
Cyber Crime Junkies · 2026-06-30 · 4 min
Key moments - from our scoring
Substance score
17 / 100
Five dimensions, 20 points each
David Dean Morrow, creator of Cybercrime Junkies and author of the Moving Target book series, issues a stark critique of how the cybersecurity industry approaches awareness and training. Rather than sophisticated attacks, 90% of breaches result from human error - social engineering and unpatched systems - yet the industry relies on fear-based messaging that leaves people paralyzed or apathetic rather than vigilant. Morrow is part of a growing movement of security leaders signing an open letter on Hack Lore demanding the industry stop giving bad advice. The episode tackles why cybersecurity awareness programs often fail: they're either boring, presented by disconnected experts, or sensationalized like movie trailers. Real protection comes from three simple practices: think before clicking, verify information before acting on it, and maintain timely patching. This message resonates with organizational leaders rolling out AI safely, designing incident response plans, and conducting tabletop exercises - people seeking practical, human-centered security rather than fear-mongering tactics.
90% of breaches involve people getting socially engineered or systems not being patched, not sophisticated attacks or technical vulnerabilities.
Fear-based messaging makes people either paralyzed or bored, and bored people become apathetic rather than vigilant - apathy leads to data breaches.
Slow down before clicking links, verify the truth before taking action against your interests, and patch your systems on time.
Security leaders are calling on the industry to stop giving bad advice and abandon fear-based cybersecurity messaging in favor of practical guidance.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode runs only ~4 minutes and the substantive claims reduce to two points: most breaches involve social engineering or unpatched systems, and fear-based training breeds apathy. Both are widely circulated truisms, not novel insights, and the rest is book promotion and a services pitch.
Most breaches come down to two main things. Someone gets socially engineered, meaning manipulated, or something didn't get patched.
Fear based cyber messaging and cybersecurity training does not make anyone safer. It makes them paralyzed or bored.
The critique of fear-based security training has genuine merit but is a well-worn position in the industry; the episode adds no new framing, evidence, or first-principles argument to distinguish it from dozens of similar takes.
cybersecurity doesn't fail because people are stupid. It fails because the industry teaches them to fear the wrong thing.
slow down before clicking, Verify the truth before doing anything against your interests, and patch your systems on time. That's not exciting, but it works.
There is no guest - this is a solo host monologue that quickly transitions into a promotional pitch for his books and his company's managed IT/security services, providing no external practitioner perspective or domain depth.
David Dean Morrow, creator and host of Cybercrime Junkies and author of the new nonfiction Moving Target book series.
I invite you to sit down with me and my team at Netg Technologies. We've been around since 1984
The only figure offered is an unsourced '90% of breaches' claim; the illustrative example is a fictional character ('Mrs. Buttermaker'), and all advice stays at the level of broad generality with no named incidents, real data, or cited research.
in 90% of the breaches, it's people that get hacked.
Mrs. Buttermaker over on the third floor cubicle with her 26 Chrome browser tabs open, is clicking on links like it's an Olympic sport.
The segment is a scripted monologue with no interviewer, no guest, no follow-up questions, and no productive tension; it ends with an overt call-to-action for a commercial service, making craft assessment essentially irrelevant.
If this hasn't pissed you off, consider following us. And if you're feeling cool and kind, please consider subscribing to our YouTube channel.
Computed from the transcript - who did the talking, and the words that came up most.
We’ve trained people to fear nation-state hackers…while getting breached by rushed clicks and skipped updates. Cybercrime doesn’t win because it’s smart. It wins because people are tired. We’ve been trained to panic about rare, cinematic attacks… while leaving the front door unlocked every single day. The boring truth that actually works: • Don’t get tricked • Patch your systems That’s it. Not sexy. Not cinematic. But it works. Questions? Text our Studio direct. We read these and when helpful we give a special shout out for those to contact us. I wrote Moving Target because overconfidence is the enemy. Hardcover, paperback, Kindle, and audiobook . Amazon , Barnes and Noble , and more. Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out at DMauro@NetGainIT.com or find more at Support the show New Exclusive Offers for our Listeners! New non-fiction Book Series is out! Moving Target: The Art of Online Camouflage drops April 14. Moving Target: The Obedient Machine drops April 21. Book 3 - Ghost and the Machine - out soon! 4 years. 400+ interviews. Available on Amazon . We are all Stevie Parker.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Ever notice it's always the overconfident leader that thinks cybercrime doesn't apply to them who gets selected and hurt the most. Moving target. Books 1 and 2, out now. Hardcover, paperback, Kindle and audiobook. Amazon, Barnes and Noble and independent bookstores. Book three coming soon. Be a moving target. Oh, I know. You're right. Have you ever noticed that cybersecurity awareness is either boring, taught by somebody who acts like they've never met a human, or like some movie trailer, dark music, green coat, a kid in a hoodie. And as it turns out, the industry still never explains how people actually get hacked. See, in 90% of the breaches, it's people that get hacked. Real people like you and me. Not sophisticated mirror arrays and hypervirtualized systems people. That's what mostly happens. It happens because it's Tuesday, someone's busy, coffee hasn't kicked in, and Mrs. Buttermaker over on the third floor cubicle with her 26 Chrome browser tabs open, is clicking on links like it's an Olympic sport. We're calling on the industry to do one thing. Stop giving bad advice. Most breaches come down to two main things. Someone gets socially engineered, meaning manipulated, or something didn't get patched. So we're joining a growing list of security leaders in an open letter that's on hack lore, asking the industry to stop giving bad advice. Fear based cyber messaging and cybersecurity training does not make anyone safer. It makes them paralyzed or bored. And bored people don't become vigilant. They become apathetic. And apathy is a good way to have a data breach. So slow down before clicking, Verify the truth before doing anything against your interests, and patch your systems on time. That's not exciting, but it works. See, cybersecurity doesn't fail because people are stupid. It fails because the industry teaches them to fear the wrong thing. If this hasn't pissed you off, consider following us. And if you're feeling cool and kind, please consider subscribing to our YouTube channel. This is Cybercrime Junkies. Hey, everyone. David Dean Morrow, creator and host of Cybercrime Junkies and author of the new nonfiction Moving Target book series. If you're a leader in an organization curious how to roll out AI safely, or if you have questions on your incident response plan, how to run tabletop exercises, or looking for 247 eyes on glass to protect you and keep you growing without interruption, then I invite you to sit down with me and my team at Netg Technologies. We've been around since 1984, before cybersecurity even existed. A simple conversation, absolutely no pressure and no salesy fluff, and you will walk away with a great roadmap no matter what. So if improving your IT, bolstering your security or rolling out AI uh, interests you, contact me directly today@dmorrowetgainit.com that's D M M A U R O Net gainit. Find out more at our website at NetGainit. That's NetGainit.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.