [46:23.920 --> 46:24.520] Thank you. [46:28.680 --> 46:29.240] Thank you. [46:29.240 --> 46:29.320] Hi. [46:29.640 --> 46:32.100] Thank you for the amazing talk and the recommendations. [46:33.660 --> 46:41.660] I've heard some pushback against phishing security tests that we give to employees to test their phishing abilities. [46:41.840 --> 46:42.060] Yeah. [46:42.220 --> 46:43.320] What's your take on that? [46:43.320 --> 46:48.380] So treat it like the military treats training, right? [46:48.600 --> 46:55.820] It should be the equivalent of, you know, war games or live fire exercise or whatever, but don't shame them. [46:56.400 --> 47:01.700] Instead, I mean, if you have to do something, reward the people that are doing really well, right? [47:02.000 --> 47:08.600] And for the folks that fail, again, don't make them through five fucking hours of security awareness training. [47:08.600 --> 47:09.920] Give them a little bump. [47:10.080 --> 47:10.760] Hey, you failed this. [47:10.860 --> 47:11.480] This is why. [47:11.740 --> 47:13.560] Shouldn't take more than, like, a couple minutes. [47:14.880 --> 47:30.820] But, again, doing a trickle approach to that kind of stuff where you're giving them, you know, just a little informative, you know, test every once in a while and see how they do is much better than trying to humiliate people, which is totally the wrong thing to do. [47:31.440 --> 47:42.600] But I definitely believe always be trying to fish your people because, I mean, good God, how many of you have, like, clicked on a button thinking it was, you know, or a link thinking it was, you know, your actual boss or something? [47:42.840 --> 47:44.340] I've been tricked a couple times. [47:44.340 --> 47:47.940] Thank God, you know, my endpoint protection had no problems with it. [47:47.940 --> 47:54.320] But I think anybody can be fooled given the right time, the right frame of mind, the right pre-contexting. [47:54.480 --> 47:55.780] It's just too easy. [47:55.980 --> 47:56.740] So keep hitting them. [47:56.840 --> 47:56.940] Yeah. [47:57.160 --> 48:01.140] Keep making sure that they remember that bad things can happen. [48:05.690 --> 48:08.510] I'm from Detroit, so I like car analogies to start with. [48:08.770 --> 48:09.130] Fabulous. [48:09.470 --> 48:09.610] Yeah. [48:09.810 --> 48:12.770] So in the automotive industry, the history is they were terrible at safety. [48:12.950 --> 48:16.470] We hurt people until there was a book that came out that said unsafe at any speed. [48:16.470 --> 48:16.870] Yes. [48:17.290 --> 48:19.770] Currently, I think the software industry is unsafe at any click. [48:19.910 --> 48:21.490] They're immune from consequences. [48:22.190 --> 48:30.590] Microsoft's a company that just touched $4 trillion and has terrible security defaults, which makes SMEs more vulnerable in almost any Azure instance or your system. [48:30.970 --> 48:30.990] Sure. [48:30.990 --> 48:43.070] When do you think we're going to get to where a not a signed by, secure by design is just a dog and pony show, but an actual consequences where if they do not ship a secure software, they do not have this. [48:43.070 --> 48:46.470] Does that change the dynamic and change what that poverty line is? [48:46.570 --> 48:46.910] Yeah. [48:47.650 --> 48:48.290] How do we get there? [48:48.370 --> 48:50.070] I would love to see it. [48:51.070 --> 48:57.650] As long as capitalism is the major push for anything being sold, it's going to be hard. [48:58.370 --> 49:00.130] We really do need accountability. [49:00.150 --> 49:10.650] I don't know if we can get there, but one of the better approaches, and I'm glad you brought up safety, that I've seen is a guy who is the CISO for a huge mining consortium from Canada. [49:10.650 --> 49:17.850] And he approaches everything that he does in his security program with the mindset of, well, how do my safety people do it, right? [49:18.030 --> 49:24.190] I put these controls in place to keep people safe, and you get measured on how safe they are. [49:24.350 --> 49:33.870] If we start doing some of that with security as well, where we're actually using the concept of safety and keeping our users safe, we can at least counter that. [49:33.870 --> 49:39.610] But as far as making the manufacturers responsible, oh, man, we've been trying for how long now? [49:40.210 --> 49:42.870] Yes, we can dream and we can keep pushing for it. [49:43.430 --> 49:44.950] Actually, you know how it could happen? [49:44.950 --> 49:46.950] If the insurance companies got on that. [49:47.150 --> 49:54.770] If the insurance companies said, oh, Microsoft, you were the reason this happened, not that they were negligent, we could see some change there. [49:54.770 --> 49:56.710] We're going to take one last question. [49:57.850 --> 49:58.550] Thank you. [49:58.670 --> 50:00.510] This is a fantastic presentation. [50:01.030 --> 50:12.170] Just wanted to say that kind of in what you were saying before, predecessor, but we track the ransomware leak sites and we analyze this stuff. [50:12.330 --> 50:23.370] And what we're seeing is that so many of the smaller industries, so many smaller companies, the other day, a metalworking shop like literally five blocks away from me in Brooklyn got hit. [50:23.370 --> 50:31.590] But the point is that the threat actors use these as a leg up to get into the bigger industries. [50:31.590 --> 50:31.730] Right. [50:32.070 --> 50:43.930] So, for example, a lot of the medical industries, they're going after the sole practitioners who have treating rights at hospitals, for example, whose, you know, their nephew may be the IT person. [50:44.110 --> 50:44.390] Right. [50:44.410 --> 50:45.950] They take care of their office. [50:45.950 --> 51:00.010] And so once you're in there, it's so much easier to, whether it be fishing, whether it be some other way, social engineering, just being able to enter this individual's network with a small businesses network. [51:00.010 --> 51:11.090] But what I'm trying to get at is that the larger companies have to understand that it's in their interest for all of us to be safer. [51:11.250 --> 51:11.430] Yes. [51:11.430 --> 51:14.070] Because then they're less likely to get hit. [51:14.250 --> 51:21.270] And so many times the big breaches that we hear about start out by some contractor getting... [51:21.270 --> 51:24.870] the huge target breach, you know, that kind of started. [51:25.070 --> 51:25.270] Yeah. [51:25.270 --> 51:26.270] So you're absolutely right. [51:26.270 --> 51:28.690] And here's something cool I've been seeing people do. [51:28.870 --> 51:33.950] So there's a couple banks in Chicago that deal with smaller, you know, mom and pop shops. [51:34.370 --> 51:36.990] And they have put together an advisory board. [51:37.050 --> 51:45.130] So when they give that company what they have to do to be compliant, to do business with them, that advisory board then explains what the hell that means. [51:45.130 --> 51:56.790] Because you give it to like a sole proprietor, like you said, and they're like, I've met people in the, you know, sole practitioner that have said, well, I can't use that tool because it's not HIPAA compliant. [51:57.170 --> 51:58.990] And we're like, like, Signal. [51:59.190 --> 52:00.690] They actually thought they couldn't use Signal. [52:01.350 --> 52:01.850] Because it was... [52:01.850 --> 52:02.230] Right. [52:02.430 --> 52:03.830] And we all had to sit there and go, wait. [52:04.090 --> 52:04.730] No, no, no, no. [52:04.790 --> 52:06.110] That's just like using your phone. [52:06.250 --> 52:08.030] Your phone doesn't have to be HIPAA compliant, right? [52:08.150 --> 52:09.030] But they don't know. [52:09.170 --> 52:12.450] And they got all these people trying to sell them the more expensive solution. [52:12.450 --> 52:18.830] So having the big companies have an advisory board as a liaison to the small companies would be great. [52:19.050 --> 52:20.490] I wonder if we could even get... [52:20.490 --> 52:25.350] You know, we have like InfraGard, which is our FBI liaison to critical infrastructure. [52:25.670 --> 52:29.150] Maybe we could start seeing things like that for minor infrastructure, too. [52:29.370 --> 52:32.850] Anybody that's trying to get a foot up at an entry level job, too. [52:33.210 --> 52:38.390] Just going around helping people make immutable backups should make you money for the next five years. [52:38.950 --> 52:39.630] So, yeah. [52:40.210 --> 52:40.730] Are we done? [52:41.010 --> 52:41.170] Yep. [52:41.170 --> 52:41.950] Yeah. [52:41.950 --> 52:42.430] Oh, yeah. [52:43.130 --> 52:43.570] Yeah. [53:00.030 --> 53:00.470] Yeah. [53:00.930 --> 53:00.990] Yeah. [53:00.990 --> 53:03.610] So, like good engineer. [53:03.770 --> 53:04.270] It depends. [53:04.710 --> 53:09.050] I mean, back in the day when people first started doing this, a lot of people were threatened with jail. [53:09.330 --> 53:12.290] I think more people are appreciative now, but I just wouldn't do it. [53:12.410 --> 53:13.790] I would talk to them first. [53:16.150 --> 53:16.510] Yeah. [53:19.050 --> 53:19.490] Yeah. [53:20.090 --> 53:21.290] That's probably a good idea. [53:22.030 --> 53:23.410] Let's hear it again for Robert Wagner. [53:23.410 --> 53:23.810] Thank you. [53:23.810 --> 53:24.470] Thank you for your pleasure.