Bridging Aerospace and Cybersecurity with Caitlin Sarian at Black Hat 2024
Caitlin Sarian, also known as “Cybersecurity Girl,” discusses her journey from aerospace engineering to cybersecurity consulting, and her decision to become a social media influencer to educate the public and encourage more women to enter STEM fields. She reflects on her experience at Black Hat 2024, emphasizing the importance of cybersecurity awareness and the evolving nature of the industry. The conversation also touches on the significance of critical infrastructure protection and the challenges of maintaining strong security practices in a rapidly changing environment.
Transcript
This is Textron tv. Hey, everyone. We're live here back in, uh, Las Vegas for Black Hat 2024.
You know, it's been a crazy first day of interviews in the expo hall. We've had amazing people coming up, talking about a whole bunch of everything. What, what really amazes me ki well, I'm gonna tell you what really amazes me in a second.
First, let me introduce you to my guest. I wanna introduce you to Caitlin Sarian. Yep.
Okay. I got it. Almost nailed it.
Okay. Caitlyn, some of you may know her as cybersecurity gal. Yeah, Cybersecurity girl.
Cybersecurity girl. Excuse me. I could be gal, but girl sounds not the head of Do Girl.
Sounds more official. Um, and Well, Caitlin, I did my part now you do your part. Yeah.
Do you know, tell us about yourself. Yeah, so I, I wasn't always a social media influencer. I ever thought I'd be a social media influencer.
But you Didn't go to school for that? We Did it. Uh, it wasn't a thing when I was growing up either.
No, we didn't have technology until I was in high school. Uh, just aged myself a little bit, but Uhhuh, um, I did cybersecurity consulting, so I actually did aerospace engineering before I even started cybersecurity. So you're rocket science?
Uh, Yeah. Rocket scientist somehow. I don't ever say that.
I don't think I'm we're, it's there. Um, but I was really interested, interested in tech consulting. And when I was going into looking at jobs, uh, I looked at EY and they said they were starting a cybersecurity practice.
I did not tell them that I did not like coding. Mm-Hmm. I was like, sure.
That sounds scary. And that was 11 more than 11 years ago. And I've just learned everything on the job.
So, um, one of the reasons why I started my social media channel is I kind of climbed the corporate ladder. It got to c everyone was kind of stuck at their house. And it really made me think about my life.
And I was like, what, what am I doing with my life? And I, I really felt like I wasn't giving back and I didn't really have like a, a full purpose. Um, I, I was helping a lot of companies, uh, uh, protect data, but I wasn't helping people.
And I ultimately always wanted to help people. And so I decided to start a social media channel. Never did I think that it was gonna go to this extent, but there were three reasons.
The first was to kind of educate the people on how to be safe online, just the general public. Yep. Um, but the main two reasons were to demystify what cybersecurity was to people, because no one really knows what, what it entails.
They don't just think that you're, you have to be a genius and you have to know how to hack and that's it. One or the other, and not Say, and I'm neither of those. I, so, um, that didn't happen.
And then the other one was really to get more women in excited about cyber and STEM fields. 'cause I, I, like I said, I was an aerospace engineer, so it is a no woman. Yeah.
I was gonna say also not a big woman in Yeah. Unfortunately. Yeah.
So I'm just excited to be here. You know, it's funny listening to you. So my wife's family, God bless that.
Yeah. I'm in cybersecurity 28 years, maybe 30. They still don't know what it is and what I do.
Right. All they know is, look, he does something with security, with computers. He makes a good living.
You know, he takes care of the family and The printer sometimes. Right. And, and that's, I am, I, I am the family.
Not only fix the printer, I can't log into Disney. Right. You know, we, we go through that with them.
Yeah. I am the it the free ITL, which is a whole nother story anyway, though. What's interesting is how is this your first black hat?
How long have you been coming? A black hat? This Is my second black hat because I didn't wear like corporate EY side.
So I always go to RSA. Sure. And again, I'm not like the coding hacker, hacker type.
And also as a consultant, you didn't really like buy a lot of products when you're Right. So blackout's not your Thing. So blackout wasn't my thing, but honestly I am, I was so excited I went last year and this year, um, I think the briefings are super cool.
Super cool. Do you think they're cool now? They were a lot cooler in the past.
Really? Oh yeah. I just, I think it's really cool to like sit in a room and know absolutely nothing.
And like almost every briefing I'm like, I don't, I'm in cyber. I've been it for what now? 11, 12 years.
And I'm like, I I, I couldn't even understand one sentence that came outta your mouth for a whole hour. But that's how cool cybersecurity is. 'cause there's so many different areas and people don't realize that you need like so many different types of brain cells and brain.
Well, it's analytics. Well, it's like medicine. You got specialties.
Right. Right. Exactly.
And, and that's, I Think it's more complex than medicine in my personal opinion. Well I, you know, I think with all the AI stuff out there, it's gonna be easier to have, to have to haveis. Right.
Almost replace doctors. Yeah. 'cause they'll be a lot better diagnosing stuff given the facts.
Um, cybersecurity, there's a lot of intuitiveness and, and personal to it. But, you know, I've been coming to Black Hat now since about 2003, 2004. Wow.
It used to be over in Caesar's. Okay. That's what I heard.
Yeah. And they didn't have a big expo hall with all the vendors. The whatever vendors were there.
It was in the hallway. You had like little 10 by 10 kind of stands. Right.
And there was briefing rooms back then though. It was really where like new, um, you know, new bugs and vulnerabilities and hacks were announced. Yeah.
So like one year there was a guy named Barnaby Jack. I don't know if you ever heard, he unfortunately passed away Barnaby Jaheim. But he was a great guy.
Brilliant hacker dude. White hat. Right.
Great White. He wheeled an ATM machine out onto the stage and hacked into it and had it spitting money out like it was making it rain money. See, that would've been an awesome, Oh, it's crazy.
Uh, there was all kinds of like crazy break breakouts. Right. You know, um, that they used to demonstrate live.
Right. And the other thing back then is, you know, it used to be sort, it wasn't one conference, but black hat def com were much more closely together. Aligned.
Aligned. Well then they still are, but they're not. Um, but it used to be the place where like the feds, the FBI, the NSA, the C-I-A-D-O-D, this is where they would come and mingle with the hackers.
Right. And so it made for an interesting dynamic. Yeah.
There was some interesting dynamic. We had the wall of sheep where they attack you and put you stuff Up. I've heard about that.
That's one of the reasons why I've actively avoided blackhead. 'cause I don't wanna be up there. No, it's happened, it happened to me in 2005.
Oh no. It was terrible. It was, it was my old fault.
But anyway, yes. Uh, but so black hat used to be a lot more interesting, quite frankly. I'm not surprised how comfortable you are here because this has become sort of RSA in the desert.
Yeah. Um, and it, I don't know if that's necessarily a bad thing. I Think RSA has also kind of taken some of black hats and black hats taken some Yeah.
Like they, they've kind of molded into Yeah. They verge be well because there's only, the audience wants very similar things to, right, right. Um, black Hat used to be much more AppSec only focused.
But now cybersecurity is so broad and, and it's, you know, and it's a little bit of everything. But that being said, it's still, it's a lot of fun. I mean, for those of us who've been in the industry a long time, it's it's coming it's summer camp.
Right. That's why everybody calls it summer camp for cyber Between, I dunno if you had a chance to get over to BSides. I, I Haven't yet.
So I think that was, I think it ended yesterday, right? Maybe. I went to the very first, uh, besides BSides here, it was bef that was the first BSides, uh, was at some little place off the strip here.
And I'll, I'll never forget, it was like, I was like this weird, there was like an un-conference before and conferences were a thing. And, but as a matter, that's how I got into DevOps really. Believe it or not.
I, I was the not for that first BSides, maybe the third or fourth BSides after that, or the fifth I was the, uh, sponsor wrangler for BSides. I was in charge of getting the, you know, helping get sponsors and all that. And um, after BSides, I went out to dinner with Gene Kim, who was the founder of Tripwire this before Gene became Gene.
And he told me about a book he was reading, writing. He showed me, you know, called he became known as the Phoenix Project. Right.
And that's what got me into DevOps. 'cause I was all about security. Um, anyway, so it's, it's a great show with a great history.
But I'm, you know, I'm jaded when I look at it. This is your second year share with our audience. What are they missing?
Not coming here? I mean, I, again, like, I think the briefings are really cool. And also, isn't it cool to think that like you went to the first BSides and now there's BSides all over the world.
Like there's a BSides in Armenia. Yes. There is.
Like, I'm Armenian so I know this, but it was like, so it's big to you that it's a big deal. Yeah. And then like, you know, there's a black hat in Saudi Arabia now.
There's like, it's it's kind of, There's been a thousand BSides Yeah. For the last however many years. It is.
Jack Daniel recently posted on his Facebook. Um, and there, you know, back when I was doing, like, I, I used to do besides RSA San Francisco, RSA APAC in Singapore. And there was an RSA usually in London we'd go to Black Hat is always in like Hong Kong or Shanghai.
Uh, This Singapore was it was there Singapore? It might have been a black hat APAC in Singapore. RSA was always in Singapore.
Yeah. Uh, but there probably was black hat there too. I mean, these are global brands now.
Right. And it talks to how big cybersecurity is as an industry. Right.
Um, like I, I will tell you for people who want to be in this industry, right. I, I think you do a great job of, of kind of showing people a, a peek inside if you will. It's an industry that A needs people.
B needs people of diversity desperately. Yeah. And, and c it's fun.
I mean, I, we, we co-sponsored a party last night down here at the, uh, where Was my invite? You didn't get it. 'cause the cybersecurity, cybersecurity marketing professionals were all invited.
I Gianna sent out a, an invite. Well, maybe I missed it. Well, we were only one of five co-sponsors at the pool.
Are you never made me Feel guilty? No. No.
I actually, we needed people to come. I was just talking about how I don't wanna go to any of the parties 'cause I'm just tired Meeting People. And So that's the thing you learn at Las Vegas.
At Las Vegas. Uh, what's conventions? No.
How many, I don't know if you, you don't have an Apple watch on, but I, I, I tracked my steps and I got my ordering and Yeah. Ordering. Do you check how many steps you put in a day Open?
I Haven I haven't looked yet, But, so I did about 15,000 yesterday, which for me is a lot of steps. Yeah. It's a lot of steps.
Um, I don't know. Today I've been in here mostly, so I haven't had a chance to live. But the night's still young.
But the other thing I will tell you about Black Hat this year and last year too, for that matter, it's 115 degrees hour, 112 degrees. It's a nice breezy day. I will never sponsor a pool party at Black Hat again.
I Why? Why did you do that? Why?
I don't know what I'm thinking. But we had a, we had a tent and it had like a mister Oh, okay. So every couple min, I felt like the broccoli at the supermarket produce cap thing, you know, and they make 'em wet.
Could Be the broccoli I'll carrot. Yeah, Exactly. But, um, yeah, never do that again.
You know, for our people. Again, people watching this from your perspective, we got the briefings, which are really cool. Yeah.
What about, have you had a chance to go on the expo floor? I mean, the expo floor is so fun and what a lot of people love, like when they first get here is all the free, the freebies that you get. Yeah.
But I just love seeing all the new startups, new technologies and like the new offerings that current companies are, are giving as well. So I, I kind of just pretend like I'm a nobody. I usually kind of like flip around my badge Yep.
And just like, walk around and just pretend like I know nothing. And just, honestly, I take it as another learning experience and just soaking it in and like meeting. And then, like you said, it's like summer camp, right.
You just get to meet really cool people that you don't normally get to see ever. I mean, when do you ever get to see cybersecurity professionals? There's, it seems like there's a lot of us.
There doesn't, but there's not No. When there's well in this concentration. Right.
In this amount. Um, so, okay. I gotta ask you the obvious question then.
Yeah. What have, what's caught your eye this year? Oh man, there's been a lot.
Honestly, I've been overwhelmed today with what's caught my eye. I also feel like there's a lot of the same stuff. I don't know.
And that's, it could be a No, there is, And then obviously then we have the AI buzzwords that everyone's like, oh, we're using ai. When honestly they used AI last year, they just didn't say it because it wasn't as big as a deal. No.
This year, this is the year for ai. No doubt. Well, but to be fair, it was the same thing at RSA.
Yeah. There, there was a company I literally just talked to, like right before I came here, um, that they are kind of using like a similar technology to blockchain. Mm-Hmm.
To make sure that like, um, critical infrastructure is protected. So if there was a ransomware incident, you'd be able to like pull it would do it. It wouldn't even, it would be able to tell you what happened before you even found out it was a ransomware.
Because they wouldn't, you would know before someone says Go ransom. And I thought that was really cool to think, because if we're talking about cyber warfare, like that's like our biggest issue right now. And I mean, if we have that ability to see our critical infrastructure and see what's going in and out before it goes in and out for a ransomware attack or any type of attack.
That's huge. That is huge. You're right.
Yeah. It is huge. Um, and that's interesting.
Critical because critical infrastructure was always one of the big, you know, kind of things here. Um, I will tell you what, you know, you said something and it's been a theme we've heard actually from a few guests today. Yeah.
Everybody's looking for what's new in security. Yeah. What's the next magic bullet?
Well here's, you know, there is no magic bullets. Stop believing in magic bullets. Yeah.
Um, but there are incremental things going on. Like, um, API security. Right?
Right. Two years ago, API security was about just knowing what APIs you have right now, it's gone to the next level. I know what APIs I have, how do I lock 'em down?
What's their current posture? You know, what, how do I report, how do I instrument it? Right.
Um, so, so much improvement in security is evolutionary not revolutionary. So if someone looks at it, they say, well, I I don't see a lot different. Right.
You almost got to take that long view and say, wow. 3, 4, 5 years ago it wasn't Yeah. It's very Different.
That's true. And I also, I don't get a lot very technical anymore, um, from that sense. So I honestly believe that you're only as strong as your weakest link.
And I always believe that no offense, people are our weakest link. Which is why I'm so passionate about, like, I hate saying cybersecurity awareness 'cause I wanna bang my head against the wall and like say if I say you need a strong password one more time, I'm just gonna just, you know, so I don't say that anymore. I say get rid of passwords.
Yeah. Passwords we need. We need.
Right. We need, we need to move on from passwords. 'cause it's, look, I, you know, I've been a using, I've been a password manager user since 2005 when I got hacked here.
Yeah. That's when I stopped. I said, where do the law die again?
Well, Not gonna be at Shink Anymore. Sometimes, sometimes you I get hit on the head. Yeah.
Especially when you're stubborn and dumb sometimes. But, um, but it's so hard because I'd like you, I've recommended password managers to so many people who aren't cyber, you know, professionals and for whatever reason people just hate him. Yeah.
They like to pick the same password and something simple to remember. And, and this is why we get all the hacks. But I'll, I'll tell you something else though.
I have it on my desk at home. A pilot at this thick of notices I've gotten in the last four months Yeah. With free credit monitoring.
Right. Makes no difference what my password is When, uh, Marine Max where I bought my boat from, right. They were hacked their entire data base of social security numbers, phone numbers, everything.
Right. I'm like beyond my, you know. Right.
It's bombing. Um, that was just the latest one. I forgot how I'd gotten three in the last month.
Yeah. And I think, again, especially to your audience, people get numb. Yeah.
Very numb. And it, it's, but that's, you can't get numb though. That's the issue.
That's what they're counting on. I Know. That's what the bad guys are counting on.
I I strongly believe that cybersecurity starts at home even before it goes into corporate. Like, I think, I think there's a huge missing element of like, we need to educate users at home to help them understand. Because a lot of the reasons why even these hacks are happening at, you know, where you bought your boat is because these users aren't educated.
Because no one cares about cybersecurity in that small company. Like it's the small businesses that are also getting breached. Like, if we start addressing this and explaining how important it's for cybersecurity awareness at home, and I don't wanna say awareness, but like just education on what these cyber Cyber security Hygiene.
Yes. Cyber hygiene and like why it's important and like why it's relevant to them. And really just demystify like, ooh, cybersecurity is not that complicated.
If you break it down, lot of common is very easy, but no one is teaching it. But CISA actually just put out their like four, you know, they four recommendations, which I think is really cool. They made it in like a schoolhouse rock type of Yep.
Video. Um, but there's, it just needs to be, I, I personally believe there should be like a cybersecurity kind of hygiene, uh, in schools. And it's not even just hygiene of like passwords and stuff, but like kids, you would actually think that adults are the ones that are the worst.
But actually kids are the worst with technology because they're born and raised with it. So they just blindly trust it. It's not that they blindly trust it.
'cause I've studied this. Oh, okay. Let's see.
You know what the problem is? What? They have no expectation of privacy.
There's nothing you could steal from them. Right. Because it's all out there anyway.
Right. You wanna, you put up pictures. Let me take my pictures.
Take my pictures. You wanna take my stuff take, I don't got stuff anyway. Right.
They don't have an expectation of privacy. So they don't protect their privacy as a result. Got it.
It's only when they get older that they got stuff to worry about. Yeah. The amount of people that have asked me if I can like, you know, delete their data off of certain sites.
Yeah, sure. It's a lot. Good Luck.
Yeah, it's a lot. I'm like, no, I'm sorry. That's, it's out there.
You know what, so again, so I get all these letters they pay Yeah. For credit monitoring. And then the next thing you get from the experience in the, of the world is let us take you off these people finder sites.
All right, go ahead. And every month I get a report. You know, you were on seven sites last month.
We took you off two the next month we took you off those four, but there were 12 more. It's a whack-a-Mole game. It's whack-a-mole.
So I, I'll play the game. 'cause I don't want people having No, no. I, I look, I you if Marine Max or whoever's paying for my coverage Go ahead.
Yeah. But, um, or at and t and I'm trying to think of the other one I've gotten recently. But anyway, it, it is, but you know, you're about the fifth person that we've interviewed today that mentioned csa.
Yeah, no, they're doing a great job. You know what, I'm usually not a big fan of the government getting involved 'cause they don't have a clue. But this current iteration, this administration, cisa is dead on.
I think they are. They're doing a great job. They're putting out great content.
They're coming out with great ideas. And I think by doing so, they're helping to accelerate industry adoption and, and people's adoption of good cyber habits. Right.
I just worry with the next election, will everything get undone? Will the, you know, the Supreme Court a couple weeks ago and the Chevron case said, well, these agencies don't really have the authority to go beyond their, you know, mandates. So are those going to, some are gonna saying CSUN can't tell us to use SBUs.
Right. You know, It, I I think there needs to be more cybersecurity professionals in like the government. In general government.
It's not harder. Good people. Well, I meant like even in like congress, senate.
Oh yeah. Well you could see that needs, you see the people here, A black guy, you think they're running for congress? No, but I mean, the issue is like, if our biggest issue in my personal opinion is cyber warfare, that's why the whole TikTok thing blew up.
And there's so many other issues besides TikTok. But um, like if, if we are trying to conquer that and tackle that, why is no one in any of this the, you know, seats? Because you Know what?
Tech, tech savviness at all. Like, they're not tech. They're not, I mean, traditionally what we've seen are these, you know, blue ribbon panels, right?
Cyber experts advise Also, where do they get those people? Because I've never heard of, I, I gotta tell you, Richard Clark was an amazing person and he, he ran, I think for two different presidents. He was like their cybersecurity person.
He was really smart, but he was only one Man. Yeah. I was gonna think One man isn't gonna do it.
Right. Um, I would love to see, and maybe it's a CISA thing if they have the authority under this new thing to set up. And I think that's what's made CSA really successful by the way.
They haven't just like sat on top and tried to dictate. Right. They've worked industry and government in the partnership to do a lot of these things.
I think that's the right approach. Yeah. I do know there's a, a girl named Madison Horn who's like running for I think Oklahoma Senate and she's like, was in cybersecurity privacy.
Well, There you have Madison Horn can send it in Oklahoma. I was like really excited. I talked to her 'cause I, I met her two years ago at RRSA and she's like, yeah, I think I'm gonna try to run.
I'm like, you should run. And then she called me. We had a call like last week or something and I was just so excited.
She's like full blown going. I I think it, you know, it's the same old, same old will look. The people who watch this are techie people.
They're cyber people. Right. It's not even them.
Well, the people who aren't cyber people really give a crap enough to but elect Someone. But that's like what we need to show is like everything involves cyber. Every part of our line Involves you got stuck on the airplanes in a couple weeks ago.
It's a cyber thing. So yeah, Like every, everything we do is in with technology. Right.
Which always involves cyber, some type of cyber aspect, some type of privacy aspect. We can't live our li unless we're living under a rock, which we can't even do anymore. Honestly.
They'd still find us. But like, unless we're living under a rock, then we wouldn't have cyber. But we have cyber in ingrained in every single aspect of our life.
I'll tell you the key, I was a political science major. Coach people vote pocketbook. Yeah.
They vote for pocketbook issues. That's true. You need to make cyber a pocketbook issue.
Oh, we can make that. Oh, I think it already, it already is. People don't realize the tax they pay as a result of a bad cyber.
Right. Anyway, Kailyn, we're about out time. This was great.
Yeah. I want to thank you for coming up here and, and, and not well at least it's air conditioned in our suite. Yeah, it's great.
Enjoy black hat. Thank You for Having me. Tell people if they wanna follow you on the various, uh, platforms, look into this one, I guess.
Yeah. So how do they do that? Yeah, if you wanna follow me, you want cybersecurity education tips or you wanna get into cybersecurity yourself or you wanna share it with family and friends?
I, my Instagram and my TikTok are at cybersecurity Girl. No space. Just all one word.
Um, also you can find me a Caitlin, the on LinkedIn. Um, but yeah, my, my whole job is to just educate and train the public on being safe online and getting more people into cyber and just educating us on What a great job. So good for you, Meg.
Thank you so much. All right, for now, we're gonna go check out. Well, I'm not gonna go check out.
It's too hot out there, but, uh, we're gonna take it easy. Have a great day. Enjoy everyone.
This is Alan Shimel for Textron.
