This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Christopher Rees. Chris is a professional information technologist, author, trainer, manager, lifelong learner, and Former Law Enforcement Officer. He has been creating courses for over 25 years and has been working as an author on Pluralsight for 11 years. He has created over 80 IT Certification training courses (52 or so with Pluralsight), and his students have watched over 1 million hours of his content. Chris really enjoys helping people advance in their careers through training and personal development.
Chapter Titles:
00:00 Introduction
05:20 What were some of the cybercrimes you came across?
10:30 Deep fake stress
13:49 What is the strategy to break up the back up?
17:17 Method and Approach for understanding risk
24:31 Interactive labs
29:57 Will AI change training methods? Will it replace SOC Jobs?
38:40 Elevate your career
41:00 Check out his Pluralsight courses
Audio:
Important Links:
Transcript
Manoj Tandon (00:01.228)
Hello everyone, this is your host Manoj Tandon. Welcome to another episode of Dark Rhiino Security Security Confidential. Today we have yet another great guest. Before I announce him, please reminding you to hit the like and subscribe button. It helps with the algorithms. It helps us keep bringing this great content to you. So do us a favor, hit the like and subscribe button. Now, while you guys are all here is to listen to
Chris Rees, he’s our guest today. Chris has been in the industry for many, many years. He’s a professional information technologist, an author, a trainer, a manager, and a lifelong learner, as he likes to put it. You know, he’s created over 80 IT certification and training courses. 52 or so have been on Plurisight. And his students have watched over a million hours of his content.
which is really very impressive. So he really enjoys helping people advance in their careers through training and personal development. He’s a former law enforcement officer. Thank you for being here, Chris. Appreciate it.
Christopher Rees (01:13.068)
Absolutely. Thank you very much as well. It’s pleasure and honor to be here today.
Manoj Tandon (01:17.452)
Yeah, likewise. So tell us a little bit about your background. You were in law enforcement before and you
Christopher Rees (01:22.616)
Sure. Yeah. Yeah. Started out my career in law enforcement back in the early 90s. I was there for about seven years, seven, eight years. Came from a law enforcement family. So my father was a 40 year police officer, police chief. My brother, had sister-in-law, cousins. Basically the whole family in some capacity was law enforcement. My grandfather was a representative. So he was in politics, not so much as far as law enforcement, but public service. And so that’s kind of where…
things started off. I started really getting into IT way before I got into law enforcement, should say tech. Back when I was like, say fourth or fifth grade, we had a, they called it a gifted program back then you go like a half day to a different school. And you would learn about computers and back then it was like TRS 80s and TI 99s on cassette, cassette decks with storage, it was no disk drives or none of that, no hard drives, no disk drives.
Manoj Tandon (02:05.74)
Okay.
Manoj Tandon (02:17.014)
You know that stuff dates you. I don’t know how many people even know what a trash AD is, but…
Christopher Rees (02:21.87)
Yeah, that was where I got started. So I was doing that for the longest time. I used to run bulletin boards, BBS systems back way before we had the internet back before AOL or Prodigy or any of those things. So I was really involved in tech from the outset. I kind of grew up in it, which a lot of my peers did not. It was much later for them. So I had a very strong interest in that from starting out. And so even when I went into law enforcement, I always tried to kind of marry the two together.
So after a few years in patrol, I went into detectives and started doing computer crime investigations and things kind of went on from there. So developed a deeper, deeper kind of a passion for tech in general and started picking up some certifications and doing some, some side learning in addition to law enforcement. So I picked up certifications around like MCSE, A plus network plus server plus, and so forth. And I had a couple offers to start teaching on the side, which a lot of, a lot of
Police do, right? A lot of folks have side hustles. I used to work a lot of paid jobs as well. And this was a little safer, a little bit better schedule. So that kind of one thing led to another and I had an offer to start teaching. And it was a tough decision in all honesty. I I left after about seven, seven and a half years and it was a bit of identity crisis. You know, I talked to my wife. I just started having, we just started having, you know, kids and building our family. So it was definitely a tough decision. Not one that I took lightly, but…
I think in retrospect, it was a great opportunity and one that I’m thankful that I was able to make that leap. yeah, it was a challenge for a moment, but I started teaching full-time day classes, evening classes. then long story short, one of my students in one of the online or the physical classes I was in brought to my attention a couple of online learning classes. that was really brand new back then. And so I took a look at a few of them and…
There was a company, still around, still good company, CBT Nuggets. They had just started out. I think they basically just had NT4.0 at that point. And so I reached out to those folks and said, I’m interested. I like the format, but I actually found a couple of mistakes in some of the training. And they were like, well, we’ve sold thousands of these. No one’s ever come back with mistake. You have an eye for detail. Would you be interested in?
Christopher Rees (04:41.454)
you know, potentially becoming a trainer or at least auditioning. I’m like, sure. So tried that, um, went through a little bit of an audition process and, uh, kind of the rest is history that, that went well. I was a trainer for them for a number of years. Um, actually I think the very first trainer they had besides the, the owner at that point. that, that went on for a while and it was a great experience. Then I moved on to, um, doing my own thing for a bit of, for a period of time. And then in 2014,
Manoj Tandon (04:44.108)
Okay.
Christopher Rees (05:08.11)
Pluralsight, I was introduced to those folks and was able to jump over and start creating training for that company. That’s been a great experience as well ever since. So with Pluralsight, as you mentioned, I’ve done 50, I think 52 courses now on security plus is the main stay. So I’ve been doing that one since 2014 and it’s been SY0401, 501, 601, 701. So each new iteration of that course,
Manoj Tandon (05:22.762)
Okay.
Christopher Rees (05:36.276)
I update the training and make it new and relevant for that specific courseware. And then I’ve done some stuff on disaster recovery and business continuity, malware analysis, high level courses, some security management courses, and then some end user training around like social media and personal privacy and AI, like a primer on AI and just cybersecurity in general, things along those lines. Another course coming out shortly on basically cybersecurity around internet of things.
Whatever basically is applicable and relevant in the industry, I try to keep up on and make it not just informative, but enjoyable. try to really make the analogies between real world things you may run into and the technical aspects, but not so much so that it’s a snooze fest. as we know, technology can get really deep very quickly. if you don’t make it engaging, people just they’ll drop off quickly. Yeah.
Manoj Tandon (06:27.81)
Absolutely. Keeping their attention is a challenge, especially I’m sure a lot of these topics can get very, very deep, very, very quickly, right? And you can get lost in the technical jungle quite rapidly. And it’s hard to keep someone’s attention. That’s an art.
Christopher Rees (06:43.918)
Mm-hmm.
Christopher Rees (06:54.082)
Mm-hmm.
Manoj Tandon (06:55.65)
So I have to ask you a couple questions as you were describing your background here. In the early days, what were some of the cyber crimes that you came across or computer crimes? And have they changed that much to today?
Christopher Rees (07:12.428)
Yeah, that’s a good question. Well, the short answer is, well, they’re always evolving, but at its base, it’s a lot of the same stuff over and over again, because cybersecurity really is not a lot of times a technical problem. It’s more of like a people problem with a tech interface. So people do the same silly things, the same dumb things over and over again. The tools they use might get more advanced, but a lot of it is social engineering. A lot of it is preying on people’s goodwill and people
just assume that people are doing things for the right reasons. So they’ll give information more freely than they should. When I started out, and again, this is back in the early 90s. So cyber crime was usually either like bank fraud or those types of things, or somebody hacking an account, which was relatively new and easy back then. wasn’t very sophisticated. Or a lot of it was like online predator type of investigations. And those things…
I mean, even, you know, it’s evolved into Dateline and I used to do this similar types of things before Dateline was even a show. And that amazes me still to this day that the same exact things happen now even is popular or as well known as those things are people are still getting, you know, caught up and still getting, you know, snagging those types of scams, or not scams, incidents just because it’s like I said, it’s a mind, it’s a mindset thing. It’s not a technology thing.
Manoj Tandon (08:36.714)
So glad you said that. I think our audience is probably tired of hearing me say that, but cybersecurity is not an IT problem. It is a business problem. that is, all you can do is manage it. You’re not gonna solve it in its entirety, because it’s a behavioral issue, as you very rightfully pointed out. Now, has the cast of characters changed? back then, like now we see…
Christopher Rees (08:46.572)
Mm-hmm.
Christopher Rees (08:50.499)
Right.
Manoj Tandon (09:00.642)
You have the ransomware for hire, you have ransomware as a service, or a lot of people in the Far East or Asia, Middle East, Africa, a lot of international bad actors. What was it back then?
Christopher Rees (09:18.36)
Yeah, back then, like I said, it was a lot less sophisticated. yeah, there wasn’t really as widespread, at least the things that I ran into were not as widespread. It was much more localized. The only real thing, like I said, when I was doing the online investigations, it really, back then it was a totally different environment because most people did not have laptops. Most people didn’t have webcams or if they did, they weren’t built into every device we have like we have today.
The big takeaway we’d always tell folks is like, you know, don’t let your kids take their laptops or their computers up to the room and monitor what they’re doing, have it in public spaces. That’s kind of going away because everyone has laptops now, everyone has phones and have cameras. So that’s a lot harder to monitor. But as far as the actual cast of characters, to your point, it’s much different now as far as just the global reach. Like I used to say, prior to…
the advent of the internet and even going back before that, like prodigy and chat rooms and all those different things. You used to have to worry about like the person down the street. Now you have to worry about the person on the other side of the town or the country or the state or whatever, because it just makes everything much more consolidated. that your child in this instance could be talking to someone across the country as easily as they could talk to someone across the state or across town or next to a neighbor. And I’ve had cases where people would travel multiple states away to meet with whoever and
Manoj Tandon (10:17.877)
Right.
Christopher Rees (10:43.222)
It was never, obviously, ended well for them, the perpetrator, but there’s a lot of things that go on that don’t get caught. And that’s the sad part is people get more more sophisticated using tools to obfuscate who they are, where they’re coming from, all that kind of good stuff. You you’ve heard the term catfishing, obviously, and people pretend to be other folks. And so you have new crimes kind of emanating from that around.
the, well, cyber bullying in general, but then cyber bullying for, for money or for, know, whatever the case might be that they’ll use that as kind of like, um, Oh, what’s the word I’m looking for? Basically just, you know, forcing people to do things they don’t want to do and, but holding ransom over their head. So not, not, not ransomware in the sense of, um, you know, corporate encrypting hard drives and so forth, but ransomware was holding people at ransom, cyber bullying, having them send.
Manoj Tandon (11:29.822)
No.
Christopher Rees (11:37.496)
whatever money or pictures or whatever, at the threat of releasing things to, you know, their friends, their family, their contacts, basically extortion is the word I was looking for. so yeah, that, that is definitely changed. with the advent of the dark web, that’s changed quite a bit too. Obviously there’s marketplaces out there that exist. You can, like you said, malware is a service ransomware for hire. And with AI tools, it becomes a lot easier to create, to craft.
Manoj Tandon (12:02.017)
As I say with AI, now even with deep faking of voices, it’s still not perfect. If you’re attentive, I think you can tell, but I think if you’re a grandma or you’re a parent that gets a call, you might be under stress and you won’t be listening for those nuances.
Christopher Rees (12:07.499)
yeah.
Christopher Rees (12:17.112)
Right.
Christopher Rees (12:21.848)
Sure. Yeah. And I’ve done that some of my training courses, I’ve used some tools like 11 Labs and there’s other ones out there that can you upload 10 seconds of your voice and it mimics it pretty, pretty closely. And so you can put together voicemails or whatever I asked for, you know, Hey sweetheart, I just dropped my phone or I’m locked out of my bank account. Can you shoot me or text me over the, our username and password or account details. And if they’re not paying attention, you know, they might do that. Or to your point calling a loved one or a grandparent.
saying, Hey, I just got an accident. need money for a tow truck or whatever. And if they’re not aware of those things, they’ll fall super, super easily fall prey. That’s one of the reasons we always say, if you run into a situation where you think that is in fact the case, then have some type of safe word or a safe phrase or some type of safe question that you can ask the person on the phone that only the real person would know. So that way that allows you to kind of very quickly determine is this a real call or is this a fake?
Manoj Tandon (13:20.61)
Now, Chris, you mentioned one of your training courses is around disaster recovery backup. Why is this statistic that I have read? Now there’s variations of it, but basically between 67 to 70 % of backups fail on restoration or get to get the company back online. What’s the root cause behind that?
Christopher Rees (13:27.469)
Mm-hmm.
Christopher Rees (13:43.726)
Mm-hmm.
Christopher Rees (13:47.65)
Well, that’s a great question. a lot of it, I think it’s in some degree situational. I actually used to manage a storage and data protection team for quite a while. So that is a real thing for sure. Part of it is because number one, you assume or the company or whoever the backup guy assume or girl assumes that the backups are legit and they’re functional. They never test them so that you can be backing things up for months or years and never test. And the one time you need it, it’s not, it’s not functional.
for whatever reason. So testing backups regularly is rule number one. But then secondly, there’s different types of backups. You have crash consistent, you have application consistent. So in most environments, it’s not just a single computer. It’s an end-tier environment. So you’ll have front-end load balancers, databases, whatever web servers, the actual servers. You might have multiple, multiple clusters involved and all of those things have to be backed up in tandem and they have to be restored in a certain order.
So if those things are not restored properly or you miss some of the backups or things are just not brought up in the right fashion, those things can fail. So a lot of the systems are incredibly complex. If it’s just a straight data backup, can nine times out of 10 recover the data or you might have the data itself, but that data feeds any number of other systems. And if those systems aren’t backed up, then it doesn’t do you a lot of good. So a lot of times it’s just a kind of a combination of
not taking a full accounting top to bottom of what it takes to bring that specific thing back up.
Manoj Tandon (15:21.416)
Is there still a role for physical media in this exercise? is there a stra, what is the strategy to break the backup from your network, if you will, so that when ransomware hits, it’s not encrypting the backup along with it? Is there a recommendation that you’re training for in those situations?
Christopher Rees (15:39.798)
Mm-hmm. Sure.
Christopher Rees (15:45.27)
Yeah, yeah, for sure. I mean, you can do a couple different things. obviously, you know, back, I don’t want to say the old days, but a lot of companies still use it, but you have physical tapes. Physical tapes can be disconnected from the network. And that’s obviously, you know, a good way to not have things encrypted with VTLs and virtual tape libraries and online backups. Nowadays, that’s, that’s a little bit harder because if you have ransomware that that is able to jump that network, that’s an issue. But
A lot of times you can have things either offline, virtually air gapped or logically air gapped. You can have cyber vaults in place so that you have your primary backup. You might have a secondary backup as a failover, maybe in a secondary site. So that way you have site disparity or diversity, but then you might have a cyber vault, which whereas it’s logically disconnected from any other network or physically for that matter. But, and it only opens up for a short period of time. The backups, it’s only a one way traversal. The information can only go in, can’t come out.
And then depending upon how sophisticated that is, you might have some things inside that cyber vault that can do deep level offline scans to make sure that there’s no corruption or ransomware or things along those lines. there’s that. You can also back up to the cloud, which can be disconnected. You can do offsite backups like Iron Mountain and places like that that can do it as well. The problem sometimes is the bad actors are becoming more more sophisticated. So they’ll let things sit and lie and wait for
days, weeks, months or more. So you’re backing up potentially, know, infected files for months before you even realize it. So sometimes you have to make sure that things are completely clean because you can basically do all your restores, get things back up and running and they flick a switch and everything gets corrupted again or encrypted again because the actual root cause was not determined. So simply restoring is not in and of itself is not necessarily a hundred percent.
You have to make sure all the gaps are remediated, all the doors are locked basically, and then you actually have a clean environment to back up into, or restore into, I should say.
Manoj Tandon (17:47.936)
Yes, you have to trust the baseline and that is your gamble, I guess. That’s the risk because that baseline very well could be corrupted and if it’s corrupted…
Christopher Rees (17:54.008)
Yeah.
Manoj Tandon (18:02.61)
All of it is in jeopardy potentially.
Christopher Rees (18:06.062)
Yeah. And there are certainly some tools out there, a lot of sophisticated tools that can measure for entropy and it can determine pretty quickly if things start to become corrupt. There’s a number of different ways to identify that and shut things down. Obviously you can put things in place that can automatically take ports offline or automatically take some of your network segments down. Or if you have micro segmentation set up properly that can thwart some of that as well. But then on the other side of the coin, that can also become an attack surface. They can just basically DDoS a specific
segment and they make you shut down ports and take your business offline without actually corrupting anything. there’s really a, it’s a dual edged sword. There’s no kind of one size fits all. It’s really a matter of what fits the business and what the risk tolerance is.
Manoj Tandon (18:49.89)
There’s that word, risk, which is used so often. Out of curiosity as an instructor, is there a methodology or approach that you like to have your students look at when they’re trying to determine risk or to quantify risk or what’s your thoughts on it?
Christopher Rees (19:12.994)
Yeah. I mean, it really boils down to, well, it’s business dependent, obviously, but there’s the business impact analysis you can do and just look at, you know, the feasibility of it. What’s the impact of it? How important is it? So you could spend a lot of money mitigating a risk that if it were actually executed, wouldn’t be that big of a deal or vice versa. You know, if you’re not really identifying that properly, you’re underfunding risks that have a high degree of executability.
And perhaps a high degree of impact. So again, it really boils down to kind of putting things into it, like a four quarter quadrant and just understanding where things fall. If you don’t necessarily have to remediate every single CVE that comes down the pipe, if you don’t have anything in your environment that matches that, and sometimes, know, folks that necessarily maybe aren’t in the know, but they get the reports might look at, my God, there’s 15 or 20 different vulnerabilities here. We have to jump on this and all of those to come to find out you only have.
maybe a handful of those systems in place or where they’re actually valid. So when it gets down to the security level, those folks understand that obviously, but the higher up you go in the food chain, sometimes that’s not as immediately apparent. So really it’s just a matter of remediating based upon impact analysis and how important it really is or how much of an implosion, if you will, would that cause the business if it were realized.
Manoj Tandon (20:39.596)
When you look at just some of the brief topics we’ve covered here, backups, bad actors, ransomware as a service, assessment of risk, cybersecurity is a giant area. And if someone wants to make a career switch into it, it can be mind boggling to them as a novice, where do they even start?
Manoj Tandon (21:11.906)
How do you coach those folks?
Christopher Rees (21:14.316)
Yeah. And that’s a great question too, because as with everything within IT, it always starts out, the first answer is always, depends. So it really is a matter of what do they have a passion for? And sometimes they don’t know because like I said, you don’t know what you don’t know. So working in a small company, a consulting company, a security-based company is certainly good to get your feet wet, maybe as a sock analyst or an entry-level job. Certainly working in small companies where you wear multiple hats is also good.
The great part about working consultancies or SOC type of environments is you get a pretty wide exposure to a lot of different companies at once versus just how one specific company does things because there’s obviously multiple ways to do pretty much anything. And then also, like you said, there’s so many different avenues to go into. can do network security, you can do perimeter security, can do OS patching, can do cyber logs, you can do…
Manoj Tandon (21:57.9)
Right?
Christopher Rees (22:13.038)
some other ones, AI or anti-AI, however you want to look at it, adversarial type stuff. You can do threat intelligence analysis. I there’s so many different areas within a specific, I should say a tower within cybersecurity. You can do digital forensics, you can do investigations, e-discovery. I there’s a lot of different ways or lot of different tunnels you can kind of dive into. So like I said, I would start kind of in the beginning looking at
Small companies that need a security, have security focus or need security, should say expertise. But if I had, if I, in a perfect world, if I had to do it, I would go into some type of sock, environment or a small consultancy company that I could, I could learn and ramp up very quickly. But by having exposure to a lot of different companies and seeing how they do that, how they do different things, because they all have different tools, all have different ways and the methods of, of attacking something that can get you up to speed pretty quickly.
Manoj Tandon (23:10.294)
Now, before you can get hired into a small company, you have to have some working knowledge or be able to sell yourself. Is there certain certification paths that you would say are a must have that you absolutely must do if you’re going to make a career switch or contemplating doing a career switch?
Christopher Rees (23:33.762)
Yeah. And again, I mean, I would never say it’s an absolute must. It’s certainly, I would say it’s a massive thing in your favor, but yeah, I would start off with like some general security certifications like security plus, obviously, you the one I’ve been creating for a long time that that is probably the best place to start because it’s, vendor neutral. It gives you a really great understanding of hardware, software networking. You know, there’s some under some underpinnings of how all that stuff works, but with a security focus.
And there’s roughly 1200 topics, I guess, within security plus that are covered or objectives. it’s wide enough where it covers pretty much everything you would need from a high level understanding, but it’s not so deep that it’s completely overwhelming. So it’s a great place to start. And then from there, like I said, there’s a number of different certifications. can go up, whether it’s through CompTIA, whether it’s through other areas, CISSP, or a multitude of other…
certification paths, but there’s a lot of ways to go. And again, do you want to work in the public sector, private sector, federal government? All those things kind of determine paths you might take because there are certain certifications that required within those specific industries that you might need to focus on.
Manoj Tandon (24:46.598)
is what’s the timeline to get a Security Plus certification? And do you have to do your Network Plus before you do your Security Plus?
Christopher Rees (24:56.352)
No, no, there’s no prerequisites for that. So it certainly helps. I mean, if you’re starting off brand new with knowing nothing, then yeah, I would recommend like A plus and network plus first to give you a deeper understanding of hardware and software and networking. But if you have a general understanding of those things, it’s not, it’s not a prerequisite. So I’ve had many, many students come through. They have just have a good general working knowledge without a specific cert and come through and pass security plus. So from a timeline perspective, if you really put the time and energy into it,
Two to three months, would say, depending upon how quickly you learn and if you’re doing hands-on labs or if you just, some people are visual learners, some people are hands-on, some people can just read something once and just retain it. So it varies from person to person, but it’s definitely attainable.
Manoj Tandon (25:43.286)
You know, to me, I guess the hands-on piece to me is critical because, you know, unless you go in and you play in a lab, a lot of this stuff, I don’t know how it gets ingrained. Maybe you’re right. There are people out there with that brain power that can snap. They read it, they know it, and it works. you know, having those labs. So these online courses that you’ve designed, are they set up with interactive labs?
Christopher Rees (26:11.266)
They are correct. Yeah. The way Pluralsight does it is basically they have the courseware and then accompanying labs. So from pretty much, I don’t know the exact number, but for pretty much most certifications, if not all certifications, there are X number of labs, know, dozens or more of labs for each topic that get covered. and a lot of the courses, a lot of the places are similar. yeah, labs are definitely important. It gives you kind of stick time, as I call it, with a specific technology.
I would also just kind of preface that and say that doesn’t necessarily mean you know how to do, if you know how to drive a car, you don’t know how to drive a tractor trailer necessarily. So it’s a matter of you understand the basics of that specific thing. But to me, if you understand conceptually how something works and just generally how anything works, you can then transfer that knowledge into other different applications because every company might have a different platform and they might have a different way of doing something. They might have a different tool they use.
But if you understand the objective and what you’re actually looking for, not necessarily what button to click or what lever to pull, but what you’re actually looking for, like the fundamental concepts of how to identify risk or malware or indicators of compromise, or even like a hackers or bad actors mindset. That in and of itself, I think takes you a long way to, cause you can learn a tool, specific tool, but if you don’t understand like the underpinnings and the psychology of why things happen and…
what things they might be looking for, what are the targets, what are the actual kind of crown jewels of your specific company, you’re not quite sure what to protect.
Manoj Tandon (27:47.626)
In terms of effectivity of training, is it better, same or worse if you do it online versus in person? What have you seen?
Christopher Rees (27:59.498)
I’m a little bit biased just because I’m an online trainer first and foremost. I mean, I’ve done classroom training quite a bit, but to me, and again, this is assuming you actually have a good online trainer. Online to me is better only because you can go through the course over and over over and over again. You can go back and rewatch. You can go back and take it again if you need to. When you take an online course, you kind of roll in the dice a bit. You might have a great instructor who’s just best thing since sliced bread and you’re lucked out and you’re great. Or you might have an instructor that
you don’t click with for whatever reason and you go through for a week or two week or however long that course might be. It might be a six month course, depending on if it’s an in depth or a boot camp or whatever. And then it’s a one and done. So then you don’t have a chance to necessarily go back. Some places might allow you to audit that course again one time, but you don’t have the ability to go over and over and over again. So for me, online works better in that fashion. You can do it at your own pace. can do some in the morning. You can listen while you’re on your way to work. You can listen after hours.
you have that flexibility. again, some people, it doesn’t work for everybody. Some people like to be in a class asking questions to a specific instructor and getting that one-on-one feedback. So again, it’s personal preference, but I think generally speaking online is a better way to go just because you have the reusability.
Manoj Tandon (29:20.864)
makes sense, especially when you talk about being able to go back and take those classes again and again and again. I guess the one thing that’s even there, you you might have an issue with maybe not the instructor as an individual, but the course as it’s generally set up and that these are somewhat complex topics.
Christopher Rees (29:38.958)
Mm-hmm.
Manoj Tandon (29:43.35)
depending on the company you’re working with, they may not have simplified them to the point into the right bite-sized chunks that are comprehensible. Is there, how do you address that problem?
Christopher Rees (29:50.542)
That’s true.
Christopher Rees (29:54.53)
Yeah. Well, and again, I’m speaking around certification courses. So, so CompTIA or whoever the, whoever the certifying body might be, they give you a set of objectives. So you have X number to cover. So no matter where you take it from, they’re going to cover the same objectives. So a certification is a little bit different sometimes from a specific course for a specific company. Like if you have a custom course, in other words. So yeah, in that instance, you have to really understand what that company, what their goals are, what their, what, what their,
what success looks like, what their outcomes are. They might want a little bit of training on this specific topic, some other training on this specific topic, some training on this specific program and so forth. So yeah, you have to make sure that you’re tailoring it to the, to the customer’s needs in that regard. certification courses, like I said, are a tiny bit different just because there’s a, you know, set, set number of objectives. but yeah, it really does. It, it varies. mean, there’s like I said, there’s no one size fits all. I will circle back on one point though, basically.
When you have, assuming it’s good training, but if you have good training, that’s online and you need to put say 500 people through that training, you can pretty much be guaranteed that all 500 people get the same content. get the same, it’s repeatable and it’s consistent. So they’re all getting the same type of training versus if you send, you know, 10 people this time, 10 people next time, 10 people next time to different online or physical courses, there’s no guarantee that they’re all going to get the same material or get it delivered in the same capacity. So from a consistency stake sake, think that.
Manoj Tandon (31:09.026)
Mm-hmm.
Christopher Rees (31:23.476)
you know, again, online makes better sense, but it really, like I said, boils down to the quality of the, of the, the company and the quality of the instruction.
Manoj Tandon (31:35.56)
What, how do you see AI changing these certifications?
Christopher Rees (31:41.58)
Yeah, I think AI is going to change everything, not just training obviously, but I do think it’s going to augment quite a bit because I think education in general, because it’s going to make it very much tailored to the actual individual. So you can tell the AI that you’re having to be using, I want to learn this, I want to learn X, Y, Z, but I want to learn it in this fashion. This is how I, this is what resonates more to me, make analogies or…
Give me visuals, give me a movie or no set up some labs for me or do whatever the case might be. And the AI will tailor it specifically to how that individual learner learns. So I think even from like K through 12, that’s going to change quite a bit because people can now, instead of having teachers and I’m making, I’m not trying to be disparaging whatnot, but traditionally, a lot of times you have to kind of teach to the lowest common denominator in a course or in a class so that everyone can progress. Whereas
When you do it in an AI fashion, at least how I envision it, that becomes very much tailored. So the smartest person and the lowest person in that classroom are going to get exactly what they need and can progress as fast as they need to. So you might have one person curing cancer at the end of a course and another person that’s still learning the very basics, but you don’t have a teacher that is kind of trying to accommodate everybody at the same time. So AI is going to, I think it’s going to hyper-personalize that whole experience.
Manoj Tandon (33:03.392)
What about replacing some of these fundamental roles? mean, we’re exploring it, you know, in our SOC. I mean, I can tell you right now the technology isn’t there, but I can absolutely see a day where a SOC analyst, maybe a level one SOC analyst really isn’t even needed anymore. I mean, the AI will, can do the job. you know, same thing with like a security plus, I’m not being disparaging, but if you look at the content that’s in there,
Christopher Rees (33:24.056)
Yep. Yeah.
Christopher Rees (33:33.07)
Mm-hmm.
Manoj Tandon (33:34.89)
It’s just like taking the SAT. can’t, know, chat GPT scores better on the SAT than a lot of American high school students. So why can’t it just score just as well on Security Plus? And now the data is, you know, it’s just there, you know, it nullifies the, the effectivity of it.
Christopher Rees (33:43.692)
Right. Yeah.
Christopher Rees (33:55.384)
Yeah. Yeah. No, I definitely don’t, don’t disagree with that. think like, like with anything there, there’s a human element that needs to come into play. I mean, at least for the foreseeable future, AI will not be like AGI level. and that, that changes day by day. So who knows when that’s going to actually appear. But, the fact is they have a human element that can, not outthink, but it can, but can think differently maybe that AI didn’t account for, or, or can be fooled in one fashion or can be abused.
in one form or fashion, but you know, on top of that, have just the general, reliance on it. that’s something we’re to break. And if no one knows how anything works, then who’s going to fix it. So you’re still going to need people that understand things under the hood and how things operate because, AI is great. I mean, it’s, it’s an amazing tool, but if everyone, if those skills go away completely and we’re completely reliant on nothing but AI, if AI breaks or it gets compromised or whatever.
It’s just like when you go to a cash register, Kind of making an older analogy. Kids nowadays don’t know how to make change. So if the cash register goes down, they have no idea how to make change and give it back to you. extrapolate that out to a much more deep technical concept. When things break, if there’s no one there that knows how to fix anything, you’re in a deep hole. So I think that those roles are not going to, at least I would hope they don’t go away completely, but they might, they’re definitely going to be augmented.
by AI and I’m hoping that those folks just move on to higher level functions, still retain an understanding of how it works.
Manoj Tandon (35:24.994)
That’s what I would have thought. Just what you just said, that they move on to higher level functions, Chris, because they’re, instead of, you know, doing long division, you can use a calculator now, you know. So let the grunt work be, let the machine do it. But really the interpretation of that is something where real intelligence is required is where the value becomes very, very high. So it’s a transformation.
Christopher Rees (35:36.974)
Mm-hmm.
Manoj Tandon (35:53.568)
And I guess with that, maybe certifications would change as well. The content of these classes might change.
Christopher Rees (35:59.66)
Yeah, I definitely think the content will change and they do change just from, from, revision to revision, but sometimes not as much as others, but yeah, that will definitely change. But as long as the actual targets, a lot of times are still humans, right? And you have the emotional, the emotional component to it, the social engineering component to it. That’s going to be very hard to necessarily mimic just because every single person is different. Every single person reacts differently. All right. So that, that is going to be hard to completely replace. but I do think that.
AI will make a lot of people’s jobs easier. It’s kind of the taglines like AI is not going to take your job, but somebody using AI might take your job. So it’s going to make that person much more effective and be able to do a lot more with a lot less physical manpower.
Manoj Tandon (36:50.688)
I’ll get worried when AI starts replacing bad actors. You know, when you have evil AI. If you can get a machine to get that good where it can exploit human emotion, depict human emotion, you know, and socially engineer an attack, well, now you’re in a totally different world.
Christopher Rees (37:10.328)
Mm-hmm.
Christopher Rees (37:18.53)
Right. Well, yeah, I mean, we’re not quite there yet. from just from like, from, from scratch, but they can certainly use those tools to help, help kind of push that down, push that can down the lane. But yeah, there’s still some bad actors behind it that are initiating all that stuff. But yeah, I mean, AI makes, makes a lot of that social engineering quite a bit, quite a bit easier. They can scrape every single thing you’ve ever done online. They can, they can take snippets here, snippets there and build a profile of you and make it really convincing. And then go talk to a coworker or a.
Manoj Tandon (37:21.147)
No, we’re not. We’re not even close, but yeah.
Christopher Rees (37:48.15)
a loved one or whatever, business associate, and make it sound just like you. same, the same use of emojis, the same slang, the same whatever, because they’ve been potentially monitoring your email for, you know, six months or a year or, know, whatever the case might be. They can, they can track a lot of your stuff. They know where you’re vacationing, what you’ve bought, what your favorite sports team is, whatever. They can use all of that in conversation to make it sound very much like you. And if they’re also cloning your voice, I mean, it’s, it can be pretty convincing.
Manoj Tandon (38:18.37)
It can be. I mean, we’ve talked about that case overseas in the Far East where that poor banking clerk sent 15 or $25 million. I forget the exact number on a deep fake zoom call. Because as a result of it, I would say that must have been some deep fake.
Christopher Rees (38:29.688)
Yeah. Right. was going to say the same thing. Yeah. I think that’s what I’m thinking of. They had like a number of different folks on the zoom call and then they had a follow up from an outside attorney that follow up on the call. Like it was legitimate. And I mean, everything seemed like it was a hundred percent up and up. Yeah.
Manoj Tandon (38:50.144)
Yeah. And then the guy executed what he thought his bosses wanted done. And so what could be, why rob a bank when the bank employees will come out and just give you the bag of money? I mean, it’s a lot safer.
Christopher Rees (38:58.231)
Right.
Christopher Rees (39:07.244)
Yeah. Yeah. Couple that with the fact that, know, extradition laws and just the ability to actually go out and try to apprehend folks in some countries is almost impossible. So they realize they can do things without much risk.
Manoj Tandon (39:23.426)
If you’re, again, getting back to coaching a little bit, because we do have a lot of folks that are practitioners in cybersecurity that listen to this show. So folks who are looking to maybe instead of make a transition into cyber, but are looking to elevate their career in cyber. Is there a training path that you would guide them towards?
or directions. Yeah.
Christopher Rees (39:49.294)
You’re saying like they don’t want to necessarily work in cyber specifically, but they just want to be more cyber aware.
Manoj Tandon (39:55.656)
No, they are there. So they’re sock analysts today, right? And now they don’t want to be a sock analyst anymore. And they want to become a security architect, or they want to become a threat hunter, or a, you know, get into intelligence, you know.
Christopher Rees (39:59.106)
Mm-hmm.
Christopher Rees (40:06.915)
Mm-hmm.
Manoj Tandon (40:16.914)
Is there a training set of pathways for those people or how what would you suggest? Where do they begin?
Christopher Rees (40:26.068)
yeah, good question. mean that, that I, my specific area of focus is traditionally been on the CompTSI since I started off with, security plus. you have, CI ATP, can have, you know, advanced, threat analysis practitioner. There are, you can do like some DFIR like forensics types of courses and so forth. So it really depends on if you want to go into like threat intelligence and analysis and be someone that augments.
other security teams and like enriches their threat feeds and so forth and kind of deep dives on specific bad actors and whether using what, know, MITRE framework or whatever, you know, baseline for understanding who’s coming in, what they might particularly target, how they’re targeting and ramping up your defenses against those specific threats, indicators of compromise and so forth. Or if you’re looking at digital forensics, forensics is really, I think, an interesting field because it’s, it can go so many different pathways, whether it’s investigations for
corporate investigations, banking investigations, financial fraud and so forth. can go into more, like I said, online cyber crime predator types investigations. really, that runs the gamut. it crosses industries, crosses every vertical. But threat intelligence, a lot of companies, at least in my experience, outside of like the medium size, the bigger size companies don’t have a lot of resources to bring in, in-house like threat intelligence, analysts and so forth. we’ll use.
Manoj Tandon (41:51.49)
All right.
Christopher Rees (41:53.55)
in recorded future or some other ones that can provide threat feeds and kind of augment what they’re currently doing. But even that’s kind of more relegated to like the, I’d say medium or larger companies. So if you’re able to take that same level of understanding and kind of pitch it or market it towards smaller companies and give that level kind of like an enterprise level of expertise to the smaller companies, I think that’s that that will be a differentiator for a lot of folks who are especially if you’re looking to break in.
So you can do it at a smaller scale to get your feet wet before you can move on to bigger and larger environments.
Manoj Tandon (42:29.654)
Very good advice, Chris. We’re actually at the hour, believe it or not. We also want to give you a couple minutes to go ahead and plug anything you’d like to. What do you want to let our audience know about?
Christopher Rees (42:35.255)
Okay.
Christopher Rees (42:39.63)
Sure. Yeah. I appreciate that. Yeah. I mean, would say check out, my courses at Pluralsight. Pluralsight.com. have Security Plus is one I’ve been working on for quite a long time and very, proud of, but I have a few other courses on social media, personal privacy. As I mentioned, I have one, Internet of Things is coming out. And I’m also going to start, I did just start a podcast.
Um, just on like folks looking to change careers and getting into it, not necessarily security per se, but just tech in general. And it’s just called my tech career. Uh, have it on Spotify now it’s only, two, two episodes in, but I’m kind of leveraging some AI tools to create the podcast and just basically just playing with it at this point. But I think it’s going to be a good opportunity to, to get some information out there and help folks that are looking to just change careers and get into tech. Um, similar to, you know, how I did many years ago.
Manoj Tandon (43:31.03)
Fantastic, Chris. Well, we’re glad you do the work that you do. Because we know keeping up on all the relevant changes, and there’s a ton of them. I won’t even, can’t fathom how long it takes you to keep updating the materials. That’s got to be a job and a half.
Christopher Rees (43:35.906)
No, thank you very much.
Christopher Rees (43:52.078)
Yeah. The train, the training is, I mean, it’s a labor of love. It’s fun, but yeah, it’s, it’s definitely probably a 20 to one, if not more ratio, depending upon how detailed the subject is. yeah, for an hour of content might take you 20, 30, 40 hours to, as anyone knows who does video editing and just background research and just keeping up on things. It’s, it’s, it’s constant.
Manoj Tandon (44:12.202)
You know, you should, someone with your background, you should write a book, something like the hitchhiker’s guide to cybersecurity, know, this.
Christopher Rees (44:20.234)
Yeah, you’re not the first person to say that I just I could have I have to be able to clone myself I think and just get some more time.
Manoj Tandon (44:25.314)
I think it would be needed because I think we see a lot of materials that are very technical, but how it all bridges together and connecting the dots is something that’s sorely lacking in the industry. And that’s where all the magic happens. It’s not in the tool itself, it’s in the integration of the whole to see what the big picture is.
Christopher Rees (44:40.972)
Good.
Christopher Rees (44:51.682)
Yeah. And like I said, and as you know, mean, 90 % of most breaches, they still occur the same way. The inroads are still the same. It’s a social engineering phishing email or some type of social engineering tactic. So that is really the biggest thing, making people aware of what to do and what not to do. And most people, they either don’t pay attention or they just assume people have good intentions. So ingraining that in people’s minds would go probably halfway down the path of securing a
an enterprise or a company, but a lot of people just don’t pay attention.
Manoj Tandon (45:26.156)
Well, audience, pay attention. How about that? That’s a great note to end this podcast on. Chris, thank you for being here. Really appreciate you being on the show.
Christopher Rees (45:28.471)
You
Christopher Rees (45:32.975)
Absolutely. Thank you so much. I appreciate it. All right. Bye bye.
Manoj Tandon (45:38.412)
Take care. Bye bye.
Read more about Chris on his LinkedIn
Take a course with Chris here
Check out the vCISO bot we created
Check out the other episodes in Season 16:
Ep. 0 Jim Love – Company Data on ChatGPT: Why What You Share Could Stay Forever
Ep. 1 Ken Underhill – Breaking Into Cybersecurity: Job Hunting Tips and Ghost Job Realities
Ep. 2 Allie Hunter – The Dark Side of Online Gaming
Ep. 3 Purandar Das and Ken Foster – “Delete My Data” Doesn’t work
Ep. 4 Tammy Klotz – Communicate properly with your team
Ep. 5 Sandra Estok – My Identity was Stolen
Ep. 6 Brett Johnson – Inside the Mind of a Former Cybercriminal
Ep. 7 Darren Mott – “Hackers Aren’t Breaking In—They’re Logging In”
Ep. 8 Stacey Champagne – “Red Flags in Cybersecurity Coaching”
Ep. 9 Craig Taylor – Phishing, Encryption, and Cybersecurity Training
Ep. 10 Christopher Rees – Will AI Change the Way We Learn
About Christopher Rees

Chris is a professional information technologist, author, trainer, manager, a lifelong learner, and Former Law Enforcement Officer.
He has been creating courses for over 25 years and has been working as an author on Plurasight for 11 years. He has created over 80 IT Certification training courses (52 or so with Pluralsight) and his students have watched over 1 million hours of his content.
He is married with 3 beautiful children and interested in working out, spending time with family and friends and being creative whenever possible.
He has been an author for over 25 years and has created over 60 IT Certification training courses.
Chris really enjoys helping people advance in their careers through training and personal development.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
