Last week, we kicked off Cybersecurity Awareness Month with the release of our series launch episode zero. Hopefully, you had a chance to check that out and enjoyed meeting our VIP cast of sassy, savvy, and expert cybersecurity partners from ConnectWise, Intelisys, and TBI. We shared fun and insightful facts about the ever-changing landscape of cybersecurity and what scared these industry pros the most about current and developing cyber trends. If you hadn’t had the chance to watch Episode 0, be sure to catch that on demand on LinkedIn, Facebook, or YouTube. And if you’re more of a podcast kind of listener, catch all twenty-three episodes ahead on Spotify or Google Podcasts. Also, for direct delivery into your inbox, sign up for our blog at TechOnPurpose.net/blog.
Today, we’re diving deeper and focusing on security awareness training, which is number one on our top cyber twenty-one best security practices. Did you know that ninety-five percent of all breaches are result of human error? That’s why security awareness training is number one on our list and why we recommend starting your journey to secure, reliable, trusted technology right here.
Don’t forget we’ll be releasing a new episode every Tuesday, starting today 10/20/21 through late spring of 2022 with brief time off for holidays with family & friends. We’ll also follow each Tuesday episode release with subsequent Wednesday, Thursday, and Friday posts highlighting our (3) contributing solution partners from that week’s episode. We hope you’ll find this an immersive, hopefully simple, educational and enjoyable experience. So how do you tune in?
To easily follow the journey ahead we’ve diversified your access options to all (23) of our coming episodes. You can follow long here on our blog, or by any of the following methods:
- Email Newsletter: sign up at techonpurpose.net/blog and have each episode delivered directly to your inbox when released.
- LinkedIn: follow here
- YouTube: follow here
- Facebook: follow here
- Podcast: follow here
Buckle up – it’s time to hit the road to #secure, reliable, trusted technology!
Read Transcript
Welcome back to Who’s in Your Cloud, twenty-one steps to secure, reliable, trusted technology. I’m Lauren Lev, Marketing Manager for TechOnPurpose, and this is Episode 1 Security Awareness Training. Last week, we kicked off Cybersecurity Awareness Month with the release of our series launch episode zero. Hopefully, you had a chance to check that out and enjoyed meeting our VIP cast of sassy, savvy, and expert cybersecurity partners from ConnectWise, Intelisys, and TBI. We shared fun and insightful facts about the ever-changing landscape of cybersecurity and what scared these industry pros the most about current and developing cyber trends. If you hadn’t had the chance to watch Episode 0, be sure to catch that on demand on LinkedIn, Facebook, or YouTube. And if you’re more of a podcast kind of listener, catch all twenty-three episodes ahead on Spotify or Google Podcasts. Also, for direct delivery into your inbox, sign up for our blog at TechOnPurpose.net/blog. Today, we’re diving deeper and focusing on security awareness training, which is number one on our top cyber twenty-one best security practices. Did you know that ninety-five percent of all breaches are result of human error? That’s why security awareness training is number one on our list and why we recommend starting your journey to secure, reliable, trusted technology right here. Let’s get started by introducing our Episode 1 cast for today. With us, we have our returning VIP cast member, Jim Bowers from TBI. Apparently, Jim, you didn’t get enough of us last week in Episode 0. We didn’t scare you off.
Jim Bowers
Not yet.
Lauren Lev
OK, good.
Matt Tankersley
Glad to have you back.
Lauren Lev
Yes. Brian Jack, CISO for KnowBe4, welcome to the series Brian.
Brian Jack
Thank you very much. Glad to be here. Sounds like a lot of fun.
Lauren Lev
Next, I am most excited to welcome our first female cast member on the vlog. Samantha Yip, Channel Success Manager from IDAgent. Sam, thanks for coming.
Samantha Yip
Thank you for having me.
Lauren Lev
Of course, of course. We have Stephen Kowski, Global Director of Sales Engineering from IronScales. Thanks for being here, Stephen.
Stephen Kowski
Thank you very much. Real pleasure to be with you all. Thank you for inviting us.
Lauren Lev
Of course. Lastly, we have our TechOnPurpose Founder and CEO, the man himself, Matt Tankersley.
Matt Tankersley
Hey, Lauren. Thanks for having me back, by the way.
Lauren Lev
Of course, we couldn’t do it without you.
Matt Tankersley
I don’t know. You might be able to. Listen, thankfully, we’ve got a full cast of experts here today on this topic, so I don’t have to necessarily be too smart. I do know that for decades of operating companies, hiring and managing a broad spectrum of employees in departments, that no one user is identical, right? I’m talking thousands of employees and everybody’s different, right? Just because you have an aptitude for technology doesn’t mean you have an aptitude for security awareness. But there’s one other sort of starting priority I’d like our listeners to hear today. It’s that you really need to understand how bad, how serious, and how everywhere these malicious actors are, and they do not just attack our businesses. They very intentionally target and attack our personal online identities. So, let me put that another way. Everyone needs to learn cyber safety, and everyone needs to apply these same tactics and awareness to one hundred percent of your personal online practices that we’re going to talk about for your business today. So, that’s my starting thoughts. Let’s hear from our returning VIP cast member, Jim Bowers from TBI. Jim, remind us who is TBI? Maybe some of our listeners hadn’t seen Episode 0 yet. What do you do for TBI? And lastly, let’s give our listeners your thoughts on the topic of security awareness training before we turn it over to our solution partners here with us today.
Jim Bowers
Awesome. Matt, thank you so much, and Lauren. Guys, thank you so much for being a part of the series. It’s an amazing series and it’s a great foundation for your viewers to really start to strengthen their security posture. So, TBI is a technology services broker. Basically, what we do is have multiple vendors within relevant spaces of technology, whether it’s cybersecurity or networking or cloud infrastructure or hosted voice, where we have multiple vendors to enable our partners to leverage those relationships to provide solutions for their client base. We also provide engineering resources. So, I’m part of TBI”s tech guru team. It’s a group of engineers and architects in each major discipline. I’m the cyber security architect. We have UCaaS, CCaas, all things voice, infrastructure, where we enable our partners to have these deeper, more complex discussions with their clients. You start selling stuff like cybersecurity and hosted voice and edge computing and all that fun stuff. This, in my opinion, I think you’re so spot on, is the number one thing that all corporations can do to really strengthen their security posture. The reason I say that is, endpoints are the number one attack vector. I like to call them starting points because that’s where the threat actors start. And who’s using those endpoints? The weakest link in the chain and that’s us, right? And they know that. So being able to educate your end user, especially in the environment we’re in, in this work from anywhere mentality where we’re not going into an office, we’re not in the psychological aspect of being in an office, being more cognizant. We’re sitting at home. We’re in a more relaxed environment, so we’re easier to fool, right? I think I read a statistic that 2019 about 30-percent of phishing or spear phishing was done through cat videos, right? Being able to distribute that, that malware and that’s a, everybody loves cat videos, but you don’t realize there’s malicious stuff going on the back end. So, being able to educate us. In my opinion, and your spot on is the number one thing all organizations- I don’t really care what size you are, what vertical you’re in, you need to educate your employees in an environment that is rapidly changing and is heavily funded, right? So, that education aspect, if my employee or my employee does not click that button, then it never goes anywhere, right? That malware, ransomware doesn’t come legit. It stops right there So, I think-this is the biggest part in our defense in depth approach. So, thank you very much for being a part of the series.
Matt Tankersley
Thanks for pointing out. You know, you said corporations early on, you brought it back to sort of where I started at the beginning, which was, it’s about individuals, right? Each of us individually, not just making good choices at work, but also at home. Listen, your personal livelihood is why you do the things you do at work. And so, you might as well protect that just as well. And I think what we’re going to find is a lot of our solution partners give us tools to do both of those things.
Jim Bowers
Absolutely. And you guys are some of the top in the industry as well. So, these are very good and they’re very good at what they do. So, listen to the smart guys on here.
Matt Tankersley
Yeah, so that gets me out of the room. And then Lauren, lets turn it over back to you and let you do a quick round of introductions for our partners and who they are and where they come from.
Lauren Lev
Well, I wanted to add too, to Jim’s point, because ninety five percent of breaches are a result of human error. As an employee of a company that makes me take a step back and think, Wow, this is really serious, but also questioning what I’m doing every day and just making sure that’s like at the forefront. And then I’m being vigilant about it, but also that I’m being provided the correct training from my organization leads to make sure I’m not making those mistakes. So, this might even be something that staff are going to be requesting from their employers. So, I just wanted to add that.
Matt Tankersley
Absolutely.
Lauren Lev
I’m on the other end.
Matt Tankersley
Yeah, Lauren, I’m sorry. I didn’t mean to cut you off, the morale of the story is, you got to stop sharing the cat videos.
Lauren Lev
Well that’s really hard. As long as it doesn’t affect the Wiener Dog videos, then we should be good on that.
Matt Tankersley
I know.
Lauren Lev
All right. Well, thanks, Matt and Jim. So, circling back, let’s do a quick round of introductions for our solution partners now and then we can circle it back to a little bit more specifics about the topic. So, Brian Jack, you’re up first. Tell us more about KnowBe4 and what your role is there.
Brian Jack
Sure. So, KnowBe4 is the world’s largest provider of security awareness training and simulated fishing. We have offices in, I don’t know, seven or eight countries around the world. 35,000 plus customers around the globe. We train millions and millions of end users every year. My role at the company is a little bit unique. I’ve been there since the beginning. I helped write and build and design the tools that we use, including the simulated fishing platform, some of our free tools, email exposure, check domains, goof tests. I’ve since moved away from the engineering role many, many years ago, which is good because. That should really be left up to an engineering team. And so, my team is in charge of actually running the cybersecurity awareness program at KnowBe4 for KnowBe4 employees. Very, very interesting role. I talk with a lot of customers. I talk with a lot of internal employees. We have a wide variety of simulated phishing, would say lures. And I think we have upwards of over 10000 different phishing tests with different landing pages, different flavors and styles. Business email compromise attachment test. All kinds of different tests that you might want to test your employees against. And then the training to follow up with it. We have hundreds, if not thousands, of different training content in various languages that are in different styles, too. Some are a cartoony, some are more traditional, some are live action. Some have even been on Amazon Prime. So, it’s a really, really interesting variety of training styles and flavors because different people learn different ways. And so, you need to understand what your company culture is and have the tools available so that your employees will learn that based on the methods that they, they learn best from, not everybody learns by doing a PowerPoint or by taking a training. Some people learn better by visualizing and learning and characters and character flaws and things of that nature. So, we like to provide the tools necessary to have your employees make smarter security decisions. And we’ve been doing that really well for over 10 years now and hope to continue.
Lauren Lev
So next up, we have Samantha Yip, from IDAgent. Sam, introduce IDAgent to the viewers and what your role is there in delivering secure, reliable, and trusted technology.
Samantha Yip
Absolutely. I mean, you know, my name again is Samantha, and I am Channel Success Manager here at Kaseya specifically for IDAgent’s. So, we offer a lot of cybersecurity solutions for managed service partners like yourself, Matt. And I’m part of the one of the services that we do offer is security awareness training, which is exactly what we’re talking about today and we do offer countless amounts of training in different languages, they’re interactive and very user friendly. And we really hope that that type of material is what users take back and maybe can even deploy in their own personal lives as well. And of course, we have simulated phishing campaign as well where you can look to use that and test your users in a really safe environment to build that security culture, to make sure that they know what they should be looking for in some threats out there. And of course, with all that comes with all the reporting, all the analytics of everything that’s going on within your organization.
Matt Tankersley
Well, Lauren, it sounds like we’re going to make sure to have everybody back for our phishing segment, which I was trying to recall what which step that was in the Cyber 21, but really glad and it’s interesting to see how related these two topics are. Obviously, each of these companies is invested heavily in ensuring that there’s some, some correlation between those two things. And I think we’re about to hear the same thing from our friends at IronScales.
Lauren Lev
Yes, so Steven, you are up next for IronScales. So, tell us who is iron scales and what your role is there.
Stephen Kowski
Yeah. So IronScales is an anti-phishing company that’s developed an anti-phishing platform that, it started in and emerged out of the Israeli Defense Force. So, we have a large work hub out of Tel Aviv and then also in the southeast, in Atlanta. We’ve been named the fastest growing cybersecurity, privately held cyber security company in the world by Inc5000. So, we’re rapidly kind of expanding because our approach is a little bit different and our views a little bit different on the market as far as the academic in the real world, right? Blending these two together is vital. Right. So, it’s about supporting the user, but and training the user, we run these phishing security tests, security awareness training sessions, but we use that data to actually inform our actual threat mitigation response. So, you have kind of these two sides of the market, people only doing technology, people only doing training, and we kind of weave these things together and there’s a continuous feedback loop between the two of them to reinforce their training. And really, what are we seeing out in the real world and how is that feeding into our training? Are we training on relevant things that we’re seeing coming in today? And then. Also, you know, how well are we working as an organization and on a campaign level and on an individual level? So, kind of tracking all that together is, you know, myself, I am a, the Director of Sales Engineering globally and helping folks with proof of value, proof of concept free trials. Meeting with customers. Trying to explain the value proposition from a technical perspective and really help them solve the problem of email phishing. So naturally, a lot of my statistics and information will be based on a messaging background. So, forgive me in advance.
Matt Tankersley
Absolutely, okay. Wow. Well, look, Lauren, we said we were going to bring the rock stars for each of these conversations to our discussion, and I think we’ve clearly done that today, just in episode one we clearly did in episode zero. And so, what I’d love to do is turn it back over you. And guys let’s just dive in a little bit deeper. I think Lauren’s got a couple of questions in particular that we’re going to pass around the room and let’s see what we can do to basically continue to raise awareness about the, the priority topic. And how do we get people to move into adoption?
Lauren Lev
Buckle up and dive in. We’re going to start ladies first, with you, Samantha. So why is this topic so important and what do viewers need to know to take, this scary statistic, the one that ninety five percent of all breaches are a result of human error, why should they take that statistic to heart and then prioritize the adoption of security awareness training?
Samantha Yip
Well, absolutely, that’s a very scary statistic, and I’m going to throw out another scary statistic out there that I have actually read. Recently, 80 percent of organizations have to deal with at least one compromised account per month. That’s significant. I mean, that’s a relatively high number. So, they’re dealing with their users compromising their own accounts. I mean, we could see this in the news daily. I mean, I want to say a couple of weeks ago, Next Level Apparel, the US based clothing company, they were, they were breached, right? I mean, if you haven’t heard, they actually publicly announced that several of their employees’ accounts were compromised in a phishing attack. And with that, they had end customers, their own employees, PII, they’re personally identifiable information, I’ll bet that were exposed. So, this is something that is happening frequently and it’s happening a lot more now that we’re all again, we’re working remotely, like Jim said a little bit earlier. So, we are in that kind of safe environment at home or wherever else we might be working from. And, and the controls are not necessarily there for employees to be safe within, you know, within the firewall, within the four walls of the office, office location there. So, we really do need to take a look at adopting and building out that security culture and part of building that security culture is including your users in security awareness training. Making sure that they know that they are vital in the first line of defense against any sort of incident cybersecurity incidents, and attacks towards the organization. So, you want to have that cybersecurity awareness training. You want to make sure that training is interactive, it’s easy for them to follow, and it’s not going to take an entire day to do. But you also want to incorporate simulated phishing so that you can kind of test out again in that safe environment, whether or not this training is actually working. And if they’re retaining this information.
Lauren Lev
Let’s turn it over to KnowBe4’s, Brian Jack. Brian, will you share with our viewers why security awareness training is so important and how do we successfully motivate our viewers to adopt it?
Brian Jack
Sure. So, if you’re not currently training your users, you’re missing a big piece of your defense in depth strategy. It’s really the, the barrier to entry is really low. If you take somebody who hasn’t had any training and you give them a little bit, that’s a drastic improvement in risk reduction for your entire company. Now, the key words that Samantha said, culture. Hundred percent, it’s not just about security awareness training. If you give someone a fifteen or twenty-five or forty-five-minute video once a year and you give them a couple of phishing tests a year, you’re not really driving home the point, right? So, when you want to implement a really, you want to implement change in a user’s behavior, you have to change the culture of the company. So, we have employees that come in. We’re a cybersecurity company. We do this. I run the program. I don’t know where they came from. I don’t know what kind of training they’ve had before. I need to get them into our culture quickly, and I need them to understand how we do things. So, we do things. Cybersecurity company here is our training. We do a lot of training. We don’t just train them on here, the threats that are out there, we say, OK, now here are your tools at your disposal so that you can be a part of our human firewall. So, there’s much more to awareness training than just giving a video or doing a phishing test or anything like that. You have to really understand what drives the person and make sure that they know they’re part of the puzzle. You’re going to give them the tools, you’re going to train them on how to use the tools, and then you need to assess that over time. So, having a platform that you can measure the success of your program, you can measure sort of a cultural shift in your organization. That’s really good. Ford loves to see that risk reduction. It’s all kinds of things. So, we, we measure not just, you know, how many people clicked on a fishing test. We measure the amount of people that are reporting the simulated fishing test. And we have metrics that go, you know, OK, here we call it fish from percentage. You want your fish percentage to go down over time and then level off. It’s very difficult to get to zero consistently, but we also measure the amount of people who reported it, and we have a metric that keeps that number very high. So, that ensures that, you know, your users are in fact engaged. They’re not sitting passive by the by the sidelines and that all those tools are working and they understand that their role in it. So, awareness training is very important. But you got to have a you got to get the buy in. You got to get the buy-in from the users and you’ve got to change the whole culture because like I said, somebody comes in, they don’t know anything. You give them a little bit of training. That’s great. But nowadays, most companies are doing something like that, and they’re at this sort of like mid-level based line. How do you go from in the middle to really a top tier security culture organization? And that’s have a ton of tools, make sure the users know how to do it, make them feel included in the process. That, that’s huge. I love it. We have a great culture, and it’s because we leverage all the tools available to us and we get people as soon as they come in the door and get them on board and understanding what kind of our mission is. And that’s, that’s a, it’s an important piece. Like I said, that the barrier to, to get into it is not, not difficult. But when you want to go from sort of that middle tier up to that top tier now, you really need to start focusing on culture shift and behavior change and identifying risky behaviors and correcting them very quickly. So, it goes above and beyond just your, your you know, your training here and there. You have to have a little bit more to the toolset.
Matt Tankersley
Thanks Brian. Hey Lauren, I know you’re going to jump to Stephen, and Stephen I’m anxious to hear your validation on the why do we need this thing? And it’s amazing how all of these topics are tied together. And we didn’t mention this today. And I think I’m going to piggyback off of what you just said. In that culture is part of the origin of this entire series for us, if you didn’t catch episode zero, one of the reasons why we created this idea of simplifying, you know, how do I get started in a simple way into having tighter securities? We had a lot of clients that just consistently refused to follow this practice. That’s a culture, right? But Sam, you guys were both just talking about that. And the point that I would add there before we come to you, Stephen, is that generally that has to start at the top because it doesn’t matter how good your CSO is, it doesn’t matter how good your HR person is. If your management isn’t bought into the importance of security, awareness training and just cyber safety in general, and it’s just not going to work out. That’s what one of the main reasons why we started this thing. We had to do a better job of educating, so didn’t mean to cut you off of the pass there, Lauren. I know you’re going to hand it over to Steven.
Lauren Lev
No, no, no problem at all. So, thank you, Brian. That was some fabulous insight. So yes, as Matt said, Steven, from IronScales over to you. Why is it important and how do we motivate adoption?
Stephen Kowski
You know, first kind of why is it important, but I want to just touch on what was just mentioned, right? I totally agree. We have to really shift the mindset of that. This is a, this is a technology problem that IT needs to solve or security needs to solve, right? It’s a, it’s a business risk problem first and foremost. It’s not, and security is a, you know, a risk function, a risk management function first and foremost. It’s not just a group of technologists. So, that’s, I totally agree that that culture needs to go throughout the environment and everyone needs to understand that they have a personal stake in that. So, I just wanted to touch on that. But why is it such an important topic? The problems are not going away. They’re actually getting worse. The attacks are getting more frequent in our context. Phishing attacks are more than doubling year over year. Right, 70 percent of them of organizations are falling victim to it. Right. The median impact of this is, like I think last I read was two hundred sixty thousand dollars and about 10 percent of them are about $10 million. Right. So, you know, when we think about it and what you’ve seen over the last year, especially is the shift into social engineering and the shift into the endpoint itself has now fallen in the rankings. If you look at this year’s DVIR, Verizon DVIR report and what’s replaced, it is the person. So, the person is more likely to have caused the breach than the thing that they’re sitting in front of and interacting with. Right. So, we have to reframe our mindset about what is an endpoint and what do we need to harden and what do we need to secure? So, the human element is key. So, we have to put that at the center of our approach. You know, the risks, I mean, are frankly everything up to and including the full shutdown of the business, right? We saw that earlier in the year with the Colonial Pipeline attacks, right? People lining up for gas and prices spiking. So, that that’s clearly but I think that also it’s, it’s surrounding those that security culture and making it a positive thing. We need to move. We are, we are moving, frankly, it’s just too many threats from enforcers of security to really enablers of security. So, it’s important to do it in the academic environment, but also to give that awareness contextually in real time as risks are arising within the given kind of tool areas, right? So, in our area of email, that looks like specific, contextual, this is a sender name address spoofing. This is a domain spoofing, right? Not just this is coming from outside your organization. Every email has that, and now everyone’s just kind of eyes glazed over and they’ve suffered from banner fatigue. So, you know, it’s you’ve got to give them real time information training ahead of time. But then also feedback, right? It’s you click a button and it and the mail goes off and maybe it gets a response. Maybe it doesn’t. But if you have a tool that’s more gamified and can give the user an immediate feedback of, “No that was safe, or that was phishing, or what have you. That’s really a great way to reinforce the learning that they’ve had in the academic environment in the real world, right? And blending those two is critical. So, that’s kind of how we are seeing it today.
Lauren Lev
Thank you, Stephen. Matt, do you have anything else that you want to add on why you chose security awareness training to be the top of our best security practices matrix?
Matt Tankersley
Well, I think everybody said it well here, right? It’s the greatest area of risk. We can say 95 percent over and over and over. And I think the goal is here how do we motivate people, right? And I think that, you know, besides sharing these truths with them, besides giving them tools, how do we get, get them to take action? And I think that’s something we’re all striving to do all day, every day. It’s interesting. We have the same conversation with some, all these things come together. Last episode, one of our other sassy, savvy VIP cast members, it was- Jim, it was Ivan from Intelisys, Ivan Paynter, and he said he had a lot of fun. We had a lot of fun talking about just clicking on stuff, don’t click on stuff, don’t click on stuff, right? And it’s, it’s just amazing. And we literally, at the end of that conversation also talked about a call that we had gotten the last Friday where the owner of a business flipped on some stuff. And boom, one hundred thousand dollars has gone out of his account, and all of this stuff is related. It’s just not one thing, we’re trying to make it simple. We’re trying to show you how to get started with the top Cyber 21, and in our belief, this is number one. It’s that culture, we got to solve that cultural mission and we got to solve the gap that people don’t want to. I don’t want to know what spear phishing is. I don’t want to know what this stuff is. And the reality is, is you probably don’t, but you got to. You just got to do it. So, you know, I think, Lauren, what’s our next step? Are we going to ask another round of questions here? I believe we are, right?
Jim Bowers
Can I tell you one thing real quick?
Lauren Lev
Oh, of course
Jim Bowers
You know, I say, you know. Yeah, I really think Brian nailed it because I’ve seen this historically through organizations I worked in and, it has to become part of the culture. I think that’s key. All HR departments should be requiring this as part of their onboarding process. They really should because just like anything else from sexual harassment training, right? It’s so critical that you just don’t put the Band-Aid on and think that it’s going to cure the woman you have to continually, continually educate that end user, and I’ll give you an example. I work for an organization that has been in the top right hand Magic Quadrant of NDR EDR for 20 years, and we were having a sales kick-off and they sent out a phishing e-mail. And these are some of the smartest people I’ve ever worked with. And it says, Hey, would you like chicken, fish or steak? For your meal at the sales, kickoff it was a fishing. Ninety two percent of the employees at the cybersecurity firm fell for. So, what I wanted to, to say is yes. Yes. Very smart employee. Very smart employees.
Lauren Lev
I would’ve fell for it. For Sure.
Jim Bowers
Yeah, I fell for it. I don’t like admitting that, but maybe you need to cut that out, edit that out please. But I think at the end of the day is Brian, Stephen, and Sam, are so right on this is so critical in your defense in depth, because if you think how threat actors are thinking today, they love chaos and look what we’ve gone through, it has given them so much content to pull that trigger. Right? And not only that, we’re working on devices not only our own individual laptops or work laptops, but our own BYOB devices. So, we need to carry that education across into our personal life, right? But this is so critical. And I think Brian again, nailed it. It’s not just I run a program. No, it needs to become part of the culture like other key areas of organizations put into that onboarding process for that culture to foster success in the organization.
Matt Tankersley
Thanks, Jim. This could be the most important question of the day. Did you choose steak, chicken or fish?
Jim Bowers
It was steak. It was. I’m a big cow fan, a big steak fan.
Brian Jack
Did you say a mistake or?
Jim Bowers
Oh yes, yes, very good, Brian. It was a mistake.
Brian Jack
I mean, what do you get? Your chance at choosing that or the fish? I mean, it was too obvious to be the fish, right?
Matt Tankersley
Yeah.
Lauren Lev
Well played.
Matt Tankersley
That’s so great. Well, Lauren I’m going to change it up for us. I want to… Let’s start again with ladies first in our last round of questions here. And you know, Sam, tell us about your strategy, in particular at IDAgent, and what differentiates you in the marketplace with your service offering, we’ve talked a little bit about that, but help our listeners focus on why your solution might be the right choice for them?
Samantha Yip
Absolutely. I mean, our solution offers a lot of customization, so you know, that being said, we customize and we work with your organization on how you want to send your security awareness training, how often you want to send it. And in terms of phishing, we also offer how, you know, customization on how, when, when to send your phishing simulation emails, and obviously, we offer a lot of different factors, and that is not sending them all at once so that, you know, everybody’s getting the same phishing simulation at one time. But in terms of further customizing that, if you see something out there in the marketplace or you’re seeing something other, that you actually want to create, maybe phishing kit or training course that we don’t actually have, our tool allows you to kind of customize that as well. So, you can kind of build out your maybe specific training course a specific theme that you want to focus on, or even if you’re seeing something very specific out there in terms of spear phishing, like Stephen mentioned a little bit earlier, you can build on a spear phishing kit that really targets maybe a certain group of your employees. We offer a lot of those customization features and of course, at the end of the day, you do want to find out what is happening in your organization. Who is taking that training? Who’s falling for those phishing simulations? Are they actually exposing credentials during these, during these campaigns? So, we do offer a lot of detailed reporting and analytics surrounding both the training campaigns as well as the phishing campaigns.
Matt Tankersley
Sure. Yeah, and listen, I think I think you might have missed an important one and I want our listeners to hear, right? And if you consider that episode one today is all about security awareness training, it’s all related, right? Next week we’re talking about, or I should say later today, it’s going to be released later, right? Is dark web monitoring, right? What is the correlation between those two? And for those that are tracking episode three, is all about complex passwords and password management. All of these things are so intertwined, and what I didn’t hear you say is the importance of it as a differentiator in the marketplace, how your team approaches, adding dark web monitoring into this security awareness training piece.
Samantha Yip
Absolutely. I wasn’t sure if I should pull that in, but we do-
Matt Tankersley
Absolutely, yeah.
Samantha Yip
We do have dark web monitoring that I think is a basic and any security posture out there as part of defense in depth right, dark web monitoring is, is very proactive, right? So, we are we are looking in the dark web for anything related to your domain, especially the exposed credentials that are out there. So, it is, it works hand in hand. We want to be able to train your employees, train your users, not to expose any company information, company credentials. And if we do, you know incidents happen and I throw out the stats that 80 percent of organizations deal with at least one compromised account per month, and if that compromised credential is out there, we at IDAgent and you have the dark web monitoring service will be able to locate that for you so that when you do find that out, you’re able to take action before anything happens.
Matt Tankersley
So absolutely grateful for that. Thank you. And come back next week for episode two, when Sam’s going to tell us a whole lot more about that. Now, let’s, let’s shift over to- now I heard you, you said, Stephen a minute ago and I said, Stephen, what’s the proper pronunciation there?
Stephen Kowski
Stephen, Stephen.
Matt Tankersley
Stephen, OK, I want to make sure I got it right. Okay.
Stephen Kowski
It was fine my whole life. And then a guy named Steph Curry started playing basketball and then everyone got it confused.
Jim Bowers
Well, I try to put your names in general, Matt. Sorry, you know you were right.
Stephen Kowski
All good.
Matt Tankersley
That’s OK. So, Brian, you’re on deck to round up the last round of questions here before we have closing comments. Steven, let me get your input. What is IronScales doing unique in the marketplace to solve these problems?
Stephen Kowski
Yeah, I think that the big problem for us and we’re really laser focused on that messaging environment. But what we want to kind of surround the users with resources from an awareness perspective and have a proactive approach that helps them in real time make good decisions based on what they’ve already learned in the kind of academic environment. And then frankly, because we have that, you know, we have like three legs of the stool, right? It’s a real-time kind of threat mitigation. It’s, you know, deep knowledge of the user and why that’s important. I’ll just touch on in a second. And then also the human element here with this training. And if you take one of these out, we feel like there’s a significant risk you’re adding to it. That’s one of the things. And one of the issues is, is how many decisions do your users really need to make in a given day if we can bring that down and then, you know, ask them only to make a few quality decisions on is this phishing? Is the spam? Is it safe? Right? We think we’re going to see a better overall response to it, right? And more, more so is we see kind of in our data, as we’re launching these like you’re going to drive the click rate down so far and then that last bit, you know, it’s really hard to get that last 10 to 15 percent. And then, you know, when you listen to you, look at some of our data, we’d even suggest that there’s something afoot if it’s lower than that likely. And the reason why is because two reasons, right? Emails that really don’t translate to templates are becoming hyper personalized when you look at phishing as a service, economies that are emerging. When you look at things like open AI GPT3, you know, we can artificially generate these hyper specific mails that are based on all this information we’re leaving out there in the open, on LinkedIn, on Facebook, on Twitters everywhere, you know. And those environments coupled with, like you said, the chaotic world, the wicked world for lack of a better term. This environment, if I told you all in October 2019, we would be creating a bunch of templates about hand-washing policies phishing and travel policy phishing. You know, this dynamic? It’s not something you can preprogram. It needs to be continuous, but it needs to make sure that it hits that right balance of not too often the right amount. You don’t want to drive a wedge between your technology folks and the rest of your environment by being too aggressive with it too often. And you want to kind of build up those folks that are doing really well and reporting all this stuff, maybe giving rewards, you know, to the top reporters in that type of thing and, and then supporting those folks that need a little bit more realizing why are we in here? We’re not trying to make you, you know, we’re not trying to punish anybody. It’s not a punitive thing. It’s we’re trying to reduce that risk. So, for us, that’s our unique kind of blended approach where it’s real, it’s adding that extra layer, right ring. Ultimately, for us, phishing is a machine and a human problem requires a machine and a human solution. So, you have to give them those means. Also, every admin out there, listening has gotten that email. Hey, what’s this email? Is it phishing? What is this thing? So, automating that, creating an orchestration around that is kind of one of the differentiators, and being a force multiplier that they can respond in real time as the threat will continue to scale over time is kind of how we approach the problem and help those users make good decisions.
Matt Tankersley
I like it. What a great segue does episode nine phishing protection, right? Advanced phishing protection, we’re going to talk about that and clearly a lot of conversation as well.
Stephen Kowski
All right.
Matt Tankersley
All right. So, Brian we’ve got you on deck. Tell us a little bit about KnowBe4. You guys, as you’ve said, are a leader. You’ve been doing this for a long time. What really separates and differentiates you in the marketplace?
Brian Jack
So, our products been around a very long time, like I said. I started in 2010, the company started in 2010 and the model was up into the left. So, over the course of a couple of years in the Gartner quadrant, we went up into the left and we’ve stayed up in that leader’s quadrant. That’s because we’ve made it really easy. Security administrators, I.T. professionals, they don’t have a lot of time. So, they need a solution that can get their users trained, aware, get their culture instilled in those users and train those users and the languages that they need and the styles that they need at the frequency that they want to be trained at. And do it in an automated fashion where you’re don’t have to worry about user management. I had five new users last week. I off boarded 10 users. I got to go in a system. I got to- no. Users thinking, features such as smart groups, which are automatically categorized risky users into certain groups. Maybe they need additional training. Maybe they need additional phishing. Maybe you want apply accounting style phish or business email compromise, or maybe sort of third party compromise phish to the accounting department. Sure, no problem. All your accounting users are already grouped to accounting groups. Just set up a thing. Quarterly, send the accounting phish, the accounting team, and I’ll track the progress over time. It’s very much a set it and it can be a set it and forget it type of tool to where it does not take a lot of time to build a very robust program to get awareness in your users. The other side is we have our product this yare, which is that orchestration piece. So, what happens when a user gets an email and they want to report it? That can go into a system where you can run automation roles, tie into virus total. There’s machine learning built into classify emails, and the interesting part about our system is that it’s specifically trained on emails manually reported by users. Not all emails. It’s very interesting when you apply machine learning to all emails, as opposed to just emails that have been kind of curated by your users. You need different models for that sort of thing. And so, this system brings it all together and it now that our console is translated into different languages too. So, our UI is translated into Japanese for a more global presence. So, if you’re a international cooperation organization, you need to have these ability to have, the different flavors and styles, or does it make sense to send a Bank of America email to your team in Norway? And you’re not helping anybody just wasting time and the cost of an attack is not going away. Sending an email is cheap, compromising a user is far easier and less expensive than trying to scale up on Metasploit and compromise a, you know, unpatched web server. I mean, it can be done, but it’s just easier to send an email. Or pick up the phone. Call them, ask him the old Kevin Mitnick way. Pick up the phone and, and start a conversation about it. Our system does phishing and SMS based tests as well. So, it’s, it’s a platform that can work for very small groups, work for big groups, you know. In a dentist office down the street or in 100,000 employee organization that’s global, it’s the same sort of process.
Matt Tankersley
Well, you know, guys, we’ve talked about this last week. Jim again, this is a constant learning process. It’s not a fixed point in time where the bad guys are never going to go any further. They’re constantly going further. We’re constantly trying to keep up and obviously stay ahead. I think, Stephen, you mentioned earlier because I thought about something, Brian, when you were talking, you mentioned earlier, Steve and then Mike, who hasn’t gotten a report from a user saying, hey is this phishing? Right? We get those all the time. And what’s funny is we have a few tools and tactics as a technical response team to go, let me look a little closer at it and I can tell right away. But then again, sometimes I can’t tell right away. And I knew coming into this series that there were things that I didn’t know yet, and I’m looking forward to learning, and it’s through conversations like this that we begin to learn. I do feel like one of the things that would help our team to help our clients to have more secure, reliable, trusted technology is tools like that. How do we simplify answering that question for a user community that isn’t educated or wants to be educated and wants to be proactive? How can we speed up that process of legitimizing that email? Well, obviously, that’s where some of your anti-phishing technologies come in that we’re going to talk about in the future. But yeah, Jim, any final last thoughts before we go around the horn one last time?
Jim Bowers
Well, yeah, I think, I think again, Brian and Stephen and Samantha were spot on in everything they said. I would like to say probably, I don’t like to make assumptions, but I think Matt you would be in that special group that needs a little more attention within Brian’s software. I mean, I just want to state that out, but I think he said another thing. The attack vector of texting, I think that’s a very, very big point because of how millennials digest information, how we’re moving hosted voice into the cloud and millennials are leveraging cell phones. And you can’t just get a call to a cell phone, I can get a text to a cell phone. So, I think that’s a very relevant piece that we need to understand. It’s just not an e-mail. These are coming in multiple ways. I think we all have gotten the text from the auto warranty, right? I think I get it on a weekly basis, but that’s a valid point that we need to be cognizant, more organizations need to be cognizant of these attack vectors are moving and changing according to how we digest information. And again, it’s not. It’s not a one-time thing. It needs to be a continual process. Again, I’m going to leverage what Brian said. It has to become part of the culture. It really does. And that’s when we start changing the tide from the threat actors who do that. But great, great series, great group of experts here. And it’s been a pleasure talking and speaking to these guys today.
Matt Tankersley
One of our strategies here is guide, is that hopefully, you know, we said motivation quite a bit. We said priority, this is a priority topic. How do we motivate people to engage? And so, I think one of the things that we want to make sure our listeners are hearing right now is that they can reach out to us in a lot of different ways. We can get you a trial for every single one of these vendors, right? We can set up trials for you so you can start learning more about safety, security, awareness, training from KnowBe4 and IronScales, and IDAgent and how each of those plays into the other areas of phishing protection and dark web monitoring and all of those things. And so, I guess unless anybody has anything specific to add about that- I saw a lot of head shaking, so I’m no doubt that we can set up trials for clients. Let’s just maybe kick it over to- we’ll let Samantha close us out before you do Lauren. And final words, Steven.
Stephen Kowski
Yeah. So, one, thank you to TechOnPurpose. Thank you to the other panelists. Really appreciate the time has been a great conversation, but I think for, for us, right, I’ve said it a couple of times, right? We’re trying to put that human at the center of our approach. They are that new end-point. We need to be kind of giving them all the kind of tools that they need to make good decisions throughout their day. But then even when they log off and go home? Right? Translating that into their personal lives as well. Right. So, but I think I said it earlier, but you know, we need to just remember it’s, it’s a risk function. It’s not. And everybody needs to be bought into that right? I don’t care who you are if you’re interacting with the company in a digital way. They really need to understand that they have a stake in keeping the company safe. Right. And so, for us, we think that, that we see a lot, that it’s the biggest obstacle we see out there is, is probably one of mindset, right? We’ve always done it this way, right? We have a different approach. And so, getting folks to kind of think about it in new and creative way instead of some of those other existing ways that have been around for years, right, is one of the biggest things to get around. But we just want to make sure that the users are having great decision making. They’re making combine those both training and threat mitigation all into one kind of place because email’s the number one ingress point, it’s the front door to your organization. You need to harden that in a variety of different ways. And you know, security awareness is a critical piece of that puzzle and folks need to understand that and understand their role in it. So, thank you all very much. Really appreciate the time.
Matt Tankersley
Absolutely, Stephen. And as we as we’ve learned from going through all of your training courses, it’s not just about email, it’s about-
Stephen Kowski
Absolutely.
Matt Tankersley
It’s about social engineering and it’s about all these other topics. It’s not just email, right?
Stephen Kowski
Absolutely.
Matt Tankersley
Stephen, so glad to have you. All right. So, if I’m going to let Sam close out, I guess we’re coming to you, Brian. Closing words?
Brian Jack
Sure thing. This is a huge issue. It’s not going anywhere. Like I said, sending an email is dirt cheap and literally anybody at almost any age nowadays can send a phishing attack. It just does not take very high skill and it still has a really high success rate. So, if you want to change user’s behavior, you got to enable, you’ve got to give them the right tools to use and then you’ve got to teach them how to use those tools right. If you’re going to, if you got to fix a car, install a door, you might not use a hammer, you might need a 10-millimeter socket wrench or something like that. So. Make sure your toolbox has all the tools that an organization needs, because when you have a problem, and you need to solve it you might need that specialized tool. Maybe that’s a particular type of awareness training. Maybe that’s a particular type of technical control or other implementation. You know, it’s not just about send a user training, send a user phishing. Your company has got to have the whole suite in place, and everybody needs to know how to use it. There’s a difference. To set up a firewall, you need the high skilled I.T. guy to do that. To detect an email and report it, everybody in the company has got to know how to use that tool, and they can. All right. Everyone is capable of doing it, but enable them. They feel good about it too. So, that’s it. I encourage you to, if this is something you’re not doing, check out any vendor. You can’t go wrong, just getting your users trained. And then culture wise, see what fits best for you. Not everything works for everyone. So, find the tools that work the best for your organization and your users and use them well.
Matt Tankersley
Thanks, Brian. That’s awesome. Sam, I know it’s the top of the hour. Appreciate it. I think Jim had to run because he had a call at the top of the hour, so he was grateful and said thanks to everybody. Sam, final words, final thoughts for our viewing audience.
Samantha Yip
I’m going to harp on again, culture. I mean, that’s really where it is. We need the buy in of our users to make sure that they are, they know that they have, that they can impact the business, right? They can protect the business. Not to mention the one thing that cybercriminals are trying to steal. It’s our information, right? Why are they trying to steal our information? They make money off this. They sell them in the dark web. So, that’s kind of a slight segue to the next episode that we will be doing. And that’s, that’s why they want this, right? So, we really need to kind of drive home the point on making sure that they’re aware of how they are trying to steal our information. And this is why we need to consider security awareness training courses as a number one, because you get emails all the time. I’m pretty sure all of us started dealing with emails the last, the last hour that we’ve been here talking.
Matt Tankersley
Exactly, exactly.
Samantha Yip
And I want to say thank you. I want to say thank you to the panelists and thank you for TechOnPurpose for having us today to discuss this topic.
Matt Tankersley
Absolutely, our pleasure. Lauren, you’ve got closing comments, take us home.
Lauren Lev
Another great episode in the books. We’re so grateful for each of you taking valuable time to join and share with our viewers today. Hopefully now everyone understands clearly why we’ve made cybersecurity awareness training number one on our top cyber twenty-one best security practices. A special thanks to all of our subscribers and viewers for following the Who’s in Your Cloud, twenty-one steps to secure, reliable, trusted technology journey. Again, I’m Lauren Lev, Marketing Manager for TechOnPurpose, and coming up next week we have episode two, dark web monitoring. On average, the malicious actor is present in an environment for two hundred and eighty-seven days before a breach is even detected. In episode 2, learn how dark web monitoring can help make you aware within hours and not months. Sam from IDAgent will actually be joining us for that episode too, so you have that to look forward to. So lastly, viewers, if you are ready to claim your free NIST cybersecurity assessment, don’t forget to visit WhosinYour.Cloud to get started today. Remember, you can catch every episode of Who’s in Your Cloud by following TechOnPurpose on LinkedIn, Facebook, YouTube and Spotify. Or just sign up for our blog to have episodes delivered to your inbox weekly at TechOnPurpose.net/blog Thank you everyone, and we will see you next week!
Ready for your free cybersecurity survey? Discover potential vulnerabilities for your business and get a copy of our #TOPcyber21 Best Security Practices to help get you started on the road to #secure, reliable, trusted technology!
Subscribe to our blog to get episodes of “Who’s In Your Cloud?” delivered direct to your inbox weekly.


















