The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/IoT Security Podcast
IoT Security Podcast artwork

Building IoT Trust: Budgeting, Community, and the Hacker Mindset with Ted Harrington

IoT Security Podcast · 2025-07-14 · 32 min

0:00--:--

Ted Harrington brings practical experience from running IoT Village at DEF CON and a consulting practice to address a core problem in IoT security: how organizations actually get motivated to invest in proper defenses. Rather than relying solely on fear-based risk calculations (avoiding bad things), Harrington advocates positioning security as a competitive advantage that drives revenue and customer trust - making it easier to secure budgets from executive leadership. The episode explores how compliance-driven approaches create a dangerous mismatch with attacker thinking; while businesses pursue PCI, HIPAA, or similar certifications, adversaries ignore these credentials entirely and look for exploitable vulnerabilities. The conversation emphasizes the hacker mindset as essential to building secure systems, contrasting checkbox security with genuine defensive thinking. Harrington also discusses the origin and impact of IoT Village, which grew from a humble behind-the-trash-can corner at DEF CON 11 years ago into a flagship village with participants winning Black Badges - DEF CON's highest honor - for demonstrating elite security research skills. For B2B operators, security leaders, and compliance professionals, the episode offers concrete language for explaining security value to boards, along with perspective on whether IoT security is actually improving (the answer: both yes and no, depending on which segment you examine).

Key takeaways

  • →Security is a competitive advantage in procurement and customer trust, not just a risk mitigation cost - frame it to boards as supporting sales and marketing missions, not just preventing breaches.
  • →Compliance and security are not equivalent; a compliant system is not necessarily secure, and attackers ignore compliance certifications entirely while focusing on exploitable vulnerabilities.
  • →The hacker mindset - understanding how attackers actually think and approach targets - should drive defensive architecture design, not compliance checklists or hollow marketing claims.
  • →IoT Village at DEF CON demonstrates the power of community-driven security research and education; winners of their Capture the Flag contest have earned DEF CON Black Badges, validating the legitimacy of rigorous IoT security work.
  • →Budget approval requires linking security investment to business outcomes your CFO and board care about - risk reduction alone is insufficient; security must demonstrably support revenue, customer confidence, and competitive positioning.

In this episode

  1. 1Introduction to Ted Harrington and IoT Security
  2. 2The Hacker Mindset and Offensive Security Importance
  3. 3Security Compliance vs. True Security
  4. 4Communicating Security Budget Needs to Business Leadership
  5. 5Security as Competitive Advantage
  6. 6Building Trust Through Data Protection and Privacy
  7. 7IoT Village Origins and DEF CON Black Badge Winners
  8. 8IoT Security Posture: Current Trends and Future Outlook

Mentioned

Ted HarringtonDEF CONIoT VillageHackableBlack HatRSAPCI

Guests

Ted Harrington

Topics in this episode

Competitive advantageDEF CONIoT VillageDEF CON Black BadgeCapture the Flag contestHacker mindsetIoT security researchCompliance versus securityRisk-based security budgetingSOHO routers

Questions this episode answers

How do you get budget approval for IoT security from senior management and boards?

Frame security as a competitive advantage that supports sales and marketing, not just as risk mitigation. Demonstrate how proper security practices differentiate you in procurement evaluations and build customer trust, making it easier to close deals and justify security spending to executives focused on revenue and profit.

What is the difference between compliance and actual security?

A compliant system is not necessarily secure. Companies pursuing only compliance overlook attacker thinking - adversaries don't care about PCI or other certifications and instead target exploitable vulnerabilities. True security requires understanding how attackers approach a system beyond meeting compliance standards.

What is the hacker mindset and why does it matter in IoT security?

The hacker mindset is understanding how an attacker actually thinks and approaches targets - what assets they want and how they'd obtain them. It's critical because it drives defensive architecture decisions; without it, companies build systems that pass compliance boxes but remain vulnerable to real attack scenarios.

How did IoT Village start and what makes it important to the community?

IoT Village began 11 years ago as a DEF CON contest called 'Hopelessly Broken' to gamify router security research. It grew into an official DEF CON village and has become significant because Capture the Flag winners have earned DEF CON Black Badges - an elite hall-of-fame-like status - validating rigorous IoT security research as genuinely important work.

Is IoT security getting better or worse?

Both. Mature IoT companies are improving their security practices, but the overall IoT landscape is simultaneously getting worse as more insecure devices proliferate. The trend depends on which segment of the market you examine.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A79%
  • Speaker B21%

Most-used words

security49better21village17secure15badge14devices13cool12black12defcon12hackers11important9connected9conference9started9sometimes8first8

Episode notes

Ted Harrington (Founder of IoT Village, Executive Partner for Independent Security Evaluators, Author, Speaker, and Podcaster) examines the ongoing challenges and progress in IoT security, emphasizing how community initiatives, the hacker mindset, and business-oriented communication can drive real change in the industry. Ted and Phil Wylie discuss practical strategies for justifying security budgets to management, the value of offensive security, and the important role of education and community in strengthening defenses. Also highlighted are how IoT security is both improving and facing growing risks due to rapid expansion, and why viewing security as a competitive advantage is vital for organizations. Let’s connect about IoT Security! Follow Phillip Wylie at The IoT Security Podcast is powered by Phosphorus Cybersecurity. Join the conversation for the IoT Security Podcast - where xIoT meets Security. Learn more at

Full transcript

32 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: We're not the only groups advocating for change in this space. But that's why things like this are really, really important, because we have to realize this problem, not only is it not solved, depending on how you look at it, it's getting worse. I would argue it's getting better and it's getting worse, but it's getting better because of the advocacy of groups like people who attend DEF CON, talk about these types of things, organize IoT conferences, develop IoT security products, service companies, et cetera. I have reasons to be optimistic and reasons for concern as well.

Speaker B: Hello and welcome to the IoT Security Podcast. In this episode, I'm joined by Ted Harrington. Ted Harrington is a partner in a consulting company as well as a founder of the IoT Village. In this episode, you're going to learn how to communicate with upper management and the business units to get that much needed budget to secure your environment as well. In this episode, you'll learn how community plays a big part in educating people on IoT and connected devices. I hope you enjoy this episode. Today I'm joined by Ted Harrington. Ted is one of my friends from the cybersecurity community and also the conference circuit. But another thing we have in common too, is Ted has done podcasts. Ted is an accomplished author. So there's things we have in common outside of, uh, cybersecurity. But we're going to focus more on the cybersecurity things, which. So I need to have Ted on my other podcast so we can dig into some other things. But welcome to the show, Ted.

Speaker A: Great to see you, Phil. Thanks for having me.

Speaker B: Yeah, it's great to see you. It's awesome to see all the global traveling and keynoting you're doing. It's pretty amazing. And you got your new book coming out, so that's pretty awesome.

Speaker A: Been keeping me busy, that's for sure. Yeah, we're approaching, uh, the final manuscript lock momentarily, so getting close.

Speaker B: Yeah, Very cool. So, having an idea how. How soon it's going to be before it's available.

Speaker A: Yeah, it'll be available at the end of this summer. So, um, it goes into production probably in the next few weeks, but I would say we don't have the exact date yet, but definitely by mid September, probably by end of August.

Speaker B: Very cool. It just would have been a little bit earlier. You could have released around Black Hat, but that. At least it'll be out. At least it'd be out for rsa.

Speaker A: Well, years ago, when we started this project, that was the goal. And, um, we'll miss it just slightly. And that was actually a really difficult decision to say. You know, I'm one. Do you, do you rush a book and you know, then forever it's rushed or do you give it the extra little bit that it needs? And I think just their commitment to quality that uh, I myself feel personally and then all the people who work for us feel that was ultimately the choice. So we'll still do something at defcon. We're still going to do some um, book launch, uh, like pre launch party type of stuff that we'll be announcing here pretty soon. We haven't finalized everything yet but the um, actual books in hand will, will follow that.

Speaker B: Very cool. Looking forward to seeing it. Hopefully I can score a copy.

Speaker A: Oh for sure.

Speaker B: Well you helped me to autograph copy.

Speaker A: Oh for sure. I mean you gave me some really interesting insights or one of the people I reached out to and I wanted to uh, really understand the hacker mindset. So I'm like, well, who do I know that I admire that understands how hackers think? And you gave me some really awesome insights.

Speaker B: Yeah. And I think it's great that you see the importance of the hacker mindset because you know, a lot of folks when it comes into cybersecurity, I think sometimes in, you know, since you're, you're know, a partner in a consulting company, you probably see this a lot is sometimes people don't take offensive security, their assessments serious enough. Sometimes they just take it as a checkbox. Um, so it's good to have folks like yourself that are going out kind of evangelizing the importance of the hacker mindset as long along with the importance of uh, offensive security.

Speaker A: Yeah, it's kind of amazing to me that here we are in the year 2025 and we still need to be educating people about why this matters and how to do it right. And I do sort of get it to some extent. I mean it blows my mind that this is still the condition. But I, I can understand the business thinking which is, you know, what is a business, what is a business incentivize around? A business incentivizes around um, top line revenue and bottom line profit. And it's difficult oftentimes for a business to think about how does doing security properly deliver either of those things. And that is, I think part of what we need to be doing is talking about not just like, how do you approach security in the proper way, but like how does that actually help a business? And so because that ultimately is the barrier I think that we're facing but yeah, a lot of times people are like, I'm told I have to do this. I don't know what a pen test is. I guess I got to do it. What's the cheapest way I can check this box? And helping people understand the differences is, uh, I think pretty critical.

Speaker B: That's good. I think that's really important for anyone listening. You're looking for consulting companies. Find people that are going to properly set your goals and objectives and not just do the checkbox because, you know, there's some people out there that say, hey, and this can be true. If you're just purely compliance, doesn't mean you're secure. You can accomplish both. So you want a consulting company that's going to help you define, help you define those goals beyond PCI compliance, whatever.

Speaker A: Yeah, because I mean, the way to think about it, right, is that a, uh, a secure system is often compliant, but a compliant system isn't necessarily secure. In fact, if it's just compliant, it probably is not secure. And that's an important way to think about it because what we need to do is we need to realize that, like, how does an attacker think? An attacker doesn't look at a system that they're, you know, gathering OSINT on or you know, performing whatever their research is. They don't go to your website and your website says, you know, we're such and such compliant or uh, we're certified against such and such standard. They don't look at that and say, oh, well, that I guess I better not bother because you're secure. That's not at all what they think. They don't, they do not care. They instead are looking at things like, well, if, if I care about obtaining this particular asset from this particular organization, how would I go about doing it? The question of whether you are compliant or not is completely immaterial to the attacker. And then when you look at, on the defender side, the companies who are, you know, pursuing compliance, that often is the only thing they care about. And that's a really, really important mismatch when you think about it. It's like imagine m probably any sport, right? If the person trying to score a goal thinks about goal scoring and the person trying to defend the goal isn't thinking about goal scoring or defending the goal, tons of goals are going to get scored and that's a really big problem.

Speaker B: Yeah, one thing too, you know, kind of talking on, uh, about the offensive security side. But I know getting budgets for security, for any kind of security can be tough because, you know, this is. People look at, you know, security as a necessary evil. They don't really want to invest in much. So what recommendations do you have for people that are communicating with the board, with senior management, to try to get budget for, uh, the security, you know, assets that they need, um, the different types of consulting they need. Do you have any tips on be able to communicate that to have a better, uh, likelihood of getting that required budget?

Speaker A: Yes, I do. Uh, in fact, I think this is such an important question that I dedicated a considerable portion to my first book, which is called Hackable, to helping answer that question. Because if there's not an incentive for the business to do it, they're not going to do it. And that is a practical reality. Like when I was writing Hackable originally, I had nine chapters. And those nine chapters addressed nine common misconceptions that most organizations face when they're thinking about security. Like, they think about how to share information. Wrong. They think about how to evaluate, uh, the severity of their vulnerabilities. Wrong. They think about how to fix them wrong. So I had these nine chapters originally, and then I started thinking about, well, why does anyone care? Like, and I started thinking about, why do companies hire us? And my gut reaction, my initial instinct was, well, companies hire companies like us. They must do it because security is the right thing to do. Like, if you're building a solution, it should be secure. And that is true, I think, of any company who hires someone like us, uh, they do care about security. But I had to also put on my sort of, like, practical and capitalist hat and realize that's not enough. That's not enough for someone to spend meaningful money or meaningful effort. And as I started thinking about, I started thinking about our customers, I realized that many of them, in fact almost all of them, fell into this other and perhaps even more powerful motivator, which is that security is a, uh, competitive advantage. So when we're thinking about a marketplace, uh, where two companies are selling similar solutions to the same enterprise, and that enterprise has to evaluate between these two, they're going to evaluate things like price, uh, service level agreements, feature set, all these types of things. But important in there is security. So let's say if these two systems are similar and no two systems are the same, but they might be similar from a marketing standpoint or the problem that they solve. Security is a difference, because a lot of companies don't take security seriously. So when one company does and they actually do the right things, that's a competitive advantage. And so this is a long way of getting to answering your question, which is that there's two ways that we can think about why to invest in security. And those two ways said simply, one way is to avoid a bad thing from happening. And the second way is to pursue a good thing from happening. Make, uh, good things happen. The first way, which is avoid bad things from happening. That's the way almost everyone thinks about security. They're like, we want to invest X dollars so that we can make sure that Y dollars of damage doesn't happen. And the ratio between X and Y is what becomes debated. Right? It's like, well, how likely is this breach to happen? If it does happen, how big is the dollar impact? Okay, so let's. Let's say Maybe it's a $10 million impact and it's 10% likely to happen. Then that risk should be computed as worth $1,000,000. That is how we should be thinking about how much we spend on security. Like, that's the classic way of thinking about risk, and that's a good way to think about it. We want to spend money that minimizes risk within a, uh, rational way of having it as a percentage basis of the bad thing of happening. Like, you wouldn't spend $10 million to avoid a $10 million thing that might happen. You just. You're not. That doesn't make any sense. That's the way most people think about it, and that's a good way to think about it. But there's a better way to think about it, too, which is this idea of security is a competitive advantage. So being able to go to your customer and say, um, here are our core values. Here's who. Here's what we stand for as a company. And one of those things, a lot of companies will say things like, we put the customer first, or we value quality or whatever. Well, security is a way that you can put your money where your mouth is. And you can say, as a demonstration of that belief, here's what we do for security. Here's how we invest in these ways. Here's why that's above and beyond what, uh, everyone else is doing when they're just trying to check that box that you were talking about, Phil, when everyone else is just checking boxes, and you're out there saying, like, well, I think that an attacker thinks like this. Here's how we invested in order to address that, and here's why we're more secure as a result. That's really, really powerful. Because for anyone who's ever been through the process of, uh, procurement of Trying to sell something to a large company, this is one of the questions that they're going to ask. They're going to ask about security. And what they're really trying to understand is, why should I trust you? And if you can answer that question with the way that you've invested in security, it's going to simplify that procurement process. It's going to lead to sales faster, maybe lead to better sales. It might lead to sales that you otherwise wouldn't close. And so while in one sense that feels kind of like gross to think about, security is a, uh, mechanism for sales and marketing, that's the reality of the world that we live in. And that is a really powerful way to think about how you can get those security budgets is how can it support the sales mission, how can it support the marketing mission, how can it drive revenue? And if you, if you're listening to this piece of advice and you find yourself saying it doesn't, then you haven't thought about it closely enough. And that's where we can get deeper into like, well, how do you argue that? And that's why I wrote a whole book trying to argue about how you can actually go do that. Um, but that is ultimately a really powerful tool that can be in your toolkit.

Speaker B: Yeah. One of the things too, when you talk about customers, if people see that you're serious about their data and their privacy, you know that's going to make them a little more likely and willing to work with you. Because nowadays you really question whether companies really care about privacy because they take shortcuts and skimp on security sometimes, and then your data ends up in a breach.

Speaker A: Uh, absolutely right. For two companies to work together, they. There has to be trust established. And in order to establish that trust, there's some burning questions that need to be answered. Some burning, not even just questions, but like, fears. Right. And so think about the person on the other side of the transaction who ultimately someone signs on a dotted line that says, I approve that we're going to do business with this vendor, supplier, or trusted third party. Well, if that vendor or supplier or trusted third party is the source of a breach of this buyer's data, where do the fingers get pointed? Right. Of course they get pointed at that finger, uh, at that supplier or that vendor. They also get pointed at the person who authorized this, uh, partnership. And so this is more than just like, it's not as abstracted as company data. Like, some people might even say, who cares about company data? Like, uh, what individual person cares about company Data. Like people might say, that's not my job, that's someone else's job. Like I don't care. But what every person definitely cares about is their own professional reputation, their job security, their ability to get uh, promoted, to get raises, career advancement. And when you're the person who has made a decision that results in this really bad thing from happening, this embarrassing is in the headlines, costs all this money to respond from, it's really, really bad for that person. So we need to do is, we need to say, like, how can we help that person who ultimately is making this decision? How can we make them look good? How can we make sure that they're able to confidently be making these, these decisions? And the only way to do that is by truly and authentically building better, more secure systems. It's not by saying hollow statements like, oh, we're, we have bank level security, we use military grade encryption, like things that aren't really relevant to the security mission, that sound really nice and buzzwordy, but uh, actually trying to build better, more secure systems.

Speaker B: So, so one of the things that I find kind of interesting is the fact that you know, you, you're, you founded the IoT village or run, run the IoT village. So out of all the different types of things you could have done like at defcon these other conferences, what was your reasoning behind starting at IoT Village?

Speaker A: Yeah, the IoT Village origin story was kind of interesting. So this goes back, um, this is our 10th anniversary of IoT Village. So this story actually begins 11 years prior, maybe 12 I guess you could say, when we started having discussions. But 11 defcons ago there was a, uh, discussion that we're having with DEF con. We had just published this research that looked at small office home office routers and we found these like really catastrophic security flaws with these devices that everyone uses, that you're using right now, that I'm using right now, that people use in their home offices, that people use in their corporate offices too. And uh, we found all these problems and we started talking with DEFCON about like, is there a way we can gamify this research? Can we turn it into like a hacking contest of some sort of. And so we did and we went to DEFCON to run this first version of this thing. We called it so Hopelessly Broken the research was called. That's, that's what the research was called. So we named the contest after that. And if you've ever been to defcon, or even if people haven't been to DEF con, you might Be familiar with the idea that at any conference there's like the main conference area and then there's like the secondary areas, like maybe go down a hallway and then there's like you go down another hallway and there's like a tertiary area. We were down like a hallway after hallway after. We were so far away from the middle part of this conference and we were in a room that we shared with some other programing. Wasn't like just a room for us. And we were in the back corner of it. We had one table. We were literally behind the trash can. So like, people would like try to throw their, you know, like crumpled up wrapper or whatever from a trash candy bar. They try to throw it into the trash barrel. They'd miss, they'd miss and it would like land on our table. So that's how like, inauspicious our start was. Um, but that event, it went great. It went really, really well. The, um, uh, somehow word of mouth got out. Our. Our area was packed the whole time. Tons of people were coming. And we saw at that time that IoT was like becoming a thing. And at that time DEFCON had only like, maybe I could be wrong the exact number, but it wasn't many. It was like maybe eight villages or maybe it was definitely less than 10. It was like a small number of villages. And for people who've never been to defcon, a village is this idea of like almost like a conference within the conference, it focuses on a particular topic area. And we started talking at DEFCON about like, well, this is. What if we expanded this idea into like a, um, let's. What if we started a new village, focused on this emerging threat vector of Internet connected devices and they agreed to it. And so we launched this new village, which at the time that was a really big deal because for like whatever it was 25 years or something, up to that point there was only like eight villages. And now a new village being introduced was kind of a significant deal. And so we went out that first, uh, that first Iot village and it was like, it went better than we could have imagined. You know, we had this like, big beautiful space. One of the things that, um, I really cared about and our team really cared about was we wanted to set an ambiance. Like, we didn't just want to have just like a brightly lit room with some tables and like, that's. While that's interesting content, we wanted it to be a place that like, was attractive to spend time in. So we had like, we bought all these like super cool connect Internet connected speakers and with these amazing Internet connected lighting systems. So this like Deep Purple vibe, like almost felt like club almost. There was ambient music playing with like very kind of like techno like down tempo type beats. And um, and then people just came and they set up for the whole time and just participated and we had all these amazing things. We had like O day hunting where people brought in devices and we found zero day vulnerabilities in them. We had a Capture the Flag contest and it's gone great in the now 10 years of IoT Village that's been happening since. Um, our Capture the Flag contest is one thing in particular we're really proud of because for people who aren't familiar with DEF con, there's this like cultural norm there. It's I, we refer to it as badge culture. Like you have your badge to get in the conference and then there's certain like special badges. If you have access to like maybe a certain special party or maybe there's an add on to your badge. The badges often like the official DEF CON badges, are games themselves. Sometimes they interact with each other and then there's this like really, really super special type of badge called the Black Badge. And the Black Badge is for reasons unpublished that basically is just like if you did something so badass that the DEF CON organizers are like, you're awesome, you get a Black Badge. And a Black Badge is kind of like a Hall of Fame jacket in a sense. It's not literally hall of Fame, but it's like if you have a Black Badge for the rest of your life, you go to DEF CON for free. And when you walk around the halls with DEF CON Black Badge, like people want to take a picture with you. You're like, you're at this really high status in the um, community. And what was really, really cool is that that first year the winners of our contest were awarded DEFCON, uh, black badge. And in the 10 years since, we've now done it four times. So four times the winners of our contest have been awarded a Black Badge because winning that contest was so hard to do. There were like so many cool elements to it. So many just cool things happen. That DEFCON was like, hey, if you win that, you're pretty cool. And um, I didn't win the Black Badge. Uh, our team didn't win the Black Badge. It was the people who participated in the contest. But for us, we're so proud that we created an opportunity for that to happen for those people. And I mean that's like as cool of a designation of, of the validation of what we've been doing, that this matters. That like the way we've been focusing on improving the security issues in IoT is important. And um, and then we just get to have so much fun. And I'm, um, I forget what the specs are this year, but it's going to be big. We got a lot of floor space. Obviously being 10 years, we're going to celebrate in a bunch of cool ways. So. Pretty, uh, exciting.

Speaker B: Yeah, I look forward to seeing it. And so on the topic of like connected devices and IoT, do you see that improving security posture wise or is this still just a real area that's people have a lot of difficulty, uh, securing?

Speaker A: So the answer is both yes and no to is it. You're essentially asking is it getting better? And I say yes and no because it's almost like if you can plot two lines on a graph, one line is, um, are companies like, are mature IoT companies getting better at security? And that answer is yes. Like the number of companies that are mature in IoT getting better at security, like that's growing. So when we think about companies who have been in IOT for, you know, several years, a decade, whatever, um, are they getting better at security? Largely, yes. Not all of them are. But the percentage of companies that are getting better at security is growing. A lot of the legacy problems are starting to go away. Like companies are starting to realize you, you just can't, you shouldn't hard code default credentials because that's publicly available information. Uh, security is being considered in the design in many cases. So these are great things. So the percentage of mature companies that are doing a better job at security is growing. So that's a good thing. However, the space overall is growing at a more rapid rate. And what that means is that there are more companies overall in the space. More of them are immature. And I don't mean that in an insulting way. I just mean like their maturity of their product development or their corporate development lifecycle. They're just lower on the maturity spectrum. So when you think of it in absolute value, the absolute value of companies who are really struggling with security, that as a number as growing, uh, exponentially, the percentage basis is improving by the. The absolute value is getting actually worse. So that's why we got to think about, uh, things like IoT Village. And we're not the only groups advocating for change in this space. But that's why things like this are really, really important because we have to realize this problem not Only is it not solved? Uh, it's depending on how you look at it. It's getting worse. I would argue it's getting better and it's getting worse, but it's getting better because of the advocacy of groups like people who attend DEFCON, talk about these types of things, organize IoT conferences, develop IoT security products, service companies, et cetera. So it's, uh, a complicated answer, but I have reasons to be optimistic and reasons for concern as well.

Speaker B: Yeah, it's interesting to hear your insight, since you deal with that on a frequent basis. But it's also kind of interesting, too. You kind of mentioned, uh, how more use of these connected devices. I mean, you've got these systems for booking rooms, uh, conference rooms, all these teleconference devices. And one of the things I think people overlook sometimes is they think about IOT and they don't really realize the impact it can have on it, the IT infrastructure. Because back in my pen testing days, one of the things we would do is we would go after printers if we couldn't get a foothold, because sometimes you could get credentials from a printer, you could gain a foothold. And then like recently, the Acura, uh, ransomware attack, where they attacked a security camera because they couldn't get a foothold in the environment, then they were able to do an SMB share into one of the systems internally and then spread the ransomware. And it seems like it's becoming more of a prime target for threat actors because EDRs are getting better on the desktop. Traditional IT is getting better, but not always the IoT and connected space is keeping the same pace, the maturity.

Speaker A: Yeah, I love that story as, uh, as an example of the way that hackers think. Right? Ah, hackers. And maybe I should pause for a moment and just define what I mean by hackers, because I think you'd probably agree with this, that a, uh, hacker isn't good or bad. A hacker is someone who's curious, uh, creative, committed, uh, you know, problem solver. And the difference between good hackers and bad hackers is, of course, their motivation. Like, good hackers want to, you know, find the problems so those problems can be fixed, so the system can be improved. And malicious hackers, they want to victimize as a pathway to gain something. And. But whether they're good or they're bad hackers, they. They think similarly. Like, different motivation, for sure. Different ethical boundaries, for sure. But in terms of how you look at a system hackers, the hacker mindset is such a beautiful thing, right? It's it's looking at something and saying, uh, I'm, I'm supposed to do this or I'm not supposed to do that, or the only way to do it is X. And hackers look at something, they say, well, what if I did it differently? You know, I'm not supposed to do X, what if I did it anyway? It's supposed to do X, what if I do Y? And your example is such a beautiful illustration of that, right? It's like, well, we're supposed to uh, see if the IT infrastructure can be attacked. Well, what about devices that could give us a way to get into the IT infrastructure that might not historically be considered part of it, like Internet connected printers? And that is such an important way of thinking because when we just follow convention, when we are just conforming, like the way to do things is this way and everyone does it that way and that's the way it's always been done and there's no room for independent thinking, well then there's these pathways that are completely overlooked. And that's the beauty of the hacker mindset, is looking at something and saying, before I go along with the established conventional conforming way, let me first think independently about that. And your story is a beautiful illustration of it.

Speaker B: Yeah, it's pretty interesting to see because I was watching or listening to a podcast several years ago, uh, from Black Hills Information Security Group and they were mentioning how I was getting more difficult to gain footholds, the traditional ways from hosts. And so threat actors are having to spread to different, uh, ways of doing that, like these connected devices which sometimes people just don't really take serious enough or they don't have the uh, education internally to secure those devices. So it's good that there's opportunities like the IoT Village to learn that. I was recently at Hardware IO in Santa Clara, a big hardware hacking and hardware security conference. It was pretty cool. Joe grand was one of the speakers or one of the teachers, uh, there he taught, was teaching a class. So it's kind of good to have opportunities through the IoT village and these kind of conferences to educate folks because if people don't know, they don't have the know how, it's going to be hard to secure these uh, endpoints.

Speaker A: Yeah, I love even the point that you just illustrated because I think it echoes part of what I was describing before, this idea that when we think about a security model, the parts we're working on should get better, they will get better. I think we can be optimistic that the areas that get focus get emphasis, get resources, security will improve. And you just described it as, it's harder to get a foothold the traditional way. But we also have to realize that at the same time, the world is constantly changing. The attack surface is constantly changing. And as the attack surface changes, those things that are newly introduced or considered in new ways, those are the weak points. And any emerging tech becomes that. So IOT is still, uh, maybe in the later stages of its adoption cycle. Like I don't think we're in the early adoption yet of IoT is pretty widely deployed by now. But you can contrast it with something like AI systems, which are in the very early stages of adoption right now, or you can contrast it with something like bring your own device, you know, mobile devices, which are in the very, very late stages of adoption. And each of those three things, if you think about them in terms of security, uh, what's the most secure BYOD has? Thethe of those three scenarios probably has the least problems now because it's been worked on for the longest period of time. The second would be the IoT devices. And the most problematic is AI because it's so emergent right now. And that's the way we need to think about emerging technologies, is that emerging tech changes the attack, uh, surface. And once the attack surface changes, we need to com. We need to reconsider the threat model. So that's what we're doing here. That's what we do at things like IoT Village, and hopefully that's what conversations like this drive.

Speaker B: Very cool. So, yeah, I appreciate your time today. It was great chatting with you and I look forward to seeing you at the IoT Village, uh, coming up soon at DEFCON. So thanks for joining today.

Speaker A: Yeah, can't wait to see you there. And for anyone who's interested to learn more about these ideas or just keep in touch with me, it's pretty easy to get a hold of me. Just find me at just my name, Ted Harrington.com and for the listeners, if

Speaker B: you want to learn more about how to secure your IoT and OT devices, check out Phosphorus IO. We have a solution to help secure those endpoints. And this is beyond just your industrial type stuff. Going back to the printers, securing printers and cameras, it helps make that a lot easier because typically that, traditionally that hasn't been easy to manage. There hasn't been really good solutions for that. And so if you like the podcast, please subscribe and share with your friends and colleagues. Thanks.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Hiring top-tier talent, leveraging open source models, and staying competitive in the age of AI w/ Benny Chen #267The Engineering Leadership Podcast · on Competitive advantage86 / 100
  • Ep 109: Cybersecurity Research 101 with Malav VyasLevelUp Cyber · on DEF CON71 / 100
  • Most Companies Aren't Anywhere Near Ready for AIUnsupervised Learning · on Competitive advantage61 / 100
  • WTF do I do now? ( It's not what you think ), with Danielle SproulsBuilding your LeaderBrand · on Competitive advantage53 / 100
  • Humility as a Competitive AdvantagePrepare4Growth · on Competitive advantage35 / 100
  • 5 Minute Break: What Does Your Brand Stand? 5 Brand-Building Questions to Ask YourselfBusiness Growth Café · on Competitive advantage32 / 100

More from IoT Security Podcast

All episodes →
  • Hacking Culture, Community, and Curiosity: Evolving Security Research in a Modern World67 / 100
  • Bridging Worlds: The Evolving Landscape of IoT Security and Regulation
  • Breaking Down Barriers: Making IoT and Hardware Hacking Accessible to All with Andrew Bellini
  • From Boardroom to Backend: Cybersecurity Tactics for Emerging Tech in Finance
  • Breaking In to Break Things: Practical Paths to Hardware Hacking and IoT Security
Explore the best B2B Engineering & DevTools podcasts →
All IoT Security Podcast episodes →