Security Confidential S13 E5 Dr. Eric Cole

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Dr. Eric Cole, a cybersecurity expert, entrepreneur, public figure, and best-selling author. His career has advanced from starting as a professional hacker for the CIA to becoming the 44th President’s commissioner on cyber security. His accomplishments have earned him an induction into the Information Security Hall of Fame and have awarded him as a Cyber Wingman from the US Air Force. His recognition has caught the interest of current clients, who include international banking institutions, Fortune 500 organizations, Bill Gates, and Saudi Aramco.

00:00 Introduction

00:19 Our Guest

01:17 Lady Luck and the CIA

05:19 Revolutionary ideas

06:25 The prioritization of Security

08:45 Cybersecurity is not a technical problem

14:30 Paralyzing with Prevention

19:53 Where good CISOs become world class

26:59 Why is the government not responsible for Cyber?

29:44 What was your advice to President Obama?

35:19 The foundation of a cybersecurity program

41:11 BOOK: Cyber Crisis

43:15 Connecting with Eric

Transcript

Manoj (00:00.944)
Hello everyone, this is your host Manoj Tandon. Welcome to another episode of Dark Rhino Security, Security Confidential. Today we have another awesome guest, Dr. Eric Cole joining us. And does he have a background? He is absolutely a cybersecurity expert. He’s been a hacker with the CIA. He’s a bestselling author. He’s written eight books, his latest being Cyber Crisis.

He has been on President Obama’s commission for cybersecurity. In fact, I think he was the commissioner. He has been inducted into the Information Security Hall of Fame. And he’s, as you can guess, worked with a lot of illustrious organizations from the US Air Force to many Fortune 500 companies. We’re honored to have him here. Thank you, Eric, for joining us. Appreciate your time.

Eric Cole (00:53.014)
My pleasure. And thank you for doing what you do and sharing the message of cybersecurity with the world.

Manoj (00:57.652)
We’re trying, but it’s really folks like you who carry the voice, because nobody really listens to me. But, you know, one good place, and we always start with this, because people always have this curiosity of, how did you get started in cyber? Or was that your training as your background, or how did you come into this? Please enlighten us.

Eric Cole (01:03.454)
I listen to you, my friend. Ha ha ha.

Eric Cole (01:23.138)
I always joke because a lot of kids when they’re little, they have these aspirations of having a certain career when they get older. And to me, I’ve always wanted to be an architect. So like cyber, now remember, I was born early 70s. So cyber security really become a thing until I sort of became an adult. So I’m getting ready to go to college and going into architecture. And a family friend is like,

Eric Cole (01:53.226)
because everything’s going to computers. So if you go into computer science with your analytical mind, you’ll have a lot more potential. So this was in the mid to late 80s, and I go to computer science, which once again is really an engineering degree. And I remember sitting there on a Thursday afternoon in a Fortran programming class going, if this is my future, I don’t want it, right? Because I was like, this is not what I want to do. This is not fun. So for some reason, and I feel like there’s always the hand of fate.

on everyone’s life, something told me that afternoon, I needed to go to the co-op office. And so I listened, I show up to the co-op office at four o’clock, they close at 430, and they’re like, oh, so you must have heard. And I’m like, heard what? They’re like, well, once every two years, the CIA recruits on campus, they’re coming tomorrow, and we have one slot left, do you want it? And I’m like, sure. So I show up.

Manoj (02:49.114)
Wow.

Eric Cole (02:52.622)
And sometimes when you’re naive and you have no idea what’s at stake, you end up doing better. So I didn’t at the time really understand the impact of the situation like you are interviewing with the central intelligence agency. So I show up and just sort of chill and cool and do my thing. And the next thing I know, one thing leads to another and they’re flying me down to DC going through the whole background polygraph and I get an offer to basically work for them.

The office that had the opening, coincidentally, not my choice, was the office of security. And I think you could see how that story got us to where we are today. So it’s a lot of these random events that all just sort of ride up to lead me to where I am today.

Manoj (03:30.031)
Wow!

Manoj (03:36.876)
I was like, back then, and I remember those days well, you know, you had to write your own code. And we were at Fortran 77 or C, and it was on the Vax platform typically, or these probably most of our audience doesn’t even know what half that stuff is. It’s, you know, it’s just, it’s so dated and so ancient. But.

It’s interesting that the cybersecurity was a focus even back then, or is there aspects of it for the CIA?

Eric Cole (04:08.57)
It was a lot, because remember, this was in the 90s before the worldwide web, before e-commerce, before the internet. Even back then, nobody had computers at their house. There wasn’t websites or anything along those lines. So what we were really focused on is really just from an operating system, like the operating systems that are on our computers.

Manoj (04:14.64)
Okay.

Eric Cole (04:36.542)
Are they storing information? Are they secure? So it was really more from a much more granular OS standpoint. And remember floppy disks that weren’t really network. So it was a completely different time and place. But what I love about it is I was there working in security from 90 to 97. So I basically was like at that forefront of when the web came out, we were right there. When e-commerce, right there. So I mean, as these technologies were developed,

Manoj (04:42.468)
Wow.

Eric Cole (05:05.686)
We were right there running across. Now, the only regret I have is I’m like, dude, really? You couldn’t have come up with Google or Amazon? Like, why did I come up with those ideas? Because none of them existed at the time. So it was sort of funny to watch while today we think Google and Amazon are these brilliant ideas. At the time when they came out, you’re like, well, that’s stupid. Who’s gonna buy something off the internet, right? Like when Gif Bezos started Avidod, believe it or not, it was…

Manoj (05:31.095)
Oh, man.

Eric Cole (05:34.826)
Everybody thought it was a stupid idea because we’re like we have Barnes and Nobles. We have Walmart. We have Home Depot Why would anyone buy things? You mean you’re gonna buy something on the internet and have it show up at your front door It just seemed like such a foreign concept But that’s the idea that I’ve realized is the brilliant innovators the people with the brilliant ideas You’re doing things that everyone thinks is crazy. So that’s my new test

When I come up with an idea, if 20 people don’t say it’s crazy, then it’s not a good enough idea, right? You want the crazy ideas because those are the ones that are revolutionary.

Manoj (06:06.952)
Yeah. And you know what the interesting thing with that is that even Google and Amazon were copying and I would say they copied off of Sears Robach and company. Because if you turn back the clock. Sears Robach was allowed America to buy off a catalog in an era when there was just Main Street USA and there was a general store and you could buy everything from a house kit to dynamite out of the Sears Robach catalog.

And I’m sure people back then said, who the hell is gonna order stuff through the mail? We’ll just go down to Charlie’s store, but the concept remains the same, but you’re right. We wouldn’t have guessed how big they have gotten so quickly. That’s happened.

Eric Cole (06:55.818)
And to me, probably the most amazing thing is the shift in what I call the prioritization of security. Like in the, in the nineties and two thousand in the nineties, let’s just do a quick preview in the nineties, security was viewed as an option, a nice to have feature. It wasn’t viewed as something that we had to have, like when you went in and presented security features at companies in the nineties, it was viewed like any other feature. What’s the benefit? What’s the value? What do customers want? Then.

Manoj (07:11.855)
Yes.

Eric Cole (07:25.538)
In 2000 to 2010, 12, we saw the shift where it’s like, no, we really need to have security, but it was still a secondary feature. It was after functionality and everything else. Then we see if we have a little money for security. But then it’s funny to watch now in the last five to seven years, when our security has almost become one of the key core drivers in building any product out there where consumers

even at some level, ask for it of what is the level of security components. And I know even non-technical people, if they go to websites and there’s not two factor or some of the basic security, they step back and go, hmm, is this really a place I want to give my personal information to because are they really going to protect it and keep it safe? So it’s sort of been interesting to watch that role in public perception of ads not really needed. We sort of need it. It’s nice to have to, oh, we must have it to keep our information and data safe.

Manoj (08:23.621)
Now, some of that thinking in certain sectors is there, but there’s a whole bunch of sectors where they are still having difficulty with spending on that. For example, if you look at medical devices or in general, OT devices that are out there. The work you did early on at the CIA where you’re looking at memory storage, how data is being accessed,

those are foundational principles that would still apply even to those devices that are being developed. And you guys kind of pioneered a lot of things. Why is it that they still don’t get that part of it right? Why don’t we have secure PLCs? Why don’t we have secure pacemakers or things of that nature? Yeah.

Eric Cole (09:14.026)
So, to me, it’s real simple and the reason is this. Cybersecurity is not a technical problem. We think it’s a technical problem and because when security first came out and involved IT, we automatically put it under that technical category. That’s why to me, one of the biggest mistakes companies still make is putting the CISO under the CIO. I’m like, no, you’re getting it all wrong. It’s not a technical problem. And here’s the issue.

with technical problems, you can solve it with money. Because IT is a technical problem, uptime availability. If you want to achieve five nines, 99.999% uptime availability, buy more stuff. Buy more redundancy, buy more pipes. And if you buy enough.

Manoj (10:00.556)
this by the way you’re you are preaching to the choir keep going

Eric Cole (10:03.894)
Yep. Yeah. So, so if you go in and buy enough stuff, you can solve it. Cyber security is not a technical problem. It’s a business problem and business problems can’t be solved. They can only be managed. So going back to your question with PLCs and others, it can’t be solved. It can be managed. So the question is this. What is the criticality of a PLC? Now I would argue just if we can play a little devil’s advocate, I would argue

Manoj (10:29.253)
Come here.

Eric Cole (10:34.13)
in OT, super secure if you follow the rules of making them airgapped. They were designed and they were built to be on an airgapped network. That was the security that was built in because you want a PLC to have simplicity of functionality, simplicity of verification. I want the code to be light and tight so I can verify and validate and know exactly what it’s doing. Security adds complexity.

security ads, other things to it. So PLCs were built and designed with security in mind of let’s make the code so light we can verify and validate. And the security premises, these are gonna be on an isolated air gap network connected to reactors or other critical devices with no outside connectivity at all. And I would argue for 20 years, they were secure. They were super solid. You didn’t see any issues or any problems.

issue. Somebody decided to change the rules. Somebody decided to say, let’s take these PLCs and let’s put them on a public network. Let’s make them accessible to the internet. And that is never ever what they were designed to be built for. So I would argue that, hey, if you want PLCs connected to the internet, which by the way, to me is insanity, but if that’s what you want, then great. We need to redesign the whole model.

Manoj (12:02.968)
Well, you know, the-

Eric Cole (12:03.17)
but PLCs are secure, we’re just not following the rules.

Manoj (12:07.536)
And the devil’s advocacy here again, what people would say is we’ve gained operational efficiencies because now we know how to deal with big data. There’s patterns that are available to us in that data from those PLCs that have made great strides in operational efficiency. And if you totally shut it off, then we won’t get that real time monitoring in real time.

ability to variate the process as it’s continuing.

Eric Cole (12:40.662)
Is that true? Is that really true or is that a good, because I will tell you, I’ve sat down with, yeah, okay. Yeah.

Manoj (12:45.512)
I don’t think personally that’s really true. I don’t. I think you could still do that in an air-gapped environment, but you wouldn’t, it would be inconvenient to show that data to outside people. It would be harder to do it. It wouldn’t be readily available.

Eric Cole (13:05.486)
Right? So, this is great case study. So let’s run with it back to my statement where cybersecurity is not a technical problem, it’s a business problem, and business problems can’t be solved, they can only be managed. So here’s what we do with our customers, because I have a lot of customers in this space. I ask them two simple questions. What is the value and benefit of connecting it to the internet? And you just named some. Operational efficiencies, ease of access, all that stuff. Awesome. Pile it up. Then, now give me in this hand,

I realize my camera is small, so I have to move my hands together. So in this hand, let’s cover all the risks and all the exposures. Everything you’re putting at risk, the impact to the company and negativity. So now I have these two piles. Now I ask you a simple question. It’s a really simple question. Does the value and benefit outweigh the risk? Are you willing to accept these risks to your business in order to obtain these values and

And the reality is in most cases, when you present it correctly, when you present both sides of the story, I would say 85% of the time, they make the right decision and go, it’s not worth it. It’s not worth it. But here’s the problem. We’re not basing our decisions on complete data. We’re only taking the one list of value and benefit and going, oh, look at all these values and benefits. We should do it. But they never stack it up against the risk and exposure. And that’s the failure.

Because I’ll tell you what, if you do that, if you come back to me and go, Eric, I understand the value and benefit. I understand the risks and we’re willing to accept the risk. The value and benefit is so great. I’m willing to accept all these risks. That’s awesome. But I don’t know a single company that actually does that. And that’s the failure where they’re basing decisions on incomplete data.

Manoj (14:55.648)
Okay, so we’re gonna put a pin in that because there’s several questions that are gonna come out of that. But playing devil’s advocate again, in that argument where in one hand you’re putting all the benefits and the other you’re putting the risks, there will be those that will say, especially let’s look at critical infrastructure. If you look at air-gapped environments, look what we did.

to Iran with Operation Nitrozeus. That was a completely air-gapped environment, right? We still penetrated it, not through the internet, but with USB drives that spun those centrifuges out of control, right? So it, and it was pure human behavior, leaving a fancy USB stick, sticks.

at various watering holes around the facility in the hopes, well, you work for the CIA, you know human behavior, that someone was gonna pick that up and they’re gonna plug it in to something that they shouldn’t plug it into, which is exactly what happened, right? And at that point it was game over. So the argument would be that if I am a critical infrastructure, if I am PG&E, or I don’t pick, I shouldn’t have, I don’t wanna pick on them for any reason. But if you’re a,

Eric Cole (16:01.71)
Yep. Yeah.

Manoj (16:16.896)
large electric operator or a big water utility or something that’s super critical. They’re like, well, if a nation state really wants in, they’re gonna get in anyways. And in the meantime, I’ve given up the benefits of operational efficiency. And what would be the counter response to that?

Eric Cole (16:42.242)
So you’re saying it’s okay to drive drunk.

I might not get into an accident, but if I’m driving drunk, I greatly increase the probability of doing it. So you’re saying, Eric, because even if I drive sober, even if I do air gaps and I do everything I’m supposed to, I could still get compromised? Even though that could still happen, why even bother put any security in place? We might as well just, since we’re going to get compromised, we might as well make it as easy and as simple for the attacker as possibly can. So because…

I know I’m going to get into an accident anyway, why not just drive drunk and the heck with it, right? So to me, that’s not really the valid argument of saying, because 100% security doesn’t exist, we shouldn’t try. We shouldn’t even put measures in place. But just so you know, I’m teeing you up because we talked about this before the show. So what we’re really talking about is the focus shouldn’t be on the prevention. The focus needs to be on the detection side of the house.

Manoj (17:40.448)
Yes. There you go. And that brings us you couldn’t have done it any better. That’s that’s all. Now, that is it was actually brilliant. It was perfect. And we did talk about this before that, which brings us to a former affiliation you had with the Air Force. And they did this study and they coined the term the prevention paradox.

Eric Cole (17:48.422)
How is that for the transition?

Eric Cole (17:53.838)
HAHAHA

Manoj (18:08.036)
in which their claim was the more you focus on prevention, the less secure you become. Your thoughts, give us a little feedback on that notion. This counter.

Eric Cole (18:19.682)
Yeah, I think it’s spot on. And the reason is this, we need to recognize that in any reasonable sense of the word, 100% security doesn’t exist. I mean, I joke, yeah, I guess we could take a system buried in the ground, fill it with cement, and maybe, maybe we could say it’s 100% secure, but it has zero value. So the law of cybersecurity is, whenever you add functionality,

Manoj (18:29.913)
That’s right.

Eric Cole (18:46.55)
you decrease security, whenever you add functionality, you increase risk. So we need to recognize that attacks are going to happen. What one of my big mottos is, embrace the breach, right? People are so terrified. Oh my God, what if we have a breach? Yeah, you’re gonna have a breach. So don’t be afraid of it, embrace it. But the whole issue is, if you focus all your energy and effort on prevention, and I think this was the point you were making.

you can restrict the system to the point where it’s paralyzing, where nobody can work and nobody can do anything. Like we use your example where we are GAP, so it makes the job harder. But, oh, Eric, they did USBs, great. So let’s block USBs. And you get to the point where you’re paralyzing the environment with so much prevention that nothing can get done.

So the concept, and a lot of people came up with it with different terms, but yeah, like you said, the Air Force, the prevention paradox, the concept is this, wait a second. The goal of security, what is the goal? The goal of security has never been to prevent all attacks. It has never been to stop all attacks. It’s never been to be 100% safe. The goal of cybersecurity,

is timely detection and response. The goal of cybersecurity is to control and minimize the damage. It’s not to prevent all attacks, because guess what? Preventing all attacks is fool’s gold. It can’t be done. So to me, it gets to the problem is, and this is where good CISOs become world-class, where they educate their executives that the goal is not to stop all attacks.

Manoj (20:17.249)
That’s right.

Eric Cole (20:31.89)
I’m the best CISO on the planet, and if you hire me, you’re gonna get compromised. But what I will promise you is, it won’t be for five years and you won’t be paying $10 million in ransom. We’re gonna catch it early, we’re gonna contain it, we’re gonna control it, we’re gonna minimize the damage. You might have 50 records stolen, you won’t have 500 million. So that’s the whole claim that security professionals that are best in their class are focused on how do we create an environment that allows functionality.

but detects and controls damage in a timely manner. And for a lot of world-class security engineers, it’s so foreign to them, because they want to secure the heck out of the system when that’s not our goal.

Manoj (21:11.68)
That’s right. I was gonna say, Eric, I don’t know if too many sizzles who have the cojones to actually make the statement you just made, right? That would actually go to their boards and say, you know, I’m not gonna stop all the breaches. I can’t. If you hire me, I won’t stop all of them. And they’d be like, well, I just won’t get hired then. Or a lot of them, believe it or not, think it’s a short term. Look at the duration of a sizzle. You know, how it’s not exactly a position you retire from in most…

organizations.

Eric Cole (21:43.234)
But why though? Because as soon as a breach happens, what is the playbook for every company? The playbook for almost every company is if a breach happens, the CISO failed because they were supposed to prevent every attack and therefore we fire the CISO. So every CISO, yeah. So, so if you’re, if you’re knowingly taking a CISO job where you know the

Manoj (21:51.216)
Shoot the system.

Manoj (21:59.876)
That’s right. Someone’s always the fall guy. So.

Eric Cole (22:13.322)
is the only solution and if there’s a breach, you’re gonna get fired? You basically have a self-imposed death sentence. You’ve been given a terminal illness where you know for a fact you’re gonna be fired, you just don’t know if it’s three, six, nine, or 12 months. Now the problem is, there’s such a demand for CISOs that if you’ve had a CISO title, you’re almost guaranteed to get another job, that most of them don’t care. But that’s the problem is, CISOs, they’re not willing.

Manoj (22:36.387)
I’m sorry.

Eric Cole (22:40.054)
to have those hard conversations because they know they’re going to get fired, but they know they’re employable. But to me, for cybersecurity to get to a level of maturity that it needs to, we need to start owning the reality that we have to have the conversations that breaches will happen. And the criteria for security has to be on how quick did we detect and how timely did we control the damage and not on binary, did we have a breach or not.

Manoj (23:06.08)
And you know, first of all, you’re a thousand percent correct, but it also gets back to, in a lot of instances, there’s an inherent conflict of interest in most organizations because the Sizzles is reporting into the CIO. And now you’ve got, you know, in a sense, the Wolf guarding the hen house kind of a situation, right? It’s, you need to break that function out completely. And it has to be independent.

to be able to give an honest opinion without repercussions on bonuses, on promotions, on all the other nonsense that people regard, I shouldn’t say nonsense, but things that people consider as being super valuable in their career moves, right?

Eric Cole (23:54.686)
And I even go a step further where it’s not separated out, it’s flip it. And what I mean by that is, what is the definition of cybersecurity? The definition of cybersecurity is, understand, manage and mitigate risk of your critical assets to disclosure, alteration or denial of access. What is IT? Availability. IT is denial of access.

Manoj (24:21.776)
available.

Eric Cole (24:24.466)
IT is one of three areas of cybersecurity. So if we really wanted to do it correctly, your CIO reports to the CISO, your chief risk officer reports to the CISO, your chief data privacy officer reports to the CISO, and then your CISO is one of the top five executives. So you have your CEO, your COO, your CFO, your CISO, and your chief legal officer.

Those are the five that should be running a company. The problem is companies are so confused. They go in and they take the CISO. They bury them under the CIO. Then they create a chief risk officer that actually is a parallel to the CIO. And then they create a chief data privacy officer that they bury under legal. And it’s like, are we really trying?

to make this as confusing and difficult as it possibly can be, because it sure looks like it. They’re just trying to just do these throw-in-the-darts, and nobody ever steps back and say, how should we do this in the most logical way possible? And there’s a really simple solution, but nobody is ever stopping for long enough to actually let rational decisions drive the organizational structure.

Manoj (25:39.096)
But Eric, the solution you propose is such a paradigm shift. That word would apply because you look at this typical sizzle, they are typically not business people in a lot of instances, and they’ve come from technical backgrounds or they’re regarded as being technical people. The CIOs has the big boy chair, right? And…

I won’t argue it, but I think that would be a paradigm shift. It’s a great idea. I think it’s a fantastic idea. I love it when people want to rearrange the chessboard. If you don’t like the way it’s set up, just change it. Ha ha ha.

Eric Cole (26:19.118)
I would argue, look at the data. Aren’t we in need of a paradigm shift? Is what we’re doing working? Why aren’t organizations saying, listen, what we’re doing is not working. Why don’t we do a paradigm shift and mix things up to try to find a solution that does work?

Manoj (26:25.021)
Yeah, absolutely.

Manoj (26:39.732)
It would take a CEO with some serious cojones to pull that off. Now, I’m sure there’s some out there that are fairly avant garde that might listen to this. And if they do and we see a change, we will highlight it. I think it’s a great, what you’re bringing up are foundational issues about managing cybersecurity, managing risk, not 100% security. And that…

I want our audience to understand that. That is foundational and fundamental to what you’re saying. And that’s so important to get, if you’re gonna get cyber right.

if you’re gonna do it. When there’s an argument, and I’ve heard this, not from a lot of companies, but I’ve certainly heard it from companies that, why are we responsible for cyber? Why is the government not responsible for it? Just like when the airlines were responsible for security, we know what a horrible job they did and they all complained and now we have the TSA, right?

Why is that same parallel thought not true in the world of cybersecurity? Because in their minds, a lot of the bad actors are state-sponsored groups. They’re like, well, as a business, we can’t compete with that. So why is this not a government responsibility? Why is this being pinned on us to spend all this money?

Eric Cole (28:13.222)
So to me, a couple of ways to look at that. First and foremost is you could have the safest car on the planet, but if you put an unsafe driver in the seat, they can still get into an accident. So ultimately, it’s the driver of the car that’s responsible for the security of the car, not the people who make the car now.

I don’t let anybody off the hook because I start off talking and I joke. When I get done talking, I piss everybody off because I blame them all. So that’s not saying that the manufacturers of software and hardware shouldn’t make it more secure, but I’m saying companies also have a responsibility for implementing it correctly. But then I’ll also caution those, be careful of what you ask for. Do you really want the government?

telling you and dictating what level of security you should have within your organization and holding you legally and liably responsible for that. Now, I think because companies, many have been asleep at the wheel, I think it’s gonna come to that, but I don’t think it’s gonna be as pretty as everybody wants because if you study and know how

Washington DC does things, how Congress and the White House passes laws. It’s not in the best interest of the people that are affected by it. It’s what’s in the best interest of the people writing and passing the law. So I’ll tell you, when it gets to that point, which it will if we continue down this road of companies not taking the responsibility, it’s not going to be the prettiest thing on the planet. But the government at some point is going to have to jump in.

Manoj (29:50.704)
That’s right.

Eric Cole (30:05.674)
and start regulating at some level if companies don’t start taking that ownership for protecting and securing their information.

Manoj (30:13.956)
What was your advice to the president when you were in that role on how to tackle this problem or some policy directives?

Eric Cole (30:24.958)
I mean, to me, it was more on national security measures. So it was more on how do we protect the nation as a whole to implement better security and protection measures, not more focused on individual companies. But my whole premise was, and it’s talking about paradigm shift, I think that’s my middle name. My parents just didn’t know it when they named me. But…

Manoj (30:29.968)
Okay.

Eric Cole (30:53.57)
Look at the internet today. The core backbone of the internet is run by the United States. And this might or might not shock you, but it’s a question I’ve been asking for 10 years and nobody can answer.

Manoj (30:57.424)
Okay.

Eric Cole (31:13.582)
Give me a list of all the connection points the United States has to the internet. Because if most of the attacks are coming from Russia or China or other areas, why don’t we just block those? And the answer is we can’t because we are the internet. Like we cannot answer that. I will tell you, I do work for Saudi Arabia. They can answer that question. They have a list of all their connections to the internet and they do a great job of blocking different traffic.

When you’re in Saudi Arabia, there are certain sites you cannot access. They are blocked at a national level. They are not blocked at an ISP level. So Russia, the same way, it didn’t make the news, which shocked me. But last year, Russia actually went in and disconnected from the internet for 48 hours. Yeah. Just to show that they could, and they could isolate and they did it as an operational readiness.

Manoj (32:05.54)
Really?

Eric Cole (32:12.77)
for the overall country and military that if there was a, if I believe we’re in a cyber war, but if there was a more overt cyber war and they needed to protect their country, they could do that. Most countries can. The United States cannot because the internet and the backbone of the United States are exactly the same. So to me, what I believe the government should have done instead of spending.

trillions of dollars during COVID on God knows what, they should have spent, I mean, that money on basically redesigning and separating out the backbone of the internet from the US connectivity to the internet. So this way we’re like every other country where we can control and manage the traffic that flows in and out to our borders. We have amazing border patrol physically. We have zero border patrol when it comes cyber.

Manoj (33:03.095)
Right?

Eric Cole (33:08.022)
Yet cyber is where more damage and more attacks are coming from. Why is that? So that was really when I worked on with the White House and other commissions, that’s really my whole soapbox that I’m on is we need to start isolating, segmenting, and designing the internet correctly so there’s a backbone and then there’s countries that connect to it. But right now, every other country is independent, but the United States and the backbone are one and the same.

Manoj (33:38.24)
Isn’t there an advantage as well though, on the one hand that’s a weakness, on the other, because we are the backbone and everyone is cycling through it, we have visibility to all the stuff that’s going on. So in terms of learning other people’s capabilities, methods, tactics, techniques, procedures, what they’re up to, what they’re thinking, what they’re not thinking.

We have a lot of visibility to that. I would assume the folks at the CIA and NSA do, at least.

Eric Cole (34:09.55)
So I hear you in theory, but in reality, there’s a couple of problems. One, all the traffic is encrypted, so we really can’t see it anymore. And two, no, internal to internal country communication doesn’t go across the backbone of the internet. It’s only inter-country communication. And then the other problem is it’s so much traffic that’s controlled by independent private entities.

that we really don’t have the visibility that you think we would have. So I would argue there’s perceived benefits, but based on the dismantled way it’s organized, we don’t actually take advantage of any of those benefits.

Manoj (34:55.888)
Okay, I learned something new today. I always thought that with the immense computational capability that the NSA has developed and their ability to pick out voices just off of cell phone calls, certainly tracking somebody across the web would be well within their capability to do at their discretion if they so chose to do it.

Eric Cole (35:19.342)
Because I like to stay alive, we’ll just, uh, what’s the next question? And I want to keep you alive too, my friend.

Manoj (35:22.512)
Okay, I like that. Well, you know, I, you know, I think, well, I think by virtue of the so many podcasts where these kinds of topics have come up, I’m sure they’re listening in on my wire and that’s good for them, you know. Do you want to know what a little cybersecurity company’s up to? Rock and roll, man. Help us out. You know, so.

So, you know, getting back to, there’s this balance between technology, understanding business specific risk, understanding of process gaps, and understanding of human behavior. If you think of it, these, I always think that these are five elements that you need to kind of, need to bring together into some kind of cohesive structure if you’re gonna build a real cybersecurity program. How do…

How do you do that? That’s a lot. If you think about it, the sizzle would be like human behavior. What do I have to do with that? Understanding gaps in process. Well, I’m just tech. I can tell you how our firewalls are set up. I can tell you how we do two factor. But do they understand the way they conduct business? Might be creating process gaps that are allowing unintended visibility.

Eric Cole (36:50.018)
I mean, to me, I agree with you completely. The way I would sort of summarize it is sort of two things. One is simplicity is the name of the game. If you look at most of these breaches, most of these issues, most of these problems, and I say most, not all, I just want to be clear here because there’s always exceptions to the rule. But if we focus on the word most and not all, most of these problems are created by functionality

that is not really needed or used. We love making things overly complicated. We love chasing new crazy features and functionality when we don’t use that. Look at the average person. I love doing this when I do live events. I’ll ask for a volunteer. And I’ll say, give me your cell phone. And they’ll give me their cell phone. And I’ll proceed to count how many apps they have on their phone.

Manoj (37:35.12)
Okay?

Eric Cole (37:45.454)
page after page after page. And it’s like, on average people have hundreds of hundreds of apps. I then go under usage. And in most cases, if you’re looking at monthly, just 30 days, they’ve only used 3% of the apps on their phone. Yet every single one of those apps is code that is running.

functionality that is enabled and potential exposures and vulnerabilities on their system. Why? Because it was easy, because it was free, because those are habits that we’ve developed that are really, really bad. But the reality is if we just went in and simplified most devices, we only put functionality you need. Not that you want or desire, but that you only need, and we remove all the extra stuff, a lot of these vulnerabilities start to go away very, very quickly.

So that’s one theme. The other theme that we have to recognize, I joked that world-class CISOs minored in psychology because you got to understand human nature. Human nature is simple. Nobody likes having things taken away from them, but if they don’t know they’re being taken away and they’re not using it, then nobody cares. I will tell you that this is a trick

Manoj (38:55.408)
All right.

Manoj (39:09.208)
That’s right.

Eric Cole (39:12.062)
I use with client after client and I’ve experiment with it. What is the number one, number one, number one method on why systems are compromised? Attachments and embedded links in email. Number one, and if we need to narrow it down, today it’s all embedded links. People are getting these scams, these spams from all these places. You think it’s from legitimate shipping services, e-commerce, your bank. You click on the link, it compromises your system.

So I used to go in and socialize. Hey, starting next week, we’re gonna block all embedded links. We’re gonna basically take them out and you have to go to the legitimate site. We’re not gonna allow it. Well, you would think I was going in and murdering people.

You can’t do that. Like, they were going nuts. They were revolting. They were going crazy. I mean, I would be in boardrooms and the vice presidents, you can’t do that. You’re taking away our rights. I mean, people go nuts. So then I had this amazing idea. I just did it and didn’t tell anybody. And guess what happened? Nothing. Nobody noticed. Nobody cared. And nobody did anything. Now, I’m not saying.

Manoj (40:19.352)
Just take it away.

Manoj (40:24.981)
Nothing.

Eric Cole (40:30.87)
You bypass your executive team. So when I’m a Vsiso, I tell the executives, they’re fully aware of what we’re doing. I say, trust me, if you want to simplify security, spend less money and be more secure, here’s how we do it. We’re just going to go in and covertly for any external untrusted sites, we’re just going to disable and remove embedded links. They’re just not going to be there in the email. No choice, no option, no nothing. And nothing, nobody will notice. And what happens is you do it. And all of a sudden,

the incidents, the breaches, the compromises drop significantly and nobody complains, nobody notices, and nobody does anything. So the name of the game is do your research, find the functionality that’s creating the biggest exposures, and I would bet nine times out of 10, nobody’s even using them or care about them. And if you remove them and simplify, that’s one of the best ways to secure your organization with minimal to no impact.

Manoj (41:30.848)
That’s brilliant. That was worth the price of entry, which was free by the way, but. Yeah. But you know what? Well, let’s get to something that you do get to charge for. Let’s briefly talk about your book, Cyber Crisis. What’s the driver behind it? What’s your message there?

Eric Cole (41:36.814)
I’m like, you’re charging, I’m gonna start charging you man!

Eric Cole (41:52.41)
So the driver behind all my books is always to solve a problem that’s not there. So a couple of years ago, I’m sitting there with some executives and they’re like, Eric, we need a simple business book written in English that executives can understand. Quick read, read it on an airplane, read it in a week, you know, I mean, simple language, but just to understand and explain the basic concepts of cybersecurity.

Piece of cake. I said, book has to exist. I said, I’ll research, I’ll find the book for you and I’ll tell you about it. I started buying all these books with these titles that look good. And they were all technical books with business titles. And I’m like, there was no good book that in two hours could explain the principles and concepts of cybersecurity to a business person. So what I do best is I solve the problem. So that’s why I wrote Cyber Crisis

high level quick overview read, so business executives can quickly understand and know the questions they need to ask so they can make the decisions that positively impact security and their environment. Because here’s the reality, executives are concerned about security. It is one of their top priorities, but nobody ever trained them. Nobody ever taught them. And most CISOs are technical. So your CISO comes in speaking techie, your exec has no clue.

Manoj (43:11.404)
Yeah, they don’t know what questions to ask.

Eric Cole (43:20.374)
what they’re saying, they have no idea what to ask, and you have this disconnect that creates friction. What I tried to do with cyber crisis is minimize the friction so everybody can speak the same language.

Manoj (43:32.524)
That’s wonderful. And it’s a much needed item. I can just say that. Everything you’ve said there is true and a lot of executives don’t, they completely don’t understand it and they don’t know what the questions to ask are. And that’s foundational. We’re at the hour. I wanna make sure we give you at least a minute to plug anything you want to plug. So please, the floor is yours. Is there anything you wanna let our audience know about? Whatever it is.

Eric Cole (43:58.894)
I mean, the big thing I want to plug is even though I have services that I charge for and all those things, to me, if you want those, you can find them on your own. What I want to plug is my job is to share knowledge and information and to make the world a safer place. I believe my purpose is to secure cyberspace. So I urge you follow me online on one of the social media platforms at Dr. Eric Cole, D-R-E-R-I-C-C-O-L-E.

I go live every day, I put a lot of this free content out there. There’s no charge, I don’t upsell because I want to make the world a safer place. The way we do that is through exactly what my friend is doing with this podcast by educating people. I would love to keep being your mentor and your guide for free. Follow me on social media where I have a lot of free content so we can continue to make

Manoj (44:48.772)
Well, Eric, that’s a wonderfully noble cause, and we’re grateful for you doing it. And we would love to have you back because I think we’ve only scratched the surface. And maybe we will get in trouble with certain agencies next time you’re on. But…

Eric Cole (45:05.046)
And thank you for saying that, because to me, that’s the ultimate compliment. Being asked to come on a show once, great. When you’re asked to come back again, that’s the ultimate compliment, so thank you, my friend.

Manoj (45:14.06)
Thank you so much, Eric. Dr. Cole, everyone, thank you.

Eric’s LinkedIn

Eric’s Book: Cyber Crisis

Eric’s Youtube

Check out the other episodes in Season 13:

Ep. 0 Chris Cazel and Rory Meikle – Streaming Services vs Cable

Ep. 1 Chris Rock – Shelf Babies: Killing and Birthing someone virtually

Ep. 2 Joseph Steinberg – Humans are the Achilles heel in Security

Ep. 3 Dave Sobel – Boring is Perception

Ep. 4 Aaron Painter – Holiday Season Verification Attacks

Ep. 5 Dr. Eric Cole – Where good CISOs become world-class

Ep. 6 Angela Bergsma – Paving the Way for Latina’s in Cyber

Ep. 7 Matt Brown – Why do 99% of Start-ups die

Ep. 8 James Potter – When you’re small, you’re the easiest target

Ep. 9 Chandra Pandey – Will the SIEM ever be Automated by AI?

Ep. 10 Troy Fine – Learning through Experience

podcast promo for Dr. Eric Cole on Dark Rhiino Security's Security Confidential podcast. Dark rhino security

Dr. Eric Cole, Ph.D., is a cybersecurity expert, entrepreneur, public figure, and best-selling author. Dr. Cole has built a solid reputation in the cybersecurity industry over the last three decades. His career has advanced from starting as a professional hacker for the CIA to becoming the 44th President’s commissioner on cyber security. His accomplishments have earned him an induction into the Information Security Hall of Fame and have awarded him as a Cyber Wingman from the US Air Force. His recognition has caught the interest of current clients, who include international banking institutions, Fortune 500 organizations, Bill Gates, and Saudi Aramco. His entrepreneurial accomplishments include three successful exits building eight-, nine-, and ten-figure organizations. Secure Anchor Consulting is his fourth cyber security business venture.

Aside from his seasoned technical expertise, Dr. Cole is a well-known public figure and author of various publications. He recently released his eighth book, Cyber Crisis, which debuted at #1 on the Wall Street Journal’s bestseller list. Dr. Cole’s accomplishments are consequential to fulfilling his goal of providing relief in cybersecurity, and his mission: to make cyberspace a safe place to live, work, and raise a family

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top