Cold Weather, Hot Threats: Arnie Bellini from Bellini Capital Calls for Stronger Digital Security Borders
Bellini Capital Managing Director Arnie Bellini connects a recent surge in phishing attacks tied to extreme cold weather across the U.S. to broader concerns about national cybersecurity posture. He argues that escalating threat activity highlights the need for stronger digital security borders and a more coordinated approach to protecting critical infrastructure and consumers.
Transcript
Hey guys. Thanks for the throw. We are here with Arnie Bellini, who's CEO of Bellini Capital, and we're having a little chat about cybersecurity and how the scams are getting a little more sophisticated, starting with these cold weather scams that we're seeing.
I mean, there's nothing sacred. People are freezing, and now people are trying to steal their money and compromise their data and do all kinds of nasty things. Hey, Arnie, how you doing?
Welcome to the show. Good. Great.
Thanks for having me. It seems like every time that there's some sort of emergency, the scammers come out from the woodwork and start making pitches for various things that are related to that, and the latest one seems to be these cold weather snaps that are becoming more common. Um, is there something we should be doing about this?
Is it just noise in the system, or is there something we can do to maybe thwart this stuff, but 'cause it sure is annoying. Yeah. Uh, well, they're gonna come outta the woodwork because they don't really ex, they're exploiting the opportunity for us to be distracted.
I mean, it, every scam works better when we are distracted, right? So when cold weather hits and utilities shut down and you know, there's mayhem going on, that's the perfect time for a hacker, uh, to come in and create some civil sense of urgency to maybe spoof you and think that make we're the utility company, and, you know, click here if you want your power restored, right? I mean, you get to pull off a lot of clever reuses, if you will, that can, that can catch people off guard and then catch them when they're really focusing on something else.
Another, you know, a distraction is, you know, a disaster that's happened. You know, you see it in Florida, I mean, I'm from Florida. You see it happen right after hurricanes like crazy, right?
You'll see it up north when, when they, you know, when they have a, a white out, you know, day where the power goes down. You know, you'll see it for that. So, so urgency is one of the things that hackers look for.
They look for you being dis uh, you know, distracted, and they look for you needing to do something urgently to restore maybe your current situation. So essentially, that's a tell though, right? I mean, the fact that it's urgent is suggests to me immediately that there might be some sort of fraud at work here because well, um, you know, folks who are offering to help you are not necessarily gonna say, you know, and you gotta do it by Thursday, right?
They're generally gonna be, Hey, we're here to help on any kind of time and effort. But, um, is, are there other tells that we should be looking for? Yeah, urgency is one of them.
Uh, and that's the obvious one, because there's no reason to do something urgently. Now, in a, in a cold weather disaster, for instance, you might feel urgent to, to try and get your power restored. So they've gotta play on that.
So you gotta look for, I mean, you actually have to just outsmart them, you know, it really comes down to that. You can't, you can't cave into the need for urgency. You just can't click anything.
I mean, at the end of the day, if you have even a second thought about a text or an email that you get with a link, do not click it unless you know it's from a known source. That is how they're gonna get in almost every single time, is once you click, they're gonna deploy malware that you basically clicking and saying, it's okay for you to come in and put something in my system that you can come back and get. So that's one, one way that they're gonna create urgency.
Don't click on things and then don't respond. Right? It's like, and if an offer's too good to be true, then it is too good to be true, and it's not true, right?
It's probably a hacker. So it's all of those things. They're gonna play on your fear, they're gonna play on your urgency, they're gonna play on your greed, right?
It also seems like the attacks are getting a little more sophisticated in the age of ai. We're seeing these deep fakes, and I think, you know, an email is one thing. You, you can kind of discount that, but I think people, if they get an audio message or a video of something, does that make it more believable?
And will this become a bigger problem? It is a bigger problem already. So, yes, and you hit the nail on the head.
AI makes these, you know, I don't even say it anymore, but you said, how can we detect it? Well, you used to be able to detect it because things were misspelled. You used to be able to detect it because it was grammatically incorrect.
You used to be able to detect it because it didn't sound like it came from your culture, right? All of that is washed away with ai. So it doesn't matter who I am, it doesn't matter how I operate culturally, it doesn't matter how well I can spell, uh, AI can clean all of that up.
And so they are getting much more sophisticated, and it goes beyond that. So it's not just that the messaging is more sophisticated, everything is way more sophisticated, or I should say can be. So it's trending to be highly sophisticated, and we have to realize that because with ai it can be a really good spoof, just like you see, you know, AI versions of, uh, say a politician, right?
It looks pretty similar, right? It's close enough. We would have to do a second look, right?
AI's gonna let the, the, the hackers get to that point where you're really gonna have to, you know, get, gonna have to be discerning, right? Uh, because they're there to fool you. Everything is there to fool you.
I can create a website and make a website look way more legitimate with artificial intelligence, you know, and s snap of a finger. I can do a denial of service attack on your company, you know, where I just barrage your internet connection with requests to come in, requests to come in, right? And you, you can't do anything but deny it.
So you can't, can't even use your internet line denial of service attack. I can spin up servers all around the world with AI much quicker than I could before. So it makes this, this new technology will be used against us.
And that's really why Lauren, my wife and I have invested, you know, $50 million at University of South Florida to actually create a, a, a college where you combine both artificial intelligence and cybersecurity. Because if they're using it, we have to use it to defend ourselves. They're being incredibly more effective offensively with artificial intelligence and they're sophistication.
We have to be that much more dedicated to defending ourselves with artificial intelligence and cybersecurity. And so it's, and I wanna also point this out, okay? It's, it's a big deal, okay?
It's a $10 trillion problem a year. Right? Now, let's just put that in perspective.
United States gross domestic product, 30 trillion a year. China's gross domestic product, 17 trillion, 13 trillion. If they're being honest, they're not.
Okay. Uh, and then, and then who comes next? Next comes if you rank it as an economy, next comes cyber theft at $10 trillion.
Oh, and then Japan, and then Germany. And then, you know, you see my point, my point is, and it's growing at 15%, right? So the cyber theft is growing at 15%.
Hey, we're really excited in the United States that our economy's finally growing at like close to 5%. That's an amazing thing. We haven't seen that since I was in high school in the seventies.
Okay? So that's an amazing thing. We have to protect our economy.
We have to defend ourselves, uh, because even growing at 15 5%, it's growing at 15%. So by 2030, cyber crime will be bigger than the United States economy, the number one economy in the world, and they're not doing anything good with the money that they steal, right? So it's one of our biggest problems that is going undetected, right?
If we had a crime wave in a city where, you know, everybody was being pickpocketed in Times Square, or, um, you know, there was some sort of massive rash of robberies, the police departments locally and federally would respond, and, you know, we do something about this, but in the, in this case, it's so ephemeral, right? It doesn't have a physical kind of connection. So what is it that maybe we should expect law enforcement and governments to be doing about this?
Because to your point, it is sapping our economy. Well, you hit the problem perfectly. That is the problem.
You frame the problem, we're not responding. It's hard to respond, right? It's, there's several problems with this.
One of the biggest problems is if this was crime, to your example, if this was crime and we saw things happening in the streets, we would demand something be done about that, right? Because we can see it, we can, we're probably, we could be involved in it, right? We could be the victim of it.
But with cyber crime, it's digital. It's, it's invisible, it's silent. Uh, and it doesn't, doesn't, doesn't seem to sting our emotions as much, right?
So we don't really do that much about it, right? But it is, that's why I'm raising the red flag here, saying 10 trillion going at 15% gonna be bigger than any of us, you know, in, in less, in five years. In five years, okay?
Five to six years, okay? If it continues to grow at this pace, we have closed our physical borders here in the United States. Thank God, we now have to close our digital borders, right?
And there's a big project to be had there that I don't really think, you know, well, lemme just say that that's where I'm putting all of my time and effort is like tracking the code on that. How do we defend our digital borders? That's the season for the new cop, Bellini College of Artificial Intelligence in cybersecurity at University of South Florida.
It's also why I came outta retirement, because this is my civic duty. I think I can help crack the code and figure these things out. But it comes down to a, a lot of things.
But one of them is we've gotta have more people entering the cybersecurity profession in the United States of America. And it is a very lucrative profession. And so that's one of the things that we're doing, is we're really getting the word out to young, young, young folks that this is a great career path, right?
Uh, we need more people, we need more cyber soldiers, right? To defend the walls, the digital walls, right? That's one thing.
Um, we have to have some government policies that are guiding Lights North stars that start to tell all of us business people and others, uh, how we should be defending ourselves and what they would consider a decent standard. It doesn't have to be regulation, it just has to be a North Star standard that, that we could follow, because it's a very confusing cybersecurity. And cybersecurity hygiene is very expensive and very confusing to most people.
It does not need to be. So some leadership in this area is gonna be very important in the government. Uh, some initiative from folks like myself and the business community and the tech community, very important.
And, and at some point, we're gonna, we're gonna solve this at some point. We just need to solve it sooner rather than later. How far can we go?
Because you'll hear security folks will say, well, I can clean up the mess, but I can't prevent those people from launching an attack in the first place. So, and they'll say the defenses are too poors. And, um, to quote, I think it was Frederick, they're great.
If you defend everything, you defend nothing. So, um, what is the role of cybersecurity people here and what can we do? Well, I would say if I were to declare a North Star, it would be pretty simple, right?
And, and I'll actually lay it out here. You know, I would say every business in the United States, every organization, in fact, in the United States must use, and I'm not gonna regulate it, but North Star should have, if you wanna be way more secure, if you wanna lock down 85% of your exposure to being hacked, here's five things that you can do. Multifactor authentication, make sure everybody in the company's using it, okay?
Have an antivirus, uh, solution that is deployed to every single device in the company, okay? Uh, make sure that you've got proper backups. Make sure that you can go back a, a week, a month, maybe even a year.
'cause for data gets stolen, we're gonna rely on that backup, okay? Or if it gets locked down, we gotta rely on that backup. Gotta make sure you're doing that well.
Okay? Fourth thing you've gotta do, you got to have user awareness training. What is that?
It's teaching every one of your employees what they need to do and what they should not do. How to be safe, how to not click on those links that are suspicious. How not to, uh, respond in an emergency.
You know, users, there's basic training. All the things that we've talked about. There's basic training that every user needs to know as well, because it doesn't matter how good I defend the digital wall, if they can get someone inside to click, they're in, right?
So that's really important. And then the fifth thing, and the last thing that's really super important is constantly assessing your risk. Constantly walking your digital, your organization's digital wall to see where there are vulnerabilities, making sure you're marching down that wall on a regular basis, evaluating whether you have any openings in the wall, whether you have any t chinches in the armor, whether they can get in, right?
And so, you know, if you did those five things, I'd say that there is, you've taken it from massive exposure to being hacked down to maybe a 10% chance. So, you know, that's pretty darn good, right? If we could defend the digital wall, like you said, you, you can't defend it all.
If you defend it all, you defend nothing. Okay? Here's five things you could do to defend 90% of your digital wall.
How aggressive should we be? Because it seems like governments especially have been a little hesitant to be on the offensive with this stuff. And yet we know that some of these attacks come from specific regions and specific areas and involve specific, uh, cyber criminal syndicates that are being protected by various things.
I mean, do we need to engage in some quote unquote gunboat diplomacy here, or is there some way we can think about this differently? I, I love the idea of gunboat diplomacy here. Okay?
We could pull that off. Okay? But I don't think that would do any good, right?
What we've gotta do is we've really gotta look, okay? It's pretty simple, right? $30 trillion gross domestic product, right?
That number is why America's number one, okay? Number one, economy, okay? Number one country, okay?
You see how much power we can yield if we use our power around the world, okay? We can do just about anything, all right? We have to stay number one, you don't want China being number one.
You don't want Russia being number one. You certainly don't want rocket man being number one, right? So, you know, the game that we're playing now is autocracy versus democracy.
That's the new game in town, okay? And it's probably never gonna end. It's always gonna be spy versus spy, autocracy versus democracy.
They take advantage of the fact that we are an open society, and they, we invite everyone, you know, into our nation, right? And they take advantage of that. So there's a few things that we really should be doing.
I can tell you this. We should not be allowing any citizens from a foreign, from the United States of America for an adversary list. We should not allow any citizens from people who are on that list, or I'm sorry, nations that are on that list.
And that list includes China, Russia, North Korea, Iran, uh, the Venezuelan regime, and I forgot the seventh one, but none of those na, if you're a citizen of any of those nations, those are our foreign adversaries. We should not allow them to attend colleges in the United States. We should not allow them to work in our colleges in the United States, because this is where we create a lot of our innovative thinking.
Okay? That's the, that's, I mean, you're gonna have to do something like that because every one of those nations has a law that says that every citizen and every company inside those nations must perform spying or intel. They call it intelligence gathering for the government.
They must, it doesn't matter where they are in the world, they must do it. And that's why you've seen so many of these Chinese nationals that say Michigan University, six of them got, uh, arrested for spying on an Air Force base. Three of 'em got arrested for smuggling and, uh, biologically hazardous material into the United States.
A good bled are called corn crop. Okay? Not, not a small thing, not at all, a small thing, okay?
So, you know, there's some really basic steps that are so obvious that are right in front of us that we can take to really solve this problem. Um, and the North Star is another one that I discussed, but I mean, there's, it's not that hard, but it is, it's something we've never done before, so it's all new, right? It just has to require, you know, kind of innovative thinking on how we solve this problem.
If we wanna be an open society, how can we be an open society and have people still as freely coming back and forth? I think the answer is, you gotta put a filter on it. You gotta put an appropriate filter on who can come and who can't come into the United States and what they can do when they're in the United States.
That's really important right there. Um, if you, if we were able to, you know, do the, the, the, the, the, the, the North Star and everybody in every business followed that we'd be in great shape, but if we lose our position with our economy, we lose our position geopolitically as well. And that's what's really at stake here, because they are destroying our economy and siphoning off our economy with these $10 trillion worth of, of hacking that's going on.
By the way, 30 billion was just confirmed, I believe, stolen from, from the state of California, $30 billion. Some would say that, you know, we, the United States give as good as we get. So do we need some sort of, I don't know, cybersecurity, non-proliferation treaty the way we have with some other things that are dangerous to everybody in the world?
Ugh. Yeah. And no one would follow that.
Like everyone would sign it and no one would follow it. Okay? So let me just tell you example.
Okay? Like, I, like China could sign it now and not be in violation of it. Because what they do is they just go to private, they go to private, uh, tech companies, and they give them contracts to hack into the United States so they can say, you know, once removed, it's like, we didn't do it.
We paid someone to do it, but we didn't do it right? So it it, there's all kinds of ways of getting around that and China's already doing that, so, uh, and they're, they're getting really good, by the way, at hacking. They weren't good before.
The Russians have been the original gangster, right? So Russia, during the Cold War, they're the og right? The original gangster of hacking, right?
They were really good. They are really good at, they're kind of distracted right now. China was always there and they were just, you could tell when they were trying, we could easily fort their hacks.
They've gotten really, really good at it. Really good at it. Yeah.
You mentioned your work with the University of South Florida. Is there other things that universities should be doing? Can we maybe pull our collective university resources better and kinda work on this problem?
It seems like it's bigger than one school. Yes, sir. We can, in fact, I just met with the chairman of the Board of Governors at the state of Florida.
That's the person that's in charge of the entire university system. And I've been proposing that we take, you know, a hub and spoke, uh, approach where we pull all of our resources on both cybersecurity and artificial intelligence and, and, and see how we can make a difference in our, in our national posture, in cybersecurity. Because someone's got a lead here, no one's really leading here, you know, and it requires leadership.
It just requires some leadership here. And it will, we can solve the problem well enough. We, it won't affect our economy.
All right, folks, while you heard it here, hey, the fight is on. That's the good news. The bad news is we're not quite as organized as we should be.
Hey Ernie, thanks for being on the show. Alright, thank you so much. All right.
And back to you guys and Stevie.