
Business Security Weekly · 2026-08-12 · 1h 8m
Key moments - from our scoring
Substance score
55 / 100
Five dimensions, 20 points each
Domain security remains a critical blind spot in enterprise security architecture, according to Ihab Shraim, CTO at CSC Digital Brand Services, the world's largest corporate registrar. The episode centers on CSC's 2025 domain security report analyzing Global 2000 companies across eight fundamental security measures: SPF, DKIM, DMARC, DNSSEC, DNS redundancy, registry locks, CAA records, and registrar grade. Shraim distinguishes domain security from brand protection - the former is an enterprise security architecture issue, while the latter addresses counterfeiting and unauthorized channels. The report found alarming trends: 87 financial services companies lack basic domain security controls despite heavy vendor investment; 88% of homoglyph-based domain names are owned by third parties (potential attackers); and 16% of all malicious domains target banking despite banks having weak domain security maturity. Criminal platforms like FraudGPT ($80/month), Worm GPT, and Fraud Wizard AI now automate entire phishing and malware campaigns, identifying uncensored LLMs and providing domain recommendations for specific enterprises. Shraim emphasizes the gap between detection and remediation - most organizations can identify threats but struggle with verified takedown processes that require human validation to avoid mistakenly taking down legitimate infrastructure. He advocates for enterprise-grade registrars, multi-lock strategies at both registrar and registry levels, and SOCs staffed by highly-paid threat hunting engineers rather than junior analysts managing alert fatigue.
The report found DMARC adoption rose from 38% to 80%, DNSSEC rose only marginally from 3% to 11%, DNS redundancy is declining, and 88% of homoglyph-based domain names are owned by third parties - likely attackers positioning lookalike domains.
Platforms like FraudGPT ($80/month), Worm GPT, and Fraud Wizard AI automate entire phishing and malware campaigns, identify uncensored LLMs for exploitation, and provide domain recommendations specific to target enterprises so attackers can launch sophisticated campaigns without technical expertise.
Brand protection focuses on counterfeiting and unauthorized sales channels, while domain security is the broader enterprise security architecture issue covering domain hijacking, DNS takeover, phishing infrastructure, and malware distribution.
Banks have purchased extensive security tools and conduct security audits that create false confidence, but the adoption of critical domain security controls like DNSSEC and registry locks remains low; security audits don't verify actual control implementation.
Approximately 90% of the takedown process can be automated through form-filling and API calls, but the final 10% requires human validation and monitoring to confirm successful takedown and prevent accidental removal of legitimate infrastructure.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers moderate insight density with some substantive information about domain security measurements and organizational challenges, but is heavily padded with introductory banter, personal anecdotes (retina surgery, Vegas stories), and extended sponsor segments. The domain security report itself provides concrete data (DMARC rising from 38% to 80%, DNSSEC from 3% to 11%), but these are delivered with explanation rather than novel analysis. The Balance Theory and WiCyS interviews add discussion of budget constraints and retention metrics, but lack the novelty and depth expected for a 68-minute show.
We found that um, if you look at DMARC which encompasses STF and DKIM because it's the layer that it's a protocol that govern the behavior of SD and uh, uh dkim from the perspective of uh, uh protocol as well as reporting and enforcement we noticed m that it rose from 38% to 80% for the Global 2000 which is awesome.
So um, this is not also from our perspective as we manage domain name portfolios uh across the world. By the way, we're the largest corporate registrar.
The content recycles standard cybersecurity frameworks and talking points. Domain security as a 'missing pillar' is presented as novel but amounts to restating that enterprises underinvest in DNS/domain controls - a known problem. The Balance Theory discussion about budget constraints and vendor evaluation is common CISO narrative. WiCyS's findings on attrition and glass ceilings in cybersecurity are from published research but not deeply challenged or reframed here. Few counterintuitive or first-principles arguments emerge.
at csc, uh, we classify uh, domain security as well as DNS security as the missing pillar in the corporate security posture.
most cyber operators, if you walk the black hat floor, you know, they need tools to prevent threats and deal with, you know, the rising, you know, um, essentially new threat vectors and ways that people can be exploiting. With AI, we, uh, kind of take a different approach to the market.
Guests have relevant operational credentials. Ahab Shraim is CTO at CSC Digital Brand Services managing domain portfolios at scale, providing legitimate practitioner perspective on domain security. Greg Baker (Balance Theory co-founder/CEO) addresses real CISO budget and vendor management challenges. Lynn Dohm (WiCyS executive director) leads a major nonprofit with workforce data. However, the interviews are brief and conversational rather than deeply technical, and no guest is brought in to challenge claims or provide adversarial perspective. Guests are friendly and aligned with the host's framing rather than brought in as independent experts.
Ahab M. Schramm, Chief Technology Officer at CSC Digital Brand Services
Greg Baker, co founder and CEO at Balanced Theory
The domain security report provides concrete metrics (38% to 80% DMARC adoption, 3% to 11% DNSSEC, 87 of 80 companies lacking measures, 88% of homoglyph domains owned by third parties, 16% of malicious domains targeting banking) and names specific attack platforms (FraudGPT at $80/month, WarmGPT, Fraud Wizard AI). Balance Theory cites spending optimization targets but no specific client cases or dollar figures. WiCyS references $127,000 ROI per employee and 32% attrition rate reduction but limited granular evidence. Ahab's discussion of attack types (domain hijacking, typosquatting, homoglyphs) is conceptual rather than grounded in specific incident analysis.
We found that um, if you look at DMARC which encompasses STF and DKIM because it's the layer that it's a protocol that govern the behavior of SD and uh, uh dkim from the perspective of uh, uh protocol as well as reporting and enforcement we noticed m that it rose from 38% to 80% for the Global 2000
there is um, uh, terminology we use uh, on dormant domain name domain names that got either picked up by a labs domain name or um, a domain name that looks like uh, the actual viral domain names.
Host questions are often generic and lack critical follow-up. When Ahab claims domain security is the 'missing pillar,' the host accepts the premise without asking for evidence of breach impact or ROI justification. Balance Theory discussion avoids pressure-testing claims about vendor evaluation or asking for specific failure cases. The WiCyS interview is warm and anecdotal but lacks substantive challenge on retention causation or whether mentorship alone explains the 32% attrition gap. Most exchanges are confirmatory rather than exploratory. Ahab's assertion that most SOCs are 'managed by the least paid person' goes unchallenged.
So let's start. Hub. Right, so Ben and I just got back from Black Hat. AI is all over the place. I didn't see much around domain security. So give us some background on why domain security, why the report, why, why the emphasis?
Well, I mean, it's part of it. I mean, where we really sit is at the program level and trying to really understand if we're going to go deploy budget.
Computed from the transcript - who did the talking, and the words that came up most.
As cyber threats become more AI-powered, attacks continue to rise. Threats can arise from all areas of a company's IT infrastructure, however most attacks utilize a domain name to infiltrate systems. How secure is your domain ecosystem? Ihab Shraim, Chief Technology Offider at CSC Digital Brand Services, joins Business Security Weekly to discuss why domain security is a fundamental blind spot in corporate cybersecurity programs. Ihab will discuss his team's research finding that 67% of Forbes Global 2000 companies have implemented fewer than half of recommended domain security measures. He will also outline the key domain security practices that teams should implement to protect their organization from the risk of domain attacks. Segment Resources: CSC 2026 Domain Security Report: CSC 2026 CISO Outlook Report: How AI Is Reshaping What's Possible for Leaders of The Security Program - Black Hat Interview with Greg Baker, Co-founder and CEO of Balance Theory Cybersecurity leaders are still making high-stakes decisions with fragmented data, static assessments, and market guidance that is often slow, expensive, or commercially biased.
Transcribed and scored by The B2B Podcast Index.
Speaker A: This week we welcome Ahab M. Schramm, Chief Technology Officer at CSC Digital Brand Services, to discuss the results of their domain security report. Then we air two pre recorded interviews from Black Hat USA 2026 from Balance Theory and Whisis. Business Security Weekly starts now. It's the show where we explore the business of security to improve the security of business. Your trusted source for emerging risks, leadership and communication. Get ready for Business Security Weekly. Welcome to Business Security Weekly. This is episode number 460, recorded August 10, 2026. I'm your host, Matt Alderman, back from Black Hat. Uh, joining me for this interview are two of my co hosts. Uh, first, Mr. Ben Carr. Ben, I didn't see you. I knew you were in Vegas, but we never saw each other.
Speaker B: Yeah, I know.
Speaker C: We were like crossing paths.
Speaker D: I did that with a number of people. Uh, it was a long week and a lot. But yeah, again, AI raised its ugly head and agentic. But, um, yeah, fun week out in
Speaker C: the, uh, hot sun of Vegas.
Speaker E: It was really hot last week.
Speaker A: Oh, really hot. I also did not see Jason. He flew in late last night from defcon, so he is not joining us today. But that means welcome Summer Fowler, who has a detached retina and shows up to the show anyways.
Speaker C: Welcome.
Speaker F: Well, thanks.
Speaker B: It's keeping me sane, Matt.
Speaker F: I did.
Speaker B: I had emergency surgery last Wednesday to reattach my left retina. And I have a gas bubble in my eye now, which I have to stay face down for seven days.
Speaker F: It's a, it's, it's an ugly scene, but. But here I am.
Speaker A: So here you are. And Jason, just a little lack of sleep. You detach retina show up?
Speaker D: I. I don't know.
Speaker A: I'm just saying.
Speaker D: Yeah, exactly.
Speaker A: Right. All right, one quick announcement and then we'll get into the interview. Threat intelligence sounds great on paper, but if it's not driving decisions, it's just another cost center. Too many teams are overwhelmed with data and still can't answer what actually matters to the business. At, uh, the Threat Intelligence Virtual CyberSecurity Summit on August 26th. Learn how to turn intel into prioritized risk insights and measurable outcomes. And you probably will hear the term agentic AI SOC at least once, if not a million times. During that session, uh, Security Weekly listeners register for free by visiting securityweekly.com threat intel using promo code CSS26SW. Ahabtram is responsible for the vision, innovation and execution of CSE cybersecurity domain security fraud protection and brand protection solutions by developing focused technology Innovation and go to market strategies. AHUB consistently delivers strategic growth and demonstrates his expertise in facilitating the alignment of corporate business vision with information technology strategies. Ahab, welcome to Business Security Weekly.
Speaker D: Thank you for hosting me. I really appreciate it, Matt. Uh, and thank you Ben as well as Susan. I'm sorry, Samar, for um, joining this lovely talk, uh, that we will be having on domain security, uh, and reporting.
Speaker A: So let's start. Hub. Right, so Ben and I just got back from Black Hat. AI is all over the place. I didn't see much around domain security. So give us some background on why domain security, why the report, why, why the emphasis?
Speaker D: Uh, we um, uh, at csc, uh, we classify uh, domain security as well as DNS security as the missing pillar in the corporate security posture. And the reason why we say that is because most um, uh, Chief risk officers, CISOs, uh, anyone who's in charge of the security operations center focus on um, uh, products that are vendor centric. Inside the DMARC of a corporation, however, the low hanging fruit for bad actors and fraudsters and cyber criminals is always targeting the easy to go get, which is domain portfolios that belong to uh, corporations online as well as DNS. And why go target the harder, uh, protected environment, which is what we classify inside the dmarco, if you will. To look at it from the perspective of firewalling inside the firewall, meaning within the enterprise. That's where all these vendors congregate and they believe that they can cover this area. But in reality, as this uh, domain security report reflects, no, they don't cover it.
Speaker A: The rules just changed. AI, like Mythos now finds and weaponizes zero days on its own. And your patch window just dropped from weeks to hours. One prompt, Titanium Atlas. It scans thousands of endpoints in seconds. It confirms which machines are actually breached, then hunts the attacker's command and control atlas, then acts to isolate, quarantine, rotate credentials and patch every endpoint in real time. Tanium Atlas AI that doesn't just answer, it executes. Find out more@securityweekly.com Tanium yeah, so you went out and looked at a set of domain security areas against the Global 2000. Ah, the results are interesting. I have the report open, um, here as well, but give us a quick overview of what you found when you did that analysis.
Speaker D: Excellent, excellent point, Matt. Um, the domain security report, uh, centralizes on focusing on all the critical or most important, um, uh, security measures that are related to domain portfolios. And by the way, when I say domain portfolios, we're not talking about the online vital domain name that a corporation has. It's a suite of domain names that are globally uh congregated or collected in one portfolio. For example you can have a ah.com and a net as well as a JP which belongs to Japan country code. So this is what we classify as the domain portfolio that belong to an enterprise. A global enterprise would fit this category quite well. So we look at eight fundamental security measures. These are spf, uh, dkim, uh, dmarc, uh, we look at dnssec, DNS redundancy which is very crucial. In fact if I give you some metrics now it will surprise you. Registry locks, CAA records and whether they use an enterprise grade um, registrar or they use a commercial grade registrar. Um uh, for example you can be with a registrar that has 10,000 domain names. That doesn't mean that registrar has all the security measures intact to protect that portfolio which belongs to ML primes. What we found, and these are the significant um, findings of our uh report for 2025. We found that um, if you look at DMARC which encompasses STF and DKIM because it's the layer that it's a protocol that govern the behavior of SD and uh, uh dkim from the perspective of uh, uh protocol as well as reporting and enforcement we noticed m that it rose from 38% to 80% for the Global 2000 which is awesome. You think in terms of that that means there's a good understanding of the market toward DMARC. We also saw that uh DNSSEC have risen from 3% to 11%. Is that good? And by the way all these measurements are um, uh gauged from 2020 when we started this report to 2025 to having 3% to 11% on a critical element of measurement such as DNS tech is not very promising from our perspective but it's encouraging because there is an increase but it's um, a very small.
Speaker A: Yeah, I mean it's a little over what 300% across five years. That's actually pretty insignificant, right?
Speaker D: Exactly. Exactly. Same apply with CAA records. So with CAA records um, this is not also from our perspective as we manage domain name portfolios uh across the world. By the way, we're the largest corporate registrar. When I say corporate not retail uh, or consumer grade registrar, we see what enterprise grade companies do globally um and we understand how we help them to protect these um, uh portfolios globally. Uh the other thing that we've noticed which is very uh, discouraging, there is a decline in DNS Redundancy and that's due to most companies have gone to the cloud and they assume if you go from one geolocation to another, your DNS provider is going to be okay. But in fact no DNS is independent from that geolocation of the cloud because you need another redundant independent. What we talking about? Another independent uh, DNS provider. Why is that? Because DNS is the tool that rules domain names to it addresses online and without it you cannot operate online or even query that particular domain name. Of our, uh, last slide we are seeing that there is ah, a lack of focus. We are uh, classified. As I said earlier, it's the missing link in the security posture when it comes to domain name portfolio management, ENS management and all these threats that target the bohemian fruit on the green side as well as the Venus side.
Speaker B: It's a really great um, it's really interesting because when we've been thinking about domain security, I think a lot of folks think of it as brand protection.
Speaker F: Right. And they really think about it from the marketing standpoint.
Speaker D: Yeah.
Speaker B: For the, for the people who are listening, um, what attacks are getting through
Speaker F: that make this a concern so that
Speaker B: people take it away and think of it more as an enterprise security architecture issue rather than just a of bunch brand issue.
Speaker D: I think this husband mo the problem on his head. Um, brand security is a valid uh, concept. In fact we do provide brand protection. But brand security uh, focuses on who's abusing that brand or had hijacked that brand or uh, is selling counterfeit uh, of products or is an unauthorized sales channel. That's brand protection. However, domain security is the bigger umbrella. In other words, brand protection or even fraud protection falls underneath the umbrella of domain security or domain management where security has to be part of that. So some of these attacks, uh, some as you alluded to, what are these attacks? Look in terms of just the domain attacks. You have domain squatting, type of squatting. You have hijacking of an actual domain name portfolio by going to the registrar and conducting a social engineering attack and gaining access on that particular domain name. Imagine if they went to the registrar and they are able to gain the entire portfolio. You don't want to hack into or penetrate the uh, DMARC of a corporation. Now you own the corporation. All you have to do, just change the DNS record because you have the authority to do so. And that's when multi lock becomes crucial. Or in fact when we say multi lock, you lock the actual changes of the domain names not only on the registrar level, but also on the registry level which is uh, a step above the registrar. In fact um, we have 13 group servers across the world and there are certain registries that are allowed to by icann the regulator are allowed to work with these registrars. And in fact we are uh a corporate registrar and we work underneath that ecosystem. So we see all these attacks, in fact we see phishing attacks, malware attacks. Think about it, when they launch a phishing attack or a malware attack, what is that attack comprised of? It begins with the domain name, it has to and then you associate it with hack machines that are IP centric and you tie both together. Now you have a phishing campaign and of course with AI which is as you mentioned that earlier you came from black hats and uh, everything is centered around um, uh, agentic SOCs or security operations centers. But what are these security operations centers are facing alert fatigue Even if they are receiving attacks with AI. Do they have all these vendors tools automated? Most likely not. And in fact that's what we see most of the time that they buy, you know, corporations buy everything under the sun. Integration is lacking. And I always say this uh, in anything uh, that I write around the uh, security operations center, enterprises which are multi billion dollar enterprises are trusting the least paid person to protect the enterprise. Think about that concept. Just give it some thought. Whether they are using agentic AI or otherwise. I believe the modern SOC or uh, the future SOC should be manned by engineers who are highly paid, capable to do threat hunting. Otherwise you won't be able to track the problem effectively and you're going to end up with case management going from layer one to layer two to layer three. And that's how enterprises get breached because nothing out there has things.
Speaker A: So we also talked about uh, business email compromise you have right. And how internally we've accounted for it. But these tax are now pivoting externally to employees and partners. And again the domain stuff is an important part of those attacks. Right? If they somehow take over the domain or get that domain access, it's more likely for them to be able to leverage these business email compromise attacks.
Speaker D: Correct? So uh, uh some are asked about the attacks and we mentioned just a small subset of the domain attack. But what uh, are bad actors or cyber criminals are using today? They're using platforms. What are these platforms? And by the way these platforms are extremely effective. For example uh, you have a platform called FraudGPT. FrogButy is a platform that is AI powered that composes the entire ecosystem of a phishing campaign from start to finish. And Deployment all you gotta do, just pay uh, about 80 bucks a month and that's it. Now you have it. And by the way, it's anonymized. There are others, uh, other platforms, warm GPT, um, uh, platforms that are one uh, platform which is by the way the most effective platform that we are seeing today. Um, it's a fraud wizard AI. This platform is the scariest platform m I've seen out there. It has the ability not only to compose a phishing attack or uh, a malware attack, but it tells you where are the LLMs, the large language models that exist out there that are uncensored, meaning those platforms that are not well trained and has weakness security controls that allows any person who downloads it to become a victim of that particular attack. So these platforms, the fraudulent platforms by the way, there's massive number of these platforms, uh, we zoom on a few that are the most famous. The ones which uses all these um, hacked IP addresses and they utilize the proxy services to hide these campaigns. And one last thing about um, this particular topic. You can have um, the most effective security operations center. That means they have detected the threat or maybe been able to predict the threat at all. Depends on the security operations center. By the way, the prediction models don't even exist in security operation centers. And if uh, they do today, they're very primitive. I expect this to become much better in the next upcoming years. Well, think in terms of the problem. Okay, we detected the problem as if we detected where the fire is. What do you do to extinguish the fire? And that's the trick on the Internet. So you have to have a vendor who will provide you not only the management of the actual domain name portfolio, but also the ability to take it down. Now there are companies that claim that can automate the entire takedown process. What they are not telling the world is that they're automating form filling of that takedown process. But the takedown process must have this component. Has it been taken down? And if it went down, can it come back up? That means that there is monitoring and to take it down you need verification, which means indemnification. And indemnification in our business is a very crucial issue because imagine if you shut down one of the big entities today, uh, multi billion or trillion dollar entity, um, uh, you know, you take it down by mistake. And this could happen by the way, it happens all the time with these automated, fully automated takedown processes. So we believe you can automate about 90% of it of the last 10 you have to validate and conform and unfortunately with our technology and based on IPv4 you have to have a human being to go validate that. And the validation is done with tools by the way. It doesn't need to be um, confirmed. For example each one. Did the ISP or the web hosting provider take that concept back? No. You can validate it with SOC tools that will allow that engineer to become proficient.
Speaker A: So huh, when I looked at the maturity, uh, I wasn't surprised on the regional side, right. Like APAC behind from some of these domain security things. One of the things that surprised me though was the rating, the ranking of banking in their domain security posture. Because I would have thought they would have been like top on the list. Like they've been regulated for a long time. It's really important to make sure that you're, when you go to your online banking that it's secure. I was shocked they weren't in the in the top. Is that a trend you've seen in the past or is it recent that that shifted? Because I would have thought they were way more mature in this area.
Speaker D: Uh, I totally agree with you there. Um, in terms of uh, the financial sector in general, they're probably the most uh, secured sector if you were to compare them with other system. But in reality you will see scary um, data at 80. For example, out of that data we found 87 companies don't even have these security measures while they believe um, they are financial companies while they believe that they are secured. And why do they have this belief that they are fully secured? It's because of that financial institution have bought every vendor under the sun and they have security audits and security audits give you the belief that you're fine. That doesn't mean they are not secure. They take good security measures. Uh, through employing good security controls. However, we expect the adoption rate to be higher and unfortunately in this case, and if you look at um, this whole thing globally, the adoption is not as good as we think. In fact, if you look at uh, a threat, for example uh, homoglyphs, uh, which is an attack on domain names, we found that um, a huge number of These attacks, or 88% of these attacks, uh, the homoglyph attacks have um, more than 60% of those are owned by what are owned by potentially bad actors. In fact, the 88% that we are referring to are dominions that are owned by third party. So think about it. Whether it's a uh, semiconductor, uh, vendor or company or a financial company or a unicorn company, that we referred to in this report because there's a heavy focus on AI the adoption of these security measures does not equate what we should see when it comes to how these domain names are being owned. To have 88% of the homoglyph based domain name being owned by a, uh, third party is quite alarming to us. It shouldn't be the case. Owning it by third party means what? It could be a lookalike domain name, it could be a sound like domain name, it could have fuzzy logic associated with it, it could have typhusquatting, uh, and the list is huge. So why is it owned by a third party? Is it a domain name that the company lacks meaning, dropped so somebody picked her up? You should question, and that's where the security operations center should go. Why did this domain name is owned by this third party and who is that third party? And by the way, that's where vendors, um, start making mistakes when it comes to domain names that are not active. In other words, let's say there is a lapsed domain name. A corporation decided to lapse a domain name due to cost save. All right? That domain name got picked up by a third party. A third party didn't activate the domain name, in other words, just sat on it, either put a PPC on it or m not even connected to uh, an IP address. Who's monitoring that domain name? And uh, what if that domain name gets weaponized four or five months later? And that's what we see. This is what we see is that cyber criminals buy these domain names and they sit on them and they don't buy one domain name or two. They are in the domain name. Google purchasing domain names, dropping domain names, watching the target. And remember all these attacks are targeted attacks. So they go to an enterprise and they watch it. And as soon as that domain name is dropped or there's a chance to mimic that domain name to create a lookalike domain or a domain name that could have an extension. Uh, for example, example.com is the domain name. You say example-one.uh com so the recipient, the average user does not have the intelligence to go decipher that domain name. They'll think it belongs to that particular company whether it's an online banking or whether it's uh, an E commerce company that could be deceived, meaning that the user is deceived that this is a legitimate, uh, company out there and where they have landed on that website is a legit website or in fact it's not.
Speaker A: Yeah, and I Noticed again, back to the banking example. Over 16% of all malicious domains are targeted at banking but yet their maturity is not as high as other industries which to me creates this really un, um, um, interesting but not really like the scary moment for, for banking is you're being targeted a lot for malicious domains. Your domain security is not in the best shape. Like that just that spells trouble to me somewhere.
Speaker D: Well said. In fact um, there is um, uh, terminology we use uh, on dormant domain name domain names that got either picked up by a labs domain name or um, a domain name that looks like uh, the actual viral domain names. Who are the viral domain names? The critical domain name that the company rely on. Let's say if it's online banking, that means online banking dot com, whatever the brand name, plus whatever is added to it. Now remember there's a lot of uh, techniques you can for example in quasi domain name, just substitute an O with a zero. Most recipients will never catch that, not because they're not smart enough but it will be very difficult to go decipher who owns that particular domain. And uh, by the way uh, these uh, uh, fraudulent platforms uh, that I referred to uh, earlier on this um, uh discussion, they do give you the domain name and multiple domain names for you to launch a phishing or malware campaign. They give you the choice which domain names you would like to activate and those domain names belong to that enterprise. All you have to do, just list the name of the enterprise and they will give you the domain name. They are that good. They are so equipped because they do this for a living. It's a 247 ecosystem that is targeting enterprises in order for them to get the best ROI on their investment. So their objective is to dust out the terminals they want to steal. So how they want to conduct the theft, they have to do it right and they have to have a proper return on the investment which is the platform that they have invested in in order for them to get uh, the best results for themselves.
Speaker A: So um, I listened to this podcast and I'm like ooh, how do I know that I'm good on my domain security? What are the first three things companies should do to get their domain security posture in shape?
Speaker D: Definitely first I would, if you are an enterprise company, please, please, please look at uh, enterprise grade registrar. These are the most important registrars on our ecosystem for me.
Speaker E: Why?
Speaker D: These are the registrars that are fully audited that they are committed by uh, policy to have their teams train on all the tactics that are being used which are the Malicious tactics. From social engineering to anything that could equate to a threat vector. This is part of their DNA. So an enterprise class registrar versus uh, a registrar who we don't recommend consumer or retail grade registrar. The second thing, please mark your viral domain name. How do you know your vital domain name? The critical domain that the corporation operates on my register website, their communication systems, anything exposed to the outside of the village which could pose an external threat to that corporation. Please look into a monitor. Monitor, monitor. You got to monitor your bulimo, you got to monitor your DNS infrastructure. And most importantly, I recommend haggling have a takedown, um, uh, apartment with you just in case. What if there is a 30,000 attack process happening on that enterprise? Meaning the campaign is attacking by 30, 40,000 machines. What are you going to do? You need a takedown, um, partner who's not going to go after every. The 40,000 or 30,000 I refer to, they're going to go to dismantle botnet and that's the critical piece. So you don't want to come and call. There is a fire, but I have a fire extinguisher with it and these are the most critical elements. Now as a first step now of course we reckon on DNS, uh, redundancy. We have multiple recommendations but the top three, enterprise grade registrar lock your vital domain names and make sure that you monitor and having a takedown partner, if you do these things at least you are somewhat protected to go and be operating online with some care. Now of course inside the firewall they are already taking care of these measures by uh, applying a security policy, having audit controls on semi annual or annual basis and the like.
Speaker A: Ahab, thank you so much for joining us on Business Security Weekly.
Speaker D: Thank you very much uh, for hosting me. I appreciate it very much and uh, look forward uh to meeting you in person.
Speaker A: Thank you for joining us. Stay tuned as we air two pre recorded interviews from Black Hat USA, 2026 from Balance Theory and Whis. We'll see you next week on Business Security Weekly. Security teams are overwhelmed. In 2025, more than 48,000 vulnerabilities were disclosed, yet only a small fraction pose real risk. Most organizations remain stuck in a reactive cycle, responding to everything without the clarity to know what actually matters. Origina, a global provider of independent software support, is built on one principle, giving organizations control over their own IT Roadmap risk and critical systems. Optus by Origina is a predictive intelligence service that brings that same approach to security. Helping teams predict risk, validate what matters and act with confidence. Visit securityweekly.com origina for a conversation with a security expert today.
Speaker C: Welcome, um, to Black Hat 2026. I'm Mike Shima. Joining me today is Greg Baker, co founder and CEO at Balanced Theory. Thanks for being here.
Speaker E: Thanks, Mike. Thanks for having me.
Speaker C: So we're just kicking off the morning for the first full day, I think of Blackout. How's it been going for you so far?
Speaker E: It's been good. Uh, you know, I love Black Hat. Every year you get to see all the people you've worked with for 20 plus years. It's like a, ah, high school reunion every year. Um, but it's, it's been good.
Speaker C: It's been. Yes, it is that good family reunion type of feeling.
Speaker E: Exactly.
Speaker D: Yes.
Speaker C: And so one of the things that I see every year is just, what are the different vendors? What do they do? What are they? A little bit cookie cutter, let's say. And every this year everything is agentic, for example, unavoidable. I was looking at balance theory and yes, there's AI involved here, but it's actually a different problem that you're focused on. It actually is pretty appealing. Tell, tell us about a bit about that.
Speaker E: Yeah, sure. So balance theory, we're kind of, you know, most cyber operators, if you walk the black hat floor, you know, they need tools to prevent threats and deal with, you know, the rising, you know, um, essentially new threat vectors and ways that people can be exploiting. With AI, we, uh, kind of take a different approach to the market. So complementary. We're focused on really the business side of building cybersecurity programs and managing the portfolio. So, uh, it's kind of the layer on top and helping folks navigate the constraint that is universal, which is the budget. So, you know, ultimately every enterprise is a bit different. It doesn't matter if your budget is $100,000 a year or 100 million. Um, it is a constraint that you have to work and operate within. So it's a challenge for organizations to build kind of the perfect cybersecurity program for their organization. And navigating, Navigating that constraint.
Speaker C: Yeah, and there's, and you said right off the top there too. So many orgs just have tools, they buy tools and often that's that dramatic pause because they buy them and they sit there or they're underutilized and they're not helping. And I think that's where you're actually focusing on, you're paying attention to.
Speaker E: Well, I think it's part of it. I mean, where we really sit is at the program level and trying to really understand if we're going to go deploy budget.
Speaker A: Right.
Speaker E: It's a, it's a very, you know, precious resource for an organization. From the idea stage of understanding why an organization needs something to actually making the investment into the implementation and ultimately value phase of the life cycle. Um, that is more than just the security team. That's a piece of that. Right. You're, you're ultimately having to navigate complexity across your IT partnerships, legal, finance, procurement, vendor management, and then getting everybody on the same page of how they're going to measure these different areas of value that come on the back end of it. So of course shelfware is always a point of that. But you know, the vendors that you're investing in today are probably going to look a lot different next year when they're here at Black Hat, uh, not just from the value that they're providing to the organization and their capability, but their cost models, their scalability, all those different factors. So, um, we actually think that the program isn't this annual exercise. Let's set a budget and go and try to execute against that. It's really a living, breathing part of how you think about security operations.
Speaker D: Yeah.
Speaker C: And I want to come back to that aspect of measurement and metrics in a second. But first, just talking about those programs, if you're clearly talking to the business aspect, the CISOs as well as other leaders, in addition to where all of the oxygen is taken up with Agentic and LM and AI, this, what are they, Are they struggling with something that is surprising to you or what are they actually focused on right now?
Speaker E: Yeah. So I, you know, ultimately, if you think about just any tech wave life cycle. So we've been in cyber for a long time. You know, first it was cloud and now you're hearing about AI. So there's always trends and over time, technology goes through waves of commoditization to bleeding edge and navigating that kind of process. So I think the biggest thing now is as the landscape is constantly changing, um, we now have this new powerful opportunity to leverage the same AI that's used to enhance security operations, to build a layer of understanding the program and understanding the decisions and being able to execute and monitor the market in more real time to navigate that change. So I think that's one of the biggest things that is the point of conversation today is not just what do we get to protect the business, it's how do we fund it, how do we build a coalition of the willing across the business, how do we navigate the complexities of the market? How do we get corporate buy in? Um, and more now than ever, uh, the CISOs are really evolving into these fiduciaries and you're seeing it's not just about security, it's about it, it's about go to market. They're really involved in a lot of those aspects of the business.
Speaker F: Yeah.
Speaker C: And I think the, I wanted to ask too about when you say understanding, it goes more than just do we have shadow SaaS or shadow IT or shadow this. That's getting good insight as well as just how many seats do we have, how many people are using our tools. But I think you're kind of hinting at more that there's something that goes beyond that understanding. Talking about like the program and governance. I think, yes, teach that out for me.
Speaker E: Let's unpack that a little bit. So, you know, if you think about, I don't know, a uh, big relationship, like the uh, big guys out there, the crowdstrikes, the Palo Altos, the Zscalers of the world, you know, shadow it is one thing, but there's a lot of leverage in understanding how to maximize the value there and build the partnership and get to the right size within that budget that starts way, way before 30 days on a renewal cycle.
Speaker B: Right.
Speaker E: And most CISOs and security organizations are busy, you know, operating the security program. So. But being able to uh, shift that decision not just 30 days before the renewal, when you're trying to figure out, well, what do we still need, what's changed, you know, what do we need to enhance, what do we need to buy? How does this now overlap with existing capability? If you can shift that decision much further left in that programmatic life cycle and kind of be always in an operation mode, uh, there, not only are you going to get better value out of the vendors, so that kind of governance around budget deploy when you actually make the investment, but you're also going to have more flexibility in how you think about the governance of risk, buy down and control coverage. Right. So ultimately everybody's trying to maximize the maturity of their program within that budget constraint. It's kind of like going to the gym, right? It starts with good hygiene day zero instead of, you know, um, getting back from vacation and going one day and expecting, you know, one day of eight
Speaker C: hours in the gym.
Speaker E: That's right. Eight minute apps. Right. So exactly.
Speaker C: No, well, and that's gotta be. There must be an appeal there for the CISO as well. The sense of we have our framework here's how we can map the controls that we've purchased, but also that we're deploying, how has that changed? How has that benefited CISOs, or has it made their conversations different with, uh, the cfo, with the other business leaders?
Speaker E: Oh, absolutely. So I think being able to actually justify the business through business terms, everybody's trying to navigate the market. Um, it starts with understanding the enterprise. Because when you're navigating the market and you're trying to go back to either fund something or build a business case or justification, being able to interpret it and put it through the lens of why that matters to the business. So rather than just saying, hey, we need to buy security technology xyz to prevent threat being, say, hey, uh, we're a Fortune 100 bank.
Speaker B: Right.
Speaker E: And we need, based on our regulations, our control policy, policy, here's our greatest aspects of risk. And by deploying this technology, we're going to be able to ultimately do something through the context of our program, what we've already bought, what we've already invested in, and close these gaps. And by being proactive on that and being, uh, that kind of proactive, uh, fiduciary, a lot of the times that CISO and CFO relationship becomes much closer. So they know that they're coming to the well because that good hygiene often leads to, you know, getting better deals and bringing operating costs down. So being able to pull forward things that are in their roadmap and fund them out of existing budget versus every time something new happens, having to go back and ask for more. So it is that connectivity across the business. That's one of the major outcomes of, you know, taking that level of governance approach.
Speaker C: And ideally, one of those, one of those aspects of that budget would be this is a budget that actually reflects our needs. It reflects what we're investing, what we care about.
Speaker E: Exactly.
Speaker C: With that said, um, I'm curious. Let's bring more AI into this. You're, I want to say, you're almost uniquely positioned to see where people are spending money in the sense of that's what they truly care about, or at least what they spend the money on. How are things changing? How is that?
Speaker E: Ah, yeah. And so for us, it's really kind of unpacking. Yes. There's. You can go and you can ask the question, well, who's buying what at what price? For us, it's more the context of why the investment was made, which is the value. Right. So if you think about different verticals, different industries, there's no, you know, cookie cutter Perfect set of security plug in technologies. There's ultimately almost infinitely amount of ways to be successful, but we're able to look across trends and say, well here's the decision logic. So rather than just you know, top five bank or top five energy company bought XYZ at ah, this price and they're buying this tech, right? It's, hey, they're making a decision to invest in AI governance and this is how they're thinking about that program. This is how capital is deployed into the vendors that they're selecting and total cost of ownership. On the implementation side, this is how they're negotiating with vendors to come in and help them be successful and then on the other side helping them be accountable to, you know, ultimately what they decided to deliver on or the ROI on the other side of the fence. So I think it's that conversation where we can really draw important insights because you can run market reports and get, you know, general industry benchmarks, but unpacking the why behind the investment decision is really what helps people create that lens of what, what matters to me as a business and what, what can I learn from what others are doing.
Speaker C: And I'm curious there too because especially looking at a uh, conference like black hat, looking at conference like RSA that has massive square footage of just vendors after vendors after vendors. Yeah, there can be some, let's, let's say just perverse incentives or that people are buying, buying a vendor because everybody else is buying that vendor. I suppose you probably can see that. I'm curious, have you talked to CISOs and see how they're reacting to that or how they can point to this, your, your insights that you're providing them so they can say we are successful because of this. Here's the positive impact we're getting.
Speaker E: I think that's that. I think if you walk the black hat floor, I mean every vendor is going to be solving a very important problem just for that own domain. Um, I think that the key and what we're really focused on at balance theory, is first know the enterprise, right? If you can know the enterprise and the needs and the contracts and what's been deployed and what the relationships look like and how they're achieving, you know, operational success, then you almost are able to put a, uh, shade of sunglasses on as you walk the floor and highlight, well, what's going to actually make the most sense in the context of my program. So when you can know the market and know what's changing with the different vendors and what their products are and what their Cap capabilities are, you know, just going out and trying to use uh, Claude or ChatGPT and ask. Give me the top five vendors, speak to suppliers. They're all going to have some inherent just limitation on what their purview is. The best way to ask that question is through the lens of the program. So I think that that's where the most valuable kind of context comes into place to help navigate. Hey, is this trying to fit a square peg in a round hole? Because I'm getting a recommendation from somebody in the market and you know, maybe there's incentive alignment. Um, and it all just starts with really understanding the program and what's going to be right for the organization.
Speaker C: I'm a huge John Carpenter fan, so when you see the sunglass, I'm thinking of they live walking through and seeing Bye.
Speaker E: Who knows, maybe it's on the product roadmap for us.
Speaker D: That would be fun.
Speaker C: But I want to. Again, I wanted to dig in a little bit too because you said, you know, you could just ask Claude as whichever, whichever chat bot you want to. Am I spending enough? That's probably, um, I think I've oversimplified that and it's going to miss context. Tell us a little bit about what is the context you pull in and how do you, how do you add that intelligence, right, to help the ciso
Speaker E: to us, there's, there's really kind of. And it's, it's a, it's changing constantly, right, in terms of how people are maximizing, optimizing around context. But for us it's not just, you know, dropping an enterprise agent into, um, you know, an organization and saying, hey, let's connect it to, you know, know, our contract management system, our Koopa and then, you know, or SharePoint where our, you know, our strategy docs or Jira, our ticketing system and then just querying it like at ragtime, right, because then you're going to get kind of mixed context answers and how that works. You might experience context wash and you know, some of those buzzwords around what's happening in AI? For us it's more can you understand and map the relationships? So how does this data come together? What does it mean? What's the reasoning behind it? And can you leverage AI in a way that makes the most sense, where it can reason through the context of the organization? So I do think that you'll probably see a lot of that on the black hat floor today. People thinking about, hey, how are we not just using this to query data fast and sort through noise but how are we really using it to unlock enterprise context? And for us it always comes back down to the why. You know, that investment decision, that's the point during the year that you can ultimately impact your budget positive or negatively. A renewal, a new investment, you know, sunsetting a technology. And we really want to understand the intricacies of how that decision was made, what the security operators were thinking, what existed out on the market, how they partnered with it. You know, how Ben or Larry or Jane on the team went through the POC evaluation. And then on the other side during implementation, what worked? Did it work as advertised? Uh, did we have to extend it? Um, you know, is it hitting SLAs? So all of that, you know, when you go ask a question is really what, what creates the right context to know what's going to be the right solution next investment event time where I have to navigate impacting the budget and
Speaker C: that feels like touching on that. Before I forget, want to bring in that idea of measures of success or metrics. And you were describing a good list of qualitative aspects of that. Is there something that you would add is just like, here's something that the CISOs should think of or that is maybe even a surprise to them that this can unlock for them to say,
Speaker E: here's what success can look, no, it's great. I mean so you know, there's kind of baseline metrics from like gaps and overlaps and cost per control and then benchmarking kind of pricing scenarios on, hey, if I'm in this shop, you know, is 40% of my budget going to one bucket versus the other or underinvesting? So you can look at it through a large variety of different ways. For us, what we're really trying to look at is maximizing capability and maturity against budget, uh, how much it's going to increase or decrease. So am I able to extend that and get more value and increase the maturity of the organization, um, without having to increase that year over year? Now of course there is always going to be opportunities to need to do that, you know, with emerging threats and go through that. But one of the things that we measure our value in to our customers, so we track spend under management per client and our goal that we try to go through the uh, first thing you do when we onboard you is put a one year plan in place and say, look, here's the optimization target and it's not in threat reduction or risk reduction or some of those harder to manage metrics. It's in just generally, you know, what's the budget target now? Understanding the leverage that we can hit to, uh, maximize against the plan. So being able to talk in dollars is, um, you know, a good thing for CISOs to be able to do.
Speaker C: Talking dollars is good. And especially to rift once more on they live. There's a whole like five minute long wrestling scene and very much the CISOs are wrestling with their budgets and their success.
Speaker D: Exactly.
Speaker C: I think this works.
Speaker E: Yep.
Speaker C: Unfortunately we're out of time to recreate that. So you'll have to come back to five minutes and recreate that wrestling seed.
Speaker F: Thanks, Greg.
Speaker D: Absolutely. Thanks, Mike.
Speaker C: I appreciate it.
Speaker E: Thanks for having me.
Speaker C: Thanks everybody else for joining. To learn more about balance theory, visit securityweekly.com balancetheorybh and for all of our Black Hat 2026 coverage from Cyber Risk alliance, check out securityweekly.com Black Hat stick around. We'll be right back after this break.
Speaker A: Zero trust is clearly the future as threats get faster, quieter and harder to detect. But implementing it shouldn't disrupt the business. Threat locker enforces default denied execution in a way that remains enterprise ready, scalable and operationally clean. Unknown software is stopped cold. Trusted apps stay contained and drift is locked down across the environment. It's zero trust that works in real enterprises and prepares you for the threats ahead. See why CISOs are adopting it at securityweekly.com threatlocker this episode is sponsored by Microsoft Edge for Business, the browser with built in protections for Microsoft 365 customers with employees using AI and web apps. More than ever, Edge for Business helps you stay in control, securing sensitive data, protecting against shadow AI and stopping threats right in the browser. You don't need to worry about added extensions, new tools or extra costs. It's the secure enterprise browser you already have built for the era of AI. Visit securityweekly.com edgeforbusiness to learn more.
Speaker F: Welcome to Black Hat 2026. I'm Jackie McGuire and joining me today is one of my my favorite people in the world, Lynn Dom. Uh, Lynn is the executive director at Women in Cyber Security. Lynn, good to see you.
Speaker B: It's so good to see you, Jackie. This is my favorite moment of the day to get to catch up with you. How awesome.
Speaker F: I know I haven't seen you since the whis's conference in dc.
Speaker B: I know it's been too long. We have to get our time together closer and closer.
Speaker D: I know, I know.
Speaker F: I was like I when we were going through who because we get to like fight over who gets to interview which people and I was like I will die on this hill. I get, I get. Lynn.
Speaker B: No, I love it. And I dressed appropriately. I know you stood up for you. I know I had to get pull up my wilds blazer because I knew who I was meeting up with.
Speaker F: Yeah. So when we were at WHIS a few months ago, a while ago now, um, we were talking about, um, you had just completed this study, um, kind of talking about talent and the benefits of being in WHIS and all of this stuff. So how, how has that gone since you guys have come out with the study and kind of started actually quantifying the value of whis?
Speaker B: Oh, well, I mean, it's going really good. It's really nice to have data and quantify the value of WHIS. We've been a nonprofit since 2019, and in 2023, we really started taking a look of what is the impact that we're making in the workforce. And then to be able to come up with the ROI of resilience, which is really interesting because right now all we're talking about is resilience and recovery in such a time of, you know, unknown territory with the tremendous growth of the rapid digitization that's going on right now. So we're here for the workforce and we're here to show employers that there is a return on investment when you partner with third party organizations like whis. And, you know, it's been really great just to not only be educated on it, but also be flexible and nimble with what the workforce needs are right now. As you know, the workforce is going through a lot and, and we could dive into that a little bit further, if you like.
Speaker F: Yeah, I think it's something you call the cyber talent paradox, right?
Speaker B: Yes.
Speaker F: What is that?
Speaker B: Yes, Well, I call it the cyber talent paradox because I was like, oh, gosh, there's so much going on here. So, you know, back in the day, we all spoke about it when cybersecurity, like, come on in, get into a CyberSecurity career. There's 4.8 million unfilled jobs in cybersecurity. There's a place for you. Well, now we're at this, this threshold of we have a surplus of talent at early career, we have AI disrupting those junior roles, and we have a deficit of skills in mid career and senior position individuals. And so it's not necessarily this workforce gap, but it is a skills gap.
Speaker F: Yeah.
Speaker B: And organizations are saying, get IC, Isaka, ISC2GAC. You know, they're all speaking the same language of, um, there's this skill supply ratio that's going on here. And so for us, we're really focusing on what are those skills necessary to be able to be the builders to, you know, um, you know, we have the necessary competencies to learn and grow on the spot, you know, when the adversaries are doing their adversarial things.
Speaker F: Um, and no, no, no shortage of ambition on that side. I think we need to learn from the adversaries. Right. Is it seems like they're, they're eager to learn new things. So we need to keep up with that.
Speaker B: Yes. And keep up with that skills and be able to continue to, to build the skills on the spot. So, uh, we're, we're constantly looking at the workforce as, as you know, with whis, we're here to be looking three to five years ahead and to be thinking about what are the workforce needs and how are we investing in the most valuable asset in cybersecurity and that will be its people. And so we're looking at the rapid digitization of the new technologies, the expanding regulatory requirements, the deeper integration of cyber and many different elements. And then on top of that, we have this long term demographic constraint of an aging population, lower birth rates, lower immigration rates, um, a falling labor force participation. We all know that less and less people are going off to college to be studying this. And so it's narrowing the pathways and it's creating a very structurally fragile workforce. And so we need to be focusing on what are the skills necessary now and how could we, you know, continue to build the skills of the future in real time.
Speaker F: Yeah.
Speaker B: And so that's where we're at right now. And it's, it's, uh, you know, the data and the studies are showing that it's a strong, strong return on investments for employer partners to be on board with the WHIS organization because we're able to fill a void that they're not necessarily nimble enough to do at this time.
Speaker F: Yeah. And so I, I know one of the things that's always been interesting to me is when I go speak at colleges, there's close to gender parity there. Right. So there are many, many women in college and then in the very early stages of security. But I think your research has shown that there's a drama drop off as women reach mid career, like five, seven years in. What causes that?
Speaker B: Well, prior to us doing research on it, we would, we would always base it on hearsay of what we're hearing. You know, a lack of mentors, a lack of career growth and Advancement and all of that. But we really wanted hard data. And so our mission is to recruit, retain and advance women in cyber security. But in 2023, we kind of peel back the layers and we're like, we could recruit fruit all we want. We do a very good job of it, getting people into cybersecurity. But if we really want to make an impact in the workforce, we have to understand what is the retention and what is career growth and advancement. If we could solve the retention issue, which is what our data is showing. Yeah, when you resolve, like WIS members have a 32% lower attrition rate than non WHIS members. That's money in employers park pockets when they, when they encourage their, their teams to be a part of the whis, or organization. But we wanted to peel back the layers, understand retention, and we partnered with Elyria Research to do that. And how they did it is they, um, quantified the experiences of exclusion to identify the state of inclusion for women m in cyber security.
Speaker F: Yeah.
Speaker B: And so in late 2023, early 2024, some really big, three big key takeaways came away from that. One of them, that women in cyber were in a glass ceiling at around six to 10 years within their crew. The second one is a very high barrier for women in cyber specifically, not other industries with a lack of career growth and advancement opportunities. And that was really interesting to Illyria because they do this across many different industries, and they never saw it as high as it was for other than women in cyber. So we kind of earmarked that and paid special note. And then the third thing is that women in cyber, um, are five times more likely to have experiences of exclusion come from their direct managers. So in 2024, this was revolutionary. Like, this was really great data, really good information. People were very eager to receive it. And I spent a lot of time doing many interviews and conferences and presenting on it. But one time after one conference, an individual came up to me and asked me, well, if it's a, uh, glass ceiling, then it's a performance issue. Women aren't capable of career growth and advancement at that.
Speaker F: Yeah, we just lose all, all of our brains after five years.
Speaker B: After.
Speaker F: Yeah, it melts out of our heads.
Speaker B: Because that makes sense, right? It just melts right out of your head.
Speaker F: Only your change.
Speaker B: You're right. We're like, oh, my gosh, how much more do we need to prove here? You know, But I heard that now it's like, well, uh, now I want to know how are WHIS members performing? You know, from non WHIS members. So we did a skills assessment and we're killing it. We're outperforming non WIS members. Gender, not even including, included just WHIS's members, non WHIS's members and you know, and, and uh, you know. So it's, it's been a really interesting journey because we're always talking about now skills based advancement, merit based advancement. We're like right on, bring it on. Because we've been ahead of the game, we've known this data and skills are the ultimate equalizer. But now we're challenged with how people are utilizing these assessments. Which uh, is what led us to do the ROI of resilience report report that uh, we released during the WHIS conference.
Speaker F: So talk more about the resilience piece because I think that's really interesting. So what is, what does resilience look like?
Speaker B: Uh, uh, it looks like keeping your workforce and it looks like we having all the wraparound services that, that add up to the return on investment. And so with the, when we partnered with four one Insights we were able to identify big key indicators that are good for, for talent for uh, individuals to stay. We had some nuggets of information like um, WHIS members have that 32% lower attrition rate and when you're a part of WHIS you have quicker um, hiring time. So it reduces that cost associated with hiring. So those are all good things. But when it comes to resilience it's about what are those wraparound services that actually has your workforce stay to avoid burn, to have career growth and advancement and also to build a team that you need necessary. So when we're looking at skills based assessments, it's not just doing the assessment with your teams and then tucking them away and being like that's good information, it's actually utilizing it as a tool. So as a tool where you could track career growth, where you could track where do you want to invest in training and then also be able to track the other um, indicators of, of career success which is your network. You've been a big advocate of that Mentor mentee. We were just talking about that earlier. Um, having a um, mentor and whis, um has all these encompassing services that we provide to make sure that we're investing in the right people but utilizing the tool wisely. Not just a skills assessment, tucking away, actually driving it to build the growth, cover the gaps and your skills and then incentivize it or give stretch assignments based on it and you know, wrap around bonuses in a structure that really makes a value or difference for your team.
Speaker F: Yeah. So are there. I would love to believe that the industry will just do the right thing because it's the right thing, or that they will foster inclusion and equity because those are good for humanity. But is there a financial reason to create a more equitable workforce?
Speaker B: Right there is, because that's really the
Speaker F: only thing that influences behavior and business at the end of the day.
Speaker B: And that's why we did the ROI of Resilience, because it was like, okay, if uh, we spoke data to you and now let's speak dollars.
Speaker F: Yeah, yeah.
Speaker B: And so with our report, and everyone could find it, you could download it from our Whisis website or go to Four One Insights. Um, it's a return on investment of $127,000 per employee per tenure because you're shortening the hiring time, you're increasing the retention on the workforce and you're creating just a happier, more innovative, more inclusive, more career growth and advancement. Individuals aren't getting bored at mid career, they're actually being invested in and therefore they're paying it forward to the employer that's paying it to them.
Speaker F: Yeah.
Speaker B: And so there is that. You know, we used to always, always say like the old saying, I don't know if you've ever heard of it, like it cost $30,000 to hire, $300,000 to fire.
Speaker F: Yeah.
Speaker B: Well, you know, that was just like a blanket statement that would be said here and there. And we're like, no, we want to know whis, like specifically. Uh, and that ROI of, um, resilience for us is to $127,000 per employee per tenure.
Speaker F: Yeah.
Speaker B: So it's fantastic news for everyone. And we're really proud of, of the information. We're really proud of the organization that we have that helped bring that to life.
Speaker F: Yeah. Well, you know, thinking about, you know, saying that WHIS's members have over 30%, like higher rates of retention. For me, one of the big benefits of whis, the network is if you are a woman who works with mostly men and you need life advice about something, there are just some nuances that if you don't, you don't go to a place that is intentionally curating a group of people who look like you, who have similar life experiences, it can be hard to get the level of detail of life advice. You know, like without other women to ask, like, hey, how did you navigate this thing? Or this perception or this, you know, you had your second or third kid and you're trying to balance like, you know, because, uh, I always say, like, when a guy takes the day off to take his kids to the doctor, it's like, oh, my God, he's such a good dad. Whereas when I'm like, hey, I need to take the day, it's like, okay, uh, yeah, go be a mom again. Right? So when you can talk to other women about, like, hey, how did you navigate this thing? Or, like, how do you message this thing? Or if you're dealing with. I think you're like, I was blown away when we were talking about this a few months ago about the women, uh, being five times more likely to experience, like, exclusion and bullying and things like that. Like that. Because I've, I've dealt with that, right? And so if you're talking to other guys about that and they're only experiencing it at 20%, the rate that you are, there's almost a level of like, okay. But when you talk to other women who've actually been there, it's much easier, I think, to get advice from people who've actually walked in those shoes. And I don't think this is like a. It's not like intentional ignorance on men's part or anything like that. It's just that experience are different. Right. And just like, you wouldn't go to a tennis coach to ask him how to improve your, like, putting game and golf. Like, you need to go talk to people who've actually been there. So I think when you think about it more deeply, it makes a lot of sense.
Speaker B: Yes.
Speaker F: So how. Let me ask you, like, with. With. As rapidly as things are changing, how do you see whis evolving over the next few years to continue to meet these crazy, like, crazy changes and technology and career path and things like that?
Speaker B: Yes, well, that's a very good question. And we're thinking about the problem continuously ourselves. So in the next three to five years, we are really focusing on building builders, making sure that we're supporting the skill sets that are necessary. We want WIS members to be indispensable in the workforce. So it's not only leadership development, but it's also really importantly those technical skills. And so whether early career, mid career, or senior positions, we're always building technical skill sets and leadership development. Hey, and earlier today, I was just approached by someone that said that she was in the AI Learning series last year. It was a new program last year. She said it completely. It got her into the job that she's at today, and it, like, changed her entire life because of that AI Learning series, like, that was just a piloted program of. Let's check. Let's check this out within her community. So, thankfully, being a nonprofit, we have to be very flexible, very nimble. We pilot programs when we have the data of success and the evidence of success and the funding to make it happen. We scale it and then we sustain it. And so we're able to do that. And if we pilot a program where we just don't see the results that we see, and we're like, okay, now into a different program, and that's what this is going to need right now. The workforce is ever evolving, super fast changing. We have to be as nimble as the workforce needs and demands. And it takes us to have an incredible group of people like you doing the good work that you're doing with us and to be able to, like, rapidly roll out something and be able to support our community in that capacity. And also what you said about mentoring, and just in general, you know, an individual that's a mentee is five times more likely to get promoted, but an individual that's mentoring, they're six times more likely to get promoted. So our mentor mentee program is designed by someone that's just a year or just, you know, uh, mid M career person will be with a senior career individual. And it's designed in a cohort to continue to develop that community. And. But we want the experience for the mentor to still be very real, very fresh. We want raw, genuine information. We don't want, you know, senior professionals mentoring early career because their experience is so different. Uh, you know, anyone over the age 45 should be mentored by someone under the age of 30, because their lives are completely different. They're living in a different workforce than anyone over 45. So we have to have reverse mentoring, too. So there's a lot going on, and we're just always assessing what are the needs, what kind of programming efforts can we roll out. But always cultivating the community wrapped around it, because that's super, super important and critical piece.
Speaker F: Yeah. I think if you, if you're at advanced level in your career, mentoring is one of the best things you can do, because sometimes you just navigate on instinct. And if you, when you mentor, you have to take time to stop and reflect on why do I do the things that I do, what do I say things the way that I say them, like, how have I navigated different problems and it makes you one. You start to kind of understand yourself a little bit better, I think.
Speaker B: Yeah.
Speaker F: And then also, you know, it's very rewarding to mentor people. And you never know when you're gonna need the people you're mentoring.
Speaker B: Oh, yeah, exactly. You never know. I become the greatest of friends and colleagues and peers with all my mentees, and we're all mentoring together. We're all learning and growing continuously. So it is really fun. And you're the greatest, Jackie, because whenever I get stuck with the mentee, I was like, Jackie McGuire, you will be
Speaker F: able to help you say something weird that'll knock you out of your routine.
Speaker C: Yes.
Speaker B: You need a little boot camp with Jackie. Let's call in my pal. So it's always great when I'm able to introduce one of my mentees to you to give him, like, a quick 45 minute, like, boost. Like, let's get this done. Here's where who this is who you need to be syncing up with. And let's do it. So I love that about you.
Speaker F: Uh, thank you so much, Lynn. We, uh, we'll get to hang out more this week, but really appreciate you coming by. It's always awesome to get to hang out. Yeah.
Speaker B: Thanks for having me. It was so great to catch up with you.
Speaker F: You all right? To learn more about women in cyber security and you really should, visit security weekly.com whis w I c y S b h for Black hat and for full Black Hat 2026 coverage from Cyber Risk alliance, visit securityweekly.com black hat stick around. We'll be back after the break.
Speaker A: Thank you for watching. If you enjoyed this content and would like to find more, see what the rest of the Security Weekly network has to offer. Visit securityweekly.com subscribe to find all of our shows and the latest episodes. Hope to see you on a future episode.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.