
Phishy Business · 2023-08-29 · 34 min
Key moments - from our scoring
Substance score
47 / 100
Five dimensions, 20 points each
Des Rock brings hard-won perspective from two decades running ethical hacking and defense companies. She identifies a core problem: boards won't fund security until breached, creating the opposite of their intention - unbreached organizations are exactly what hackers target. Rock explains how internal politics prevent CISOs from even disclosing vulnerabilities to their own boards, let alone the public, undermining breach notification rules like the SEC's four-day requirement. She critiques the cybersecurity vendor ecosystem for treating decision-makers like targets, using aggressive badge-scanning tactics that mirror phishing campaigns. Rock highlights the false economy of point solutions: EDR (endpoint detection and response) is just antivirus on steroids and misses 30% of breaches that originate internally. She advocates for transparent, affordable, full-stack SIEM solutions like Siemonster to democratize security beyond large enterprises bound by regulation. The episode unpacks why budget constraints force dangerous trade-offs, how marketing dollars - not merit - determine which tools land on corporate radar, and what authentic vendor communication looks like.
Hackers deliberately target organizations without breach history because they know these organizations likely have weak security postures and aren't prepared. Organizations that have already been breached typically invest in stronger defenses, making them less attractive targets.
30% of breaches across all industries originate internally. EDR systems won't detect insider threats because they function like guard dogs that don't bark at people they know - making internal breaches invisible to EDR-only defenses.
CISOs face intense internal pressure and job security risks when reporting vulnerabilities, even internally. Des Rock describes being asked to create two reports - one truthful, one board-friendly - and witnessed a CISO lose their job after a discovered vulnerability was reported, creating a culture where disclosure is suppressed.
Vendors aggressively collect attendee information at conferences, bombard decision-makers with unsolicited contact, and use high-pressure sales tactics on security professionals - the same psychological manipulation tactics that phishing campaigns employ.
EDR is antivirus on steroids that alerts when attackers attempt entry. A full SIEM system collects and correlates all data, allowing forensic investigation after breaches and detecting internal threats EDR cannot see. EDR is like removing security cameras and keeping only a guard dog at the door.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuinely non-obvious ideas - hackers deliberately targeting companies that have never been breached, the two-report system that suppresses internal disclosure, and the dog/EDR analogy to illustrate why 30% internal breaches go undetected - but they are spread thin across 34 minutes of casual chat, dinner-party anecdotes, and surface-level observations about AI and regulation.
Who hasn't been breached? I already know the chances of them having a very strong security posture is low. They're the ones I'm targeting.
30% of all breaches across all industries happen internally. So that means that the dog will not bark at somebody it knows.
The framing of unbereached companies as hacker honeypots and the observation that neurotypicals - not neurodiverse people - struggle most with remote discipline are genuinely counterintuitive; however, the AI-cuts-both-ways point, the 'regulation is behind' take, and the Scully effect (a well-documented existing concept) are recycled territory.
I will tell you that the neuronormals are the ones having a hard time being disciplined enough to work at home
I used to think hire more women, now I think represent more women in media
Des Rock is a genuine dual-sided practitioner - founder of a pen testing firm that pivoted into a commercial SIEM product - which gives her real operational credibility; she is not a career podcast guest or pure thought-leader, though her scale and name recognition are modest.
We were running all 24, seven and mimicking normal hackers. So there wasn't an area in which we couldn't get in
I've walked into a building with two coffee cups in my hand, knowing that I can infiltrate the...through, you know, the um, proximity, uh, cards
A small set of concrete numbers appears - 11% women in cyber leadership, 22%/15% autism employment rates, the 30% internal-breach statistic, Splunk named as the sole competitor at entry - but sourcing is absent throughout, no dollar figures or client names are given, and most claims remain at the level of anecdote or assertion.
30% of all breaches across all industries happen internally
only 22% of adults with autism are in full time work. And in the US that proportion drops to 15%
The hosts set up reasonable topic pivots and have done some background research with statistics, but every guest claim is met with agreement or praise ('I love that,' 'that's mad'), no figures are challenged for sourcing, and the closing three questions are generic boilerplate that produces little additional substance.
I love that
how would you introduce yourself to someone at a dinner party?
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of Phishy Business, we talk about the improper mindset of not thinking about security until after you have been breached, and some of the major problems this can cause. We do this through the lens of SIEM, ethical hacking, and a focus on the need for leadership in teaching organizations how to be secure. We also discuss how some IT leaders try to keep the results of pen testing quiet. Our special guest is Dez Rock, CEO of SIEMonster. After dropping out of law school, Dez became an entrepreneur and has run businesses for the last 20 years. Dez has spent a good deal of time in ethical hacking, building great experiences and great stories over the years with both physical and virtual security. She also has plenty of great insights about being a female CEO with ADHD in the cybersecurity industry. In ‘Exposing Shortcomings in Cybersecurity Leadership and why we need more Dana Scullys’, we discuss: What made Dez and her team successful as ethical hackers and how this helped make their product better. How there needs to be more transparency about cybercrime, not only between organizations, but within them as well.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Too, uh, many organizations will sit around the board and say, well, we've never been breached before, so why do I have to spend money on this? Now that's the mindset. You become low hanging fruit for hackers. Because I'll tell you how we think. We think. Well, who hasn't been breached? I already know the chances of them having a very strong security posture is low. They're the ones I'm targeting. I'm not targeting the ones that have already been breached. Much like if you have a home invasion, the very first thing you do is change the law.
Speaker B: Hello and welcome to Fishy Fitness Business, a series dedicated to exploring the lesser known side of cyber security. I'm Alice.
Speaker C: And I'm Brian and we're colleagues at mimecast. Every episode will be joined by a special visitor who is definitely not your average guest to share tales of risk, reward and sometimes ridiculousness.
Speaker B: We'll be looking for new ways to think about cyber security to learn how we can all improve in the fight to stay safe. So, Brian, ahead of this episode, I wanted to dig out a few stats to introduce our guest.
Speaker C: That sounds great. You know I love a good statistic.
Speaker B: Well, so firstly, I wanted to find out how many women were in leadership roles in cyber security. And while I found varying numbers from different studies, around 11% seemed to be about the average. And I was really surprised to see that only increased slightly to around 25% for all or positions in security.
Speaker C: It is shocking when you kind of find those statistics and you bump into them, but those definitely sound about right.
Speaker B: Absolutely. Yeah, I was really, really surprised. And I also then started looking into numbers for say, neurodiversity as well and found that in the UK specifically, only 22% of adults with autism are in full time work. And in the US that proportion drops to 15%.
Speaker C: As a parent of a, uh, neurodiverse child. Neurodiverse people usually excel in roles that require deep focus, quick thinking, and a strong ability to make decisions under pressure. So let's be honest, the cyber security industry is often perfect for that.
Speaker B: Absolutely. I couldn't agree more. And this is why I think today's episode will be a fascinating discussion. Our guest is Des Rock, who is female CEO with ADHD with lots of opinions on neurodiversity, being a woman in tech, and plenty of other interesting things.
Speaker A: Hi, thanks for having me.
Speaker C: Good to have you on. Um, can I just introduce a couple of other facts about you after dropping out of law school? Probably a good decision. Uh, certainly. I would think so anyway, is decided to become an entrepreneur and has run businesses, uh, for the last 20 years. She's now the CEO of a business called. I hope I pronounced this right. Seam monster. I guess this sort of falls into the category of, uh, Ciso. Siso. Ciso. Um, which is a SIEM solution. So. Welcome, Des.
Speaker A: Okay, now I can say it. Hi. Thanks for having me. I'm so happy to be here. Clearly a little too eager there. Um, yeah. That was a wonderful introduction. Thanks, guys. I appreciate that.
Speaker B: Thank you so much, Des. And we're so excited to have you with us today. So we always like to maybe start by simplifying things a little. And we'd love to ask you how. How would you introduce yourself to someone at a dinner party?
Speaker A: That's a really good question, because I don't necessarily go to dinner. Who does go? So this is theoretical, right? Because I've not been invited to a dinner party where they didn't know who I was. Was. Before I walked in the door, but just say I did. Actually, I probably make up something completely different. And role play is that. Is that.
Speaker B: I love that.
Speaker A: I would. It would be a lovely holiday from what I am and what I do. You know, I would, uh. And I have done that, by the way, in the past. Not at a dinner party, but when a doctor had asked. Asked my occupation before they saw my son. And, um, and I thought, how on earth does that make a difference? So, um, I. Do you want to know what I put?
Speaker B: Oh, please.
Speaker A: Oh, I put pole dancer. I really did love it. Oh, my God. That's the best answer. Uh, because I thought, money is money. What do you care how I make my money? And by the way, that speaks to, you know, the hacker in us, right? What is this data gathering that you're doing? And what's the nefarious purpose? Like, why do you care? Anyway, so back. The, uh, dinner party. Yeah, I'd probably. Probably, uh, be mischievous and play. Yeah.
Speaker B: Fantastic. I love that. So if we're maybe to look into your career to date, would you be able to give us a quick overview of your career and how you got to where you are today?
Speaker A: Oh, okay. So it's very eclectic, which is kind of signature, um, move for anyone with, uh, adhd. And it's been a bit of this and a bit of that, and. But there has been a theme all the way through, and, um, that is, uh, leadership all the way through. So I always find myself in leadership positions. Um, and the skill set seems to be the same. Um, so I'M being vague there, but the skill sets always been find a problem, examine the problem, master the problem, fix the problem, move on.
Speaker C: And before you started your current company, Siemonster, you ran a penetration testing company. Could you kind of tell us how you landed up in the ethical hacking space?
Speaker A: So, you know, being pen testers, you are. It was a wonderful time because, uh, we were differing from the auditing companies who were doing checkbox, uh, tests and things like that. If you know anything about penetration testing, they usually run from nine to five. And we were running all 24, seven and mimicking normal hackers. So there wasn't an area in which we couldn't get in, which was fascinating. We pivoted to seamonster being basically red team, blue team. So red team is obviously, uh, um, offense, and blue, uh, to me is defense. We switched to defense or a, uh, solution because one of our clients actually asked for a solution. And we went and had a look at the market, and the only thing at the time that was available was Splunk. And I'm not sure if. I'm sure all of your listeners would be very familiar with Splunk. And so hence we entered the market. Yeah.
Speaker C: And maybe if you could just, I mean, obviously the timing and not kind of following the guys in the suits and ties type approach to penetration testing. Yeah. Um, why were you so successful in that space? And you know, how much of that could translate into to what you did with Sequencer?
Speaker A: We didn't clock on at 9 to 5. We didn't work Monday to Friday. We didn't take public holidays off. In fact, we knew that the weaknesses of any company would be during the holidays, on a Sunday when no one's on shift. And so we would exploit that, which is exactly what you would expect hackers to do. They do not clock off, um, and take, you know, public holidays often, the rest of it. And, um, we were adept at social, uh, engineering as well. So we were very good at studying our target and finding weaknesses there as well. So, um, and by the way, when we first started, that's literally how we, um, we gained customers. We would say, look, we know you're using so and so for your, you know, penetration testing. Um, but here, let us do it. And if we can get in, if you're safe, that's fantastic. You get a second look for free. If we get in, we'll let you know, and that's the only. And then you can pay us. And, uh, we gained a lot of business that way because we always got
Speaker B: in I love that and I think that's absolutely fascinating. Do you have any stories that you can share with us of organizations that you've been able to infiltrate?
Speaker A: So there was one that was a, ah, an adult video company.
Speaker C: Right.
Speaker B: Okay.
Speaker A: And um, they. And um, that was an interesting, uh, client for sure. But they were asking for auditions in the form of. I can't remember what the form was. It might have been cd. I can't remember whatever the form was. But immediately we saw that and we sent them in a Trojan and um, and got in that way. So. Yeah. And they obviously shared that around and. Because we knew because of how many, uh, desktops it hit and uh, we were in. Yeah. Wow.
Speaker B: Well, I can imagine it wasn't that easy, but you make it sound much easier than it must have been.
Speaker A: There are times where I've walked into a building with two coffee cups in my hand, knowing that I can infiltrate the. Through, you know, the um, proximity, uh, cards that we have that will secure, uh, you down. So nobody. Well, I'll just walk in with two. It's just confidence. It's a, that's what con is short for. Obviously. It's a, it's a confidence act. So walk in and then be able to plant something within their network, physically plant something within their network, and then just walk out again. I've done that as well. Yeah, your average pen tester doesn't go to that length, which is why we always got in, because there's always a weakness. Always. We were putting, uh, our passwords on sticky notes on our monitors up. I mean, I guarantee you there's people still doing that or I wouldn't be surprised. Yeah. Or their 1Password, master password on their sticky note and still thinking they're secure. Or they might, you know what I mean? That's still happening now. So it's a very human thing to think. It won't happen to me.
Speaker B: Yeah, absolutely. And you mentioned there earlier as well, around kind of red team and blue team, from your past experience, how would you say you've maybe used your red team skills in your current organization?
Speaker A: Oh, absolutely. When you build a defense software, all you're doing is just building the very basics, the scaffolding of. Here's what it does, you know, because a SIEM is basically a data collection log that will uh, enrich all of that data for people to be able to correlate and see where their threats coming from. Now, um, on the surface, anyone can do. Any developer can do that. But if you have got a background in penetration Testing and hacking. You know exactly how you would hack. So then I can counter that. Does that make sense? Like there's no one. It's kind of like asking for um, burglars to secure your home with a security system. They know how they get in, so they know what to, how to protect you. And that's one, that's what gives us the edge.
Speaker C: I mean that's quite a good kind of segue to this concept of organizations just not knowing enough how to secure themselves. I mean do you feel that organizations would be more secure if there was kind of more transparency about the vulnerabilities that they had? If they could maybe learn from their peers and some of the strategies that they were using? Even though I actually saw something on LinkedIn recently which I thought was uh, quite amusing, is they use that sort of post game interview that they do with uh, football coaches and they pretended it was a CISO being kind of interviewed after a, you know, a data breach. But I actually think that's a great idea. What are your thoughts on that? Kind of very, very open. This is what happened. Just this is how we're going to fix it in future.
Speaker A: So look, being a CISO is a very, very difficult role, um, because it's your neck on the line and at the same time you don't have um, full length of being able to put all of the um, policies and implementations. You can sort of, let me put it to you this way. Most of the breaches that you're hearing about are the breaches that have gone public. Right? So for everyone that's gone public, I can assure you, and I already know that there are so many that never make it onto the news that have had ransomware, that have had this, that have been, have, they've kept it in house because um, simply because uh, the damage of the PR damage it would do. So now let's. You're touching on the reason why we don't openly talk about breaches. We don't openly talk about vulnerabilities because there are other aspects within the organization that throttle that. So it's very difficult for CISOs to be able to sit around and have a fireside chat and say, this is what I'm doing. That should be what happened. That is the spirit of what should be what happened. We should all collaborate, but it doesn't happen because we've got other things that um, are holding uh, that corporation at bay.
Speaker C: So what are your views on the. And there's various rules. If you look at GDPR or some of the other privacy laws that are around the world, um, they all have kind of breach notification clauses. And recently the, the securities and Exchange Commission has brought out kind of new rules around, uh, um, and, and most people are overhyping this somewhat, but it's still kind of a breach notification requirement after, you know, within four days of realizing a breach is material.
Speaker B: Right.
Speaker C: Do you think that's a good thing? Um, is it going to sort of force more disclosure?
Speaker A: Um, it's a step towards transparency and what you're going for. But let me tell you, even internally there would be blockages to breach notifications. For example, you know where you are talking about the war stories from when we were pen testers, we were asked to present two different reports. One, the actual report and two, a board ready report. Let's fix that first. Let's fix it so that internally they know what their, uh, vulnerabilities are. And in one in particular, when the vulnerability was discovered by us, and you're paying us to discover this vulnerability, it is not a public one. That CISO lost their job. And so there is a lot of pressure to be able to tap dance in that role. There's no freedom there to be able to do and successfully, um, you know, disclose even to their board, even to their CEO. So you're talking about to the public. I'm talking about even internally that's going on. Like I've, I've had to send reports to a, uh, Gmail, I've had to meet in cafes. Uh, we've worked all the way around the world and these are governments that will ask me to go into a walk into a cafe and have a chat. What they really want is the report, but they don't want it sent to their email just in case. So if you're dealing with that, you see what you're dealing with, what you're presenting. And here's what my reality has been. So it's very different. What you're saying is a token step towards the right direction, but we do have a while to go.
Speaker B: That's mad. And I know it's something that we've discussed quite a lot on the podcast with, you know, some of the CISOs, um, that we've had the privilege of speaking to, have been talking about sometimes that, ah, disconnect between say, the cyber security leaders and the board members. Why do you think, I guess it's so hard to find that common ground. And maybe second question, what do you think they can maybe do to help find that common ground?
Speaker A: So unfortunately, the Best conversion rate would be a hack. So people will finally take security seriously. Once it goes back to what we were saying about passwords, everyone thinks it's not going to happen. To me. Too many organizations will sit around the board and say, well, we've never been breached before, so why do I have to spend money on this? Now that's the mindset. You become low hanging fruit for hackers. Because I'll tell you how we think. We think, well, who hasn't been breached? I already know the chances of them having a very strong security posture is low. They're the ones I'm targeting. I'm not targeting the ones that are already been breached. Much like if you have a home invasion, the very first thing you do is change the locks. This is again part of hacking is human, uh, psychology. This is 101. You know what happens when someone gets hacked, right? So, and what they do, what that organization does, the ones that have not been hacked, they're primed for it. But it's interesting that some governments around the world are trying to put fines in place and things like that, which to me, I laugh at that because that's pretty much what an average ransomware would be, you know, so do you know what I mean? Like if you're paying one way or another, how about we just, you know, how do we take it seriously? Uh, this is a age old question, I suppose and I think it's much to do with the security space is so behind. Same with the law. Like our legal system is not coping with our privacy laws, with our security laws, cyber laws and all that sort of stuff. We're playing catch up. Um, we're also playing catch up in a corporate world too.
Speaker C: And what advice would you give to marketers to say cybersecurity vendors? I mean there's a, there's quite a big kind of trend at the moment where everybody's complaining about IT vendors in, you know, in general, cybersecurity vendors in particular, that sort of almost being better sort of phishing.
Speaker A: Exactly.
Speaker C: Bamas than anybody else and all of those kind of.
Speaker A: Exactly. Because you've got, uh, look, look, I know the decision makers in the IT space. Hi guys, how are you doing? Um, I think that they are extremely tired of being sold to most conferences. You're basically walking and you know the scan your badge and you're holding your badge very carefully so no one scans it because you don't want to be bombarded. It is extremely fatiguing and tiring. All you wanted to do was check what's out there and learn what's out there. And you're being bombarded simply because the people behind those booths, uh, one thing and one thing only, get as much detail as they can. And by the way you're talking to security people and you're going about it in the most insecure way possible, it is a juxtaposition that you're putting people in. All I know is how I cut through that and I try to be as transparent as possible and as honest as possible. For example, some of the, I mean we do seem right. So we, I walked into that space thinking, well no, I'm actually going to be a little bit more transparent here that I'm going to tell you what the bottom line is. No more surprise bills, there's no more oops data, there's no more of this. It is what you, you know, it is what it is. Now, will that be successful for me in the long run? You're going to have to circle back and ask me again in a few years time, but I think that there is way too much hype, noise, rubbish out there. Um, and so the way to stand out, and this is, I guess what I'm employing at the minute is to be authentic.
Speaker B: Absolutely. And I think in terms of that point on accessibility as well. And unfortunately, I think it's often the smaller organizations as well that really need that support, especially if they are uh, growing and want to become larger organizations. What do you feel needs to be done to make cyber security something that everyone can have hopefully equal access to and that everyone is able to prioritize.
Speaker A: So you're hitting the core of the very reason we're here. I mean one of the reasons we entered this space is to democratize security, to make it affordable. So it wasn't just the big guys in town who could afford the locks on the door because up until now it's the people who were uh, compelled for security. The people who had uh, uh, legislation against them and regulations against them that had to secure. Right. So if you're handling credit cards and you've got GDPR and all that sort of stuff and all of this, you know, you are compelled to do this. Well, that's no longer the case. Hospitals are being targeted because they're a huge data source of personal data that can be used against them. For example, universities are the same. There are other sectors that are not necessarily moneymakers, like the finances, the banks and insurance companies that are rolling in it, but they are also requiring security. Now banking, the, the way in which um, my competitors will price is to gouge. It's basically to say, I know, I know you need this because of legislation and I know this is what the budget that you can open up. That's fantastic for the banking sector, not so good for say for example the university sector.
Speaker C: So when it comes to security budgets, you know, a lot of organizations, particularly the smaller ones, buy point solutions that solve a single problem. Not ah, really giving much thought to how the entire ecosystem could work together.
Speaker A: You're right that we have increased uh, awareness of EDR products, uh, out there. Um, and let me, and, and so, and that's the latest, and I gotta tell you, the marketing machine behind the EDR solutions. So the base uh, is fantastic. EDR is just antivirus on steroids. And that's all it is. Let me put it back to base, right? So remember the days when you used to have video cameras in your, you know, in your organization, stuff like that. And you can monitor and keep up to like a month's worth of. And if something happens, you could see it. It's like saying, forget that. All I want to know is who's coming in. So that's edr, right? So who's, who's attempting, what hacker is attempting to come in? So that's basically rip out all of that monitoring service and put a guard dog and he'll bark when someone's at the door. That's the best analogy I can give you. The issue with that is there's two issues with that. If your CFO comes to you and says, hey, we've had a breach that's happened a week ago, all you're going to do is go back a week ago and ask your system, did the dog bark a week ago? On and on, right? That's number one. Number two. Number two, 30%. And this is a statistic that blew me away. 30% of all breaches across all industries happen internally. So that means that the dog will not bark. And this is the analogy I'm going with. The dog will not bark at somebody it knows. So if it's an internal job, you are going to get no alerts from your system at all. So you are not safe with a plain old EDR system. The reason why you're dismissing a full system is because of price. And it goes back to what I was saying before. Um, that's it. You know, any system should be a full coverage of all the data you're having. And, and our organizations, I see this a lot, they pick and choose the data that they want to uh, secure down. So they'll say we'll monitor this but not this. Now remember, that's a hacker's dream right there.
Speaker C: And I think that's part of the problem is a budget. You're dealing with the cfo. So we sort of, the CFO is generally sort of running counter to the old security adage of defense in depth, which most financial people see as duplication, which isn't. It's a series of controls that if one fails, you know, you'll hopefully the second or the third one will catch it. But we're seeing more and more that people are trying to delay this, uh, defense in depth. Um, would you agree with that? Is or are there ways of actually making things financially viable and achieving the same outcome?
Speaker A: Well, you know, the one lesson I want to give, and it touches back on marketing, is, is that the products that your organization is considering are uh, usually the products on your radar because the marketing team or the budgets of those organizations are large enough to bring them onto your radar. So no, they do. That does not equate to being technically savvy, the best out there, or the cheapest or most affordable. Right. It's just because remember those who are starting out, those who have got a product, they're not going to be on your radar until they get the marketing dollars in order to be there. You know, the advertising dollars to be on your radar. Or if you Google uh, so and so product versus so and so product, all of those articles are written by said product and put up there as a marketing tactic.
Speaker B: If we delve also into the accessibility piece from say, access to the market for say neurodivergent applicants. I have a nephew for example, he has Asperger's. I was just absolutely horrified that you know the statistics. Around 22% of UK, um, autistic people in full time employment. What challenges do you think are there and what do you think say the cybersecurity space in particular can do to overcome that?
Speaker A: First off, I think those statistics, I question those statistics because anecdotally I would say that within it, neurodiversity is a lot higher than that. Uh, especially with coders, especially with especially insecurity as well. I think that what's holding that statistic back is, um, shame. We do not admit that we are diverse. We don't or we're undiagnosed because it's very, very new in diagnosing. So there's a lot of behaviors that you will know of. Your old, your uncle, your older, this Older, you know, and when you look back and you go, they were probably diverse and never diagnosed. Does that make sense? So the coupling of the no diagnosis and that's okay. It's nothing changes when you're diagnosed, by the way, other than knowing, um, as well as, um, acceptance. And so there's a lot of people I know personally who have neurodiversity and will not publicly say it because of the stigma and shame. So those are the two things that are holding back that particular statistic. But anecdotally, I'll tell you, it's a lot higher.
Speaker B: Absolutely. And I think I completely agree. I know, um, or I knew of somebody who was working for a large governmental organization, and as you say, they had a lot of, um, or I think the majority of their team of, say, coders, et cetera, internally were on the spectrum and absolutely phenomenal at their jobs. You know, you couldn't pick better people to be able to take on those roles.
Speaker A: Let me just, Let me just. We're talking as if, like, they're special people or. I tend to think of them as like the X Men, right? They're. Neurodiversity is nothing but a brain that's wired differently. That's it. And up until, uh, relatively new, so the Industrial revolution and, you know, of our modern history, this was never a problem. We were the ones when it was go time. It was us on the front lines because we could think faster and do things in a different pace, whereas the. No, uh, so, you know, other people would be like, oh, we do not know what to do when it comes to immediate change. ADHD people are the ones you want on the front line. We're the ones who can handle that pressure. So what I'm saying is there was no diagnosis back then. There were definitely people who were wired differently and had different functionalities in our society, in our community. It is now that we've told people to sit down, shut up and go to school and pay attention and all of those restrictions that all of a sudden these, um, traits or the, you know, the way we're wired is now a problem. Oh, you must be able to communicate with everybody. You must make ey contract. You must do this. You must. All of these social rules that we've put in place, uh, a social construct that we've invented. And so that's what's causing. All of a sudden there's a difference. And let me tell you, we need that. We definitely need a variety of all sorts.
Speaker C: So something else you've spoken about and I think it links directly to this is you've always been quite outspoken about having a remote team and how this environment allows everyone to thrive. Um, but there's obviously a challenge because particularly CEOs and sort of more senior management kind of seem to always lean more into getting people back into the office. What is your advice to organizations who just can't seem to get this remote model working correctly?
Speaker A: I think that leans onto what the discussion we're talking about. Most of my team are diverse and most of my team work very, very well and in completing their jobs without management over their head saying, you need to find the discipline to do this, if I was going to turn the tables, I will tell you that the neuronormals are the ones having a hard time being disciplined enough to work at home and require some sort of structure, uh, in which they toddle off to work in their new environment and have water cooler chats and all of this sort of stuff, whereas most of the neurodiverse people will be like, please leave me alone to do my work. I'll get a lot more done this way. We've been a tech team for so long that working remote has worked definitely well for us. But as we increase, I can certainly see staff that require. Isn't it funny that you need to employ staff that have skills and yet you still need to manage them to remind them how to do their job? Um, and so then you're thinking, how do I do that from a distance? Oh, I need to stand over their shoulder and make sure they're doing their job. Because that's ostensibly what it is coming into work is making sure that they're not stuffing around on social media. Right. Um, or, or as I heard recently, some guy who had software on his laptops when they were remote working a clicker so it would move the mouse once in a while so they could pretend that they were online. But if you have that mindset, if you're having to force somebody to do their job, I think you're going to find the same no matter what. It's just that working remotely is making it easier for people to take the easy road.
Speaker B: And so DES maybe to also looking at say, gender diversity as well, for example, would you be able to share with us your experiences as a female CEO in what could be classified as quite a male dominant industry?
Speaker A: It's an interesting ride. Um, I've been in the same space for how many years now and the CEO and founder of a seam company and yet I will have uh, uh, a Man, explain to me what a seam is on LinkedIn. Do you know? There's not. But. So. Oh, wow. I. I'm trying. I'm hit. I really am reining it in this week. We could do it. I could do a TikTok on this alone. Um, on. On that, you know, the feelings that that evokes. Uh, and I can't say feelings because that's a weakness when you're a woman. Um, but you know, the issues that that evokes. So, look, it's a challenge, but I will flip that on its side and tell you that any person of any minority, by the way, who is in a field that is not necessarily there, you can be assured that they've worked twice as hard to get there. Right. Because I cannot walk into a room ever and tell people I am a professional at this industry and be taken seriously. If I was a man and I said, hey, I'm a securities professional and I've been doing that, no one would even question my credentials. Uh, I have to speak for at least a half an hour, an hour before people will assume that, oh, yes, she does know what she's talking about. So I'm constantly having to prove my knowledge before I'm accepted everywhere I go. And that does depend on even what I'm wearing. If I'm too casually dressed, that will affect it. If I've got makeup on, that'll affect it. If I'm. How I wear my hair, that'll affect it. Uh, we live in a world where we're judged by the way we look. And, uh, so that's answering all your questions of what it's like being a woman in a male dominated sector. I don't think it matters what the sector is. That's what it's like.
Speaker B: And what do you think can maybe be done to help support women to progress into these roles?
Speaker A: Does anyone? Do you guys were X Files fans back in the day with, uh, what were the names of the characters that
Speaker C: would be giving away my age?
Speaker A: Right. So Scully and Mulda. Uh, that's right. So when that show aired, the fact that they were seeing a woman on TV in a stem role, like science role. Right. So it was forensic increased the intake of women in that area and they called that the Scully effect. So, uh, I actually think I've changed my view on this. I used to think hire more women, now I think represent more women in media, which is where we get out, you know, where if we can see it, we can be it. So we need more women being portrayed in roles in a really cool way, in a very marketably cool way, in roles of the areas in which we would like more women in, rather than pushing, uh, employers and forcing them to be able to, like, hire more women. I think it's far more successful, um, to inspire women to go into these roles.
Speaker C: So, Des, time has absolutely flown. Thank, um, you so much for taking the time to speak with us today. Um, there's so many other questions I'd love to ask you, but we always like to end our episodes by asking our guests three simple questions.
Speaker B: So, Des, maybe looking back over your career first, what would be the one insight you'd wish you'd learned sooner? Or that you could go back and
Speaker A: tell your younger self, this too shall pass if something is worrying you. This too shall if some. If you're super excited and super happy and it's the best day of your life. That too shall pass. I've sweated the small stuff and the big stuff unnecessarily. Um, I think that share said it once, like, it's a. She calls it the five year problem. Will this be an issue for me in five years? Am I be thinking, will I be thinking of this in five? And if the answer is no, it really goes down on. Lowers down on my catastrophe scale? Yeah, I love that.
Speaker B: Thank you.
Speaker C: And is there anything that you're listening to or reading at the moment that you'd recommend?
Speaker A: The best podcast I can recommend is called the Hidden Brain, um, and it's a study on human behavior and psychology. And I really think that affects every aspect of business in life and your personal life and everything like that. It's brilliant, uh, brilliant knowledge in small format and digestible format. That's what I'm listening, uh, to. And will, um, and will follow.
Speaker B: Oh, fantastic. Thank you. And so maybe looking into the future, this time next year, say, where do you think we'll be in the world of cyber security and what trends do you think we might be spotting?
Speaker A: Uh, well, I'd be remiss, not to mention AI, because apparently that's. I've got to jump on that bandwagon. So. But I. The only thing about AI is, and I know there's a rush for everybody to include AI in there, I, I tread a lot more carefully because I know that whatever tools, uh, are out there for defense are also out there for hackers to use. Like, if we honestly think we're going to implement tools to make it easy, you know, our job's more easier, we're automating it. You are, ah, remiss if you think that hackers are not going to use the exact same tools to make their jobs more easier. As a counterpart, uh, the War Store is open for both sides, um, and the future of cybersecurity. I actually think that regulation will see more regulation around the world where we, uh, companies are made to, um, have a better security posture because they are holding people's data. And I see increase, um, of that because companies on their own, left to their own subject, um, to hold and secure people's data, don't have the motive because there's no money in securing people's data.
Speaker C: Finally, is there anything we haven't covered that you'd like to add where our guests can find out more about you?
Speaker A: Uh, if you're interested in hearing anything that I've said or wanted to have a chat to me, for sure. Like why, you know, here's somebody who's in the industry and doing something differently. I'm on LinkedIn under des Rock Dez, uh, the platform formerly known as Twitter, and my handle there is Des Traction. D, E, Z. Traction, yeah.
Speaker C: Good name.
Speaker B: M. Yeah, absolutely. Well, fantastic. Thank you so much, dez, for joining us today. It's been a wonderful discussion. And thank you also to all of our listeners for joining us on this week's fishy business. It's been a pleasure to have you with us. If you have enjoyed our podcast today, please do leave us a review on Spotify, itunes or wherever you're hearing this. And feel free to follow us on our Mimecast LinkedIn page if you'd like to learn more about what we discussed. Until next time.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.