Securing the Future: How Cyber Insurance Mitigates Risk and Cost – Tech.Strong.Women. EP49
In this episode hosts Jodi Ashley and Tracy Ragan dive into the world of cybersecurity and cyber risk with Lauren Winchester, head of cyber risk control at Travelers Insurance. The conversation explores the real-world costs of data breaches, the growing role of cyber insurance in helping businesses investigate and recover from incidents, and how underwriters evaluate organizational risk. Lauren shares her unique path into cybersecurity—from human rights law to cyber risk—and emphasizes the importance of continuous learning, proactive defense, and employee education.
Transcript
Hi everybody. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jody Ashley, executive producer here at Techstrong, and I'm here with my co-host, Tracy Reagan, creator, and CEO of Deploy Hub.
Before I introduce today's guest, I want to give you a quick update about what's happening here at Textron. We recently launched our newest website, Textron It, so be sure and go check it out. Coming up on the Textron Events calendar on June 4th, you can join our virtual version of RSAC, virtual AI and Security transforming Modern App Dev.
This includes all of our speakers from our in-person full day event at RSA this year, plus a lot of added extra content. You can also register for Cloud Native now 2025, which is happening in August. com.
Be sure to tune in every day to Techstrong TV for great shows and interviews. Okay. Tracy, what's on your mind today?
Oh, security's always on my mind and, and, and the cost of security. We've had some recent, um, sort of state of security reports released that talk about the cost, but when you see articles and you see things are really happening in the world, um, around security and what the costs are, I think it opens your eyes. So just today, a little, uh, a company called Lee Enterprises.
You know, they are a, uh, they're a, a newspaper I would call a journalistic platform. Um, and they got hit with a $2 million restoration cost. Wow.
Uh, from an attack that they experienced. Now, this is just a one time attack event. This isn't like $2 million to go fix everything and make sure that they have secure software.
And this was just a, this was just one, one episode. So it's a reminder, and it, this is not a huge company, but you know, they do say that they operate in 72 markets in 25 states. So this impacts people who are looking at news and it's embarrassing, right?
So everybody out there, software security, cybersecurity, it's an expensive process. You better have some insurance because you could get hit with a $2 million just restoration cost. I really can't imagine it.
It's gotta hit the bottom line pretty hard. Oh my goodness. Well, I think we have the right guest here today for this conversation, don't we?
I think we do Just a bit. Today's guest, I would like to introduce her. Everyone, this is Lauren Winchester.
Lauren, tell us about yourself. Hi everyone, and thank you so much for having me on. Um, so I head up our cyber risk control, um, offering at Traveler's Insurance.
And so what that means is when companies go and purchase cyber insurance as part of their policy, my team is involved to help them from a risk mitigation standpoint. So whether that be our cybersecurity experts on the team who are available to answer any and all questions they might have as they move along in their security journey. Um, we also have incident response experts who help our claim professionals.
Um, you know, when the worst does happen and there's a $2 million respiration, right? How, how do we help them, um, you know, mitigate and, and make that a little bit less impactful if possible? And then we have threat intelligence.
So, um, working on what are the emerging threats? Who among our policy holder base might be impacted by that, and how do we get the alert out? So taking a very proactive approach to cyber insurance because our interests are so aligned with the companies that we're insuring.
So, you know, I really have only started recently learning about cyber cyber insurance. Could you, what does it cover? I mean, I, I am literally asking as somebody who, who have, we've not really looked into it for ourselves.
I know it's becoming more and more important. What does it cover and how does it work? Yeah, great question.
And you know, anyone who's a business owner or in the position to influence purchasing insurance should be thinking about cyber insurance. Because the main question I'd ask is, are you connected to the internet as a business? Like, pretty much everyone, right?
Um, but so cyber insurance is speaking specifically to like commercial insurance businesses who are purchasing insurance, right? Not talking about individuals right now. Um, and that insurance policy is meant to help them investigate if you've had a potential data breach and then respond if you have, um, because there's a lot of costs that go into that incident response.
So it means, um, potentially hiring a law firm to help you understand, um, what it is the company's obligations might be based on the facts as they present themselves. And to also keep that investigation under the privilege and work product doctrine. It involves hiring a forensics firm to help identify what's happened.
Um, have we contained the situation? Have we kicked the bad guys out? Um, and then what did the bad guys do once in the system?
Um, in the case of ransomware, it can be a negotiator who has to go and, um, you know, negotiate with the threat actors and then ultimately pay Bitcoin to, um, get the decryption key, uh, if that's necessary, data recovery specialist to help get the data back up and running. Um, and then if it's determined, there's data that of, of individuals that might trigger notification obligation, you're gonna have to do notice. And you know, everybody who's gotten their letters in the mail from a massive data breach, right?
Where you get your credit monitoring and that sort of thing, that all is a lot of time and money. And so cyber insurance is meant to be that risk transfer so that companies don't have to go it alone and they can leverage their policy, they can leverage the great rates with all of those different vendors I mentioned. Um, so, you know, should your company have this happen to them and you don't have insurance navigating that is very difficult and expensive.
So what about, so how do you look at a company to assess how much you charge? I mean, I know that sounds like a terrible question, but are you looking at companies who are, do, do you look at to see if they have some level of compliance tooling? Do you or you do you just say, Hey, you need insurance, these are the things that we'll do, do you, you know, if I, if I drive a, I used to work for, I did some work with for farmer's insurance, and we did actuaries in, in insuring people for cars.
And I can promise you if you were 17 and you had a Volkswagen Bug, your insurance was gonna be higher than a 60-year-old who was driving a Lincoln Town car. Do you have something like that that you, you, you gauge how secure a company already is? Yeah, to preface, I'm not an underwriter, so this is more my understanding of the underwriting process and like generic to all cyber insurers.
But, um, yeah, so there's, um, there's ways that underwriters are going to assess the, the riskiness of an organization. They're gonna look at the size of the organization, the revenue that they, um, bring in on an annual basis. They're gonna look at the industry that they're in.
Is that an industry that's targeted more heavily or more likely to have a lot of personally identifiable information? So in healthcare, for example, tons of protected health information, um, that needs to be secured, right? Also more of a target by threat actors.
So that can be riskier. Um, and then they are going to ask about, uh, they have an application and they're gonna ask about cybersecurity controls. Um, and these are kind of to try and assess, you know, are you the low hanging fruit or not?
Do you have some of the key controls in place that underwriters like to see, um, that we know time and again, have mitigated against attacks, um, and made attacks, you know, kind of minimized the blast radius? Should there be, uh, a threat Actor going after them? Yeah, she said it.
She sent blast radius. Blast Radius. Oh, good.
I love card. Oh my gosh. That pretty much Describes it really well.
It's a blast. Radius one and a gang once and a text on gang, every time somebody said Blast radius, we only could drink some coffee Water, and we're wishing it wasnt That. Cheers.
Blast radius. Cheers. That's Hilarious.
That is the whole point, right? Is to mitigate the blast radius. Yeah.
And cyber insurance is one tool in your arsenal, right? Like I, we always say it's not if, but when, right? You can have a ton of great security controls in place, but still be targeted by a sophisticated threat actor or just have an employee who doesn't follow the process and procedure and you end up having, um, you know, an incident.
And so it's everything kind of in depth that you can have. And cyber insurance is one of them. I love the, it's not if, but when Tracy and I have had this conversation when even just like five years ago when I started doing stuff here, you know, we would put together these panels about, it's not if it's when, and we would get people who would literally wouldn't be on there because they fully believed that they could prevent everything.
And I was like, are you crazy? Back then I thought it was crazy a little bit, and now it's just, you don't hear anybody saying that it's, and it's, that's five years. It's, you know, completely flipped.
Maybe they still think it, but they're not saying it out loud anymore. You're so the sign beside behind you, I have to say it, it's killing me. Tracy, do you see her sign?
I do. That's hilarious. I know.
And actually these are like some of the top used passwords, uh, I don't doubt it. Password zero run CTO, CSO security guy. So yeah, we've got Confirm character, Five factor identification in our house.
Yes. And I hate him. I drive my husband nuts too.
Yep. Well, when you're exposed to it, you get, you, you are a little more cautious. Right?
So then let me ask you, so if you have cyber insurance, then can you ensure for a certain dollar amount for the cost of this mitigation? And would that include getting help with, in the case of like, um, Lee Enterprises of a $2 million to a restoration cost? Would that cyber insurance cover some of that?
Yes. Yeah. So basically you're going to talk to an insurance broker that, you know, anytime you're trying to get commercial insurance, the company talks to their insurance broker to purchase, and the broker's going to help the policy holder help that company figure out how much insurance do they need.
Um, and so they'll use different industry benchmarks. They'll use examples of other, you know, clients anonymously to kind of help the company figure out how much limit do you need to buy. And in some instances for large companies, they're buying what's called towers, where you're getting 5 million from the first insurer, another 5 million from another one, and you're building a tower.
The massive data breaches you hear about in the news, hopefully many of those companies have purchased quite a lot of limits. Um, but smaller companies might purchase a million or 2 million. Um, and so in that example where there's 2 million in restoration costs, and I, and I don't know that example personally or like whether that included other types of costs and vendors I mentioned, but yes, you're, you're looking at, you know, how do you get the company back up and running?
And quite a lot of those costs can ultimately be covered under the cyber policy. Um, but companies need to be, um, really upfront with their carriers and let them know we're experiencing this attack live, right? That way the carrier can approve the vendors or make the vendor recommendations and everything can go as smooth as possible so that, um, you know, ultimately you can try and get those costs covered.
Yeah, I think the data breach, the IBM uh, late last year did a data breach report. And I think that they, and this, I, I, I believe this was correct, it's been a while since I read it, but I think that they predicted, um, $9 trillion in global costs for data breaches. That's how, that's a huge number, right?
Huge. That's global. So, you know, it, uh, you know, the, the numbers are pretty outrageous and and staggering.
And to think that we're paying these people in Bitcoin and, and just, it's so, it's so bad. It's so down and dirty and gross, isn't it? I mean, there's so much they can do though, to try and prevent, I know, I know The worst case happening, you know, But, you know, security oftentimes is like testing and software.
If we weren't try to push something out, we'll avoid testing and we'll avoid security. It's, they are the two, two areas of it that will get pushed back, uh, in, especially in times of recession or in times of, um, of economic uncertainty. These things will get cut, which means that are these, these nation, um, states that are really pushing these attacks, they thrive in that, absolutely thrive in that.
So I think that from an economic standpoint, we don't know what's happening to the economy in the us. Nobody really does, but it doesn't look good. And much of what's was used to be in the government, like CISA and NIST are not being really funded anymore and everybody's gone.
I feel like the only re resolution right now is just to get insurance and see what happens, right? Because what else is there to do if you, if if you're, if, if you're at the a c level, I'm trying to make these decisions, are you going to rely on your, your, your development teams and your security teams to be able to protect you? I don't think you can.
I really don't. Yeah, I mean, I don't envy any C-suite right now trying to figure out their budgets for the coming year and, um, you know, what to prioritize, right? I think, um, insurance can't be your only answer and never should, right?
Because, um, ultimately investing in the right security controls is what can help you avoid having an incident in the first place. And, um, certainly any company should wanna be trying to protect against that because of the reputational harm that can occur as well. Right?
Um, but I, you know, I would say making sure that you're investing in cyber insurance is going to be that backstop that, you know, that keeps your company running and gets you back up and running faster. You're working with experts, you're able to, you know, hopefully weather that storm. And then I think that there are a lot of, um, you know, low cost security actions that companies can be taking even in trying economic times, right?
Um, so you mentioned cisa and they have tons of resources on their websites so that even small businesses, even if they're not critical infrastructure, right, can go on SSA's website and pull down how to do cyber risk assessments and what are some free tools and none of that's disappeared or gone away, right? They can still leverage those free resources. Um, and then similarly, if you buy cyber insurance, you can work with a team like mine and try and get that free help that comes along with your policy.
So I think companies just have to be more creative in how they approach security and make sure any aspects of it that make them super low hanging fruit they address now. Um, and then yes, be very compelling in your presentation to the C-suite or the board, um, as to why you need what you need and why. Yeah.
Well, and It seems like it, this is pretty elementary and dumb, but I don't think companies educate their employees enough. I mean, something as simple as clicking on something you shouldn't can be a disaster, right? Right.
I mean, it can create this backdoor that they can be mining for months before anyone figures it out. And I, I had a couple instances that I'm not gonna specifically, um, talk about, but things just things in general, like, you know, getting in and changing addresses on invoices and banking information and paying the wrong people, um, you know, and that's someone clicking on something they shouldn't, and I just don't think people hammer that. You know, we get all this time, we've been doing this for years, our CEO somebody will get an email or a, a slack message or text message that says, I need you to run out and buy a bunch of gift cards from Walmart.
I know. And just thinking I would of our ceo, it would never be something he would ask one of us to do. But it's always funny 'cause it always happens to the newest employee and we're all laughing because it's happened to all of us at some point in the last few years.
Yeah. But it's, it's as simple as just hammering on a regular basis, don't do this, don't do this. But not just saying don't do it, but saying why, like, when you get a security message, go do this.
It'd be really nice if they said, so this is why we're asking you to do this. Maybe there's not a problem now, but we could be a potential problem. Give us some explanation.
We're just all sitting around running around changing something and we're like, why did we have to do that? I mean, educated. Yeah.
But I don't feel like there's a lot of that going on. I get it from my husband because of who he is, but Right. I don't think as employee, as an employee, I don't think I've ever had that hammered into my head as an employee anywhere I've worked.
And that could be free. I mean, like that, that's, that's kind of where, where I land on this. Like obviously you can pay money to a great software vendor to do, um, employee security awareness training and hopefully have the why in the, in that as well, um, to do phishing testing, all that good stuff.
Um, but like, honestly, it's, it, it can be done by one security person at your company taking an example of one that was received and turning it into an email training for employees and say, Hey everybody, we got this and here's an example of a phishing email and here's what would've happened if someone did it. And then to your point about, you know, attacks that are super preventable, it's not always the big flashy ransomware attacks, right? That we obviously get those kinds of claims, but day in, day out we get social engineering fraud claims where someone's wired funds to a bad actor.
And that can happen in a lot of different ways. Often involves an email compromise. But so many of those could have been prevented if employees have been properly trained on and regularly trained on out ofAnd authentication, which costs no money.
You pick up the phone and you call a known number if someone is trying to change instructions on you. And so that's where I think like, you know, we all can be resource restricted in the coming year, who knows? But companies can do that sort of training and the why and prevent some of the attacks that we see.
Well, and it's so easy to look at an email and be like, that is not a real email address. Right? I mean, it's so obvious when it's some gobbledygook messed up thing that's not your Facebook account.
That's not, you know, your bank, that's not, you can, I mean, that's really elementary stuff that you can teach people that just look at the email address that's, go find an email you've gotten from your bank before. Does that look Slow down, down, slow down, down, well down, slow down, slow down, down. No.
And just take a quick look at this email and, and ask yourself why, and don't feel like you can't call me. You know, that's, that goes to like the culture of a company too, that from the top, it needs to be communicated. You will never be reprimanded for taking a moment and calling to verify something.
Like, we want you to do that. And that's that security culture you have to build. And that, you know, we talked about this once in Textron gang on this topic, but I wanted to point out the shame that is oftentimes involved in somebody clicking on an email that they know they shouldn't have and they won't tell anybody because they're ashamed of themself.
And when they, what they should be doing is saying, ah, I just screwed up somebody I got, I'm, I'm, they're, I'm gonna track anyway. Please Help me. I don't know, you know, I gotta, I, I wanna tell everybody I did this.
And then on the training topic, while I think that it's super important for, um, employers to think more about training, I would love to see it more from a state level or a federal level. Why don't we have public service announcements on a regular basis about cybersecurity and how these, uh, how these games are played? Because if you don't understand that, that that is how the game is played, then you fall into it so easily.
There's not enough education and awareness around how these bad actors get in what the game is. They know it very well. But my neighbor probably, I, I don't know it all that well.
I don't spend my time figuring out how these guys get in or how these people get in. So I think that it Impacts your personal life horribly. And then it impacts horribly.
Yes. Professional life people, you know, you hear elderly people who aren't computer savvy who are giving their money away to people because nobody's, it's horrible. No, but if you gave them a class to take, they would go out and they would watch it.
You if like a a RP gave something out. Exactly. Older people would be like, they're trying to teach me how to protect myself.
I'll go watch that. I'll learn, you know, that's the, what they need is something packaged up so they don't have to go do their research 'cause they don't know what to look for. But yeah, I mean, we need, we, and it just seems like we have a government right now that's just, nah, let's just cut back on all the stuff that keeps us safe and protects us across the board from fraud and problems and, you know, do other stuff and the stuff not a focus right now.
For sure. And, and when you, I do have to learn about it. There's some online certification class that's gonna take me eight hours.
I don't wanna do that. Mm-hmm. I really don't.
I want something to be served up to say, on a regular basis. I wanna hear a commercial that says, Hey, did you know that this is one way to get into your system? This is one of the cyber games.
Don't play it. No. Just on a regular basis.
So I can begin hearing what, how, how these, these types of problems happen. How do you get it out there? Like there are good resources.
You know, FTCs website has always had really good consumer resources related to cyber crime, FBI, um, this, uh, some states, um, have good consumer groups related to, um, preventing data breaches or threats that they're seeing. But I agree the messaging direct to consumer and how that happens is certainly lacking. And I don't know how you solve for that and get it into the proper channels.
And obviously that costs money too. But, uh, the resource generation has been there. I would say, Well, we don't know where the resources are unless you're in the cyber business and then you know where they are.
Yeah. And you're the ones that already trying to protect yourself. And the p the, the general public becomes our employees.
This is why it's so important for the general public, because we need to get training at that level. And maybe it needs to start in K through 12. Maybe more information should be brought to that and interacting, you Know, our, our writing, They're already mining all this and they know they're really savvy.
'cause that's the, the world they've lived in, the tech and the, you know, gen Xers. Yeah. I don't know Until I gotta college savvy, but maybe not safe.
I I, I, you know, I don't say necessarily translate, so I You're right. Yeah. There is nothing there.
But it's, you know, again, to your point of whether government does that or does private industry try and monetize that, you know, it's hard to say what's the right way to get the message out there. But, um, certainly lacking on the individual front and very scary, particularly for elders, um, and the fraud that gets reported to the FBI. Yeah.
So you've been doing this for a while, it looks like I, you know, I was looking at your LinkedIn profile and you were a research fellow at, uh, Setton Hall. So is that when you first started getting into, um, cybersecurity and risk management? What, what brought you to this, this industry?
Yeah, interesting question. So yeah, when I was at Theme Hall Law school, I was a research fellow related to, um, nothing cybersecurity really. It was related to Guantanamo detainee work actually.
Um, and reading through troves of gov, redacted government documents and trying to piece together what the story was. Um, so it was really cool work. Um, then I graduated, I ended up at a law firm.
I was doing commercial litigation and data privacy work for a little while. Um, and I got an email kind of cold email out of the blue, um, saying, are you interested in a, um, a fascinating career in data privacy and data breach response? Um, and I'm like, yeah, maybe, you know, I've done a little bit of data privacy work.
That sounds cool, I'll take a coffee, you know, and rule number one, say yes to things, right? Like try and say yes to new opportunities to meeting people, the networking. So what, you know, no harm in getting the coffee and learning more.
Um, but, uh, that coffee went really well. I met an incredible woman who became my mentor her life, and, um, ended up having a really cool job at another cyber insurer, um, where we did data breach response and we're helping policy holders on every single claim and how to respond to data breaches. So that really flipped it where I then started spending the majority of my time on, um, data privacy and cybersecurity and, um, how incidents are occurring, how we can try and stop them.
So did you have to become, uh, you went from law to a very technical platform. Cybersecurity is super technical, this is why it's so hard. What did you do to get yourself up to speed?
Did it, was it just over time you started learning these challenges? I mean, I, I, I, going from law to cybersecurity, I, there's some, there's some things I understand, but really being able to understand the tech, I don't, how did you do that? Well, and I won't profess fully understand tech either.
Um, you know, I think I've learned enough to be dangerous. No. Um, what I did, I think, um, one of the things is always be learning, right?
And, and be learning from people who know a heck of a lot more than you. And so when I took that job and I was on all of this incident response, I sat in on the initial calls with counsel and follow up calls, and I learned from these amazing attorneys who were doing this day in, day out, who really know the law and really know, um, you know, how to do incident response. And then I would sit on the forensic scoping calls and learn from the forensics experts of how they approach the forensic investigation, what are the steps they're going to take.
And then I'd sit in on update calls to learn, you know, what they found, how they've gone about doing that, and read through their reports at the end of what they found. So while I could absolutely not do the forensic investigation and be hands on keyboard, figuring out what the threat actors did in the system, um, I did get a really great understanding of how they were approaching it, what they were looking for, what are the common vulnerabilities they might be trying to leverage, um, as the attackers go through their process, what frameworks are in use to evaluate what the attackers are doing. And then I got very interested in what sort of data can we collect from those investigations to try and help on the front end because we're in this position to be able to see which of our companies we insure get attacked and which don't, and is their commonalities or, you know, differences in the controls they have in place.
What makes one ransomware attack, you know, $5 million and what makes one $200,000, um, or what stops one kind of early in its tracks. And so I think that's where I've just taken my natural curiosity and tried to figure out what are those patterns. But I would not profess to you to be able to do the forensic investigation.
I wouldn't profess to be able to, you know, actually deploy the VPN when, you know, you're trying to put A VPN or how to exactly go about doing VTNA. I just know what are these different controls, why do we want them, and what are the right environments to consider using them? Well, it's, that's technical enough.
So kudos to you. And I love that you used the word curiosity, because that is what drives all of this learning, right? We have to be curious.
And sometimes I don't feel that we're curious enough to ask all the questions that we should. Curiosity is so important. I know women, women Are very curious.
Get busy sometimes you can't be curious, right? Easy. Like you get busy.
And I get that. Like, you gotta have to, you have to find the time to be able to stay curious. And I've had this, some months I am, I come out of it and I'm like, I didn't, I don't think I learned anything new.
I got way too into my day-to-day. And how do I try and build back in that time to learn, You know, in, in almost every case in, uh, women in, um, in this industry and in tech, um, in particular, uh, women don't have enough time to be curious. And I believe it does hold us back.
But you can't, if you're gonna go home, you can't go home and then hang out on the computer and learn about stuff and work and then come home and do that. And a lot of men do. They're very interested in it and they're not necessarily taking care of the kids or running kids to school.
So we do have a disadvantage in that area. E especially women who are taking care of a family or a, or a provider for an elderly or a parent. It can be a challenge to stay curious and stay frosty and keep learning.
It's hard. It's very hard. So I think it's cool that you did it And you have to try and find like when you're, if you're a woman who's juggling, you know, home life, and it, it, it can be anything that you might be caring for elderly folks in your family, right?
Or in my case, I've got little kids and my husband's wonderful and we split a lot of that load. But yeah, when I sign off for the day, a lot of times I'm not able to log back on and I'm, you know, steeped in going to a sports game or, you know, um, reading to my kiddos. And that's great 'cause that's what gives me balance and brings me joy.
But, um, I think because my job, um, is related to cybersecurity and data privacy and insurance, I can build in some blocks of time to try and do that learning as well and not feel guilty, right? Like, I should be reading articles related to cybersecurity or incident response or cyber insurance. Um, and if I want to block off a half hour of my day to make sure I'm catching up on some articles or listening to a podcast, that's all helping me in my job.
And so I think women should feel free to take the permission to do learning related to their careers and jobs during the workday. And obviously that's not accomplishable every week, but that's something I'm trying to feel better about and not guilty about. Well schedule A meeting, right?
It's a, you know. Yep. I literally block it off if I'm like, I really wanna read this article, I'm gonna block off time.
Mm-hmm. I do the same thing. That's the only way I can actually do it.
I'll just block off a section of my day. I have three days a week that I just block off so I can spend time learning. That's awesome.
So in other areas of your life, it looks like you did work for a women's way. You probably aren't doing it now 'cause it sounds like you have a busy schedule, but tell us a little bit about it and what you did there. Yeah, that was, that was pre covid and, uh, free two kids I think.
But, um, yes, I was on the board for Women's Way, um, and, uh, women's Way is a organization based out of Philadelphia. Um, they do great philanthropic work. They have grant making, um, for local organizations that help women and girls.
Um, and so it was my first board experience and it was a very cool experience to be able to sit in there and see how, um, if there were some men on the board too, but how professionals in, in the, um, Philly area can kind of help drive decisions and, and, um, change for an organization. Um, but yeah, that was, that was a great experience. Right now I'm not doing any board work on the side just 'cause Afo mentioned I'm constraints, but That's, but I'm guessing that human rights is still something that you're interested in because that's what you were doing in college.
So, you know, do you have some aspiration to do any work in that area in the future? Yeah, I think potentially it's something I always keep up on and read on. Um, and I keep in touch with my old professor from law school and some of my old colleagues there.
Um, the, something I've always kept abreast on, and I do think there can be tie-ins to it in the cybersecurity world as well. Obviously when you think about like how different threat actor groups are forming and where, and like, um, just kind of the, the, I have no sympathy for threat actor groups, but why are they forming? And is, is it a mechanism to actually be able to, um, gain, you know, uh, make a living?
Like some folks are making a living and feeding their families off their work as a cyber threat actor. Um, I don't think that's a valid way to go about life, but it's interesting when you kind of put it in the geopolitical context of how well there Was a, there was, there was an article not too long ago about, uh, these, uh, nation states who are using human, human trafficking and they're sitting in these, basically these, I don't know, warehouses or however they've got them, you know, and all they do are the phone calls and the, the hacking. So they may not be doing it voluntarily.
Yes. No. And that would be a massive human rights concern, right?
And it's, uh, it goes to also like what company or what countries are, you know, potentially permitting that within their borders as well. Um, but yeah, I mean, I'd definitely love to get involved, um, back in that space at some point. Um, but I have, I have really enjoyed just diving in and learning about cybersecurity.
So, um, that takes up most of my time right now. Well, I think that that intersection between human rights and human trafficking and cybersecurity, it is weaving itself together. So you might be a perfect person to help solve The problem.
I get to start researching that. Yeah, absolutely. Yeah, You should.
It was a really interesting article. Um, and I don't remember now who, uh, like some world organization, uh, published it. Uh, there may be something out on, uh, I'll go Google that.
Yeah. And Security Boulevard. Yeah.
Yes. It was, uh, it was sort of frightening to be honest, to think that we'd have these human traffickers who were having these people, you know, we think of sex trafficking, but we don't think of tech trafficking, Tech traffic. Yeah.
No, I mean, from, from, you know, my understanding of kind of the threat landscape, a lot of times, uh, it's not that it's not a human trafficking situation and more, um, about monetization and how can you know someone make a lot of money kind of using their technical skills, living in a country that's not going to enforce against 'em as long as they don't attack that country. Um, so that, that's been like the primary, uh, kind of method. And then obviously there's folks within the United States that are doing it too, and very good at hiding.
But, um, I definitely can't read to read that article. Yeah. And on the topic of reading before we run out of time, I always ask people for their favorite book or a book recommendation, and we've had some really amazing ones.
Um, one of my favorite one was a book called The Failure of the Logic of Failure. There's another one that's on, um, zero day vulnerabilities called They Tell Me This Is How the World Will End, which was pretty scary. And it's a really good read and it, it's, Don't read it at night.
I was gonna, trying to keep yourself a Nightmare. I know. Well, it, it gives you the, what it tells you how those games are played.
Do you have one for us that we might, uh, pick up and read and learn more about cybersecurity or any topic that you'd like? Well, on, I'm not reading a book right now on cybersecurity, but I am reading a book by, um, a woman author who is in my industry. Um, a woman named Judy Selby, um, an attorney.
And she did a lot of, um, uh, coverage work and insurance work, but a lot of cyber insurance work. She wrote a book called The Untold Secrets of, uh, or to Thrive as a lawyer. But I think the, the like lessons she's giving in it are more broadly applicable than just that of kind of how to succeed within business.
Um, and, um, so anyway, I highly recommend that. I love to promote women authors and independent women authors. Right.
Um, so Judy Selby, go check her out. Awesome. Right.
Well, we are, we are at the end of our time here today. It goes by very fast. Um, Lauren, really appreciate having you here.
I know it took us a bit to, to line this up, which is common 'cause we're all really busy people. All right. We really appreciate you being here with us, Tracy.
Thank you. And, uh, you know, I think that we all have to be, start educating ourselves and be more curious about this topic, about, you know, how to protect ourselves. And I do hope someday that we're gonna see more public service announcements and more education in the K through 12.
Absolutely. Absolutely. All right, everyone, thanks for joining us for another episode of Techstrong Women.
Stay tuned for a bunch of new content on Techstrong tv and we'll see you next time. Thanks.

