The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Authenticate This! The Cybersecurity Leadership Podcast
Authenticate This! The Cybersecurity Leadership Podcast artwork

The Myth of the Unhackable System with Elliott Franklin of Fortitude Re

Authenticate This! The Cybersecurity Leadership Podcast · 2025-12-02 · 45 min

0:00--:--

Key moments - from our scoring

Substance score

56 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber14 / 20
Specificity & Evidence9 / 20
Conversational Craft11 / 20

Elliott Franklin, the CISO at Fortitude Re (a reinsurance company), brings 20 years of cybersecurity experience across healthcare, higher education, manufacturing, hospitality, and financial services. The conversation spans his unconventional career origins - including hacking his high school's grade system as a senior, which led to a security career - and his philosophy that effective security requires balancing technology, awareness training, and practical implementation. Franklin addresses the growing sophistication of cyber scams fueled by AI-generated deepfakes and spear-phishing, arguing against the polarized view that either security awareness or technology alone solves the problem. He shares Fortitude's implementation of deepfake detection in Microsoft Teams with MFA challenges, discusses the friction created by complex authentication schemes like MFA with number matching and conditional access, and explores emerging solutions like passwordless biometric authentication. The episode concludes with a discussion of identity wallets - a Gartner-recognized but undermonetized concept where individuals control a centralized repository of credentials and personal data, granting selective access to organizations rather than allowing companies to store sensitive information independently.

Key takeaways

  • →Cyber scams are becoming highly customized through AI and deepfakes, requiring a combination of continuous security awareness training and detection technology rather than MFA alone.
  • →Passwordless authentication using biometrics (face/fingerprint scanning) can reduce user friction while maintaining security, though implementation challenges remain across different organizational contexts.
  • →Identity wallets - centralized, individually-controlled credential repositories - could shift data governance from organizations storing information to individuals granting selective access, but require federal regulation and standardization to be viable.
  • →Security awareness must be quick and practical (like Franklin's annual 'Hack in the Box' demonstrations) rather than burdensome annual trainings that employees rush through on mobile devices.
  • →Organizations face a tension between adding security layers (MFA, number matching, conditional access, step-up authentication) and maintaining usability for both employees and customers.

In this episode

  1. 1Elliott Franklin's Background: From High School Hacker to CISO
  2. 2Building Security Programs at Whataburger: Lessons from Quick Service Restaurant Operations
  3. 3Transitioning to Financial Services: Reinsurance Security Challenges at Fortitude Re
  4. 4Evolution of Cyber Scams in 2025: Deepfakes, Customization, and AI-Driven Threats
  5. 5Balancing Security Awareness Training with Technology Solutions for Scam Prevention
  6. 6Multi-Factor Authentication Friction: Moving Toward Passwordless and Biometric Authentication
  7. 7Identity Wallet Concept: Centralized Personal Data Control and Privacy Standards

Mentioned

Fortitude ReWhataburgerElliott FranklinNIST Cybersecurity FrameworkMicrosoft TeamsRaspberry PiApple IDGoogle IDGartnerAmazonChick-fil-A

Guests

Elliott Franklin

Topics in this episode

NIST Cybersecurity Frameworkbiometric authenticationPasswordless authenticationMultifactor authentication (MFA)Conditional accessFortitude ReMicrosoft Teams deepfake detectionNumber matching authenticationStep-up authenticationFIDO keys

Questions this episode answers

How are deepfakes being used in corporate security threats?

Elliott created a deepfake video of his CEO from a YouTube source and sent it to board members; deepfakes are now being weaponized in scams because they're free, easy to create, and increasingly convincing, making them a major vector for social engineering attacks.

What is Fortitude Re's approach to detecting deepfake attacks?

Fortitude recently implemented beta deepfake detection technology in Microsoft Teams that challenges users detected as deepfakes with multifactor authentication, kicking them out of the call if they fail to provide the MFA code.

Why is MFA alone insufficient for preventing cyber scams?

MFA focuses on authentication but doesn't address the customized, AI-enhanced social engineering scams that exploit personal information people publicly share (children's activities, location, interests) to make phishing attempts appear legitimate.

What is an identity wallet and how would it work?

An identity wallet is a centralized, individually-controlled credential repository (similar to using Apple ID to log into Google) where users store all personal data and selectively grant organizations access to only the information needed, rather than organizations independently storing customer data.

What was Elliott Franklin's entry into cybersecurity?

As a high school senior, Franklin hacked into his school district's grade system to check his class ranking; the hired security company that discovered it offered him a job fixing the vulnerability across all district schools.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains a mix of practical observations and repetitive discussion. Elliott provides some useful insights on identity complexity, legacy system management, and the tools-plus-education approach to security, but much time is spent on tangential stories about Whataburger, burger preferences, and personal anecdotes that don't advance cybersecurity substance. The identity segment with Speaker C offers deeper value, but overall there's significant filler that dilutes the insight density.

Identity is the new perimeter. It's been the new perimeter for 10 plus years maybe probably longer, 15 years maybe. But and so finding somebody that really understands identity and end to end identity flowing from the authoritative source and birthright access and role based access and all of this and entitlement reviews.
You've got to have a combination of both. You've got to do both. And so I think to your point though, we're on this, in this lean, agile, you know, you've got so, so you've got so much to do every day.

Originality

10 / 20

The episode largely recycles standard cybersecurity talking points: tools plus training, NIST framework, identity as the perimeter, business case building for security investments. While Speaker C brings fresher perspective on identity configuration tools versus true identity expertise and the application vendor ecosystem problem, Elliott's contributions are conventional wisdom. The deep fakes discussion and passwordless authentication are current topics but not deeply original in treatment.

If we can go into those leadership meetings and we have to have the strategy, I mean even sometimes as security leaders, not infrastructure, there's a, there's a fine line but we've got to go in and not say if you don't patch these we're going to get hacked. But hey, this is business resilience.
Identity is the new perimeter. It's been the new perimeter for 10 plus years maybe probably longer, 15 years maybe.

Guest Caliber

14 / 20

Elliott Franklin is a working CISO with 20 years of hands-on experience across multiple industries (healthcare, manufacturing, higher ed, hospitality, financial services). He has demonstrated practitioner credibility: built security programs from scratch, executed actual migrations, managed teams, engaged with real business decision-making. However, his primarily anecdotal communication style and the heavy Whataburger narrative reduce his positioning. He's a legitimate operator, not a pure thought leader, which is valuable, but the interview doesn't fully leverage his depth.

I spent right around five years there building their information security program kind of from the ground up.
I mean there's all kind of examples. One is, you know, when I was in healthcare and we had these million dollar robots and they were running on Windows NT and you're thinking again, they're generating massive amounts of revenue.

Specificity & Evidence

9 / 20

The episode lacks concrete metrics, timelines, and named examples of actual breaches or implementation results. Elliott mentions million-dollar robots on Windows NT, family-owned restaurant with 800 locations, and some vulnerability-related incidents, but provides no numbers on damage, cost, resolution time, or concrete outcomes. Speaker C references implementation costs being 3x licensing and migration duration of 6-12 months, but without specific company examples or verified data. Most claims remain anecdotal rather than evidence-backed.

One is, you know, when I was in healthcare and we had these million dollar robots and they were running on Windows NT and you're thinking again, they're generating massive amounts of revenue. They're working, they're working perfectly.
implementation and maintenance is through the roof. And so again, to be able to maintain the tool, especially if you don't have somebody on board that can do it, we're paying two or three or four or five, sometimes five times what we're paying in licensing costs just to someone to maintain the tool.

Conversational Craft

11 / 20

Speaker A and Speaker C ask reasonable opening questions but fail to push back or dig deeper into critical claims. When Elliott makes broad assertions (e.g., 'security awareness is dumb' vs. effective), the hosts acknowledge but don't challenge. Speaker C offers substantive follow-ups on identity complexity and business problems, but the conversation often meanders into anecdotes without redirecting. The episode lacks the sharp, pointed follow-up questions that separate surface-level interviews from investigative ones. Most exchanges are collegial agreement rather than productive tension.

Well, like, I love that you jumped into the, to the business side of what burger. I was more curious.
Yeah, no, that, that's great. And yes, I fully agree with everything you said.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B57%
  • Speaker C33%
  • Speaker A10%

Most-used words

identity68security34different31tools28human19tool15first14didn13somebody13hard12information12number12technology12whataburger11system11folks11

Episode notes

In this episode, hosts Aaron Lentz and Tim York sit down with Elliott Franklin , Senior Vice President and Chief Information Security Officer of Fortitude Re . Elliott is known as the Cybersecurity Whisperer. He shares his fascinating journey from hacking his high school's grade system to leading cybersecurity programs across diverse industries, from quick-service restaurants to healthcare and financial services. Key Takeaways: 00:00 Introduction. 01:10 Building a comprehensive information security program from the ground up. 07:27 Early career security lessons from testing systems as a high school senior. 12:25 Deploying deepfake detection technology in video conferencing platforms. 16:40 Digital identity wallets could revolutionize personal data control and privacy. 21:45 Creative network segmentation solves challenges with outdated infrastructure. 27:16 Risk assessment and framework adoption must precede technology purchases. 31:47 Talent shortage in identity and access management remains a critical challenge. 36:24 Non-human identities, including APIs and tokens, create security vulnerabilities.

Full transcript

45 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to Authenticate this, the cybersecurity leadership podcast for CISOs and identity leaders. Navigating the complex world of identity. From real life breaches to internal missteps and everything in between. We bring you authentic stories, hard earned lessons and actionable insights to help you lead with confidence when chaos strikes. Our goal is to humanize identity, uncover actionable solutions, and explore the business of identity beyond the spreadsheet. This is Authenticate this, where identity Identity meets leadership. Hello and welcome to Authenticate this, where we focus on the human side of identity. We have a special guest today, Elliot Franklin, also known as the Cyber Security Whisperer. We'll have to dig in on that one, Elliot. But Elliot is the CISO at Fortitude. He's got a very, very interesting background. We'll dig into some of that today. But there were a few things that I want to jump in immediately. Your background, Elliot, I looked at your resume. It looks like you spent some time at Whataburger.

Speaker B: I did, yes. Back in San Antonio, their headquarters. So I spent right around five years there building their information security program kind of from the ground up. And uh, it's a great, you know, at the time, it's no longer, but at the time, family owned restaurant, 800 restaurants across 10 states, lots of heavy, heavy credit cards. So PCI compliance was very, very interesting times.

Speaker C: Love it.

Speaker A: Well, like, I love that you jumped into the, to the business side of what burger. I was more curious.

Speaker B: I was actually. I don't know, your, your favorite.

Speaker A: And you know, I grew up in San Diego and it's a big, um, you know, we're big in in n out and there's competition in n out versus Whataburger. And I kind of consider myself a burger connoisseur. And I gotta say, my Whataburger experience was, was pretty solid.

Speaker B: I'll tell you. When the first one came into Texas, I was, I was there, I was still working in. And it. The first in and out came into Dallas, the Dallas Fort Worth area. And so our CEO, our president went up, their founder went up there, or Mr. Dobson went up there and gave them like a pair of boots, like a pair of cowboy boots to the general manager and said, welcome to Texas. We welco competition. And they were like right next to each other. And it was so interesting because the lines were so long. People would then just come over to Whataburger anyway, so I loved it. But it was, you know, lots of, lots of great times there. It was, uh, great. Just all kind of weird things that you have to do in, in retail, like in the physical security side and dealing with fraud. And we had the cameras on the registers and how some of the people, you know, being open 24 hours. We had some very smart. You talk about hackers, very smart employees that would sit there and figure out how to do the ring up a, uh, free burger for their friends by like hitting water like eight times on the register. And then this book came out like the Hacker's Guide to the POS System or something. And you're thinking, wow, I mean these people, how are they thinking to do that? And they don't think they're going to get caught. It's just wild.

Speaker C: Wow.

Speaker A: I didn't even know that existed. So they would hit, they would hit water button eight times.

Speaker B: And then some sort of. Yeah, some sort of way that they found out just by playing around, being bored at night at 2am and nobody was in the restaurant and like, oh, oh, it rang up a burger for free. Oh my gosh. My friends can. I mean just wild things like that. And of course they got caught and having to go in it sometimes and grab a register out of a restaurant unannounced and put it in my car and head back to the office, do forensics on it for different reasons. And those are the kind of things you don't. Again, it was a kind of a, um, one person show there. I was kind of like until I could hire some folks. So dealing very closely with a physical security guy. I mean again, people in the drive through, you think we're open 24 hours and you've got folks that again, they would say whataburger is a place where we come and we, you know, after all the bars close. And uh, some folks just couldn't wake up from their hangovers. And unfortunately we had to have the police come help escort them out. We're just like, no, just park, just sober up. But uh, just the things that you have to deal with there. It was very interesting. But I loved my time there. It was good.

Speaker C: Do you, do you have a collection of little number stands?

Speaker B: We started just buying those because we did. You're right. It was marketing. We're like, first people were stealing them, were like, come on. But they would get their graduation year or their wedding year, 19, whatever. Yeah, you're exactly right. That was so. It's like, hey, that's great marketing. Just buy all those extra numbers and let people take them. And then you started selling the fancy ketchup on Amazon. I mean all of this stuff, it was Just an incredible, It's a cult following and it's, it's just really cool.

Speaker C: It's the silliest thing. I mean, I remember in high school, people would have those little numbers on their dashboards or whatever and talk about their favorite orders. And I didn't go for a long time. I moved to Texas in high school. I was like, whatever, it's a burger joint, like McDonald's, Burger King, whatever. And I finally went like four years after being in Texas. And I was like, oh, like there are some things that Texans are very proud of. And I would say in a silly way, but there are some things that are actually worthwhile, including that.

Speaker B: I'll, uh, just add one more thing. What was interesting at the time. Again, it's been a long time since I was there. But it was never fresh, never frozen. And so they would find local farmers around ranchers and, and make sure that the meat was never frozen. And the thing that I appreciated is they made all employees spend three days a year in a restaurant. So I had to actually go. You know, you had to buy the OSHA approved shoes and the grease resistant pants and everything. And you're going and you're working in a restaurant for three days. And I'll tell you what, that is a lot of work and working there 12 hours on your feet and the general manager didn't give you any slack. Like I had to hand her my phone and she locked him away in the office. And you're working for 12 hours straight. And that's a lot of work. And it also gives you an appreciation for. Here I am pushing down all these policies. We have push down a laptop policy that we made, like, made all their training be done on laptops. And they're like, well, this doesn't work. It doesn't work. You need to see this and that. And so spending three days a year in a restaurant, it was really eye opening and helped us go back to the corporate office. You say just not sit there and make policies and push them down. It was very interesting mindset.

Speaker C: Okay, I want to dig into that because I think that's really cool and more companies should do it. And I've seen some, some companies do it and some don't. Um, and there have been companies like Exxon that make you switch every six months to new jobs. Right. Like as you, as you are. So that's really cool. But I want to know what, what's your favorite order at Whataburger?

Speaker B: Well, see, here's what I always had to tell everybody. I have a food allergy, so. A gluten allergy. So I couldn't eat a single thing except for the salads. So I don't have a favorite order. I would. All I could eat was the salads. But, yeah, it's interesting in that regard.

Speaker A: Well, maybe that's, Maybe that's why you're no longer there and you're working in the security space. So let's, let's, let's pivot a little bit. So from, uh, from a fortitude standpoint, I find it very interesting that as we were doing research to talk to you, Elliot, we're like, okay, well, what does Fortitude do? Reinsurance. Right. It's like. And so you're in the security realm, like, a little bit different. But how does it CISO fit and work in the security realm, kind of with your mindset?

Speaker B: Well, I mean, so I'd never heard of reinsurance until I actually got this job offer. I had no clue what it was. But, you know, I think I've worked in pretty much every industry to your point. I've worked in health care, higher ed, manufacturing, hospitality, quick service, restaurants, for the most part. Security. Security, yeah. There's a few regulatory changes, but if you follow a good framework like the NIST cybersecurity framework, you're going to be HIPAA compliant, you're gonna be PCI compliant, you're gonna be high trust. All these different. So there's just different risk levels and different threat levels. And so when you go into financial services, I think it's a higher. It could be a higher stress level because I think you're targeted a little more probably because of the finances, whereas if you. But I don't know, a lot of these attacks are just spray and pray. They don't really care who you are until they. Until they get in and see, in terms of the ransomware, different things. But I love security because it's different challenges every day. You're solving different problems every day. It's not boring, it's not monotonous. Uh, and so that's why I continued to do it for 20 years. When I first. First was out of, you know, my senior year in high school, and I was trying to figure out what I wanted to do. I was a volunteer fire, you know, in the volunteer fire department. Different things. And both my parents were school teachers, I knew I wanted to do something like public service. And so I was like, well, I guess I want to be a police officer. And my mom was like, yeah, you're not going to Be a police officer. You're not mean enough. And I was like, oh, okay. She's like, you would never. You give everybody a warning their whole lives. And so I'm like, okay, all right. So I think she was right. And then I hacked into the high school grade system there, where my dad was the principal, my mom was a teacher, and I was like, okay, shouldn't have been the CZ dad. And so he called the company, and they gave me a job for the next two or three years while I was going through college. And I worked for this company, securing these networks, these novel networks through all the school districts here in Texas. So very. It was. I was like, okay, this is what I want to do.

Speaker A: So as a senior in high school, your father was the principal, and you hacked into the. The system?

Speaker B: He wasn't my principal, but he was principal of one of the schools. Yeah, in the district.

Speaker A: He was.

Speaker B: Yeah, in the district, so. And it's a small town. Trust me. There was 46 people in my graduating class. It was a very small town in Texas, but, yeah. And so the company they hired to protect those called me and said, hey, let's talk. And I told them how to fix it and what I did, and they gave me again a bag. A bag phone. I'm dating myself and a truck. I was like, okay, you're going to drive around to all the schools we have contracts with, and you're going to fix this. I loved it.

Speaker C: Was it espionage? Were you doing something for your dad, for the other school? Like, I got to steal their secrets?

Speaker B: No, what I was doing was I was pulling up the grades. I wanted to see where I ranked in the grade system, you know? And so I was, uh. I was like, oh, my gosh. I got. I can see who the valedictorian is. I can. I could have changed my grades. I was like, oh, I was number 10. I was number 10. Although I wasn't top 10%, because, again, if you only have 46. But yeah, I was like, oh. I printed it all out. I'm like, oh, my gosh. I had socials. I had everything. I'm like, how much. This is not. This is not cool. This is not normal. Funny.

Speaker A: The origin stories of the cybersecurity whisperer. I'm sure, you know, since. Since your senior year, high school and today, obviously, in your leadership roles, from a security standpoint, you've seen a lot of change. But one of the videos that. On the Cyber Security Whisper YouTube channel that you recently posted was about cyber scams evolving in 2025 specifically, and in the future. And so let's dig into that. How have you seen cyber scams evolve and where do you think they're going?

Speaker B: Well, I mean, that's a scam, uh, can be used so many different ways. I think what's so frustrating is there's folks out there saying, mfa, mf, the mfa, it fixes everything. And certainly that's important. But from a scam perspective, I mean, look, my mom's been scammed multiple times and I'm beggar now. They call me, text me. It's just, it's so easy now when you get that text that says you haven't paid your toll. And I'm like, for example, here in, you know, in Tennessee, like, there are no toll roads that I'm aware of. So when you get that, just delete it. Like. No, but the scams are getting so, so customized because we give away all of our information and so they're just seeing that you're posting, you know, where your kids are or what game they're playing or what sport they're in, and they're making it so customized. The. Just getting to where it seems very realistic. And of course we can't leave out deep fakes, right? Because they're, they're free and easy. I can go create them. I created one of my CEO saying something, pulling one of his YouTube videos down and sent it to a couple of our board members. And they were like, wow, this is, I mean it sounds better than him. But, uh, the scams, I can't imagine how they're going to, they're just going to continue with these deep fakes and

Speaker C: ah, it's tough because they're, as you use. It feels like as people use more and more AI for those scams, they're learning that balance. The AI is learning the balance of. I think for the longest time, scams were predatory around people who didn't read thoroughly, like the content of an email, right? Like, they were like, oh, there's all these misspellings. And so there was almost a pro, right? Like, like, oh, well, if they didn't read and catch these little things, that means we're gonna, we got them right? Like, right. Catching little things. We got them off guard because it's 2 o' clock in the morning when they're reading it, whatever, right? And now it sound, um, signs. Like there's a lot of the things that have maybe kind of like your CEO is like, well, this is, this is too polished, right? So it's like Gone too far. And it feels like that went, that had a very short window with AI support. And it's already kind of finding that, that middle perfect balance of what's normal human communication or human to human communication. And that's. It's really hard to, to fight against scams, especially when you're looking at like the smallest misspellings and URLs. Right? Like the URLs look more real than they used to, you know, like just hover over and check it. And so I mean, uh, it's hard, it's hard to be predictive. But like, what kind of way do you think we're going to be able to prevent those types of scams beyond just. Is it training individuals or do we have to use technology to fight against scams? Like especially scams that use scams, uh, that use AI?

Speaker B: Yeah, and it's a great question and a great point because I know there's people on both sides very polarized. Like some people are like, security awareness is dumb, it never works. And some people are like, you just got to buy more tech. And obviously the answer is in the middle. You've got to do both. And so I think to your point though, we're on this, in this lean, agile, you know, you've got so, so you've got so much to do every day and a lot when I do my monthly phishing test. And again, some people are so against and so opposed to doing those tricking your employees. A lot of folks are doing it on their phone because they're so in such a hurry and they don't know how to click and hold to see the rl. They just want to get their job done. They just want to get to the next thing so they can actually take some time off at the end of the day. And so I think it's gotta be a combination of both. Uh, I'll tell you what, we just implemented a, maybe a beta or first in terms of a vendor, we've implemented something in Microsoft Teams that does the deepfake detection. So if it thinks somebody in one of the squares is a deepfake, it will challenge them in their square with multifactor. And if they don't put in the multi factor code, then it kicks them out of the call. And so I think we're going to have to do both. We're going to have to do more technology to help with the detection and we're going to have to do continuous training. But the training's got to be quick, effective. It can't take a lot of work. And so I'm, um, huge on security awareness. But I do the annual. I do a hack in the box. I'll bring out all my hacking toys every October and do Inside the Mind of a Hacker and teach those classes at all three of our offices and show them the Raspberry PIs or different little hacking devices. But at the end of the day, we've got to find some technology and encourage people to use it on their home machines as well in their personal devices. And I know that's people, uh, don't like installing things on their personal phone for work, but if you can install some sort of. Or give them some free tools that they can install that you're not monitoring to help monitor those links when they click on them, those kind of things. I think it's a combination of the two because I just hate to see at a relative $6,000 in gift cards. Really? Because supposedly she bought something from Amazon and had to return it. I mean, it makes no sense if you sit there and think about it. But these scammers are so good when they make these calls. They're so convincing.

Speaker C: Yeah. And it's coming up where it's happening at major impacts to businesses. And I, I don't know about you, man. I get. Well, my wife will say, like, at her job, she gets. They've got a. They poorly deployed, uh, an SSO solution. But so she gets. She gets prompted for MFA too often. But she's like, that's your job. It's your fault. Aaron. This is why I have to do all this mfa. I get grandparents who are like, why do I have to do this in order to, like, I barely know how to use like the app on. On the phone for banking. And I also have to figure out how to do this mfa, like, and they don't understand why there's so much friction involved to do it. We're sure, as an industry trying to remove that friction. But that's something that I think it feels is something else we're also struggling with is like it's either training friction of our end users or friction in the action of trying to authorize or authenticate and authorize. So it's like, what tools can we use to actually prevent that friction? Are there any that you know of today that are really, actually helpful? Or is it like, hey, we just one person got hacked to doing this, so let's just make sure nobody gets hacked in the same way next time.

Speaker B: Yeah, you're right. Like corporal punishment kind of thing. I do hate that. I mean personally in our organization we're looking and I know this has been a trend for a while and probably a lot of folks are ahead of us in this regard. But we are trying to in the next 6 to 12 months go passwordless and again use that biometrics off of your phone so you don't have to put in that code when it pops up. You can just scan your face or your fingerprint or what have you and go passwordless. And I think that's going to help. But again the bad guys are always seem to be one step ahead. But the whole MFA and then MFA with number matching. Yeah, it's a pain. And then conditional access and step up authentication, all this different stuff. Yeah, it's a pain, but you've got to do it. Do you go to a Fido key? Do you. What do you do? I mean that's going to be very challenging to implement in certain, in certain cases. So you're right if you're talking about your customer base, that's a whole nother level of. Do you make your customers use MFA with number matching and different things? Probably so in some regards because otherwise the fraud they're going to experience and you're going to be out thousands of dollars, hundreds of thousands of dollars. If you're a financial institution that you can't get back, it is, it's unfortunately. Do we look at geolocating or do we look at different things in terms of authenticating you only when you're in your certain area or it's creativity would be great in that regard. Something that's easier yet more secure would be fantastic.

Speaker C: Something that, that I, we talked about in the identity space. It was you know, on Gartner's hype cycle and I don't know that well. I don't know that there's a lot of money in it. So I don't think it's gone anywhere. But it is the concept of the identity wallet but more to me like it's done in small batches. Are you familiar with that?

Speaker B: I don't think so.

Speaker C: So the idea very similar in ways of like standard trust models, like key certificates. So just finding standard model. I've got an authentication models today. I basically have a central wallet that belongs to me, Aaron Lens and it's got every, it's got all of my certifications in it. So it's got my Social Security number, birth certificate, my scuba certification, my. What do they call transcripts, all that kind of stuff.

Speaker A: Your golf handicap index, my, my Handicap.

Speaker C: Exactly. My gin. My gin. Yeah, exactly. All of it. And so that's a wallet though that now it has to be centrally managed somewhere and I can then trust other places to leverage it. So for example, when I go to Chick Fil A, they don't need to know my gym and they don't need to know my scuba information. They don't need to know anything about my social. But I do want to hand them maybe some of my, like my name. Maybe I want to hand. I don't want to do this. But say they ask and I allow them to take my address for so they can send me marketing and my text messages and, and my email address. Right. Like I will give them that permission. So now I control who has access to my information. And now. And the idea with it though is it's also not to say that say Chick Fil A or Whataburger. I should have used Whataburger there. Whataburger doesn't store that information. But like if we follow a certain amount of standards or uh, like if we, if we basically use, if we regulate and say look, Whataburger can no longer house my information. They have to get that information from my identity wallet.

Speaker B: They're just going to query it.

Speaker C: Exactly. Query. Because compute power and speed has gone way up. We couldn't have done this 20 years ago. Right. But it's gone up. I can go then leverage against my identity wallet and no different way of like using my Apple ID to log in at Google id so it's all centrally stored. I uh, also can leverage it in the same way of like those identity shared services like Google, except for authentication. It's got identity data and everything about me in one spot. And I as an individual get to say yes or no at any point. I can revoke access to people all in one spot. The trick is is while there, this wallet concept has lived in some identity providers that are out there or technology companies that is not centrally governed. Right. And so there are some states who do like driver's license as part of it. But I would love to see it expand across everything and then be federally sort of regulated in some way. When we talk about stuff like that though, do you see a world because I don't know that you can monetize that. Do you see a world where we could actually get to something closer like that? Or do you think there's too much risk in having everything centrally managed? We shouldn't do that anyway.

Speaker B: Yeah. Oh man. It's the whole. I always try to keep politics away from work. And there's. I know there's a lot, but I'm. But I'm heavily involved in, in politics. I've held some elected officers and different things, so it's hard for me to do that. But from a. Uh, yeah, that's. To me, I do now I absolutely understand what I'm about as digital identity, but I do like the concept of, you think about all the delete me law, the companies where, you know the different California laws and different things where you need to be able to request that your information be deleted from a. From a company. I mean, that would make that so much easier because I have worked at companies that were subject to that and was such a pain. We didn't even know 16 different systems we had across three different. Eight different subsidiaries. We didn't know where all your data was. So when you send in a request to delete your data, we're like, well, great, I'm going to go find it now. And we may or may not have it. And we, we have only 30 days to respond to you on these different things. So from that standpoint, that would be fantastic. There's going to be pros and cons to everything because again, m. You're right. Who's going to own and maintain that system? They're obviously going to be heavily attacked and heavily targeted since they are the central processor. But I don't know that. I don't. What are, what options do we have? What are some other options in terms of. Digital identity is so hard when somebody does one, when you call, when you need to reset your two factor, when you lose your phone. These companies take three, four, five days. Send us a copy of a driver's license. Send us a copy. And I just went through a case where I was trying to take advantage of a warranty on a cell phone that one of my kids dropped in college and needed to replace. And of course, because of all the fraud that they have with the warranty, I had to scan my driver's license and they're like, well, but I just moved. And so my driver's license is not, uh, with my new address and it didn't match what was on billing. And they're like, well, we don't know who you are. We can't honor this warranty. And I'm like, holy cow. So again, digital identity especially, we need something because what we have now is not working. I don't know what the answer is.

Speaker C: I, uh, don't know that there is one. Except for us I'll do it together. I had one more follow up topic on what you were asking and then I'm sure we want to move on to another topic topic here. But with that in mind of what you're saying, you're talking about having to like all of the acquisitions of a company. Right. And all those together make it even harder when you don't know where the data is. One thing that we talk about a lot on this, this podcast is, is that I like technology, uh, both like uh, technology like as far as supporting tools like an identity or any cybersecurity technology and hackers both seem to outpace the ability for a organization to remove legacy applications. Acquisitions are part of that problem. We are, I'm asking you because I don't know that there's an answer and I hope somebody in the world has it. But how do you fix the outpacing problem of that? Especially when those systems are often random, uh, are uh, often critical assets to the business and operating and generating revenue for that business. Do you, are you able to work with your business partners to talk like are you part of those conversations where you're like hey, we need to upgrade these systems or move off of this old system, move to something else. I mean the amount of people who are still on, not to say there's nothing there's entirely anything wrong with mainframe, but things in mainframe that haven't been updated in any way. Do you have any sort of ways that you have found an ability to transition people?

Speaker B: Yeah, I mean there's all kind of examples. One is, you know, when I was in healthcare and we had these million dollar robots and they were running on Windows NT and you're thinking again, they're generating massive amounts of revenue. They're working, they're working perfectly. Like there's, but they're, they're running an operating system that uh, is well over, I don't know, 15, 20 years old.

Speaker C: Right.

Speaker B: But and so certainly there's not been patches for them for many years or updates. So it's super hard to make a business case for some of those. So some of those I just ask for, hey, let's figure out how we can segment them. There's all these technologies out there to completely segment them. They don't need to be connected to anything potentially or only have right one way on their traffic. Maybe they're only outbound, no inbound traffic and just be creative with those. I think maybe what you're getting to, what I have more struggles with is when you do have These acquisitions and you buy another company and they've got their own active directory, they've got their own identity system and then you're trying to integrate those. We're going to force them to be on our domain and it takes 18 months and in the meantime they've got all these vulnerabilities and they've got you know, you federated the access and now this person hacked in here. The identity issue to me is a lot more struggle than the legacy hardware. I mean yeah, I worked in another area, another company that had a data center that they hired me to migrate to lead the infrastructure team and migrate that data center uh, completely to the cloud. And ah, some of those servers, well over 20 years old, never even been turned off the old RSA hard tokens, they didn't even know where the master key files were. It was a complete disaster in that regard. But they were doing it to stay alive. Like if we don't migrate this and we these machines turn off some of the. Nothing was under warranty, some of the sans again drives were failing. We had to go buy them on ebay to just keep it running so we could migrate it to the cloud. So uh, to me a lot of that's education. I know I harp on that and probably because my parents are both educators. If we can go into those leadership meetings and we have to have the strategy, I mean even sometimes as security leaders, not infrastructure, there's a, there's a fine line but we've got to go in and not say if you don't patch these we're going to get hacked. But hey, this is business resilience. Like if these turn off the hardware is going to fail. Like here's a solution. The cloud is never, I've never found the cloud to be cheaper but it's, it's quicker, it's more usually if you configure it more resilient and it's got better SLAs and things like that. But hey, even if you need to move it on prem just a newer gear, there's gotta be a business case that you can work with one of, uh, you know, a provider and show it's not gonna cost you any more. Don't make fluff numbers up but if we're down for an hour, which we were or two hours every night when rebooting these security devices to hack into them so we can at least get things reconfigured, you're gonna have this downtime that you wouldn't have had if we would have Just kept up with the hardware and you don't have to do it overnight. But P2V, you're moving everything virtual. I mean, you really can save money or at least increase your resilience by. But you've got to come with a business case. You can't do the fear, uncertainty, and doubt thing. It's got to be hard numbers. And you've got to work with your CFO and the different folks on that before you come in and just say, the sky is falling.

Speaker A: What's really interesting, Elliot, we started down this path a few minutes ago, talking about the bad actors evolving and kind of how the breaches are changing. And, uh, what my opinion is that they're utilizing human emotion to create urgency, movement. And it's like, hey, you're scared to push back on your boss. Your boss is saying, buy these, right? Or in the case of, you said, your mother got hacked. It was like, oh, the FBI just sent me a note saying, my data's leaked if I don't pay a money. Like, like, they use fear and they use human emotions. So as we started talking as humans here, the instinct is more tools, more tools. But then you said, more tools plus education. And that's what the best CISOs do, is we need to combat the human emotion with human emotion and also tools. And I just want to highlight that we went down that path, but it's like, hey, the answer is both. We need people, we need communication, we need to remove the human emotion. And our tendency to go straight to tools has to happen because we need those tools, and they're necessary. But the human side is really where the best CISOs make the most change and make the most impact.

Speaker B: Yep, Yep. Human element is, is extremely important. I mean, I, I. There was another story this week that, I mean, again, it was, I've, uh, had a couple of people that just get the phone calls, the phone calls from the bank say, hey, somebody's, you know, we, we saw malicious activity in your account, suspicious activity. We're going to send you a link so you can change your password. And I mean, they do. They click on the link and they change their password and give it over to the bad guys, and their, their accounts drain within, you know, minutes. No technology can stop that. I mean, you know, maybe you can have some sort of spam filter on your phone, but they spoof any number they want anyway. So the education is that I've hammered into everybody that I talk to is hang up and call them back at the number you know, is right. You know, if your account's hacked. Yeah, banks will call if your account is hacked sometimes. Great. Hang up, call them back at the number that you know on your, on your bank statement or on the website. But yeah, that's exactly right. We've got to have a combination of both.

Speaker C: And one thing that's interesting about that, I guess I just sort of clicked, is that once you get to a point where tools aren't working, I mean our, our human is not just grabbing the tools out of desperation for something to solve something. So like, to your point, maybe that's where we have to ask ourselves is when we leverage tools, are we looking for the tool? Because it seems so daunting to be able to solve something and we're looking for the magic elixir out of some sort of hope for getting out of desperation. And maybe that's instead where we need to lean on each other, both inside of organizations as well as inside of our industry of how do we combat certain issues. So it's not necessarily a, uh, tool that solves it, are there, speaking of sort of leaning on each other, are there things that, are there people that you work with regularly in our industry to just to bounce ideas off of?

Speaker B: Yeah, no, that, that's great. And yes, I fully agree with everything you said. And when you've come into a company, you've got to look at like an actual risk assessment, do a, do a NIST CSF self assessment and look at the areas and then determine from a risk based approach what processes you need to change first. You know, people process first and then technology has got to be last after you do the people and the people in the process part are the unsexy thing that people, including myself usually hate to do. But yes, in terms of, I'm a member of the FS ISAC, the Financial Services Information Sharing Analysis Center. There's ISACs in almost every critical infrastructure, health and across all the different uh, verticals. I'm also part and serve on the board here in the local ISSA chapter of the Information System Security Association. And so we have monthly in person meetings where we're visiting with folks and chatting. And here's a problem I'm running into. There's all kind of slack groups and I don't, I'm not good on slack so I don't really participate in those just because I've got too many other things. And there are obviously there's industry conferences you can go to as well, but some of those are just too big in my opinion. So the ISACs are great. My local security groups are typically great as well.

Speaker C: Cool.

Speaker A: There is a. I guess we didn't. We didn't address this, but we discovered that we're both owned by the same private equity firm, Carlisle. And there's a group of Carlyle CISOs that get together. In fact, you guys are getting together in next 30 days, right? 60 days.

Speaker B: Yeah. Yeah. That's huge. And I know a number of, uh, PE companies and firms that do that now, and they bring their port codes together, you know, in different leaders, whether it be CIOs, CFOs, CISOs. I think it makes a lot of sense because, again, why reinvent the wheel? Let's talk about the challenges that we're having. And the thing is, we're not going to be in the same industries, right? They, uh, purposely diversify in all kinds, across all kinds of different industries. But security is security is security. And so what challenges are you seeing? What tools are working, what tools aren't, what processes are working, what's not, you know, in your security awareness, in your tabletop drills? Again, no technology for tabletop drills, but they are vital and critical, and business resilience drills and risk assessments and those kind of things. So let's get together, let's chat about what's working, what's not in those areas. That's my biggest fear. When somebody gets into the field and they go to the big conferences. RSA black hat, uh, defcon, and I'm on the RSA conference board. So, I mean, a little bias there, but when you go to these and there's a thousand vendors and you're like, oh, you're exactly right. I need that to solve that. And I need that to solve that. Like, well, but what's your plan? Like, do you have people to manage it, or how are you going to implement it? Or have you. Do you even have a written policy about that first? Because if not, you're going to fail, the company's going to say, hey, we gave you a million bucks for this and nothing.

Speaker C: You haven't.

Speaker B: You haven't improved any capabilities, and then that's on us. We wasted their money. So that's a challenge.

Speaker A: Yeah. Uh, you mentioned a couple other challenges, right? Picking the right product, understanding how to roll it up. And also, we, uh, understand there's challenges for CISOs with resources. How are you finding resources in region, in market, with talent? And are you finding those resour specifically around identity? Yeah.

Speaker B: So I'm not one to jump on the bandwagon of it's, you know, of it's impossible to find cyber folks because I know for the longest time there was negative unemployment and now, but now with all the layoffs unfortunately there are tons of cyber folks out there. But still, I still look at the philosophy. If I can find somebody at the help desk or that has worked their way up or that is really outgoing writing scripts and those. I mean I started in the help desk and so for a couple of years I think you have a very well rounded understanding and then you can kind of be trained to move into cyber. But yeah, I think I've struggled personally with finding roles, filling identity roles. Identity is so again so vital. Everything starts with identity. Identity is the new perimeter. It's been the new perimeter for 10 plus years maybe probably longer, 15 years maybe. But and so finding somebody that really understands identity and end to end identity flowing from the authoritative source and birthright access and role based access and all of this and entitlement reviews especially if you're you know, a publicly traded company and you're under stocks and it's just so critical and privileged access, it's just identity is huge and all the domains within Identity and so to find somebody that understands identity and again yes technology is important but do they understand the concept of identity end to end um, and federated identities and working with different companies and then can they understand applying, creating some sort of roadmap to then um, put the underlying technologies in place? Because again if you can't provision someone quick enough, if you can't deprovision them quick enough that you have a hostile termination or something, they remain in their system, they take down all your systems, they hack you because you terminated them. Identity is just so critical and it has been extremely challenging for us to find uh, qualified identity folks to come in and join our team.

Speaker C: It's a tough space. I did want to know. I thought that was funny about the identity is a new perimeter and it has been for ten years. Uh, so I guess it just is the perimeter and the old perimeter is like as network. So so I just need to start calling it the old perimeter versus the perimeter.

Speaker B: That's right.

Speaker C: No, we have that. We've seen that problem a lot but a lot with, with finding real identity experts or just in people in training too. Right. And training them in the right way. And I think it's because as application development has uh, evolved so rapidly in the last 15 years or so where we are seeing more and more configuration based tools and so people who get into identity, there's nothing necessarily wrong with that. Inherently. But as people are getting into identity, I can know identity by taking training on a configuration based tool and become at least a mid level expert on it. On the tool to your point like, and that's on just the tool. And the problem with identity is while, while security is security. I like what you talked about earlier, if we all follow nist, well we've got a pretty high standard. Whereas identity plays is we are working with the most variable thing in the world and that is humans, human emotions. Right. And those human emotions also tie into how businesses evolve and created and what they're what drive drives a business. And so with each different culture or community that makes up a business over 10 to 100, 200 years to make that business, each business has also adopted a way of operating that's different from like one hotel chain to another hotel chain. And an uh, outburst is whataburger. While there's similarities in marketing, they're still very different. Look at their menus. Five items versus 500 items. Right. But they both have what we would call as a fast food burger joint. Right. And so, and I say all of that because all of that matters when we talk about identity. Sure there are parts of identity that are just security focused arguably. And I could still argue that the rest of this matters. But like you talk about privileged access management, right. There are still humans who are operating all those service accounts, apps that are out there who are afraid of, of the impact to your job to manage those, those credentials and the people who are going to yell at them if they have to rotate passwords all the time and they can't access them quickly. So every aspect of identity actually ties to how a business operates. And so for somebody to be an identity experts, they first need to do what you said, Elliot, uh, and that is understand how to apply identity concepts to the specific business and understanding how that business's community and culture evolved over time, which led to all the tools to their overarching ecosystem. You don't need to know all history evidence. There are certainly standards and identity that apply across all of them. Like, like I'm going to be able to tell you I've got my 130 capabilities of identity and we can map them to what people do, but we're going to need to assign levels of like ability to adopt and risk associated to them. And that's where I'm finding that disconnect with an uh, identity expert and somebody who knows an identity tool. And I think in our space I'm gonna, I'm segue Just a little bit back to our, to our, all of our most recent history. Through Covid, the identity space bloomed fast or blossomed fast. And a lot of parts of security did too. Just because everybody had to work remote, especially in the SSO authentication space. I wish it was in the authorization space, but especially in the, the authentication space. It just, it just skyrocketed. And so a lot of people jumped in to that space, which was very configuration heavy and became like identity SMEs and leverage tools that were configuration based. And so now their job, they're looking for new jobs, but they don't understand all of the complexities of privilege access management and they certainly don't understand identity governance and administration. Which is the biggest burden to uh, identity governance and administration is not necessarily compliance rules. I mean all this is important. I'm not saying it's not. It's not compliance tools and everything else. It's the myriad of applications that we have to connect to, to be able to operate for, for authorization and provisioning, deprovisioning of accounts. And that is history, right? That is understanding how all of that works, how the business uses it, and convincing the business to adjust. So that to me is why we still have a shortage in identity experts is because I think people fast tracked to understanding the technology and the tools without understanding how to apply those tools to business needs. That's my soapbox.

Speaker B: And you know, I can't disagree. I fully agree and I think even myself as uh, security professionals, I think we put that usually at the bottom of our list. Just because of what you said earlier. When I go to conferences, that's not the cool, sexy things. You know, I'm seeing this AI tool and this vulnerability tool and this new SIM tool and this new alerting tool and all these. But identity, oh, that's boring. I mean, come on, just create my accounts, delete my accounts for us. Something we're looking at this year is the, not you mentioned it, the non human identities, I mean the APIs, the tokens, all of those. We continue to see companies get hacked based on those. And you're exactly right. Rotating them, knowing where they are, knowing who all you even have them with. So that's what coming in. That is my whole ecosystem of identity. It's human and non human identities, provisioning, deprovisioning, entitlements. It is huge. And we're not even a large company.

Speaker C: Oh, that's actually a good point. Most organizations, it's not the, it's not the size of the company, it's not the revenue you generate, it's not the number of employees that you have, it is the number of applications in your environment and then the use cases you look to tackle. Because just in provisioning there's 20, right? Like there's rehires and legal holds and re, like there's rescind offers, all that stuff, uh, in just one category there's subcategories. Right? So when we talk about identity, it seems to get pretty big pretty fast. So my advice for people, not that our audience asked us this because they're not present, but for people who are looking for identity experts, is that's where to start, is look for people who are interested first and how to solve business problems. And then you talked about the sexy part of the uh, like of conferences, uh, is not out of desperation or not out of just pure cool factor, but look for, for sexy solutions with all these tools to solve those business problems. And ask yourself, I mean it's a business question, but what's the roi? Some of these tools are very expensive. And then you start to account for, then you, then it starts to transition into where it does matter is like how much revenue does my company make, how many users do I have? So what's, what's my license cost going to be? All that kind of stuff. But at the end of the day the first step is what solution am I trying to solve for?

Speaker B: That's right. You've got to have. And we, we don't do very detailed RFPs. I mean we, we create spreadsheets with some simple requirements, maybe 20 or so requirements and we just look across the partners. And certainly cost is one of the factors. But something that's caught us off guard was licensing. Licensing because of our size isn't that much, but implementation and maintenance is through the roof. And so again, to be able to maintain the tool, especially if you don't have somebody on board that can do it, we're paying two or three or four or five, sometimes five times what we're paying in licensing costs just to someone to maintain the tool. And that's on me in terms of if I'm a leader and I selected that tool and I didn't know that up front that it was going to be that challenging to maintain. Like do we need a simpler tool or is this just identity? And so all tools are this hard to configure and to maintain because it's constantly changing. If the HR team creates a new role, we've got to go in and put that new role. And now what are the entitlements for that role? And if we don't, they're going to not have their licenses on day one and they're not going to be able to work and, and then, oh, you're connecting into this portal which doesn't have SCIM provisioning. So we're gonna have to manually email somebody that's gonna have to go create their account. I mean again that's that ecosystem and I think it takes a team. I don't know that even one person can do it.

Speaker C: Yeah, I don't want to get too much into what we do because we just try to avoid what our company does as part of the podcast and just talk identity. But that's something we get challenged with a lot is when I started an industry it was pretty common for people for, for vendors to talk about that implementation will be 3x the cost, the new story. And I think a lot of this is because identity tools are looking to supplant or replace existing identity tools in their ecosystem. They're like how do we sell not just value but cost reduction? And so they don't necessarily talk about the cost of migrating which often the migration costs can be as much or more than initial just green slate implementation. And so that's something we spend a lot of time with. Tim is our channel guy, does a lot of that with our, with our partners. We do a lot of that with just as part of the pre sales process of talking about. Look, if you're going to do this like what is, what does done look like to you? And then we'll tell you is it worth getting there? Do you need to adjust your done? Because if uh, you look for everything that's like golden Identity, it's going to be too expensive for most companies.

Speaker B: That's right.

Speaker A: And by the way Elliot, you could make a decision today based on the information you have today, based on the tools available today in your current environment, your goals and it's the right decision. But everything changes in a month or a year.

Speaker C: Right.

Speaker A: It's constantly changing. And that's the other struggle is you're making great business human company decisions based on data and information. It all changes. And that's the conversation of the bad actors evolving. And we need to match that evolution or evolve faster than them. And they're proving to evolve more quickly than we can. They're more agile, unfortunately.

Speaker B: Yeah. And identity is one of the challenging ones with my web security or my email security or some of these others, it's literally an API. I could change out that vendor in a heartbeat. It would take me a week and nobody would even know on the back end. But identity is not that way. If you're changing your IGA solution, good luck. Even if it is API to API or something. But all of the rules and all the business rules and role based access and all that, I can't imagine anyone can do it again even with the small companies 6 to 12 months and all the cost for that migration to a different system. And that uh, makes it a lot more challenging when we make this decision when we're going to go with a new IGA platform or something. We know we're going to be locked in for at least three years because it's going to take 12 to 18 months to even get there. So we won't even really know what it's like.

Speaker C: Yeah, and I. Okay, I won't keep soapboxing so much. But one other big thing we talk about some on this podcast is our identity shouldn't be that hard to replace the tools. I mean we build them so they can be sticky. You centralize a lot of data. Things like SSO replacements require re registration of mfa. So there are some friction points to doing migration. But the hardest part about migrating has nothing to do with the identity tools. And there's a configuration process, sure, right. But it's the lack of followed standards of security standards by the applications you connect to. So there's which have created the bad business process or the hard to implement business processes over time that like for I can't remember who, who it was that sent it to me. And plus there was an article from the JP Morgan CISO too that was basically like here's the cost I have to spend just to get it to get to pay. I have to pay this extra amount of money to get a license to do security on this application. To do SSO to this application. How is that not out of the box cost? You've already developed it. How is that not just a standard? And so until we start regulating application vendors over enterprises, I don't think we're going to overcome the cost of migrating identity platforms.

Speaker B: Man, I couldn't agree with you more. And I love that letter. I don't know his name, but I've read that JP Morgan sees that he's written multiple letters like that and published them on their site. You talk about he's obviously, I mean he's there, that's a large enough company, they can actually make a difference. Couldn't m agree more. You're exactly right. This one is this configuration and this one is that. This one allows you to do that. You're exactly right. You're going to. You're going to nickel and die me. And you're going to charge me for mfa. You're going to charge me for sso. Really? Okay, well, what does the contract say? And if we get hacked, it's going to be your fault because you don't offer that. Uh, exactly right. We've got to put pressure on our vendor partners, especially if there's competition out there. The only one that does it, obviously it's going to be a little harder. But if there's competition. Yeah, let's move on. Let's find somebody else that includes that. I mean, just bake it in.

Speaker A: It's.

Speaker B: You got to be a partner and they should want to do it because they want to protect their platform. Look at. I don't know. I don't we name names, but obviously there's some big CRMs right now that are dealing with. With challenges because they don't have security first. And so now their companies are getting hit and they're just brushing their hands. No, not our problem. You didn't have the best practices turned on. Well, why wasn't that a default? So.

Speaker C: Right.

Speaker A: Well, Elliot, you've highlighted a lot of the modern and current issues that CISOs face today. And it's not just business, it's not just people, it's not just processes, it's everything included. And the best CISOs focus on the human side first and the tool side. And so I love what you're doing. We really appreciate you coming on the cyber security whisper. We're going to link all of your videos and stuff because those are fun. I'm going to start watching those weekly and, uh, I might even start sending those out to my network. So I appreciate that, Elliot. Thank you again.

Speaker C: Thank you.

Speaker B: All right, thank you.

Speaker A: Thank you for joining us in this episode of Authenticate this, the cybersecurity leadership podcast. Check out the show notes for links and resources mentioned in today's show. If you enjoyed the show, please leave us a five star review and be sure to subscribe so you don't miss on any future episodes.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Episode 433: Passkeys, Passwords, and the End of SMS MFAMicrosoft Cloud IT Pro Podcast · on Conditional access88 / 100
  • AI Is Having Its Dropbox MomentAI Proving Ground Podcast · on Conditional access85 / 100
  • The $443 Billion AI Lending Bias: Why 65% of Good Customers Get Declined | Carla Canino, Founder and CEO KindleePurpose Driven FinTech · on biometric authentication85 / 100
  • Commvault On Cyber Recovery Why Disaster Plans Fall ShortThe Business of Cybersecurity · on NIST Cybersecurity Framework80 / 100
  • The Illusion of Control: Cybersecurity, AI and the Risks Beneath the SurfaceThe Financial Executives Edge · on NIST Cybersecurity Framework72 / 100
  • Beyond the Token: How to Secure Agent Identity Across the Full Permission Chain with Jasson CaseyCyber Sentries: AI Insight to Cloud Security · on NIST Cybersecurity Framework71 / 100

More from Authenticate This! The Cybersecurity Leadership Podcast

All episodes →
  • Securing Millions of Lives Through Identity-First Strategy with Richard Henderson of Alberta Health Services76 / 100
  • Human Skills That Define Tomorrow’s CISO with Matthew Rosenquist of Cybersecurity Insights
  • Student Experience Meets Cybersecurity Strategy with Zach Lewis of University of Health Sciences and Pharmacy in St. Louis
  • Challenging AI Threats and Strengthening Human Vigilance with Steve Cobb of SecurityScorecard
  • Creating Psychological Safety in Security Teams with Susanne Senoff of PROS
Explore the best B2B Ops podcasts →
All Authenticate This! The Cybersecurity Leadership Podcast episodes →