The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/Cyber Crime Junkies
Cyber Crime Junkies artwork

Stop Taking Bad Advice. An Open Letter To The World

Cyber Crime Junkies · 2026-06-30 · 4 min

0:00--:--

Key moments - from our scoring

Substance score

17 / 100

Five dimensions, 20 points each

Insight Density4 / 20
Originality5 / 20
Guest Caliber3 / 20
Specificity & Evidence3 / 20
Conversational Craft2 / 20

David Dean Morrow, creator of Cybercrime Junkies and author of the Moving Target book series, issues a stark critique of how the cybersecurity industry approaches awareness and training. Rather than sophisticated attacks, 90% of breaches result from human error - social engineering and unpatched systems - yet the industry relies on fear-based messaging that leaves people paralyzed or apathetic rather than vigilant. Morrow is part of a growing movement of security leaders signing an open letter on Hack Lore demanding the industry stop giving bad advice. The episode tackles why cybersecurity awareness programs often fail: they're either boring, presented by disconnected experts, or sensationalized like movie trailers. Real protection comes from three simple practices: think before clicking, verify information before acting on it, and maintain timely patching. This message resonates with organizational leaders rolling out AI safely, designing incident response plans, and conducting tabletop exercises - people seeking practical, human-centered security rather than fear-mongering tactics.

Key takeaways

  • →90% of breaches involve people falling for social engineering or failing to patch systems, not sophisticated technical exploits.
  • →Fear-based cybersecurity training makes people paralyzed or apathetic, reducing rather than increasing vigilance and security behavior.
  • →The three practices that actually prevent breaches are simple: slow down before clicking, verify the truth before acting, and patch systems on time.
  • →Cybersecurity fails because the industry teaches people to fear the wrong things, not because people are inherently stupid.
  • →An open letter on Hack Lore signed by security leaders is calling the industry to abandon fear-based messaging in favor of practical, human-centered awareness.

Topics in this episode

Incident response planningTabletop exercisesSocial engineeringPatch ManagementHackLoreMoving Target book seriesNetGain IT TechnologiesAI safety rolloutcybersecurity awareness trainingfear-based messagingFear-based messaging in cybersecuritySystem patching and updatesAI security rolloutHack LoreNetgain Technologies

Questions this episode answers

What percentage of breaches are caused by people rather than technical exploits?

90% of breaches involve people getting socially engineered or systems not being patched, not sophisticated attacks or technical vulnerabilities.

Why does fear-based cybersecurity training fail to make people safer?

Fear-based messaging makes people either paralyzed or bored, and bored people become apathetic rather than vigilant - apathy leads to data breaches.

What are the three core practices that actually prevent most breaches?

Slow down before clicking links, verify the truth before taking action against your interests, and patch your systems on time.

What is the open letter on Hack Lore asking the cybersecurity industry to do?

Security leaders are calling on the industry to stop giving bad advice and abandon fear-based cybersecurity messaging in favor of practical guidance.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

4 / 20

The episode runs only ~4 minutes and the substantive claims reduce to two points: most breaches involve social engineering or unpatched systems, and fear-based training breeds apathy. Both are widely circulated truisms, not novel insights, and the rest is book promotion and a services pitch.

Most breaches come down to two main things. Someone gets socially engineered, meaning manipulated, or something didn't get patched.
Fear based cyber messaging and cybersecurity training does not make anyone safer. It makes them paralyzed or bored.

Originality

5 / 20

The critique of fear-based security training has genuine merit but is a well-worn position in the industry; the episode adds no new framing, evidence, or first-principles argument to distinguish it from dozens of similar takes.

cybersecurity doesn't fail because people are stupid. It fails because the industry teaches them to fear the wrong thing.
slow down before clicking, Verify the truth before doing anything against your interests, and patch your systems on time. That's not exciting, but it works.

Guest Caliber

3 / 20

There is no guest - this is a solo host monologue that quickly transitions into a promotional pitch for his books and his company's managed IT/security services, providing no external practitioner perspective or domain depth.

David Dean Morrow, creator and host of Cybercrime Junkies and author of the new nonfiction Moving Target book series.
I invite you to sit down with me and my team at Netg Technologies. We've been around since 1984

Specificity & Evidence

3 / 20

The only figure offered is an unsourced '90% of breaches' claim; the illustrative example is a fictional character ('Mrs. Buttermaker'), and all advice stays at the level of broad generality with no named incidents, real data, or cited research.

in 90% of the breaches, it's people that get hacked.
Mrs. Buttermaker over on the third floor cubicle with her 26 Chrome browser tabs open, is clicking on links like it's an Olympic sport.

Conversational Craft

2 / 20

The segment is a scripted monologue with no interviewer, no guest, no follow-up questions, and no productive tension; it ends with an overt call-to-action for a commercial service, making craft assessment essentially irrelevant.

If this hasn't pissed you off, consider following us. And if you're feeling cool and kind, please consider subscribing to our YouTube channel.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cybersecurity4industry4cybercrime3moving3target3leader2doesn2gets2book2hacked2breaches2systems2happens2hasn2open2clicking2

Episode notes

We’ve trained people to fear nation-state hackers…while getting breached by rushed clicks and skipped updates. Cybercrime doesn’t win because it’s smart. It wins because people are tired. We’ve been trained to panic about rare, cinematic attacks… while leaving the front door unlocked every single day. The boring truth that actually works: • Don’t get tricked • Patch your systems That’s it. Not sexy. Not cinematic. But it works. Questions? Text our Studio direct. We read these and when helpful we give a special shout out for those to contact us. I wrote Moving Target because overconfidence is the enemy. Hardcover, paperback, Kindle, and audiobook . Amazon , Barnes and Noble , and more. Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out at DMauro@NetGainIT.com or find more at Support the show New Exclusive Offers for our Listeners! New non-fiction Book Series is out! Moving Target: The Art of Online Camouflage drops April 14. Moving Target: The Obedient Machine drops April 21. Book 3 - Ghost and the Machine - out soon! 4 years. 400+ interviews. Available on Amazon . We are all Stevie Parker.

Full transcript

4 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Ever notice it's always the overconfident leader that thinks cybercrime doesn't apply to them who gets selected and hurt the most. Moving target. Books 1 and 2, out now. Hardcover, paperback, Kindle and audiobook. Amazon, Barnes and Noble and independent bookstores. Book three coming soon. Be a moving target. Oh, I know. You're right. Have you ever noticed that cybersecurity awareness is either boring, taught by somebody who acts like they've never met a human, or like some movie trailer, dark music, green coat, a kid in a hoodie. And as it turns out, the industry still never explains how people actually get hacked. See, in 90% of the breaches, it's people that get hacked. Real people like you and me. Not sophisticated mirror arrays and hypervirtualized systems people. That's what mostly happens. It happens because it's Tuesday, someone's busy, coffee hasn't kicked in, and Mrs. Buttermaker over on the third floor cubicle with her 26 Chrome browser tabs open, is clicking on links like it's an Olympic sport. We're calling on the industry to do one thing. Stop giving bad advice. Most breaches come down to two main things. Someone gets socially engineered, meaning manipulated, or something didn't get patched. So we're joining a growing list of security leaders in an open letter that's on hack lore, asking the industry to stop giving bad advice. Fear based cyber messaging and cybersecurity training does not make anyone safer. It makes them paralyzed or bored. And bored people don't become vigilant. They become apathetic. And apathy is a good way to have a data breach. So slow down before clicking, Verify the truth before doing anything against your interests, and patch your systems on time. That's not exciting, but it works. See, cybersecurity doesn't fail because people are stupid. It fails because the industry teaches them to fear the wrong thing. If this hasn't pissed you off, consider following us. And if you're feeling cool and kind, please consider subscribing to our YouTube channel. This is Cybercrime Junkies. Hey, everyone. David Dean Morrow, creator and host of Cybercrime Junkies and author of the new nonfiction Moving Target book series. If you're a leader in an organization curious how to roll out AI safely, or if you have questions on your incident response plan, how to run tabletop exercises, or looking for 247 eyes on glass to protect you and keep you growing without interruption, then I invite you to sit down with me and my team at Netg Technologies. We've been around since 1984, before cybersecurity even existed. A simple conversation, absolutely no pressure and no salesy fluff, and you will walk away with a great roadmap no matter what. So if improving your IT, bolstering your security or rolling out AI uh, interests you, contact me directly today@dmorrowetgainit.com that's D M M A U R O Net gainit. Find out more at our website at NetGainit. That's NetGainit.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Spot That Vish!Simplifying Cyber · on Social engineering90 / 100
  • If Your MSP Says ‘All Good’, Can They Prove It?The Small Business Cyber Security Guy · on Patch Management89 / 100
  • The Real Cost of a Ransomware Attack: The Ransom Is the Least of Your ProblemsThe Backup Wrap-Up · on Incident response planning88 / 100
  • Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom LangfordSecure & Simple · on Patch Management78 / 100
  • How Data Brokers Fuel AI-Driven Social EngineeringWhat's Up with Tech? · on Social engineering75 / 100
  • From stealing servers to saving lives: Working in red teaming | Jim BroomeCyber Work · on Social engineering69 / 100

More from Cyber Crime Junkies

All episodes →
  • Broken English and an AI Chat Window: The Perfect Hack
  • Weird Dangerous Findings on The Dark Web
  • How to use AI at Work (and Not Get FIRED)
  • 500 Years in Prison? Meet The Human Behind AT&T Hack
  • AI in Healthcare-Hope or HYPE?
Explore the best B2B AI & Data podcasts →
All Cyber Crime Junkies episodes →