Eric Johnson on Why AI Literacy Is the Next Frontier in Cybersecurity Training
Eric Johnson, senior cybersecurity advisor for Backblaze, explains why artificial intelligence (AI) literacy programs need to be a crucial element of any modern approach to cybersecurity training initiatives for end users.
Transcript
Hey guys. Thanks for the throw. We're here with Eric Johnson, who's senior cybersecurity advisor for back Blazing.
We're having a little chat about, well, the lack of cybersecurity awareness in the age of ai. Eric, welcome to show. Thanks for having me and wife.
Alright. I would argue we've always had a lack of cybersecurity awareness, but maybe things are gonna get worse in the age of ai. Explain.
So, I guess I would say I agree with you. We've always had needed improvements. Uh, but AI has made the gap between the training that most of our employees contractors today receive versus the actual, uh, threats That, and the emerging threat landscape that's developed, that gap is the widest that it, it's been in my career.
So give us some examples of things that, that we need to be more aware of and can we actually defend against these things? 'cause sometimes I feel like some of these more advanced threats are reaching the point where only another machine can detect them, and it's not clear to me humans can detect them. So that's definitely part of it.
Um, I'd say many companies today are, are facing, uh, the, the need to use AI and the need to be to develop AI literacy is, is critical. So absolutely, you have to be using AI to defend, uh, and every company out there is now facing AI threats. So things like, um, phishing, uh, that we had a better handle on like two or three years ago.
It's now become quicker and easier. Even the social engineering, uh, is now automated through the use of ai. Um, so it's more important that on the defense side, we're also using as much AI as we can.
Um, but AI can never remove the human in the loop. So that subject matter expertise is also very important. Um, and, and we're never going to sort of outrun that.
Our people will always be the last line of a defense against these types of threats. So, uh, using AI literacy will help, or improving AI literacy will help people be, uh, catch it better because the years of being able to say, Hey, it's it. Look at the misspellings, look at the address, the simple stuff is not happening.
The ais are correcting that. They're getting over the language barriers. Uh, and so it's really just increasing people's awareness about what are the types of emerging threats now that we face.
Do these threats have any kind of a tell that people should be looking for? So let's say it's not misspelled something or other, but are there other things that are indicative of something is amiss? So, one of the, so I just recently went through a cybersecurity awareness training.
And so one of the things I did was to target our, uh, our training this year towards the actual types of incidents that we face. Um, like many companies, things like credential stuffing, uh, is a very common thing. So we recently enforced mandatory MFA, uh, out for many of our customers.
Um, but for, for many systems that's, uh, alone is not adequate enough because with the amount of data breaches and password credentials that are leaked in the wild, uh, that's not a good enough security measure. So, uh, companies like us have to be doing regular checks for account takeovers. Uh, we have daily reports that we go through to flag accounts and then go back and get them, ensure that they are secured and backend owner's hands.
Um, but we can't stop if someone's, uh, email is compromised. Um, and so that is something many companies are having to deal with, uh, this day and age. You just can't rely on just a simple like email MFA factor securing someone's account.
Um, and then that's, that's just them trying to get into your account. Uh, once someone is into your account, then they're trying to, uh, see what they can, uh, get, download, uh, delete and kind of get into their ransomware stage of things. So, um, and then there's a variety of threat actors today.
It's a lot of, uh, issues we deal with are, uh, back to nation state actors. Uh, so I've, I've done a lot of talking about the DPRK, uh, it workers scheme schemes. That is something many companies, the US companies face, and that is something that, uh, I would say since the pandemic, uh, we also have faced a higher amount of fraudulent, uh, uh, workforce.
So things like, uh, fake candidates, fake jobs, uh, fake websites that, uh, some of these nation state actors are using to actually harvest identities to then go out and create these fake jobs. So, uh, what some people can do about it is, is the old adage of, you know, if it's too good to be true, then someone's probably trying to take advantage of you. So, uh, there is no free lunch.
You know, common sense needs to be factored in that you need to kind of think twice before clicking on anything. And if, yeah, if something seems too good to be true, then yeah, don't fall for it. Um, but, and then just assume if, if you have clicked on something, report it so that security teams like myself can go in and make sure accounts are safe and secure.
Mm-hmm. Will this get a little worse maybe in this regard? We're all talking about AI agents and we're building and deploying these things, and all these AI agents are gonna be interconnected to various systems, and each one might have different levels of connections.
And when one of those AI agents gets compromised, suddenly the attacker will have access to a lot more stuff than they ever had to before, where they theoretically had to at least log into four or five different things. Now they'll just hack one thing, and that'll be that. Yeah, I would say both the speed and the impact has increased, um, so they can get into accounts faster.
Um, the, the number of credentials, you know, that consumers are still reusing across multiple companies is still way too high. So, you know, we need, uh, you know, longer passwords, better adoption of password vaults, people need to stop reusing credentials. Um, but we're just in a day and age now where, uh, it is almost more assumed compromise and, um, they need to be moving to higher authentication assurance levels like, uh, one-time passwords and things that really move beyond email and SMS.
Mm-hmm. You mentioned MFA, is that enough at this point, or is that kind of just the new table stakes, but we need something above and beyond that? Exactly.
So, uh, email and SMS as a secondary factor are not good enough. Um, because often they can spoof, uh, uh, an SMS message or trick someone into that, or they've, uh, also have access to email. So, um, it's not uncommon that then the attacker can go ahead and, and get through that vector.
That's why it's important that stronger things like biometrics or like a Fido two based, uh, authentication method is used. Uh, you, you can't, you know, force that higher level of standard across a variety of devices and, and wide customers. Um, but that's why, uh, we definitely recommend, you know, take as high as a security posture as you can get used to, because yeah, MFA is just the table stakes today.
It's not enough. Mm-hmm. Um, as you kind of think all this through for a minute, will we, um, need to replace our cybersecurity platforms today?
I think there's a debate going on about whether or not this whole shift to AI will require new tools and platforms all together, or are we just gonna gonna wait for our existing tools and platforms to get AI capabilities and just go from there? Well, I think with, um, any of the great disruptions or ages of transformational technology, I think comes change comes, uh, new innovations. Uh, you know, even passwords today with the innovations in crypto, they're not good enough.
AI is figuring out how to decrypt them faster than ever before. So passwords aren't, aren't safe as much as they were a few years ago before ai. Um, and yeah, I think there's gonna be many systems that are gonna have to have additional checks.
Um, many companies are now investing in putting AI into their products. That change is gonna have to happen to try and keep on pace because your traditional indicators, uh, of compromise aren't gonna be good enough. They aren't gonna be fast enough.
You, you need to have AI that can do, uh, alerts and look across different telemetry sources, uh, faster than a human can do. So we need that AI help. But, uh, it is also going to probably go through a phase of, of, as we upgrade or replace these security systems, it's gonna make false positives from AI just as high as the, all the false positives that security operation teams have been buried with for years.
So I think it's gonna take time to kind of normalize. Um, and that's why, you know, in general, I say right now the, the bad uses of AI are kind of outpacing the good right now. Uh, and that's why things like AI literacy and bridging the training gap, uh, just important right now to get visibility to people so they know about what are the types of threats, what could the impact be, how do they recover from them?
Um, because unfortunately it's getting too common that different accounts are getting compromised. Mm-hmm. Do you think the proverbial bad guys or maybe a, a lot more AI literate than we are at this point?
So I think many companies are still in the stage of trying to, uh, figure out how to use AI responsibly. Um, some are even debating, you know, with the lack of governance out there, you know, should they, should they not be doing it? But I kind of view it like the days of social media, you don't really have a choice.
Um, if you don't use it, you're gonna get left behind. Uh, and while some companies are still figuring out how do they use it, the bad actors are not waiting to ask questions like that. They're finding every possible exploit, every b breach, every zero day vulnerability, and they're sending it all into AI to exploit and automate, you know, pen testing offensively as much as they can.
So, so yeah, the threat levels with AI have definitely increased things. Uh, the, you know, the silver lining is hopefully it will cause some, uh, I think I looked at some recent, uh, data breach reports. Uh, PON Mon Institutes one I followed for four or five years, and this was the last, the first y first year, and I think seven since they've ran it, that they said, uh, the, the time to actually resolve an incident has finally come down.
So they attribute that to better training, better awareness. Um, but yeah, it, it's interesting times a ahead with the use of AI and, and companies need to really become, uh, literate, start using it, start learning from it, um, or they're really gonna be left behind from bad actors. I think to your point, one of the things that we've seen in recent years is that bad folks are not going to the trumble of actually writing malware and sending it in and trying to embed it.
They're just stealing credentials and logging in, um, in the age of ai, is that gonna be a lot easier for them to do? And so maybe that first point of weakness is, as you were saying, our credentials, but what do we do about it? So I think, um, again, just trying to narrow the gap between, uh, and so increased security awareness.
So companies need to make sure that, hey, you should not be going through, I mean, two or three years ago it was all your standard phishing wailing, spear phishing kind of attacks. You need to be educating them on current and emerging threats on, Hey, if, if you get a fake remote job offer that seems too good to be true, don't give them your identity credentials. If you're reusing any passwords across accounts, you need to to stop that and instead to adopt longer, uh, or even, you know, use a password vault to generate your passwords.
Um, and then, you know, teaching people that there's so many breach reports out there, they can go check their accounts and see what passwords have been compromised. And so I think it's, you know, it's your cybersecurity hygiene is becoming, uh, something that only security professionals used to know how to dig in and, and look and see, have you, you know, has your information been posted on the dark web kind of stuff. And I think we're now starting to see more breach reports and things online that more of your general consumers can go out and and check.
Um, we just need more people to be aware that you are going to be likely more compromised and you're not gonna stop that. Um, but you just need to educate people on how do you check it, uh, when should they be rotating their credentials? Um, and definitely using, you know, 5 0 2 level of, uh, authentication, uh, get, get them more familiar with things like password list authentication or, uh, one-time passwords.
Um, I know I, I look at the folks like my parents, the, the elderly generation, they, it's a big deal for them to even use standard MFA with SMS. Um, and so I think, you know, it's, it's gonna be a, a challenge going forward, but it's, it's, it's a norm that people are gonna have to shift to, just like when people shifted to using the internet for searching. So AI is just exacerbating the need to make that shift faster.
It's as much a cultural challenge as it is a technical one. Correct. So what's that one thing you see folks doing today that just makes you shake your head a little bit and go, folks, we need to be a little bit smarter than that.
So probably the, the biggest thing for me is the maybe explaining problems away or, or even rationalizing or, or normalizing, um, fraud, waste abuse, uh, thinking that like, you know, Hey, I'm, it's not a problem for me or I'm not affected by these things. Um, part of when I give trainings on to talk about things like the D-B-R-K-I-T workers scams or the fake jobs or the fake websites is 'cause people assume that like, oh, I see that in the news, but I'm not really impacted by that. Well, if someone's say, another trend that picked up over since the pandemic is this concept of overp employment.
And there's a lot of debates out there about whether or not having multiple jobs is, you know, ethical or not. It's perfectly legal. Uh, but what keeps me up at night about it is, you know, with it, it's been reported that DPRK, uh, it workers have targeted freelance platforms.
And so what I've seen in my personal experience is where people get really good at juggling multiple jobs and, and not telling their employers about it, there's a chance that, that they might employ a sanctioned D-P-R-K-I-T worker. And at that point, that does become illegal. So I think just raising awareness to people that what some of these things might be in the gray, debatable.
Is it unethical or not? Well, there are clear lines that say, Hey, yes, if you hire a freelance helper that happens to be from North Korea, uh, then that is illegal. Mm-hmm.
Well, folks, you heard it hear, we, um, are unter constant threat is the only way to think about it. But what's changing is the bad guys are experimenting with more stuff and things you never imagined before that they would do are now possible. And well, we all need to get smarter about it.
Eric thinks being on the show. Thanks for having me, Mike. All right.
And back to you guys in the studio.