
Cyber Leaders · 2026-05-08 · 44 min
Key moments - from our scoring
Substance score
62 / 100
Five dimensions, 20 points each
Taz Wake brings a rare military intelligence background to civilian cybersecurity leadership. Starting as a signals intelligence specialist in 1993, he transitioned through government agencies before founding his own incident response and risk assessment firm in 2010 - a company now 16 years old. His perspective bridges military counterintelligence with modern threat hunting and IR, and he's built SOCs and threat hunting teams at major organizations like Unilever while authoring key SANS courses that have trained thousands. The conversation covers what separates outstanding incident responders (technical depth, communication skills, genuine curiosity) from the rest, why threat hunting matters in reducing dwell time from 18 months to 15 days, and how AI tools are changing the attackers-versus-defenders equation without fundamentally altering its spy-versus-spy nature. For security leaders evaluating IR capabilities or building threat hunting programs, Wake offers both tactical frameworks and strategic perspective on what actually works.
Threat hunting is the proactive practice of searching your environment for compromises that security tools have missed, similar to physical security patrols. It has been the primary driver of dwell time reduction from 18 months in 2010 to approximately 15 days today, though Wake notes 15 days still allows attackers to cause significant damage.
Beyond technical depth across diverse platforms, the most important traits are strong communication (with both technical teams and victims), genuine curiosity about solving challenges, and the ability to remain calm and methodical under pressure - essentially being the calm in the storm.
After 16 years in the British Army working in signals intelligence, electronic warfare, and counterintelligence roles, Wake left in 2010 with deep government and security sector contacts. He leveraged those relationships to found his own incident response and risk assessment firm, which has been operating successfully for 16 years.
Wake views AI as a tool that both sides will use to speed up their operations, but doesn't fundamentally change the core dynamic: human attackers versus human defenders. The question becomes who wields these tools more effectively rather than whether AI creates an inherent advantage.
A user clicked a fake help desk pop-up, was socially engineered to provide personal banking credentials, and had their life savings stolen. Wake's team responded quickly enough to contact the bank's counter-fraud team (whom he knew from SANS instruction) and halted the fraudulent transfer, saving the victim's money.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains solid practitioner insights about incident response, threat hunting, and operator mindsets, with concrete skill hierarchies and dwell-time statistics. However, much of the content is conversational scaffolding, banter about animals, and predictable security talking points (Linux myths, certification value) that circulate regularly in the industry. The signal-to-noise ratio is moderate - genuine lessons exist but are padded with filler.
At the very base level, there's an absolute technical requirement. As an incident responder, there is an expectation that you'll understand technology well enough that it doesn't matter what you're having to deal with.
Fully understand your network. Don't rely entirely on things like CMDBs or existing network diagrams, understand the actual data paths, understand where people can access things, understand where the data resides. That's the 99% of every single intrusion I've ever worked.
The episode rehashes well-worn industry narratives: the Linux security myth, human error statistics, certification debates, and community engagement platitudes. While Taz's personal experience is authentic, the framing and conclusions mirror existing security discourse. The dwell-time reduction metric is cited from Mandiant/CrowdStrike (not original data), and the broader themes lack contrarian or first-principles thinking.
there's this often quoted stat that, you know, 95% of breaches involve and are caused by humans... It's quoted all the time. But it goes back to an IBM report in 2015
The Mac operating system, it's security models based around someone stealing your Mac device. The Windows operating system, it's security based around malware. They've got two different threat models, so they implement security differently.
Taz Wake is a legitimate practitioner with 16 years in military intelligence/cyber, 16+ years running an incident response firm, and deep experience leading SOCs and CERT functions at enterprises (Unilever). He is a SANS instructor with authored courses, making him operationally credible. However, he is not currently a CxO at a major organization or leading large-scale defense at Fortune 100 scale, which would elevate him further.
Leaving the service in 2010, he founded his own company, which he still has, specializing in incident response, risk assessments, compliance, and training.
He's built SOCs and threat hunting teams at various major organizations. He's a SANS instructor and a faculty member of the SANS Technology Institute. He led incident response and CERT functions at Unilever.
The episode provides some concrete examples (Singapore phishing case, dwell time dropping from ~540 days in 2010 to ~15 days today via Mandiant/CrowdStrike), but relies heavily on abstraction and anecdote. Taz deliberately avoids naming clients or incidents for legal reasons, which is understandable but limits evidential weight. Few specific threat actor TTPs, dollar figures, or metrics are detailed beyond the dwell-time stat.
the dwell time, the amount of time an attacker can be in environment before they get detected, has dropped dramatically from like a year and a half in 2010 to 15 days or thereabouts today.
I've dealt with an incident whereby, and this is kind of like almost feels trivial, but there was uh a user in Singapore, they'd browse to a suspicious website, uh, a fake help desk pop-up had come up, they'd clicked on it
The hosts (Kieran and James) ask reasonable opening questions and show genuine curiosity about Taz's background and philosophy. However, follow-ups are often superficial or derailed by extended banter and tangents (ferret naming, t-shirt riffs, animal anecdotes). Critical probing is absent - hosts rarely challenge Taz's claims or explore contradictions. The threat actor naming game and animal tangents, while entertaining, displace deeper technical interrogation.
So you could give us a sense of some of the buzz around incident response? I mean, why do you love it so much? Why are you so passionate about it?
How did you do that? What happened? Was it difficult? Were you nervous? And did it change anything?
Computed from the transcript - who did the talking, and the words that came up most.
In this episode, Ciaran and James are joined by Taz Wake, Digital Forensics & Incident Response expert, to talk about the realities of defending organisations today. Drawing on his background in military intelligence and years on the front line, Taz shares insights on incident response, threat hunting, and the common myths the industry still gets wrong. Contact: Have questions or comments? Email us at cyberleadersnetwork@sans.org
Transcribed and scored by The B2B Podcast Index.
Welcome to Cyberleaders with me, Kieran Martin. And me, James Lyne. Now we're both from the Sands Institute who are kindly backing this podcast. I myself am a techie, a massive geek who spent my life chasing cybercriminals around the internet.
Less of a techie, I dealt with cybersecurity operations and policy and government and set up the UK's National Cybersecurity Centre. But together, James and I are trying to unpack the weird, wacky, wired, and wireless world of tech security and all the complications it involves. That's right, Kieran. This podcast is the voice for security leaders.
We want CISOs, security directors, and frankly everyone beyond to build up their knowledge of what works, what doesn't, and ultimately secure their organizations more comprehensively and quickly. Well, frankly, ideally makes some cyber criminals miserable too. Well, first of all, James, good start to an audio podcast. Nice haircut.
Very aerodynamic. Yes, you look like a thug. In fact, you look like a baddie. You look like a criminal.
And I mean a physical one, not a cyber one. A bit of cyber roleplay. Yes. Now, let's go back to baddies.
Let's talk about some baddies. So I'm gonna take you back to something you said at the start there. Oh, so you were listening this time, Kieran. That may be a first.
I hang off your every word, my friend. All of them. Even the ones I don't understand when you like talk about computers and hacking and stuff. I listen then, too.
And which particular bit or bite did you want to haul me up on today, Kieran? I'm getting paranoid. I feel like I've made an error. I have to watch my words or double words more carefully.
There was a lot of data size puns in there. It was. But I want to talk about baddies today. So in that wonderfully spontaneous yet repetitive introduction that we both do, we always talk about chasing baddies around the internet.
And you've come today in character. You've come looking like one. Well, yes. I mean, you've got to get inside their headspace, don't you?
I've spent the last 20 odd years of my career chasing cybercriminals and their exploits and malware and frankly trying to make their lives difficult. Well then let's go back to data. How many baddies have you chased? Uh well, it's hard to think, but it's a lot.
I could probably more easily name the ones we've managed to deal with with law enforcement, but um, where are you going with this, Kieran? Are you trying to create a chasing baddies league table? That's exactly what I'm trying to do, as a matter of fact, James. Yes.
Can I ask why? Well, I'm not really trying to create a baddies league table. I'm just trying to work out whether you've spent more time chasing baddies than our guest. Because we've someone today who spent more time in what I would call the front line of the front line of cyber defense than pretty much anyone I know, except perhaps maybe your good self.
We've someone joining us today who's seen it all and done it all from a whole range of different perspectives and jobs. Indeed we do. And I frankly would be quite happy to be beaten in the baddies chasing league tables by this individual. We have a guest today, folks, who started his career in the military, who's in intelligence, working on human intelligence operations, counterintelligence, and in electronic warfare, obviously very closely related to cybersecurity and more so every day.
Now, without getting too much into his age, he was in uniform at the time when the military started to worry about what we now call cybersecurity and started to specialize in that. Leaving the service in 2010, he founded his own company, which he still has, specializing in incident response, risk assessments, compliance, and training. But he's done way more than that. He's built SOCs and threat hunting teams at various major organizations.
He's a SANS instructor and a faculty member of the SANS Technology Institute. He led incident response and CERT functions at Unilever, a massive organization. I can only imagine the challenges there. And he is the author of two pivotally important SANS courses on incident response and threat hunting, which means he's had thousands of students go through his classes learning these key concepts and well supporting that general theme of trying to make life difficult for the cyber criminals.
Kieran, we're gonna have to figure out if he gets credit for all those students by proxy, because if so, he's definitely got me beaten. I think that might be the case, but let's figure it out. There's some kind of tree there, isn't there? But uh anyway, look, on the more friendly side, he's got an entire barnyard full of animals, which we'll have to ask him about.
So um, my powers of deduction tell me he basically never sleeps. And he's gonna talk to us about a whole lot. And Kieran, we're gonna struggle to contain our lines of question and the length of the podcast as usual. As normal.
Yeah. So it is, of course, based on that introduction, you probably had it from the barnyard full of animals, the truly remarkable Taz Wake. Welcome, Taz. Hi everyone.
Hi, James, hi Kieran. It's uh absolute pleasure to be here, and that was an incredible introduction. I am honored. Well, it's fully deserved, and I think fitting with your background and the mystique around everything you've done.
James is looking like a thug with a short hair, and you're off camera. So this is good because I'm gonna start with a question we ask everybody about your journey into cyber, but I'm really looking forward to your answer. There's as many different answers as there are guests. So you join the military in intelligence work.
This is a pretty scary time, the beginnings of a pretty scary time that we're still in. The world starts to go on fire at the start of this century. And you emerge from this period when you come out of service in 2010, and you're ready to take on the world of cyber thugs and thieves in the private sector. So clearly you didn't go into the military in cyber, but you came out of it ready to go.
So I'm guessing you're not going to be able to tell us everything about your early career and what led you to pivot to cyber. Some of that will probably be classified. So here's two options for you. One is you can tell me and James everything, just go through all the classified operations, all the really cool stuff, and then we'll edit it out.
It'll be like one of those government document releases you see where it's mostly black ink blotched over the words. Beep, beep, beep, beep, beep, beep. And our listeners can just listen to that, or maybe something less high-pitched, maybe just the sound of silence. So that's option one.
Option two is you can tell us whatever you can about your early life and career and how you ended up fighting digital baddies, having started off fighting physical ones in the military. Your choice. Uh, I think I will absolutely go with option two there. Oh, okay.
The 35 minutes of silence isn't exactly a selling point. But no, so as you described, I join you. I mean, I actually enlisted in 1993. Wow.
Uh, I started off as uh what we referred to at the time as an operator special intelligence. And that meant you go through a variety of different jobs. Uh, at the end of basic training, I was specialized in electronic warfare, signals, intelligence, that kind of thing. Postings to Germany, really, really interesting jobs.
There's a whole range of things. The Cold War's over at this stage, but not quite. We still had uh occasional threats, Middle East, Africa, places like that. Throughout the 16 years, we changed jobs in the Army, or certainly my trade in the Army, we changed jobs every two years, which meant I had the opportunity to bounce around a whole raft of things, lots of uh secondments to other government agencies.
I spent a bit of time working in tri-service organizations, a bit of exchange trips with the US, which was quite fascinating. But a lot of it revolved around the terms intelligence and security. So we kind of look at it as a double-pronged effort. We're attempting to similar as that we talk about cybersecurity today.
As an intelligence operator, I'm attempting to gather information from the enemy, and as a security operator, I'm attempting to prevent the enemy from gathering it from us. And that was kind of the big blow. Interestingly enough, in 1993, I was actually sent on a computer security officer's course, which was kind of the first step into what we'd call cybersecurity today. Someone was ahead of their time?
Yeah, it was very different to how you'd look at things today. That's probably the easiest way to describe it. It was very much uh we'd probably refer to it was auditing today. Right.
There was a lot more into just making sure the processes were followed, making sure the passwords were rotated, that kind of thing. There was less focus on the more direct technical cybersecurity we'd expect in the year 2026. But that did evolve, absolutely. Uh, it evolved quite a bit until my last posting with the army I was on a second, so at a government agency.
And I've kind of reached the point where I thought, I've had enough, I've done some really interesting things. There aren't that many more new, interesting things ahead of me, and that's the the point to which I decided to leave. Uh, and basically, because of a lot of background, uh protecting organizations, that kind of thing, yeah. Uh some very interesting investigations, none of them I could talk about, sadly.
Uh-oh. Uh but if anyone ever wants to get down and say with me, I've got some incredible stories that I can uh try and declassify a little bit. I will bet you do. Yeah, that was kind of the point to which I thought when I left, uh I was very fortunate.
I formed my own company. And the biggest advantage I had really was having lots of friends and contacts in the industry. Uh so we've been managed to be successful, and here we are 16 years later, still doing cybersecurity. Love to see it.
And of course, oh, how things have changed as well, Taz. Absolutely. I was thinking back to those days you're describing, and of course the roles have changed, but the nature of the problem, the scale of the problem, the use of technology, I mean, it's just been a whirlwind. When you were there during that period, towards the end of it, you know, there's still a very unstable world and so forth.
How much were the military thinking about cyber and so forth at the point of your departure? And do you get any sense, done if you're still in touch with people? You know, how much has all this changed now, given that quite a lot of all the things going on in traditional military circles? Yeah.
Where's it all at now? So certainly by the time I left, the army had very much pivoted. We'd gone from the early 90s of a computer security officer. We had uh an information security unit in the intelligence corps, ever very skilled.
They do a lot of science training as a prime example around that. Uh so there had very much that kind of happened in the early 2000s. Right. I think when Stutznet, Hitler news in 2009, that kind of made everyone really aware of the additional levels.
Yeah. And you you might even remember around about like 2007 when we had the fears about uh supply chain attacks and we could no longer talk about restricted information over the telephone network. Yeah, yeah, yeah. Uh that kind of thing.
They were the mindsets that people were very much going into. Yeah. I think it's quite modern, really. It's a well, like James said, it's night and day difference to when I started.
Yeah. I think the the technical details will have enhanced today. I know the army still has a very strong, dedicated cybersecurity capability. The technical details will have improved, but I think that real mindset approach probably changed in the early 2000s.
Yeah, nothing like an exploding centrifugue to focus the minds, I guess. Anyway, I rudely interrupted Jim, so I'll hand you back to him now. That's quite okay. We got to exploding centrifuges already.
That's a great start to the podcast, which is probably going to make my next line of questioning seem mundane, but I actually think it's really important. Taz, I don't normally read out bits of people's official biographies. Well, mostly because it makes people think I've just been lazy and that's all I've looked at. And where would people get that idea from, James, that, you know, maybe somebody else did all the research?
I don't know. I mean, any clues? Well, I exact. I can't even possibly imagine.
No. Anyway, sorry, I'm interrupting again. Exactly. And in a world of AI, we shall assume that perplexity or ChatGPT did the work.
Excuse me. I'm much cheaper. And certainly better. Maybe.
But there are a few bits of your official biography, Taz, that are so good I wanted to quote them and ask you about them. After all these incredible achievements and experiences, you're described as an incident responder at heart. I love that quote. And then you're quoted kind of talking about seeing individuals fighting the good fight every day and catching an attack in flight, responding quickly enough to get ahead of the exploitation to defend the environment.
It means someone or some organization is better, more secure, and able to return to normal life. I just love that. And it takes me back to the first bit about how you're an incident responder at heart. So could you give us a sense of some of the buzz around incident response?
I mean, why do you love it so much? Why are you so passionate about it? And insofar as you can, any highlights or cool stories that aren't classified and require beeping. Absolutely.
Uh you've hit the nail on the head there, James. I think for me, absolutely, incident responses is where cybersecurity really gets it from. And I think there's a couple of reasons for it. First of all, there's the slightly uh historic approach of the fact that it's always quite a nice feeling to do something good for people.
I mean, when I joined the army, I had lots of reasons for joining, but part of it is around that sort of being part of a bigger picture, protecting things, that kind of idea. There's a little bit of a cynical approach in some cybersecurity areas in that really what we're doing is protecting shareholder value. But incident response is a little bit different. There's genuine ways that we can actually protect individuals.
Most of my work isn't really in like ICS OT environments. But if we look at those as an example, the instant responders there are genuinely saving lives. There's risk to life that their actions are preventing. The people dealing with a nation-state attack in Ukraine, for example, are going to save lives.
And that's hard to compete with, let's say, as an auditor that doesn't have that same kind of feeling for me. Yeah. Regarding the kind of activities as well, the scope that we can get in IR is phenomenal. One day we can deal with a nation-state threat act gaining access to a critical database system and taking uh the entire NHS down.
And then in the next day, we've got an individual who's had their bank account attacked and all their funds stolen. So for me, doing IR is a combination of an incredibly very challenge. There's the saying no two days the same is absolutely true here. It really is the case of, well, a sort of there's a rhyme between events.
They're always different enough that we have to use our brains, we have to think. And then there's always that feeling at the end of it, you've actually made someone a little bit better. Uh, you asked for examples. I mean, that is always a little bit challenging.
I don't want to get sued out of existence for an NBA or go to prison. Or require bleeping. I actually thought James had said require beating. I thought that was upping the ante a bit with his new haircut.
But anyway. Absolutely, yeah. Both approaches aren't ideal. I'm scared of them both.
What can you safely disclose? Uh well, some of the more common ones then. I've dealt with an incident whereby, and this is kind of like almost feels trivial, but there was uh a user in Singapore, they'd browse to a suspicious website, uh, a fake help desk pop-up had come up, they'd clicked on it, they'd rang through, and the attackers socially engineered them to connect in at their own personal bank accounts, and they had all of their life savings extracted. Now, as an instant responder, that's heartbreaking.
That's not just a company impact, because it was while the attacks started on a company device, hence I get involved. The actual individuals felt personal pain. Of course. Now we were quite lucky with it, was the most recent one, although it's rare.
We were quite lucky in that we were fast enough that we were able to engage with the bank. We could speak to the bank's counter fraud. And again, I'm just gonna do a little bit of an advertisement for Sans here because uh the head of their counter fraud team knew me from a Sans class, which absolutely facilitated a lot of this. But we were able to stop the fund transfer in flight.
Right. Uh, and this person managed to save their money. That's the great feeling at the end. I love that.
Oh, just seeing the cyber criminals not get money. Oh, so satisfying. And that's an absolutely lovely example. And I do also feel obliged to point out that now that you've plugged Sands twice, that has is not being paid for this podcast.
This is not an invomortial. Um no, I don't work for Sans. No, I don't work for Sans. But no, we will come back actually because the more serious point is about communities of people who trust each other, which I know is something you're big on.
But look, before we leave incident response, you've talked about some great stories and so forth, but give us some themes to take away about good incident response. You mentioned there's enough difference, but there may be some patterns too. So for people listening out there working, what have you seen that makes for a good incident response? So there's a hierarchy of skills that an incident responder needs.
At the very base level, there's an absolute technical requirement. As an incident responder, there is an expectation that you'll understand technology well enough that it doesn't matter what you're having to deal with. If you're dealing with a compromised Mac device and then you're pivoting into a compromised Cisco firewall, as an inst responder, you can't just say that's not my specialization. You've got to be able to understand enough to keep going.
This isn't about being the expert, so there's a slight difference when we're talking about maybe digital forensics. If I'm going to stand up in court as an expert witness, I have to have a deep subject matter expertise. IR not quite that bad. Moving up from the technical level though, because lots of people manage that, where it really becomes different are a couple of key traits that inter-responders have.
You've got to be a good communicator. An interresponder absolutely has to be able to talk to technical people and victims. If you are a very technically focused person and you can't communicate with the victim, it's going to slow things down. Absolutely.
If you can't communicate with the board, you're not achieving your recommendations, your remediation actions aren't going to work. You get a failing there. And the last, but probably the most important element, you've got to be interested. You've got to look for the challenge.
It's like you'll probably remember this from the olden days. It's like you've got to be the person who does crossword puzzles, who does logic problems because you're interested in that challenge. And that's kind of what gears people towards being very good incident responders. Excellent.
Yeah, it makes a lot of sense to me. Years ago, I heard this line that I think applies to what you're describing: that a great incident responder has to be the calm in the storm. They have to be kind of very zen. They have this ability to follow a checklist and be repeatable and evidence-based and methodical and calm, whilst also pursuing all these completely diverse and different scenarios.
And that's quite a fascinating intersection of style challenges for people who do this stuff well, isn't it? Absolutely. I mean, James, that's probably the best summary I've ever heard. That's exactly it.
You can have that one for free. No, no, no, no. Don't flatter him. I've written it down.
So I'm gonna make a note of that. And from now on, that's mine, just to be crystal clear. You can see his head. It's quite big enough.
We could attribute it to you, you could put it on a t-shirt. Oh, t-shirts. We're back to t-shirts. Sorry.
Wait, we haven't had a t-shirt for a while, have we, Kim? We haven't had a t-shirt for a while. I might be about to make another one. So, you know, hold on to your chair.
Taz, let's pivot over here to one of the other things that you're very well known for, very experienced in, and a little related to this, that's threat hunting. Now, one of those areas that's, you know, well understood by some. And at a high level, the term is pretty self-explanatory, but not really, actually. If you don't kind of know the details, it kind of stops at the I'm hunting threats level.
So, yeah, what is it to you and where and how do you think it works best? Okay, so at a very basic level, threat hunting is the proactive approach where defenders are looking in their environment to see is there a problem that our security tools have missed. It's similar in physical security. We we have similarities with security guards doing patrols inside the building.
They're looking for someone who might have broken in and not set off any alarms. That's kind of the thought process that drives it. It is critical. I mean, we look at lots of statistics like Mandi and CrowdStrike, they're showing that dwell time, the amount of time an attacker can be in environment before they get detected, has dropped dramatically from like a year and a half in 2010 to 15 days or thereabouts today.
That's nearly all down to threat haunting. And as organizations get better at this, that's going to reduce because 15 days, still a long time. As I'm sure you can imagine, James, if you're active on a network for 15 days, they're not recovering, they're rebuilding. I could cause all manner of chaos in 15 days.
It's absolutely game over at that point. There's no hope. Isn't it just? And Taz to your point as well.
So wonderful the dwell time is reducing. So that's a huge improvement. One of the things on my mind, though, is of course AI and automation and agents coming into this space. That's going to have a very interesting impact on that dwell time stat, potentially in both negative and ways, right?
I kind of struggle to think through the next couple of years and what might happen there. I don't know if you have a profound realization for folks, or more of a it'll be different and hard type summary. The problem today is this is very much a definition of interesting times. I don't have anything profound.
I think it is going to be a significant change. We are seeing attacker behaviors speed up, absolutely. But most organizations that are deploying some form of LLM with inside their security boundary are also speeding up their response. So it could be that we are going to see them increase in lockstep.
The the main point around that though is ultimately the LLM is just a tool. For me, a cyber attack and its defense is still a very traditional, almost like spy v spy sort of thing. It's a human at one end of the attack chain and a human at the other end of the attack chain. It's just about how we utilize these tools to our best advantage.
Yeah, I really subscribe to that viewpoint too. And I know this is trivializing kind of different technology use cases, but I stand by the statement in Macro at the end that said it before, if both sides have AI, then once again the edge is human. But there is a very important, of course, threat hunting thing that I do have to ask you before Kieran follows up with what will no doubt be a more serious question. Don't bet on it.
There is, of course, this trend of the amalgamation or concatenation of threat hunting into thunting. How do you feel about thrunting? I'm not altogether sure where to go with that. I think that probably describes it in of itself.
Yeah. Is it when we finally put in the bleeps? That's not a term I'm going to utilize on a regular basis. I think we have a call on it.
Yeah, I'm with Taz. You silenced me. I had no idea where that came from. I think I said earlier in this podcast about James, I even pay attention to the words that I don't even understand.
And here we go. So that's perfect. But anyway, thank you for taking us to the humans because I want to ask about humans. So this thrunt thing, oh my god, I'm doing it.
This threat hunting stuff. Infectious. I know. Could be a teacher.
Oh god. Could be a company. Thrunting document. No, no, no, no, no.
That would get blocked. And rightly so. And breathe. Now look, threat hunting, humans.
You and James have talked before going back to the human, you've talked a lot about what you learn technically and so forth, what you need to do. What do you learn about the adversarial mindset and even the adversaries themselves? And James accused me of asking a more serious question, so I'd better trivialize it. As well as that, I wanted to ask you what about threat actors?
I mean, you know, if you had to make a league table of threat actors as opposed to baddie catchers, you know, any particular groups that you've dealt with or studied over the time that you think, oh, they're a difficult bunch. So what do you learn about the adversaries and who do you worry about? Real good question. All of them is the short answer.
So there's a whole range of skills and things like that. Some of the some of the ones we refer to as, I mean, we use the term APT quite uh loosely, but some of the APTs we refer to like shiny hunters. Yeah. They are uh always in the news, they are always doing very high profile, high monetary gain attacks, but they're incredibly low skilled.
Yeah. Uh nearly everything that shiny hunters do is down to a misconfiguration, basically default passwords being exposed to the internet. Shiny hunters make a few millions. Yeah.
I'm not trivializing that, but as an inter responder, that's not really a threat act that you worry about because investigating them is not really. That's challenging. The defending against them shouldn't be that challenging. Yeah.
They're the high noise, very, very profitable, annoying criminal groups. The ones that create more of a problem are the genuine nation states, the pandas, the bears, that kind of thing. That's where we see more skilled trade craft. And they're also very often difficult to really get to understand what they're happening.
Their techniques are a lot stealthier. There's a lot more required for our investigations. That's where the problem really lies. The good news is they don't target that many people.
We get a lot of noise, but when they do, it's uh it is a very difficult, annoying investigation. Brilliant. Now, let's develop this a little bit further and we'll get on to the state of our industry, cybersecurity, and so forth. Now you've been constructively outspoken, I think is the way that I would put it, about all sorts of things to do with this industry.
And we're going to ask you about all of them. Well, no, as many as we can fit in. So let's turn a bit to digital infrastructure and some of the myth busting you've done. So you've become quite famous and a bit controversial sometimes about this.
Linux is a secure operating environment, myths. And that's just one example of you taking on some of the structural problems about core bits of hard and soft digital infrastructure that seem to be at the root of so many of our difficulties. How are we getting on with all of this stuff? We're getting better.
Yay. There is definite trends of improvements, would be the easiest way to describe it. But there is a genuine problem. And one of the reasons why I don't know if I like the term outspoken, but I'll lean into it.
One of the reasons behind that. I like it. We've kind of allowed ourselves to get into a kind of static mindset. The key truth of cybersecurity is tomorrow you need to learn something that you didn't know today.
This is a constant thing. The things that I thought were gospel truths in 2003 just aren't correct today. Absolutely. And if I'm not able to make that mental leap, I'd be wrong.
Yeah, yeah. The work that I do would be incorrect. And I think we struggle a little bit. So I will use the Linux one as an example.
Yeah. A lot of that came out. I went to a couple of uh conferences and I had uh reasonably senior people within cybersecurity making statements to me about Linux and Windows that will probably last true in 1997. Right.
And I'm like, we've got to have this constant learning mindset where we adapt and evolve relentlessly, really. Yeah, it's so funny, Taz. And I'm omitting some confirmation bias to your position and a love of a little bit of outspoken as well. So others could argue with us, but we love a story in cybersecurity.
We love to introduce a concept or an idea, a quip or a trope, a slogan. And then once it's, you know, in the language of security professionals, we hold on to that idea for so damn long, so hard. To your point on this kind of Linux thing, the relatively true position kind of back in the day, that a great deal of the general attack space was malware, focused on Windows, and that Linux enjoyed relative immunity to that problem, very fair. But that, of course, morphed into this well, it's secure and you don't have to worry about this stuff.
Yeah. Which is hilarious because whilst Linux provides incredible frameworks for security and customization in the right hands, I mean, out of the box, it provides some ludicrously fantastic ways for attackers to hide information and compromise just because they're not necessarily using a traditional piece of malware like on a Windows computer. And I still find people who hold to that idea today and will tell me there's no malware for Macs and iPhones and so on. We've got to slay these stories.
We've got to be outspoken. 100%. You've hit the exact nails on the head there. I mean, there's two kinds of angles to this that I don't know if frustrates the right word, but there's two kinds of angles that I think is an industry we need to be a bit better at.
First of all, the concept of secure is kind of meaningless without a threat actor. So you could be secure against an asteroid strike or secure against theft. Um, without trying to go too technically, but if we use like operating systems as an example, the Mac operating system, it's security models based around someone stealing your Mac device. The Windows operating system, it's security based around malware.
They've got two different threat models, so they implement security differently. If you say one's more secure than the other, you're kind of missing a significant element of a point. Yeah, you've got to say against what. Yeah.
Yeah, exactly. That what is the important bit. And then as you said, James, the key point for me is Linux, Linux operating systems. I love them.
I spend most of my life in Linux. Uh they can be secured against most things we'd consider an attack, but they don't come out of the box that way. The exact opposite when you first install it. No auditing, often weak privilege escalation paths.
Yeah, so it's about understanding. And instead of just sitting back on our heels and thinking to ourselves, oh, 20 years ago I was taught this, therefore it must be true. I think it's about that. We need to constantly understand that everything's changing and learn to adapt.
Yeah, constant re-evaluation. I think that's exactly right. And be careful with those tropes and stats and challenge yourself against what, against who type questions. One of my examples, I'll share very quickly to kind of support your point, Taz, and then Kieran will no doubt come up with a better question.
But you know, there's this often quoted stat that, you know, 95% of breaches involve and are caused by humans. And you kind of go, well, that's kind of briefs well at the surface. It's quoted all the time. But it goes back to an IBM report in 2015 where they specifically said that that was true in insider threat cases.
They weren't talking about the whole threat landscape and totality and all the API attacks, malware, web app, et cetera. It's a very specific niche. And people never quote that bit because it's not as catchy. And then in more recent studies that have happened over the last year, the great, you know, Verizon data breach report stuff is similar, they say that the stat is more like 68% the way people think about that, with humans clicking something they shouldn't and so on.
And much of the rest of the delta is made up from credential theft misconfiguration of systems and so on. Well, okay, but that's a bit like saying 95% of problems happen in a kitchen because there is a chef. Well, yeah, like of course. But you've got to be so careful on these tropes and stories.
It can really cause resource allocation issues and security leadership, can't it? Absolutely. That's exactly it. I think we do fall into this mindset.
And maybe it is a little bit, but there is a lack of data. I know getting reliable incident and intrusion metrics is always hit and miss. No one likes talking about them. For example, I don't think there's more than three cases I've worked in the last year that I could mention, let alone add into some kind of statistics thing.
But without that, it's always going to be a little bit more cause and effect challenged. Yeah. Well, let me jump back in here and I want to take you back to something you said a little while ago, and it was about the Linux environment. But I wanted to ask you about it because it's got wider applicability.
So you said you didn't like, or you mightn't be completely comfortable with the word outspoken. And that's fair enough because you're not one of these people who jumps up on a conference stage and says something outrageous and arresting, but you do challenge myths and you do try to put people right and make changes. But you told a really interesting story to get back to storytelling, but you didn't have time to develop it. So I wanted to ask you about it.
You're talking about earlier in your career, and there's some senior figures in the industry essentially talking nonsense about Linux to your face, and you push back. How did you do that? What happened? Was it difficult?
Were you nervous? And did it change anything? Because these are the things that have to be done, but they're not easy. Yeah, I don't think nervous isn't quite the right word.
Uh I was ultimately unsuccessful. Right. I might as well lead with a failure first. So this was a conference.
There was uh vendors talking about it, and the vendor had basically taken the stance that the problem that you've got with cybersecurity is that you all use Windows. If you come to us as your managed service provider, we'll migrate you to Linux. Linux is secure. Yeah.
In the questions part, I said that's not really the case, tried to ask it. And I did notice the thing that really stuck with me is almost all of the other attendees agreed with the vendor. I had people telling me that I didn't understand Linux, which I found quite entertaining. Yes.
Lots of people telling me I was a Luddite, I didn't understand the future, I was just the Windows fanboy. And ultimately, I don't think I convinced a single person in that session. Right. But it did inspire me to try and spread the word to everyone else who might be a bit more open-minded.
And you did have some success in that respect. And that brings me on to another question. And I'm gonna try and stick with you now. Things that are slightly controversial.
Now, having inadvertently accused you of shilling for Sans, having done two plugs, I'd forgotten I was going to ask this question because it's a belter. So last year you write an article on LinkedIn, and you know, it's called Cybersecurity Certifications. Are they worth it? Well, that's hardly something SANS would have paid you to do.
Absolutely not. So this is a SANS podcast. So cybersecurity certifications, are they worth it? Yes or no?
All right, you can have the classic cybersecurity answer if it depends, but what does it depend on? And more seriously, how does this whole debate about certifications, which has been running for a very long time? Now, what does it tell us about the state of our industry and the whole battle to get enough skilled people into the fight that you've been in and inspired so many others to get into? So I'm gonna avoid doing a consultant trope and saying it depends, although that's kind of the answer I want to give.
You've put me on a spot. Yeah. So I'll veer away from that. I'm gonna say yes.
Okay. I do think they are actually genuinely, and this has got absolutely nothing to do with any relationship with sounds or anything like that. I believed in them. The reason why I have a relationship with SANS is because I believe training and certifications are essential, not the other way around.
And why is that? Well, ultimately, so certifications, there's kind of two ways of looking at them. Uh, there is a certification whereby you can demonstrate that you know something. So if I go and do something like the cloud security certificate, it's just a straightforward exam that shows I understand the cloud.
Yeah. That type of certification allows you to go to other people and create that sort of like selection of trust. So, for example, let's say if I want to be an expert witness and I want to present to the court that have expert credentials, I can present to the court, here is a certification by this recognized body that says I know XYZ. That makes my ability to be an expert witness much easier.
If I'm applying for a job, it makes my ability to demonstrate to the hiring manager that I know something much easier. I'll come back to that because there's a little caveat there. That's where people get the most frustrated, I think. But the expert witness one is pretty useful.
That's one type of certification. They are absolutely worth it. They allow you to demonstrate to people that you can do things, maybe an insurance company, maybe a hiring manager, et cetera. Yeah.
Where it really pays off, though, are the ones that teach you something as well. A training class followed by a certification, for example. And I think this is where the biggest advantage can happen for cybersecurity as an industry, really. We've got lots of people, and there are a couple of caveats.
We'll hold on to that for a second. There are lots of people who need to know more. Right. I said earlier on that we've got an entire industry of people who maybe did a university class in 2004 and think the ext3 file systems, the default file system in the entire world, hasn't been true for a decade.
Yeah. I do miss it though. It was a nice file system. The easy days.
By doing training, we can improve, we can become better than that. We can learn what the state is today. And that to me is the essential thing. We've got to learn new skills.
Even if you think you've got a set of skills, like the very first, I'll use the air quotes where honest why you can't see them. The very first cyber investigation I did was like 1993. Right. The skills that I use today are completely different.
So I have to keep doing training and learning to keep that improving. Yeah. So that's the value. The bit that I've kind of hedged away from that leads to a lot of discussions, are people start to get a little bit focused on maybe the numbers, which I think is the challenge.
We mislead ourselves. There's a couple of perceptions that people tend to have. And a lot of it is that simply having the certification or the training isn't always enough. Yeah.
So I could have, let's say, I mean, I've been an expert witness in the past. I have been eviscerated on cross in the past. Right. Despite having certifications, it didn't save me.
No, sure. But without the certifications, I wouldn't have had the chance. And I think that that's quite a significant thing. There's also the cost-benefit trade-off.
And I think without drilling into numbers, the reality is we've got a lot of people who are in a very well-paid industry. Yeah. They should be willing to invest in making themselves better if they want to continue to be well paid. Yeah.
That's the bit that creates the most arguments with people. I think we've got to understand this. And from an employer's point of view, there's the old Henry Ford saying about uh what if I train my employees and they leave? Yeah.
What about if you don't train them and they stay? Yeah. Very good point. That's the biggest problem.
Yeah. So for me, long-winded roundabout way. No, very good. They absolutely are worth it to me.
And we'll put your LinkedIn post in the show notes because it's very, very good and very balanced. James. Thank you. It is indeed.
And as you note in the post, you know, there's no silver bullet. One is in charge of one's own career, and there are ways to do this without certifications, if you'd like to, and you suggest some of that too. But again, I admit confirmation bias in thinking that take is right from my perspective. But let's pivot to a couple of other spots before we run out of time, Taz, which I knew was going to be a problem on this podcast.
Just a question here about people and cybersecurity. One about the community and mentoring. You know, it's very clear from, for example, your last LinkedIn write-up that you're passionate about seeing people vicariously succeed in this industry. And you've done a lot of this.
You've spoken and written very proudly and movingly about it. Tell us a bit more about that and what you think could be done to bring more talent through to face these future challenges. We've got to help each other more, ultimately. We've got to understand the fact that there's a little of a perception, a minority of the community for it is a perception that if you help people, they're going to take your jobs.
I see this occasion with instant responders. Yeah. They're very reluctant to allow SOC analysts to sit alongside them because they feel if the SOC analyst can do it, they'll lose the job. That's not how it works.
Everything about cybersecurity is community driven. No one ever believes when I say this, but I am an introvert. And even if you don't like being around and talking to people, cybersecurity, you've got, you've got to find a way to make that work. You've got to share information.
Oh, threat actors are doing it. Threat actors have very active communities, they have active knowledge sharing. As defenders, we've got to get more into this. We've got to be more active.
We should attend more conferences. We should go to things like B-sides. We should be talking more. And I don't want to get told off uh talking about sounds too much again.
But as an example, pretty much every science class I teach, someone on the class says to me, Oh, here is this great tool I've written, here's my GitHub, here's this thing I've got. And that's then something that everyone, me included, can take away and utilize in our future work. And just by simply being around people and share these ideas, that's where cybersecurity gets better. It is awkward.
I understand that a lot of people, we have a certainly a stereotype within cybersecurity of not liking to talk to people, but we're amongst friends. This is the ideal opportunity to discuss topics that we've got a shared interest in. I think this is really how we can make cybersecurity better across the board. I love that, Taz.
And, you know, look, I think the next few years of cybersecurity are going to be very interesting. Whether you're, you know, hands-on keyboard, you're kind of in a sock, you're doing malware reversing, you're pen testing, you're in security leadership, AI, as well as the eternal pressure of kind of threat actors, will significantly reshape the profession. I don't think it will eliminate roles. I think there will be more of them, but the roles will be different.
And, you know, working through that disruption, using these technologies so that we come out with more good versus bad just requires that type of community engagement and discussion and togetherness. And I just I I want to underline the thing you said. The bad guys are doing it. So if we don't, we are going to set ourselves up for failure.
So a crucial and important point there, and lots of opportunities to get in engaged in the community. And many of them don't even have to be expensive. They can be free. But Taz, I do have an important last question for you before we go to a close here, because I know we're burning through time.
We mentioned in the opening your ludicrous collection of animals. We're reliably told at this time of recording that you have two pigs, four goats, two donkeys, a pony, a horse, six chickens, and five cats. So three questions. One, what why?
Why? Two, how? Like, how do you have the time? And three, perhaps most importantly, are they named after threat actors?
Uh like extra excitable pony, a punitive goat. I mean, I mean we could have great fun with this, but but are they named after threat actors? And if not, why not? So I'll go, I'll go through the three reverse and no, they're not named after threat actors.
Now you've said it, though, that's a fantastic idea. I really like that. I think any new ones will be from now on. Generally, most of them have really boring names.
Like, so for example, the goats. Goats are registered animals, so they have a little tag in a rear with a number that's registered in like the councils list. So I just call them by their number, like 406 and 428 and stuff like that. I haven't actually named them, even though they're 10 years old now.
How do I find a time? With difficulty. I think the the key is like you said earlier on, I just avoid sleep. Most of my work is actually done outside UK hours as well, which kind of helps a little bit.
And now we're getting into summer, it's a bit more daylight. But the big one, why? The interesting question about it is I don't really like being indoors. I find, I mean, let's say you if you spend 12 hours working in an incident and you need a way to decompress, going outside and trimming a goat's hooves, fighting the goat to let it trim you its hooves, getting beaten up by the goat.
That's a very, very good way to just kind of wash it all off. Yeah. It sounds like a future incident response presentation. That time I fought the goat.
Well, and it's also a pretty convincing answer because I can't imagine there are too many incident responses that you can lead from the outside. So, you know, dealing with all these things. But wrestling horses probably is a good way of decompressing. I know we're running out of time, but I can't resist this given that James said, you know, there's endless potential fun in this game.
We don't have time for much, but here's one bit. Okay, I'm gonna read out four animal-related threat actor names, and you have to tell me which one is a real, actual threat actor named by a credible cybersecurity company. Is it mournful donkey, indifferent pig, charming kitten, or resentful chicken? Which one's real?
The kitten. Yes. It's crowdstrike's a random English, isn't it? Lost well works with CrowdStrike, so CrowdStrike's the naming conventions I know the best.
Hey, if you'd have said one of Microsoft's I'm done. You know, I thought Mournful Donkey was almost plausible. Yeah. I like that though.
That is good. Last season I suggested Erudite Badger, and no one has made that happen yet. So I'm quite sad about that. Oh like that.
We've covered several. We've got to stop. We've got to stop. We're out of time, Kieran.
I'm gonna put the brakes on the threat hunter name in this occasion, but no doubt we'll have Taz back with a terrified ferret. Stop it. Okay. We'll have him back for an update on his farmyard animals and presumably his new acquisition of several ferrets based on that suggestion.
So look, Taz, we are gonna have to bring things to a close. But there is a pretty key thing we like to do at the end here, isn't there, Kieran? My favorite bit. Yes.
Yes, your favorite bit. Go on, tell them what it is. So, Taz, look, as you know, it's only fair if we have people listen to us about our, you know, naming conventions and so on, we give them something really pithy and useful at the end. So we are asking you for your 30-second takeaway.
So, Taz, this is a podcast about lessons for cybersecurity leaders. So, if you've got 30 seconds with a cybersecurity leader, what would you advise them? Something to pay attention to, to ignore, whatever it may be, 30 seconds of brilliant wisdom. Fully understand your network.
Don't rely entirely on things like CMDBs or existing network diagrams, understand the actual data paths, understand where people can access things, understand where the data resides. That's the 99% of every single intrusion I've ever worked. If you can know your land better than the threat actors, you can respond better, you can defend it better. Oh my god, I think that's the first one that's ever come in in under 30 seconds.
That's the most Taz thing ever. That's fantastic and very, very useful. Highly efficient. Maybe we'll have to slow it down in the broadcast version to overshoot 30 seconds like everybody else.
Well, look, thank you, Taz. That was incredible. That is it. Sadly.
It was brilliant, but tour de force, so much there, and one of the best takeaways ever. So thank you, Taz. Thank you for joining us. Thanks very much.
Thank you to everybody for listening. And you can leave us feedback at the podcast site or you can email us at cyberleaderspodcast at sans.org. Tell us whatever you want.
And with that, thank you for listening. Thank you for listening. Keep cybering. So for me, Kieran Martin, and me, James Lyon, it's goodbye, and I'm off to buy a ferret.
Bye bye.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.