Security Weekly Podcast Network · 2026-06-24 · 1h 1m
Key moments - from our scoring
Substance score
48 / 100
Five dimensions, 20 points each
Robert Siciliano, architect of the strategic human firewall at ProtectNow, challenges the fundamental approach to corporate security training. After two decades of phishing simulations and annual compliance-focused courses, he argues traditional security awareness has failed because it treats human behavior as a checkbox rather than engaging employees where they actually are. The episode explores why generic, compliance-driven training doesn't change behavior: employees don't care about security risks they perceive as irrelevant to their personal lives, and organizations bombard them with rules that trigger security aversion instead of appreciation. Siciliano's strategic human firewall shifts from awareness (knowing facts) to appreciation (caring enough to act), grounded in personal security relevance. He illustrates this through dialogue-based engagement - questioning assumptions about home security systems, paranoia versus risk management, and oxygen mask principles - showing how conversations unlock genuine behavior change. The discussion covers scaling this approach across large enterprises, the kitchen table effect where employees teach family members, and how to build organizational culture around security as a positive enabler rather than a burden. Relevant for CISOs, security leaders, and HR teams struggling with persistent human-centric risk despite significant training investments.
Traditional training treats security as a compliance checkbox delivered through one-off annual courses focused only on phishing, missing the complete risk picture. Employees don't care about security because it's presented as irrelevant to their personal lives, and compliance-driven approaches trigger security aversion rather than genuine behavior change.
Security awareness is intellectual knowledge (neck up) about security risks, while security appreciation is emotional commitment (from the heart) that makes people actually care. Appreciation happens when employees understand how security protects their own personal lives and identities, which then drives permanent behavior change.
It uses dialogue and engagement to help employees develop situational awareness and critical thinking, turning them into proactive participants who verify information rather than defaulting to trust. This transforms security from a fear-based compliance exercise into a mindset of managing risk.
The kitchen table effect is when successful security training results in employees going home and teaching the concepts to their families, cementing the lessons for life and creating a multiplier effect that traditional phishing simulation training cannot achieve.
Siciliano demonstrated scaling through hybrid events - speaking to 400 people in person while broadcasting live to 5,000 worldwide via Zoom, with real-time Q&A. Employees often ask identical questions and have the same concerns, so answering one person's question in a dialogue format addresses many participants simultaneously.
Our reviewer’s read on each dimension, with quotes from the episode.
The interview contains a handful of genuinely interesting angles - the biological trust default, the loneliness loophole, and reframing paranoia as the enemy of security adoption - but these are surrounded by lengthy anecdotes about audience reactions and the panel segment is almost entirely surface-level commentary that adds nothing a practitioner couldn't have inferred themselves.
When they figured out the loneliness loophole. And the 25% of all humans wake up every day just feeling lonely. And like hunger pains, the pain and ache of loneliness, we will do almost anything to extinguish it.
that security appreciation gap is the chasm between an employee's intellectual understanding of risk...and the emotional commitment to act on that risk
The 'appreciation vs awareness' reframe and the paranoia-as-cultural-resistance argument are mildly fresh angles on a very tired topic, but the core thesis - that phishing simulation checkbox training doesn't change behavior and security must feel personal - has been circulating in the security awareness space for years; the panel segment recycles entirely standard takes.
We as a culture have a negative view as to what security is. We think it's a bad thing, truly a bad thing. Paranoia is a mental health dis ease...Security is about managing risk. It's about gaining a degree of control. It is the complete opposite of security.
it is truly what we call security appreciation. It is the shift from basic awareness, which in my mind...awareness is in your head. It's neck up, which is knowing, to appreciation, which truly is from your heart up, which is caring.
Siciliano brings genuine longevity - 30 years speaking on personal security to practitioners - but he is fundamentally a professional speaker and author rather than an operator who has built and measured enterprise security programs at scale; the panel members contribute casually without establishing meaningful practitioner credentials in the transcript.
I literally have been speaking to real estate agents for 30 plus years because realtors are murdered and they also handle personal and sensitive information. So I've been speaking to, uh, realtors about how to prevent being killed and how to protect their email since 1995.
I just spoke to a company that basically rolled out 5G. They create most of the chips in your cell phones. I've spoken an auditorium of probably a beautiful auditorium with probably 400 people that was broadcast to 5,000 people worldwide.
There are a handful of concrete statistics - Constella's 300 billion exposed records, the $124 trillion boomer wealth transfer, rough audience adoption rates for password managers - but most figures are asserted without sourcing, the claimed outcomes of Siciliano's own approach are anecdotal, and the panel discussion references breaches (Snowflake, Tesla/Apple) only in passing without substantive analysis.
Constella says 300 billion of our records have basically been exposed over the past couple of decades. You know, about 20 billion of those records are passwords.
there's $124 trillion transfer of wealth that's occurring right now between the baby boomers and their kids and their grandkids
The host asks a few functional follow-ups - notably 'How do you scale a dialogue across a large enterprise?' and 'How do you get it to stick?' - but never pushes back on any of Siciliano's unsubstantiated claims or asks for measured outcomes from his approach; the panel discussion is largely agreeable crosstalk with no productive tension.
Robert, can I ask you a question about that? How do you scale a dialogue across a large enterprise?
AI isn't solving cyber security workforce woes. Huh? You don't say.
Computed from the transcript - who did the talking, and the words that came up most.
The 2026 Verizon DBIR has arrived and the results are in... Even with a substantial increase in Exploitation of Vulnerabilities, All Credential Abuse is still the top initial access vector for breaches, which means the human is still the weakest link. Why haven't security awareness training and phishing campaigns worked? Robert Siciliano, Architect of of The Strategic Human Firewall™ at ProtectNow, joins Business Security Weekly to explore why humans, not hackers, are the ultimate deciding factor in organizational security. The industry needs to shift from security awareness to security appreciation. Robert will discuss: How you can build a culture that actually protects your people, your data, and your operations in an era of AI deception. Why most companies are still performing 'Security Theater' - checking boxes and hoping for the best - instead of driving genuine behavior change. How Trust and Denial quietly fuel most disasters, why interactive training is the only way to make the lessons stick, and how leaders can scale this entire framework without needing a Hollywood budget.
Transcribed and scored by The B2B Podcast Index.
Matt Alderman: This week we welcome Robert Siciliano, architect of the strategic human firewall at ProtectNow to discuss why we need to transition from security awareness to security appreciation. In the leadership and communications segment, should CEOs be held personally accountable for cyber attacks? Placing communication at the center of every leadership transition AI isn't solving cybersecurity workforce woes and more. Business Security Weekly starts now. It's the show where we explore the business of security to improve the security of business. Your trusted source for emerging risks, leadership and communication. Get ready for Business Security Weekly. Welcome to Business Security Weekly. This is episode number 453, recorded June 22, 2026. I am your host, Matt Alderman. I hope everyone had a great Father's Day weekend and I have a full crew today. First, Mr. Jason Elbaker.
Jason Elbaker: Let's go.
Matt Alderman: Father's Day.
Jason Elbaker: Thank you. Happy Father's Day. Yeah, it was a good day. Family, friends, kids, barbecue lobsters. Winning, right? All day long, that's winning. So, um, it's been a, uh, it's been a World cup summer for me. So my son and I went to our second game uh, last week and we got to see Norway play, which they're pretty amazing too. The Vikings in the stadium are, are pretty wild. They're loud, they like to row and they have a bunch of fun. So good stuff.
Matt Alderman: Kind of like the Scots the week before.
Jason Elbaker: Absolutely. They've been taking, I don't know if you see the news, but they're taking over everywhere they go.
Matt Alderman: Yes, they are. Also joining me this week, Mr. Ben Carr. Also happy Father's Day.
Ben Carr: Thank you very much, Matt. Happy Father's Day to you and everyone else. Um, yeah, happy to be here today. Looking forward to, uh, diving into it. It was a nice long weekend for me with bankers holiday on Friday there, so.
Matt Alderman: Yeah, yeah, I had one too. So got a nice three day weekend, was good. And last, definitely not least, Summer Fowler, your husband. Happy Father's Day.
Summer Fowler: Yes. Happy Father's Day to everybody. We had a good, we had a good weekend as well. Cookout with family and friends and now we're getting ready to head to Slovakia for the big international tournament for my son. So hopefully we'll be bringing back the gold.
Jason Elbaker: Nice.
Summer Fowler: Nice.
Matt Alderman: Really nice. All right, uh, one quick announcement then we'll get into it. Security leaders are being asked to cut risk control costs and prove roi all while threats continue to escalate. Soc teams are overwhelmed and throwing more tools at. The problem is not working at the AI for Next Gen SoC on June 24th. That's this week learn how to use AI to drive efficiency, reduce analyst burnout, and improve security outcomes without increasing spend. Security Weekly listeners can register for free by visiting securityweekly.com NextGenSoc and use the promo code CSS26SW. Robert Siciliano is a security analyst, bestselling author, and the architect of the strategic human firewall. Is one of the world's most recognizable educators in personal and corporate protection. He is a straight talk voice for a digital age. Robert, welcome to Business Security Weekly.
Robert Siciliano: So happy to be here. This is the, uh, big league. So very honored to be here. Thank you.
Matt Alderman: Ah, uh, thank you, thank you very much. I, I mean I've only been doing this eight years. Paul's been doing it, what, close to 20. So he's the big leagues. All right, we're going to talk about security awareness training. So let me, let me set the tone a little bit. We've been doing security awareness and training and fishing for 20 years. It hasn't worked. It's not working. I guess the big question to me is, why isn't it working?
Robert Siciliano: I think that, um, corporate America has essentially ruined security awareness training. Security awareness training was never meant to be what it is today. Um, it really has only been around like you said, you know, 15, 20 years, which is basically phishing simulation training. And that is the extent of it to a degree. Uh, it might be delivered annually during Cyber Security Awareness Month. What is that? October? October, sometimes via micro elearning and uh, hopefully at least you know, quarterly. Um, and that is just, you know, basically talking about one issue revolving around security, which is phishing. You know, is that security awareness phishing, like that one problem, and I don't know that, that it provides a complete picture. It doesn't even talk about the risks that the human faces on a regular basis. It just talks about a singular problem and it's kind of missing the point.
Matt Alderman: Zero trust is clearly the future as threats get faster, quieter and harder to detect. But implementing it shouldn't disrupt the business. Threat locker enforces default denied execution in a way that remains enterprise ready, scalable and operationally clean. Unknown software is stopped cold. Trusted apps stay contained and drift is locked down across the environment. It's zero trust that works in real enterprises and prepares you for the threats ahead. See why CISOs are adopting it@securityweekly.com ThreatLocker
Jason Elbaker: I was just going to say, is this a situation that, like in many organizations, we've fallen victim to insecurity. We treat it as a check in the box compliance requirement. It's A question that we get asked during vendor risk and we say, sure, we have this program, but it's very tactical. It's not, you know, it's transactional. It's not something that we really put the human into the, into the mix here. It's a check in the box and that's dangerous.
Robert Siciliano: It was accepted as a form of, you know, regulatory um, compliance training that um, you know, popped up like I said a couple decades ago. And essentially it bombards employees with complex and personal rules that trigger security aversion, plain and simple. And that compliance trap I think is a false sense of security felt by meeting those regulatory requirements while the actual human behavior remains unchanged and vulnerable.
Summer Fowler: You've. Go ahead, Matt.
Matt Alderman: I was going to say, so I spent some time trying to address this human risk problem which by itself is also not an EAS problem to solve for. And the way people thought they were going to do this, and I think this is part of the mistake and this is why I want to get into different ways to do this is we started trying to monitor behavior and then we're trying to use that to bombard them with micro learning now. Not big courses. No, no, no, no. Like 3045 minute, 45 second clips and try to teach them in the moment. It's still not working. It's super difficult. And we haven't changed any behavior.
Robert Siciliano: No, because people don't truly care about security for one. And uh, I'm happy to get into that. They don't care about security goes against our core beliefs. And uh, they especially don't care about security in the workplace because it ultimately isn't for them to begin with. We are a self interested or selfish creature by, by design, it's not necessarily a bad thing. And we're not actually speaking to the employee or the user as to how security affects them first. And as a result we're talking about, you know, an issue that ultimately isn't their problem to begin with. And so we've essentially put the cart before the horse. We're not talking to the employee where they're at. And uh, ultimately you know, we're selling metrics to the COO who says, okay, good, your metrics work continue, here's your budget. And that it really doesn't necessarily fix the issue of that employee and their behavior in regards to what risk actually is, not just at work, but you know, uh, in totality. So in the end nothing changes.
Ben Carr: Well, I also think if you give, if you get beyond, but let's say you got beyond the problem of it not mattering to them because they perceive it as a business issue, not a personal issue. Right. Um, and if you got beyond the regulatory issues, if we're just doing it as the check the box, we're also not, we have a problem with generics. We're not tuning it right to the specifics of the individual or their task or function or the security related to them. It's more of a generic assessment of, again, phishing or general email security or general, uh, how not to let people tailgate when you're coming in the office with a badge. But it's nothing to do with the difference between someone who's actually generating code versus the person who's actually generating financial statements versus the person who's ordering food for the cafeteria. Like, it's, it's not specific to the individual. And so when people look at it, they see no tie back to their own job or function or the relevance to their, their, uh, world as they see it. Right.
Robert Siciliano: Yeah. And in the end you're not actually, we're still not actually treating the actual issue of security. These bad things aren't gonna happen to me, that they only happen to other people. Like I said originally, we don't actually want to actually engage in security because we don't wanna think that bad things can happen to us. Lookit, humans are pro. We are beings that trust by default. And trust means that we want to and need to trust each other. I need to trust my wife, she needs to trust me. Man needs to trust woman, woman needs to trust man so that we can procreate. That is our default. That is how we come out of our mama. And so we go throughout our lives wanting and needing to trust each other fundamentally to procreate. Security means there are people out there that I should not trust that mean to hurt and harm me.
Ben Carr: Right.
Robert Siciliano: And we don't necessarily want to think that we are going to be hurt and harmed. So instead of actually acknowledging those risks, we instead say, you know what? I'm not going to worry about that. Those things, I'm not going to think about those things. They're not going to happen to me anyways. And we actually function in denial and in the end nothing gets solved. We put our head under the covers and we could just continue trusting. So when the phone rings, you get a text message or an email in your regular life, you want to believe that the person on the other end actually has good intentions. You don't want to think that bad things can happen to you. And none of that is Actually discussed in the existing security awareness training that's being offered in corporate America today. Therefore we're still experiencing what, 3,000 data breaches on average every year. And last stat I saw was like 75% of them have something to do with human error, which they click the link, download the file, agree over the phone and so forth. So what are we doing? We've put the cart before the horse. We're not talking to the human where they're at, and we're essentially shoving do this, don't do that down their throat or else they get fired. That doesn't work. So when I'm hired, they're hiring me because they're like, okay, we just want our people to care, just make them care. Like our metrics are good, but still we have problems. Why? Because you're not talking to the human where they're at. You're not engaging in even a degree of empathy. You're engaging in metrics and people don't respond well to that.
Summer Fowler: Robert, you talk about, um, that strategic human firewall and I think that's what you're getting to now in making, making people care. Um, can you tell a little bit more to the listeners what makes it strategic? What makes that human firewall strategic?
Robert Siciliano: So I would imagine, or I'm sure that everybody who's uh, on this call, um, today, uh, looks at every single phone call, email and text message and you're kind of dissecting it in real time, like what's going on here? What is this trying to accomplish? Your BS radar is up. You are already a strategic human firewall. But you don't just do that via, uh, phone calls, emails, text messages, pop ups and so forth. You're doing that when you're walking down the street. You're doing that while you're driving. You engage in situational awareness pretty much probably wherever you are, no matter what you're doing, you have head on the swivel, so to speak, looking to the right, looking to the left, knowing what's going on behind you, right? And when you're walking down the street, you see that in the concrete and the sidewalk, the tree, the roots have pushed up the concrete and you let your family know so they don't trip over it, right? You see that stuff? That is strategic human firewall. You're engaged in paying attention, right? Most people don't do that at all. When I say most, I'm talking like 90 plus percent of the world's population aren't truly paying attention. We've seen more pedestrian Deaths in the past decade. Because not only are the people actually looking at their phone as they're crossing the street, the drivers are doing the exact same thing. People aren't paying attention, they're getting killed as a result. And so strategic human firewall really is a proactive governance. It's a mindset that is designed to block deception. Right. It turns employees from passive targets into active detection layers. Like they're looking for it not because they're worried, not because they live in fear, not because they're paranoid, which is a big deal. And it's resistance to security, which I'm happy to talk about. It's the shift from I trust what I see by default to I, uh, verify everything. It goes way beyond zero trust, right. It is truly what we call security appreciation. It is the shift from basic awareness, which in my mind, from my perspective, awareness is in your head. It's neck up, which is knowing, to appreciation, which truly is from your heart up, which is caring. Right. It's basically when employees appreciate how security protects their own lives, behavior changes permanently. You know, how do I protect my own identity, how do I manage my own passwords, how do I protect my own money and bank account, how do I protect my kids digital footprint and so forth. We don't talk about any of that stuff. And the self interested, selfish aspect of humanity needs that first before they care about phishing simulation training to begin with. And as a result, right. That security appreciation gap is the chasm between an employee's intellectual understanding of risk, which they have a general understanding of it in the emotional commitment to act on that risk, or that knowledge, which is appreciation, truly, it makes them care, which ultimately achieves what I call the kitchen table effect, which basically is the multiplier effect, where successful training ends with the employee going home, teaching the concepts to their family, cementing those lessons for life. Try doing that with phishing simulation training. It just doesn't work.
Jason Elbaker: So, so Robert, how, how do you start to make that what I'll call depending on your culture? Right, because some cultures. Exactly the position you're talking about, how do you make that monumental shift of culture? Because it's going to take a lot, it's going to take a lot of stakeholders to be on board. Because the last thing you want to be doing is teaching this, um, philosophy and getting it, you know, put into your daily work activities. And then you look up and the C suite isn't doing it, the C suite's not supporting it. The C suite is giving a blessing to ignore the cybersecurity training because it's friction on the business. How do you combat that? Uh, that's a big lift to change, uh, an entire culture.
Robert Siciliano: Actually, it's really just a single decision. Yeah, let's do this. Look, when we. I'm a dad. Happy Father's Day. And, um, I have spent my past 17 years with my younger and 20 years with my older having a dialogue. And that dialogue often revolves around, you know, they come home upset, and I listen and I contribute based on my life experience. I try to shorten their learning curve by providing them with examples that I've seen work for me and others. And ultimately, you know, we hug. And, um, they move forward with a little bit more information that they can use to change their reaction or response to when that might happen again. And that dialogue truly is what, um, I find gets my children, um, happy and motivated in Dean's list and honor roll and balanced. Right? And so I, um, wouldn't call myself, like, this crazy parenting expert because I screw up here and there, but I know enough that I have adjusted kids, right? And I know that, like, current security awareness training is a monologue. It's being talked at. Whereas when I engage an audience, it's a conversation, it's a dialogue. I ask questions, they ask questions. I say, I ask questions, like qualifying questions, belief, challenging questions. How many of you have a home security system, which is like, a really simple question, and I might get, like 15% of the room to raise their hand. And the reason why I asked that question is because security starts in the home. Okay? All security fundamentally is personal security. Even at the highest levels of government, those that are responsible for protecting our critical infrastructures, it begins for them at home. If you truly believe in security, you're gonna do your job that much more effectively. Okay, so how many of you have a home security system? If I get 15% of the room to raise their hand, that's a lot. And then I start asking questions, okay, so why don't you have the home security system? And the answers begin to, you know, come like they raise their hand, okay, we don't have a home security system because we have insurance. As if insurance is going to protect you at 3am so right there you can see how not well thought out they are. And then the next answer is, oh, we don't have a home security system. Because my husband says, if they're going to break in, they're going to break in. There's not much we can do to prevent it. And my response to her is, yeah, you should divorce that guy because he's engaged in fatalism, because he doesn't truly believe in security to protect his family. She doesn't laugh, but the rest of the room does. And then the next most common answer, which is the most telling answer, is, well, we don't have a home security system because I don't want to live like that. And I say, what does that actually mean? And she says, well, I don't want to live in fear. I don't want to have to worry. And I said, well, okay, so I'm a guy that actually has 20 plus security cameras. And so what might you think about my disposition, my belief systems? Like, I wake up every day with 20 security cameras. Maybe a little excessive, but I got a decent sized property. Maybe a little excessive, but what might that say about me? What do you think they say immediately, he must be what?
Matt Alderman: Paranoid.
Robert Siciliano: Yeah. And she says, exactly, I don't want to be paranoid. Which is so telling because most employees think that their CISO is paranoid. He or she is making me do this because they're paranoid. We as a culture have a negative view as to what security is. We think it's a bad thing, truly a bad thing. Paranoia is a mental health dis ease. People who suffer and truly suffer from that are essentially out of control. Security is about managing risk. It's about gaining a degree of control. It is the complete opposite of security. So when you begin to explain this to a live audience in a dialogue, they're like, whoa, I never really thought about security like that.
Summer Fowler: Huh, huh.
Robert Siciliano: That's interesting to me. I'm interested to hear what you say. So now, when I'm hired, initially, I walk in the room, they introduce me, the entire audience is looking at me with a scowl in their face. Okay, security guy, tell me what I already know, please. Now let's get this over with. Right? Arms crossed, the whole thing. And as I engage them in this dialogue, you know what happens? The hands go down by their side. Their eyes begin to wide open a little because now they're curious. The scowl goes away from their face, and as the arms go down, the hands begin to go up. You know why? Because they got questions, and they've had questions for their entire adult lives that they could have asked the ciso, but they never did because the CISO was inaccessible. Right? And those questions revolve around things like, how do I know what links are okay to click when I do? Ah, a Google search, which is like the most basic question you can possibly think of. But they all Ask it because they want to know, because no one's ever actually provided them the answer, because they've never had an opportunity to ask the question ever. Because there's never been a dialogue regarding security awareness ever in their lives, both personally and professionally. So the answer to your question is a dialogue is how you get buy in, is how you begin this process. And everybody who's in the room, including the stakeholders, are now like, huh, huh. So that's how this is done. That's how you actually engage in security awareness, which actually truly is security appreciation. Security is a good thing. So I ask you guys a question really quick. When you're on the airplane and the flight attendant is providing instructions in regards to the oxygen mask, what does she say? When the oxygen mask comes down, what do you do first?
Matt Alderman: Pull it down to start the flow of oxygen.
Robert Siciliano: And then what?
Summer Fowler: Put it on yourself.
Matt Alderman: Then you put it on yourself?
Robert Siciliano: Yes. And why is that?
Summer Fowler: Because you don't want to pass out?
Robert Siciliano: Well, so that you can actually take care of others.
Matt Alderman: Take care of others?
Robert Siciliano: Yeah. I mean, that's truly, like, ultimately the end game there, right? Like, you're with your kids and such, so, yeah, you would think put them on your kids first, but, like, what good are you if you're passed out now? You've got two breathing kids screaming, taking off their mask now because they don't know what to do. The point is we need to train the human where they're at, engage them. What security is risk management versus what it isn't paranoia.
Summer Fowler: Robert, can I ask you a question about that? How do you scale a dialogue across a large enterprise?
Robert Siciliano: I just spoke to a company that basically rolled out 5G. They create most of the chips in your cell phones. I've spoken an auditorium of probably a beautiful auditorium with probably 400 people that was broadcast to 5,000 people worldwide. And I was answering questions from people overseas via Zoom, you know, and I'm answering questions in front of 400 people to 5,000 people. And it's interesting because when somebody asks a question and I say, yes, sir, you had a question. And he asked the question. And then, like, you know, 10 seats down, a woman had her, uh, hand up earlier. Yeah, you had a question? Oh, he just asked it for me. Because they all have the same questions. They all have the same concerns. Everybody does. And to this day, nobody, with the exception of me, truly is answering those questions, because I don't know that anybody who's a CISO has the background that I do. My background is personal security. Like, I Literally have been speaking to real estate agents for 30 plus years because realtors are murdered and they also handle personal and sensitive information. So I've been speaking to, uh, realtors about how to prevent being killed and how to protect their email since 1995. So that perspective. All security is personal, truly is. It begins violence. And theft prevention is personal security. Theft prevention is personal security. Stealing your identity is personal security, even though it's digital. It begins with the human in their personal security, in their want, in their need, in their recognizing of risk, which they don't truly understand because they're not being trained to do so.
Matt Alderman: So Robert, you, you talk to a group, you have this dialogue. To me, that's the starting point to get them to start to understand. But then how do you continue this? Do they bring you back every quarter, every year? Like, what's the recommendation is, look, I got Robert in a room. He answered all these questions. People, uh, have a different appreciation for what we're trying to do. Then what, how do you get it to stick? Right, okay, like, what is that ongoing program look like? Because I think that's the other question that companies are trying to figure out. Because, look, I get security awareness training every month. It's part of my checkbox mentality. It's part of our SOC 2. I have to do it, right? Look, we know it doesn't work, but all right, I'll do it because I'm the chief Product officer. I should go through the training and not look like the ding dong. But what should companies be doing? How often should they be doing it to allow this to continue?
Robert Siciliano: Okay, there's a couple things there. So first and foremost, like, I would love it if they hired me every quarter, semi, annually, every year. That's not going to happen.
Summer Fowler: Right?
Robert Siciliano: Which is fine. My goal is a paradigm shift. My goal is to shift behavior by shifting people's thinking. And you shift people's thinking first and foremost by truly defining what security isn't, which is not paranoia. And you have to kind of go through like the rigmarole of getting them to the point where you challenge their belief systems and you know what security is, what security isn't. And they go, ah, uh, aha.
Summer Fowler: Uh-huh.
Robert Siciliano: Got it. Now what's next? So 100% of the time when I get off the platform, there's a line of people waiting for me, right? And they're always like, hey, you know, like, I gotta tell you straight up, man, I don't want to be here today. I came here because my boss made Me, come here today, I didn't think I really needed this because, you know, I'm pretty savvy with this stuff. But I gotta tell you, this was great because it's not what I thought it was gonna be, which is kind of what, why they hired me to begin with, right? Because I gave them something different. And they said, because you talked about me and my risks and my concerns, I get a question like, do you do this for high school kids? Like, do you do this for women's groups? Like, I really wish my spouse was here because he or she would have loved it. That's the type of reaction that you want to get. And so the dialogue that we have with the audience is like, okay, so my dad can't stop clicking links. My mom, who, you know is widowed now because my dad died a few years ago, like, she's, uh, involved in all these romance scams. What do I do? And here's the deal. Every single company officer has the same people in their life with the same problems, including the ciso, including the coo, including the CEO. Every employee has the same people in their lives with the same problems. And so knowing that and knowing how to address those people, who you are now prepared to provide security appreciation, security awareness training as an individual because you truly recognize risk. Now, after literally an hour and a half of dialogue, you know what to do now, because you've just experienced a paradigm shift. Look at when we experience health issues, right? We learn by default as a result of the potential tragedy or ongoing treatment that we're getting, we become experts in this unfortunate issue that we now have to learn about because of a disease. Uh, we have. You do not want to have to learn about security as a result of being victimized. You do not necessarily have to learn about a potential health issue by becoming a victim of a disease. There are certain diseases that you could actually, like, eat the right foods, drink the right fluids, uh, or the right amount of fluids, get enough sleep. Like, do certain things proactively, move work your cardio so you don't become sickly. Like, you can engage in basic one on one security practices and not become a victim. And your mindset going forward is different because you understand what to do now. You appreciate the value of this information, whether it's health information, diet, nutrition, exercise, security awareness has in your life. That's not a complicated thing, but we don't do that at all. So when the stakeholders are actually in the room, as I'm presenting, all of leadership now has what they need, but so do the frontline employees. It is truly not that difficult to do.
Jason Elbaker: It is where do they go from there, right? So you spend an hour and a half with the team, they get their minds blown because they've never heard security spoken to that level in that way. But like you made reference to taking care of your health. I could go sit there and see a motivational speaker who's an excellent exercise physiologist for an hour and a half. But at the end of the day, you know what I have to do? Get my ass up at 5:30 in the morning and work out every day. I have to go eat right and do a diet and I have to take care of myself. What's the Karen feeding after they speak? After they speak to you? After you speak to them. What's the care and feeding to make sure they get on that health trip?
Robert Siciliano: It is such small increments, like such small stuff, like small little changes in behavior end up ultimately being big things, right? So it's like, you know, like back in the day in New York, like the broken windows theory, you know, spray paint everywhere, broken windows. All they did was just clean up, you know, they cleaned up and then before you knew it, like New York was beautiful, right? And people's behavior changed. Well, when it comes to security awareness, it's like I get in front of a live audience, one of the most common questions I ask is like, how many of you can honestly say you're using a different passcode for all your critical accounts? If I get 10% of the room to raise their hand, that they're using a different passcode, that's a lot. How many of you are using two factor authentication for all your critical accounts, including your personal email? If I get 15% of the room to raise their hand, that's a lot. How many of you are using a password manager? If I get 10%, that's a lot. These basic questions. And then I turn around and say, okay, did you know? And I show them, you know, Constella says 300 billion of our records have basically been exposed over the past couple of decades. You know, about 20 billion of those records are passwords. And I show them. I take them live to Russian forums and show them passwords for sale on the Dark web. And this is why you can't be using the Same passcode across 20 accounts. And they're like, whoa, I didn't know that. Uh, so password manager, which one do you recommend? And now like that basic, basic thing, they're like, okay, password manager, but, but, but what if the password manager gets hacked, fatalism. Like that's. These are how you break down the barriers, right? And then you show them. Oh, I've had a Password Manager for 20 plus years. It's great, you know, it manages my digital life, my privacy, my security. I don't remember any of my passwords. It's like my mobile phone, I don't know my mother's phone number, but my phone does. I don't know my passwords, but my password manager does and so forth. It's like, oh, that's good. Basic 101. Start with passwords, start with two factor. How do you set up two factor authentication? Google it. You search Gmail. Two factor. You search AOL. If you still use AOL, you're adorable. Two factor. And they laugh and it's funny, you know, like basic stuff and. And all of a sudden like they're engaged in two factor authentication because it now makes sense to them. They're using a password manager because I can't believe I didn't use a password manager up until today. This is so easy, like basic stuff. And that turns into bigger stuff and bigger changes in behavior. All you've got to do is get out and walk a couple of miles a day, if that. You've just got to make better choices in the menu that are less sugary and less starchy. We're not talking about this massive overhaul of your life. We're talking little small changes in behavior, not these huge things that are burdensome. Look at if security is not easy, people aren't going to do it. If security is not like at all. Like if it's too cumbersome, overwhelming, forget it. Not doing it. And we're seeing a backslide in behavior when it comes to security. People are giving up. They're truly throwing their hands up in the air. They have given up. Look it up. Look, security backslide. Google it. And that's not because it's harder. It's because it's overwhelming and nobody's providing perspective.
Matt Alderman: So I just went through this last week. My in laws got a text from Apple Security.
Robert Siciliano: Oh my God.
Matt Alderman: Which doesn't exist. And the aftermath was not fun. But it boiled down to here's a password manager to manage all your passwords and turn two factor authentication on all your stuff, period. That's what I told them. Now they do, but they didn't.
Ben Carr: Right?
Matt Alderman: And rule number three, never ever download a piece of software from somebody you don't know or trust. Like just don't do it. Because that was the Other thing is they got her to download software onto her phone, so I had to basically erase the phone, start over from scratch. This has happened just last week, right? They're in their 80s, right? This is the baby boom generation we're dealing with. Some of them are our, uh, employees, some of them aren't. But this is the environment we're in, Robert. And that's why this topic's so important, because there's so much of this that just happens every single day.
Robert Siciliano: What organized crime is doing right now is awful. It is truly altering people's lives, where they're losing everything and literally taking their own lives in some cases. It is awful. And at the same time it is truly awesome what they do. How they have basically figured out how to manipulate humans in so many ways by attacking our biology, by attacking what I call the human blind spot, which is our want in need psychologically and biologically to trust others. When they figured out the loneliness loophole. And the 25% of all humans wake up every day just feeling lonely. And like hunger pains, the pain and ache of loneliness, we will do almost anything to extinguish it. And, um, none of that is discussed with a live audience when it comes to managing risk. And all of that means everything. Because it does. Because there's $124 trillion transfer of wealth that's occurring right now between the baby boomers and their kids and their grandkids. 124 trillion. And that generation is the target of all of this organized crime right now. Pig butchering, wrong number text scams. It's all perfect and it's brilliant. And it's being supported by AI and deepfakes and voice cloning and AI is scaling neural puppetry and they want to know what links are okay to click on a Google search. So until we actually engage the human and actually have a dialogue with them, engage in a bit of empathy. And I'm not asking a single CISO to walk out there and hug your employees and hold their hand. I'm asking you to kind of flip it on its head a little bit. Change the paradigm even just a little bit, Just a tinge more empathy. Go beyond the metrics, just a little bit. Think about your mom, think about your dad, think about your widowed sister maybe, and how vulnerable people are and how worried and fearful people truly are. We're like we are adults handling adult world. The adult world, often like our five year old emotional selves often when you think about it, strife and conflict when it comes to security. Similarly like when you're five years old and you're playing with Johnny and Johnny bit you because kids bite. You're like, whoa, Johnny's not to be trusted. But we don't necessarily take the lessons of Johnny biting us and being hurt and harmed and actually learn from them. We say, oh, I don't want that to happen to me again. And we kind of curl up in a ball a little bit and we don't want to think about that stuff ever again versus learning from it. And so you can take other people's experiences and tell stories and actually like get in front of a live audience and have a full blown dialogue and talk about like real world events that are happening right now and like how interesting they are because it really is interesting. And truly there has never ever been a time in history to actually have that dialogue than right now, today. Because AI and deepfakes are like modern day Hollywood stories. It's like Mission Impossible meets the minority report meets 007. It is awesome. It is such a brilliant, beautiful, energetic story is what it is. And it's scary as hell and it keeps people on their, the edge of their seat. And they want to know because this is interesting. You know what's not interesting? Cybersecurity. Cybersecurity is dead and they've ruined security awareness. If you talk about cybersecurity at all, it's dead. They don't want to hear about it, they don't want to come, they don't want to pay attention, they don't want to be in the room. But you talk about AI and deepfakes and voice clones and all that stuff. They're like, whoa, I'm, uh, interested in what that has to say. And you structure the title and the program description around that and the learning objectives around protecting yourself and your digital footprint and your and your passwords and your family's information. They're like, I want to come to that. That's how you make that happen.
Matt Alderman: We're going to cover that in an article on the next segment. Robert, thank you so much for joining us on Business Security Weekly.
Robert Siciliano: Hey, don't get me started.
Matt Alderman: This episode is sponsored by Microsoft Edge for Business, the browser with built in protections for Microsoft 365 customers, customers with employees using AI and web apps. More than ever, Edge for Business helps you stay in control, securing sensitive data, protecting against shadow AI and stopping threats right in the browser. You don't need to worry about added extensions, new tools or extra costs. It's the secure enterprise browser you already have built for the era of AI. Visit securityweekly.com edgeforbusiness to learn more. The rules just changed. AI, like Mythos, now finds and weaponizes zero days on its own. And your patch window just drop from weeks to hours. One prompt, Titanium Atlas. It scans thousands of endpoints in seconds. It confirms which machines are actually breached, then hunts the attacker's command and control atlas, then acts to isolate, quarantine, rotate credentials, and patch every endpoint in real time. Tanium Atlas. AI that doesn't just answer, it executes. Find out more at securityweekly.com forward/tanium. All right, we got them wound up. Now we're going to get into this week's articles. All right, um, so there's a couple in here that are interesting. They kind of tie into this topic
Jason Elbaker: just a little bit.
Matt Alderman: Uh, first article, regulatory Whiplash. Why cyber resilience is now a governance imperative. Um, I think it always has been. I think the industry is just now catching up to the last eight years, Jason, of what we've been trying to tell people.
Jason Elbaker: Yeah, I mean, we talked about it a little, uh, before on the other segment. I mean, we've been treating it like this static compliance check in the box. Just spreadsheet. Right. And we can't be doing that anymore. You know, we need to learn the lesson of that because, uh, just treating it from a compliance perspective, checking the box exercise. Nobody cares about the, uh. When you're a mal actor, you don't care about the organizational boundaries, you don't care about the rules that are in the spreadsheet.
Summer Fowler: Right.
Jason Elbaker: So, yeah, that's. It should be those answers to those questions like we talk about all the time, that should be a byproduct of your good security program.
Matt Alderman: Cybersecurity can no longer operate as a technical control function in isolation. Must be embedded within enterprise Risk Management Board reporting, strategic decision making. Boy, that sounds like the last, uh.
Robert Siciliano: Yeah.
Jason Elbaker: Years and years and years and years conversation.
Matt Alderman: I know, I know. Here we. Here we are.
Robert Siciliano: Here we are.
Matt Alderman: We're just in our spreadsheet, Jason.
Jason Elbaker: Uh, I can guarantee you, Matt, if we went to one of our podcasts from about seven years ago, we probably said in five years we're going to be talking about the same thing. Yeah, I'm sure we could find one of them.
Matt Alderman: Yeah, yeah, look, and we talked about a little bit of this last week, Jason. I think a little bit. And I've seen this, this evolving trend. Some of these areas. Right. This data sovereignty thing is a real thing, folks. Right. And I, uh, deal with it almost Every day now. Like, it's gotten to the point where nobody trusts anybody in the world.
Summer Fowler: Yeah.
Matt Alderman: Okay. Therefore, my data has to stay in my country. I think we're going to see more of this. It changes how you have to approach some of this stuff in the issues that get, um, injected here in how you manage your ongoing business. Like if you're a SaaS provider that's running in the US and has no plans of figuring out, no, this is a major impact to your business and to the way you operate. And I don't think people are really thinking through some of this yet. No.
Jason Elbaker: And like we said last week, it's going to force businesses to think about whether or not they even want to do business in certain countries now.
Ben Carr: Exactly. Uh, yeah. I think it's going to put some additional thought to the limitations of expansion.
Summer Fowler: Right.
Ben Carr: Like, you know, there are always concerns. You look at, like, what's the cost under new territory, jurisdiction, whatever. But I think regulatory and, you know, cyber, cyber, um, regulation on this is going to raise its head and people are going to say, yeah, it's just not functionally something we want to get involved with to do business in this country. Right. And So I think SaaS is going to be less ubiquitous because it's going to be very regional, limited.
Summer Fowler: I agree with that. I think you're exactly right. Although it's interesting that. And I agree with the fact that that cost driver is a big deal. However, we still have organizations. You know, when you look today at, um, you know, clue in the Salesforce integration issues that have happened and what happened with Snowflake, it's like we care about this data sovereignty issue because of the cost, yet we don't worry about integration accounts. We, you know, Tesla and Apple may have had some of their data stolen in, you know, their, some of their IP stolen in a breach just over, you know, the past 24 hours. And it's like we don't care where our data is with other partners or those integrations. And so we need to pay attention to that as well.
Ben Carr: Yep.
Matt Alderman: Yeah. Article number two. Should CEOs be held personally accountable for cyber attacks?
Jason Elbaker: Welcome to the party.
Ben Carr: Yeah, they should.
Robert Siciliano: No.
Matt Alderman: So the answer is yes. The real question is, will they be held accountable?
Jason Elbaker: Probably not. Probably not. And you know, I look at it this way too.
Summer Fowler: It's.
Jason Elbaker: It's the blessing and the curse. Right. Think about what happened when CISOs became personally liable. What happened to the amount of CISOs who wanted to be CISOs anymore.
Summer Fowler: Yeah.
Jason Elbaker: Yeah. What's going to happen when CEOs start looking down the barrel and they're like, you know what? Yeah, I don't think I want to do that. You know, are we, are we setting it up for, I don't know, some type of talent stall, you know, where you have CEOs not wanting to take the job because of that. Yeah. I mean, personality M is a big freaking deal. Big deal. Yeah.
Matt Alderman: But the CEOs also have had a level of protection around them for other areas. Yeah, yeah, yeah.
Jason Elbaker: But here's the thing. I would hope you hadn't, uh, had a CEO who understands finance coming in. Right. They have that knowledge, they have that background. They don't know anything about cybersecurity coming in, so it's a flying spot for them.
Ben Carr: Uh, there are a lot of people who have the financial experience. Right. But I've also seen a lot of people come from product backgrounds that don't really have the financial experience. Right. That a CFO would have in their role.
Jason Elbaker: Yeah, yeah.
Ben Carr: They're protected by liability. Right. Like, they're protected by, um, you know, with indemnification for the job. Like that's pretty typical for a CFO or CEO. Right. Um, and generally named officers. Right. Who are included in the policy. It hasn't been for CISOs. I just think this a good fit. Whereas you start to see that connection. It's, oh, when the CISO asks for, um, coverage now. Right. We're going to offer it. Because I understand where that's coming from. Right. They understand how that connection.
Jason Elbaker: I think my point is, I don't think the likelihood is high that's going to happen. Um, because they're not going to want to take on additional liability at all.
Ben Carr: Uh, this goes back to that question of like, are we going to see regulation for this? Right. Are we going to see, uh, the SEC or somebody else, like, you know, start to apply guidance around this? And I think, I think they need to. Right.
Summer Fowler: Yeah. I think the challenge is that they've done a better job at being able to say, what do reasonable financial controls look like? And defining those reasonable cybersecurity controls that evolve over time as threats evolve, as other things evolve. I think that's where the challenge lies. Uh, the stick by which we measure hasn't been created yet.
Ben Carr: Yeah. How do we do? Balance sheet hasn't really changed that much, but, uh, cyber control certainly have.
Matt Alderman: They have. But let's go back to the first article. Let's talk about this. In a risk kind of component, you can identify material, non material risks. We, they do it for Sarbanes, Oxley all the time from a financial perspective. Right. So there is some. There is some precedence here. If we could actually figure out how to quantify our cyber risk, we could use some of the same measurements for our financial risk to understand what's material, what's not material to the organization to allow the CEO and the CISO to potentially sign off on those risks. I'm just saying, like, this is not.
Summer Fowler: Yeah, I don't disagree with you, Matt, but what, you know, where I think there's a real challenge is if we take this all the way through, uh, to a court case, and now you're trying to explain these things at. Even on the most fundamental human level, explaining the financial things is easier than explaining the cybersecurity things. And, I mean, I think that if we took this all the way down the chain, things start to settle, they fall out. And we see it even in court cases today where fewer things that, uh, have a technical cybersecurity side actually make it into a courtroom. They settle outside because it's so complicated. They know that it's going to be really tough for a jury or even a judge to be able to sort through it.
Matt Alderman: We'll just hire Robert, put him in front of the jury to educate them on the importance of cyber security, because that's exactly what he was just talking about in the last segment. Our employees don't know the issues of cyber security, let alone a jury.
Jason Elbaker: Right.
Matt Alderman: Gosh.
Summer Fowler: All right.
Matt Alderman: Three forces are redefining the transition from manager to leader. A lot of AI stuff in here. And what's kind of forcing some of these, uh, changes?
Jason Elbaker: Yeah, I mean, it's changing the dynamic as to how we work at the end of the day. And if you're a middle manager, director level, you better start embracing these tools, because you got to be able to move quicker, faster, make decisions faster. And I kind of like how they broke out some mindset shifts. Instead of being a specialist, you need to start getting into that generalist of, um, speaking to the business, speaking to technology, speaking to how they interact with each other. Turn from being a tactician to a strategist, really using the tools that are available to make you more efficient and make decisions faster.
Summer Fowler: So the thing where this article fell short from, for me is that he started to use the words that I find as almost the most important, but failed to actually get far enough. Like, he talks about, you know, analyst to integrator, um, bricklayer to architect. But there's also the element of being a leader. Is you have to inspire people. And this is lacking that inspiration and direction. Now, he does mention strategy and he does mention diplomat, but neither of those really speaks to. Like, when you really think about those great leaders, some of these things, they even have people underneath of them that, that they do. They're the people that are saying, this is the direction where we need to go. And, and I, uh, I'll help get us there, and we're going to get there together. And, you know, that inspiration, to me, is just something that was really lacking in this
Matt Alderman: next article, placing communication at the center of every leadership transition. Now, this is talking about transitional leadership.
Summer Fowler: Yeah.
Matt Alderman: However, to your point, Summer, this communication is also important during those other transition manager to leader transitions as well. Right?
Summer Fowler: Yeah.
Matt Alderman: That starts to bring in some of the missing components that I think the previous article did not have.
Summer Fowler: Yes. You know, the other thing that I was thinking about this as Robert was talking, um, you know that we are, you know, intrinsically somewhat selfish. And when you think about. And you know, we've all been through those times in companies where your company's shutting down or you're laying people off, it is important to remember that when you're communicating any sort of change, you have to communicate how it's going to impact the people that you're communicating to almost first. Right. It can't be. This is what's happening to the company at large, and this is what's happening to. It has to be about the people you're communicating to, because that's their concern. You know, Robert wasn't wrong in that. If you can say, this is what's changing and here's how it's going to impact you, I think that's important just
Jason Elbaker: to tether into that, Summer. It has to be proactive. It can't be reactive. The biggest piece to take out of this article, at least from my perspective, is you want to be able to define the narrative, not have the narrative defined for you. Because when people assume they're going to build their own narrative, and that's not a good thing. That is not a good thing because it's going to be based on fear and anxiety and a fear of the unknown. You have to define the narrative proactively, get ahead of it.
Robert Siciliano: Yeah, yeah.
Ben Carr: And I think when you're looking at communicating, you have to understand the entire audience. It's not always just the audience that you anticipate the message going to. There's a much larger audience in that. Right. And so how that's going to be perceived, how that's going to be translated, um, by people who consume that messaging. It's really, really important that you think about the full scope of that.
Jason Elbaker: And to your point, Ben, it may be different communications to different audiences.
Ben Carr: Mhm.
Jason Elbaker: You have to really think about that ahead of time. Right. You have to think about that because you may have to take a communication and write it a specific way for specific audiences. And it's gonna, it's gonna take you time, it's gonna take time for you to do it, but at least you're delivering the message to the audience the way the audience needs to get it.
Ben Carr: Yeah.
Matt Alderman: Yep. AI isn't solving cyber security workforce woes. Huh? You don't say.
Ben Carr: I thought everything got solved by AI.
Matt Alderman: I just thought everything was instantly solved with AI magic.
Ben Carr: Just go to copilot and say do it all and it doesn't.
Matt Alderman: I, I told you guys, right? I've been working on this, I've been working on this new app, been using the vibe coding. It's great in some things. It, it truly is. But then you will get into rabbit holes and I'm telling you, it can't figure itself out. No wonder it hasn't solved all of our cyber security.
Ben Carr: Uh, I was working on something the other day and I got like significantly way into it and then it said, you know, that's awesome. If you want to take to the next step, tell me, you know, give me this and I'll take it to the next step. And I gave it this. And then what I got had nothing to do with what I just asked it. And it's like, where did this go wrong? Let me start over.
Matt Alderman: It does help in certain areas, I will tell you that. Like I've seen, I've seen improvements in certain areas, but then, man, there's just some things it can't figure out and it just slows you down. You, uh, uh, will get caught into loops. Like I've been working on just simple stuff like, simple stuff like permissions around Google Meet invites and who owns them for the recordings and the transcriptions. I've been looping around this thing for over a week, almost two weeks, because as soon as I fix one thing, it breaks something else.
Jason Elbaker: So now, so now think about this. We're, we're technologists and cyber security professionals who've been in technology our entire careers. Let's take, I don't know, a finance clerk. How do you think they feel trying to use these tools that get thrown at them? Hey, we got this new fancy AI for our, you know, our uh, ERP system ready, set, go. And they're not getting the readiness training and they're not getting enabled, they're not getting what they need to be able to perform, and they're trying to work their way through it. We have a hard time as professionals. Yeah, imagine that.
Summer Fowler: I think the way that the tie in from this, from the last two articles is that the rollout of AI in many places has not been strategic in thinking about what they want to achieve. It hasn't been communicated well. And so we have that leadership communication failure. And then, like you mentioned, the training isn't there. It just seems, you know, it would be really hard. It would be like handing someone a TI85 calculator that's probably like the ancient version that they've never seen before and said, go do your advanced calculus on this. And they just want to throw it down and do it on paper because they don't know how to use that, that calculator. And so you need to train them and you need to go through it. So I think that this does tie in nicely to the other leadership angles.
Matt Alderman: And the last article help employees get better, not just faster with AI. That's ultimately the goal. Right. We think these tools are just going to make us faster. And as I said, in certain cases it will make you faster, in other cases it will make you a lot slower. And we need to help our employees
Jason Elbaker: understand this is what, this is what I've seen, I've seen it erode, uh, quality because they talk about work slop. And you get folks who want the easy button and they'll literally take whatever AI produces, copy and paste and throw it out there to the masses. Hello. Some of the articles that we put on the show, right. I mean, we looked at some of them and said, yeah, that's like 90% AI. Uh, no doubt about it.
Summer Fowler: Right?
Jason Elbaker: Yep. It's the work slop. Our quality, our output quality is going to diminish if we allow it.
Ben Carr: Yeah. My two biggest concerns is that, you know, we're going to generate a lot of information with the expected accuracy, but the accuracy isn't going to be there.
Jason Elbaker: Right.
Ben Carr: That's one certain thing. Then the other thing is we're going to get to the point where we've replaced people for tasks, um, especially on the cyber side, um, thinking that there's going to be some efficiency. And then we're going to get to the. Where we realized it's cost. Right. Is much higher. And when you shut off the cost on the AI side, you've got no one to backfill to take up that task because you've gotten rid of the worker on the other side. Whereas if you're paying the yearly salary for somebody, I mean, you've got them for the whole year, you've got that embedded cost. Um, and you know what it is, right? There's no magic window where at the end of the month somebody just gives you an invoice for AI costs and you're like, oh, that was how many tokens? So I think we need to look at fast is slow and slow is fast. Make sure that we're looking at the quality going in and you'll get faster going out. But you got to question everything.
Summer Fowler: I think it's also a reminder that critical thinking is not going to ever be taken over. So I think that all of us will get better and the world will get better with the use of AI. It still is going to require the critical thinking of where it needs to be applied and how we check and make sure the outputs are what they should be, et cetera, et cetera. And so for the people listening who are worried about their kids or worried about their own jobs in the future, stay that critical thinking side of things. Um, be really, really curious and don't be afraid to try and fail, but know where to do that, right? You know, like pick those low consequence areas to do some of this early experimentation.
Matt Alderman: I see it today, right? Like we have some developers that are, they depend 100% on AI and don't have the critical thinking, so they can't explain what the code's doing. And that's a mistake. Right? Then I have, on the other side, I have folks that don't embrace any AI. They're just building everything from what they know. There's actually a balance. And that's what I'm starting to see is how can I speed, gain. Gain efficiencies? Uh, not speed. How do I gain efficiencies with critical thinkers that can leverage AI to help them be more efficient in producing code to get out the door, Right? I think that's the balance we're looking for. Because the critical thinking is going to look at the code and go, why did it do that? Like, that doesn't make sense to me. Uh, but if you don't have that skill set, you're going to push that code into a pr, it's going to go in, it's going to fail, it's going to get a bug, and then AI is going to try to rewrite it, which is kind of the loop that I'm stuck in, you know, I just wanted to do a, uh, simple turn on record and transcribe. It says, hey, I did it for you. No, you didn't. It's still broken, right? Like, that's not what we want to get ourselves into. And it's trying to figure out that balance. What's that?
Ben Carr: Uh, yeah, it's broken better.
Matt Alderman: Yeah, it's broken better.
Jason Elbaker: To your point, and to be honest with you, all of your points, there needs to be a focus on quality. There needs to be quality metrics that are instilled now. Right? Instead of just speed to product or speed to action, you have to have quality built into it. Have to. It has to be a metric that you're looking at.
Matt Alderman: I guess Six Sigma is coming back.
Jason Elbaker: Yay. Let's go.
Summer Fowler: It'll be seven. Seven now. At least seven.
Matt Alderman: Oh, wonderful. Uh, thank you all for joining me today. It was awesome to have you all here. Thank you, everyone, for watching and listening. We'll see you next week on Business Security Weekly.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.