The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/LevelUp Cyber
LevelUp Cyber artwork

Ep 112: Understanding Security Awareness with Tom Kirkham

LevelUp Cyber · 2024-10-25 · 36 min

0:00--:--

Key moments - from our scoring

Substance score

53 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality9 / 20
Guest Caliber12 / 20
Specificity & Evidence10 / 20
Conversational Craft11 / 20

Security awareness often gets overlooked despite being foundational to cyber resilience. Tom Kirkham, CEO of Kirkham Iron Tech, a managed security service provider specializing in continuous cybersecurity awareness training, walks through why this matters at scale. The hacking industry exceeded $8 trillion globally last year - larger than most national economies - and operates as a numbers game using phishing simulations, ransomware delivery via compromised emails, and targeted credential theft. For companies, the stakes are existential: up to 60% of businesses close within two years of a significant security breach. For individuals, password reuse across accounts creates cascading vulnerability when one service is compromised. Kirkham emphasizes that over 90% of security incidents stem from human failure, not technical exploits. His core recommendation: make security awareness top-of-mind through continuous training and phishing simulations, use password managers like 1Password or Keeper to enforce unique credentials, and adopt the mindset of questioning urgent emails before responding. The episode targets risk-aware leaders, HR heads implementing training programs, and individuals seeking to reduce their attack surface without becoming paranoid.

Key takeaways

  • →The hacking industry is a $8+ trillion global business operating at scale using conversion-rate thinking, meaning most attacks succeed through volume rather than targeting specific high-value individuals.
  • →Over 90% of security breaches result from human failure like clicking phishing emails, not technical vulnerabilities, making continuous awareness training and phishing simulations essential defensive tools.
  • →Password reuse across accounts creates a single point of failure: if one service is compromised, attackers gain access to email and all linked accounts, which is why unique passwords managed by tools like 1Password or Keeper are non-negotiable.
  • →Nation-state actors (China, Russia, Iran) use hacking and social media to steal intellectual property, influence elections, and create societal chaos, making cybersecurity a geopolitical concern beyond individual risk.
  • →Up to 60% of businesses fail within two years of a significant security event, making breach prevention a core business continuity responsibility for leadership.

Guests

Tom Kirkham

Topics in this episode

Phishing simulationsSecurity Awareness TrainingRansomware attacksIntellectual property theftPassword managers (1Password, Keeper)Nation-state cyber warfareManaged Security Service Provider (MSSP)Dark web threat economyCredential theft and keyloggersAI-generated phishing emails

Questions this episode answers

Why would hackers target me if I'm not wealthy or famous?

Attackers operate at massive scale using automation and volume, not targeting individuals by name. They encrypt data and demand ransoms of hundreds to thousands of dollars per victim, or sell access lists on the dark web to other criminals with different objectives, making every person a potential target regardless of perceived importance.

What information do threat actors steal from companies and what do they do with it?

Objectives vary by threat actor: ransomware operators seek money and install backdoors/keyloggers to sell to other specialists; nation-states like China steal intellectual property (described as potentially the greatest wealth transfer in history), Russia conducts cyber warfare on critical infrastructure, and some actors pursue ideological goals or personal data for doxxing and social manipulation.

How do I remember all my passwords without reusing them?

Use a password manager like 1Password or Keeper, which securely stores and auto-fills unique, randomly-generated 20-25 character passwords across all devices. After 30 days of use, most people prefer it to memorizing passwords and avoid the single point of failure that password reuse creates when one service is breached.

What's the most common way companies get breached?

Phishing emails that mimic trusted vendors or internal leadership, often with urgency or file attachments that trigger macros to deploy ransomware across the network, exploiting the fact that even security-aware people can be fooled by AI-generated content designed to match organizational hierarchies and communication patterns.

What should companies do first to improve security awareness?

Make security awareness top-of-mind by implementing continuous cybersecurity training and phishing simulations to keep employees alert, test them regularly with realistic emails, and foster a culture where people pause before reacting to urgent requests and question whether the tone or request matches what they'd expect from the sender.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode covers foundational security awareness concepts with some useful specifics (password manager recommendations, phishing simulation tactics, the $8 trillion hacking industry statistic), but relies heavily on well-worn platitudes ('make security top of mind,' 'don't click suspicious emails'). The core advice - use password managers, run phishing simulations, invest in training - is sound but not novel for a B2B security audience. The intellectual property theft discussion and nation-state motivation breakdown add modest depth, but much of the runtime is spent on elementary definitions and fear-based framing rather than actionable insights a sophisticated operator wouldn't already know.

security awareness is just being aware of what your risk is or your company's risk is
over well over ninety percent of security events are due to human failure

Originality

9 / 20

The episode recycles standard security awareness frameworks without meaningful contrarian or first-principles thinking. The framing of hackers as a scale business with conversion rates is clever but not new; the password manager advice is standard practice; the nation-state objectives (IP theft, election interference) are widely known. Tom does not challenge common assumptions or present surprising counterarguments - instead, he reinforces conventional wisdom with examples that illustrate rather than interrogate existing orthodoxy.

They're using They're thinking in terms of marketing terms. You know, what's our conversion rate?
there's tens of thousands of people that are attacking tens of thousands or even millions of people at a time. You start realizing that they're just playing a numbers game

Guest Caliber

12 / 20

Tom Kirkham is the CEO of a 25-year-old managed security services provider and has clearly worked with global manufacturing companies and other enterprises. He has practical operating experience and authored books on the topic. However, the transcript does not establish deep expertise in security operations, incident response, or advanced threat intelligence - he positions himself as a 'generalist that evangelizes cybersecurity' rather than a practitioner who has managed major breaches, scaled detection capabilities, or led security transformation at Fortune 500 firms. His credential is real but not exceptional for a B2B security podcast.

Tom is the CEO of Kirkham Iron Tech
I was recently hired by a really good sized company, global manufacturing company

Specificity & Evidence

10 / 20

The episode includes some concrete data points ($8 trillion hacking industry, 60% of businesses fail within 2 years of breach, 90% reuse passwords, one $3.5 billion ransomware attack netting masterminds $200-300M each) and specific tactics (Excel macro attacks, AI-generated spear phishing, keyloggers sold on dark web). However, most claims lack granular evidence: no named breaches analyzed, no specific client outcomes quantified, no timeline details on attack progression, and vague references to 'hundreds of videos on YouTube.' The guest relies on generic examples rather than detailed case studies that would allow operators to extract actionable patterns.

one ransomware a global ransomware attack a couple of three maybe four years ago that netted three point five billion dollars globally
up to sixty percent of businesses go out of business within two years of a significant security event

Conversational Craft

11 / 20

The host asks competent setup questions and occasionally probes deeper ('what kind of information are threat actors trying to accomplish'), but rarely challenges Tom's claims or pushes back on vagueness. When Tom makes sweeping statements like 'up to 60% of businesses fail within 2 years,' the host doesn't ask for sources or explore exceptions. The conversation follows a predictable script - intro, definitions, motivations, solutions, career advice - without memorable follow-ups or productive friction. The host does attempt to connect concepts (security culture, early education) but doesn't use these to interrogate Tom's assumptions.

That's a great question, and it's really Inchan
I was recently hired by a really good sized company, global manufacturing company, and they had personnel that repeatedly, we're failing their simulated phishing email attacks

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

security27password20awareness12email12money11cyber10everybody10risk10industry9dollars9mind9different8attack8cybersecurity8objectives8better8

Episode notes

Did You Miss My LinkedIn Live on Cybersecurity Awareness? Catch the Replay! I had the pleasure of sitting down with Tom Kirkham, Founder and CEO of Kirkham IronTech, for an incredible LinkedIn Live discussion on the fundamentals of cybersecurity awareness. Together, we broke down the essential steps everyone should take to protect themselves and their organizations from today’s evolving cyber threats. Tom shared valuable insights and practical tips that are easy to implement right away. If you couldn’t join us live, don’t worry - you can still catch the replay! Watch it now and take control of your cybersecurity. #Cybersecurity #CyberAwareness #LevelUpCyber #SkillsBasedHiring #CybersecurityFundamentals #CyberUp

Full transcript

36 min

Transcribed and scored by The B2B Podcast Index.

Good afternoon, and welcome to this week's episode of Level Up cyber My name is Tony Brian and your host and executive director at Cyber Up. This is going to be a fun one. I think it's a topic that is near and dear to a lot of companies and a lot of individuals. Hearts, and I also think it's one of the things that we have a tendency to overlook and underestimate.

It's a really simple thing that I think we take for granted. It's the concept of security awareness. Right. We all know the things, we all know what to do.

We know we don't click this and we don't click that, but do we really know and understand some of the risks and things that come along with it. So very excited today to have Tom Kirkham join us. Tom is the CEO of Kirkham Iron Tech and is a really well versed in helping companies and individuals with the security awareness training. So Tom, welcome to the show.

Oh thank you for the kind words, Tony, and it's my pleasure being here. You know there's I won't soapbox too much. If you've listened to the show for a little while, you've heard me ramble on about the idea of data care and the GULA Foundation, and Ronisson and GULA founders attenable just their idea of data care and the concept of self ownership of when we are responsible for our own things, much like our own health. Right like that concept resonates with me.

So security awareness is such a critical part and foundational component to that aspect of somebody being more cyber conscious and cyber aware. So definitely excited to jump into it. So you and I have had a chance to get to know each other and learn all the incredible things about your career. But for the sake of everybody's benefit, I love just introduce yourself.

Where you've come from and how you got to where you're at today. What is your origin story? Oh wow, Well I went to college for economics, believe it or not. But basically this company is about twenty it'll be twenty five years old in January.

And it started out as a typical IT service provider and we did break fix business. And that's if you hire out your IT break fixes, you just pay them by the hour when something's broken right, and then a little over It was probably close to fifteen years ago we started getting into managed services, and we started seeing the security landscape changing. So then we changed into a managed security service provider, making security job one. That's kind of a difference between a typical managed services provider, which is basically you write a check every month and they make sure nothing breaks and everything's maximized for performance, productivity, and efficiency.

But when these. Hackers really got really good at their stuff, and then the NSA was breached and their offensive cyber warfare tools like stucksnet was stolen along with the source code, that changed the game. You know, a typical antivirus is no longer effective off the shelf antavirus. We our clients do not use anything that can be bought at Best Buy or office depot.

We're putting industrial strength security defensive tools in place. Wrong button. I like it. So you know what sparked your interest in the idea of security awareness, And let's just for the sake of everybody's benefit, let's define what is security awareness?

And you know what is security awareness? Well, security awareness is just being aware of what your risk is or your company's risk is. And it's very common for people to think that, well, why would someone want to hack me? I'm not wealthy.

I don't own a company. Uh. I'm in the middle of nowhere. I'm you know, so I don't think it's going to happen to me.

And the same thing with companies. You know, we talked to law firms and just all sorts of different types of businesses. Uh. And the smaller they are, the more likely they're going to think that, well, a hacker doesn't want to attack me.

I don't really have to worry about it, you know. You know that's that only happens to Sony Pictures Corporation or JBS Meat Supply Colonial Pipeline a couple of years ago. You know that that's because that's all they hear about. That's what's on CNN.

But what they don't understand, what most people still don't understand, is the vast majority of these attacks are done at scale and volume. And the hacking industry is huge. Last year it was over a eight trillion dollars globally. It's so big that if it was a country, it would be the third largest GDP on the planet United States, China and then the hacking industry.

And when you start realizing that there's tens of thousands of people that are attacking tens of thousands or even millions of people at a time. You start realizing that they're just playing a numbers game. You know, they don't care if you've got money. But if they get on your computer and they encrypt all your data on your computer, but you've spent the last twenty years digitizing all of these family photos and maybe they hold it ransom for five hundred dollars.

Are you going to pay that, you know? Or are those photos that you spent so much time collecting worth that kind of money. They don't know who you are, and they don't even care who you are in these attacks. And if they don't know who you are or care who you are, after it's all over with and if you pay the ransom doesn't matter.

There was one ransomware a global ransomware attack a couple of three maybe four years ago that netted three point five billion dollars globally, and the two masterminds behind it netted two to three hundred million dollars each and the rest of it went to the rest of the gangs that were involved. Yeah, other companies in the it's my I'm telling us mind boggling. There are companies on the dark web that provide bucs and services to hackers. It's a huge industry.

In fact, it's so big now you go on the dark web and they complain about administration problems and HR problems and uh, but they're just playing a numbers game. That's it. Yeah, conversion rates, you know they're using They're thinking in terms of marketing terms. You know, what's our conversion rate?

I think give that amount of money. First of all, it's crazy, and I've always just heard that the underbelly of the system that does these things right, because these are professional hackers that are at scale, that have made companies and their entire purpose is to have people hacked daily, right in miss numbers game. But just it blows my mind is to think of the scale of that, and it is alarming, and that does put a little bit of fear right and uncertainty, and at least as an individual, like, hey, what is all these things out?

And I think most people are generally shocked at just the volume and how large these attacks are every single day. So we're going to divide this conversation at two kind of buckets, right, a company bucket in an individual bucket, but the core of it will I think we'll tie back and the end will be about the same. So you know, why is this important for companies that are hiring people every single day, that are selling and making products or manufacturing things. You know, it's they can't just go Why can't they just go widgets and do their business and hope that things work out for the best.

But they have Why do they have to invest in things like this to increase the awareness of their workforce? Oh? Well, because they're going to get caught. They're going to get hacked, they're going to have customers compromised, they're going to have systems shut down.

It's going to cost them money no matter what happens. But here's what the research also tells us, and it depends on the research study, but up to sixty percent of businesses go out of business within two years of a significant security event. That's that's it. That's what the numbers are, and sometimes it's as little as six months.

So excuse me. So if you imagine all the attorneys that you work with, or your banker, your financial advisor, your doctor, your dentist, all those personal financial and health records and all of that, if they get compromised. Those types of businesses thrive on their reputation. So at the very core of it, a business has to think about their reputation.

What would happen in the case of the security event, and there's rules and regulations that require them to report it in most states, and it's. Going to be public knowledge. And so if you do nothing more than just cut that risk to your company down, that's your job as the owner or the CEO or the president. That's what your job is is to analyze risk.

And when you comprehend that, you realize that, well, I can't afford this. I mean, we can't afford to be breached. It's just the cost of doing business. It's it's not rolling the dice.

And what my company specializes in is dropping Let's say their risk is ten percent in any given year, and having a breach, we drop it down to point oh one or point one percent. There's no such thing as one hundred percent protection. But the important thing to that we have a problem with our own clients, and that's around the security awareness and security training. And it's when.

You understand that over well over ninety percent of security events are due to human failure. You know, the ransomware attack, it's typically. An email attack that's just a con job. You know, it'll appear like it's coming from a vendor that you know, if you're in the law business, it's going to be one of the research firms.

You know. So somebody in bookkeeping just gets an email that says attached or all the outstanding invoices for your account, please pay immediately, or we're turning. The service off. And bookkeepers just trying to get their job one, our job done, and they click on the Excel spreadsheet.

Excel spreadsheet calls a macro. The macro calls the Windows disc Encryption service and starts encrypting everything it can find on the entire network. And so it needs to be top of mind. And that's what security, continuous cybersecurity awareness training does.

And then we also usually tie in phishing sims or phishing simulations to where we're constantly testing our clients and their people and our people. And it doesn't matter how smart you think you are, you can be fooled by these these emails. You know, the days of misspelled words, bad grammar, broken english, bad graphics, those are over. They're so rare to see anymore that sometimes we'll pass them around the office just just for a laugh.

No, these, in fact, we simulate fishing, a phishing attack on ourselves, right, So we get one or two emails a week that no one, even the people that set it up, really just don't know what the email is. So and there's only been one person in the company that's never been fooled, and it ain't me. I just so happened to be working on Google security settings one time and that's when the phishing sim came out. Hey, we see you've changed your Google security settings.

Click here to review them. I mean, it's right at the same time, coincidentally, and I clicked on it, and I got a two minute video on everything that I did wrong. I completely blew past all the things that. I know, the SLAM method where you you know you here's what you look for or you know, if it had been out at if I hadn't been working on those, I probably wouldn't have fallen for it.

But it just goes to illustrate, especially now in the day of AI generated emails, they can identify the hierarchy or the organization chart inside of a business and somebody bookkeeping could get a business or an email from somebody that is like this. This happened to a friend of mine. He owns an insurance company. It looked like it was from him, and it was an email that says, please wire fifty thousand dollars to this city account in New York.

And it wasn't unusual for that company to move fifty thousand dollars around. But it got trapped. They had policies in place, you know, I have counting controls to trap it. But it could have easily not been caught, and that would have just that money would have vaporized.

We just alluded to it a little bit from I said to the next question is what kind of information are thread actors trying to accomplish or get from these companies? Right? Or individuals? Right?

And will lead into people next. But you know, what what is it they're looking for? Is it trade secret sales? Like?

What is it they're trying when they are trying to poke and prode and find things or do these fishing campaigns. What is the information they're trying to get from companies? That's a great question. Uh, it depends on what the thread actor objectives are.

Now, the majority of hacks are for money. But the interesting thing is on a modern ransomware attack is they'll also deliver other bad stuff, malware viruses or whatever on the computers. And then when their ransomware attack is over, they go out on the dark web and sell a list of servers that they've installed backdoors on, or a list of workstations that they've installed keyloggers, which is used for credential theft. So other specialists in the hacking industry will take that list for whatever amount of money, you know, one hundred dollars or fifty whatever it is, they'll buy that list and then they will hack according to their objectives.

Now, when when you start talk other than money, what are the objectives? Well, when you're looking at nation state, we're seeing it right now, and we've been seeing it for ten years, but it's finally getting mainstream attention. But it's being used like China, Russia especially and Iran is using hacking and personal information and social media to influence our society and political and elections and you know the makeup of our government. And it's happening on both sides.

This is not a political discussion at all. Just be aware that you're being manipulated by foreign interest, and they're objective is to create those countries. Objective is to create chaos in Western democracies. They don't really care.

They just want more and more tribalism that we're seeing in society these days. In the case of China, for the past thirty years, maybe longer, one of their big objectives objectives is to steal intellectual property. And if you think back thirty years, China was more or less a third world country, and now some of the cities in China are far more advanced than the most advanced American or European city. And you can't make that.

Change in society that fast without getting intellectual property and patented things and techniques and all of these things to move that fast. There's some. There's some historians that say that that theft of intellectual property that China did over the past few decades is the greatest transfer of wealth in human history. And then you then you've got nation states doing it.

For cyber war. So everybody, pretty much everybody listening is familiar with them wanting to attack critical infrastructure. You know, there's a list of seventeen but water utilities, electric gas supply, chains, you know, and all of these different things. So that's more chaos.

But it's also a war. That's a war, it's a battle, it's it's it's not kinetic warfare, it's cyber warfare. So there's some of that going on. There's some people, there's some hacker or threat actors that do it for dosing or ideological reasons.

If you look at what the group Anonymous has done off and on over the years, they had an ideological purpose for hacking this particular company, Edward Snowden, the the oh I can't remember the name of the deal down in Panama about all this high net worth individual money that was moving around. Those documents were all stolen and publicized. So it depends on what their objectives it and there are many, many, many objectives. But once they get into the system, no matter what if that's not their specialty, the specialists that specialize in docsing or stealing intellectual property or any of the other objectives they're they're going to find out.

They share all that information with each other. They're there, they. Understand you imagine, imagine all the specialties there are under the roof of a good sized hospital. M.

D. Anderson Cleveland Clinic, Mayo whatever. There's there's that that type of specialization in the entire hacking industry, and they hang out together. I know it's a tight group, and I'm glad you alluded to the intellectual property is.

I know, I've seen a couple of talks where you just see Chinese airplanes that look identical to the US airplanes. You know, it's an ABC plane, but they call it an A B D plane, and it's all the same stuff, and it's you know, billions of dollars of research and R and D and stuff put into these things. And it's easy to exponentially get ahead of your peers if you're you're taking their stuff and doing it. So great, great answer, and a really solid example of just what all is at risk transitioning to the human side or what's all it's all human, but to the individual side.

You know what, what what do the bad folks want for me? Right? I'm just I'm just a person living in my house, trying to raise my kids and pay bills. You know, I don't have a whole lot to going on with me.

You like, what do they want for me? That's a great question, and it's really Inchan. You know, I've got the two books on Amazon and the one that the hack the Rich book. It's about the special needs of high net worth individuals.

And I wrote that before AI was being used by the hackers to where they could automate targeted attacks. So that gets that gets you what you. Want to know there as an individual, So that book is more appropriate for anyone. In things on how better to protect yourself?

You know numbers, the research tells us that ninety of the population reuses passwords. Even though sixty percent know they shouldn't, they still do it. So what what why is that a security risk? Well, number one, it's probably not secure in and of itself.

Right, it's your your your dog's name, and the birth year or the birthdate of your firstborn, or it's your college mascot one, two, three, and all of that can be scraped and gathered off of Facebook and LinkedIn and different places, and they just automate trying out passwords and then once they get into something, they get a successful match if you've reused that same password everywhere else. And say your. Email gets well, first of all, if your email gets compromised, they pretty much got keys to the Kingdom.

So because. What's the most common way to reset the password. It's through email still. But if you use the same password on your email as you do your Facebook, and when Facebook gets compromised again, that password will be stolen.

It'll be in the dark web in minutes, hundreds of millions of records or on if not billions or records or on the dark web. But if you're using that same password on your Chase account, your City account, or Merrill Lynch account, your your medical online medical account, all of them are compromised by using the same password. That that is a huge, huge no no. And what I have so many passwords to remember, it's hard.

I don't everything requires a password us your name. What can I use to keep it all strang is there are there tools and things that I could use a leverage because inherently we're all humans, We're a little lazy, let's be honest. I can't say that I'm immune to that, but like, you know, how, what are some tips and tricks for me to use to not be a target for those things or make myself vulnerable or easier target. Right, So you're you're so kind to queue that that t that ball up for me.

So the answer is a password manager, of course, and uh that that's a it's a piece of software. If you'll just commit, it's a lot. They're all a little clunky. It's not the software's problem.

It's usually around websites, but you'll and so since they're a little clunky, sometimes on certain sites people get frustrated. But if you'll commit just a couple of three days to using one, you'll keep using it and then thirty days later you'll wonder why you didn't start thirty years ago. So what a password manager does? It securely not only stores the password, but also transmits it to all your devices.

So you've got it on your phone, your desktop, your laptop, your tablet, whatever. It's always with you. And it generates a password, and you can spin it up to twenty twenty five characters, which is what I do all the time, randomly generated special characters, upper lowercase numbers. And you don't care what the password is because it's always there, and in most cases it's going to automatically feel in your credentials on the website.

So, and it also looks for duplicates like you're reusing passwords. But it also makes it unique for every log in that you have. I think my password manager may have fifteen hundred to two thousand records in it because I've been using one for thirty something years. And just to name a couple.

I'm not compensated in any way really for these two companies. But one Password is great. Keeper is also really good. I guess in a way I am compensated by Keeper because that's where a partner with Keeper.

But those are. Both really good password managers. What you should not do is use the password manager it's so called password manager in your browser, unless it's Safari. Safari is okay, but you should not ever store credentials in Chrome.

They've had breeches. You got to remember what's Google? What is Google selling? They're selling you.

You're the product with everything Google makes, so security is not really job one at Google. And the same thing applies to Facebook and other social media platforms that you're. Not paying for. But since Chrome has been compromised, quit storing it in browsers.

Use a password manager, and I promise you, like I said, if you stick with it, you'll wonder how you ever lived without one. I haven't met anybody that said I gave it thirty days and I can't do it. And I've never heard that from anybody that I've grated for not using a password manager. So, you know, we've got about five or so minutes left and I definitely want to get to some like advice and best practices, right, So we laid a salid foundational what we're doing and why it's org to companies individuals, But like, what do we do?

Right? I mean, obviously we just alluded to a password manager. But if I'm if I'm a company in an organization, where can I start to find some answers and some solutions to give me peace of mind tonight? So I want to trust my employees, but I also want to empower them to learn the things.

So where's a good place to be in? Well, I personally, I think it's it's make it top of mind. You know, you go into any decent sized city or small town for that matter, it doesn't matter. You know, pretty much everyone's been exposed to one on one street cons right.

You know, you know, if you're in New Orleans, I know you've been exposed to them there because they they can tell you where you got your shoes, right, You know that CON's been going on for decades now. You've just got to be understanding that. You know, you don't want to react to an email just because it's urgent. You want to take a moment and say, does this sound like something say it looked like it came from me.

Does this sound like something Tom would say? Or does this sound like something he would request? In the case of that fifty thousand dollars email that my friend company was tested with, after they read it or somebody else laid some eyes on it, they go, he wouldn't say it like that. You know there would be more to it.

And you can't get there as a company unless you make it top of mind. Security has to be job one, So you got to think in terms of a con job is most likely way you're going to get breached personally, a business, anything, and if you do as if you do nothing but just get some cybersecurity awareness training. We have probably hundreds of videos on YouTube around different types of hacks and what to do and how to secure yourself. They're all available for free.

And if you have a company, if you're the head honcho, you know, if you are ware, the buck stops, especially if you've got investors or stockholders to answer to. You better have answers, and you better understand the risk you're taking but not showing. Making security job one. I was recently hired by a really good sized company, global manufacturing company, and they had personnel that repeatedly, we're failing their simulated phishing email attacks.

Right, it's something you should implement, and in my approach hopefully made a difference. They had never tried what I was talking about. And that's to make security job one. You've got it bank at top of mind, and that'll make can better, better employees, better for the company, and better for them in their personal life as well.

It's it's just really getting a fine appreciation for that that that sheer size and scale of it of the industry. So if you going by numbers again, if you implement a continuous cybersecurity awareness training in your company, you're going to cut your. Risk in half. All of these cool super industrial Fortune one hundred level defensive tools at my company and other others deploy we wouldn't have to do that, and well we'd still do it, but but we really have it there because we know humans are going to fail.

That's why we have to have them. Yeah, it's unfortunate and it is what it is. But you know, incorporating what I would consider a culture of security, speaking about it any opportunity with all hands. Just making that a consistent theme that you're talking about in the regular is huge.

I know, we kick tires early on in our existence about you know, just creating cyber aware people and finding ways, you know, through screwtyware, just training to get people certified. Right. Everybody likes their certificates and their hours and completion to feel like they're part of something, So that was always kind of in top of mind for me. And then I think the other piece that we've started to do is just having those conversations earlier.

Right, you know, we're putting iPads and iPhones in the hands of toddlers right now that have access to the world that could with a wrong click spend a lot of money on an ituness account or buy something right, so you know, there's there's a lot of risk that comes along with it. So I thought we found that the earlier you start having these conversations with students around the importance of protecting yourself and how you own your own data, like really getting that in because I don't to your point, and I think you've just confirmed in my mind this doesn't go anywhere for the foreseeable future.

This is this is a new norm that we have to reset our expectations and just get into a mindset of being security first and putting you know, thinking about that on a regular basis. So but earlier you get in with young students and start having these conversations, you're you're you're inspiring them one to one just be better stewards of their own data and stewards of company data. And two maybe you know, helping people grow into the field and sector and you know, push them towards a career, which we know, we've seen all the data.

We know that's an important part. So, tom Man, that was some great content. Everybody gets the same last question though, so I can't I'd be remiss not not to ask you. So, what advice would you give to somebody looking to level up their cybersecurity career.

That's a great question. I think it would be very beneficial to, uh, look at all the different specialties, you know, just like the specialist on the black hat side, you know, there's specialist on the white hat side, they're specialist in. The gray hat area. Uh, look inside there, because being a cybersecurity whatever, Uh, that's a generic term and if you deep dive into it, you may find that you're just really enthralled with being you know, incident response or being part of blue team, Red team stuff, or or somebody like me, a generalist that you know, evangelizes cybersecurity.

I think you know, different companies look for different things when they hire people. This comes up almost every day with me. We because of the nature of our business and we don't really have time to go into it a whole lot here, but we we weigh people with security credentials certifications higher than we do college degrees because the industry just changes way too fast. So that brings in Another point is maintain lifelong learning.

You you can't be any You're not going to be dedicated to cybersecurity if you don't read threat intelligence reports, look at new threat techniques and technology, new con jobs. You got to stay up to date with the criminals and what their the FBI calls them the lets say, tools, tactics, and procedures. You know, what's there, what's their method of operation? How do they go about doing their their craft, and if you're not sure about that, I think you'll you'll find your way because it is a very big industry.

And those are the two things that I would I would point out if you want to go to work for a fortune five hundred, get that college degree. But those certifications are going to be super super important. And the farther you go up that ladder of certifications, the more money you're worth. Yeah, that's a great answer.

I like the uh that always a lifelong learner because I'll too often have met a lot of folks they do the thing to get the thing. I mean, like, I'm good, I don't have to worry about this. But I think cyber is such a such an expansive sector and industry with so many different verticals and pathways as you could pick. You have to always be learning and find out what your passion is and continue to push.

You found yours early, which is awesome to hear. So it's awesome. Yeah, it's you think about the pace of change and just information technology. You know what you know, get Moore's law, CPUs double and speed every eighteen months will add warfare to that technological pace of change.

You know, think about how World War two. The technology just changed so much in four years. Well that's how fast it changes in cybersecurity. There is no static you know it X.

If you're truly good and passionate about it, you will maintain learning. But there's not many industries left that you can't keep learning. So yeah, those are falling off. Well, Tom, I appreciate you joining us today, you know, quick plug.

So Tom's got two best selling books that are out there. One is called Hack the Rich. It's you know, we tie it until we talked about today? Is that?

What is that personal ownership that you need to do as an individual right for you know, kind of focused towards a high net worth person, but I imagine there are best practices that are applicable to everybody and aspired. We all aspire to be hind networth. So when I get ahead of the power curve, you're there, right, So go pick that one up. And I'm gonna have to pick up the cyber Pandemics Viible Guide.

It scares me a little bit off the title. And you know, sometimes I you know, I you know, nine years ago I got into this space and learned quickly that a little bit like Wizard of Oz. What you see behind the curtain, it's a little scary. So you know those things that you know there's ignorance is blessing some of these regards around understanding all the bad the tactics procedures you alluded to a second ago, so both those would be great read.

So Tom, thank you so much for joining us. Be sure to check out the book and if you got any questions, I'm sure people would love to. People can feel free to reach out and LinkedIn if you've got questions and go. So thank you so.

Much time, it's been my pleasure. Thanks for having me and everybody please stay vigilant, make it top of mine. Yeah. Well, thank you so much for tuning in and I hope everybody see everybody soon.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Spot That Vish!Simplifying Cyber · on Phishing simulations90 / 100
  • S7 Episode 7: Trevor Davis on The AI Revolution in Creative IndustriesDigitally Curious · on Intellectual property theft86 / 100
  • Insurance Without the BS - What Founders Actually Need to KnowThe Fractional CFO Show with Adam Cooper · on Ransomware attacks81 / 100
  • The Bad Guy's Different Set of RulesSecurity Breach · on Ransomware attacks78 / 100
  • Ep. 5: Food and Agriculture featuring Jonathan Braley, director of the Food and Ag-ISACThe Security Detail · on Ransomware attacks78 / 100
  • From Ransomware to Recovery: How One Rural Hospital Transformed Its CybersecurityEncrypted Ambition: Where Ambition Meets Encryption · on Security Awareness Training75 / 100

More from LevelUp Cyber

All episodes →
  • Ep 118: A Dive into Multi-Factor Authentication with Sairam Durgaraju49 / 100
  • Ep 117: LinkedIn Best Practices with Jessica Cassidy68 / 100
  • Ep 116: Ask a CISO with Steve Zalewski79 / 100
  • Ep 115: The Non-Technical Side of Cyber with Susan Klement66 / 100
  • Ep 114: Top 5 Cybersecurity Best Practices with James Bierly77 / 100
Explore the best B2B Engineering & DevTools podcasts →
All LevelUp Cyber episodes →