SardineCon SF/2026

Learn More
Fraudology

Firewall Humano: Por que a Confiança é a Maior Vulnerabilidade na Era da IA

Episódio #404 de Fraud/ol/ogy com a participação de Robert Siciliano e Karisse Hendrick.

Bem-vindo de volta ao Fraudology.

Se você trabalhar tempo suficiente com fraude, segurança ou confiança e segurança, começará a perceber algo.

A tecnologia está sempre mudando.

A fraqueza que os criminosos exploram nem sempre muda tanto assim.

Ainda é confiança.

Neste episódio, recebo Robert Siciliano, analista de segurança, autor best-seller e arquiteto do Strategic Human Firewall. Robert passou anos ensinando pessoas e organizações como criminosos manipulam a confiança, a atenção e as suposições do dia a dia. E, sinceramente, é exatamente essa a conversa que precisamos ter agora.

Na era da IA, a fraude não está apenas se tornando mais técnica. Ela também está se tornando mais convincente.

E-mails melhores. Vozes falsas melhores. Melhor capacidade de se passar por outra pessoa. Melhor timing. Histórias melhores. Os criminosos não precisam que todas as pessoas dentro de uma empresa falhem. Eles precisam de um único momento em que o ponto cego humano assume o controle e alguém confia na coisa errada.

É aí que o firewall humano se torna tão importante.

Não como um slogan. Não como mais um módulo de treinamento de conformidade. Mas como uma verdadeira camada de prevenção a fraudes e de comportamento em segurança. O objetivo não é envergonhar as pessoas por clicarem em algo. O objetivo é ajudá-las a entender como a confiança é explorada, por que a engenharia social funciona e como uma melhor compreensão de segurança pode tornar os funcionários mais atentos no trabalho e em casa.

Porque, se o treinamento apenas ensinar as pessoas a passar em uma simulação de phishing, isso não é suficiente.

E já vimos esse roteiro antes.

O que você vai ouvir neste episódio:

  • Por que a confiança é uma das maiores vulnerabilidades em fraudes e cibersegurança
  • Como Robert Siciliano desenvolveu a estrutura Strategic Human Firewall
  • Por que o ponto cego humano torna a engenharia social tão eficaz
  • Como a valorização da segurança difere do treinamento tradicional de conscientização em segurança
  • Por que simulações de phishing podem gerar fadiga quando são tratadas como punição
  • Como os hábitos pessoais de segurança podem fortalecer a conscientização dos funcionários sobre segurança no trabalho
  • Por que a fraude impulsionada por IA torna a gestão de risco humano mais importante, e não menos

O que o firewall humano significa na prática: como a confiança é manipulada, o treinamento de conscientização em segurança funciona melhor quando se torna pessoal e prático, como fraudes impulsionadas por IA tornam a engenharia social mais difícil de detectar e mais fácil de escalar, e como os funcionários podem se tornar camadas ativas de detecção quando sabem o que questionar.

Você deve ouvir este episódio se você:

  • Trabalha com prevenção de fraudes, cibersegurança, confiança e segurança ou gestão de riscos
  • Estão repensando o treinamento de conscientização em segurança para funcionários ou equipes
  • Quer entender como a engenharia social funciona na era da IA
  • Se preocupam em reduzir a fadiga de segurança e a culpabilização das vítimas
  • Precisam de uma forma mais humana e prática de desenvolver a prevenção a golpes e a educação sobre fraudes

Se você gostou deste episódio, não deixe de assinar e avaliar o podcast no iTunes, Spotify, YouTube ou em qualquer plataforma onde você ouça podcasts. Isso ajuda muito a divulgar o programa.

Notas do episódio e principais aprendizados

Por que a confiança é a vulnerabilidade que os criminosos continuam explorando

Muitas conversas sobre prevenção de fraudes e cibersegurança começam com ferramentas. Filtros melhores. Controles melhores. Detecção melhor. Tudo isso é importante.

Mas os criminosos geralmente procuram o caminho que oferece a menor resistência. E, muitas vezes, esse caminho é a confiança.

Alguém confia em um e-mail porque ele parece familiar. Alguém confia em uma ligação porque a voz soa certa. Alguém confia em uma solicitação porque ela parece vir de uma pessoa em posição de autoridade. Esse é o ponto cego humano.

E em uma era de IA, esse ponto cego fica mais caro.

Fraudes impulsionadas por IA tornam os golpes mais convincentes, mais personalizados e mais fáceis de escalar. Portanto, a questão não é apenas se a tecnologia consegue detectar todas as falsificações, mas se as pessoas sabem como desacelerar o suficiente para questionar o que estão vendo.

  • A confiança costuma ser a primeira brecha explorada pelos criminosos
  • A engenharia social funciona porque parece algo normal no momento em que acontece
  • A fraude impulsionada por IA aumenta a qualidade e a escala da enganação
  • A prevenção de fraudes precisa levar em conta o comportamento humano, não apenas os sinais técnicos

Por que o treinamento de conscientização em segurança muitas vezes não atinge o objetivo

O treinamento de conscientização em segurança pode ser útil, mas somente se realmente mudar a forma como as pessoas pensam e agem.

Muitas vezes, o treinamento vira apenas um exercício de conformidade. Assista ao vídeo. Faça o quiz. Clique pelos slides. Talvez seja pego em uma simulação de phishing e acabe se sentindo constrangido na frente da sua equipe.

Isso geralmente não melhora o comportamento em relação à segurança.

Isso gera fadiga.

A observação de Robert sobre a mudança de conscientização em segurança para valorização da segurança é importante porque as pessoas tendem a se importar mais quando entendem como o risco se conecta às suas próprias vidas. Se os funcionários aprenderem como golpes miram suas famílias, suas contas bancárias, seus dispositivos e suas informações pessoais, a lição se torna real.

E, quando isso se torna real em casa, fica mais fácil aplicar no trabalho.

  • O treinamento de conscientização em segurança deve desenvolver discernimento prático, não apenas conformidade
  • Simulações de phishing podem sair pela culatra quando geram vergonha ou ressentimento
  • A valorização da segurança ajuda as pessoas a entender por que o comportamento é importante
  • A relevância pessoal pode tornar a conscientização de segurança dos funcionários mais eficaz.

Por que o firewall humano deve ser uma camada ativa de detecção

A ideia de um firewall humano pode soar um pouco corporativa se não tivermos cuidado.

Mas a versão prática é simples.

Os funcionários não devem ser tratados como alvos passivos dos quais se espera que nunca cometam erros. Eles devem ser treinados e apoiados como camadas ativas de detecção, capazes de perceber quando algo parece errado e saber o que fazer em seguida.

Esse é um modelo muito melhor.

Porque as pessoas costumam estar mais próximas do pedido suspeito. Elas veem a mensagem. Elas ouvem a ligação. Elas percebem quando uma solicitação de fornecedor parece um pouco estranha ou quando uma interação com o cliente não corresponde ao padrão habitual.

O objetivo é ajudar as pessoas a filtrar a intenção, não apenas o tráfego.

  • Um firewall humano ajuda os funcionários a reconhecer intenções suspeitas
  • As equipes de segurança precisam de canais de relato simples que não punam a curiosidade
  • A gestão de risco humano funciona melhor quando os funcionários se sentem apoiados
  • A educação sobre fraudes deve ensinar as pessoas o que questionar e como escalar a situação

Por que o efeito da mesa de cozinha é importante

Uma das ideias mais fortes deste episódio é que o treinamento em segurança se torna mais útil quando sai do ambiente de trabalho.

Robert fala sobre o efeito da mesa de cozinha, e eu acho que isso é importante.

Se alguém aprende a identificar golpes de uma forma que ajude a proteger seus pais, seus filhos, seu cônjuge ou a si mesmo, é muito mais provável que se importe. Não porque a empresa mandou se importar, mas porque entende o risco de uma maneira pessoal.

É aí que a educação sobre fraudes se torna prática.

A prevenção de golpes não é apenas algo que os funcionários fazem pela empresa. É algo que eles podem usar no dia a dia. E quando o treinamento é apresentado dessa forma, ele deixa de parecer apenas mais uma exigência corporativa e passa a ser visto como uma informação útil.

  • Hábitos pessoais de segurança podem fortalecer o comportamento de segurança no local de trabalho
  • A educação sobre fraudes se torna mais eficaz quando se conecta com a vida real
  • Os funcionários ficam mais engajados quando o treinamento ajuda a proteger suas famílias
  • A confiança digital começa quando as pessoas entendem como estão sendo alvo

Por que o fatalismo é um problema de segurança

Robert também fala sobre algo que vemos o tempo todo.

As pessoas sabem que deveriam usar gerenciadores de senhas. Sabem que deveriam ter cuidado com links. Sabem que deveriam desconfiar de pedidos estranhos. Mas então decidem que tudo isso parece complicado demais, irritante demais ou simplesmente inevitável.

Isso é fatalismo.

E os criminosos adoram o fatalismo.

Se as pessoas acreditam que não conseguem se proteger de qualquer forma, elas deixam de tentar. Isso cria uma brecha. Não porque sejam descuidadas, mas porque o sistema parece esmagador.

É por isso que a empatia é importante no treinamento de cibersegurança. Se quisermos que as pessoas mudem de comportamento, precisamos encontrá-las onde elas estão. Não envergonhá-las. Não assustá-las. Não afogá-las em jargão. Ajudá-las a entender o risco e dar a elas passos que realmente possam usar.

  • O fatalismo torna as pessoas menos propensas a adotar proteções básicas
  • A fadiga de segurança aumenta quando o treinamento parece punitivo ou irrealista
  • A educação empática pode reduzir a lacuna de valorização
  • Uma melhor gestão de riscos humanos começa com comportamentos que as pessoas conseguem manter

Conclusão final

A barreira humana não se trata de culpar as pessoas por fraudes e falhas de segurança.

Trata-se de reconhecer que as pessoas já fazem parte do sistema. A questão é se as preparamos bem ou se as deixamos descobrir sozinhas quando a fraude já está diante delas.

Em uma era de IA, essa preparação é ainda mais importante. Criminosos podem tornar a fraude mais discreta, parecer mais convincente e agir mais rápido do que antes. Por isso, os funcionários precisam de mais do que um simples treinamento de cibersegurança para cumprir tabela.

Eles precisam de uma formação prática sobre fraudes. Eles precisam de contexto. Eles precisam de uma forma de relatar o que parece errado. Eles precisam entender por que a confiança está sendo atacada em primeiro lugar.

O melhor firewall humano não é construído com base no medo.

Ela é construída com base na consciência, na valorização e na capacidade de pausar antes que a confiança se torne uma vulnerabilidade.

Conecte-se com Robert Siciliano CSP, CSI, CITRMS | LinkedIn

  • #1 autor mais vendido e palestrante em segurança cibernética
  • Arquiteto da Proteção CSI | O Firewall Humano Estratégico™
  • Especialista em Identidade Social Cibernética e Proteção Pessoal
  • 50 Melhores Palestrantes de Segurança Cibernética nos EUA

Conecte-se com Karisse Hendrick | LinkedIn

  • Apresentadora do podcast Fraudology
  • Especialista premiado em ciberfraude
  • Consultor de Prevenção de Fraudes em Comércio Eletrônico
  • Consultor de startups, palestrante principal e
  • Consultor para comerciantes da Fortune 500

Guests

Robert Siciliano
Analista de Segurança
Episode transcript
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
00:02
Welcome to Fraudology Podcast, where we dive into the science and study of online fraud from the perspective of an e-commerce fraud fighter. I'm Karisse Hendrick. Welcome back to Fraudology. Today I have a great guest. We just had a great conversation before I hit record, so I know that this conversation, now that I've hit record, is going to be great. My guest today is Robert Siciliano. He really explores why humans, not hackers, are the ultimate deciding factor in organizational security. Today we're going to dive into how you can build a culture that actually protects your people, your data, and your operations in an era of AI deception. And while, you know, a lot of you, most of you in this audience are in fraud prevention or, you know, security of some sort, and we have that mindset, we also recognize that not everybody does. And I think that it really needs to become our personal missions and the missions of our companies to make sure that we are talking about security in the right way. And Robert really does that. He is a security analyst. He's a best-selling author and the architect of the Strategic Human Firewall. As one of the world's most recognizable educators in personal and corporate protection, he has a straight-talk voice for a digital age. He's been on CNN, Fox News, CNBC, and Anderson Cooper 360, and you've probably read his insights in The Wall Street Journal, The New York Times, and Forbes. He's also served on the board of the Identity Theft Resource Center, which we know well about, and is a core contributor to the Realtor Safety Initiative. So this next point I just have to read because I think it's funny. He is a man who literally goes to the extremes to prove a point, once even buying a working ATM on Craigslist just to demonstrate how easy our secure systems can be cracked. So, Robert, welcome to Fraudology.
Robert Siciliano
01:50
Thank you so much. I actually deployed that ATM in downtown Boston. I put a car battery inside of it with a step-up transformer and an ATM skimmer on it with a small camera. And we deployed it in Faneuil Hall. And immediately people started using it. It didn't dispense any cash, but it recorded their, you know, credentials. And when we showed them what happened, you know, they freaked out a little bit. And of course, we let them delete the video. And in the process of doing this, a big burly Boston biker cop saw what we were up to and he got upset, threatened to arrest us. And so we had to kind of break it all down, and we just moved over to Fenway Park and did it all over again. And actually, when I bought that ATM, when I bought it off of a guy that owned a bar north of Boston...
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
02:34
I was going to ask you. Yeah. Who'd...
Robert Siciliano
02:36
You buy? Yeah, on Craigslist.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Henddrick
02:37
Right, right.
Robert Siciliano
02:38
We got it back to the office and, you know, busted out the manual, and I brought a good hacker friend of mine to buy it. And so he was all excited that we had the manual. We had an ATM. He took the manual home that night, called me 5:30 the next morning. He's like, "Hey man, I want to come over and check out this ATM." I'm like, "Dude, it's 5:30." Click. He was there in like 10 minutes and he plugged the ATM in. It started booting up and he starts punching a bunch of codes into the keypad as he's, you know, got one manual in one hand and punching, you know, codes in the keypad. And it started to spit out the receipt. But the receipt was like, not like, you know, five or six inches in the off. It was like a 30-foot receipt.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:18
Whoa.
Robert Siciliano
03:19
And he starts laughing. He goes, "Look at this, look at this." And I pick up the receipt. It had over like 1,000 credit and debit card numbers on the receipt. So what he did was he cleared the ATM's logs of all the recent transactions, and they printed out in real time. So I bought a data breach. Yeah.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:38
: Yeah. Was it the full 16 digits or was it?
Robert Siciliano
03:40
: Yeah, it was everything.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
03:41
Oh, wow. It was everything.
Robert Siciliano
03:42
Yeah, yeah, yeah. And I quickly learned that the ATM industry is relatively unregulated. You know, it's the same companies or people that, like, dispense cigarettes and candy bars and soda machines are also in the ATM business, you know? And yeah, I don't use independent ATM machines as a result.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:04
No, I don't either. I mean, I never bought one on Craigslist and tested it, but I do always go to the bank and use their ATM. And yeah, of course, I trust that a lot more. And I trust that they are regularly looking at it for skimmers too, because a guy at a gas station isn't going to know what to look for.
Robert Siciliano
04:19
Generally, yes.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
04:20
Yeah, generally. Right. I mean, there's always an exception. But yeah, it's funny. I don't always think about all the little things that I do every day, you know, habits and things like that, that just come naturally to me now because I've been in this industry so long and I know what could happen. But like, another thing I do regularly that my husband just rolls his eyes at is, you know, we order quite a bit of things from online. I mean, I think everybody does. And I always take the stickers off of my boxes before recycling them because I don't want my name and address out there, right?
Robert Siciliano
04:50
I am obsessed with shredding. I destroy everything. Nothing that possesses any sensitive information at all, including prescription bottles, goes in the trash or recycles. I destroy everything. And not only that, like when I am speaking at a conference and I get a handful of business cards at the end, I destroy the business cards too. I don't want a criminal pulling business cards out of my trash and then posing as me, communicating with my audience members. Now, is that ever going to happen? Probably not. But that's the way that I think. And that to me is managing risk.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
05:24
Right. I couldn't agree more. So let's start from the very beginning. I always like to ask people how they got to where they are now because I think we've all had, you know, they're not linear journeys. How did you get started in security and how did you decide to become an educator?
Robert Siciliano
05:41
So when I get off the platform after, you know, an event, 100% of the time people ask me, "So how did you get into this? Like, what are you, like, former CIA, Secret Service, FBI? Like, are you law enforcement, military? Like, how do you know all this stuff?" And I'm like, "Yeah, you know, I literally, like, I'm from the streets of Boston, man. Like, that's literally where I learned everything." So I grew up in Boston and I've seen all kinds of stuff, all right? And I've taken an interest since a young age as a result. And so for me, it truly started. And I I've been doing what I do professionally for about 30 years, and I'm 57. But I really have been doing it since I was like a teenager, you know? And so that's really about 40 years. And it really, really started when I was like 12 years old. And my dad let us go into downtown Boston. You know, we got in the train, me and my little brother. He was eight, I was 12. And you could do those things back then. We had a really long leash. And we got off the train, and there's five kids waiting on the street for us. And they beat us up and they took our money. I was not prepared for that at all. So I go home and my dad explained to me, "Oh, those boys today, they were the wolves, and you and your brother, you were the rabbits. They are the predators and you are the prey." And I was like, "All right," you know, I didn't exactly understand what he was saying, but I kind of got it. And then about a year later, I was at summer camp, like many kids do. And I met a girl, you know, I was 13, she was 13, and we liked each other. It was kind of like my first crush and we were holding hands on the bus and everything. And we get off at her bus stop one day at the end of camp, and we're sitting on her front stairs and she's looking at me kind of all solemn. And she says to me, "I think you should know that my mother's boyfriend assaulted me." Now I knew what she was saying was bad, but I didn't really understand what she meant. So I go home and I asked my dad, "Dad, what's sex and what is rape?" Because I really didn't know what she was talking about. Mind you, I'm 57, so this is like 40 something years ago. Kids, we didn't know about sex like that just wasn't. Karisse Hendrick: Not, no. Robert Siciliano: We really didn't have that dialogue.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
07:43
We didn't have the Internet. Our parents didn't talk to us about it. Yeah, there might have been.
Robert Siciliano
07:47
We didn't even have porn, like we had none of that stuff, you know. And so now I've been involved in a multiple-attack situation. I meet a young girl who's been a victim of sexual assault. My radar is up at this point and I want to understand why everybody isn't as nice as mummy and daddy. And so I began to read up on it. I began to study it, and I gravitated towards professions revolving around personal protection as it relates to violence prevention and theft prevention. And so by my late teens, early 20s, I was teaching real estate agents personal protection because when I bought my first house, I was 19 and I bought my first multifamily, and I'm working with the real estate agent. And, you know, she's like, "So what do you do?" I'm like, "Well, I teach women self-defense." She's like, "Oh, we need that." I'm like, "Yeah, women need that." She's like, "Well, Realtors need that."
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
08:36
Oh, yeah.
Robert Siciliano
08:37
I didn't really truly understand what she was talking about until I did because we went into a particular house, which there was a bunch of people squatting in it and it was like really concerning. And so I put together a program for her in her office right after that. And so now I'm like teaching Realtor safety and security as a profession in my mid-20s, and I bought my first computer to manage my business. That computer was an IBM PS/1 Consultant, which is the make and model of a device that had a Windows 3.0 operating system with 150 megabyte hard drive. And I had to buy a card to install so I could have dial-up connection to AOL. So I was selling books and I was selling like all kinds of stuff to the agents, and I needed to accept credit cards. So I set up a point of sale in my computer software so I could accept credit cards and use AOL as the dial-up. And about a month after I did that, I got hacked in 1995.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
09:37
Oh, wow.
Robert Siciliano
09:38
Yeah, I lost thousands of dollars. I was devastated because, you know, like, I'm seeing all these charges and I'm seeing like all this loss and like, what happened? I called the bank. I called the credit card company, and they explained to me, "Yeah, like this is credit card fraud. Like you are a victim of this, but you have to pay. Like that's how it works." And I did. And I lost. And so as upset as I was, you know, I had already been in the business of personal security and personal protection again, violence and theft prevention. And so when that happened to me, like I've always reverse engineered the bad actor's process so I could explain that to my audience. So I could explain like, this is what they do, this is how they do it, and this is how you protect yourself from it, right? And so as upset as I was, I was like amazed. I was awestruck. You know, what they did was awful, but it was kind of awesome. You know, like if they could do it to me, they could do it to anybody. So I started to focus on it and I started to pay attention to it. And I started to teach the agents about, you know, this is a real thing. And as time went on, by the mid-90s, mid to late 90s, identity theft, like Social Security numbers being in the wrong hands, started to become a real problem because municipalities started to post all of their information online, not knowing the value of the Social Security number. And before you knew it, identity theft was a real problem. And so I started to meet victims of that too. And so now I'm speaking about data breaches and credit card fraud and pure identity theft before a credit freeze was even a consideration, okay. And so now here we are like late 90s, early 2000s and 9/11 hit. And when 9/11 hit, what I had been doing for probably the past six or seven, eight years began to mean something and matter to pretty much everybody. And so I went full time around like October 2001, right after 9/11. And I've been doing it ever since, you know. And back then I started to see data breaches of like, you know, 300,000 records compromised at a university in Southern California make national news. 300,000 records is like, you know... Karisse Hendrick: Nothing now. Robert Siciliano: But it made national news and I was the guy they'd call to say, "Okay, what is this? How does it happen? Like what does it mean?" Like I literally just got off the phone with a news channel in Orlando before I got on this podcast to discuss a data breach. A company called Instructure, I think they're called, that handles like all the schools' e-learning. 270 million records, I think, were compromised. 8,000, 9,000 schools, like just happened like this week, you know. So I'm still the guy they call when that stuff happens. And what has happened in the past 30, 40 years is that fraud is now eclipsed like the illicit drug trade, like hacking, cybercrime has eclipsed the illicit drug trade. We're at about 300 billion records in the hands of criminals. About 20 billion of those are passwords. Fraud, cybercrime is a true business at this point and treated as such. Whereas consumers, our coworkers, our employees, our neighbors, I don't know that they've changed at all. I don't think that they're doing anything different today than they did 30 years ago. I think they still completely resist security. They don't effectively manage passwords. They could care less about two-factor authentication. They don't lock the doors to their homes. They don't have home security systems. Security, as far as they're concerned, it can't or won't happen to me. Why would I install a password manager if it can be hacked, and so on. So that's today what I talk about and how to overcome all of this resistance to security.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
13:30
So when you go into companies or, you know, other gatherings of people to talk about security, what's your approach? Because I know it's very unique compared to other security, you know, typical security educators.
Robert Siciliano
13:47
So most security training today is, you know, do this, don't do that, or else. Most security training is check-the-box compliance, you know, phishing simulation training that, you know, is designed to provide a certain amount of metrics. And if those metrics, you know, pan out well, then, you know, that employee doesn't get fired or reprimanded and such. Okay, but I've been getting calls since post-COVID. "We just want our people to care about security. Our phishing simulation training is essentially plateaued. It's peaked. And we just need to get them to care. We need them to effectively recognize risk. How do you do that?" Well, you know, when I'm hired and I walk onto the platform because the company hires me and I'm introduced and I'm looking out at the audience at like, you know, 100 people, 500 people, it's the funniest thing to me because it's like clockwork. I look out in the audience and if they're not looking at their phone because they could kill us, they're looking at me with a scowl on their face and their arms are crossed, right? And they're like, "Okay, security guy, tell me something I don't already know. I got to get back to work. I don't want to be here. I don't need to be here. I understand how this stuff works. Just get this over with." And so I begin a dialogue with them, and that's the operative word, dialogue, because most security awareness training is a monologue, which is ineffective with a topic that involves sociopaths and psychopaths, you know, murderers and hackers that mean to do harm. There's worry. There's fear. There's like real emotional concern here. And we're trying to fix that with a talking head animated monologue, which doesn't work. And so I begin to ask them questions to kind of like get them to understand what risk actually is to them, and at the same time see the flaws and the vulnerabilities in, you know, their own information. But more importantly; so that they can, I can challenge their belief systems as to what security is versus what they think it is. Okay. And so I begin that by saying like basic questions like, so how many of you actually honestly use a different passcode across multiple accounts? If I get 10% of the room to raise their hand, that's a lot, right? How many of you use two-factor authentication across all your critical, including both personal and professional email? Like including personal email, right. If I get 15% of the room to raise their hand, that's a lot. Okay. And I explain to them, well, did you know that there's like 15 to 20 billion of your passwords on the dark web? And I take them on the dark web and I show them raw data and they're like, "Whoa, like, like that's, I didn't know that." Like they don't know that, you know. And so as you walk them through, I take them to Russian hacking forums and show them Social Security numbers of Obama and Trump and Biden, you know, in, in like people that they know, Ashton Kutcher. They're like, "Whoa, like this is, this is, I didn't know that this was real." Like they think it's just like in movies. They don't know that it's actually happening. And so as I dissect it and show them they're like, "Okay, okay, okay." And so what happens is all these questions are designed to get them to care about security. And so once they see the vulnerability with the passcodes, they're like, "Okay, so how do we fix that?" We start talking about password managers and they're like, "Whoa, well, what if the password manager gets hacked?" So now they're already showing resistance. So I've got to break them down and show them how like, look, these password managers are owned by companies who are security companies. They have bank level, military grade encryption. And I just show them how it works and how it saves time, how it fills out forms. It's making their lives easier. Like, "Whoa, this is great. Who knew?" Because nobody's telling them about that stuff, which is so ridiculous to me. And so in this line of questioning, I ask them like, "Okay, so how many of you lock your doors?" Because, you know, we're talking about personal security here. Like this is personal security depending on whether it's, you know, rural or suburban or urban depends on how many hands go up. And you would be amazed at how many people don't lock their doors. Okay, wow. And the next question is, "How many of you have a home security system?" And all of these questions are designed to get them to see themselves and what their risk quotient is. Okay. So when I ask a question about home security systems, this is the clincher, because if I get 15% of the room to raise their hand, that's a lot, which means 85% of the room doesn't have a home security system no matter where I am in the country, okay? And then I ask them, "Okay, so why don't you have a home security system? I mean, you've seen the commercials, you read the police blotter, it happens, you know." And so when I ask them and, you know, the majority of them don't, I go, "So why don't you?" Hands start to go up. "Well, we don't have a home security system because we have insurance." Okay. I mean, what good is that at 3:00 a.m. when an intruder breaks into your house and you're in bed, you know, not well thought out. And most people aren't that well thought out when it comes to this. And then the next answer is, "Well, we don't have a home security system because my husband says if they're going to break in, they're going to break in. There's really not much we can do to prevent it," which is fatalism. And people use fatalism to justify why they don't engage in security all the time. And when I hear that, I say, "Yeah, well, I would divorce that guy, frankly," okay. Because I mean, you know, I got two daughters, I got a honey, and my house is locked down at 3:00 a.m. to reduce risk. I'm not going to be like, "Yeah, what are you going to do?" Can you imagine? Like I would never. Okay. But the most common answer that I get, and this is like really where it all begins, which is really when it takes hold, is because they, I asked them like, "You don't have a home security system because of insurance, because, you know, fatalism?" They say, "I don't have a home security system because I don't want to live like that." I say, "What does that actually mean?" And they say, "Well, I don't want to have to worry. I don't want to live in fear. I don't want to always be looking over my shoulder," as if installing a home security system is going to make you worry. And they say, "Well, I, I, I just want to trust people. I, I don't want to have to think about those things." So what they're really truly saying is, I would rather live in denial. And that is a lot of people. And so as I say to them, "Okay, so I get all that. Well, did you know that in the U. S. every year like one to two million homes are burglarized every year, and that like in the next 10 years that means like 10 to 20 million homes will be burglarized? Now, I'm not telling you this to like create fear or worry. I'm telling you this because this is just the way it is."
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:22
The fact. Yeah.
Robert Siciliano
20:23
And then I say, "Okay, so with all of this logic that y'all are, you know, directing at me, I'm a guy that has like 20-plus security cameras," which is true. "And so if I've got 20-plus security cameras, what might you think about me, my disposition, my worldview? I wake up every day. I must be what?"
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:39
Paranoid.
Robert Siciliano
20:40
That's what they say.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
20:41
That would be my guess, yeah. Robert Siciliano 20:43): Yeah. And I say, "Well, did you know that like paranoia is in fact like a mental health disease? Like that's what that is." And so people who are effectively paranoid, they live in high alert, they live in red alert because their mind is tricking them and they truly do believe that others are out to get them. And that is a mental health issue. That's not what security is. Security is putting systems in place to manage and reduce risk. Security is putting your seat belt on because it's the smart thing to do. But when we as a culture, when we view security as worry and fear, effectively paranoia, that dichotomy prevents us from engaging in the process of managing risk. And that's where most of us are. Most of us, I'd say 80 to 90% of the population, that's where they're at. And if we think we're going to solve that with phishing simulation training, we haven't and we won't.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
21:42
One new feature that's already recently introduced to their product suite is called the Anomaly to Rule product. You know, you had mentioned to me when we were first talking that, you know, consumers don't actually want security. It goes against their core beliefs. And I thought that that was interesting to me. Like I hadn't ever thought of it that way. But as you explained it, it made sense because, so can you share a little bit about why consumers don't want security? I mean, I guess I've always thought just they just don't know any better; but they don't. It goes against their core beliefs. How?
Robert Siciliano
23:12
Okay, so I've been doing what I do now, like I said, for like 40 years, okay. And the conclusion that I've come to is that you and I, all of us, we possess what I call the human blind spot, okay? And so the human blind spot is our want, our need, our psychological, our biological instinct to trust each other, okay. And so we are born trusting as an interdependent species. We are dependent upon each other for our survival. Man needs woman, woman needs man to procreate. And the basis of that is we need to trust each other, okay? And so not trusting others goes against that core belief. Not trusting others, I think, is a learned behavior. So we've learned to not trust others as we grow, as we navigate the world, often when we're relatively young. So for example, you're playing with Johnny on a play date at the age of six or seven, or maybe even like, younger, four or five, and Johnny bites you because kids bite. And you learn through physical pain that Johnny is not to be trusted. Okay. And so you learn through physical harm, through betrayal, through people hurting you in a number of different ways, that not everybody is to be trusted. But we don't necessarily take those lessons and apply them effectively when it comes to managing risk. We take the hurt, we take the pain, we take the betrayal and we kind of like, wish and want for that never to happen to us again. And we kind of engage in a certain level of denial, like it can't happen to me or it won't happen to me, or we use fatalism to justify that denial. And we basically do nothing about it. We don't put any of those real lessons to work for us. And as a result, we go through life not truly understanding and recognizing risk or what security truly is, and just continue to just engage in the human blind spot. And what that means is every time the phone rings, every time an email comes in, every time we get a text message or a pop-up for that matter, we want to and need to by default trust the person on the other end. And ultimately, I consider this like a cognitive gap where biological trust overrides suspicion in essentially leaving the door wide open for all kinds of social engineering, fraud manipulation, AI-enhanced deception, manufactured urgency. And so think of it like as this biological default to trust and our psychological shortcuts or the heuristics that criminals use to bypass human logic and to bypass our emotions. Again, like biological impulse versus intellectual understanding. It's that internal conflict between our evolved survival instincts and our modern knowledge or lack of knowledge of digital risk. And so I'm 30, 40 years into this type of education training, and I don't see that, like, we as a culture, we as a species are any different today than we were 40 years ago. Why? Because of the human blind spot. And nobody, nobody is speaking to that with that vernacular that I'm aware of other than me. And until we change the vernacular from do this, don't do that, or else, yeah, these are the consequences with no empathy, no sympathy, right? No understanding of the fears and the worries that humans have regarding that, those predators and thieves, the sociopaths and psychopaths, until we actually address the human where they're at, I don't know that we're ever going to change the conversation. But starting with leadership, those who are paying attention here today, that's where we begin. Karisse Hendrick(00:27:10): Yeah, well, yeah. And you know, I was mentioning before we were recording that, you know, so many of the largest breaches recently haven't been through hackers, you know, traditional hacking like they were 10, 15 years ago. They've been through social engineering. They've been through, you know, phone conversations or emails, you know, spear phishing emails to customer service agents or, you know, help desk or IT help desk or whatever it is to gain access to the keys of the kingdom to inside the company's, you know, systems. And then that's where they're getting their customer data and all of their PII. And it reminded me of the really big breach of all the casinos or a large portion of the casinos in Vegas that really shut them down for like a week where people couldn't even open their hotel doors because they were under ransomware. And they shut down every single computer because of ransomware. And nobody could gamble. Nobody could see a show, nobody could, I mean, nobody could eat dinner. Like it was crazy because everything ran on their computers. And when they did an analysis on, you know, where the point of compromise was, it was all through a customer service, you know, person who thought that they were giving access to someone in the company that was working from home that day. And they weren't. They were giving access to bad guys that were, you know, going in, getting all the documentation and all of the, you know, getting access to all of the systems and then locking them down until they got a ransom. And that could have been prevented by good security awareness training where it wasn't just a check-the-box exercise. And it wasn't just, you know, do this, do that. It was, hey, let's break it down. Like you need to actually be thinking about what are the motivations of the person on the other end of the phone call, right? Are they, should I trust them? You know, my trust is a currency and it should be valued. And, you know, does it make sense to give them that trust?
Robert Siciliano
29:04
I've seen that as much as 75%, if not more, of breaches are as a result of human error. And we say error, right. But I, I think a lot of it is being tricked, manipulation. Karisse Hendrick: Manipulation. Robert Siciliano: And when, look, I work with victims all the time and 100% of the time when someone's victimized for whatever reason, they always say, "How could I be so stupid?" And here's my response to that. I don't think a single person who is hoodwinked, let's say, is stupid. I don't think that any of these people are stupid. I think they're just human. I think that they have a human blind spot that no one's ever explained to them. They trust by default. And the bad actors understand the art of manipulation. It's as simple as that. I don't think they're stupid. I just think they're human and they haven't been properly educated because we've been engaged in what, cybersecurity for maybe 25, 30 years, if that. It's a brand new thing in our culture, in humanity for that matter. And we've addressed it by engaging in phishing simulation training. When I was doing this in the early 2010 to 2015, PhishMe contacted me and Rohyt Belani, I think his name was. And, you know, "Hey, this is my new product." It was like a brand new technology, a brand new way of training. And I was like, this is great, you know, and I started to see it being implemented left and right. And, you know, before really isn't that old. And they've only been around for like, I think less than 10 years, you know, not that long, more or less, you know? And Kevin Mitnick was like, they're basically like their spokesperson, so to speak.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
30:46
Oh yeah, he used to speak at the conferences I attended.
Robert Siciliano
30:50
It's a relatively new technology, but I think it's a compliance trap is what it truly is. I don't think it necessarily moves the needle where it needs to go to actually solve the problem of human hacking. Okay, it solves to a degree, the issue of phishing to a degree, but I don't know that it necessarily solves the problem. I think it's necessary, but that security fatigue that I think we're experiencing now is caused by that compliance trap. It's bombarding employees with complex, impersonal rules that ultimately truly trigger security aversion. And that compliance trap is truly a false sense of security felt by meeting regulatory requirements while the actual human behavior remains unchanged and vulnerable.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
31:38
Okay. That's the way I feel about PCI compliance with credit card handling is just, it's just a check-the-box thing, right? It's not actually stopping fraud from happening. It's not actually stopping hacking from happening. It's a way to, you know, push it to somewhere else, right? Like when you squeeze a balloon, the air doesn't go away. It just moves to another place. And, you know, if you are doing the compliance piece, you know, sure, the things that you are learning for, if you are following them and if you want to follow them and you've understood why, then sure, you know, they could be effective. But then all that happens is the criminals adapt and they start calling, you know, they start reaching out with different types of attacks, right. They start contacting with different types of attacks. I'll never forget, and I've shared this example on the podcast before, but when my grandmother was still alive, yeah, I did my best to educate her on, you know, giving out her Social Security number and, you know, giving out her credit card number and that type of thing over the phone. And I would say, you know, grandma, the Social Security, or no, it wasn't Social Security. It was the IRS will never call and ask for your Social Security number. They'll never call and ask for your credit card. You know, don't ever give them those things if they ever ask for it. Well, she embarrassingly called me, you know, months later and said, "I think I gave out my Social Security number, and I think it, it was wrong." And I was like, "Okay, well, what happened?" "Well, you told me about the IRS, but you never told me that Social Security Administration wouldn't reach out and ask for my Social Security number." And I kind of did like a facepalm. And after that I started, you know, recommending to people instead of saying these guys won't call you or, you know, these guys won't call you or do this and this, instead, I brought it down to best practices. And it sounds like that's what you do too. Right? Password managers, freezing credit, you know, the type of things that way we're not saying, hey, they'll never do this because the moment we educate on that, like the Nigerian prince scam, as soon as everyone understood that that was a scam, they stopped doing it. And they started, they're doing other scams now. Those Yahoo Boys in Nigeria are doing the sextortion scams to young adult men that are, you know, turning to suicide because they're so scared that they're going to, you know, get outed with these pictures that they sent, you know. So it's awful. So I mean, I think, I guess I'm just reiterating what you're saying is that if it's just a check-the-box exercise, all you're doing is making the criminals shift their tactics, right? They're not going to go away. It's not going to stop fraud. It's not going to stop security. Yeah.
Robert Siciliano
34:12
We have to change the human's understanding of risk and what security is truly versus what it isn't, right? Which, you know, paranoia and such in phishing simulation training still is necessary. It's designed to fix the problem of phishing. But what it fails to do is address the human where they're at. And it fundamentally doesn't make the employee care. It doesn't make the employee care. They don't care. Okay.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
34:36
If they don't care, they're willing to do workarounds. They're willing to, you know, just bypass it, right? Like, oh, I'm asked to redo my password every three months. I'm just going to do it to the one that was before. I'm just going to add a one or I'm just going to add, you know, they're not going to care if they don't understand the why.
Robert Siciliano
34:53
And they're annoyed by it. And what happens as a result is we engage in, when something bad happens, we engage in blaming the victim and in some cases even shaming the victim, right. And that leads to what I call the silent failure, essentially a compromise of that human's brain, their wetware versus their software, that triggers no technical alarms and often goes unreported due to the shame barrier. And the shame barrier is that emotional wall that prevents victims from reporting a breach. And we can break that by treating mistakes as data, not causes for termination. But we can't do any of that until we actually address the human where they're at. And there's a way to go about that that involves a dialogue versus a monologue. It involves engaging in a level of empathy, which we don't really do that in a corporate environment like we could or should, especially with security training. And if we treat all security as personal, the core belief that people protect what they love. For example, teaching someone to secure their child's digital footprint, protect their own identity, their own Social Security number, their own credit card numbers, manage their own passwords. Like we are a selfish, self-interested creature that, you know, we need to care for ourselves first for a reason, right? When we get on a plane and the flight attendant is providing safety instructions and she talks or he talks about the oxygen mask, what did they say to do with the oxygen mask first?
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
36:25
I immediately thought of this before you even started to say it. They say to put the mask on first before you help your child or anyone else.
Robert Siciliano
36:32
Yeah, because you are ineffective unless you take care of yourself first. You and I need a good night's rest. We need to nourish our bodies with foods and fluids in order to be functional, to take care of our loved ones, to take care of our clients or employees and such, do our jobs effectively. We need self-care and we need self-care when it comes to security. We need to take care of our own security first before we care about the corporate bottom line. Okay. And that is only accomplished with a dialogue challenging belief systems when it comes to what security is versus what it isn't. Okay. And so the idea behind all of this is we prepare that human not just on how to recognize a phishing email, but truly how to recognize risk in every aspect of their lives. You know, they're walking down the street looking to the left, looking to the right and what's going on behind them. Know what situational awareness truly is in the physical world leads to understanding situational awareness every time the phone rings, every time you get a text message, every time you get an email, every time there's a pop-up. What is the motivation of this person who potentially is paying unwanted attention to me? Yes. What are they trying to accomplish by getting me to call the phone number in the body of the email, click the link in the text message, react and respond to the phone call and so on? And by creating this aware human, what we are doing is we're turning them into what I call, and this is the methodology that I've developed over the past 30, 40 years, we all know what a firewall is, right? A traditional firewall filters traffic. Human firewalls filter intent. So I've developed what I call the Strategic Human Firewall. So a Strategic Human Firewall, like you and I, are already a Strategic Human Firewall. We want everybody to think like we do.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
38:36
Which is a good thing in this case, yeah. When it comes to this, yes.
Robert Siciliano
38:40
When it comes to managing risk, okay, we want everybody to think like we do. Okay, so a Strategic Human Firewall blocks deception, all right? It's a proactive governance. It's a mindset that turns humans, consumers, employees from passive targets into active detection layers. Okay? A passive target is, you know, someone who doesn't recognize their own human blind spot. They trust by default. They give the benefit of the doubt. They don't want to think or believe it can happen to them. They look at security as being worry and fear and paranoia versus active detection layers. See risk for what it actually is. And the goal of this is a shift from I trust what I see by default to I verify everything. Okay. And so what that means is they go from basic security awareness to what I call security appreciation. Now the shift from awareness, which is knowing, to appreciation, is caring. Okay? And so when an employee appreciates how security protects their own lives first, that's when behavior begins to change. Okay. I call this the security appreciation gap. It's basically like this chasm between an employee's intellectual understanding of risk, which is awareness, and the emotional commitment to act on that knowledge, which is truly appreciation. And what this ultimately accomplishes is what I call the kitchen table effect. And the kitchen table effect is the multiplier effect where successful security appreciation training ends with the employee teaching the concepts to their family at home around the kitchen table, cementing those lessons for life. Try that with regulatory compliance check-the-box phishing simulation training.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
40:39
Right, but when you explain like, hey, when you use the same password for multiple things, somebody could use your credit card and, you know, make purchases on it, or someone could log into your air miles account and drain all of your air miles and you can't go on that vacation. Or, you know, these are the things that actually could happen if you don't do X, Y, Z. I think that that has a different impact on people than just this is what you should do, you know?
Robert Siciliano
41:04
Look, I'm a dad, right? And, you know, one of my girls comes home and she's got a problem. Like she's on the verge of tears, whatever it might be. And honestly, like there isn't a week that goes by that somebody in my house isn't crying.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
41:17
I mean, you have teenagers. I understand. I have a teenage girl as well.
Robert Siciliano
41:21
Yeah, it could be me crying for that now, you know. So my daughter comes home and she's, she's just about in tears. My job at that point is to stop what I'm doing, is to recognize her for where she's at, right? And it's to gently and gingerly get her to start talking and to find out like, what is it that is, you know, harming, hurting or just bothering her, right. And so from that point on, empathetically, my reaction is to deliver a caring and concerning response that generally is from my life experience, how to react and respond going forward, providing perspective so that she can take my life experience and apply it to her limited life experience in such a way that she can, I can help her cut the learning curve. So now going forward, she has an understanding of what to do as a result, okay. And in that process, providing a certain level of perspective that gets her whole again. Right now, I'm not asking your CISOs, your security awareness managers to start, you know, hugging and holding your employees by the hand. I'm not asking you to do that. What I am asking you to do is engage in a bit more empathy, a bit more understanding that your employees truly don't know what to do. They truly don't understand this stuff. They truly don't know that the email they keep getting that they keep clicking isn't Amazon, right. And our frustration with them is truly only because those who possess the Strategic Human Firewall, we haven't taken the time to educate, inform the way we really could or should. And I don't know that like many people in that position ever had the understanding of what to do and how to do it because we've all been fed, or they've been fed, phishing simulation training and a manual that doesn't really truly understand the human where they're at. And I don't know that like many people, unless they've come from, say, my experience of being in a multiple-attack situation at a very young age, recognizing victims of sexual assault, you know, being with the real estate agents that are actually murdered, right, and are actually experiencing true risk. Can you effectively communicate cybersecurity training with that level of empathy? I do it innately based on my experience. It's entirely and totally possible to be accomplished if you haven't lived a life that I have. It's entirely possible. It's just a matter of reframing what the dialogue can and should be.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
44:13
I think that's a great challenge for people listening because, you know, a lot of us are, you know, human firewalls and Strategic Human Firewalls ourselves. But I have heard in conversation with other people, especially with the rise of pig butchering over the last few years and the transnational organized crime and, you know, the human trafficking attached to it and just how they're stealing a generation's worth of wealth and how Cambodia's GDP, 50% of Cambodia's GDP is now because of scams. You know, all of these facts. I've heard more of a desire of fraud fighters to want to start to, you know, share a PowerPoint at a community center or at a, you know, their church elderly group or whatever it is. And I think, I don't know if you know Erin West, I don't know if you're familiar with her, but she's really, she's a former prosecutor, that U. S. attorney that has done a lot of research and actually gone to some of these, you know, compounds in Cambodia and seen, you know, what they look like and what they're doing and their tactics and all that. And she's very big on educating and disrupting, you know, this because she spoke to victims for years when she was a district attorney and tried to, you know, help them get their money back through the crypto system and worked with Secret Service to do that if she could. And I think that that's a really good challenge for those of us that are here, that do think like that, right? That do look, you know, behind her. So there are just inherently not skeptical, but not, not cynical, but skeptical, right? Like that. We're not, it's not that we don't trust everyone. It's just that we're always asking what's their motivation? What's the motivation in this email? What's the motivation in this phone call? What's the motivation in this text message? What's the motivation, you know, for this person that showed up at my doorstep that wants to sell something? I think that's really the key. And you mentioned that for those of us that think like that, I think that the greatest gift we could give to people that are in our lives is to also train them to think like that. Not to be paranoid, not to be, you know, over the shoulder and everything else, but just, hey, what's the intent? What's the motivation behind all of these things? And you'll protect yourself more.
Robert Siciliano
46:19
So I am the guy that they call, I speak to wealth managers' clients all the time. So you're a financial service professional, you know, your JP Morgan Chases and Fidelitys, and I'm the guy that goes in and speaks to the clients of the wealth manager because the clients are targeted all day, every day. You know, we know that there is $124 trillion transfer of wealth that's occurring right now. The greatest transfer of wealth in human history between the baby boomers and their children and grandchildren, Gen X, Gen Y, Gen Z, and millennials and such. So my dad, 78 years old, worked for 40 something years, compounded interest, paid off his mortgage, has wealth that likely will go to me and my siblings when he passes eventually, right? That money is the target of organized crime. And so when the wealth managers call me, it's because their clients are being bombarded, often victimized. And so now I go and I speak in front of an audience of people who have lost thousands. And at the end of the presentation, they come up to me and they are broken. Some of them, you know, they've lost all of their wealth in their late 60s, mid 70s.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
47:32
Retirement funds, college funds, yeah.
Robert Siciliano
47:36
They're literally broken. And like, I've hugged and cried with these people and it is preventable, but we're not engaged in the process of actually preventing it because we're not engaged in a dialogue like we should. And until we do, it's going to keep getting worse and it's not going to get any better because the human blind spot and the loneliness loophole continues to be used to exploit and the criminal enterprises have figured that out. And unless we, the fraud fighters, actually do something about it, it's going to keep getting worse. But we have a chance to fix it. We do right now, but we don't have a lot of time.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
48:25
No, I appreciate your optimism. I mean, but that optimism comes with, you know, empathy for the people that have all have lost it and also a realistic, you know, perspective of what we're behind. There's more of them than there are of us and their, you know, resources are endless and they're, you know, multiplying it by AI and it's just, you know, but at the same time, we're not helpless, right? We're not hopeless. We can, we can, you know, do what we can to share with the people in our lives. And, you know, even if that means going outside of our bubble to say, hey, you are a target. Like, it used to always bother me when I would tell friends, you know, hey, if you use this free app, all of your information is being used, right? Like, hey, did you know that Fitbit app, when the Fitbit was a big deal, like you're right, you're typing in everything you're eating. You have geolocation on where you're taking your evening walk. All of that information is being sold because you're not paying for that app. They're selling your data. And I remember a lot of my, most of my friends would reply with, I don't care. Like, why should I care if they have my data or not? Like, what are they going to do with it? Well, they're going to do a lot, right? They're going to, you know, impersonate your gym. They're going to, you know, call you up and say, "Hey, I know that you walk around this park every day. You know, I, they happen to, you know, be your neighbor," or whatever it is. They're going to use that. Yeah. So, you know, educating friends and family on like, it's not just, oh, I don't care or what are they going to do with that? They can, they can know what websites I visit. They can know what my passwords are. I don't really care to actually just be thinking about the motivation there, right? Like there's always a reason for people doing something.
Robert Siciliano
50:07
Yeah. So let me leave you with this, right? So I started to tell you about like when I'm hired and I walk in the room and there's like a whole audience of people that, like, have their arms crossed and with the scowl on their face. And as I ask them all these various questions, I'm challenging their belief systems. What begins to happen is, and this, this should happen in everybody's training, what begins to happen is the arms begin to go down by their side. Like they literally, like the arms begin to like go from crossing across their chest to being put on their lap or down by their side. And it's kind of fun to watch because they literally like lean into the conversation, like their head begins to go forward, the scowl goes away and the eyes begin to open up a little bit wider. So you can, you can literally see them leaning into the conversation and through their facial expressions, the curiosity has now taken over. And as the arms go down by their side, the hands begin to go up, meaning now they have questions because now they want to know, right. And at the end of every single presentation that I do, I got a line of people coming up to me and they say, "Listen, I came here because my boss told me I had to come here. I didn't want to come here. I didn't think I needed to be here; but I'm so glad that I came because it's nothing like I thought it was going to be. This is really good. I wish my spouse was here because they would have loved it. Do you do programs for high schools?" Like that's how it should be. They should walk out of a security appreciation training enthusiastic. That's how it should be. And like they say, "Look, you know, you scared me a little bit; but in a good way. Like you motivated me to get a password manager. You motivated me to change up my passcode. I'm going to install two-factor authentication for everything and we're going to engage in the backup services." You talked about like all the basic things. Still, this very day, one of the most common questions I get in every training that I do, one of the most common questions is how do I protect my credit cards? And another one is how do I know what links are okay to click when I do a Google search? Like basic, basic, basic 101 digital literacy type questions that, like, and that just tells us like that people really, truly don't know. And so our job.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
52:09
No, we haven't been taught. The Internet has just, you know, grown and advanced and gotten bigger and faster and we've got more and more across the Internet, and, you know, all the other things, and we're doing banking online and we're doing all these things online and nobody's taught, you know, literacy, security literacy or, you know, security hygiene, as I sometimes call it.
Robert Siciliano
52:30
Fraud fighters should look at security awareness training, that it should evolve to security appreciation and that what we provide is digital literacy as it pertains to cybersecurity. And we truly, as the messengers, right, we need to walk the talk. So we need to be the message. We as the messengers, we need to be the message, we need to walk the talk. We personally and professionally need to do all the things that we expound upon. So that means I think self-defense classes, I think locking your doors, I think home security systems, I think password manager. I think that we need to do all the things that we talk about.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
53:16
Yeah, and I think at the end of the day, it doesn't make you more, when you know these things and when you think this way, it doesn't make you more worried that it's going to happen. It actually gives you security and a feeling of, you know, I feel protected, right? Because knowledge is power. So I really appreciate your time today. I really appreciate your perspective. And I think my listeners will too. I mean, either to help inspire them to talk more about security and security mindset and that type of thing with, you know, the people in their lives, or honestly to have you come in and talk to their people because they know that the check-the-box security training just doesn't work. So I will put a link to your LinkedIn and your website in the show notes for anyone to reach out to you that wants to. I really appreciate your time and all the hard work that you're doing. You know, this is the more you do, the less we have to do, right? So it all works. It's all within an ecosystem.
Robert Siciliano
54:12
I say connect with me on LinkedIn. If you could spell Siciliano, you can find me easy. I'm posting something on my, I've got like, you know, tens of thousands of people following my LinkedIn newsletter. Check me out there. I'm constantly providing, you know, great content to, you know, expand upon my methodology, my philosophy that anybody can consume and anybody can do. And then otherwise I'm at protectnowllc.com. Protectnowllc.com.
A smiling woman with short brown hair and glasses, wearing a black and white striped blazer.
Karisse Hendrick
54:38
Okay, perfect. Well, thank you so much. I really appreciate it. And everyone else, I will speak to you soon, next week.