Security Confidential S10 E1 Jax Scott

This week on Dark Rhiino Security’s Security Confidential podcast, host Manoj Tandon welcomes Jax Scott. Jax is a cyber influencer, author, speaker, podcaster, President, and Founder of Outpost Gray. With over 13 years of experience working in IT and cyber, both private and public sectors. Jax spent a significant portion of her life serving in the Special Operations Command, spearheading global Cyber, Electronic Warfare, and Intelligence operations. She is also the co-host of the cybersecurity podcast 2CyberChicks.

00:00 Introduction

00:16 Our Guest

01:52 Being in the Special Forces as a Woman

04:30 Cultural Support Team Program

07:47 Jaxs’ Current Mission

09:29 What is an Entry-Level Job?

11:49 How Jax began her journey into Cybersecurity

16:07 Data Breaches: What’s broken?

18:07 Company Policies and Bringing Awareness

19:38 Compliance isn’t security

23:17 NIST vs CMMC vs ISO

27:03 Who uses CMMC?

30:56 Resources for CMMC Outpost Gray CMMC Video

32:12 What should the Federal Government be adopting?

36:45 HackBack

41:58 Connect with Jax

Transcript

Manoj Tandon:
Hello everyone. Welcome to another episode of Dark Rhino Security’s Security Confidential. Today we have a very special guest, Jax Scott. She is a cyber influencer, author, speaker, podcaster, and host of the podcast 2 Cyber Chicks. She has over thirteen years of experience in IT and cyber, both private and public sectors. She spent a significant portion of her life serving in Special Operations Command, spearheading global cyber, electronic warfare, and intelligence operations. She is also the president and founder for Outpost Gray. I don’t know where you get the time to do all that, Jax, but welcome to the show. Thank you.

Jax Scott:
I am happy to be here. It’s awesome that we’ve been trying to make this happen for months now, and there’s been rescheduling, so I’m thrilled to be here. Obviously, we’re going to be talking about a topic I enjoy: cybersecurity. So it’s going to be a good time.

Manoj Tandon:
We’ve had the pleasure of seeing you on TV, and we’re honored to have a celebrity personality here. In cybersecurity, we don’t have that many celebrities, so we’re going to take what we can get here.

Jax Scott:
I think that’s going a little far—celebrity—but I do appreciate it. Thank you. I think that’s because a lot of us are introverted. I’m actually introverted, and we’re like, “No, I don’t really want to be in the spotlight.”

Manoj Tandon:
Speaking of introverted, I would never believe that. But you made a statement that might break the shell a little bit here, and I’ve got to ask it. I’m paraphrasing, but I believe what you had said in the research we had done was: what makes you special as a cyber operations soldier doesn’t make you successful as a civilian woman. What does that mean?

Jax Scott:
Yeah, that’s a great question. That came out of talking about being in the Special Forces and being a woman operator in that space. Just to paint a picture, that’s a very male-dominated space. Cybersecurity is male-dominated, but it’s kind of a different male-dominated. These are males that are trained to be killing machines.

When I was working with them, we were deploying into austere and very kinetic environments, so getting shot at. You have a different mindset. Even though we’re at the forefront and we’re fighting a war within cybersecurity, it’s very different when bullets are flying at you.

The mentality that you take on in that space as a woman is that you have to shed, in a lot of ways, the things that make you so unique as a woman, which is having empathy and being emotional. You can’t be crying in combat when you see your buddy die. You have to be very mission-oriented and mission-focused.

Empathy will get you killed in a lot of ways. So what made me an extremely effective special operator within that space, when I came to the civilian sector and had my first corporate America job in 2019, was very challenging for me. I didn’t really connect with the males in the space, much less the women, because I was what you would call aggressive.

But I wasn’t cussing. I knew better. I had worked in civilian space long enough. I knew having proper English was key and having good communication skills. But what made me different is I was very aggressive, very mission-first, very mission-focused. I didn’t have empathy. I didn’t lead as a leader with empathy. I didn’t have really any true emotions.

Once I started to learn that that’s actually our superpower as women—yes, all women listening out there, it is okay to have empathy and emotion. It is a superpower. I think that’s what makes you and I so unique. I started to realize, “Oh my gosh, I can actually be myself.” But I had to, in a way, shed who I was and what made me successful as an operator in that space, and almost become a new, refined me. Not lose me, just learn how to become a new refined version of Jax to be successful within the civilian space.

Manoj Tandon:
That’s absolutely incredible, and it’s very powerful that you’re willing to embrace both sides. I didn’t realize you were in kinetic situations. At the time, in Special Operations, were women allowed in front-line combat positions?

Jax Scott:
So what’s unique about the role, and a lot of people don’t know about this program that was developed, is the Cultural Support Team program. It was actually established by McChrystal in 2010 because we had an information gap in Afghanistan.

The reason why is the male operators were unable to talk to half the population, which were the women and the children, due to cultural and religious norms. Unless they were directly related to those women and children, they were not allowed to speak to them. So we had a massive information gap.

They established this program, the Cultural Support Team program. The idea was to train women, send us through a physical assessment and selection, psychological evaluations—basically similar to what the males went through, but in a shorter period of time. Then we went through cultural training.

What happened is we went out as two-man teams. It was myself and another CST, and typically an interpreter, a U.S. citizen that spoke the language. We deployed and then embedded and attached onto these teams where we would literally live in the villages.

There were times where I was on a compound and there were twelve people, and I was the single woman. I was with a group called an ODA, and I worked with this element. I helped bridge that gap and get the information off of the women and children to help close the information gap.

During that time, I worked village level, I worked at the government level, and then was afforded an opportunity to go into a direct action team where I did strictly kinetic operations. We would embed at night, we would do our operations, and there were many times that we were surprised. Well, we didn’t really surprise them. They were actually expecting us because somehow the information got out.

What was supposed to be a very short operation turned into a twenty-four-hour operation where we’re bedded down, running out of supplies, and just getting shot at for twelve hours. It was a wild world. A lot of people don’t realize there were women serving in the front, even before women were allowed to go into combat roles, before Congress had approved it. There are a lot of women, and once you do that and try to integrate into the civilian sector, it can be challenging.

Manoj Tandon:
It’s hard for males too. Over about half of our team base here at Dark Rhino is ex-military. What you folks have done and experienced, I don’t think a book or a movie can describe it. Either you have to be there to understand it, or I’ll just have to say we can barely imagine what that was like. But we’re grateful that you folks were there.

Jax Scott:
Absolutely. It was a great experience. It definitely made me grow up and see that we’re very blessed to live where we are and have the comforts that we have and the freedom that we have.

Manoj Tandon:
Until you’re out there in the trenches, you don’t realize what a great place this nation is. Switching from that mission to now, you’re doing so much in the world of cybersecurity, and you’re even hosting your own podcast. What would you describe your current mission as in information security? What are your plans for this generation or our community, if you will?

Jax Scott:
Put out as much information as possible. I’ve never been posed that question, but if I had to answer in a short sentence, that would be it.

I do have a YouTube channel. I do have a podcast. I wrote a book. The book is for entry-level people that are trying to break into the industry, or individuals that have been in the career for maybe less than five years and are still trying to find their footing and pivot. You see people enter and realize, “I didn’t want to be a SOC analyst. I want to maybe be a pentester.”

So I’m all about putting the information out there. I think a lot of this has to do with when I first got into IT, before cyber was a thing, in 2008. I didn’t have a mentor, and there wasn’t a lot of free information out there. Had there been, and had I had a mentor, I think the trajectory of my life would have been very different. I would be in a different place. Obviously, I would not be here having this interview with you, so everything happens for a reason.

But I think that’s why I do what I do now, and I help so much in the community. Giving back will reap so many rewards for yourself, and it just makes me feel good when I see others succeed. So that’s really my mission: keep putting the content out there and really hope it impacts somebody’s life.

Manoj Tandon:
Where do you see the biggest gaps in information? Since you’re putting so much content out there, in your mind, what three or four things do people looking to pivot to cybersecurity need to do well to make that pivot go well?

Jax Scott:
I think the key is that entry-level piece. That’s one of the biggest challenges for individuals trying to break into the space: understanding what is an entry-level job. I have identified a lot of resources, like NICE. I can’t remember what the acronym stands for. It’s under NIST, but NICE has a phenomenal site that actually breaks down what is an entry-level job and then what is the feeder from that job into other positions.

I still think that is an area that needs to be communicated more because we have individuals who say, “I want to be a pentester,” but you and I both know that’s not an entry-level job. So it’s communicating that and then setting realistic expectations.

Then it’s also teaching individuals in this space that recruiting isn’t like recruiting for an HR position or a resource management position. It’s almost a hidden market. In this space, it’s very unique because you have to network. You need to get out there. You have to network. I believe it’s a very different job-hiring process than it is for a lot of different jobs.

And if there is a third thing of information that I think is critical for people to know, it’s that this arena is like no other career field I’ve ever been part of. It’s a community, and it’s a global community. I have so many friends that I’ve worked with all over the world. Again, it goes back to, I don’t think you see that in an HR job as much as you do in this community because there are so many organizations out there, and it’s a global presence. So you are building a global family.

Manoj Tandon:
You’re absolutely right. Just on our show, we’ve had so many women from across the globe, even as far-flung places as Nigeria and Kenya, who are in cybersecurity and are making a difference. It is very much a global community. You couldn’t have said it any better.

I think we all need to learn from each other because this is one area where the fundamentals will apply across the board. When did you pick up cyber? While you were in the armed forces, or was this something in civilian life? What was your first entry-level job then?

Jax Scott:
That’s what’s wild. I will say I was extremely fortunate. Like I mentioned, I broke into IT through the military in 2008, and I was miserable. I hated my life. I was doing SharePoint and help desk, and I actually wanted to get out. I tried to get out. I almost left the military.

Manoj Tandon:
Don’t blame you.

Jax Scott:
I was terrible. I was like, “I want to go as far away from IT as possible.” I won’t go into detail, but long story short, until I broke into cyber in 2019, I had all these opportunities getting thrown at me to join cyber. “Hey, you should join cyber.” It was in capture-the-flag cyber games. “You should work for this company. You should do this.”

Even my units, because I was an electronic warfare officer now—because I got out of IT. I was like, “I’m going to go electronic warfare. I’m going to work on the electromagnetic spectrum. I’m going to get what I thought was far away from IT.” Cyber didn’t work. I kept getting pulled in.

Then in 2019, I deployed to Germany for Atlantic Resolve, an operation where we support NATO operations and stuff. Long story short, they didn’t have a slot for me, but they wanted to bring me because SF works differently. SF will bring talent, and you will fit in where you fit in if they know you have a certain talent set.

They were like, “We’re going to bring you out there as a fire warrant officer,” which is like those big guns. They were like, “You’re going to be in the fire warrant officer slot, even though we know you’re electronic warfare, but you’re probably going to do cyber.”

I’m like, “What?” My sergeant major and my commander told me, “You have two options. You’re either going to succeed or you’re going to fail.” That’s how SF is. They’re like, “Go do great things.”

So I ended up in Europe. I am a warrant officer, so I work very autonomously. I don’t have a team. I’m now in this active-duty cell, and I’m a Guard member, active Guardsman. I’m the only EW. Next thing you know, I just start picking up phone calls, calling people, calling people, and I identify some of the gaps within cyber operations.

Next thing you know, fast-forward, I’m doing all of these forward-deployed operations into Ukraine and Moldova and other areas. I’m starting to help NATO and our host nation partners on their cyber strategy. It literally opened up this entire world for me, and I was like, “Oh my God, there is so much to do in cyber. It’s not just fixing printers.”

That’s when I realized it was different from IT. I can’t tell you how bad I wanted out of the technology space when I say that. But that’s where I went, “I’m going to give this a shot.” Before that, I was working in the intel space a little bit because of my prior experience, and I was afforded an amazing opportunity at a company to do cyber threat intel. That’s where I started. It was not really an entry-level job, and I got slid right in. That’s what I did for the next couple of years. I did cyber threat intel. It was a great experience prior to doing this huge pivot into where I’m at now, the GRC space. But yeah, my journey was not linear by any means.

Manoj Tandon:
And you were a red teamer for a while.

Jax Scott:
Yeah, wild.

Manoj Tandon:
So you very much define the one thing we try to stop in cyber, which is lateral movement. But at the same time, I think for our listeners, it’s important to hear that you said a lot of very profound things there. When you’re looking for that job, understand entry level. You need to get in the door first. Get in the door, and then look at Jax as an example here. Look at how she successfully navigated from position to position. You made your own opportunities, and that’s how you advance.

Cyber is a place where there are so many paths that it’s limitless. Penetration testing is a very small part of it.

Speaking of that, let’s look at the world of data breaches briefly. You can’t open the front page of Apple News or The New York Times and not see some kind of cyber story. Somebody got hacked, something happened. What are we doing wrong? There’s so much information out there. What is broken where resilience is not coming about and we continue to pay these ransoms?

Jax Scott:
That is the million-dollar question, because if we could figure it out, I think we would have fewer breaches. But my answer—Jax’s answer—is I think we’re relying too much on technology and not putting enough emphasis on the personnel to train them up. What is the number one cause of a breach? It is human error, right?

Manoj Tandon:
Human error. I am so glad you said that. That was not designed, people. To all the audience that’s listening, that was not set up. She didn’t even read the questions.

You’re absolutely right. The number one cyber asset in the company is its people.

Jax Scott:
Yeah. We need to go back to the basics. We need to start remembering what one of those basics is. We need to figure out a way—and there are platforms that are coming out—to gamify cybersecurity training. That’s key. We’ve got to get individuals that work in the HR department, that are not directly aligned, like the sales team, to understand how to identify a phishing email and why it’s important that you do not click on it.

What could actually happen? Explain that to them. I think if they could understand it better, instead of this fictional world that they maybe see on TV of what hackers do, I think we could get better at reducing some of these breaches.

Manoj Tandon:
I couldn’t agree with you more. What about policies as well? Companies spending time on implementing good cyber hygiene policies and then raising awareness with their employee base beyond phishing, like don’t pick up a USB drive and stick it into your port from a trade show you went to. Be careful where you’re charging your cell phone, or don’t give your passwords to other people. Really simple things.

Jax Scott:
I think policies are as effective as the leadership behind the policies that support them, but also the procedures that follow the policy. You can have a paper all day that says, “Don’t put any USB into your computer,” but you’re going to need a procedure for that. You’re probably going to need software that prevents that because let’s be honest, employees are still going to try to put a USB in their computer. So we have to prevent that.

I think it’s a holistic approach of not leveraging one too much. You can’t put too much pressure and too much reliance on humans because they’re going to have human error. But we also can’t put too much reliance and trust in our systems. Instead, we need to have a balance all the way around and understand how we can use each of these to overall create a secure environment for ourselves. But there’s not one answer, unfortunately, to make this happen.

Manoj Tandon:
So when we look at the world of this, it takes us right to the world of compliance. Is compliance a false god, Jax? In some way, because we see some of the most compliant companies with the biggest data breaches in the history of data breaches.

Jax Scott:
Yeah. Compliance isn’t security. It is a way to measure your maturity. Obviously, you’re going to be able to, like the NIST Cybersecurity Framework, list as a cybersecurity framework. You can go in; it’s a zero through five, and that organization might be a one or two, and that’s their maturity level.

But even though you might get them to a five optimization, and you know that the set of controls that you’re looking at are optimized at five, doesn’t mean that the adversary isn’t going to be able to leverage one of those vulnerabilities that happen. Microsoft always has vulnerabilities. Doesn’t mean there’s not going to be a zero-day that comes out. Doesn’t mean that one of those phishing emails isn’t going to get past that spam filter and your human is still going to click on it.

You can have all the controls in place. You’re going to have multiple frameworks layered on top of each other: PCI compliant, HIPAA compliant, all these compliances. But again, it goes back to human error, and it goes back to looking at it in—what I love is policy, compliance, systems, like technology to support it, and then that training piece. It’s a holistic approach. You’ve got to have all of those.

Too many people think, “Oh, Target was a great example of this.” I think it was their PCI. They had just gotten the compliance checkmark, gold star, you’re good to go. Less than a month later, their breach happened on their POS system. That’s a perfect example of how compliance is not security and does not protect you. You have got to have both. You’ve got to look at risk holistically.

Manoj Tandon:
That was through an HVAC contractor, no less. Third-party risk. Their SOC apparently—I don’t know the whole story, so I’m just giving the summary—their SOC was getting the right signals. They were just ignoring it.

Jax Scott:
Yeah, it was coming in and they weren’t recognizing it. I don’t remember why. I did a couple of research papers on this, but I remember one of the agencies finally had to step in because it was going on for so long and they weren’t taking action. They finally had to step in, and that’s how they got notified. It’s a wild story. If anybody hasn’t heard it, it’s crazy. But that’s a great example. They were compliant, yet they still got hacked.

Manoj Tandon:
That is wild. You look at JPMorgan got hacked. Marriott got hacked. All those organizations, I am certain, would have immense cybersecurity teams and meet all the compliance standards that are available out there. But we see this so often, Jax, that companies say, “Well, I’m SOC 2 compliant,” or “I’m HIPAA compliant,” and then they say, “That’s my cyber program.” They’re not taking the view that you’re espousing should be done.

Jax Scott:
It is a problem. Not only are we relying too heavily on technology, but we’re relying too heavily on being compliant, air quotes, to guide us in how secure we are.

Manoj Tandon:
Given all these compliance standards, I had a quick question for you. We have a lot of small and medium businesses that are part of our demographic, and in their world, CMMC is coming up, especially if they’re doing work with the federal government. Do you have any insights on NIST versus CMMC versus ISO? What’s a fundamental difference between these programs? Do you have guidance on that?

Jax Scott:
Yeah. I’m pretty familiar with CMMC and NIST. ISO is one of the international standards, and although I’m not familiar with ISO, I have looked at it. In this space, controls are controls, and they’re going to have similarities within those controls and standards.

ISO is more broadly used within the commercial space, where you’ll see NIST more in the federal space. CMMC, Cybersecurity Maturity Model Certification, is actually based off one particular NIST framework, NIST 800-171, which focuses on CUI data, controlled unclassified information.

Just to take a step back, the purpose for CMMC was to secure the supply chain, the defense industrial base supply chain. How they’re doing that is through this certification process of, “Okay, we’re going to come in. You’re going to have this list of controls.” I think it’s 108 controls or something for Level 2. Regardless, it’s a decent amount of controls, and it’s to evaluate specifically.

They already should have other frameworks, maybe NIST 800-53, and they’re going to have, on top of that, 171 to say, “Okay, how are you securing that CUI data? How is it segmented? How is it encrypted?” They overlap on top of each other for that organization to be able to go after and bid on contracts.

What’s really interesting, and people don’t realize this, is even before CMMC was introduced in 2019 by the DoD, organizations were self-attesting that they were already in compliance with this, according to a DFARS rule, I think it is the 7012 rule. They were already saying, “Hey, our CUI data is protected.”

So when CMMC came out, depending on what level you’re at, it’s just taking that power away from those organizations and making them go through a third-party assessment to verify: are you truly protecting your CUI data?

Now we’re realizing, because of the conflict around CMMC, a lot of individuals and organizations are upset about it. To me, that only tells me these organizations were likely, in a way, falsifying that they were indeed having their CUI data protected. I’m probably going to get hate for saying that. But if you were that organization, you were already doing what you were supposed to be doing. If CMMC came out, minus the money—and I know that’s a big issue, the money to get the third-party assessment done—but there are a lot of complaints where some of their arguments don’t have a good base because you should have already been doing this. You are saying you’re already compliant. Now it’s just getting that certification. It’s going to be an interesting space.

Manoj Tandon:
But the one thing with CMMC is it’s not a one-size-fits-all approach, right? The person who’s making the bolts for a particular widget the federal government is using might have a different level of standard to meet than the guy that’s making the embedded software. All the other standards were kind of a one-size-fits-all. CMMC was supposed to offer flexibility.

Jax Scott:
There is some within Version 2.0 now. I haven’t been keeping super abreast of everything within the last couple of months. CMMC sometimes moves like pond water, and then it’s fast and furious. Nothing is happening, crickets, and then all right, now it’s action.

The last I saw was 2.0 was helping create some of that definition for those organizations that may be less at risk. Where you saw that was at Level 2, and Level 2 did the split-off where we saw you could still self-attest or you had to get the third-party assessment done. That was based on what your possible CUI data was, and it was really based around national security risk.

So if you’re Level 3, you’re obviously probably making or supporting military-grade equipment. But that Level 2 is like, is it the guy who just has the bolts, or maybe it’s the individual that helps support making that military-grade equipment? They’re going to have to get that third-party.

I think they’re trying to make it where it does have better definition of who needs what level. But you’re right, it’s definitely not a one-size-fits-all, and I think they’ve got an unrealistic mission, the CMMC AB, to really try to figure out how to put this umbrella over the entire defense industrial base. I think they’re doing the best they can with the tools they have.

Manoj Tandon:
Good, fair points. Let’s see how this plays out. There are a lot of companies still working on that path to CMMC compliance, and let’s see if it makes us safer.

Now, we are talking about unclassified data. I’m assuming for classified information, it’s a completely different path.

Jax Scott:
Yeah, 100%. Just to have classified information, you have to be qualified to have a SCIF, and you go through certain requirements to get that as an organization. You’ve got to go through a whole bunch of other qualifications.

These are just for organizations that have, specifically, that CUI data. It might not be classified. It’s sensitive unclassified information. Somebody listening might say, “But it’s unclassified information.” Correct. But what if you could get the bolts guy’s information, and then you could corroborate his information with the blueprint guy’s, and then you corroborate that with the other guy who supports making the military-grade equipment? You can put that all together, and you could tell a really good story. That’s where it becomes more sensitive in nature, even though it is technically unclassified information.

Manoj Tandon:
What you just described was how Tom Clancy got the information for all his books.

Jax Scott:
Go Tom Clancy. I haven’t read Tom Clancy in a while. I need to check that out. I need to read books other than business books and cyber books or NIST frameworks.

Manoj Tandon:
He did exactly that. People always thought he had access to classified information. I’m sure in the later years, maybe he did. But when he wrote The Hunt for Red October, that was all garnered from public information, putting the pieces together.

In terms of resources, could you point our listeners to any for CMMC? Any sites or any place you can guide them to that would help them on their journey?

Jax Scott:
Yeah. I actually did a CMMC video on my YouTube channel. They can just go to Outpost Gray—gray with an “a.” There’s a CMMC 2.0 video. It explains just what I talked about, like the splitting off at Level 2. It’s actually in way more detail, and it goes through the controls and everything. I think it’s super helpful.

Jacob Horne is also a great resource. The guy is brilliant. Check him out. He’s always in the mix with CMMC.

Then the CMMC AB, I think they have a fan page website that you can go to. It has really good relevant information on where CMMC is and what’s happening in the space. I would encourage attending the monthly town halls when they have them. I haven’t gone in a while, but they’re usually every month, the third Tuesday or something like that.

Manoj Tandon:
Thank you. We’ll let people know in the show notes. That’s good information people can have.

Switching over to a higher-level policy position, what are some of your thoughts on what the federal government should be adopting in terms of policies to make a difference in information security?

Jax Scott:
One of the areas that I’m pretty passionate about is public and private partnerships. It’s an area that I’ve done a lot of research in. Being that most of my career has been in the public sector, the federal sector, I see—like I mentioned about my deployment to Europe in 2019—I really witnessed firsthand how disjointed we were with our public and private partnerships.

There are a lot of challenges having those public-private partnerships: certain titles, Title 10, Title 32, Title 50. But what I want listeners to understand is that the private sector owns the majority of our critical infrastructure. Yet if there was a big data breach or something was to happen, we as the United States federal government, from what I’ve seen, do not have a clear path on how best to support them.

We saw Colonial Pipeline happen. That was a very low-level attack, in my opinion. It could have been much greater from what happened. They were going to be up online, and they even got some of their money back. That was the best situation that we could have seen as far as our critical infrastructure being impacted, but that was just a little bit of a taste.

What if something catastrophic was to happen? Say, for example, Texas has a separate grid that’s separate from the other grids within the United States. What if something happened to that grid that shut down a very large portion of America? How would the public sector go and support that? It’s not clearly defined.

I think that’s an area where our legislature and administration—and they are working on it, and so did the prior presidents before. They are trying to tackle this problem: how are these public-private partnerships going to work? And how are we going to get these industrial leaders to be more secure overall?

That’s the other challenge. They put pressure on them to be more secure, and then the private entities push back and go, “Cool, you pay us to do that. You send us the individuals. You send us the professionals.” So we’ve got to figure this solution out because our adversaries aren’t going to wait for us to figure it out. As you know, our SCADA systems and all those systems are just extremely vulnerable. That’s just one area where I think we need to have more focus.

Manoj Tandon:
Ted Koppel wrote a book on that. I don’t know if you’ve read Lights Out, but he talked about that.

Jax Scott:
No, I’ve heard about this book. I need to read this. I’m writing it down.

Manoj Tandon:
Please do. It’s a good, easy read. You could read it on your next airplane flight. He talks about how critical infrastructure and the grid are very vulnerable, and we’ve known that for a long, long time.

But the private sector saying, “Fine, federal government, you want us to be more secure, you pay for it”—I think this is where the private sector has to take responsibility. They’ve got to step up to the plate.

I think it’s necessary that it forces a change in mindset. This is just my opinion, but the old way of putting in IT systems and procuring them and instantiating them really is not the most effective way to create a cybersecurity umbrella.

Jax Scott:
It’s going to be interesting. I’d love to work more in that space. I’d like to get more involved, maybe at committee levels that are working in the space, specifically within critical infrastructure.

Manoj Tandon:
It’s a rabbit hole.

Real quick, I want to take two minutes and get your opinion on hack back. Could you explain what it is and then your opinion? Do you think it’s an effective approach the administration is putting forth to curb cybercrime?

Jax Scott:
Yeah. Hack back, also known as active cyber defense, is what it was originally called many years ago. Through my research, I’ve identified that the federal government has been recommending active cyber defense since 2005, with professionals in this space explaining that passive defense is not going to be effective long-term, as we’ve seen through the rise in overall breaches and ransomware attacks.

What hack back is referring to is where an organization that has been attacked will then retaliate against that organization, nation-state, or threat group that attacked their systems.

Now, there are a lot of challenges associated with this. One of the biggest ones—and you know this, especially working in your space, and I know it working in red teaming and cyber threat intel—is the word attribution. Really knowing who actually attacked me, right?

So the idea is, “Yeah, that makes total sense,” but the actual execution is much harder to achieve. Where there’s a gap in knowledge, and through the research that I’ve identified, what if we do hack somebody back, but we hack the wrong threat group or nation-state? Maybe we hack China instead of Russia, just as an example. What would happen? What would that retaliation look like? We don’t know what that retaliation would look like.

I know there have been examples where countries identified a hacker, and their retaliation to hacking back was a missile strike. So we obviously want to avoid going from, “They hack us, we hack you,” and now we started kinetic war. It’s a very delicate spot.

What’s interesting is, and it hasn’t come out yet, the current administration has proposed, as part of their national cybersecurity strategy that was supposed to come out three months ago and is still pending, to talk about this active cyber defense, hacking back.

I will tell you through my research—I don’t know if you’re familiar with this—but there was actually a law. Hold on, I have it written down. This was really fascinating when I found out about this law.

As we all know, we know about the Computer Fraud and Abuse Act of 1987. That still today has a lot of influence within our space of cybersecurity, and it also influences this possible hacking back because bottom line, it says hacking another system is illegal.

There was a law that I identified that I had no idea had been presented in 2017. It was H.R. 3270, the Active Cyber Defense Certainty Act, also known—I love this—as ACDC. So ACDC was presented in 2017 to do an amendment to our very old legacy act of the CFAA, to refine it to allow us to be able to take a defensive posture when a threat actor attacked us.

Now, it got turned down and never made it. I think it got dropped in 2019 because there was too much ambiguity and too many individuals who were like, “No.” Obviously, it’s a sensitive topic. That was the first time in legislation that anything had ever been presented on the possible use of hacking back.

Until we can get our federal government on board with this, the key is defining what that is going to look like and making sure that we have that attribution. But you and I both know attribution takes a substantial amount of time. What are we going to do? They hack us, and then we take, what, two months to get attribution to hack them back? Instead of just securing our environment and using those resources to secure the environment. It’s a catch-22.

Manoj Tandon:
Everything you said is spot on. The consequences of hacking back are unpredictable unless you have dead-nuts attribution. Even if you do, not all the time can you predict what that outcome is going to be. But it’s certainly a very interesting concept.

If you look at the SANS sliding scale of cybersecurity, proactive is the right-hand-most side of that. Thinking about what the word proactive meant, it’s a very interesting concept, and let’s see where it goes.

Thank you. I wasn’t familiar with some of those laws myself, and now you’ve given me a little bit of reading to do. Jax, I know we’re just slightly over. I wanted to give the last couple of minutes for you to plug whatever it is that you’d like to plug. Let our listeners know what’s going on. The floor is yours. Let them know whatever you’re thinking here.

Jax Scott:
Absolutely. Thank you, Manoj and everybody, for just having me on the show. I loved it. It was an honor.

If you’re wanting to connect with me, hit me up on LinkedIn, Jax Scott. You can find me there. YouTube, Outpost Gray, gray with an “a.” If you’re going to be in Colorado for the ISSA conference in March, come find me. I will be there speaking about branding.

I do want to end on this note, especially for any individuals out there who may be wanting to break into the industry and are struggling. If you’re listening to this, I would tell you: don’t give up. You will eventually break in. Build your network. Make sure you’re networking with individuals. Leverage LinkedIn as much as you can to build up that network.

Don’t give up the fight because we have a talent shortage. We do need you. So keep making that fight happen. If you have questions, reach out to me. I’m not super responsive on LinkedIn because I’m in school and it’s a lot right now. But this has been outstanding. That’s all I’ve got for wrapping.

Manoj Tandon:
Wrap it up. Thank you so much, Jax. It’s been a real honor. You’re fantastic, and we look forward to having you back sometime in the future as you get more and more involved and have new things. Don’t forget about us. Come back and let us know.

Jax Scott:
Absolutely. Absolutely. Thanks.

Manoj Tandon:
Thank you very much.

To learn more about Jax visit LinkedIn,

Visit Jax on Twitter

Learn more about Jax on her Website

 

Check out the other episodes in Season 10:

Ep. 0 Dark Rhino Security – Oktane Conference

Ep. 1 Jax Scott – Helping Pave the Way for Women in Cyber

Ep. 2 David Meece – The Secrets of LinkedIn’s Algorithm

Ep. 3 Mike Rice – How Smartwatches Lead Iran to U.S. Troops

Ep. 4 Mike Rice – Why is the U.S. Banning Tiktok?

Ep. 5 Shea Nangle – Hack-Back: What does it mean?

Ep. 6 Josh Mason – U.S. Air Force Academy to Teaching Cyber

Ep. 7 Joel Beasley – Stop Playing the Victim Role

Ep. 8 Melissa Thornley – How Do You Build A Leader

Ep. 9 Rory Meikle and Chris Cazel – April 14th Tech News

Ep. 10 Tom Dusenberry- Building Successful Video Games

Jax Scott's profile picture for Dark Rhiino Security's Security Confidential podcast

Jax is a cyber influencer, author, speaker, podcaster, and the President and Founder for Outpost Gray.

With over 13 years of experience working in IT and cyber, both private and public sectors. 

Jax spent a huge portion of her life serving in the Special Operations Command, spearheading global Cyber, Electronic Warfare, and Intelligence operations.

She is also the co-host for the cybersecurity podcast 2CyberChicks.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top