Strengthening Human Cybersecurity Defense – Toney Jennings, EBI
Everything BlockChain Inc. (EBI) CEO Toney Jennings explains why humans as the first line of cybersecurity defense need more training and encouragement.
Transcript
This is Techstrong tv. Hey guys, thanks for the throw. We're here with Tony Jennings, who's the c e o for e b i, and we're talking about that first line of defense and maybe that arguably last line of defense, the human, and where they play in this cybersecurity strategy.
Tony, welcome to the show. Uh, glad to be here. Thanks.
Good. Uh, good to see you again. Most of our issues these days are, can be traced back to simple mistakes that humans are always gonna make.
And the question I have is, is that fixable or should we just accept the fact that mistakes are gonna be made? I know we invest a ton of money in training, but I was looking at my wife's cybersecurity training recently, and it was roughly equivalent to traffic school, and I was like, I don't think that's gonna make a lot of difference at the end of the day. So what can we do with, you know, humans to make them a little more resilient to cybersecurity attacks since they are the weakest link?
Yeah, sure. Well, I think that's a great question. Um, unfortunately, humans are humans.
Uh, you know, we're all gonna make mistakes from time to time, mostly, uh, inadvertent, of course. Uh, which I guess that's the issue, right? Um, uh, you know, you're gonna make inadvertent mistakes.
It's gonna open doors, uh, the bad guys are gonna get in. And, uh, unfortunately, I think that's something that, uh, I don't know that you can ever entirely eliminate. Um, but certainly I think you hit on something important just now about training.
Obviously training is one of the things that probably caused least in the organization, probably one of the things that theoretically is easiest to do. Um, and I just think that, uh, a lot of the training and the doubt that is out there is pretty superficial. It doesn't happen enough.
It's not reinforced enough. Uh, so I think, unfortunately, you know, from my perspective, one of the best things you can do is train people, make them aware. Um, and, uh, you know, then it, it, it that point you, you hope for the best, I guess.
And no hope's not a great strategy, but, uh, at the end of the day, uh, I think humans are gonna be humans. Uh, so I think training is, is gonna be one of those things that just has to happen. I think it's gotta get better.
I think it's gotta reinforce the right behaviors, and, uh, I think you'll, you, you'd see better results in those situations, And we make training better. Can it be more fun? You know, we hear a lot about gamification, right?
Seems like there's just, you know, not enough of that being a plot. Yeah, I think that's true. Uh, like I said, I think the quality of the, uh, training varies.
Um, some of it's pretty dry. Uh, some of it's just one of those things that's like, uh, nails on a chalkboard to try to, to sit through and get done. Um, and I think oftentimes too, um, I'm not sure in some organizations how enforced it really is.
You know, you, you get your little, uh, notice to, uh, get your cyber training done and things like that. But at the end of the day, you know, I don't think all organizations enforce that equally. So, uh, I think it's a problem of, uh, just, you know, top down commitment.
Uh, I think it's, uh, probably another element, as you said, is the training could be more interesting. It could be more thorough, it could be more, uh, more fun, so to speak. Uh, I don't know if it, if it, if it could be gamified in some way.
People always like that sort of thing. Um, but I think, I think you're hitting on, uh, the right issues there, which is, um, you know, you gotta have the top-down, uh, you know, commitment. Uh, you've gotta have training that people wanna take and training that when they do take, it reinforces the right behavior and it sticks with, uh, that user.
There's also a tendency now to kinda penalize people for their cybersecurity mistakes sometimes. Is that right? Um, a productive approach?
Is that how we need to go about things? Or does it just kinda encourage people not to report issues because they know they're gonna get blamed for it? So basically it all gets hidden underground until it becomes a major problem.
Sure. Well, you think intuitively that, uh, you know, uh, some sort of punitive action would, would make a difference, but, uh, I think you hit the nail on the head. I think what that means is certainly, uh, if I'm seeing my coworker undergo some sort of punitive action, uh, that doesn't look too pleasant to me, I'm more than likely just not gonna report the problem at all, and I'm gonna kind of try to fly under the radar.
So, uh, I think that, uh, I think you hit the nail on the head there. We hear a lot about artificial intelligence these days, and of course, the bad guys seem to be crafting things that are harder to identify for a human in the first place. So, have we reached some sort of level of complexity where it's not gonna be possible for humans to recognize a phishing attack or a business email compromise because it's gonna be too sophisticated, so maybe we need to rely more machines?
Yeah, well, I think o obviously now you're getting in an area of, uh, of a lot of debate and whatnot, but, uh, I think certainly AI can play a role for the bad guys and the good guys, right? So the, the bad guys are gonna employ AI to be more and more human-like, uh, the good guys are gonna use AI to try to do to, uh, you know, detect things, uh, that might be a little more subtle than a, than a human might, uh, might notice. So I think it's gonna be used by both sides.
I think the, uh, the, uh, the, uh, jury's still out on how effective it's gonna be for either, um, but, uh, you know, I, I I think that certainly AI will play an important part going forward. I just don't know if we really know exactly how that's gonna shape out yet. Are there a set of best practices somewhere for cybersecurity professionals on how to engage people on a human level?
I mean, is that something we need to develop? Because it seems like a lot of people are, you know, they're kind of intimidated by those folks at the very least. Sure.
No, I think that's a great question. Uh, quite frankly, I mean, clearly there's frameworks out there, uh, with c i s and NIST and things like that, where you have, uh, best practices, frameworks from the perspective of controls, policy tools, things like that. Uh, and they're very good for frameworks.
Um, oftentimes though, they don't really get down into what we're talking about here, which is the psychology of the human. We're really talking about that point. Uh, you know, you need to accomplish this, so here's the tools or controls you put in place to, to mitigate that risk.
Uh, so those frameworks are very good. Uh, the better organizations, I think, can mitigate to certain degree some of the, of, of the damage that humans can cause. Uh, by implementing those controls, by implementing a framework and deciding a few things, deciding, you know, how important is your data?
Which data is important, where is it at, uh, and how do I protect it? So just take kind of a risk management approach to things. Uh, put the barriers around the things that are important and don't spend as much time and money on the things that are, that are less important.
Uh, so there's very logical, uh, you know, best practices, frameworks and things like that that are out there to help you do that. Um, but I think at the end of the day, to your point, I don't know that it gets really down to the psychological level of the human, which is really what we're talking about. But having said that, implementing those frameworks, implementing those controls, to the degree it makes sense for your organization to get the level of maturity you need for your organization based again, on what kind of data, how damaging could it be to my organization if I lost that data or it was compromised?
I think putting those controls in place can mitigate to a certain degree, um, you know, some of the damage that could be caused by inver inadvertent actions by, you know, your employees, by that human that we're talking about. Um, again, I don't know that you ever completely get rid of that, uh, but I think certainly, uh, like I said, putting boundaries, putting controls around around those things can at least mitigate, uh, what we probably know would be, uh, an eventual mistake by somebody in the organization. Do the cybersecurity people need to change the way they approach things?
I remember watching a panel a couple of years back where the CEO said if his security people had have been around when they invented the phone, they would've told them not to use it, because some data might, or information might leak. So, you know, how do the security people kind of have a meaningful conversation with the business? Well, I, I think you, you just said it right there.
You have to have a conversation at the business level, not at the cyber level necessarily. Cuz to your point, um, you know, uh, you know, cyber guys are always gonna think in terms of risk and they're always gonna think worst case. And they're always gonna think that, you know, you've gotta, you know, protect everything to the utmost, uh, degree you can.
But I think, obviously, you know, most level at the C level, uh, I've got limited resources, I've got a mission I've gotta accomplish. Uh, security needs to be an enabler, uh, not a blocker. And so I, you know, I always encourage cyber guys to really think of it from the perspective of overall business risk.
Cuz that's really what, how you need to think of it and don't, uh, you know, if you talk in that sort of language to A C E O or A C F O or, or a C I O, um, it's, they're gonna be a lot more receptive to, to what you're saying, cuz you know, you, you don't want, uh, to be one of those guys where, you know, to hammer everything's a nail, right? Uh, cyber guys, I think they need to be much more nuanced. They need to be aware of, of the business, what's important to the business, and then craft their approach, their language around let's fix and protect what's important to the business.
Uh, let's not waste a lot of time and energy and resources on things that are less important. So I think it's really taken a really, a holistic business risk management approach, uh, is the way I typically encourage, uh, cyber guys to think about, uh, how they approach the C-suite and how they h how it'll be more, uh, how, how, how you'll have more receptive ears at the, in the C-suite, uh, to those types of conversations, quite frankly. What are the implications of a lot of these regulations and laws and the national SEC cybersecurity posture document that the administration's putting together?
And that strategy that goes with that buried in there is, you know, efforts to hold people more accountable for how they manage data. What are the implications of that for the business and then users? I mean, how will that manifest itself ultimately?
Yeah. Well, I think it's already manifesting itself. I mean, and it's unfortunate that in my mind, you know, you have rules and regulations and, uh, you know, mandates like that because people aren't doing what logically they should be doing.
And so this is, uh, an attempt to kind of force them to do some minimum level of effort around, uh, you know, protection and whatnot. Obviously part of that is, uh, you know, some sort of a carrot and a stick approach where if certain things don't get done, uh, you know, there's consequences, uh, at, at the personal level. So I do think that will help.
Um, again, I hope that it doesn't, uh, cause uh, an underreporting of issues or a hiding of issues and things like that cuz someone doesn't want to get fired or someone doesn't, doesn't wanna get punished, you know, they don't wanna reap the consequences of, uh, you know, poor decisions or poor management. Um, but I do think it's inevitable, uh, if you oftentimes look at, uh, compliance mandates that are out there that typically start off a little soft, uh, with suggestions and best practices and things like that, and over time, uh, they typically tighten down and become more punitive and, and such. So I think there's just a natural progression of, uh, you know, like the, these sorts of things.
Um, where, but, but ultimately I think, you know, that somebody's needs to be held accountable, you know, particularly when it's, uh, there's irresponsibility from a management perspective, uh, when there's poor decision making. I do think there's a place for that. I think it's just gotta be applied in the right area and in, in the right dose, so to speak.
Do we need something that feels like, you know, uh, a cybersecurity PR campaign? I'm thinking back to the days World War II where, you know, everywhere you went, there was a post that said, loose lips, sink ships. So is that part of what we need to do?
Well, you know, I would've said that probably 10 years ago, I think now, if you, you look at the paper every day and something's happening. So I think awareness is there. Um, I still think that some, sometimes, um, things like cybersecurity are viewed more as insurance, you know, by, uh, by, uh, you know, business leaders than, you know, an actual necessary program that you have to implement.
I think that's changing, uh, clearly as, uh, businesses, I mean the, uh, results sometimes of, uh, ransomware attacks or, you know, you know, cyber penetrations, things like that are pretty brutal. So, uh, I, I, you know, I, I think there's enough of that going on now. There's an and, and, you know, enough of these folks talk around the water cooler that, uh, they're beginning to understand that, uh, while it may seem like an insurance policy, uh, when you're talking about putting a cyber plan in place, uh, it, uh, it's, for some businesses it just takes one or one or two incidents to wipe out your business and you're gone.
So, um, I think that, uh, yeah, I, I I just think that, uh, uh, you know, over time, uh, you know, this has become a little bit of a self-correcting problem in that, uh, I think where awareness 10, 15 years ago, you, you, that would've been made a lot of sense. I don't know. No, don't know if it'd be as effective now, because I think the awareness is there, there just needs to be the will.
If you've got the awareness, then you've got the will to do something about it. So I think, uh, the awareness is there, and I think because of the consequences that people are realizing now, the will to basically implement a program and, uh, make smart cyber decisions is, is getting better. All right, folks, you heard it here.
It's all about the will of the people. You gotta get them motivated to do this whole thing, otherwise, all the tech in the world isn't gonna make up for human errors. Tony, thanks for being on the show.
Yep, good. Glad to be here, Michael. Thanks again.
Look forward to the next one And back to you guys in the studio.