Cybersecurity Training and the U.S. National Security Strategy – Jennifer Addie, MACH37
Jennifer Addie, COO and strategy director for MACH37, a cybersecurity accelerator, explains how if the U.S. National Security Strategy is to succeed there will need to be much greater emphasis placed on cybersecurity training.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Jennifer Addie, who's c o o and strategy director for MTH 37.
They are a cybersecurity accelerator. They help companies get launched, and we're talking about the national security strategy as outlined by the United States government. Jennifer, welcome to the show.
Thank you. It's nice to be here, Michael. I looked at that document and I'm sure so did you, with a lot of interest.
It's the United States governor appears to be getting serious about this whole effort to secure all our assets and work with companies, but you can't help but read this document and if you know anything about cybersecurity and the shortage of skills out there without coming away with one question, which is you and one army. So what is it or how is it that we're gonna implement this thing from your perspective? How can we get this job done?
That's a great question. Yeah. How is the big thing?
I mean, your point initially is most important, which is they've at least set their intention. They at least have drawn attention to this, and they're now communicating outwards. The way I think a lot of systemic change happens is sort of at three levels and, and it's gonna be at the individual level, right?
How people view cybersecurity and cyber at large. How may they reframe it in their minds to be just the computer nerds in the corner versus an everyday part of their lives, an everyday part of every job, and keeping themselves safe, as, you know, using it as a life skill. You have the institutional approach, which is, you know, the corporations and the other organizations have to acknowledge it, make it a priority, set metrics around it that, um, are meaningful that'll, you know, help measure actual progress against real goals.
And then you just need systemic change how institutions are connecting to each other and how they're working together. And so when you think of that in terms of infrastructure, right? The US national infrastructures, only 15% is owned by the government, and yet they are tasked with trying to protect all of it.
And so how does government industry work together in that more systemic way? Um, and if you could also scale it globally, right? Our weakest link, uh, makes us all vulnerable.
Or if cyber war breaks out, how does everyone work together as a system? And so, you know, from the micro to the macro level, it's gonna be important for people to, one, reframe how they understand cyber, to accept the fact that it's going to be a, an integral part of their lives and an important life skill, uh, and part of every job. Uh, and three, be willing to acknowledge the fact that we are safer when we work together and can, can link systems appropriately and acknowledge where there's risk, uh, rather than ignoring it until it gets too late.
Are there any ways to approach this from, um, higher levels of automation? And I'm asking the question because to your point about the weakest link, you know, all we have to do is look around and we don't get too far without running into that weakest link, and they're not getting any smarter. So how can we, um, find ways to augment them using the technology and maybe do it in a way that doesn't necessarily require hundreds of millions of cybersecurity experts that we don't have?
Yeah, right. Humans are often the reason why phishing attacks work, and a lot of that comes back to lack of education or awareness. I think there are a couple, couple approaches, uh, making it, um, more accessible in terms of understanding how to behave with technology, just digital acumen writ large across the society, understanding what, what risk is and where to protect yourself and where to trust systems.
And also when you're looking at the way that they structure attacks and how they happen, put resources against the most vulnerable places. Use tools and other digital tools to help maybe be that, that a screening guide and use humans around making some of the decisions. A lot of technology, uh, is centered around automation.
Uh, with automation comes vulnerability. Uh, and so the balance, however, as computing, if, uh, there's going to be sort of, uh, improvements on both sides, you're gonna have attackers who become more sophisticated, but you're also gonna have protection that will as well. And so the, the point, and then in terms of cybersecurity is ensuring that those who are in charge of setting up protections are not only, you know, ahead of the attackers or aware of the attackers, but really approaching it from a diversity of mindsets.
When you think about security in general, a lot people don't understand. They don't understand why they would do it, they don't understand them, they don't understand, uh, they think about systems and how they decide to choose the vulnerabilities that they go after. And I think the more diversity we have in terms of our understanding of different adversaries and the different attack mechanisms, uh, the better sense people have for, okay, this is, this could be a vulnerability when something pops up on in order the email looked very strange or suddenly, you know, crashes in a strange way.
So we have a hard time assessing our risks, and that risks should inform our behavior. I mean, do we need to, you know, make this part of everybody's education class and starting grammar school? And do we need to send everybody back to class and say, Hey, this is how you live in a digital age, Right?
Are the equivalent of, uh, teaching grandma to program the V C R I? I think, um, if you ask folks at Mock, we would say education's critical. And a lot of folks avoid cyber education.
They, we notice that the part of the skill gap issue is the fact that people aren't choosing to go study it. They might find it dry or overly technical for their tastes. And so really, I think it comes down to, you know, what, which elements of cyber are critical in different areas of society?
So people often ask us, you know, why aren't there, you know, more minorities in cyber, uh, why aren't people who don't have engineering degrees in cyber? And, and the answer is they can be, and they often are. And one of the best ways to approach a career in cyber is to start where you're most interested.
So if you love working in hospitals, that's great because there are a lot of cybersecurity needs in hospitals, in records, in patient care. And so when you think about, um, getting those cyber skills, starting where you are or where you love is a nice way to begin. So there might not be this ubiquitous set of skills that everyone learns in their job tomorrow, but they can start bulking up on their skills in their current jobs right now.
Because one of the questions that comes up is, what can we do in the immediate timeframe and what's long-term? The long-term is a little bit easier to answer because point, you can put some kids in school, make it part of their esteem curriculum and, you know, have them come out ready to go, uh, which assumes a lot of communication awareness from, you know, the front lines of cyber security faculty vocation system and into the corporations. But I do think those programs are important too.
So I, I think in the immediate term, it's, it's basically beginning to educate people. What is the cyber element of every job that's worked? And what is your responsibility and what, what can you build in terms of awareness from that point?
In addition, having those basic skills and accessibility to learning those things. If people say, I don't pay, pay my bills online because I'm scared, right? How can we get more people comfortable with understanding how to do that in a safe way and increment them up from wherever their starting point is?
But more importantly, as you know, for long term, getting some of those education skills, um, built around the fun elements of life, right? Children in schools love steam class 'cause they get to program robots that, you know, can go, you know, pick up snacks from the other side of the room, things like that. And so making it fun, making it part of of life where, you know, maybe they program a robot today, but they're flying, um, a U A V, you know, when they're an adult or they're, they're driving remote construction equipment.
Uh, and same with institutions. The organizations can very easily integrate cyber education as a workforce requirement, uh, beyond just the, don't click on the email, um, type of, uh, you know, workshops and things like that. Alright, so when little Johnny tries to steal little Jill's robot, she's gonna smack him over the head with some cybersecurity defense.
That's right. But, but how do we make this more compelling? Because frankly, a lot of the education programs are about as interesting as going to traffic school.
So how do you kind of make this more engaging? We hear a lot about gamification, but can we actually make training fun? I think you can.
I, you know, a lot of it depends on what aspect of it is, but even when you ask people what is cyber, they'll, they'll sort of give you that doey look, uh, maybe computers, right? And so getting people to understand what does cyber and cybersecurity mean, uh, and what are the things that they might need to learn? And so I, I think gamification is one approach.
The other is, uh, using teams and, and sort of the human side of things. We, our humans were built to interact together. We enjoy spending time together.
And basically working as a group is often how cybersecurity experts enjoy working. When you look at the hiring, uh, in cybersecurity, uh, elite cybersecurity professionals will look at, you know, what, what's the type of job? Is it interesting to your point, what are the working conditions and who will I get to work with?
And so I think a lot of training, you know, we all have to learn math, we all have to learn, you know, English and poetry. And, and, and some of us love all of that, and some of us don't, but we all learned it. And I say, so I think if it, it goes back to, you know, learning techniques and making it part of our real lives.
I think a lot of education often centers around, you know, theoretical concepts, but if you, you know, teach a child how to, you know, protect, you know, something that's very important to them and they realize they just, you know, locked, you know, not locked that out of the Amazon account or whatever it is, they, they can start understanding where, where the risk and where the, the benefit can be. So I do think, you know, it might start with robots, but then it edges into other areas they care about. If you talk to a middle schooler, uh, which I have one, social media is a big, big deal, and there's a lot of vulnerability there, and engaging with their peers is an incredible part, important part of their, their world.
So how do you do that in a safe way? So they all have intrinsic motivations that they want to drive towards or maybe protect and integrating into people's lives. I think, you know, is, is one area one way to really go about making people care a little bit more about learning it?
You think the bad guys who seem to be very organized these days are kind of laughing at us because, you know, they see us kind of stumbling around and they're kind of like, we just make it too easy for 'em. Yeah, I think, I think that's true. And I think a lot of organizations, um, a lot of the decision makers aren't educated enough on cyber to know if the people they're hiring are really covering everything down.
And, and because technology changes so quickly, it's a very difficult ask to say, are we completely shored up? Are we a hundred percent protected? Because the answer is pretty much no at any given time.
They're, you know, the, the code is evolving, the sophistication of the attacks, the way they're using, you know, generative AI today, uh, when they were just doing phishing, you know, attacks last month. So I, I think it, it's a, it's a daunting task and most people say, I'm just gonna trust someone else with it. I don't wanna have to necessarily know all the ins and outs, um, can actually work to people's detriment because if you're running an organization, you have a sense for what's important to protect, what vulnerabilities might there.
And so I think the more that leadership collaborates with cyber experts, the better defenses they can build. It's much like, you know, defending a city, uh, many moons ago, right? The more you know about what's inside the city and what needs to be protected, the better you can fortify it in certain places.
All right, well, working that analogy and coming back to the government strategy, do we need a component of this that is really about, uh, just driving awareness like we might have in wartime where we're gonna have a campaign that says, you know, loose lips, sink ships, that kind of thing. I mean, is that where we're at? Is this become a national emergency?
I think it's become an international emergency. I, yes, I, I mean, I don't know if, if a campaign would do it, and we see elements of that, that lack of awareness at every level in cyber that we work in. And one of the areas, what we see, particularly with startups where, you know, we work with early stage startups is folks aren't thinking about, um, who they're, who are doing business with, right?
So they may have a legitimate business transaction, but may not realize that they just took money from someone who might, uh, you know, steal their IP and use it against the na national infrastructure in the future. And so I think there is a wartime mentality in terms of the way that geopolitics is influencing markets and the way the markets are maybe ignoring geopolitics. It's a luxury to assume that, you know, cybersecurity and the capitalist market is separate from geopolitics.
Uh, most other nation states don't operate that way. And so I think the more that people understand that all of it's interconnected and they can educate each other on where it's vulnerable and what the consequences would be to making certain, maybe just, you know, profit-based decisions that could end up making, you know, very, very bad security situations, I think the more that happens, the better. And, um, that takes a lot of people from a lot of industries to start connecting and coming up with, I think some maybe more simple approaches together.
You'll get these very long documents, uh, well-intentioned without a lot of simple strategies. And so I think, you know, to your point, wartime might be a great analogy. Okay, all I have to do is go collect rubber tires.
I, I, I, that's a, that's a starting point. And so the question is what are the rubber tire equivalents for the cyber situation right now? All right, folks, while you're heard it here, cybersecurity, when I think about it, is really a civic duty.
It's part of an obligation we have to the country and to each other, so behave accordingly. Jennifer, thanks for being on the show. Thanks for having me, Michael.
All right. And back to you guys in the.