The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Exploring Information Security
Exploring Information Security artwork

[RERELEASE] What is the perception of information security - part 1

Exploring Information Security · 2026-04-28 · 23 min

0:00--:--

Key moments - from our scoring

Substance score

53 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality11 / 20
Guest Caliber11 / 20
Specificity & Evidence9 / 20
Conversational Craft10 / 20

The episode examines the fundamental perception gap between information security professionals and the broader business world. Chris Madeleina shares a telling conversation with a C-level executive who characterized security as 'a great racket' - arguing that companies have been convinced they need security (SOCs, staff, tools) when many don't actually require it, and that cybersecurity insurance and basic IT safeguards would be more cost-effective. The hosts explore how outdated security training models (focused on avoiding clicking bad links rather than explaining *why* threats matter) fail to resonate with executives and employees alike. Madeleina emphasizes that modern threats - sophisticated spearphishing targeting managers, advanced adversaries stealing intellectual property and trade secrets - require actual education and contextualized awareness, not fear-based scare tactics. Tundablock shares his approach of tying security lessons to personal finance (credit card monitoring after breaches), using memorable content (Star Wars memes for executives), and demonstrating that security benefits employees outside work. Both speakers stress that security professionals need to shift from 'don't do this' mandates to explaining value and relevance, while also reconsidering how the industry positions itself relative to IT - noting that over-emphasizing separation from IT infrastructure has paradoxically alienated the developers, network admins, and other technical teams security depends on.

Key takeaways

  • →Security training often treats employees like children by telling them what not to do (don't click links) rather than explaining why threats matter and how they're relevant to their roles and personal lives.
  • →Modern advanced threats target managers and executives with spearphishing campaigns matched to their LinkedIn profiles and interests, yet C-level executives often exempt themselves from security training while mandating it for staff below them.
  • →Executives often view security investments through a cost-benefit lens where cybersecurity insurance and basic IT safeguards appear cheaper than staffing SOCs and security teams, requiring security professionals to demonstrate concrete business value rather than relying solely on fear.
  • →Security professionals have inadvertently alienated IT teams (developers, network admins, sysadmins) by insisting they are 'not IT' and 'security,' creating friction with the very infrastructure and technical teams they depend on to implement controls.
  • →Connecting security awareness to employees' personal lives - like monitoring credit cards after known breaches - helps demonstrate that security benefits them outside of work and improves buy-in better than enterprise-only threat narratives.

In this episode

  1. 1Terminology: Information Security vs Cyber Security
  2. 2Executive Perception: Security as a Business 'Racket'
  3. 3Cost-Benefit Analysis and Insurance Over Security Investment
  4. 4Evolution of Threats: From Easy Targets to Sophisticated Attackers
  5. 5Phishing and Red Team Mentality Misalignment
  6. 6Security Training Deficiencies and Outdated Approaches
  7. 7Connecting Security Awareness to Personal and Home Security
  8. 8Presenting Security to Executives with Engaging Communication

Mentioned

EcentireSonyBrian KrebsArs TechnicaTwitterLinkedInSemanticBsides DetroitCircle City Con

Guests

Chris Madeleina

Topics in this episode

Penetration testingSecurity Awareness TrainingSOC (Security Operations Center)Cybersecurity insuranceEcentirePhishing simulations and red team activitiesSpearphishing targeting executivesDomain Admin attacksBotnet threatsCredit card fraud monitoring

Questions this episode answers

Why do some business executives view security as an unnecessary expense?

Many executives believe that cybersecurity insurance is more cost-effective than hiring security staff, and they question whether their company's data is valuable enough to attract serious criminals, failing to understand that advanced adversaries target trade secrets, R&D, and business processes rather than just credit card numbers.

What's wrong with how most organizations train employees on phishing?

Traditional security training tells employees to avoid clicking bad links or watch for suspicious invoices, but doesn't explain *why* phishing is dangerous to the company or how attackers are evolving - so training becomes outdated and employees don't understand the real threat.

Who is most vulnerable to targeted spearphishing attacks?

Middle managers and C-level executives are increasingly targeted with sophisticated spearphishing because they're unlikely to have received security training (they exempt themselves), making them easier targets than lower-level employees who've attended security awareness sessions.

How can security professionals change the perception of security in their organizations?

By educating rather than lecturing - explaining why security matters to employees' personal lives (like credit card fraud), using memorable content (humor, relevant memes) for executives, and demonstrating business value rather than relying solely on fear of breaches like Sony.

Why is it counterproductive for security teams to distance themselves from IT?

Security professionals depend on developers, network admins, and sysadmins to implement controls and maintain systems, so emphasizing separation and superiority alienates the exact technical teams and disciplines that security relies on to be effective.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains several substantive ideas about perception misalignment in security (the 'racket' framing, executives exempt from training, outdated training approaches, mismatch between threat models and defensive postures), but much of the discussion is repetitive and tangential. There is useful conceptual ground - the distinction between training and education, the executive exemption problem, spear-phishing targeting managers - but these are explored in a conversational, meandering way rather than packed densely. A B2B operator would extract 3-4 actionable insights but wade through considerable filler.

he kept calling it a racket... we have persuaded everyone to believe they need, uh, their own soc, that they need security in their company when they don't really
the middle managers are said, hey, send people to training and they exempt themselves, they send everyone under them and then the executives, uh, don't want to go to it

Originality

11 / 20

The core insight - that security professionals have oversold security scope and that training often talks down to users without explaining why - is sensible but not particularly novel. The 'racket' framing is interesting as a hook, but the follow-on discussion (fear-based motivation, executives not attending training, phishing targeting managers) are well-worn observations in the infosec community. The Admiral Ackbar meme anecdote is personable but not a fresh idea. Little here would surprise a seasoned security leader.

we have persuaded everyone to believe they need, uh, their own soc, that they need security in their company when they don't really
we're telling them the obvious stuff like don't click on bad links... they don't have, uh, a full understanding of uh, the value that like an actually trained infosec expert will bring

Guest Caliber

11 / 20

Chris Madeleina is presented as working in security (pen testing, red teaming, phishing simulations at Ecentire) and has given talks at security conferences (BSides Detroit, Circle City Con), suggesting solid practitioner experience. However, the transcript offers minimal evidence of large-scale operational authority, major wins, or unique vantage point. He is a competent mid-level operator with relevant hands-on experience, but not a standout founder, CISO at scale, or recognized thought leader whose unique credentials would elevate the episode.

I do red team activities and I have clients who are still interested in the idea of sort of the capture the flag mentality
I do a lot of the phishing for ecentire. And uh, one of the things I try to really stress, uh, to our clients when I'm presenting the report to them

Specificity & Evidence

9 / 20

The episode relies heavily on anecdote and conceptual argument rather than named examples or hard data. The Sony breach and a local zoo compromise are mentioned in passing; a C-level executive conversation is described but not named or detailed with numbers. Claims about phishing rates, training efficacy, and threat actor behavior are general observations, not backed by metrics, timelines, or concrete case studies. A B2B operator seeking actionable specifics (e.g., actual phishing click rates, ROI data, named companies or incidents) will leave disappointed.

we were having a conversation about, uh, about security and he Kept saying, uh, how great, uh, how great he thought the, the field I was in was because it was a really great racket
we had our local zoo got compromised, and I read about it on Brian Krebs

Conversational Craft

10 / 20

The host asks open-ended questions and attempts follow-ups, but rarely presses the guest on specifics, challenges claims, or digs into nuance. When the guest makes a provocative claim (e.g., some companies don't need security, or that we've built a 'racket'), the host does not interrogate the logic or ask for evidence. The conversation drifts; the Admiral Ackbar tangent is entertaining but not a hard follow-up. There is no adversarial energy or genuine pushback - it reads as two security people agreeing and riffing rather than a host working to extract insight.

So that's kind of like a, that's kind of like a bottom line type of thing... I think that's some of the perception there.
Yeah, he mentioned the idea of cybersecurity insurance... Yeah, absolutely.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B69%
  • Speaker A31%

Most-used words

security46information19phishing14perception11email10credit9training9executives9level8card7trying7back6executive6didn6users6cyber5

Episode notes

In the second episode of the refreshed edition of the Exploring Information Security (EIS) podcast (wow, that's a mouthful), I talk with Chris Maddalena about the perception of information security. Chris recently gave a talk on FUD at BSides Detroit and CircleCityCon this past Summer, prompting me to explore the topic of information security perception with him. I think perception is something very important to the infosec community, especially, now that it is becoming more relevant in the public eye. In part one of this two part series we talk about perception What is the perception of infosec in business? How do we change the perception of security? We start getting into where security fits in an organization What is the perception of information security - part 1 With Chris Maddalena [ RSS Feed ] [ iTunes ]

Full transcript

23 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: What is the perception of information security? Part 1. Welcome to the Exploring Information Security podcast where you will learn, explore and grow your security mindset. I am your host, Tundablock, and in this episode we will be exploring what is the perception of information, or should I say cyber air quotes Security. With me today to do that is Chris Madeleina of Ecentire. Chris, how are you?

Speaker B: I'm good. How are you?

Speaker A: Good. Excellent. Fantastic. Um, so let's get to the tough question right away. What is the perception of information? Or should we. Okay, so should we, let's set the standard. Should we go cyber or information security?

Speaker B: Oh man. I think that actually plays a lot into the perception of it as a whole too, is which way you go with it. Uh, I usually say information, uh, security just because infosec is a lot faster to sec.

Speaker A: I think a lot of, and I think a lot of people use one Infosec. I think infosec is so, so much cooler than cysec or cybersec or, you know, whatever. And cyber, like back in my day, way back in the uh, 2000s in the early years of the Internet meant a whole different thing.

Speaker B: Oh yeah, Yep. Um, I was around for that.

Speaker A: Information security seems more of the proper term. And I think a lot of information security professionals essentially are burnt out on the word cyber because it's everywhere. It's very flashy, very cyber. You can't say information. Can't say.

Speaker B: That has a lot of punch to it.

Speaker A: So what is the perception, uh, of information security in the real world?

Speaker B: We were talking about this, uh, before we started recording was I feel like we have a kind of a complicated relationship with the people who aren't in infosec or aren't heavily involved in it. Uh, because it's really hard to look at security from the outside and accept it at face value because a lot of it is people telling you to do things that you haven't had to do before you don't really want to do. It's going to make your job a little bit harder, um, at least up front. Uh, you're going to have to get used to some new security controls and you just don't really want to do it and you don't really understand why anyone would want you to do, um, can kind of be summed up and I was having in a conversation I had with, um, a high ranking C level executive of a rather large company, um, a few weeks ago and uh, he knew what I did and we were having a conversation about, uh, about security and he Kept saying, uh, how great, uh, how great he thought the, the field I was in was because it was a really great racket. And he didn't mean it, you know, to be negative. He, uh, you know, he appreciated it, um, and wasn't being totally down on security, but he kept calling it a racket. And part of his reasoning behind that was there are industries that he felt need security, banks need security, because of course they do. There are companies that need security. But he felt that we have persuaded everyone to believe they need, uh, their own soc, that they need security in their company when they don't really. So we've managed to somehow expand what should be a small industry into a much larger one by convincing everyone they should give us a job no matter what industry they're in. So we've therefore kind of uses his words, made sure that we have a job almost in every single company. And that kind of took me off guard, that idea that there were companies that didn't need security because the information they had wasn't valuable, um, or that it wasn't, uh, of interest to, to criminals.

Speaker A: So that's kind of like a, that's kind of like a bottom line type of thing. So you think, think uh, about like the Sony thing and some of the comments that their sea level executive made with, in regards to if I can, if I can pay for a security breach at like a million versus putting in, you know, staff and appliances for 10 million, I'm actually making out at the end there, you know.

Speaker B: Yeah, absolutely.

Speaker A: I think that's some of the perception there.

Speaker B: Yeah, he, he mentioned the idea of cybersecurity insurance and that, you know, if he can staff a whole SOC, paying them 50, um, to $70,000 a year for like a dozen people, you know, he's considered like, oh yeah, you have a really great security team. Like, but I can pay, you know, 100,000 and cover myself, you know, for any legal fees that might come from a security breach. It's like, why wouldn't I just do that? Uh, and I like to think that I was able to at least persuade him a little bit that there was value to uh, uh, the personal, whether it was just personal identifying information that they might have, uh, credit card numbers. Uh, but he thought his kind of counter to it. He's like, but he's like, you just call up the credit card company, that's their job, that if someone steals your credit card, they'll give you a new one. They covered the cost because why, why should I pay, you know, hundreds of thousands of dollars every year, plus training, you know, plus office space, all that for security people when I can have insurance and then just kind of do, you know, have the IT people do, like the basic security stuff. And a lot of that, I think, comes from this, this old understanding of, of what a hacker, uh, you know, was maybe up to just a few years ago. You know, we've kind um, of started seeing a better class of criminal in a way. As we've made security better, we've made it harder for, you know, people to get at some of the really easy stuff. It's no longer that easy, at least, you know, unless someone makes a horrible mistake. And we do see that from time to time. You know, people can't just easily grab credit card numbers from a company or, uh, or really great information that's of value to them. So you end up with people who are the real threat or the people who are able to get in there, sit around for a while and steal information from you. Um, like I know, uh, friends of mine who are pen testers, Um, I do red team activities and I have clients who are still interested in the idea of sort of the capture the flag mentality. Try to get Domain admin is often what they want. Try to access this particular system. And a lot of that's an old mindset where they perceive their security as, we're trying to keep you from owning us from coming in here and becoming domain admin. But the criminals that are really coming after those big companies that are spending lots and lots of money to protect a domain admin, the hackers aren't trying to, you, uh, know, join their IT department and become domain, you know, become a sysadmin for them. What they're trying to do is just get in there and access information. They want to go in there and steal R and D. They want to find out where you're getting your, your parts from, you know, how much are you paying, you know, what is your markup. They want to steal your business so that then they can walk away with it and you're done. You know, there's nothing really more to say because they don't, they don't need Domain Admin to get that. Um, we were talking about phishing also before recording. And that's another thing. You know, I do a lot of the phishing for ecentire. And uh, one of the things I try to really stress, uh, to our clients when I'm presenting the report to them is letting them know that, hey, I got this many people and it's really great that uh, you know, this person reported the phishing email or, you know, I will only manage to get a handful of people versus whatever our average is. Uh, but one thing that I really want to stress is that I want you to go, I want you to look at this report and I want you to take a hard look at everyone that I successfully phished. I want you to figure out what kind of control they have in your, in your network. What do they have access to, what you do, what network drives can they see, all that kind of thing to figure out how bad would it have been if I was actually after something of yours? Um, I don't know how many of them actually do that after the fact. Uh, but it's definitely something I try to drill into them in the report and when I present it. Because a lot of, uh, people still look at security as kind of like I was saying, it's been thrust upon them. They don't really need it. Um, it's almost like it's ah, you know, like stranger danger for adults. Like you're telling them the obvious stuff like don't click on bad links. I know all about bad links. I don't need, I don't need to pay you a salary to sit there and tell me not to click on bad links. But they don't have, uh, a full understanding of uh, the value that like an actually trained infosec expert will bring to their company.

Speaker A: So, so, so how do we change that perception then? So, I mean, should we start treating them a little bit more like adults or. Because within the IT industry, you know, users have kind of a bad reputation because they, they do a lot of silly thing, dumb things on a regular basis. So I mean, it's. And I guess. So how do they, how do we change the perception of security in that regard?

Speaker B: Yeah, for sure. I mean we, I think treating people like adults and taking the time to educate them, uh, is a big deal. I gave a presentation, um, at Bsides Detroit, um, this past weekend or two weekends ago.

Speaker A: Um, well, by the time this podcast came out, it was mid July.

Speaker B: Okay, yeah, yeah, so it's mid July. I, uh, also gave, um, uh, this presentation at Circle City Con in June, um, where I talk a lot about the idea that there's, there's training that. And which is often what we give to users, what we give to executives and middle managers and employees. And that's. Sometimes it's dated. Uh, you know, look over this old document that we drew up five years ago on how to defend yourself against phishing. Um, and training usually ends up taking shortcuts. Like you're telling someone, hey, here's what a phishing email is. Look for a bad link, look for, you know, these items and it's probably going to come in the form of like a fake invoice or like a social media notification. You know, you give some examples and you drill it into their head that this is what they should look for. But you're not educating them how to really defend themselves. You're telling them to be a watchdog for a very particular thing that probably isn't even done anymore.

Speaker A: Right.

Speaker B: Um, and often that training is given to, you know, low level employees, uh, not the C level executives, not the middle managers. Because the middle managers are said, hey, send people to training and they exempt themselves, they send everyone under them and then the executives, uh, don't want to go to it, so they get like a, a brief version of it, their own special version and they just don't go either. Um, you know, and to, you know, kind of talk about phishing. That's where we're seeing a lot of activity now is people are being specifically targeted because they're a middle manager and they're like, you probably haven't been trained how to defend yourself against phishing or you didn't, probably didn't pay attention. And I'm not going to send you a social media invite. I'm going to send you, uh, you know, this totally, you know, banal looking thing that you probably, you know, I think you'll click on because I checked you out on LinkedIn. It matches up with your interests. You know, they're going to specifically spearfish, you know, a small collection of managers or C level executives. They're not really trying to do like the scattershot approach of just hit everyone in the lower ranks and see what, see what you get. But that's still effective too because we haven't actually educated them. Um, whereas, you know, I'm kind of using educate as the um as a different term to say like it's training. But you explain to them why they should look for a certain thing you're going through and explaining, here's why this is this way and here's why it's relevant to you, which I think is what a lot of um, security education is lacking is. Yeah, we do kind of teach uh, users, uh, like children in a lot of the ways. We tell them like, hey, don't, don't put your hand on the stove, it's hot. And you know, in that kind of scenario it's, well yeah, it's hot because it's the stove. So you should just know that, right? But they don't know why they shouldn't be touching the hot stove. They, we're not actually explaining to them why, why that particular thing is bad. Uh, we're not explaining to them why it's relevant to them. Um, there's still users. I know there's people in my family, friends that are like, oh well yeah, I know all about what you do for a living. But when I try to tell them you should apply that to yourself at home, they go, oh no, no, no, I'm not a business. Because a lot of our media and a lot of our training focuses on enterprise, uh, security. You know, everything you see in the news is, well, Sony was hacked. You don't really hear too much about what happens at uh, least not in sort of the mainstream news. You see it in some of like Ars Technica. More um, tech savvy websites talk about users being targeted by malware. Um, whether it's like a rat or just something that's going to steal their personal information, um, one of the big things that a user needs to look out for is becoming part of a botnet, that sort of thing. Um, and users don't realize that their computers are so fast now. They're still, many of them still kind of look back at the 90s and go, I remember I had a virus once. It made my computer run dog slow.

Speaker A: There was like weird pop ups.

Speaker B: It was really weird. I reloaded Windows and it fixed it so I had a virus, right. But they think like, well, I have semantic installed so that'll protect me and my computer's running fine so uh, everything's good. They don't understand what can happen.

Speaker A: So that's actually something that I've tried to start doing is within my organization we have a monthly newsletter and uh,

Speaker B: we have a blog post.

Speaker A: I probably get maybe two readers a week, two readers a month maybe, I don't know. But one of the things that I try to do is I try to try to see if I can um, to improve their security awareness and mindset is to kind of tie that in back to home so that, you know, because like you said, I think that's a very important thing is that a lot of our stuff is catered, kind of like the enterprise. But a lot of the stuff that can be done at the organization that can improve their mindset can also be done at home. Um, checking you Know, just being mindful of stuff like checking credit cards on a regular basis. We had our local zoo got compromised, and I read about it on Brian Krebs, and we actually shot out an email to everybody saying, hey, you might want to check your credit card if you were to the gift shop or the concession stand during this time period. Go get a new credit card. And oh, by the way, here's some ways to, you know, pay attention to your credit on a, your credit card on a regular basis. And the business for that is that if they've got to go deal with some identity fraud, that's going to take them away from work. So, I mean, it's teaching them to be at home. It's, you know, it's kind of just being more of a, hey, we're not here to just drill in, stop clicking on links and stuff. It's here to, uh, benefit them as well. And so that's, that's one of the things we're trying to do as far as changing the perception of security, is trying to show them that we can be some benefit outside of work.

Speaker B: Yeah, I think that, that, that's, that's really awesome. I'm glad you guys do that. I think that's really good because it is really hard to demonstrate why it's relevant to someone or, you know, try to pitch, uh, an executive on, well, here's why we need another security analyst. Or, you know, we want. Why. Here's why we want to do a pen test or whatever without falling back on the really easy motivator, which is that fear we don't want to be Sony, which is totally fine when framed properly. But so often you see news articles or blog posts or someone's trying to explain why security is relevant, uh, to whatever, to an industry, to a certain company, or just to people in general. And it's really hard to, uh, get that point across without falling back on that really reliable motivator. Uh, just fear and letting them like, well, you don't want, you want this to happen to you, but then that just makes people scared and they overreact or they just think like, well, I'm not interesting enough to be targeted, so it's not going to happen to me. And so you haven't really accomplished anything to let them know, like, well, yeah, you're probably right. Maybe you won't be compromised, uh, you know, this year, or maybe you're not very interesting to be targeted, but it doesn't mean you can't just be scooped up in some really big, you Know, just scattershot fishing campaign or you know, something like that.

Speaker A: Right. So I find it interesting that you also said that, you know, executives are not, um, like they're not going to this training, they're sending the lower staff to it. But they kind of like, oh, I got a phone call to go out. And I've seen that happen before too. Uh, and so I think as security professionals, I think we could step up and try to look for opportunities to stand in front of managers and C level executive type stuff. One of the things we have is, and my organization is very much a pro security type of environment, so it's a lot easier for me or other organizations can be a little bit tougher. But one of the things that I've done is I've given a talk, like a quick 5, 10 minute talk on phishing emails and what we've seen within the organization and to have an impact. I, you know, I was like, you know what? I'm going to try something. I'm going to throw some memes in here. So we take these. A lot of people build these slide decks for our security conferences. They put the funny memes in, some memorable memes. And so I decided to apply that to the executives. Now you also have to realize that you're dealing with what your audience is. So I can't use any memes that recently maybe they don't understand. So I went for a Star wars meme and I used Admiral Ackbar three times in my slide deck to an executive showing them about phishing, like the current phishing emails that we're seeing. So I'm also kind of showing them kind of the tactics and stuff. I'm not saying don't click on this, but I'm saying here's some. And I'm showing them like funny stuff. That's like one of the phishing. I love the phishing emails that are like, um, uh, this, you know, clicking on links within an email can be a security violation. You know, like it's an actual security warning within a phishing email, which I always love to see. But you know, I did that talk and everything and people seemed to like it. And the next day, um, I had our assistant, um, executive director from the HR director called me yelling it's a trap into the. And asking me about the phishing email that she. Or a suspicious email that she got. So, you know, you can. Because they're C level executives doesn't mean that they don't. They're not people either, you know. So I think Sometimes that can be a little bit intimidating. But you know, taken I think and I think as information security professionals we need to be up there uh, informing them on that kind of stuff and kind of showing them the benefit like, like you said. I love that you said that. It's, it's fear has been a very, a uh, tool that we've used to motivate people. But we can also look at it from a different angle and try to show the benefit of security.

Speaker B: Yeah, I definitely agree with that. That you know, definitely know your audience and certainly there's probably C level executives that you could give a presentation to that would want very uh, straight laced presentation. Um, but I mean that's also how they'd get the information. But yeah, if you can, you can get a hook like that where someone thinks of Admiral Ackbar and gets a laugh when they're looking at an email and that gets them to look at the attachment a little bit more closely and look at the email header. Perfect. Um, the other thing I was thinking about for um, as far as perception is a couple of things and uh, I think it help with the executives too if we could actually figure out uh, how to present this is. I know I see a lot of conversations, whether it's on Twitter or people giving a presentation at a security conference, blog posts. Um, is the security people don't want to be considered it. Like you know, they want to be considered security. M. Which, which I personally agree with. I do think that ah, it's different enough and kind of we've been talking about there's you know, we should be out there training people. We should be explaining things. We should um, you know, be the guiding factor.

Speaker A: We want to be the guidance that.

Speaker B: Yeah, yeah, yeah, we want to guide. We don't want to be infrastructure because we really, that's not what we do. Um, you know we work with infrastructure, we work within it and we look at logs and things like that. But we're not there to uh, to maintain things that were there to, to guide and look out for people and. But uh, there's also this kind of this attitude where some people get so like no, we're not it. We don't want to be considered it. That I, I've talked to it people that actually like quite a few people that I know that are, whether they're developers, uh, that are you know, in it, um, or you know, QA people are people, you know, people that actually like network admins, sysadmins and they'll ask me uh, like oh, yes, you work in it. And I'm like, oh, you know, I'll casually like, oh, no, I'm. I do security. And they're like, yeah, that's it. And I'll be like, well, no. And I'll try to explain and I realize it's a. It's admiral. It's a trap.

Speaker A: Because.

Speaker B: Yeah, because they'll be like, well, I'm a developer. I'm it. I don't say we're developers, you're it. And it's like there's been this weird. I think without totally meaning to, we've kind of alienated a lot of the people we have to work with to make them feel like where. Like, no, no, no, we're not one of you. We're security.

Speaker A: And that will do it for part one of what is the Perception of Information Security? Hopefully you learned something if you didn't drop me a line on Twitter timothydblock or email me at timothy.dblockmail.com and let me know what you didn't learn. And we'll try to cover it in a future podcast. Have a good one, Sam. Mhm.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Internet Will Never Be This Secure Again, IEEE's Kevin Curran on AI and CybersecurityThe Business of Cybersecurity · on Penetration testing81 / 100
  • July 2026 CMMC ConnectCyberspin · on Penetration testing80 / 100
  • Gary Martin from Scan Ninja AIEnergytech Startups · on Penetration testing77 / 100
  • 🇩🇪 #31 - RevOps bei SoSafe: Skalierung, Signale und Sales-Innovation, mit Alexander SchwabThe Commission Corner · on Security Awareness Training76 / 100
  • Bridging the Customer Protection Gap: How Insurers Can Respond to Generational Shifts in Risk and ReadinessThe Future of Insurance: Industry Leaders · on Cybersecurity insurance75 / 100
  • The Strategic Human Firewall as AI Impacts Regulations, Cyber Pros, and Employees - Robert Siciliano - BSW #453Security Weekly Podcast Network · on Security Awareness Training68 / 100

More from Exploring Information Security

All episodes →
  • [RERELEASE] What is the perception of information security - part 258 / 100
  • Exploring the Quantum Horizon: Why We Need CBOMs Today
  • Exploring the Risks of Model Context Protocol (MCP) with Casey Bleeker
  • From Combat Zones to Corporate Lobbies: A Guide to Physical Security with Josh Winter
  • [RERELEASE] What is a SIEM?
Explore the best B2B Ops podcasts →
All Exploring Information Security episodes →