This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Darren Mott. Darren, author of get cyber smart, is a retired FBI agent with 20 years of experience in cyber and counterintelligence investigations. He played a key role in strengthening FBI-Russian collaboration on cyber threats and created the FBI’s first program blending counterintelligence and cyber disciplines. Now, he owns an investigative and consulting company called Gold Shield Cyber. Mott holds master’s degrees in education and cybersecurity policy and hosts The CyBUr Guy Podcast, CyBUr Smart Morning News Update and the Tactical Cyber Podcast.
Chapter Titles:
00:00 Introduction
02:50 No one gets to where we are at the beginning
12:59 Stupid Cyber Criminals
19:01 Proactive vs Reactive
32:52 How big of an amount until the FBI is involved?
40:28 Get CyBUr Smart
Audio:
Important Links:
Transcript
Manoj Tandon (00:01.204)
Hello everyone. Welcome to another episode of Dark Rhiino Security, Security Confidential. This is your host, Manoj Tandon. And today we have another awesome guest, but before I announce him, I wanna remind you guys to please hit the like and subscribe button so we can keep bringing you this great content and having fantastic guests. And speaking of guests, our guest today is Darren Mott. Darren is the author of Get Cyber Smart.
He has been a former FBI agent. He spent 20 years with them in cyber and counterintelligence investigations, played a key role in strengthening FBI Russian collaboration on cyber threats and created the FBI’s first program blending counterintelligence and cyber disciplines. Now he owns an investigative and consulting company called Gold Shield, cyber.
and he has a master’s degree in education and cybersecurity policy. And when he has free time, he hosts three podcasts, the Cyber Guy podcast, the Cyber Smart Morning News, and Update and the Tactical Cyber Podcast. I hope I got them all right there, Darren. Forgive me if I messed up one of them.
Darren Mott (01:18.956)
Now you nailed them. All correct.
Manoj Tandon (01:21.116)
Okay, well, it’s an honor to have you here and I’m looking forward to this because I don’t have to do a lot of talking. you know, the the
Darren Mott (01:28.451)
Well, I want to say thank you because I usually don’t get asked a lot to be on podcasts. I have to find people to be on podcasts. So I appreciate when people say, can you come on our podcast? I’m happy to talk to whomever, however.
Manoj Tandon (01:39.828)
You know, I think someone with your background that’s kind of surprising you might be you might get a lot more invites after this
Darren Mott (01:49.047)
I’m a poor advertiser and poor marketer, I’ll be honest. I’m trying to do that better, but we’ll see how it goes. It’s all good.
Manoj Tandon (01:54.014)
You know, there are so many awesome people out there like you with tons of experience in cyber. And, you know, we’ve had over 160 guests and I don’t think we’ve even lit the candle. But most of them, like you said, don’t do a lot of advertising. And you kind of have to go find them as you well know. That’s probably the biggest challenge of doing a podcast.
Darren Mott (02:06.478)
Mm-hmm.
Darren Mott (02:18.998)
Yeah, but I will say, I most people when I ask, they’re usually willing to do it. So it’s, it’s, I just can’t be afraid to ask. That’s, that’s the case. I’m not really afraid to ask. I just don’t know where to go. Like I’m, I’m, I’m a bad organizer. Like for the, for the cyber smart morning news one, that’s pretty easy. I bring up my 24.
windows and find the six articles I want to talk about and kind of bang that out pretty quickly. Cyber Guy one takes a little more time to find someone because it’s going to be a longer form content. The tactical cyber one’s even harder because it has a very specific methodology to what it tries to do. So that one’s a little harder to fill in, but we make do as best we can.
Manoj Tandon (02:53.264)
Yeah, I understand. And it is a lot of work, believe me. I mean, we have a lot of work with one and I have a very good team that helps us. Without that, I don’t think we’d be able to. So let’s do a little bit of a background on you. Everybody loves these origin stories. And at some point, someone’s gonna say, all right, I think you guys have done enough of these, but there’s…
Darren Mott (03:08.462)
Mm.
Manoj Tandon (03:19.802)
Everybody wants to know how did this all begin, you know, or did you wake up and say, I want to be cyber and be.
Darren Mott (03:25.686)
No, and I will say that’s the same first question I ask everybody because no one gets to where we are at the beginning. We all did something different and somehow fell into this, in my experience, fell into it some way into whatever it is our area of our expertise. And I’ll be honest, my origin story starts back in 1977. So I’m 58 now, but in 77, I was 11. My mother was a programmer for a bank and they had this huge hunk in…
you know, internal server that she was programming to do, you know, keep the account straight and it had a big dot matrix printer, but it had a little screen about, you know, smaller than the size of your iPhone screen. And I was just fascinated by it. And she created like this little game for me to play on. And I kind of fell in love with computers at that point, but ironically didn’t move towards computers when I got to college nine years later, seven years later, because
And this is a long part of this. I’ll make this very quick. I had appendicitis when I was in ninth grade, decided, hey, I’d like to be a doctor. These hospitals are kind of cool. I don’t know, kind of weird. So got to college, tried to be a doctor. After two years, took the MCAT, did poorly, realized I didn’t want to do this for six more years and decided not to be a doctor, but stayed in biology. Ultimately, did a bunch of different stuff, spent a lot of time trying to figure out what I really wanted to do, and ultimately went back and became a teacher, teaching biology, chemistry, physics in high school. And then…
Manoj Tandon (04:43.859)
Wow.
Darren Mott (04:44.938)
Yeah. And then in 1998, my wife and I were talking, we had just had our, my wife was pregnant with our second child. And I was teaching summer school. And we’re like, is this what we want to do? Just be teachers? Because she was a teacher as well. And a week and a half later, I applied to the FBI had fallen across their website, and they were said, accepting applications for special agents. And I thought about law enforcement here and there. And you know, the FBI has a pretty interesting name recognition. They do good marketing for the most part.
Manoj Tandon (05:06.536)
Wow.
Darren Mott (05:14.656)
And so I sent in my application, figuring the worst I can say is no. And all along, though, I was always working with computers in some way, shape, form. bought my first PC in 1992. It was a Hewlett Packard. And I did a bunch of stuff on that. I was on the initial, you know,
Manoj Tandon (05:23.22)
Okay?
Manoj Tandon (05:32.436)
What was that, a 286 box?
Darren Mott (05:34.83)
If I’m lucky, it was 286. Yeah. And I was on prodigy, right? I was on prodigy learning how the internet and the World Wide Web was working at that point. When I was in college, most of my roommates were computer science majors. So they had what was it? It was a digital computer in 1984, 85, which none of it was network, right? In 80, 45, there was no internet. They were networked to the school.
Manoj Tandon (05:57.854)
Well, there was DARPA in that, but yeah.
Darren Mott (05:59.808)
Yeah, but college students weren’t accessing that at the time. it was limited access, let’s just say. Yeah. And then at the school, I was kind of like the computer person, because I kind of understood how all these things worked. Even the computer, the lady who did the technology didn’t understand it. we had a, this one school had a Windows, one school, I was at two schools, one school had a Windows, one school had a Mac. So I got to learn how to use both of those things. And then when I got, and I,
Manoj Tandon (06:02.356)
the
Yes, it was limited access.
Darren Mott (06:27.566)
applied to the FBI, went through the process and they hired me. Partially because I focused a lot on this computer skill set that I had. It was mostly self-learned. It wasn’t like I went to college for it. I was kind of learned it myself. And they needed cyber agents because at the time I was assigned to the Charlotte field office in North Carolina and they were one of only 16 of 56 field offices that had a cyber squad. So I was one of the original cyber squads in 2000 when I showed up.
Manoj Tandon (06:37.192)
Very cool.
Darren Mott (06:55.682)
beginning of 2000, I showed up in Charlotte, put on the cyber square, which I wanted to be. I wanted to do the cyber stuff and got it, which was great. Ended up in Charlotte, which was great, great city. And then pretty quickly jumped into the fire.
because no one kind of knew how to do cyber stuff at the time, especially the FBI surely didn’t. I tell a joke in my presentations that at the time, the FBI spelled cyber with an I instead of a Y. So, and there was no, they didn’t really do that, but that’s the joke. But there was no cyber division yet. was, the cyber stuff was all kind of passed around to different divisions. And so no one really knew how to handle any of it. And so I got lucky, I got a pretty good source and ended up running a five year undercover investigation.
Manoj Tandon (07:18.825)
Well.
Darren Mott (07:36.376)
targeting what at the time was called the wear scene. This was the, these individuals that all over the world that basically took anything, any copyrighted piece of digital material and they broke the encryption or broke whatever and sent it out there for free. Still goes on today. It’s, mean, the impact was limited.
Manoj Tandon (07:39.934)
Okay.
Manoj Tandon (07:52.588)
now you can just buy software. mean, you can break the encryption on Blu-ray. That’s trivial. You can break the encryption on DV, whatever you want.
Darren Mott (07:58.542)
Sure. at the time, were making, yeah, yeah, at the time, this is 2001, we’re making the argument that this is a $3 billion a year loss to legitimate, which it was. And we could show stats that people were losing jobs because the companies were losing money and all that kind of stuff. So, and so I created this undercover that no one had done before. And the nice thing for me is at the time, no one knew how to do any of it. And so no one told me no. They’re like, yeah, okay, go ahead and do that. So I had my own offsite.
which was about 20 miles from the office. had a, at the time it ultimately became a 12 terabyte server farm, which in 2003 is big at the time. I built it all. None of it was pre-configured. was all, I went to this one store and they loved me because every couple of months I’d show up with it and get by $10,000 worth of equipment like hard drives, motherboards, cases, all that kind of stuff. built.
Manoj Tandon (08:52.02)
12 terabytes. Wow.
Darren Mott (08:54.606)
I keep in mind the first server, the first terabyte server I created was with 100 gig drives. So there were, there were no, yeah, 100 gigs. So there are 10, 100 gig drives all rated together and then they would crash. They would fail. I had mirrored servers that led into the, led it, led it, led to the main server so that I could obfuscate where I appeared I was coming from. I was paying $7,000 a month for an AT &T T1 connection into our office. And then ultimately the nice thing is technology move quickly because
At the end of my time, I was paying $1,500 a month for a DSL line, which served the purpose that what I needed, all these bad guys thought that because we told them that we were in Canada, all their stuff would be protected. And they had no way to prove that we were wrong, because we got the cable company to obfuscate our traceroute. So when you tracerouted my IP address to my server farm, the last three dots would would be blank. It wouldn’t say where they were actually that actually showed up in
in a little town in North Carolina near Charlotte. And we would say, well, the reason that those jump is because there’s VPN connections that forward us into Canada, and you can’t tell what that is. And they were all these guys, I mean, they were criminals. They’re not exactly smart criminals, but they’re like, okay, that makes sense to us. Let me send all my evidence to you. So I up doing two big take, I had two large takedowns in 2004, 2005, part of a large FBI major case, ended up.
arresting people in like 30 different US cities and seven different other countries across the world who were involved in this organized crime ring, if you will. So we ended up dismantling like five or six different groups.
Manoj Tandon (10:34.61)
And this was all on pirated materials.
Darren Mott (10:37.45)
All on pirate midter, it was a it was a priority back at the time. I mean, that wouldn’t be the same today. But at the time it was or least we convinced people of it was and I had that I had my case there was a case in Washington that was based on records by the RIAA was the victim, the Recording Industry Association of America was the victim. There was a case in California where the victim was the Motion Picture Association of America. So they were they were dealing with with groups that
Compromised DVDs and all that kind of stuff and and we met you may say look What’s the big deal and sure 20 years later? You can probably make the argument, but at the time it was a big deal because of the amount of loss instilled
Manoj Tandon (11:15.1)
anybody anymore? mean, your kids know what a DVD is?
Darren Mott (11:19.274)
Yeah, sure. No, not. My kids do. My kids are in their mid-20s. I still know, but I think other kids probably don’t.
Manoj Tandon (11:24.596)
Yeah, mean, any more streaming took care of that, right? mean, and that was a whole industry that just failed to adapt to changing times, unfortunately. But for you, it did matter. One question for you on that, how did you guys, because at the time, even today’s the law in the books that you’re allowed to make, if you own the media, you are allowed to make a copy of that media for your personal back.
Darren Mott (11:30.092)
Yes, sure.
Darren Mott (11:51.854)
Sure, yeah, sure. But they weren’t doing it for their own personal good. They were distributed to the world. And the thing was, yeah, no, they were, oh, well, no, they were Napster after Napster. Napster was first, showed what you could do, and then these were Napster on steroids. But then the thing is, it was a very interesting community because if, Windows, let’s say Windows 7 came out, and that may have been later, but let’s use that as an example. Windows XP, I think, is probably the best example. When Windows XP came out, a group breaks the encryption and makes it available to the world.
Manoj Tandon (11:56.516)
Also, they were they were Napster before there was a Napster.
Darren Mott (12:20.812)
That’s the only copy the world has. It’s different now, but at the time it was a very, I don’t wanna say ethical, but they had these issues where if the group mage released the Windows XP key so that you could have a free version of Windows XP.
no other group was allowed in this community to be able to crack it themselves. they were the first to try to be the first to market. Again, they made no money off of it. They were causing loss, but they weren’t making any money specifically. so if you were the first one to break the DVD on Spider-Man, then everybody who downloaded that copy of Spider-Man was downloading the same exact copy because it belonged to X group.
And that changed over time. But at the time, that was kind of how it was set up. And they all communicated on IRC, and IRC channels. And we had our own IRC channel for our stuff. We actually created different channels for different groups, because we actually were looking at five or six different groups at the same time. So it was interesting, just needless to say.
Manoj Tandon (13:08.382)
Thanks.
Manoj Tandon (13:22.862)
well, even today, doesn’t the FBI own or should I say law enforcement own a whole bunch of the nodes on the Tor network?
Darren Mott (13:32.578)
don’t know if I can answer that question here in this particular community.
Manoj Tandon (13:34.608)
that that that that that that that’s a good because there’s a lot of people that think that they’re obfuscating their activities by using it and I don’t think so. I’m just going to say it. I don’t I’m not buying that right now.
Darren Mott (13:45.185)
Mm-hmm.
Darren Mott (13:49.016)
I would say there’s, I would say, I’m gonna say there other three letter agencies that probably do stuff as well, but they have different authorities that maybe conversation for different podcasts.
Manoj Tandon (13:58.674)
Yeah. In all the years, I’d love to get your take on two things. What was a smart, if we can use that word, a smart criminal operation that you saw that might’ve gotten away with it, but they’re, they were not, they screwed up. And then what was the dumbest crime you saw cyber crime wise?
Darren Mott (14:24.396)
Ooh, that’s a rough one, right? So there’s a lot of dumb. I mean, I will say like the the undercover had they were all dumb because they would move their material from their home computers. So I mean, it made it very easy to find them because you just track their IP address and it went right to them. It was very easy. So they were all kind of stupid. They learned they would learn afterwards how to do things. But at the time, no one’s using VPNs. No one was. They were just logging in from their from their house. So those would be the dumb ones as far as the smart ones and.
Manoj Tandon (14:34.569)
Huh?
Manoj Tandon (14:44.66)
.
Darren Mott (14:53.046)
You can argue this is not necessarily cybercrime, but it is cybercrime, but it’s run by nation state actors. It is the Chinese are very good at what they do. They are not well, they and I will say they’re stupid too. So you we talk, we hear a lot about China hacking, stealing intellectual property and they do that all the time. And they lie about it. absolutely. Well, yeah, no, not.
Manoj Tandon (15:08.954)
Yeah, but they’re leaving breadcrumbs in their code, man. I mean, they’re telling you… Go ahead, I’m sorry. I didn’t mean to interrupt.
Darren Mott (15:15.022)
No, I gonna say, no, I had, so I was gonna tell you a stupid, a stupid, one of the ones that were caught was because they were, they were using the infrastructure they use to hack into the companies they were hacking into to buy stuff from Amazon, that they’re buying stuff from Amazon, send it to their home with their name. So, I mean, you know, China is good at what they do, but they have bad operational security too. So it is, it’s, it’s crazy. You know, it’s hard now to, to, really find, well, I’ll tell you what, the ones who are smart, the ones you never hear about.
Manoj Tandon (15:18.002)
Yeah, please.
Darren Mott (15:44.78)
right? Salt Typhoon, Volt Typhoon, you hear about them so they’re not doing, they’re doing something wrong because their information is getting out. But there’s plenty that you’d never hear from. There are plenty of hacking groups that are not making the news, that you’re not getting CISA reports on, the FBI’s not, because they don’t know who they are. They don’t know what they are, what they’re doing. And they’re not loud about it. The ransomware groups are loud because
They want it to be known that if you get hit with our ransom, you’re not going to get your data back unless you pay the ransom. Or we’re going to extort you with the data too. We’re going release that as well. So LockBit, Alphabet, all those guys. Or not Alphabet, but Alphavie. All those guys, they need to be loud about what they do because they need the victims to believe or know that the only way I might get out of this is to pay my ransom. Now, if I have backups, maybe I’m good. There was a report yesterday or two days ago.
that the average time to ransom, TTR, is about 14 hours now. That’s the average. Some of the good ones can do it in seven to eight hours. So if they’re doing that, they’re not getting in the backups. So your backups could still work. If you have backups, most companies don’t have them or don’t test it, so they don’t know if it works. Correct. Right. Because they don’t. No, yes. Right. Yeah.
Manoj Tandon (16:49.774)
And most of their backups still don’t work though. Darren, mean 70, what’s the stat on that? 70%, right? 70%.
Darren Mott (16:59.086)
Sure, but I mean if you’re happy to be the one lucky one that your backups work, you’re good to go. But you’re going to be the rarity. Everybody else has got to decide. They have to decide, am I paying the ransom or not? Because in the FBI, they will say, don’t pay the ransom. There’s plenty of entities that will say, don’t pay the ransom because all it does is entice them to continue to do more. My argument is that’s a bad argument simply because you can’t get everybody to stop paying the ransom.
So let’s just stop saying that. You shouldn’t, but we understand if you have to. There was a thing going around a year ago where they were proposing regulations or rules or laws that said, we’re going to fine or punish the people that pay the ransom. Well, that’s stupid. Why would you double punish a victim already? mean, it is what it is. mean, there’s ways you can make that. You can make it so they have better cybersecurity by using carrots instead of sticks, but everybody wants to use a stick.
Manoj Tandon (17:39.422)
That’s crazy.
Manoj Tandon (17:51.892)
I mean, imagine that Colonial Pipeline if they had not paid the ransom and they were operational, they just shut down. So now our natural gas prices stay up.
Darren Mott (17:57.612)
Well, let’s keep in mind that the…
Yeah, but Colonial Pipeline didn’t know what they didn’t know, right? So it would hit their business office. It didn’t hit their distribution and their pumping and all that other stuff. So that could have continued on. They just didn’t know any better. But you’re right. They had to pay the ransom to carry on. It still caused a host of problems, but it is what But again, here’s the argument I make all the time on every podcast. Colonial Pipeline, I’m pretty sure they make money. I’m pretty sure they’re not in the poorhouse and not, you
Manoj Tandon (18:11.272)
That’s right.
Darren Mott (18:30.926)
claiming, filing their taxes, hoping to get all the tax breaks. They make plenty of money that they should have the good cybersecurity in place, but they don’t. So for a small company, a medium sized company, how are you doing it? So it’s a lesson that no one wants to learn the lesson that these big company, mean, Microsoft, how many times we gotta hear about Microsoft? How many times you have to update your windows once a month because there’s 70 vulnerabilities they found. So.
At least they’re updating, right? But again, then who patches if the small ones aren’t patching? So I say all the time, find someone to help you at least understand what I like to call the cybers. I’m going to copyright the cybers because no one else uses that term. But I kind of use it it makes me laugh. Because I always talk about politicians always trying to do the cybers. And they need to stop trying to do it because they don’t do it very well. That’s it. Again, I’m running into tangential areas here.
Manoj Tandon (19:09.822)
Go ahead. Well, you’re not going tangential because you summarized almost 160 podcasts. So we’ve had this issue continues. It continues in the enterprise. It continues in the medium business.
Darren Mott (19:23.278)
Yeah, right.
Manoj Tandon (19:35.634)
I don’t see it changing because foundationally until the owners of these operations actually understand what real cyber risk is and how it comes about, they are going to not invest in it. To them, this is just an insurance, it’s disaster avoidance. That’s.
Darren Mott (19:55.978)
Right. I, yeah, I reposted a guy’s post today on LinkedIn that makes a great point about proactive versus reactive. You know, the average cost of a data breach now is roughly four to $5 million. So, you know, let’s let’s assume that’s going to happen to you in the next five years. Everybody’s going to get hit at some point if they don’t do anything.
So are you preparing for that four to five million a year? Or are you paying maybe a hundred thousand a year for preventative measures? Because if you pay a hundred thousand over the five years, you’re only paying half a million versus the four million or five million dollar hit you get in that one instance. I don’t think enough companies recognize that because again, cyber is a cost. It’s not it’s not going to make you money unless you’re in cybersecurity, then it will. But if you’re not in cybersecurity, doing the cyber stuff is not going to make you money. It’s going to lose you money. But they don’t recognize the
annual loss expectancy versus the single loss experience or expectancy.
Manoj Tandon (20:47.78)
Yeah, they don’t. they are absolutely not bringing in their people and processes into the equation. A lot of people are just throwing tech at the thing, which…
Darren Mott (21:00.406)
Mm-hmm.
Manoj Tandon (21:03.582)
To me, that’s just like, okay, you checked a box that didn’t really go anywhere because unless you are really looking at the process and the governance that the tech is supporting, it doesn’t matter because I’m just gonna walk in the front door. You can have all the bolts you want.
Darren Mott (21:20.556)
Right, I made a post a week ago so go that the hackers aren’t hacking in, they’re logging in.
Manoj Tandon (21:24.872)
Yeah.
Darren Mott (21:25.166)
I mean, put all the EDR on you want. It’s good to have it. I understand if you can afford it and you can use it, that’s great. But there’s now methodologies, bad guys have figured out how to get around the EDR. And most of the time they don’t really care because, you know, if they can find the vulnerability, great, they’ll find it exploited if they can. I mean, how many times we got to talk about Cisco and Palo Alto and Fortinet and all of their devices having vulnerabilities that give you user level access if you configure it right. The bad guys know that. They look for
Manoj Tandon (21:45.106)
Yeah.
Darren Mott (21:51.81)
the patching. So when the CVE comes out, they say, okay, what’s this vulnerability? How do I then utilize against it? Because I know that at least half of the companies that utilize this technology aren’t patching and anytime soon, mean, Move It is the perfect example.
I mean, that lasted six months and the patch was out in June and November people were still getting pounded by move it vulnerabilities. it’s, I mean, we talk about education a lot too. Being an educator, I’m trying to now in my, with my own business, try to blend education and cybersecurity into, cause those are my passions, right? How do I teach people to understand this? And that’s what I kind of, what I try to do with my podcast is
I don’t get into technicals. can’t code. I’m going to be honest with you. I am not a coder. I’m not going to come in and code your network correctly with all your tools. That’s not my thing. But I can understand strategically and tactically, here’s the things you should do that will lower your risk. Because all you’re going to do, any company should want to do is lower the risks. So when they go to sleep at night, they know they’ve done pretty much the most that they can do to keep themselves protected. But most don’t take the basics and say,
What don’t, where’s my problems? I’ve created a 10 piece risk assessment for like nonprofits and the church I’m working with to say, hey, look, I know you’re not doing anything. So I’m going to start with these 10 simple things. I mean, you can use the CIS 18. If you want to go NIST 800 171 and bring in 110 controls, you do that. You do you. That’s not my thing. Do these 10 basic things. I know you’re not doing them. Let’s figure out what you’re not doing. And then let’s patch that gap system and then work from there.
Manoj Tandon (23:17.204)
Dude, I’d just say DOOTS is a top three. I can tell you there’s a lot of companies that don’t even get that and big corporations, right? Where, forget about the little guy. But you know, it brings up a point here. Like, let’s take something as simple as patching. I’d love to get your opinion on it. You should, like you said, update in the theoretical world your Microsoft environment whenever Microsoft is releasing those patches.
Darren Mott (23:21.229)
Yeah.
Right. Yeah.
Darren Mott (23:34.956)
Mm-hmm.
Manoj Tandon (23:43.934)
but in a real world in this medium business that’s let’s say there’s a plastics manufacturer.
These guys are running antiquated equipment and the OEM on that equipment is not, they never update anything. Those guys suck at it. I’m just gonna call it for what it is. mean, they’re totally, and if you want the latest, then you have to, huge capital expenditure to get the latest update. It’s unreasonable to expect those guys to be able to then patch those machines that would actually shut down their operation, because they couldn’t.
Darren Mott (24:00.823)
Mm-hmm.
Manoj Tandon (24:21.254)
run anymore.
Darren Mott (24:22.658)
I think not only that I think they don’t know I don’t they don’t know what patching they have to do. They’re not aware of that. Go ahead. I’m sorry.
Manoj Tandon (24:26.398)
They don’t even, yeah. So what do they do? So how do you address, what’s your, how do you go about addressing that?
Darren Mott (24:33.302)
Yeah. So you have to look, think company, well, first of all, you need someone in your leadership that at least will take cyber ownership to say, look, here’s the worst case scenario if this happens. So let’s use your plastic manufacturing example. Some leader in that organization, I say, okay, let’s say we get hit with something.
But again, the problem is they don’t know what they’re gonna get hit with. Is it gonna be business email compromise? Is it gonna be ransomware? Is it gonna be attack against the OT part of the side? And if you bring in OT, that’s a whole different conversation altogether than just the IT, right? So your example brings in both IT and OT, operational technology. But so when you need that leader to say, I recognize that if we go down tomorrow because of pick your poison problem, and again,
Manoj Tandon (25:09.138)
Yes.
Darren Mott (25:20.63)
In all my podcasts, I say the same thing, understand the threats targeting you so you can assess your risk. Most companies don’t understand the threats targeting you. I have a whole pyramid of threats that go from the skip kitties all the way to nation state actors. So depending on if you’re a plastics company, if you’re providing plastics to national defense, like you’re creating the windshields to the F-35 fighter plane,
your information is pretty important. So China is probably targeting your company to figure out how do you make the plastic? And then maybe they need to take you down if there’s going to be I mean, there’s a lot of different mechanisms here. But if you don’t understand who’s targeting you, you can’t protect against it. So some leader has to actually take the time to say, look, there’s two types of companies in this world. Those that have been hacked, those that have not been hacked yet. Where do you land?
Manoj Tandon (25:51.486)
Sure.
Darren Mott (26:06.058)
Or that’s a third part that we don’t talk about much. Those are currently hacked that don’t know it. That’s the third one, but they’re part of the first part too. But so you have to look and say, we haven’t we’ve been lucky. We’ve dodged the bullet. Let’s keep dodging the bullet by figuring out how to make the bullet go elsewhere. And again, without that leadership, then you’re never going to get to that point because no one cares, right? We’ve talked about it before. No one, you know, small, medium. They don’t think about it. They don’t care. that’s why, you know, that’s why I started my consulting things. I think I want to talk to companies. They look.
Here’s what, at a minimum, start with just here’s what you need, what you don’t know, here’s what you don’t know and how you can kind of start to address it if you choose to address it. If you don’t want to address it, that’s the choice you make. You’ve made that risk assessment. You’ve taken risk avoidance is the way you’re going. And you’re knocking on wood, that nothing ever happens. eventually, something will happen. Because the bad guys will find you eventually.
Manoj Tandon (26:57.592)
Yeah, especially if you’re part of a supply chain that is really juicy, right? Like you mentioned, if you’re making the windshield to an F-35 or you’re a supplier to, I don’t know, the NSA in some way, or you do whatever, you make sites for guns, whatever the case may be. And you might be a gateway into a much larger operation, right? And it’s…
Darren Mott (27:00.984)
Mm.
Manoj Tandon (27:27.176)
those guys need to really look at sectioning off their networks in some ways and understanding it. But the other thing that happens is there’s so much jargon. mean, in the cybersecurity industry, we have more acronyms than the US military, or we’re pretty darn close to it. You can just throw them out all day, PAM, MFA, you know?
Zero trust, edge devices, you just go out there, just talk. Someone that’s running a business is gonna have their head explode because they’re not gonna understand what are you talking about, right? How do you take, is there a place, let me ask the question this way. Is there a place to…
take something like the MITRE ATT &CK framework and say, these are all the TTPs that we are vulnerable to. Okay, because no one is vulnerable to all of it. I mean, there might be threats that someone’s not gonna exploit. And then say, of these, the bad actors that operate in our sector really use these three.
So if we’re gonna shore up out of 12, we can’t afford to do all 12. We just don’t have the money. But do we do these three and this is what it’ll prevent. Is that a viable approach or do you think that’s even, Darren?
Darren Mott (29:07.502)
I think so, but I think it still goes back to the basic piece is do you understand who’s targeting you? Right? If you’re a bank, you should know that criminal organizations are the ones going to target because they want your money. Nation states aren’t necessarily going to target a credit union because they don’t necessarily need the money per se. North Korea does, but they do cryptocurrency specifically, not only targeting banks. So that’s an exception. But if you don’t understand who’s hitting you, then how would you even know which ones you need to look at? again, think it goes again, it goes back to the leadership piece.
You have to have someone in your organization that’s going to lead the cyber piece to say, I recognize this is going to be a problem. So let’s start figuring out.
What are the basics? We start with the basics. Start. You’re at nothing. So the MITRE framework is something that’s that’s going to be over here, way over, like over here. You got to get these things in place first before you even start talking about the MITRE attack framework. Which pieces of this do we need to worry about? You need to worry about do I know do I have a baseline for my hardware, do I have baseline for my software? Do I have the right password management in place? Do I have access controls correctly? Do I have an incident response plan? Have I tested the incident response plan? Have I educated the employees to understand what the threats are? How do I do that? And then you can worry about OK,
All those things are in place. We’ve done a couple of things to get us a little better further down the road. Now we need to go to that medium road. You need to, you need to walk. I mean, sorry, need to crawl, walk and run. Let’s crawl first. MITRE ATT framework’s probably in the walking phase. So once you’ve got to crawling, let’s figure out how to walk. Let’s take MITRE in and then look at that. Okay, which of these pieces are important to us? And that’s where most companies are gonna have to look in themselves and say, look, no one here can do this. Sure, we have IT guys.
IT guys, as you know, are not cyber guys, cybersecurity guys. They’re cyber guys, not cybersecurity guys. Yeah, they’re not, but they need to work together. They need to, like, you have to have an IT person and a cybersecurity person that can work together. All my experience is they fight against each other. I don’t get it. I don’t understand that. The organization I just came from, all they, all IT, we were the cybersecurity piece.
Manoj Tandon (30:45.458)
I’m so glad you’re saying this and it’s not me. So go keep going. Yes. Yeah.
Darren Mott (31:05.452)
The IT people were pains in my ass because they just didn’t want to say, OK, I understand what you’re saying. Let’s work to fix it. It was like, ooh, this is our network. If you say that, then I have to turn off the guest Wi-Fi. Whatever. mean, pick a problem. But it’s not like we were trying to be adversarial, but it seems to be there’s always that adversarial piece. But the IT guys should appreciate the cybersecurity folks. And the cybersecurity folks need to appreciate the IT folks because the IT has to stay up to go.
so that the cybersecurity people have something to look at and the IT people need the cybersecurity people say, look, here’s a hole, we need to fix this hole because someone’s gonna come in from that. But that’s my experience. Maybe your mileage may vary there differently, but I think that’s.
Manoj Tandon (31:45.328)
No, it doesn’t. you know, one of the things that a lot of people we work with don’t have a CISO, but a lot of these organizations where one does exist, it’s still today, a lot of them report into IT, right? And to me, there is an inherent conflict of interest there.
Darren Mott (32:04.204)
Yeah, right, right,
Darren Mott (32:09.356)
And I think and I think that the rise of the virtual and the fractional CISO is good. But I don’t know if that’s a job I would want because I don’t want the risk pushed on me. I would do I would do that for a company, but I’m not taking the risk on it’s still your risk because I’m to tell you how to reduce your risk. If you don’t listen to my recommendation, that’s on you. That’s your that’s that’s the executives, the executive board fall who said, hey, this guy said we should have done these things. We decided not to do them because I couldn’t get my ESPN fantasy football in time. So I had to keep that hole.
So, you know, we just got hacked. We’re going to fire him anyway, because he didn’t protect us like he was supposed to. And that’s, I think, larger companies are moving away from that model, but small and medium are still trying to figure out how that space works. Because you can’t, a lot of them can’t afford a full-time CISO. And a lot of them don’t think they need, they don’t need a part-time one because they have their IT guy who’s going to do the cybersecurity stuff. Then the IT guy is going to tell the leadership,
Here’s the things I think we need to do and leadership can’t do that, can’t afford it because and then there’s no, he doesn’t have the backup to say, well, here’s why you need to do it because that’s not in his skillset.
Manoj Tandon (33:09.779)
Yeah.
Manoj Tandon (33:15.036)
No, he’s a techie and he doesn’t know how that affects operations. It gets back to if you don’t have someone in leadership that’s gonna take ownership of this problem, well, you got an uphill battle.
Darren Mott (33:17.43)
Mm-hmm. That’s fine. There’s nothing wrong with that.
Darren Mott (33:25.742)
Mm-hmm.
Darren Mott (33:29.474)
We all do, we all do, but it’s job security, right?
Manoj Tandon (33:32.456)
Yeah, hey, you know, but you would, I’d like to see the world change a little bit in this regard. And I don’t know. And there, the data’s out there. It’s all hiding in plain sight. You just go out there and Google it. There’s thousands of us out there that have said the same thing, yet the same pattern keeps repeating, just keeps happening. So, you know, of…
Darren Mott (33:43.565)
Mm-hmm.
Manoj Tandon (33:56.388)
those companies, well, let me ask another question. To get the FBI’s attention if you’ve been ransomed, how big does the number have to be?
Darren Mott (34:05.582)
Good question. That’s a great question. Depends on where you are. If you’re in Mobile, Alabama, you may not need a big ransom for them to come help you because it’s a small office with a very small corporate.
infrastructure. And so they may want to go do that because they really don’t have that’s going to be big to them. If you’re in New York, that’s a different situation because there’s people getting hit with ransomware all day long. So if you don’t have a certain threshold value, then they may not even come out to talk to you. So it’s going to depend on the the on the office that represents you. Smaller offices will do have a lesser lesser threshold than larger offices. But even then
For most ransomware stuff, the FBI will respond simply because there’s intelligence in that forensic information that’s valuable to understand who’s the group doing it, right? in that case, if they can figure out, this is LockBit’s ransomware tool, right? LockBit creates the ransomware and then affiliates use it, blah, blah, blah. So they know it’s LockBit and maybe they have the decryption code to unlock it. They certainly, the FBI has a full cache of
fully accessible decryption codes. Most of probably don’t work anymore because once they’re realized, the bad guys create new ones and it doesn’t matter. But there may be some that work that you may be able to encrypt it. So if you have a ransomware attack, certainly go there. There’s a bigger issue than ransomware that most companies don’t think about because the news doesn’t talk about it enough because it’s not sexy and that’s business email compromise. It’s a much huger issue, much more loss. It’s like 29 times loss per year than ransomware. And that is when a bad guy gets into somebody’s email.
or fictitiously creates an invoice from a vendor and sends it to the company and says, here’s my invoice, pay it, blah, blah. Well, most people don’t realize, most people will wait if they suffer that loss, like they pay that $100,000 invoice and realize it was wrong, it was fake. They’ll like spend a lot of time doing whatever before they actually call the FBI because they’re afraid or whatever. However, if…
Manoj Tandon (35:43.846)
Yeah
Darren Mott (36:03.798)
you are a victim of a business email compromise and you contact the FBI within like 48 to 72 hours, there’s a 70 % chance you can get your money back. Most companies don’t realize that. There’s a thing you have to go through with IC3, but they’re very quick to the trigger. if you say, know, an hour ago I sent out a $200,000 wire payment, IC3, the Internet Crime Complaint Center, which is basically the cyber portal for the FBI,
will work with the local office and they will most 70 % of the time or more depending on the timeframe, the money will be reversed. Now there’s certain there’s aspects to that where you understand how the bad guys work. They’re doing this to multiple companies and all goes into one pot and then they up wire transferring it out, but they don’t know when it’s there. So they’ll go look at it periodically and then pull it out.
Manoj Tandon (36:34.61)
Wow
Darren Mott (36:52.94)
The way that the kill chain works is whoever is the first one to report it, they go to that pot. If the pot has money in it and it’s your, you’ll get your money back. But if you’re like the fourth person and the money’s gone, then you may not get the money back. So it depends on it’s or it’s a whole thing. But all that to be said, if you are a victim of business email compromise, contact the FBI quickly. And I’ll add an addition to that. Most businesses need to know who their local FBI contact is because it’s better to know who they are.
Manoj Tandon (37:06.644)
Darren Mott (37:21.932)
before you have an incident than when you’re in the middle of the incident figuring out who do we have to call? Who do we go to?
Manoj Tandon (37:27.165)
So how do they do they pick up the phone and call the FBI?
Darren Mott (37:30.572)
Yes, every FBI office has what’s called an office or a private sector coordinator. That person’s role is to understand the businesses in their area of responsibility. So like I was that for the Huntsville for the Birmingham division in northern Alabama. So I would go out and companies would call and say, hey, can you have someone come talk to us about cyber threats? Can you have someone come talk to us about white collar, whatever, whatever they want to talk to most of them want to talk about cyber stuff, right? Because that’s one that everybody knows about. Because, you know, white collar crime is
you’ll get that but most people wanted to understand the cyber threat. So then I would get to know who that person is, I would document that, you know, for company A, this is the point of contact. So I would know who that is, they would know who I am, because a lot of times, we get information that a company in our AOR has been hacked, because another three letter agency or somebody else has found that information and said, hey, we believe this company is in your AOR, here’s their data that’s been stolen, they don’t realize it’s been they’ve been hacked, the actor still in the network.
will go to the company if we know a point of contact, we can go to the company and say, hey, here’s the situation when you’ve already got that relationship. Any company in any place in the country who’s listening to me now, you can call the FBI right now and they will put you in touch with the private sector coordinator to set up a meeting to have them come out and do an awareness training cost you nothing. But then
They can get you in touch with or at least make a contact with someone on the cyber squad so that when you have you have a cyber and so you can you know who to contact. Do I have time to tell you a quick story about where this went wrong for somebody? So there was a CIO for a company that contacted me out of the blue. Now this CIO knew had a friend who knew me personally. He was the other CIO was part of a group of five that I had that were very important companies in.
Manoj Tandon (39:02.158)
Yes, yes, you do.
Darren Mott (39:21.708)
the Northern Alabama region. So I would talk to them quarterly and give them information and do presentation like that. So that the other CIO contacts him to hand me somebody at the FBI. He’s called Darren, he’ll tell you what you need to know. So the CIO calls me and says, Hey, I got I was reached out by this agent they claim to be from the Birmingham division cyber squad. They want to tell me something about my network. I said, Okay, yeah, he is a cyber agent in Birmingham. And if he’s calling you
You want to call him back. He’s got some information. I didn’t know what the information was. This was new to me, but I confirmed he was who he said he was. Well, the CIO apparently didn’t believe me because did nothing. Didn’t contact the agent back. The supervisor of the cyber squad set this CIO an email saying, look, we have intelligence that this ransomware group is in your network right now because we had intelligence seeing it happen. We were watching them move files from here into this company’s network.
Manoj Tandon (39:49.684)
Okay.
Darren Mott (40:14.046)
And the supervisor said, here’s how you can find the files. Here’s how you can remove the files. They are ransomware files. You want to get them off your net system. Well, the CIO didn’t believe that email, didn’t believe me, didn’t believe the original agent, decided to email the special agent in charge of the Birmingham division to confirm that all three of us were who we thought we were. Keep in mind, bad guys are in the system already. CIO…
Manoj Tandon (40:38.76)
Yeah, he’s on the clock at this point.
Darren Mott (40:41.134)
Well, no, CIO emails from their internal email system. So the bad guys saw the email, we assume, saw the email between the CIO and the SAC, and they show up the next morning, system’s locked up. They got hit with a ransomware. So again, didn’t have a contact in the FBI. If they’d had the contact, they would have protected themselves, because we would have said, here’s the stuff. They could have removed the files, and they could have been clear. But again, that’s an example why you need to know who your FBI guy is.
Manoj Tandon (41:09.842)
I think that advice was worth the price of admission to this episode for sure, which was free, but that’s brilliant. I think most companies do not know to do that. That is really awesome. I don’t want you to go before you talk about your book. I’d like to tell us a little bit about Get Cyber Smart. What’s the story behind it? And I do want to sign copy by the way.
Darren Mott (41:25.645)
Right.
Manoj Tandon (41:39.793)
So.
Darren Mott (41:39.928)
Sure, give me your address, I’ll be to send it to you and Emily. So about a year ago, I said, have a lot of stories. I have a lot of different anecdotes and stories about victims I’ve spoken to, people I’ve spoken to. And so I came up with the idea of, me put together kind of, again, the basics, right? Again, being an educator, being in cybersecurity, I wanted to bring those two things together. So I put together a bunch of different stories and organized it in a way that…
provides information. It’s basic information, right? When you read the book, you’ll say, you know, kid, I do all these things. This makes perfect sense to me. it’s not really made for you. It’s made for the people who call you and say, how do I create multi-factors in that case? I don’t understand what that is. So there’s stuff on, so every chapter starts with a story, but then it goes into a point that the story relates to. like there’s a chapter on protecting your family and at home. So protecting your kids and the elderly. So there’s two stories in there about
Manoj Tandon (42:30.452)
This is a chapter on particular family and, I think it’s a particular case in your, in the album, it says, which one is in there and which one is in I think that’s that you can listen on the album that’s, know, in the album.
Darren Mott (42:37.71)
a lady that I helped prevent become a victim of a romance scam. And there’s another one where I helped a family protect their son from sextortion. So the stories kind of lead to what those things are. And then there’s mechanisms to protecting yourself from that.
There’s references at the end of every chapter that say, here’s more on all of these topics if you want to go to it. One thing I will say, when I wrote it, I had the idea of creating a YouTube channel to do certain videos on parts of it. I have not got around to it. So if you see the book and you go to the YouTube channel, there’s nothing there. So I just haven’t.
haven’t done that part. I’ve kind of fallen down on that. But the book I finished, I wrote it myself, published it myself. there are some type 17 typos. There’s one guy who I gave a who bought it, who decided to send me an email saying, here’s all your typos. I’m like, yeah, well, I can’t fix that now. So it is what it is. You won’t necessarily notice them if you’re reading quickly, but you may see them. It is what it is. I will say this anybody. Let me tell you this. So anybody who’s listening to this podcast, who would like a who would like a free PDF version of the book, if you email me
Manoj Tandon (43:26.706)
It’s okay.
Darren Mott (43:38.262)
I will send you a free PDF version.
Manoj Tandon (43:40.382)
What is your email?
Darren Mott (43:42.03)
Darren at GoldShieldCyber.com. Or you can find me on LinkedIn too. can me up on LinkedIn if that’s easier, but either way. But yeah, Darren at GoldShieldCyber.com.
Manoj Tandon (43:45.854)
Thank you.
Manoj Tandon (43:52.936)
Fantastic. So Darren, we’re down to a couple minutes here. We want you to have the floor and talk about anything. Plug whatever you want. Anything that you want our audience to know about.
Darren Mott (44:04.268)
Well, I appreciate you having me on. Like I said, I love coming on podcasts because I get to kind of freeform my thoughts more than I do on my own podcast, where I kind of have to like you do. I’m going to ask you a question, hope you can answer, and I follow up on it. So if anybody wants me to have me on a podcast, I have to come talk about the FBI, talk about other stuff. One of the things we didn’t get into is my dealings with Russia. So I spent two years of my life at FBI headquarters trying to get the Russians to help us with cyber stuff.
I went to St. Petersburg, Russia three times, saw the Hermitage, the largest museum in the world in St. Petersburg three times. I was drunk all three times because they would meet with us for two hours, take us to this Georgian restaurant. And if you’ve ever had, and I’m going to offend Georgians here and I’m not meaning to, this is the country of Georgia, not the state of Georgia, that Georgian food is not for me, right? It’s just not, lamb tongue is not my thing. But I mean, they may, but you had to drink the vodka. So I’m not a drinker, but when I was in Russia, I was a drinker.
Manoj Tandon (44:56.176)
Okay.
Darren Mott (45:01.494)
And then they would take us to walk through the Hermitage for three hours. saw the same freaking Fabergé eggs three times. they’re very nice, but we always started at the same place. And ultimately, I will say we had some success with that because they ended up arresting the guy for us. And we got restitution on two cases. Not huge restitution, but two bad guys paid Apple and American Express some restitution for their crimes. So there was a little success there, but it was what it was.
Manoj Tandon (45:29.746)
That should be the prelude to part two.
Darren Mott (45:32.844)
Yes, it should. Yeah, we talk all about Russia and all that stuff and them listening in on our rooms and having our rooms bugged and following us all over the place, all that kind of stuff. Yeah, so that was good times. But.
Manoj Tandon (45:41.886)
Well.
There’s, please keep going. Yeah.
Darren Mott (45:47.404)
No, that’s it. And I was going to say, in my, pod, you mentioned the podcast at the beginning, cyber guy, cyber guy podcast, which is my original podcast, actually killed it for a year because was doing the cyber smart morning news three times, five times a week. So I didn’t have time for it, but they’re, they’re both now going cyber in both cases is spelled C Y B U R the BU is a reference to the BU and bureau federal bureau investigation. would call like our, our phone, our view phone, our view car, like on stuff. And then tactical cyber is more of a
Here’s practical things you need to do to protect yourself from either your business or your family, without, you know, let’s stop talking about strategies and talk about tactics. Certainly politicians like to talk about the cyber strategies, but they suck at the tactical piece. And I’m sick of strategies. Let’s talk about tactics. So those are my three key areas. My company is new. I’m still trying to figure out what that looks like, but it’s okay. It’s a fun process. I’m now a solopreneur. I have no idea what I’m doing, but it’s fun.
Manoj Tandon (46:38.42)
I’m sure you’re gonna be immensely successful, The industry needs people like you. But it’s been a pleasure having you on. We really appreciate you taking time out of your busy day and would love to get you back for part two. mean, there’s so much about the GRU that I’d love to ask.
Darren Mott (46:47.79)
Well, thank you.
Darren Mott (47:07.688)
FSB FS I didn’t deal with the GA you I did FSB SVR or now I didn’t do SVR as MSB and MVD were the two kind of main ones I had to deal with
Manoj Tandon (47:08.881)
FSB!
Manoj Tandon (47:15.752)
Well, would love to get some insights. So we will definitely get you scheduled back because there’s a lot of people that would be interested about that topic. Well, hey, Darren, again, thank you.
Darren Mott (47:19.894)
Anytime.
Darren Mott (47:28.47)
Yeah. I remember most of my trips to Rajshri, even though he’s drunk half-time. Sorry.
Manoj Tandon (47:37.0)
Well, we’ll definitely reach out and schedule that, but thank you so much for doing this, Darren. Really appreciate you. It was wonderful talking to you. Thank you.
Darren Mott (47:46.52)
Thanks for having me.
Read more about Darren on his LinkedIn
Get his book
Check out the vCISO bot we created
Check out the other episodes in Season 16:
Ep. 0 Jim Love – Company Data on ChatGPT: Why What You Share Could Stay Forever
Ep. 1 Ken Underhill – Breaking Into Cybersecurity: Job Hunting Tips and Ghost Job Realities
Ep. 2 Allie Hunter – The Dark Side of Online Gaming
Ep. 3 Purandar Das and Ken Foster – “Delete My Data” Doesn’t work
Ep. 4 Tammy Klotz – Communicate properly with your team
Ep. 5 Sandra Estok – My Identity was Stolen
Ep. 6 Brett Johnson – Inside the Mind of a Former Cybercriminal
Ep. 7 Darren Mott – “Hackers Aren’t Breaking In—They’re Logging In”
Ep. 8 Stacey Champagne – “Red Flags in Cybersecurity Coaching”
Ep. 9 Craig Taylor – Phishing, Encryption, and Cybersecurity Training
Ep. 10 Christopher Rees – Will AI Change the Way We Learn
About Darren Mott

Darren Mott, author of get cyber smart, is a retired FBI agent with 20 years of experience in cyber and counterintelligence investigations.
He played a key role in strengthening FBI-Russian collaboration on cyber threats and created the FBI’s first program blending counterintelligence and cyber disciplines.
Now, he owns an investigative and consulting company called Gold Shield Cyber. Mott holds master’s degrees in education and cybersecurity policy.
Darren hosts The CyBUr Guy Podcast, CyBUr Smart Morning News Update and the Tactical Cyber Podcast.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
