
Purposeful Communication Through PlexTrac with Dan DeCloss
We’re joined by sponsor and guest Dan DeCloss, CEO and Founder of PlexTrac, on the podcast today to talk about communication and collaboration between the red and blue side of cybersecurity and why security success depends on those two sides working together. On their mission to build stronger, more productive, and well-rounded security teams, PlexTrac provides incredible and insightful metric and messaging tools that change the game for the cybersecurity industry. Timecoded Guide: [05:36] Understanding PlexTrac’s history and mission for cybersecurity teams [09:58] Lack of empathy and understanding in red team and blue team communication [18:48] Breaking through the resentment and confusion within a team [24:45] Envisioning the future of PlexTrac’s community impact [27:52] Caring about your cybersecurity mission beyond yourself Sponsors: Thank you to our sponsors Axonius and PlexTrac for bringing this season of HVR to life! Life is complex. But it’s not about avoiding challenges or fearing failure. Just ask Simone Biles — the greatest gymnast of all time. Want to learn more about how Simone controls complexity? Watch her video at axonius.com/simone PlexTrac is pleased to offer an exclusive Red Team Content Bundle for Hacker Valley listeners. This bundle contains both our "Writing a Killer Penetration Test Report" and "Effective Purple Teaming" white papers in ONE awesome package. Head to PlexTrac.com/HackerValley to learn more about the platform and get your copy today! What is the function of PlexTrac that would help you the most as a pen tester? With prior hands-on experience on the red side, Dan found his journey to creating PlexTrac to be full of moments where he wanted to fix the same problems he encountered over and over with reporting and communicating. One of these problems was solved easily with the addition of a video feature, a simple function that has existed since PlexTrac first began but is instrumental and is a huge time-saver for visual learners. “As a pen tester, I hated finding that I had 20-odd screenshots if it's a pretty complex exploit. I think the adage for us is like, if a picture's worth 1,000 words, then a video is worth 1,000 pictures, right?” What do you think are some of the gaps in skills that organizations face when hiring these professionals to perform offensive operations? Communication is key— not just in life, but in this episode. While we’ve discussed skills gaps previously in cybersecurity, Dan is quick to point out that a consistent gap he sees in all areas of cybersecurity is effective communication. PlexTrac keeps this struggle to communicate in mind and creates easy, simple pathways and functions that encourage communication and facilitate collaborative problem solving. “If there's one area that I really emphasize with anybody that I'm mentoring or have hired in the past is, as a security person, whether you're red or blue, you really do need to be a good communicator and be able to communicate risk effectively within the right context.” What would you want to say to those folks that don't see eye-to-eye from the red or the blue side? We’re fighting the same fight, no matter if we’re on the red side or the blue side of cybersecurity. Dan’s message for our warring red and blue teams throughout the industry is to understand the importance of your mission and to not let relationships between red and blue feel clouded with misunderstanding or resentment. No one’s job is harder than anyone else’s, and each role on offensive and defensive plays a part in our collective victory. “I'm gonna just be point blank about it…Are you trying to just prove a point about your knowledge and your skills? Or, are you actually trying to make the world a safer place?” What would you want to say to all those folks out there [in cybersecurity]? As PlexTrac aims to make a huge impact on our community, Dan and his team acknowledge a need for a unified, focused, and collaborative cybersecurity industry, with hard workers on both the red and blue sides. With PlexTrac’s assistance in making reports, measurable results, and communication that much easier, our team at Hacker Valley is thankful to be a part of PlexTrac’s amazing network and can’t wait to share more tools like this with all of you. “I think keep fighting the good fight, for both sides, and recognizing that your mission is vital to the safety and security of your organization and the world at large, right? We are all in this battle together.” ---------- Links: Spend some time with our guest, Dan DeCloss, on LinkedIn, and the PlexTrac website Keep up with Hacker Valley on our website, LinkedIn, Instagram, and Twitter. Follow Ron Eddings on Twitter and LinkedIn Catch up with Chris Cochran on Twitter and LinkedIn
18 Aug 202235min

Confident Communication through Storytelling with Anne Ricketts
Anne Ricketts, Founder & Principal of Lighthouse Communications, brings her techniques for public speaking and presenting to the show to help Chris and Ron unpack unhelpful mindsets around storytelling and unhealthy speaking habits. Covering the basics from filler words to hand gestures, eye contact to working the camera, Anne explains the role storytelling plays in the way people communicate at the office, out in public in their free time, virtually on Zoom, and even onstage at events like TEDx. Timecoded Guide: [00:00] Why Anne became a communication coach [05:16] How COVID impacted public speaking and presentations [12:57] Why you shouldn’t stop hand gesturing [18:38] How to stop saying “um”, “like,” “so,” and other filler words [22:45] What makes storytelling an essential career communication tool Sponsor Links: Thank you to our sponsors Axonius and AttackIQ for bringing this episode to life! Complexity is increasing and manual asset inventory approaches no longer cut it. That's where Axonius comes in. Take control of security complexities by uncovering gaps in your organization. Sign up for a free walk through of the platform at axonius.com/get-a-tour AttackIQ - better insights, better decisions, and real security outcomes. That's why we partnered with them to create free cybersecurity trainings! Check it out at academy.attackiq.com Why was communication coaching your chosen profession? Anne wasn’t always a communication coach, but she’s always been passionate about helping others speak. In fact, prior to 2013, Anne taught English as a second language to a variety of people, first in Italy, then in San Francisco. When Anne founded Lighthouse Communications, her goal was to help everyone, English speaking or not, communicate efficiently and confidently. Speaking skills and storytelling talent can open up a world of opportunities for anyone, and Anne is excited that she can help others unlock their potential everyday. “I really like helping people because there's so many small things you can do to look more confident, like the way you stand or projecting your voice. If you look more confident, you start to feel more confident.” In the past two years, because of the pandemic, what have been the ways that you've seen communication coaching change? With so few events and courses happening in-person, Anne had to shift her mindset around coaching and her advice she gives to clients. Virtual presentation unlocked a new world of communication, but comes with new rules and a learning curve. Thankfully, Anne has learned to love the world of virtual and believes that when professionals give their all to connecting with their audience, amazing communication can still occur, even from long distances away. “Normally, when teaching a class, you can see if someone's struggling or confused, you can walk over and connect with them. Everything was happening so fast in the Zoom room, I personally felt like I started from scratch.” How could someone who isn't the biggest fan of small talk reset and reframe small talk in a way that's valuable for them? Networking and communicating can feel like a chore, especially when small talk is involved. Anne believes that small talk, as awkward and boring as it may be, allows professionals an amazing opportunity to practice connecting with others on a small scale and hone their listening and storytelling skills. Ask curious questions to connect with others during small talk moments, and don’t fear the occasional awkwardness that comes with meeting someone new. “If you want to be good at small talk, it's just being curious. Asking questions like, ‘Hey, what's that in your background?,’ or in person, ‘Tell me more about yourself. Oh, interesting. Where did you go to school?’ Asking specific follow up questions and just being curious.” What advice would you have for anyone that has impactful details to share, but doesn't really know how to make it into a story? Storytelling is one of the most valuable skills a professional can learn, according to Anne. Stories allow us an opportunity to connect with others emotionally and mentally, and can even inspire someone to action with the power of simple words. Anne’s biggest advice around the art of storytelling is to practice. Listen to the stories others tell, build your experiences around a framework that feels personally right to you, and practice, practice, practice. “What makes for a good story is tension, emotion. We want to know what was going through your head during that security hack, what was the reaction, what was at stake, and that's not necessarily, on an everyday basis, how we're trained to speak at work.” --------------- Links: Keep up with Anne Ricketts on LinkedIn Check out Lighthouse Communications on LinkedIn and their website https://www.youtube.com/watch?v=xDI32BRr2pY Connect with Ron Eddings on LinkedIn and Twitter Connect with Chris Cochran on LinkedIn and Twitter Purchase a HVS t-shirt at our shop Continue the conversation by joining our Discord Check out Hacker Valley Media and Hacker Valley Studio
16 Aug 202230min

Representation Without Technicalities with Mari Galloway
We’re breaking down the concept of difference makers this week, and we couldn’t help but call upon Mari Galloway, CEO of Women’s Society of Cyberjutsu, to be our guest during this conversation. As a black woman in cybersecurity who has dedicated a large portion of her career to helping women and girls become a part of the cyber community on both the technical and non-technical sides, Mari is a stunning example of making a difference and creating a path to expand cybersecurity beyond stereotypes. Timecoded Guide: [01:29] Defining the difference makers and explaining the OODA loop [13:52] Introducing Mari and the Women’s Society of Cyberjutsu [20:14] Finding her purpose in helping others find their purpose [25:06] Explaining the roles and paths available outside of strictly technical [30:31] Understanding imposter syndrome and forging a freedom-based career journey Sponsor Links: Thank you to our sponsors Axonius and PlexTrac for bringing this season of HVR to life! Life is complex. But it’s not about avoiding challenges or fearing failure. Just ask Simone Biles — the greatest gymnast of all time. Want to learn more about how Simone controls complexity? Watch her video at axonius.com/simone PlexTrac is pleased to offer an exclusive Red Team Content Bundle for Hacker Valley listeners. This bundle contains both our "Writing a Killer Penetration Test Report" and "Effective Purple Teaming" white papers in ONE awesome package. Head to PlexTrac.com/HackerValley to learn more about the platform and get your copy today! What is that like to see people go from taking that original red pill all the way through starting their career in cybersecurity? When we talk about making a difference, many of us don’t get to see our impact as clearly as the Women’s Society of Cyberjutsu sometimes gets to see. Mari tells us numerous stories of women throughout this episode, including herself, who became a part of this industry because of the instrumental work they do in outreach and education. For Mari, seeing women change their minds and majors to become a part of the tech industry shows how vital this work is. “These are the moments we're waiting for, whether it's one person or 50 million people. We want you to feel confident enough to get the skills you need, get in the industry, continue to refine those skills, and be super successful.” What would you equate your purpose to, and how does everything you do fit into it? Like many of us, Mari isn’t entirely sure what her purpose is, but she knows that she enjoys helping the next generation and making a difference in the landscape of cybersecurity. Working with a nonprofit is not an easy job, even if it is rewarding, and Mari still prioritizes her freedom alongside meeting her purpose. No matter what Mari’s future holds, she knows that this work and this purpose to help others will always find her. “I think as I get older, as I start to take steps back to just kind of look at what's happened and the impact that I'm having and others around me are having on the next generation of folks coming up, I think my purpose is to help people. It's to help other people see their potential.” How do you feel like creating that safe environment has affected others? Helping others find their footing in the cybersecurity industry can be extremely rewarding, especially when Mari found herself in a situation of uncertainty when she first joined the Cyberjutsu Tribe. The community of cybersecurity and the stereotypes around hackers can feel incredibly uninviting from the outside. Offering people, especially women and young girls, an opportunity to step into a safe space where they can ask anything has been huge for Mari. “We call it our Cyberjutsu Tribe, and we want to make sure that anybody that comes to us feels like they can reach out and touch us and ask us questions and get answers and just have a conversation with us.” How do we invite more people in and let them know that there are opportunities in cyber outside of technical roles? Whether you’re hacking, selling, managing, or marketing, there is a space for you in the cybersecurity world. You don’t have to code or to be extremely technical to fit in this industry anymore, and you don’t have to have a certain look. The Women’s Society of Cyberjutsu prioritizes educating people on every role involved in the industry and showing them that they don’t have to be a tech wizard or a computer guru to find a satisfying and profitable position. “You don't have to look like this to be a hacker. You can look like me…That stereotype, I think, is dying, as we see the number of women coming in and men coming into the space that don't look like that anymore.” Links: Spend some time with our guest, Mari Galloway, on LinkedIn, Twitter, her website , and the Women’s Society of Cyberjutsu website. Keep up with Hacker Valley on our website, LinkedIn, Instagram, and Twitter. Follow Ron Eddings on Twitter. Catch up with Chris Cochan on Twitter.
11 Aug 202242min

Security Team Operating Systems with Christian Hyatt
Christian Hyatt, CEO & Co-Founder of risk3sixty, knows the secret to building a strong cybersecurity team, and he calls it: Security Team Operating Systems. Walking through his entrepreneurial journey from inspiration as a young child to discovering his interest in the new phenomenon of cyber to co-founding risk3sixty, Christian covers every aspect of intelligent leading and team building. Ready to take your team to the next level? Christian knows 5 key elements you won’t want to miss. Timecoded Guide: [00:00] Tackling cybersecurity as a business owner in an emerging industry [07:04] Building better teams with an emphasis on core values [14:16] Noticing the potential of decentralized technology and data [18:51] Stepping away from hands-on technician work to be the boss [22:37] Leading healthy teams through missions, KPIs, and meeting cadences Sponsor Links: Thank you to our sponsors Axonius and AttackIQ for bringing this episode to life! Want to learn more about how Mindbody enhanced their asset visibility and increased their cybersecurity maturity rating with Axonius? Check out axonius.com/mindbody AttackIQ - better insights, better decisions, and real security outcomes. That's why we partnered with them to create free cybersecurity trainings! Check it out at academy.attackiq.com Where did the journey of wanting to be a cybersecurity and privacy business owner begin for you? While many guests on Hacker Valley take the journey from technician to eventual business founder, Christian felt the urge to become an entrepreneur from a young age. Watching his father and grandfather run their own businesses, Christian understood the responsibilities of taking this journey and wanted to make an impact in an industry that was blossoming with potential. Cybersecurity came into Christian’s life later, when he was employed at a consulting industry, but he saw the potential for growth immediately and wanted to be a part of it. “Along the way, what I learned about myself is I really love building teams. When we built risk3sixty, we were really culture-oriented, even from the early days. We were thinking about scaling the business, career plans, coaching plans, culture kind of stuff.” What are some of the lessons you’ve learned in the process of building your team at risk3sixty? Christian cites the books Traction by Gino Wickman and Scaling Up by Verne Harnish as two of his biggest inspirations and influences for team building early on in his entrepreneurial journey. Both of these authors heavily focus on the people element of professional teams, and Christian has implemented that same approach when forming cybersecurity and privacy teams at risk3sixty. The right people in the right positions will make or break a company, which is why risk3sixty has training and apprenticeship programs in place to build a strong foundation of skills with people who are passionate about learning and growing with the company. “It turns out, if you get the right people in the door, you invest in them, you coach with them, you develop relationships, they're going to serve your clients like no one else is going to do it. They're gonna be part of that mission, they're gonna want to serve, and you do great work.” Now that you aren’t as hands-on with security assessments as a CEO, what have you learned from the bigger picture, macro-perspective role you have now? Many cybersecurity technicians feel understandably cautious about taking over C-level positions because of the lack of hands-on technical assessment work. However, for Christian, he’s enjoyed gaining a different perspective on the industry and learning the “why” behind the “what” as CEO of risk3sixty. As CEO, Christian is able to better understand overarching trends and changes in the security assessments his company performs and has the opportunity to talk directly with security executives about opportunities for growth and investment. “You can walk into an organization and if they don't have a strong leader at the helm, they don't have a security team operating system, they're a little bit dysfunctional, I know already that I'm going to see some problems in there.” What are the most important characteristics that you're finding for folks that are leading really healthy cybersecurity teams? Security team operating systems are made up of the non-technical skills and characteristics that make a team effective. When Christian’s team at risk3sixty needed to hone in on these specific elements, they narrowed it down to 5. Teams need to have a (1) defined purpose and mission to go after and a (2) core set of values to not only guide them through their work, but also understand their (3) set of expected behaviors and standards. There also have to be (4) consistent meeting cadences in place and (5) a solid, standard process of goal setting, KPIs, and score carding. “A great team defines their purpose and mission. Usually, that’s aligned with a business objective. It might be about protecting data, it might be about customer trust, whatever it is that makes sense for that business, they've set a mission that that team can rally around.” --------------- Links: Keep up with Christian Hyatt on LinkedIn Check out risk3sixty on LinkedIn and the risk3sixty website. Connect with Ron Eddings on LinkedIn and Twitter Connect with Chris Cochran on LinkedIn and Twitter Purchase a HVS t-shirt at our shop Continue the conversation by joining our Discord Check out Hacker Valley Media and Hacker Valley Studio
9 Aug 202227min

Learning from Cybersecurity Legends with Davin Jackson
Those on the red team may not be household names to the everyday person, but they are absolutely legends and icons in the world of cybersecurity and hacking. While we have our personal favorite hackers between the two of us, we also invite our guest, Davin Jackson, to share his favorite cybersecurity legends and the lessons he’s learned from them. Timecode Guide: [00:50] The importance of red teaming, especially during this season [02:17] Ron and Chris’ first experience working in a red team environment [11:23] Communication and collaboration between blue and red [16:53] Knowledge gained from Davin Jackson’s humble beginnings in tech [22:19] Gaining the blue perspective with Hacker Valley Blue Thank you to our sponsors Axonius and PlexTrac for bringing this season of HVR to life! Life is complex. But it’s not about avoiding challenges or fearing failure. Just ask Simone Biles — the greatest gymnast of all time. Want to learn more about how Simone controls complexity? Watch her video at axonius.com/simone PlexTrac is pleased to offer an exclusive Red Team Content Bundle for Hacker Valley listeners. This bundle contains both our "Writing a Killer Penetration Test Report" and "Effective Purple Teaming" white papers in ONE awesome package. Head to PlexTrac.com/HackerValley to learn more about the platform and get your copy today! _____________ Legends, Icons, Teachers, and Friends From Marcus Carey to Johnny Long, we’re excited to share the legends that had an early influence and lasting impact on our careers in cybersecurity. While our two backgrounds in red teaming are different, we can attribute so much of our success and our ability to share our knowledge with all of you to the experts that were willing to invite us to join and learn the best hacking techniques alongside them. “I think that's the most important thing in red teaming, it’s passing that knowledge on to someone else.” - Chris Cochran Communication, collaboration, and community instead of red vs blue It is not two teams with two separate fights when we’re talking about red teams and blue teams. Often, when cybersecurity is too focused on this split between offensive and defensive, we forget to collaborate and fall short of improving on issues we discovered. Communication between red and blue can be a costly struggle, which is why we’re happy to see our sponsor PlexTrac stepping in to develop communication technology for these teams. “There's this push and pull of collaboration. On one hand, you want the red team to work autonomously…but on the other hand, they do need insight if you’re going to go deeper and deeper.” - Ron Eddings Legends met, lessons learned, tech loneliness understood In the latter half of our episode, we’re joined by Hacker Valley Blue host Davin Jackson, also known as DJax Alpha. Davin started his cybersecurity journey with no computer of his own. Working his way up from basic tech jobs at corporations like Circuit City, lessons Davin learned from the legends he looked up to include finding a mentor, focusing on networking (even when it feels like a dead end), and being always willing to share what you’ve learned. “It’s about consistency, and you have to have self control and discipline…It’s one thing to get it, but it’s another to maintain that success.” - Davin ---------- Spend some time with our guest, Davin Jackson (DJax Alpha/Alpha Cyber Security) on his website, Twitter, Instagram, Facebook, and weekly on the Hacker Valley Blue podcast. Follow Ron Eddings on Twitter and LinkedIn Catch up with Chris Cochan on Twitter and LinkedIn Keep up with Hacker Valley on our website, LinkedIn, Instagram, and Twitter.
4 Aug 202229min

Finding the Right IT Teacher with Kevin Apolinario
Kevin Apolinario, better known as Kevtech IT Support on Youtube, brings his teaching skills to Hacker Valley to talk about the barriers to entry in IT. Disheartened by the lack of good advice given to him as he entered the tech world, Kev breaks down programs and concepts, such as helpdesk, for IT practitioners that may not have access to expensive equipment or formal education. Anyone can learn IT, and it’s Kev’s mission to help everyone find the method and the teacher that helps them learn the best. Timecoded Guide: [00:00] Forming Kevtech IT Support to give the right IT advice [07:21] Helpdesk success through customer service skills [11:49] Printers on VPNs and other major IT troubleshooting lessons [15:56] Customizing teaching and learning experiences for each IT practitioner [19:54] Better IT and cyber online communities through shared passion Sponsor Links: Thank you to our sponsors Axonius and AttackIQ for bringing this episode to life! Want to learn more about how Mindbody enhanced their asset visibility and increased their cybersecurity maturity rating with Axonius? Check out axonius.com/mindbody AttackIQ - better insights, better decisions, and real security outcomes. That's why we partnered with them to create free cybersecurity trainings! Check it out at academy.attackiq.com What was your inspiration to start teaching as Kevtech IT Support? Kev hardly had a traditional journey into IT, instead having jobs in the restaurant industry and law enforcement before even considering entering the tech world. When Kev became a Field Technician for the Department of Education and began learning the ropes of IT, he realized there weren’t resources available for someone of his background to learn simple concepts or master common technical programs. After dealing with the frustrations of education gaps and unreliable advice, Kev decided to be the person for new IT technicians to learn from. “My journey was rough, because I didn't have anyone guiding me, I didn't have anyone telling me what certs to get. I didn't have anyone telling me the tips and tricks for starting in IT.” Was it intentional to interweave your name and brand and have them be synonymous? Hacker Valley feels synonymous with Chris and Ron’s branding for themselves, and Kev maintains a similar element of that with Kevtech IT Support, especially considering he weaves his name directly into his branding. For Kev, this was an entirely purposeful decision, born out of his own desire to be known as Kev, the helpdesk IT guru on YouTube. Building a brand with authenticity about who he is personally and professionally shows other IT professionals that their work or education experiences don’t have to be separate from who they really are. “That was on purpose for me because I always wanted to be known as the helpdesk guru of IT. Someone that does IT superbly and helps everyone…I wanted to actually show people real-life experiences.” How would you go about having a tough conversation with somebody whose passion isn’t in IT or cyber? Some people are just in it for the money, whether that “it” is IT or cybersecurity. Considering the spotlight being placed on cyber labor shortages and tech skills gaps, many professionals have considered joining the field without the passion to support their new job shift. Although Kev believes everyone should be welcome to learn about IT, he understands that there’s a cause of concern in making IT all about the money. The industry needs passionate individuals, Kev explains, and the desire to learn needs to be present when you take that next step into IT. “I'm sorry, but this field is not for everyone. If you're going to work helpdesk, or IT support, you need to know how to deal with customer service, you need to know how to deal with people.” What piece of advice would you have for cyber or IT professionals looking to level up their community? From Kev’s perspective, gatekeeping isn’t just mean, it’s legitimately harmful to the IT community. IT professionals can’t level up without leaders willing to step up and teach their knowledge. Hiding IT tips or tricks doesn’t save careers, it only succeeds in hurting other IT practitioners and negatively impacting customers relying on that expertise. Kev advocates for increasing transparency within the IT and cyber communities, and explains that gaining knowledge should be valued more than capital gains by practitioners and professionals. “I believe in helping the community, I believe in sharing your knowledge. So, the more engaged you get with the community, the better it is for everyone.” --------------- Links: Keep up with Kevin Apolinario on LinkedIn Check out Kevtech IT Support on YouTube and Discord Connect with Ron Eddings on LinkedIn and Twitter Connect with Chris Cochran on LinkedIn and Twitter Purchase a HVS t-shirt at our shop Continue the conversation by joining our Discord Check out Hacker Valley Media and Hacker Valley Studio
2 Aug 202224min

Making Hacking Accessible with Deviant Ollam
In this season of Hacker Valley Red, we focus on cybersecurity legends in offensive operations with a legend in the physical pen testing and lockpicking: Deviant Ollam. As a pioneer in our industry and an author of two incredible books about lockpicking, Deviant shares his history from hobbyist to professional and all that he’s learned along the way about making the secrets of the hacking world accessible to all. Timecoded Guide: [01:28] Defining the pioneers in cybersecurity [08:47] Deviant’s first explorations in lockpicking [16:03] Accessing and democratizing hacking secrets [18:58] Becoming an author to transfer his knowledge [23:12] Seeing the past, present, and future of hacking Sponsor Links: Thank you to our sponsors Axonius and PlexTrac for bringing this season of HVR to life! Life is complex. But it’s not about avoiding challenges or fearing failure. Just ask Simone Biles — the greatest gymnast of all time. Want to learn more about how Simone controls complexity? Watch her video at axonius.com/simone PlexTrac is pleased to offer an exclusive Red Team Content Bundle for Hacker Valley listeners. This bundle contains both our "Writing a Killer Penetration Test Report" and "Effective Purple Teaming" white papers in ONE awesome package. Head to PlexTrac.com/HackerValley to learn more about the platform and get your copy! And be sure to come say hello to us at Black Hat at Booth #1686! ---------------- What does it mean to be a pioneer in cybersecurity? As our season focuses on legends, it’s important that we explain what makes these individuals such a vital part of our community. In the case of this episode, we explain that our guest Deviant is nothing short of a pioneer. Deviant has been willing to take on new challenges and revolutionize the industry throughout his career, influencing hundreds of individuals and leaving a lasting educational impact on the entire industry. “That ‘zero to one’ part can be the hardest part of any progression in any field, but especially in cybersecurity.” — Chris When you reflect on changing this whole industry, how does that make you feel? Despite our guest’s legendary reputation, Deviant is humble about his achievements, caring more about how his work has impacted others than himself. What he focuses most on in his teaching, presentations, and writing is making lockpicking and penetration testing accessible and understandable. Instead of harboring secrets and perpetuating exclusionary policies, Deviant wants anyone to be able to master these skills and understand this knowledge. “I’m not the first one who ever did this. What I like to think of my contributions is that they have chiefly been making it accessible and democratizing this knowledge.” — Deviant Do you think it's harder today to stand out than it was a couple decades ago? For Deviant, our globalized internet and algorithm-focus social media sites are both a blessing and a curse. While knowledge can be found on every corner of the web and anyone can become familiar with information that was once borderline inaccessible, Deviant also recognizes that younger hackers and lockpickers will have a very different rise to success than he did years ago, especially due to fragmented audiences and tricky algorithms. “We have more avenues to put yourself on display, to put yourself out there than ever before, but that means the audience is fragmented and is spread so thin.” — Deviant What piece of advice would you have for the folks that want to make an impact in security and technology and in our community today? Although success will look different for newer members of our cybersecurity community, Deviant is confident that the younger innovative minds of the future will be able to solve so many of the long-standing problems within our industry. However, he reminds our younger audience that they need to still respect the tenured members of the cybersecurity world and to learn from them without oversimplifying the issues past professionals have faced. “Start thinking about it in a way that doesn’t use ‘just,’ because every old head in the industry has heard that….We couldn’t ‘just’ do it, or we would’ve ‘just’ done it.” - Deviant ------ LINKS: Spend some time with our guest, Deviant Ollam, on his website, Twitter, Instagram, and Youtube channel. Keep up with Hacker Valley on our website, LinkedIn, Instagram, and Twitter. Follow Ron Eddings on Twitter. Catch up with Chris Cochan on Twitter.
28 Jul 202234min

Cyber Espionage & Entrepreneurship with Karim Hijazi
Karim Hijazi, Founder & CEO at Prevailion and host of the Introverted Iconoclast podcast, comes to Hacker Valley Studio to discuss his varied experiences in entrepreneurship. With a humble start in bartending, Karim explains how learning about people inspired his exploration into counterespionage and cybersecurity. Armed with stories from the streets of NYC to the hallways of his own companies, this episode is a look into the mind of a successful entrepreneur and founder of 2 incredible businesses. Timecoded Guide: [00:00] Bartending in NYC and its overlap with espionage and entrepreneurship [07:14] Real-life knowledge application in cyber intelligence [12:15] Founding Unveillance and being acquired by Mandiant [18:22] Karim’s entrepreneurial mindset and his journey with Prevailion [24:51] DIY podcasting with Introverted Iconoclast and learning to tell his stories Sponsor Links: Thank you to our sponsors Axonius and AttackIQ for bringing this episode to life! Want to learn more about how Mindbody enhanced their asset visibility and increased their cybersecurity maturity rating with Axonius? Check out axonius.com/mindbody AttackIQ - better insights, better decisions, and real security outcomes. That's why we partnered with them to create free cybersecurity trainings! Check it out at academy.attackiq.com How do your experiences in bartending and espionage overlap? The jobs taken as a means to an end just might teach something invaluable. This was the case for Karim, who took a job bartending to make ends meet while he figured out what he wanted to do with his future. At the time, cybersecurity and counterespionage weren’t on Karim’s radar, but bartending taught him about people; how they act when they want something and how to connect with them even in the busiest and most public places. Learning this changed the game for Karim when he got into the espionage world and assisted him even more so when he became an entrepreneur in the industry. “It's just learning the way to slowly gain a confidence level with someone. It's actually where the word "con man" comes from, confidence man. Ultimately, that is how you get the information you need.” What are the different aspects that organizations or individuals look at with counterintelligence? At Karim’s own firm, the shift from competitive intelligence to counterintelligence focused around three security aspects. One, identifying weak spots and vulnerabilities, noticing your points of exploitations and vectors of attack. Two, taking advantage of disinformation, using it to root out moles within an organization and throw off cyber adversaries. Finally, three, finding out where your information is going and noticing where there is weaker security than your own. Karim emphasizes that in this third aspect, it is not so much about an organization’s strategy when the information is still at home. It’s harder to secure information once it goes elsewhere. “A controlled rumor within an organization can do several things. It can weed out a mole that you may have, a spy within your organization that maybe you don't know about, that's been able to be hired and gotten through the background checks and whatnot.” When you look back to starting your journey as an entrepreneur, what are some of the wrong assumptions you made early on? Karim, like many entrepreneurs, was under the impression when he founded his first company, Unveillance, that he should be seeking to hire, not to do anything himself. While hiring is an important part of being a business owner, Karim has realized that it's better to learn how every piece of the machine of a company works before hiring. Trying things out for himself and taking a chance on his own abilities hasn’t been easy, but it’s made him a better leader for his employees. If they drop the ball or need his assistance, he’s able to lead from a place of understanding and call the shots with his own vision in mind and his own knowledge to back him up. “As a CEO, it's almost imperative for you to go and try it all, even if you fumble through it and you get by with something that is subpar. It's better to have tried it and understand it, so now you know how to call the shots a little better.” What prompted you to start your podcast, Introverted Iconoclast? Ironically enough, Karim’s podcast was a do-it-yourself project born out of having an employee drop the ball on creating it for him. Relying on himself and struggling his way through the beginning, Karim realized that podcasting is not just about the equipment and the idea behind it, it’s about the stories being told. Focusing on the lead up and context around some of his own career stories and professional highlights, Karim was able to discover the rhythm for his podcast and build a solid foundation of content that opened up doors for new topics to be addressed and new guests to welcome onto his show. “It's very cathartic for me. Speaking the stories out loud, rather than just sort of regaling people over a dinner or thinking back on them nostalgically, is extremely interesting because you remember things you don't remember when you're casually talking about them.” --------------- Links: Keep up with Karim Hijazi on LinkedIn and Twitter Check out Prevailion on their website Connect with Ron Eddings on LinkedIn and Twitter Connect with Chris Cochran on LinkedIn and Twitter Purchase a HVS t-shirt at our shop Continue the conversation by joining our Discord Check out Hacker Valley Media and Hacker Valley Studio
26 Jul 202233min