Security Confidential S16 E9 Craig Taylor

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to Craig Taylor. Craig is a seasoned cybersecurity expert and entrepreneur with nearly 30 years of experience managing risk across industries—from Fortune 500 corporations to SMBs. As the Co-Founder and CEO of CyberHoot, he has pioneered a positive reinforcement approach to cybersecurity education, helping businesses eliminate risky behaviors and build a positive cybersecurity culture. With a background in psychology and extensive experience leading security programs at Chase Paymentech, Vistaprint, and DXC Technology, Craig specializes in incident response, governance, and compliance. A CISSP-certified professional since 2001, he is a recognized thought leader, public speaker, and advocate for making cybersecurity training engaging, fun, and effective.

00:00 Introduction

01:16 Our guest

08:40 There are two types of companies

10:00 We taught them how to Phish

12:12 Business Email compromise

13:50 Go back to the way your parents ran security

16:19 What do I do first?

26:12 Changing your passwords is not good for you

29:00 Encryption

31:30 What to look for in a Password Manager

35:17 “Unsubscribe” button mishap

46:15 Cyberhoot

49:05 Free Training from Cyberhoot

Transcript

Manoj Tandon: Hello everyone, this is your host Manoj Tandon with another episode of Dark Rhiino Security: Security Confidential. We have another fabulous guest, but before we get to him, I gotta remind you—show us a little love, hit the subscribe and like button. It does wonders for the algorithm and helps us keep bringing this content to you.

Getting back to the show, today we have Craig Taylor joining us. He’s been in the business for over 30 years and has been a CISSP since 2001, so that should give you an indication of how long he’s been in cybersecurity. He’s currently the CEO of CyberHoot and has worked with companies like Chase Paymentech, Vistaprint, and DXC Technologies. He’s spent years looking at risk across multiple industries and really focusing on the people side of cyber.

Craig, thank you for being here and giving us your time.

Craig Taylor: Manoj, it’s my pleasure. I’m really excited about this. We had a little time to get to know each other beforehand, and I’m looking forward to this—it’s going to be fun.

Manoj Tandon: That’s the most important thing—it should be fun. Most people are listening in their cars, so they should enjoy it. Let’s start with your background. How did you get into cybersecurity?

Craig Taylor: My degree is in psychology. I studied what motivates people—how humans and even animals learn through operant conditioning, positive and negative reinforcement. I quickly realized I didn’t want to pursue a PhD or become a counselor—I just wanted to understand what makes people tick.

At the same time, I had a passion for technology. I worked on an Apple IIe as a kid, loved the early internet, and worked in university computer labs in the early ’90s. That was when email and the internet were just becoming a thing.

Right out of college, I found a job through an online posting—on Net News Protocol—at a firewall company around 1994. I didn’t know much about internet protocols at the time, so I bought every O’Reilly book I could find and taught myself. That’s how my cybersecurity journey started.

Over time, I worked at several companies, and in 1999 I joined CSC, which later became DXC. I worked in their web hosting division before AWS existed, got my CISSP, and spent the next 20–25 years in cybersecurity.

About 10 years ago, I co-founded CyberHoot. It was really a combination of my psychology background, my love of teaching, and my cybersecurity experience.

Manoj Tandon: So what exactly does CyberHoot do?

Craig Taylor: We teach cyber literacy. Most people have basic computer literacy, but they’ve never been taught how to safely operate in a digital environment.

For example, we teach people how to recognize phishing emails, manage passwords properly, and use tools like password managers and multi-factor authentication. The goal is to give people confidence—so they don’t panic every time they get a suspicious email.

We also use a mix of positive reinforcement and realistic simulations to train behavior effectively.

Manoj Tandon: That’s fantastic. And you’re right—negative reinforcement doesn’t really work. People disengage when they feel punished.

Craig Taylor: Exactly. Some organizations use “three strikes and you’re out” policies, but studies—like one from the University of Zurich—show that this actually makes things worse. People who go through those programs sometimes click more phishing links later, not fewer.

Manoj Tandon: That makes sense. You can’t expect perfection from imperfect humans.

Craig Taylor: Right. And attackers only need one mistake.

Manoj Tandon: That brings us to people as a cybersecurity asset. They’re often underutilized because organizations don’t explain the “why” behind policies.

Craig Taylor: Exactly. When people understand the “why,” they’re much more likely to adopt secure behaviors.

Manoj Tandon: Let’s talk about business email compromise. How do you address that?

Craig Taylor: The key is verification. If something seems off—like an unexpected invoice or a request to change wiring instructions—you must pick up the phone and confirm it using a trusted number.

Never rely solely on email for financial changes. That’s how millions of dollars get lost.

Manoj Tandon: But people don’t want to pick up the phone anymore.

Craig Taylor: True—but if you want to keep your money safe, you have to. I’ve handled multiple incidents this year involving wire fraud—each over $100,000—because someone didn’t verify.

Manoj Tandon: That leads into risk. Where should organizations start?

Craig Taylor: Start with a risk assessment. You have limited time and budget, so you need to prioritize. Identify risks, rank them by likelihood and impact, and focus on what matters most.

I also add “materiality”—how important that risk is to your business. That helps prioritize effectively.

Manoj Tandon: That’s a great point. Not every risk matters equally.

Craig Taylor: Exactly. Focus on what keeps your business running.

Manoj Tandon: And for smaller businesses, hiring a full-time CISO isn’t realistic.

Craig Taylor: That’s where fractional or virtual CISOs come in. You can get expert guidance without the full-time cost.

Manoj Tandon: Let’s shift to passwords. There’s been debate about frequent password changes.

Craig Taylor: NIST has updated its guidance. Frequent forced changes don’t work because people cheat—they just modify existing passwords slightly.

Now the focus is on longer passwords (15+ characters), no forced expiration unless there’s a breach, and using password managers.

Manoj Tandon: That makes sense.

Craig Taylor: It’s all about psychology.

Manoj Tandon: Before we wrap, what are the biggest cybersecurity threats in 2025?

Craig Taylor: AI is a major one—especially deepfakes and privacy concerns. We’re seeing scams where attackers clone voices and trick family members into sending money.

One defense is having a family “safe word” that only trusted people know.

Manoj Tandon: That’s practical advice.

Craig Taylor: Another growing threat is more advanced phishing—AI makes it more convincing, but the fundamentals are the same. People still need to recognize suspicious behavior.

Manoj Tandon: Any final thoughts?

Craig Taylor: At CyberHoot, we’re trying to educate a billion people. We offer free foundational training and phishing simulations at cyberhoot.com/individuals.

If you find value, bring it into your organization. You can also reach us at cyberhoot.com or email sales@cyberhoot.com.

Manoj Tandon: And if someone wants to reach you directly?

Craig Taylor: craig@cyberhoot.com.

Manoj Tandon: Fantastic. Craig, it’s been a pleasure. We’ve only scratched the surface—would love to have you back.

Craig Taylor: I’d love to come back. Thanks, Manoj.

Manoj Tandon: Take care, Craig.

Read more about Craig on his LinkedIn

Learn more about CyberHoot

Access FREE Training with Cyberhoot

Check out the vCISO bot we created

Check out the other episodes in Season 16:

Ep. 0 Jim Love – Company Data on ChatGPT: Why What You Share Could Stay Forever

Ep. 1 Ken Underhill – Breaking Into Cybersecurity: Job Hunting Tips and Ghost Job Realities

Ep. 2 Allie Hunter – The Dark Side of Online Gaming

Ep. 3 Purandar Das and Ken Foster – “Delete My Data” Doesn’t work

Ep. 4 Tammy Klotz – Communicate properly with your team

Ep. 5 Sandra Estok – My Identity was Stolen

Ep. 6 Brett Johnson – Inside the Mind of a Former Cybercriminal

Ep. 7 Darren Mott – “Hackers Aren’t Breaking In—They’re Logging In”

Ep. 8 Stacey Champagne – “Red Flags in Cybersecurity Coaching”

Ep. 9 Craig Taylor – Phishing, Encryption, and Cybersecurity Training

Ep. 10 Christopher Rees – Will AI Change the Way We Learn

Craig M. Taylor is a seasoned cybersecurity expert and entrepreneur with nearly 30 years of
experience managing risk across industries—from Fortune 500 corporations to SMBs. As the
Co-Founder and CISO of CyberHoot, he has pioneered a positive reinforcement approach to
cybersecurity education, helping businesses eliminate risky behaviors and build a culture of
security awareness.


Craig’s journey began with a Bachelor of Arts in Psychology (Honors) from the University of
Guelph in 1994, blending an understanding of human behavior with the technical rigor of
cybersecurity. Over his career, he has led enterprise security programs at Chase Paymentech,
Vistaprint, and DXC Technology (formerly CSC), where he developed cutting-edge risk
management frameworks, compliance programs, and cybersecurity roadmaps. His expertise
spans incident response, governance, and security program development, making him a
sought-after leader in the cybersecurity space.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top