
Cyber Work · 2025-08-18 · 57 min
Key moments - from our scoring
Substance score
49 / 100
Five dimensions, 20 points each
Jim Broome brings over two decades of hands-on experience in information security and red teaming, and he reflects on how he arrived at this career path - starting with early exposure to computers through his father's interest in ham radio and RF engineering, then progressing through bulletin board systems administration, forensics investigations, and eventually professional penetration testing and red teaming work. His background is unusual in that he worked backward from incident response and forensics into offensive security testing, which gave him deep insight into how attackers actually compromise systems. At Direct Defense, which he leads as president and CTO, Broome oversees security assessments, penetration testing, and specialized OT (operational technology) security work for organizations across multiple industries. His firm emphasizes peer review and collaboration - Broome himself still participates in active engagements rather than purely managing from above. The company operates dedicated practices for network penetration testing and OT security, with Broome personally qualified for sensitive OT environments thanks to his RF engineering background inherited from his father.
Broome started with early computer exposure through his father's ham radio interests, ran one of Georgia's larger bulletin board systems (BBS) in the Fidonet network with roughly 5,000 subscribers, maintained computer networks for school boards, and worked extensively in help desk, server administration, and incident response roles before transitioning to penetration testing.
Broome emphasizes that soft skills are more important than technical knowledge in red teaming, drawing from his background observing how users actually behave and the 'silly things that users do all day' - vulnerabilities that enable social engineering and human-centered attacks.
Direct Defense operates dedicated practices in network penetration testing and OT (operational technology) security, serving organizations across multiple industries with security assessments and red team operations in both IT and specialized operational environments.
Yes, Broome still occasionally does active red team work himself and goes through the company's peer review process, maintaining a hands-on approach rather than purely managing from above.
RF (radio frequency) engineering background, inherited from his father's ham radio interests, qualifies Broome to work in closed OT environments and specialized operational technology security assessments where standard IT knowledge is insufficient.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains genuine practitioner insights - red team readiness criteria, the MIT-grad clustering exploit, AI/SOAR noise discussion - but is heavily diluted by biographical anecdotes, team name-drops, disaster-bingo banter, and generic career advice. Useful content is present but sparse relative to 57 minutes.
a pin test is what we now call a red team. Uh, so it was a $25,000 no questions asked, no scope asked. We will just tell you when we're gonna start. And that's it.
I had a lot of big multinational companies that, for whatever reason, I got really lucky at the time. MIT was graduating a lot of Compsci guys and early InfoSec, uh, builders that they all read from the same manual. So, uh, the running gag was, uh, I would call the company up, find out where their Boston office was. Get the IP range for that and I would attack that office 'cause I knew exactly the blueprint on how to break in.
There are a few genuinely interesting observations - the MIT-grad monoculture as an attack surface, OT security's false sense of air-gap safety, hiring from event planning and education for soft skills. But the bulk of the framing (punch-in-the-mouth metaphor, red teams not being pass/fail, soft skills matter most) is well-worn security-podcast wisdom.
OT still lives in this, um, utopia that no one's ever gonna get access to the tools. And so really the, the only thing preventing, uh, bad things from happening is just getting access to this one app or this one piece of hardware
the foundational, um. Skillset that we're looking for, which is actually soft skills. They already know how to communicate. So, you know, one of the biggest things we've, uh, been very successful with is people looking at career change early in their career
Jim Broome is a genuine long-tenured practitioner - ISS X-Force, DirectDefense CTO, hands-on OT and physical red team work, US Olympic team security testing - not a thought-leader type. He speaks from real operational experience at scale, though he is a regional/mid-tier name rather than a globally recognised figure.
I was one of the very first companies. It was literally us and like at stake, uh, you know, we were the only two real big companies on, the. Private sector doing this type of work
we've actually supported them through multiple, um, you know, uh, years of testing, so I can, you know, we can go back and definitely have beer conversations over the first Beijing in Olympics all the way to
The episode is above average on specificity: named clients (Symantec 1996-97, Wizards of the Coast 2002, Chrysler), concrete numbers ($25k no-scope tests, 185,000 Chrysler employees, $8M RSA token proposal, 4.4 brute-force attempts per hour, domain admin in 10 minutes). The MIT-company anecdote loses credit for keeping names vague, and several security observations remain hand-wavy.
did one of the very first pen tests for Semantic way back in the day. so like 1996 and 97
we got really lucky at the time. MIT was graduating a lot of Compsci guys
The host asks a few substantively useful questions (red team readiness metrics, phishing vs. red teaming distinction) but predominantly runs a warm PR-style chat. He telegraphs answers before the guest finishes, never pushes back on any claims, and burns significant time on generic openers (childhood computers, what are you reading) and banter about disaster bingo and ants.
can you talk about what metrics companies should use when determining the appropriate time to carry out red teaming? Like what, what should they already have done and put in place before they even think about getting you and your team on the phone?
I'm not gonna ask you to name or shame any companies that, uh, were especially unprepared
Computed from the transcript - who did the talking, and the words that came up most.
Get your FREE Cybersecurity Salary Guide: Jim Broome of Direct Defense has been doing red teaming since before it became a term - back when a "pentest" meant $25,000, no questions asked and walking out with a server under your arm. In this episode, Jim shares wild stories from decades of ethical hacking, including breaking into major tech companies, causing a cardiac event during a physical penetration test, and why he believes soft skills trump technical knowledge for aspiring red teamers. Learn why most companies aren't ready for red teaming, how to transition into cybersecurity from unexpected fields like education or event planning, and what it really takes to succeed in offensive security.
Transcribed and scored by The B2B Podcast Index.
1 - > Chris Sienko: Today on cyber work. 2 - > I have a great conversation with Jim Broom of direct defense. 3 - > Jim has been doing red teaming since before it became a term 4 - > and pen testing back when pen tests were basically red team 5 - > operations. 6 - > Jim talks about some of his wildest red team stories and we 7 - > find out why Jim thinks soft skills are more important than 8 - > all the tech you can study.
9 - > If you have any interest in ethical hacking of any sort, you 10 - > must not miss this week's episode of cyber work. 11 - > The IT and cybersecurity job market is thriving. 12 - > The Bureau of Labor Statistics predicts 377, 500 new IT jobs 13 - > annually. 14 - > You need skill and hustle to obtain these jobs, of course, 15 - > but the good news is that cybersecurity professionals can 16 - > look forward to extremely competitive salaries.
17 - > That's why InfoSec has leveraged 20 years of industry experience 18 - > Drawing from multiple sources to give you, cyber work listeners, 19 - > an analysis of the most popular and top paying industry 20 - > certifications. 21 - > You can use it to navigate your way to a good paying cyber 22 - > security career. 23 - > So to get your free copy of our cyber security salary guide 24 - > ebook, just click the link in the description below. 25 - > It's right there near the top, just below me.
26 - > You can't miss it. 27 - > click the link in the description and download our 28 - > free cyber security salary guide ebook. 29 - > Your cyber security journey starts here. 30 - > Now let's get the show started Welcome to this week's episode 31 - > of the Cyber Work Podcast.
32 - > I'm your host, Chris sko. 33 - > Our my guests are a cross section of cybersecurity 34 - > industry thought leaders, and our goal is to help you learn 35 - > about cybersecurity trends and how those trends affect the work 36 - > of InfoSec professionals, as well as leaving you with some 37 - > tips and advice for breaking in or moving up the ladder in the 38 - > cybersecurity industry. 39 - > My guest today, Jim b Broome is a seasoned it IS veteran with 40 - > more than 20 years of information security experience 41 - > in both consultative and operational roles.
42 - > leads direct defense where he is responsible for the day-to-day 43 - > management of the company as well as providing guidance and 44 - > direction. 45 - > For service offerings. 46 - > Previously, Jim was a director with ACU Event Labs where he 47 - > managed, developed and performed information security assessments 48 - > for organizations across multiple industries, while also 49 - > developing and growing a team of consultants in his charge prior 50 - > to ACU event labs.
51 - > Jim was a principal security consultant with Internet 52 - > Security Systems, ISS and their X-Force penetration 53 - > Jim Broome: Uh. 54 - > Chris Sienko: Uh, Jim has also developed and provided training 55 - > courses on several security products, including being a 56 - > primary author of the Checkpoint software, uh, CC, uh, 57 - > S-A-C-C-S-E-C-C-S SI training program, as well as creating and 58 - > delivering numerous client-focused training programs 59 - > and events.
60 - > Uh, Jim is a. 61 - > Star superstar, red Teamer, and as we will 62 - > Jim Broome: Hashtag. 63 - > I'm old. 64 - > It's okay.
65 - > Chris Sienko: he is Yeah, I, I know all of us. 66 - > Yeah. 67 - > Legendary in the, in the field here. 68 - > It means we've been here a long time, but, uh, we are gonna talk 69 - > about, uh, red teaming and, and go real deep into it.
70 - > So, 71 - > Jim Broome: Sure, sure. 72 - > Chris Sienko: you for joining me today. 73 - > Welcome to Cyber Work. 74 - > Jim Broome: Yeah.
75 - > Thanks for having me on board. 76 - > Chris Sienko: My pleasure. 77 - > So Jim, uh, tell me about what got you interested in computers 78 - > and tech. 79 - > I'm guessing the tech bug bit you hard later on.
80 - > Uh, or were you always into it like this? 81 - > Jim Broome: definitely always into it. 82 - > Uh, I was, uh, early adopter, courtesy of my father, uh, so 83 - > hardcore ham, uh, you know, self-taught soldering when he 84 - > was like five all the way up to, so he was, he was a nerd in his 85 - > own Right. 86 - > in his own era.
87 - > Uh, and so by the time I came along, Yeah. 88 - > Was like my first computer, I think was when I was six, and 89 - > that was, like the Timex Sinclair, uh, all the way up to 90 - > the ti, you know, 99 4 A then eventually, uh, into, uh, more 91 - > industrial systems, uh, such as, uh, the original like, uh, Z one 92 - > hundreds early PCs, uh, you know, that did PCM and so forth. 93 - > So I've been using for a long time. 94 - > Uh, and then in my own right, uh, I.
95 - > Kinda started, you know, working with computers and grew up in a 96 - > small little area in coastal Georgia that, uh, wound up being 97 - > able to actually like, maintain the computer network for the, 98 - > uh, organization or for the, for the school board around there. 99 - > And then, uh, eventually was able to start one of my first 100 - > companies just doing, you know, you know, back when you could 101 - > make money building pc, uh, you know, building PCs and, and you 102 - > know, kind of growing from there.
103 - > So really the, From the ground up of the earliest days, uh, 104 - > running one of, you know, one of the, you know, more moderate 105 - > sized bulletin boards in the state of Georgia, you know, 106 - > phyto net early days. 107 - > So yeah, the, my, you know, my propeller spins, uh, pretty well 108 - > there on the hat, so, yeah. 109 - > Chris Sienko: the, uh, what, what, what were, what was part, 110 - > what, what was going on in the, the BBS? 111 - > What type of, uh, like groups did you have?
112 - > Jim Broome: Um, so I was the phyto net area coordinator for 113 - > my area code. 114 - > And then, uh, roughly had about 5,000 pay subscribers on the 115 - > platform. 116 - > And, you know, we had an amalgamation from those that are 117 - > really old. 118 - > They remember Wildcat VBS and VBS for gaming and so forth.
119 - > So we kind of had to roll our own experience. 120 - > Um, you know, we got fortunate, if you will, and that's, you 121 - > know, the, the euphemism in there simply because, um. 122 - > The German auto manufacturers were coming into Mayport in 123 - > Jacksonville, and there was a problem with acid rain back in 124 - > those days. 125 - > And so the, the paint jobs were going bad while in dry dock, so 126 - > they moved all that production up to Brunswick, Georgia, which 127 - > is where the area I lived in.
128 - > Uh, and so we inherited a whole bunch of Germans that understood 129 - > net mail and you know, like, you know, pre a OL there was no 130 - > CompuServe dial up, those type of things. 131 - > And so they, you know, essentially that was like the 132 - > only game in town for the longest time. 133 - > Between that and, uh, like the, uh. 134 - > Uh, St.
135 - > Mary's, which is the, uh, home of the Kings Bay, you know, uh, 136 - > or submarine fleet. 137 - > Chris Sienko: Yeah. 138 - > Jim Broome: so it had a bunch of, bunch of people that, you 139 - > know, were nerds in their own right and were using email and, 140 - > and or what would become email, uh, before there was internet. 141 - > And then, uh, you know, roughly by 93, 94, we were starting to 142 - > get gobbled up by some of The, bigger organizations.
143 - > And, uh, but yeah. 144 - > I remember being a US robotics tester with 144 phone lines and 145 - > all the fun stuff that comes with that. 146 - > Chris Sienko: Love it. 147 - > I love it.
148 - > The, the Silicon Valley of the South there. 149 - > Yeah. 150 - > That's 151 - > Jim Broome: Oh yeah. 152 - > Chris Sienko: Yeah.
153 - > Yeah. 154 - > Big tech influx. 155 - > I love that. 156 - > Uh, so yeah, you, you mentioned that you, uh, started out in, in 157 - > kind of building computers and also network security.
158 - > Uh, you know, and I, I do this already about you because I look 159 - > at everyone's, uh, LinkedIn experience profiles to get a 160 - > sense of your, uh, sort of narrative, 161 - > Jim Broome: Mm-hmm. 162 - > Chris Sienko: of your, your career leading up to being 163 - > president and CTO of direct defense. 164 - > So, um, I wanna kind of. 165 - > Ask if you remember a point where you started sliding away 166 - > from network operations and into red and blue teaming as your 167 - > primary focus, or was that something you were interested 168 - > in?
169 - > And then it just, when the time came, you jumped over there? 170 - > Jim Broome: I was always interested in, like, uh, the 171 - > biggest part was just supporting, uh, so, you know, it 172 - > wasn't in the industry. 173 - > Uh, it wasn't like you could just dive into this and so you 174 - > had to kind of quote unquote, you know, uh, make, make your 175 - > own and, and go out there and, you know, kind of build your 176 - > career path. 177 - > And so at the time it, was, I.
178 - > From general, what we now call help desk and, you know, server 179 - > administration, network administration, operations, 180 - > keeping things up, you know, during natural disasters like 181 - > hurricanes and and whatnot. 182 - > Um, you know, learning from those experience, um, you know, 183 - > in my own right. 184 - > And then finally just, you know, supporting users and seeing the 185 - > silly things that users do all day, um, or that we don't have a 186 - > manual for Uh, and so, uh, you know, that turned into.
187 - > Um, you know, email 188 - > Chris Sienko: Yeah. 189 - > Jim Broome: from the earliest days, or if you remember, Palm 190 - > Pilots, 191 - > Chris Sienko: yeah. 192 - > Jim Broome: you know, you know, you know, users leaving, you 193 - > know, leaving a device, which is still a problem with, uh, BYOD 194 - > these days, you know, lost or, you know, stolen phones. 195 - > We didn't have, you know, mobile device to management platforms 196 - > to help us.
197 - > And so having to figure out what's going on, having to work 198 - > with law enforcement, which. 199 - > Was also a background because of the proximity to the federal law 200 - > enforcement training center there in Brunswick, Georgia, 201 - > actually known as glenco. 202 - > Um, you know, I got my earliest days in my, honestly, my teenage 203 - > years learning how to do basic dos forensics, uh, back in those 204 - > days. 205 - > And so, um, through that, I, you know, took that into my 206 - > professional career.
207 - > And so I was always the guy looking at how they got in or 208 - > reviewing, like, you know, how, how bulletin boards were broken 209 - > into and how user accounts were compromised all the way up to 210 - > personal devices. 211 - > And if you remember, um. 212 - > Uh, PC link, uh, the way to copy two files and when they've 213 - > actually added their own first, uh, dial up fossil driver, you 214 - > know, that became when they've actually added their own first, 215 - > uh, dial up investigations.
216 - > 'cause someone world outward dialed them and found their 217 - > phone number and 218 - > Chris Sienko: Wow. 219 - > Jim Broome: onto their pc. 220 - > So, 221 - > Chris Sienko: Yeah. 222 - > Yeah.
223 - > It's a, it's a, it's a long tradition. 224 - > I mean, you're, you're, you're talking about stuff that, you 225 - > know, almost kind of goes back to, uh, you know, like phone 226 - > freaking in the seventies and stuff like that. 227 - > And like 228 - > Jim Broome: oh, yeah, that's, that, that's, that's my core 229 - > book, that's my core background, so, yeah. 230 - > Chris Sienko: of a, all kind of a continuum, which is really 231 - > cool.
232 - > Uh, you mentioned, um, doing work for, uh, weather, weather 233 - > stations or weather communication. 234 - > What, what was that like? 235 - > Jim Broome: Um, you do going through weather events. 236 - > So essentially by living in the Caribbean, I, uh, for a while 237 - > there I lived on the Virgin Islands.
238 - > I've gone through lots of, uh, hurricanes and so forth, and so 239 - > in, uh, helping both, uh, like? 240 - > fema, uh, federal or local responses get back online. 241 - > You know, as an example, I as a, in my teenage years when I was, 242 - > uh. 243 - > My, it.
244 - > would've been my senior year, my family moved down to the Virgin 245 - > Islands, and we, we went through Hurricane Hugo down there. 246 - > Uh, at the time my father was an engineer for a, uh, local radio 247 - > station. 248 - > So we were the only game in town for six months. 249 - > Like everybody else, all the towers were down, things like 250 - > that.
251 - > But we were able to get back online using the a am 252 - > transmitter side, just because, you know, again, my dad being a 253 - > a, an RF nerd. 254 - > Uh, you know, being able to back go to 1950s copper wire between 255 - > two points and be able to actually be the only form of 256 - > communication to the local public. 257 - > So, you know, if you, you know, have a, you know, belief in a 258 - > higher power or whatever that may be, that was our cause for 259 - > being there at that time to be able to, you know, bring 260 - > communication back to the island.
261 - > Chris Sienko: Love it Now, um, uh, you know, I always wanna ask 262 - > about your, your current job role. 263 - > And obviously, uh, direct defense is a, you know, is a, is 264 - > is a organization that I think our, our listeners are gonna 265 - > know about. 266 - > Like, what type of tasks and projects do you work on as 267 - > president and CTO in an average week? 268 - > Jim Broome: Um, well, I know teasingly, I had also head 269 - > janitor.
270 - > Uh, but uh, uh, outside of that, uh, really today is, uh, you 271 - > know, working with the various teams on the various projects 272 - > they're going on to, uh, you know, from a business leadership 273 - > side, actually figuring out what's next for us as a company, 274 - > what's our growth strategy, and, you know, all the way up to 275 - > marketing and things. 276 - > So I kind of, my hands in a lot of buckets at the end of the 277 - > day, 278 - > Chris Sienko: Are you 279 - > Jim Broome: from a prac.
280 - > Go ahead. 281 - > Chris Sienko: yeah, I was gonna say, are you ever looking in on, 282 - > on sort of like projects that they're working on, on, on a 283 - > technical side? 284 - > Are 285 - > Jim Broome: Sure. 286 - > Chris Sienko: like checking their homework and stuff like 287 - > that?
288 - > Jim Broome: Um, Yeah. 289 - > I mean, honestly, at the end of the day, we are a services 290 - > company, so, you know, we have to review our, you know, we, we 291 - > believe in peer review. 292 - > Matter of fact, I still occasionally, you know, break 293 - > out the old rusty, uh, you know, uh, backpack and, and go do some 294 - > work myself. 295 - > And I go through our own peer process.
296 - > So it's not like, oh, it's my name's on the door. 297 - > No, it's, we still believe in making sure it's collaboration 298 - > across the board. 299 - > So, um, Yeah. 300 - > uh, really working with the net pin guys.
301 - > Uh, you know, in, in addition to that, we have a dedicated OT 302 - > practice and. 303 - > Thankfully, my hair is gray enough. 304 - > I, I qualify, uh, that I can go and work inside of those 305 - > environments. 306 - > And so, uh, that also gets into my own background of also being 307 - > an RF nerd from my father, 308 - > Chris Sienko: Mm-hmm.
309 - > Jim Broome: of, uh, working inside of those, you know, 310 - > closed environments. 311 - > Uh, you know, doing work with specific utility companies as 312 - > they add new solutions to their, um, you know, field area 313 - > networks, all the way up to what's on the side of your 314 - > house, uh, legacy wise. 315 - > And so, you know, that. 316 - > could be, you know.
317 - > Black box testing scenario or an actual, like proper or Faraday 318 - > environment, um, you know, testing radio signals and so 319 - > forth. 320 - > Like even just, just recently we got a request to see if, uh, 321 - > someone could do GPS hacking. 322 - > Like, Yeah. 323 - > been there, done that.
324 - > Um, here's the requirements. 325 - > Um, you know, you can't do this in the wild boys and girls. 326 - > You will go to jail if they catch you. 327 - > Uh, so it's more of, you know, here's.
328 - > Here's the environment you need to provide for us to be able to 329 - > do this. 330 - > You know, not only ethically, but also, you know, you know, 331 - > without causing damage to the immediate area. 332 - > Um, which there are environments that, that, you know, work like 333 - > that. 334 - > Uh, you know, you can easily look us up as one of the 335 - > certifiers for.
336 - > In flight entertainment systems, uh, for the PCI, you know, 337 - > standard as well as, uh, infotainment within automotive 338 - > and in, uh, marine. 339 - > Uh, so we get a chance to kind of play with, you know, you 340 - > know, infotainment and Lansing and air, uh, all the way up to 341 - > utility companies and, you know, you name it, you know, you get 342 - > it thrown. 343 - > You know, most recently was doing some device hacking for 344 - > tele, you know, coming to market telemetry, medical devices.
345 - > Chris Sienko: Yeah. 346 - > Jim Broome: so, you know, it's, it's always fun, uh, if you 347 - > will, to, uh, you know, be on the offensive side. 348 - > On the defensive side, I'm still a forensic guy, so, you know, 349 - > from, you know, business email compromises and working with the 350 - > team all the way up to uh, you know, really acting as breach 351 - > coordinator, uh, during ransomware events and helping 352 - > clients get back online, that's. 353 - > Also a skillset set that myself and other couple of colleagues 354 - > here, like, you know, Chris Walcott, who, uh, also 355 - > represents the OT practice, he and I have played disaster 356 - > bingo.
357 - > And there's not many boxes we haven't, you know, ticked off 358 - > yet. 359 - > So it's one of those things that 360 - > Chris Sienko: board. 361 - > Jim Broome: yeah, it's a skillset we can bring. 362 - > Uh, we, we haven't been able to tick off, uh, locust, haven't 363 - > gone through one of the plague locusts yet.
364 - > I've heard about one in the data center. 365 - > Chris Sienko: Okay. 366 - > Jim Broome: and then, uh, haven't done a tsunami. 367 - > Uh, I've done flooding, I've done volcanic eruption.
368 - > I've done a trail de train derailment through the front, 369 - > uh, through a data center. 370 - > So, yeah. 371 - > Chris Sienko: I dunno if you've seen the movie phase four, but 372 - > if you, you'll have to watch out for a tech takeover by, uh, 373 - > Legion of Sentient Ants, uh, that they could add that one to 374 - > your, if you have an extra room on your Bingo card there. 375 - > Yeah.
376 - > Jim Broome: Uh, yeah. 377 - > Why? 378 - > Well, yeah, yeah, I do remember it. 379 - > And then, uh, uh, teasingly, I have gone through a plague of, 380 - > you know, ants and not in a data center, but in a personal 381 - > computer, so, yeah.
382 - > Chris Sienko: They weren't, they weren't, they weren't as as 383 - > smart 384 - > Jim Broome: Not a Cynthia. 385 - > They were just looking for warmth. 386 - > Chris Sienko: They were just looking for a warmth. 387 - > Okay, well you, uh, you know, I wanna do this, uh, for a change 388 - > because, uh, you mentioned in your LinkedIn description of the 389 - > job, I work with 390 - > Jim Broome: Mm-hmm.
391 - > Chris Sienko: of people. 392 - > Uh, and we don't always get to do that, but yeah. 393 - > Tell me about your amazing team. 394 - > Like you really have, you know, the type of work where you have 395 - > to have kind of people who are top line in terms of, of red 396 - > teaming and defending, you know, pen testing, forensics, like you 397 - > said.
398 - > Uh, tell me about the people you work with. 399 - > Jim Broome: Sure. 400 - > Yeah. 401 - > I mean, um, start on the offensive side.
402 - > Uh, really we've got, uh, you know, folks like Nick Schumann 403 - > who leads the team over there on the net pin side, as well as the 404 - > red teaming practice day to day. 405 - > Uh, you know, we got individual contributors like Jesse, uh, 406 - > Rodriguez, uh, who is kind of our, one of our little stalwarts 407 - > and loves to go out there and do all the physical pin testing. 408 - > Uh, most recently got a chance to play in a prison. 409 - > So that was fun.
410 - > Uh, and then, uh, on the, uh, application side, we've got the 411 - > quite a few contributors that met Everett, uh, you know, 412 - > running the shop as well as, uh, Sean, um, you know, uh, Sean 413 - > Stewart, uh, running, you know, running with the crew and Sean 414 - > Sherman, sorry, uh, running with the crew as well. 415 - > Uh, and individual contributors, like, uh, um, uh, let's see. 416 - > Uh. 417 - > Uh, Hudson, uh, uh, just recently I got a chance to do a 418 - > couple of, uh, fun projects for a few companies We can't name, 419 - > but, uh, you know, I got into actually being able to do some 420 - > protocol analysis and reverse engineering.
421 - > You know, time is always an an important factor. 422 - > Uh, you know, you know, you know, cheat code for everybody. 423 - > If you really wanna start, you know, doing protocol analysis, 424 - > play with time. 425 - > Uh, and then, you know, from the, you know, managed services 426 - > side, uh, Charlie, uh, you know, uh, bun and crew, you know, run 427 - > that, you know, practice from a day to day standpoint.
428 - > Uh, recent acquisitions would be like, uh, Andrew Kagan, uh, who 429 - > is our IR specialist, all the way to the guys that are there 430 - > on the front lines, you know, day in and day out. 431 - > Like, uh, you know, both Dan Brunell and um. 432 - > Uh, Steve Pua, you know, just handling cu you know, customer 433 - > and events as they come through 'em. 434 - > So it's kind of, 435 - > Chris Sienko: Yeah.
436 - > Jim Broome: touch a lot of people every day. 437 - > Uh, roughly, uh, yeah, this week about 128 employees. 438 - > Um, so. 439 - > Chris Sienko: Now, as, as, as as president, CTO and as you said, 440 - > janitor, I'm assuming you probably had at least some, uh, 441 - > overseeing, if not outright, uh, influence in hiring these folks.
442 - > So can you talk about what you to pick these team members if 443 - > there were certain attributes or things in their background that 444 - > attracted you to them? 445 - > Jim Broome: Um, sure. 446 - > Actually, uh, that's a deeper dive. 447 - > Uh, literally just got finished doing a presentation at Rocky 448 - > Mountain InfoSec, uh, about helping people get into the 449 - > industry or doing a career change, but realistically and 450 - > more opportunistically as an employer, I.
451 - > Uh, number one is we try to be as concise as possible. 452 - > We're looking for specific talent or specific roles. 453 - > Uh, really the contributors that we're looking for when we talk 454 - > about consultants either have a really good background in that 455 - > skillset, so they're a little bit more senior in their 456 - > journey. 457 - > Um, all the way up to the ones that are just coming into the 458 - > industry that we're looking for some self-starters, uh, but more 459 - > importantly, really showing that drive and really have that basic 460 - > foundational, um.
461 - > Skillset that we're looking for, which is actually soft skills. 462 - > They already know how to communicate. 463 - > So, you know, one of the biggest things we've, uh, been very 464 - > successful with is people looking at career change early 465 - > in their career. 466 - > Um, for better, for worse, we've been very successful in hiring, 467 - > uh, a few people that were coming outta the education 468 - > world.
469 - > Uh, you know, they're already class teachers. 470 - > Um, and most recently, especially for, you know, the 471 - > ladies, uh, out there, uh, that Are most com uh, commonly coming 472 - > from event planners. 473 - > Uh, as well, uh, you know, so they, they, they understand how 474 - > to work in pressure, uh, but also, uh, uh, those coming from 475 - > the medical field. 476 - > So, uh, you know, again, better for worse, you know, looking for 477 - > a change in career.
478 - > And they already understand the concept of working under a 479 - > methodology or a process, and so they really get it. 480 - > Foundationally, we just need to teach them the technical part. 481 - > They already got the soft skills to run and, and lead an 482 - > organization 483 - > Chris Sienko: are 484 - > Jim Broome: a room. 485 - > Chris Sienko: are you sort of recommending to them that they 486 - > come to your company or are they, they, they were actively 487 - > looking for this type of work and were making the job change.
488 - > Is it, is 489 - > Jim Broome: I also do career counseling for people looking to 490 - > just try to get in and cut their teeth. 491 - > So it's like, do you start with, you know, my, my part is I don't 492 - > have a formal education. 493 - > Uh, you know, you know, high school, you got my good enough 494 - > degree, 495 - > Chris Sienko: Yeah. 496 - > Jim Broome: to Georgia Tech for three weeks and said, nah, I'm 497 - > good.
498 - > Uh, and basic, you know, met some people along the way. 499 - > They started some bigger companies like Chris Klaus at 500 - > ISS, uh, but, uh, the, the joke being that, you know, this Is a 501 - > new, you know, if you will, this is a blue collar job. 502 - > it, is a trade skill. 503 - > And so there is apprentice and mentorship programs that we can 504 - > bring in.
505 - > There are certifications that people don't have to go get a 506 - > four year degree. 507 - > I do recommend it if your, if your ultimate goal is to be 508 - > management in five years or less, but if it's not, come on 509 - > board. 510 - > Let's come to work. 511 - > Don't go into debt and we'll train you along the way.
512 - > Um, and so that's kind of my, my biggest, you know, uh. 513 - > You know, give back, if you will. 514 - > Just making sure that A, we foundationally do it as a 515 - > company, but b, you know, talk about it to other employers out 516 - > there like, Hey, you know, there's, there's no reason to 517 - > look for a four year degree because 90% of the content being 518 - > taught at, at the higher ed right now is not applicable to 519 - > the job you're hiring for. 520 - > Chris Sienko: Right.
521 - > Um, now boy, you, you got me wanting to, to, to tangent a 522 - > little bit here. 523 - > Can you talk about like what attribute. 524 - > some of the, you know, the, you said you had people from 525 - > education, you had people from event planning. 526 - > What, what attributes of those former I mean, I could, I could 527 - > make a whole matrix outta this.
528 - > 'cause that, that's a big part of our listenership and our, you 529 - > know, customer based is people who are trying to transition 530 - > into cybersecurity later in life from other 531 - > Jim Broome: Mm-hmm. 532 - > Chris Sienko: careers. 533 - > So like what, uh, of, of, of the type of, uh, job roles that you 534 - > mentioned, what, what attributes, uh, from their 535 - > previous job, uh, directly match to what you're trying to teach 536 - > them? 537 - > Once you get the tech in'em.
538 - > Jim Broome: Yeah. 539 - > I mean, the biggest part of that is, again, it's gonna be soft 540 - > skills. 541 - > So being able to communicate effectively and concisely, um, 542 - > you know, all the way up to, you know, if you're looking for 543 - > someone that, that is looking to be a principal consultant in a 544 - > short amount of time, you know, they've gotta be a leader. 545 - > They've gotta, you know, draw attention to themselves because, 546 - > you know, let's, let's be real.
547 - > There's a difference between engineering, consultant and 548 - > engineer is a highly skilled, trained, you know, individual, 549 - > uh, that's delivering on the skill that they've been taught. 550 - > So was the consultant, but they were mostly paid for their 551 - > opinion. 552 - > So if you don't learn how to express your opinion, you're 553 - > gonna struggle to get advancement. 554 - > And so, you know, we hire consultants.
555 - > Uh, we we're looking for, you know, people that are 556 - > opinionated and, and you know, do go out and do the legwork And 557 - > the homework for themselves. 558 - > That's something that's kind of intangible. 559 - > I can't, I. 560 - > Teach you to do that.
561 - > I can do my best to foster it to you, but you gotta want to. 562 - > Um, And so that's kind of one of the bigger challenges of finding 563 - > the, those people that want to be out in front or at least part 564 - > of the conversation and have a, having a voice in a room to, you 565 - > know, be part of a team or be part, you know, help guide a 566 - > customer to their, their end goal. 567 - > Their end destination. 568 - > Chris Sienko: And 569 - > Jim Broome: secondarily is problem solving number one.
570 - > Like, you know, how do you handle pressure and how do you 571 - > like, you know, from, you know, teasing back in the day where, 572 - > you know, Oh, my, my laptop busted on the plane. 573 - > All of you like, you know, corporate can't gimme a laptop 574 - > fast enough. 575 - > yeah. 576 - > Go rent one from Best Buy for the day and just get the job 577 - > done.
578 - > Uh, you know, those type of things. 579 - > Just, you know, all the way up to, you know, uh, colleagues in 580 - > the industry that, uh, you know, a couple generations ago they 581 - > came in from the analog to digital migration of audio. 582 - > So guys like Martin B or uh, Lee Baird as an examples, they were, 583 - > they were formerly sound engineers, sometimes roadies, 584 - > uh, for well name acts. 585 - > And, and, and you know, they got, that's how they got their 586 - > teeth and they, 587 - > Chris Sienko: I 588 - > Jim Broome: cut their teeth on, you know, working under 589 - > pressure.
590 - > And they had that mindset of wanting to continue to learn, 591 - > but they also had a really good opinion and they, you know, they 592 - > would, we were more than willing to share that opinion in a, in 593 - > a, in a setting. 594 - > And those are, you know, really the biggest intangibles. 595 - > I, I, I, I can't. 596 - > You know, train you.
597 - > I can, I can give you the mindset, but you gotta want it 598 - > to be able to really connect it. 599 - > and understand where it's gonna go. 600 - > And that's the thing, that's the character I, I constantly look 601 - > for So 602 - > Chris Sienko: So look, so looking at those, those types of 603 - > candidates and knowing that they don't have, uh, the technical 604 - > background, what is the, what is the sort of basic bootcamp for 605 - > someone who came from, say, events planning or education or, 606 - > uh, audio, you know, AV or whatever.
607 - > Like what, what is the baseline of tech? 608 - > You need them to understand that you're gonna sort of teach them 609 - > on the 610 - > Jim Broome: It really depends on, you know, you know, the good 611 - > news is we're in industry. 612 - > The bad news is we're in industry, so now we have 613 - > specialization. 614 - > Chris Sienko: Yeah.
615 - > Yeah. 616 - > Jim Broome: I think literally for the presentation I tracked 617 - > out like 30 potential skills or, or jobs you could go do in this 618 - > industry today. 619 - > And that was even I. 620 - > A lot of that was rolled up.
621 - > Uh, but, you know, to, to directly answer the question, 622 - > like if you're looking for an entry level SOC analyst working 623 - > your way up to lead analysts, you know that, you know, basic 624 - > foundation, CompTIA, you know, security plus, plus, you 625 - > understand just the general concepts of why we log things 626 - > all the way to learning, you know, the next advanced levels, 627 - > which are, you know, either learning the specific technology 628 - > or learning an actual, um, you know, methodology like, uh, 629 - > malware analysis, forensics, you know, those will train you into 630 - > the jobs that we're looking for.
631 - > You know, the technology should be transferable because, you 632 - > know, as an MDR provider, I use several tools. 633 - > So, you know, I need you, you know, ultimately I'm gonna have 634 - > to train you to be proficient in those tools. 635 - > But you need to understand the basic, you know, framework of 636 - > why we're doing it in the first place. 637 - > So it's, those certifications are the ones I'm looking for.
638 - > Be it, you know, GIAC and Under Sands and individual, uh, you 639 - > know, courses all the way up to, you know, people that, you know, 640 - > when we talk about offense security, the OSCP, um, you 641 - > know, even the. 642 - > Um, you know, the, the newer reverse engineering classes that 643 - > have been coming out, uh, hardware hacking, so forth like 644 - > that, that have been very tangible for us. 645 - > Um, and then even, you know, some of our. 646 - > You know, uh, most recent, uh, hires as well as, uh, folks that 647 - > have gone to their, you know, starting to lead their own 648 - > shops, uh, you know, using Nolan Johnson as a great example where 649 - > here's a, you know, uh, literally a, a young guy, a kid, 650 - > not to, you know, he's now 26, uh, but we've known him for a 651 - > long time.
652 - > But, you know, he's, he got his first CVE at 17, you know, he's 653 - > been doing hardware hacking, you know, for, um, you know, Android 654 - > devices for decades, you know, at this point. 655 - > And so he, you know, kind of grew up in a, in a, in a. 656 - > Bug bounty economy all the way up to now. 657 - > He literally paid, you know, uh, he's just getting, uh, uh, 658 - > engaged and getting ready to buy his first house, and he's paying 659 - > for it with bug bounty money.
660 - > Chris Sienko: Wow. 661 - > Jim Broome: so in addition to being a principal, you know, 662 - > consultant at the end of the day, So, 663 - > Chris Sienko: Amazing. 664 - > Jim Broome: yeah. 665 - > Chris Sienko: yeah.
666 - > Uh, uh, uh, as, as our listeners know, a third thing that 667 - > Jim Broome: Yep. 668 - > Chris Sienko: is death, death and taxes, at least here on 669 - > cyber work, is that if we post a new episode with the words red 670 - > team in it, uh, our numbers are gonna spike. 671 - > So we like to get, uh, do our best to get as many people as 672 - > possible talking about. 673 - > You know, this most appealing and roguish version of ethical 674 - > hacking.
675 - > 'cause I, you know, I think we all have, uh, the idea in our 676 - > head of, of what this looks like, and I think some of it's 677 - > actually true. 678 - > Jim Broome: Mm-hmm. 679 - > Chris Sienko: can you talk about some of the big companies or 680 - > brands that you've done red team operations on, 681 - > Jim Broome: Uh, we will give you dated references if that works 682 - > for you. 683 - > So, uh, I mean, I might end, you know, I was one, you know, very 684 - > fortunate to actually work at Internet Security Systems.
685 - > Back in the day. 686 - > We were one of the very first companies. 687 - > It was literally us and like at stake, uh, you know, we were the 688 - > only two real big companies on, the. 689 - > Private sector doing this type of work, you know, as a vendor 690 - > of products, we were doing it simply to show people why they 691 - > needed to buy our products.
692 - > Um, and so, you know, but both alumni here, like Phil Brass is 693 - > an example. 694 - > His name was on part of the patent for system scanner and 695 - > internet scanner, uh, Caleb SMA of, uh, web and spec fame. 696 - > And, you know, you know. 697 - > New, new companies.
698 - > You started, uh, right and left Lately, uh, you know, we all 699 - > came from that same core environment of really just 700 - > teaching, you know, companies they needed to. 701 - > So my answer is gonna be a little dated and old guy-ish or 702 - > ageist ageism, which is back in my day. 703 - > You know, a pin test is what we now call a red team. 704 - > Uh, so it was a$25,000 no questions asked, no scope asked.
705 - > We will just tell you when we're gonna start. 706 - > And that's it. 707 - > And it was a real, you know, for lack of a better analogy, it was 708 - > a punch in the mouth. 709 - > Is the organization prepared to, you know, you know, withstand a 710 - > direct attack?
711 - > And how, how good are they? 712 - > And in most cases, back in those days,'cause again, firewalls 713 - > were not common yet, um, really didn't start seeing those 714 - > commonplace till like 2001. 715 - > Uh, it was pretty easy. 716 - > Uh, in most cases it was really, uh, you know, you would.
717 - > Break in, you know, if they had a firewall, cool. 718 - > If they didn't, you'd almost be guaranteed to break in. 719 - > They were using, um, uh, like a Qualcomm's pop service, you 720 - > know, for pop three email. 721 - > And that was always notoriously, you know, uh, over flowable, uh, 722 - > all the way up to SCO boxes and, you know, Solaris boxes back in 723 - > the day, which I always carried about a good half dozen o days 724 - > in my back pocket for those.
725 - > Um, very easy to, to find an unpatched system. 726 - > Breaking it off you would go. 727 - > Um, or in the rare instance where they were actually, uh, a 728 - > challenge, uh, you just basically call up the front desk 729 - > and find out where the data center was, fly out to the 730 - > facility because part of the pen test was to put a file on a 731 - > server, the capture the flag moment. 732 - > So I, I'd physically walk into the data center and, and walk 733 - > out the door with the server, like, okay, you know, do I win 734 - > now and sit in the parking lot with a, with a server under my 735 - > arm?
736 - > Uh, and so, you know, being able to push all those buttons, yes, 737 - > it was very cowboy-ish, uh, but be able to, you know, push out 738 - > those buttons and really drive the point of why we're doing the 739 - > testing is really, you know, like, man, make, make it hurt, 740 - > make it painful. 741 - > Um, so, uh, teasingly to, you know, asked for a name and so 742 - > like, uh, did one of the very first pen tests for Semantic way 743 - > back in the day. 744 - > Chris Sienko: Wow.
745 - > Jim Broome: so like 1996 and 97, um, um, all the way up to other 746 - > organizations that, um. 747 - > You know, from, you know, engineering the, the picket.com, 748 - > I basically spent my time on the, you know, uh, the 1 0 1 749 - > corridor between, uh, you know, El Camino real and all the way 750 - > down to the Mil pita exit. 751 - > Uh, so you know, from Google, you know, at one point there was 752 - > some, Microsystems was on the right hand side of the street.
753 - > Google was over here into, it was two blocks down, so you name 754 - > it. 755 - > We tested them all. 756 - > Uh, at some point in time, but so they're, you know, fairly 757 - > dated, you know, we're talking, you know, nearly 15 years ago in 758 - > 20 ca 20 years ago in some cases, but every single one of 759 - > 'em. 760 - > Yeah, exactly.
761 - > I hope they've changed the solutions by this point. 762 - > Chris Sienko: right? 763 - > Jim Broome: but in most cases, Yeah. 764 - > it was many of the common mistakes of, uh.
765 - > You know, early wifi in 2001, when that, when that hit with, 766 - > uh, Peter Shipley going to Bewa at the Napster building and 767 - > doing that presentation, we were there hanging out and, you know, 768 - > had fun with him. 769 - > Uh, and then the next day we all went out and got these kits and 770 - > built them. 771 - > We were driving up and down and, you know, literally you were 772 - > jumping in and outta network. 773 - > So like jumping on, you know, Google's network or this network 774 - > without actually, you know, doing anything.
775 - > You're just pack caption as you're going down, you know, the 776 - > highway at 70 miles an hour. 777 - > Chris Sienko: Right. 778 - > Jim Broome: Um, all the way to, uh, our favorite one, and 779 - > without naming names. 780 - > Um, I, I went through a rash for about, uh, nine and a half 781 - > months there.
782 - > Uh, I had a lot of big multinational companies that, 783 - > for whatever reason, I got really lucky at the time. 784 - > Uh, MIT was graduating a lot of Compsci guys and early InfoSec, 785 - > uh, builders that they all read from the same manual. 786 - > So, uh, the running gag was, uh, I would call the company up, 787 - > find out where their Boston office was. 788 - > Get the IP range for that and I would attack that office'cause I 789 - > knew exactly the blueprint on how to break in.
790 - > 'cause they were all MIT grads. 791 - > Uh, so literally I had an entire sump, you know, a nine month, 792 - > you know, window of just breaking in just because I knew 793 - > they all went through the same instruction manual and did the 794 - > same thing time and time again, 795 - > Chris Sienko: Yeah. 796 - > Jim Broome: had the manual literally 797 - > Chris Sienko: Any particularly unusual events or wild moments, 798 - > or has any of your team ever been arrested during red 799 - > teaming?
800 - > Jim Broome: never been arrested on our side. 801 - > Um, obviously everybody knows the, story of what happened with 802 - > the guys over coal fire a couple years ago. 803 - > Uh, but. 804 - > Chris Sienko: they were on the show to tell the story.
805 - > Yep. 806 - > Jim Broome: Yeah. 807 - > Yeah. 808 - > But at the same time, uh, literally, you know, we've, I 809 - > can tell you in my personal career, the only two places I've 810 - > ever been caught physically had first strike capabilities.
811 - > So, you know, that was, you know, doing other work, uh, 812 - > outside of that and, you know, so, you know, never 813 - > underestimate the power of an 18-year-old with an M 16. 814 - > Um. 815 - > Uh, 816 - > Chris Sienko: Okay. 817 - > Jim Broome: outside of that, in the, in the, in the private 818 - > sector?
819 - > No, I've never been caught in, in process of, uh, however, we 820 - > have had a couple of guys, um, you know, using Jesse as a great 821 - > example, literally his first engagement coming in, um, the 822 - > customer actually engaged us to go in. 823 - > They actually wanted a physical penetration to the facility, 824 - > didn't let anybody know and on. 825 - > Fortunately, the person that caught him as he was walking 826 - > through the facility tried to kind of manhandle him a little 827 - > bit to get him out.
828 - > Like, I don't, you know, you're not supposed to be here. 829 - > And in the process of wrestling around and, you know, it was all 830 - > on video. 831 - > Jess, you know, Jesse never touched him. 832 - > Just basically, you know, let, let the guy push him back out.
833 - > Uh, but during that process, the guy actually started going into, 834 - > uh, a cardiac event. 835 - > Chris Sienko: Whew. 836 - > Jim Broome: So having to stop the PIN test and literally go 837 - > over there and pull off the a ED off the wall and, you know, you 838 - > know, help the guy. 839 - > So not only did we successfully break into the building, but we 840 - > also, you know, helped the, uh, helped the poor gentleman that 841 - > was there at the customer site, uh, you know, and got him, he 842 - > called first response and, you know, got him through the fast 843 - > forward a year later, uh, they let Jesse go back and do the 844 - > same penetration test and the first guy to meet him was that 845 - > guy who immediately came up and gave him a huge hug.
846 - > So it does end out well. 847 - > Chris Sienko: Yeah. 848 - > Glad you 849 - > Jim Broome: Yeah. 850 - > Chris Sienko: Right.
851 - > Um, you know, I, I'm not gonna ask you to name or shame any 852 - > companies that, uh, were especially unprepared or, you 853 - > know, what brought, brought down, you know, for them. 854 - > But can you talk about any clients or companies that were 855 - > strong enough to really keep your team at bay? 856 - > Does anyone ever get an A grade from you guys? 857 - > Jim Broome: Um, short answer is yes, I, I'll put the caveat.
858 - > Um, usually it's been scoped. 859 - > Uh, so there's been been a few things that, uh, you know, the 860 - > gloves aren't off. 861 - > Uh, again, I, I go old school, which is, you know, this should 862 - > be a real world event and you should not, you know, you know, 863 - > everything should be on the table. 864 - > I.
865 - > That's not the reality where we live in, especially now because 866 - > of insurance and compliance and X, Y, Z. 867 - > Um, but, you know, my own career, I can tell you the, my, 868 - > my favorite, uh, example of that was, uh, if you remember, 869 - > wizards of the Coast Magic, the Gathering Online when it first 870 - > launched in what, 2002? 871 - > Chris Sienko: Mm-hmm. 872 - > Jim Broome: That was one of'em.
873 - > Uh, so, you know, I was charged to break into the facility that 874 - > hosted their systems and actually tried to attack their 875 - > systems and they did it right. 876 - > Literally there was only two ports. 877 - > Didn't matter if you were on the internet or inside the building, 878 - > and there was only two ports open, so they were locked down 879 - > and, you know, properly logged. 880 - > They had their own, uh, security, you know, solutions in 881 - > place.
882 - > And they caught me. 883 - > Um, so I was like, you know, you know, props, you know, 884 - > physically didn't catch me. 885 - > I, I still was able to, you know, get out, get outta the 886 - > building with the servers, but they were locked down really 887 - > well. 888 - > Uh, fast forward to today's environment, really the things 889 - > that we're getting asked to do.
890 - > time and time again, uh, because of the OT practices really 891 - > testing. 892 - > Uh, environments that are getting prepared for other major 893 - > sports event. 894 - > Um, which if you think about all the. 895 - > Solutions that are in play during that time just to be a 896 - > host city.
897 - > Uh, you've got state, federal, you name it, they're all there. 898 - > Uh, plus the event itself and, and all the things that go with 899 - > it. 900 - > So we get asked to, you know, or tasked, if you will, to test a 901 - > lot of different things. 902 - > Um, you know, so sometimes they're prepared, sometimes 903 - > they're not.
904 - > Um, you know, one of the things I we constantly talk about 905 - > publicly is OT still lives in this. 906 - > Um, utopia that no one's ever gonna get access to the tools. 907 - > And so really the, the only thing preventing, uh, bad things 908 - > from happening is just getting access to this one app or this 909 - > one piece of hardware or this, and you'll be amazed what you 910 - > can find at, uh, Harbor Freight. 911 - > Uh, so, you know, so, you know, you can bypass, you know, 912 - > physical bypasses all the way up to, um, you know, literally, uh, 913 - > we have one utility provider that they have this really cool 914 - > thing that if you're familiar with the way the, um.
915 - > Power works if there's a storm now, you know, if you grew up as 916 - > a kid, especially in the south, get a lightning storm and it 917 - > blows out the whole area. 918 - > Nowadays that's minimized because they have this magical 919 - > box at the top of the, of the pole that, you know. 920 - > back in the day, the guy would have to go out there with a long 921 - > stick and, you know, pull the fuses at the top to uh, you 922 - > know, just, just minimize the impact of the area.
923 - > Now these things are automated. 924 - > They're called in inte Intel Raptors. 925 - > And so, you know, that software, you know, is the vendor that 926 - > makes that software, makes a very, very compelling security 927 - > model. 928 - > Chris Sienko: Mm-hmm.
929 - > Jim Broome: up to the utility company to implement that. 930 - > And so in many cases it's just, you know, can you get access to 931 - > someone's laptop and you make that software off of there. 932 - > And you know, I've, I've proven time and time again that, you 933 - > know, the solution actually has robust security. 934 - > You guys should really roll this out.
935 - > 'cause otherwise just, I, I went over to the maintenance bay and 936 - > just stole your laptop out of the truck. 937 - > Chris Sienko: Well, you got me thinking about, yeah. 938 - > Now that you said, uh, major sporting events, I, I don't 939 - > suppose you've ever read team to an an Olympic 940 - > Jim Broome: Um, not a city. 941 - > uh, but, uh, you know, 942 - > Chris Sienko: venues.
943 - > Jim Broome: our company's based in Colorado, so, uh, we're right 944 - > there with the, uh, us uh, you know, team USA. 945 - > We've actually supported them through multiple, um, you know, 946 - > uh, years of testing, so I can, you know, we can go back and 947 - > definitely have beer conversations over the first 948 - > Beijing in Olympics all the way to, 949 - > Chris Sienko: Wow. 950 - > Jim Broome: which was very interesting to the most recent, 951 - > uh, Olympics.
952 - > So, you know, just, you know. 953 - > Chris Sienko: I feel like I could feel like every, every 954 - > answer is giving me 15 more questions. 955 - > So anyway, I, I won't, I won't. 956 - > We, we won't, uh, uh, you know, linger in the glory days.
957 - > 'cause I 958 - > Jim Broome: Mm-hmm. 959 - > Chris Sienko: about a more practical aspect of this 960 - > discussion. 961 - > Uh, one common thing I hear with pen testers and red teamers, and 962 - > I just spoke with someone, uh, last week, ed Williams from 963 - > Trustwave, talking about. 964 - > Um, issues with red teaming is that, uh, a lot of companies 965 - > jump too fast into hiring red teams against them, maybe 966 - > feeling that it's the thing you do once you get to a certain 967 - > size or it's a, you know, a vanity marker or something like 968 - > that.
969 - > So, what, could you talk about what metrics companies should 970 - > use when determining the appropriate time to carry out 971 - > red teaming? 972 - > Like what, what should they already have done and put in 973 - > place before they even think about getting you and your team 974 - > on the phone? 975 - > Jim Broome: Um, so first and foremost, uh, you know, it's 976 - > great question actually. 977 - > Uh, so first and foremost is are they ready?
978 - > Are they have, have they gone through penetration testing and 979 - > they reliably are repelling them? 980 - > They're not. 981 - > Finding a lot of highs and, you know, uh, critical unpatched 982 - > things because I'm not there to validate you patch and unpatched 983 - > the box. 984 - > I'm there to actually break your security.
985 - > Um, and so, you know, that's part of the, and part of the 986 - > norm is expecting what the results are supposed to be. 987 - > You know, a red team is not supposed to be. 988 - > Run some scans and sprinkle some meta. 989 - > Boy, you can call it a day.
990 - > That's, that's not the engagement. 991 - > It's, it's supposed to be a punch in the mouth. 992 - > I'm here to either simulate stealing stuff Or legit steal 993 - > stuff, uh, you know, from the organization. 994 - > And it's your job to detect, you know, I.
995 - > Quarantine me and isolate me and get me out of there and then, 996 - > you know, come back and write a report on everything I touched 997 - > and did. 998 - > Um, and so it's really that, you know, I also can do the duality 999 - > of this, which is I also, you know, help manage a soc. 1000 - > Uh, so I see both sides of the equation of, you know, what is 1001 - > the red team and is the organization prepared? 1002 - > So that's, that's really the first and foremost.
1003 - > You know, the, the question we try to qualify outta the gate is 1004 - > what are, what's your goal? 1005 - > What are you hoping to get out of this? 1006 - > You know, I, I'm happy to help you write this so you can get 1007 - > the proper funding. 1008 - > You look, you need, uh, you know, and, and drive the, the 1009 - > point home of you need these things.
1010 - > But realistically, you know, when we talk about red teaming. 1011 - > It is that going the next step? 1012 - > And so, uh, the most common example we get to is, oh, can 1013 - > you do phishing? 1014 - > Sure.
1015 - > We do phishing all the time. 1016 - > Um, you know, what do you want us to do? 1017 - > Do you want us to actually, you know, use those creds, log in 1018 - > and pivot and check someone's email? 1019 - > You want us to actually drop payload on your systems and 1020 - > circumvent your EDR and really get persistence in the 1021 - > environment?
1022 - > No, no, No, I just need somebody to tell me if they click the 1023 - > link and I'm like, well, that's, that's no. 1024 - > before, 1025 - > Chris Sienko: Yeah. 1026 - > Jim Broome: that's user awareness training. 1027 - > That's not exactly.
1028 - > Chris Sienko: Before is our arrival anyway. 1029 - > Jim Broome: sorry, sorry, sorry, sorry. 1030 - > Chris Sienko: No 1031 - > Jim Broome: Yeah, yeah. 1032 - > Chris Sienko: I 1033 - > Jim Broome: mean, but, but again, Yeah, apologies.
1034 - > Uh, but yeah. 1035 - > just, uh, but you know, the concepts, you know that that's 1036 - > user awareness training, that's a feedback loop to see if people 1037 - > are getting the message. 1038 - > I'm here to really test it, and that's, that's really the big 1039 - > qualifier is like, you know, we want to go the next mile. 1040 - > Matter of fact, most red teamers will pay you because they have 1041 - > so much fun doing it.
1042 - > Chris Sienko: Yeah. 1043 - > Jim Broome: Uh, you know, to get, to be able, you know, the 1044 - > gloves are off. 1045 - > I really can actually go do the things I've been, you know, 1046 - > wanting to do for a long time. 1047 - > And that's kind Of where physical comes into play.
1048 - > And one of the things that we prompt people, especially when 1049 - > we talk about um, events, uh, or, or preparedness, is, you 1050 - > know, please get someone from HR involved in legal. 1051 - > Um, you're, you're, you know, we are gonna push buttons and, and 1052 - > it's not, and you know, it's truthfully not. 1053 - > And. 1054 - > Uh, intended to be a harassment or, uh, you know, like, you 1055 - > know, piling on somebody.
1056 - > This is an education moment for the organization across the 1057 - > board. 1058 - > And, uh, we can use one example of, you know, we, we did a 1059 - > phishing campaign. 1060 - > They caught the typical example, um, and then we went back and 1061 - > did another one. 1062 - > And all we did is we trolled'em for a little bit, used some TPT 1063 - > to write up a campaign.
1064 - > And what we had found out was this particular organization was 1065 - > partnered with a local hospital. 1066 - > It was coming into the time of the year, sorry, not camera. 1067 - > Uh, it's coming into that time of the year where it was time to 1068 - > volunteer and give back. 1069 - > And so it was, we were rolling into Thanksgiving and so we 1070 - > wrote a campaign saying, Hey, who here would like to sign up 1071 - > for a$500 gift certificate to vol to volunteer at this 1072 - > hospital that you work with, with, you know, sick kids?
1073 - > Everybody in the company fell for it, including the CEO. 1074 - > Chris Sienko: Yeah. 1075 - > Yeah, yeah. 1076 - > We've, we've, we've talked on, 1077 - > Jim Broome: Yeah.
1078 - > Chris Sienko: whether you wanna really sort of use the, the 1079 - > phishing nuclear option on things like, you know, you've 1080 - > lost your insurance or there's no bonus this year, and things 1081 - > like that, like that, that, that, those have a shockingly 1082 - > high open rate. 1083 - > Of course. 1084 - > Jim Broome: But again, it's the reality of, you know, like 1085 - > thankfully the c Yeah. 1086 - > after the initial shock, the CEO actually saw that, you know, 1087 - > this was intentional, you know, you guys paid for it and we kind 1088 - > of, you know, uh, walked someone off the ledge.
1089 - > Chris Sienko: Yeah. 1090 - > Jim Broome: we treated it and immediately pivoted to a 1091 - > education moment. 1092 - > And that's kind of the thing I, I, I do a lot, especially with 1093 - > when we talk about penetration testing or just red teaming, um, 1094 - > you know, you hired us to break in. 1095 - > That's kind of what we do.
1096 - > That is my job. 1097 - > So don't treat this, you know, treat it adversarial outta The. 1098 - > gate, but don't treat it as this, you know, pass fail thing. 1099 - > It's our job.
1100 - > I'm always gonna get in. 1101 - > If you really, if I'm allowed to really use what I got at my 1102 - > disposal, what I really wanna do is give you context on how long 1103 - > it takes. 1104 - > And so, you know, like part of my penetration testing is, you 1105 - > know, uh, learning to write with context and, you know, talking 1106 - > to a customer is like, well, you got some really. 1107 - > Busted processes and here's what's going on.
1108 - > And they were, they were all upset. 1109 - > 'cause I broke in. 1110 - > I was like, that's my job. 1111 - > I mean, just to kind of measure you guys, it took me an hour and 1112 - > a half.
1113 - > My normal is under 20 minutes. 1114 - > Chris Sienko: Yeah. 1115 - > Jim Broome: So, you know, you, you, you lasted an hour and a 1116 - > half with a, with a quote unquote skilled pin tester or 1117 - > skilled attacker sitting inside your office and, and, and 1118 - > beating up on everything. 1119 - > So that's pretty good 1120 - > Chris Sienko: Well, yeah, yeah, yeah.
1121 - > The, the poet Mike Tyson once said everyone has a plan until 1122 - > they 1123 - > Jim Broome: until you get punched in the mouth. 1124 - > Yeah. 1125 - > Chris Sienko: uh, so yeah. 1126 - > So I mean, I guess to that, to that end, can you talk about why 1127 - > it would be bad to get a red team run on your, before your 1128 - > security system is ready to handle it?
1129 - > Is it just a waste of money? 1130 - > Is it demoralizing? 1131 - > Or is that punch in the mouth maybe gonna actually drive some 1132 - > change? 1133 - > Jim Broome: Um, it's too, uh, the bad side of the equation is 1134 - > Yeah, really you're, you're gonna.
1135 - > Hurt some feelings. 1136 - > Um, and, and really just kind of, you know, it, it's, it's 1137 - > more the education and more the, um, you know, advertisement 1138 - > marketing, if you will, within the company. 1139 - > Why we're doing these type of things. 1140 - > As far as preparedness, really, again, that's gonna be a reality 1141 - > check for companies.
1142 - > Uh, my favorite example of that one is I. 1143 - > Uh, you know, everybody has a disaster recovery plan, business 1144 - > continuity plan, and then ransomware come in. 1145 - > You know, threat actors get in there and they delete. 1146 - > The first thing they go in there is they log into the Veeam 1147 - > server and delete all the backups.
1148 - > So the question is, when is the last time you did an offsite 1149 - > backup and is with inspect of your business operation, you 1150 - > know, requirements. 1151 - > The answer's almost 99.9% of the time. 1152 - > No.
1153 - > uh, you know, two months outta date. 1154 - > And it's, you know, that's too big of a window. 1155 - > We gotta go pay the ransom to get our data back. 1156 - > Um, and that's the reality.
1157 - > Like say, you know, if we really went this far, then we do 1158 - > ransomware simulations that go that hard. 1159 - > Like, Hey, I can touch it, I can delete everything you got right 1160 - > here. 1161 - > I won't do it. 1162 - > But, um, or we put, you know, a couple thousand files on your 1163 - > file server and we intentionally delete and encrypt that folder.
1164 - > So every EDR and everything else in the world should have been 1165 - > screaming, uh, just activity wise that we were doing this and 1166 - > we were shuffling it out to mega to io and all the other, you 1167 - > know, typical recipients, just to see if you could see it. 1168 - > So we can give you as near real world as possible with a few, 1169 - > you know, safety measures in place. 1170 - > But again, it's are you prepared? 1171 - > Um, this is not treat it pass fail, but this is an education 1172 - > moment on how you can actually take these as initiatives, 1173 - > validate your findings, kind of go from there.
1174 - > Um, you know, I can, I can give you the, the best red team. 1175 - > Most recently we went through, um, large organization. 1176 - > They had actually three socks. 1177 - > Uh, they have, uh, uh, an outsourced, um, uh, MDR provider 1178 - > doing one specific, you know, visibility story.
1179 - > They have a normal eight to five soc, but then there are large 1180 - > global, you know, organization. 1181 - > So they have an extended SOC that handles things after hours. 1182 - > You know, when we got in there and started doing our testing, 1183 - > I. 1184 - > All I had to do was a couple of things and looked, I knew they 1185 - > were gonna fail, um, simply because they weren't logging the 1186 - > right things.
1187 - > And that was part of the conversation. 1188 - > Like, you know, you, how much are you spending on your 1189 - > solutions today? 1190 - > Are they properly giving you the visibility you're looking for? 1191 - > You think they would, you know, knowing that someone's coming in 1192 - > scheduled.
1193 - > It was no, you wasn't blind, it was everybody. 1194 - > It was participant as a purple team. 1195 - > Um, just basic homework like, Hey, what's the video to detect 1196 - > file deletion and file renaming and, you know, if, if everything 1197 - > else fails, can I see files move in my environment? 1198 - > Nope, none of that was turned on, so.
1199 - > They were totally blind. 1200 - > And I was sitting there with the sock, like, anybody see it yet? 1201 - > How about do we, this, you know, the, you know, the bad actors 1202 - > over here? 1203 - > You already got his IP address and like, you know, nudge, 1204 - > nudge, nudge, nudge, nudge.
1205 - > And finally I was like, all right, you know, the reason 1206 - > you're not seeing this is, you know, I gave him the answer key. 1207 - > So once they turned that on, magically they could start 1208 - > seeing, you know, the activity going on. 1209 - > And they gave him that visibility story. 1210 - > Um, but that's just basic foundational fundamentals.
1211 - > So if you. 1212 - > You know, you think you're prepared, but in reality you 1213 - > haven't gone back and just made sure that, you know, you're 1214 - > actually logging this stuff. 1215 - > You, I can hold you accountable, uh, in this scenario. 1216 - > And so that was the, that was the, the, the biggest learning 1217 - > thing was there was a lot of that foundational things that 1218 - > had just never been done.
1219 - > Chris Sienko: Yeah. 1220 - > Yeah. 1221 - > Now, um, I imagine an especially disastrous, uh, report from, 1222 - > from a red team. 1223 - > Uh, you know, attack might be something you could take to your 1224 - > leadership and say, uh, you know, in, in case you wanted to 1225 - > whistle past the graveyard, or you don't think we have the 1226 - > money, like, find the money.
1227 - > Like we, you know, like it, it certainly would open that 1228 - > conversation up with a, with a, a more concrete example, I 1229 - > suppose, 1230 - > Jim Broome: Um, Yeah. 1231 - > but that also comes back to the maturity organization as well 1232 - > as, you know, how good their CISO is. 1233 - > You know, sitting down with CISOs and just kind of having 1234 - > the, the brass tacks of what is your insurance policy, what 1235 - > technologies have you invested in?
1236 - > Chris Sienko: Mm-hmm. 1237 - > Jim Broome: is your real, you know, uh. 1238 - > Uh, the, you know, worst case scenario, a risk profile, you 1239 - > know, risk tolerance in the organization. 1240 - > You know, when we deal with ransomware as the, as the, you 1241 - > know, the, you know, the good guy helping the customer get 1242 - > back online, uh, like the bigger challenge there, just, you know, 1243 - > the realm of reality of how many systems failed.
1244 - > I. 1245 - > I was like, you could have tested yourself to see, you 1246 - > know, beforehand, but unfortunately we got a real 1247 - > world example. 1248 - > Um, and then, you know, the secondary part of just the 1249 - > reality of, you know, why this failed, we didn't think about 1250 - > that. 1251 - > You know, the, if then, you know, like, you know, the good 1252 - > news, bad news, in my case, in my own background of growing up 1253 - > around some natural disasters, I.
1254 - > You know, you know, it's really hard to restore a server when 1255 - > there's no building. 1256 - > Uh, and so, you know, you, you kinda learn the hard way of us, 1257 - > like, you know, I'm just gonna take, you know, my backup 1258 - > restore process and I'm gonna break certain parts of it to see 1259 - > if I can still get a recoverable backup out of this thing. 1260 - > Um, that mindset doesn't exist at times, and so you kind have 1261 - > to retrain people or, or help them develop that muscle to just 1262 - > question the entire process and, and look for foundational 1263 - > visibilities, 1264 - > Chris Sienko: Yeah.
1265 - > Jim Broome: across the board. 1266 - > Chris Sienko: You've stated emphatically in various articles 1267 - > and interviews that you've, you've written that AI tools and 1268 - > various automations have made attackers a lot more, uh, 1269 - > effective and, and subtle, but that the defense side hasn't 1270 - > necessarily kept up with the times. 1271 - > Uh, can you talk about some changes you'd like to see the 1272 - > security industry adopt to better address these sort of 1273 - > speed and efficiency challenges, uh, 1274 - > Jim Broome: Um, sure.
1275 - > A couple answers on that one. 1276 - > Um, so the bigger challenge that we have, whenever any new 1277 - > technology comes out and, you know, like, uh, I'll use SOAR as 1278 - > the first example and then go to, you know, ai, can we, you 1279 - > know, soar. 1280 - > For better or for worse, especially the first couple 1281 - > generations was there to automate noise. 1282 - > It was to close things out that was quote unquote driving the 1283 - > sock, you know, uh, bonkers because it was just low 1284 - > confidence, low low fidelity type of alerts, you know, signal 1285 - > to noise ratios we talk about.
1286 - > And like, you know, there's not a lot of detection coming out of 1287 - > this, or a lot, a lot of, you know, true positive this is an 1288 - > attack. 1289 - > Um, and so. 1290 - > That's where the first source were spent majority of the time. 1291 - > You know, like the investment, the vendor creation, the, the, 1292 - > the stories they would come to market with was all about just 1293 - > clearing out noise.
1294 - > That's kind of where we're at right now with ai. 1295 - > Uh, AI is cleaning out noise faster and letting us get and 1296 - > trying to surface higher signal to noise or higher confidence 1297 - > alerts up to us. 1298 - > When we're still stuck with a lot of noise. 1299 - > And so what I really work with a lot of socks on purple teaming 1300 - > is let's get to the quick, you know, like you don't need to 1301 - > spend a lot of these new, these new technologies are great, but 1302 - > you don't need'em.
1303 - > If you can actually just always have a, you know, if this alert 1304 - > goes off, it's highly confident we're having a bad day. 1305 - > I mean, They're there will be some false positives along the 1306 - > way, but you know, at the end of the day I can always kind of 1307 - > rely that we, we should all act if this comes in. 1308 - > And, you know, orchestrating a sock is the same way on our side 1309 - > of, you know, what we call a. 1310 - > Sev one priority, one severe warning.
1311 - > You know, there should only be a handful of those. 1312 - > Like this is worst case scenario. 1313 - > Def con rally, everybody. 1314 - > There shouldn't be a hundred of those.
1315 - > You know, the D one down, like high P two, whatever you wanna 1316 - > call it. 1317 - > You know, there. 1318 - > should only be like 30 maybe tops. 1319 - > Like there's only certain, you know.
1320 - > But again, highly, highly confident. 1321 - > So we know we have proof positive what we have to work 1322 - > and where AI is hopefully helping us and starting to help 1323 - > us. 1324 - > As if we move further to the left of low confidence, now 1325 - > we're down to 40, 50, 60, 30% confident that this is a sign of 1326 - > an initial attack. 1327 - > And greatest example I can give you that is literally every 1328 - > holiday season, uh, as the runup, uh, to, you know, from 1329 - > Thanksgiving forward, the amount of, uh, brute forcing and, and, 1330 - > um, uh, phishing campaigns that go against our, our clients, 1331 - > especially, you know, it doesn't matter if you're on G Suite or 1332 - > if you're on uh, M 365, they all have the same issue.
1333 - > They all get hit. 1334 - > 4.4, you know, 4.4 times per hour.
1335 - > Uh, and so you're literally seeing all this stuff come at 1336 - > you and like, alright, now I know one of you got hit. 1337 - > Chris Sienko: Mm-hmm. 1338 - > Jim Broome: so how, you know, like, like the bad guy hasn't 1339 - > logged in yet. 1340 - > So I don't have proof positive the account is compromised, but 1341 - > I think it kind of is.
1342 - > And so that's where you're looking for, you know, the 1343 - > enrichment story from soar. 1344 - > And now ai, which is alright, it's, it's probably a personal 1345 - > VP n provider more than likely out of M 24, you know, 24 7 out 1346 - > of New York or down out of uh, LA or down out of Miami. 1347 - > So that's the, or you know, that's who owns the IP address. 1348 - > It's already Got a, eh, reputation.
1349 - > Uh, now I can actually associate this with logging in. 1350 - > This person's never come in from this before and then, you know, 1351 - > start. 1352 - > Applying just a basic threat model of is the likelihood high 1353 - > this user has been compromised? 1354 - > And then work with the organization to have a level of, 1355 - > is it.
1356 - > okay if I just go ahead and knock your user offline and 1357 - > reset their account right Now, 'cause I think they are 1358 - > compromised. 1359 - > so it's like that early kill switch. 1360 - > And so CISOs are starting to really ask for that. 1361 - > Like, you know, like you, you know, Jim, you guys caught it 1362 - > when the bad guy already logged in.
1363 - > I need you guys to start catching it. 1364 - > Before they even log in. 1365 - > And I was like, well, now we're getting into analytics and you 1366 - > know, Microsoft and, and Google haven't cracked that nut yet, 1367 - > and you're expecting a human to figure it out for you. 1368 - > So let's, let's sit down and just come up with a level of 1369 - > confidence, you know, if I can see the following things.
1370 - > And that's where we're looking for AI and those type of tools, 1371 - > they're really start adding value. 1372 - > And they're not there yet, but they're, they're, they're 1373 - > starting to come, you know, I give'em about another 12 to 24 1374 - > months and they'll be there. 1375 - > Chris Sienko: Got it. 1376 - > Now, 1377 - > Jim Broome: Yeah.
1378 - > Chris Sienko: our listeners who are, are glued to this episode 1379 - > and, and are already thinking about doing red teaming 1380 - > themselves as a career, uh, what should they be working on 1381 - > immediately to put their feet on the career path they want? 1382 - > Or are there certain things that you've noticed younger, ethical 1383 - > hackers are not paying attention, paying enough 1384 - > attention to or keeping up with that you think is crucial? 1385 - > Jim Broome: Um, multi-story again, I go, I always go back to 1386 - > the soft skills.
1387 - > First and foremost, learn to write, learn to have context in 1388 - > your writing. 1389 - > Like I was giving the example of. 1390 - > Typically takes me 20 minutes. 1391 - > You guys lasted an hour and a half.
1392 - > You know, that is, you know, at the end of the day a client is 1393 - > hiring you, especially for a red team to validate something. 1394 - > Either their investment for the past year on security 1395 - > technologies or you know, new SOC provider, whatever it may be 1396 - > is working or it's not working. 1397 - > Learn to write with that context. 1398 - > Secondarily is really.
1399 - > Taking it beyond just the initial, what, you know, you 1400 - > know, run, scan, run Metasploit, that's not, you know, that's not 1401 - > red taping. 1402 - > Uh, in most cases you can actually do a lot of damage with 1403 - > never running to exploit inside the environment either getting a 1404 - > password log, you know, physically breaking in and 1405 - > picking a lock all the way up to just honestly walking around the 1406 - > building and asking people to let you in.
1407 - > Um, once you're in, you can actually start looking at file 1408 - > cabinets, that old stuff called paper. 1409 - > You know, there's Still a lot of it in this industry, 1410 - > Chris Sienko: Yep. 1411 - > Jim Broome: all the way up to, uh. 1412 - > Chris Sienko: lot of, A lot of Post-it notes on people's 1413 - > computers, on your 1414 - > Jim Broome: Sure.
1415 - > I mean, using, using Jesse as our example there, he, uh, you 1416 - > know, there's actually an article on the, on the website 1417 - > that we talk about where he essentially posed as a 1418 - > groundskeeper. 1419 - > They had a very formal interview process, including having to 1420 - > come out and do a CBT training, uh, on the company. 1421 - > They hired him. 1422 - > They, they gave him a job offering and he finally had to, 1423 - > you know, divulge, he was a pen tester at the end of this.
1424 - > Like, you know, thanks for the job, but I think I'll, I'll keep 1425 - > my day job. 1426 - > Uh. 1427 - > Yeah, but the, the joke was during the, the CBT session, he 1428 - > literally just walked in there, unplugged, you know, unplugged 1429 - > the computer that they gave him access to and plugged it right 1430 - > into his laptop and started, you know, he got domain admin in 1431 - > like 10 minutes and then finished the CBT test. 1432 - > Chris Sienko: Whew.
1433 - > Boy. 1434 - > That that's a, that that's the, the, the, the, the report you 1435 - > don't want to share with your boss, like 1436 - > Jim Broome: Actually they took it in stride. 1437 - > Chris Sienko: Okay, 1438 - > Jim Broome: again, it's like, you know, this is our job. 1439 - > The question was, you know, why didn't you have, you know, why 1440 - > couldn't you detect a rogue device on your network?
1441 - > We haven't invested in nac. 1442 - > And you know, basically you just kind of give'em the whole play 1443 - > by play. 1444 - > And eventually when, when it was all said and done, you're like, 1445 - > alright, we get it. 1446 - > We see how we failed.
1447 - > The only thing that we had was we, we asked you for an ID and 1448 - > we put you in a room with live network jacks that don't need 1449 - > live network jacks. 1450 - > Chris Sienko: Yeah. 1451 - > Yeah. 1452 - > Now, like when you've hired red team members in the past, 1453 - > Jim Broome: Mm-hmm.
1454 - > Chris Sienko: interview question or line of questioning that 1455 - > really sort of surprised them or knocked them back on their 1456 - > heels? 1457 - > Or are there certain things that. 1458 - > Red team, red teamers to be should be like ready to, to 1459 - > rattle off in a, in a moment's notice. 1460 - > Jim Broome: Um, the one that usually poses everybody is, 1461 - > gimme an example of where you felt and what you learned from 1462 - > it.
1463 - > Chris Sienko: Mm-hmm. 1464 - > Jim Broome: You know, a lot of people aren't prepared to answer 1465 - > either they think it's a personal slide or something like 1466 - > that. 1467 - > But no, we're we, you know, as a, as a an employer, I'm looking 1468 - > for how you actually compartmentalize learned and, 1469 - > and move forward. 1470 - > You know, my, my own personal career, uh, using the example 1471 - > was, uh, working at Chrysler for about nine months.
1472 - > I was the only non-union guy in the shop, so it was the best and 1473 - > worst engagement I ever worked on, 1474 - > Chris Sienko: Mm-hmm. 1475 - > Jim Broome: literally. 1476 - > You know, on, on top of that insult injury was, uh, I, I, I 1477 - > drove a Honda at the time, so that was another big no-no. 1478 - > Uh, so my car would be keyed every day from, you know, the, 1479 - > the folks that were there.
1480 - > So it, it was kinda like that scene from, uh, uh, Roadhouse 1481 - > without the, without the mullet. 1482 - > Uh, but. 1483 - > Chris Sienko: right. 1484 - > And you didn't get to not be nice at the end of it 1485 - > Jim Broome: Exactly.
1486 - > Yeah, exactly. 1487 - > Uh, but you know, my claim to fame is I helped get him from 1488 - > four character passwords to eight character passwords. 1489 - > And I literally had to sit in front of the union during a 1490 - > major charter and listen to them for three days, try to get more 1491 - > funding. 1492 - > And I was like, you know, again, timing wise is, you know, I 1493 - > asked you to remember four more characters.
1494 - > You ought already told me to go pound sand. 1495 - > I had this thing and it was the RSA, you know. 1496 - > Uh, to, you know, back in those days the badge, um, it was like, 1497 - > you know, there's 185,000 employees globally. 1498 - > We're looking at spending$8 million, or you guys can help me 1499 - > remember, four more characters to log in.
1500 - > Chris Sienko: Mm-hmm. 1501 - > Jim Broome: Like I had to, you know, the joke was I walked up 1502 - > on stage and I had the three ring binder note and everything, 1503 - > and I just kinda like, you know, like, you know, security is 1504 - > like, nah, I just ripped it All the shreds and kind of talked to 1505 - > 'em as plainly as that. 1506 - > Uh, and yeah, I got my, my stuff got voted that it was literally 1507 - > the only thing that got voted through. 1508 - > Chris Sienko: great.
1509 - > Yeah, no, I was gonna say communication again. 1510 - > Yeah. 1511 - > You 1512 - > Jim Broome: Yep. 1513 - > Chris Sienko: gotta know your audience.
1514 - > Uh, so what's the best piece of career advice you ever received? 1515 - > Jim Broome: Um, honestly, be humble. 1516 - > Chris Sienko: mm-hmm. 1517 - > Jim Broome: Be humble and don't be afraid to ask.
1518 - > Um, at the end of the day, I, now, I will, I will, I will 1519 - > caveat, I was raised the military way. 1520 - > You only get to ask once. 1521 - > Uh, after that. 1522 - > You gotta go figure it out for yourself.
1523 - > Um, and so, um, you know, that, that's kind of the biggest thing 1524 - > I tell people is, you know, you, you know, I want you to get the 1525 - > confidence to actually contribute to a conversation if, 1526 - > if not, lead the conversation in the very near future. 1527 - > Um, but be humble. 1528 - > When you're coming up there, like you will, you know, like I 1529 - > was that young guy. 1530 - > I literally, it's using the example, I was 24, the next 1531 - > closest academy was 54.
1532 - > Uh, so age, everything, everything that could go against 1533 - > you as a, a very young employee in a very large company. 1534 - > And I got the opportunity to actually go up there and shine 1535 - > just because I had a few people that were willing to listen to 1536 - > me. 1537 - > Um, and so same time of, you know, be humble when you're 1538 - > actually asking and, and, and more importantly contribute. 1539 - > And that's all, that's all we're ever asking across the board is, 1540 - > you know, you know, peer, you know, peers, teammates 1541 - > contribute.
1542 - > So, Yeah. 1543 - > Chris Sienko: Perfect. 1544 - > Jim Broome: Yeah. 1545 - > Chris Sienko: so I'm always looking for new recs.
1546 - > So, uh, let me just ask, is there anything you're currently 1547 - > reading or listening to or watching these days, whether 1548 - > cybersecurity or not, that you're especially excited about? 1549 - > Jim Broome: Uh, unfortunately it caught me at a bad time where I 1550 - > literally just got in the middle of moving. 1551 - > So I haven't had a chance to, 1552 - > Chris Sienko: Okay. 1553 - > Okay.
1554 - > Jim Broome: a little upside down, but, uh, reading wise, 1555 - > honestly, uh, uh, haven't really had a chance to kind of, you 1556 - > know, get down in, into new weeds, uh, uh, or, you know, new 1557 - > reads on that side. 1558 - > But, uh, you know, with my. 1559 - > Both my kiddos, uh, who, who are 26 and 21. 1560 - > Uh, we have shared TV shows, things like that.
1561 - > So just kind of getting into some of the stuff like, uh, um, 1562 - > uh, what was it? 1563 - > Uh, drawing a blank at the moment. 1564 - > So anyway, 1565 - > Chris Sienko: Okay. 1566 - > Jim Broome: just Yeah.
1567 - > Haven't, Yeah. 1568 - > haven't had a chance to, uh, you know, commit that one to, to 1569 - > memory. 1570 - > Just, just watch the first three episodes. 1571 - > Chris Sienko: You got a lot, you got a lot, you got a lot going 1572 - > on right now, so that's, uh, totally understandable.
1573 - > So, alright, well I'm gonna let you go here, but one last 1574 - > request, um, tell our listeners more about direct defense and 1575 - > how listeners can find direct defense and Jim Broom online. 1576 - > Jim Broome: Sure. 1577 - > Sure. 1578 - > Um.
1579 - > So, yeah. 1580 - > at the end of the day, direct defense, we are cybersecurity 1581 - > services company. 1582 - > Um, you know, for ourselves we specialize in offensive testing. 1583 - > Actually, the majority of the revenue for the company today is 1584 - > based on penetration testing services.
1585 - > We do a lot of it. 1586 - > Um, so it doesn't matter if it's just your annual penetration 1587 - > test to, you're looking for a large programmatic approaches to 1588 - > continual penetration testing. 1589 - > We got you covered, uh, both on network and app. 1590 - > Uh, in addition to that, we do managed services along the way 1591 - > so we can help you not only.
1592 - > You know, identify your vulnerabilities, but we can 1593 - > actually monitor'em for you and make sure you're getting'em 1594 - > patched. 1595 - > Uh, as well as, uh, you know, keep your back, make sure the 1596 - > ransomware guys are not inside your network, uh, you know, from 1597 - > a day-to-day basis. 1598 - > And then we have a, uh, dedicated OT practice as well. 1599 - > So, uh, we like to say we help secure the things you can't live 1600 - > without.
1601 - > Uh, that would be water, power, light, 1602 - > Chris Sienko: Very 1603 - > Jim Broome: All the way up to, uh, automation of assembly line, 1604 - > which is actually one of our biggest customer segues of 1605 - > manufacturing today. 1606 - > so.com? 1607 - > Yeah.
1608 - > Chris Sienko: com. 1609 - > All 1610 - > Jim Broome: Www direct defense.com. 1611 - > Yep.
1612 - > Chris Sienko: right. 1613 - > And can our listeners follow you on LinkedIn? 1614 - > Jim Broome: Yes. 1615 - > Again.
1616 - > Yeah. 1617 - > Chris Sienko: Great. 1618 - > All right. 1619 - > Jim Broome, B-R-O-O-M-E.
1620 - > All right. 1621 - > Well, Jim, thanks for your excellent stories and insights. 1622 - > This was a ton of fun. 1623 - > I really appreciate it.
1624 - > Jim Broome: Yeah. 1625 - > Appreciate it bud. 1626 - > Chris Sienko: Uh, so this has been another episode of the 1627 - > Cyber Work Podcast. 1628 - > Thank you for listening and watching.
1629 - > If you have any topics you'd like us to cover or guests you'd 1630 - > like to see on the show, drop'em in. 1631 - > The comments, make use of our YouTube community tab or just 1632 - > let us know by commenting on our new TikTok channel. 1633 - > Uh, before we go, please check out InfoSec institute.com/free 1634 - > for a wealth of free and exclusive things for cyber work 1635 - > listeners.
1636 - > Uh, that includes our free cybersecurity talent development 1637 - > playbook with in-depth training plans and strategies for the 12 1638 - > most common security roles. 1639 - > Including SOC analyst, pen tester, cloud security engineer, 1640 - > information risk analyst, privacy manager, secure coder, 1641 - > ICS, professional and more. 1642 - > Or take a look at our cybersecurity salary guide for 1643 - > the latest data on popular certifications in their related 1644 - > roles, as well as the average salaries for these roles.
1645 - > We've also got security awareness posters, search study 1646 - > eBooks, and you can sign up for 100 plus free courses for a free 1647 - > month of our info skills InfoSec skills platform. 1648 - > Uh, learn incident response forensics. 1649 - > Security, architecture and more. 1650 - > One more time.
1651 - > That's InfoSec institute.com/free. 1652 - > last time. 1653 - > Thank you to Jim Broom and direct defense, and thank you 1654 - > for watching and listening.
1655 - > Jim Broome: Yep. 1656 - > Chris Sienko: Chris Seko signing off. 1657 - > Until next time, make sure to learn something new every day. 1658 - > Keep one step ahead of the story and don't forget to have a 1659 - > little fun along the way.
1660 - > Bye for now.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.