Security Confidential S20 E3 Craig Taylor

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes back Craig Taylor. Craig is a seasoned cybersecurity expert and entrepreneur with nearly 30 years of experience managing risk across industries—from Fortune 500 corporations to SMBs. As the Co-Founder and CEO of CyberHoot, he has pioneered a positive reinforcement approach to cybersecurity education, helping businesses eliminate risky behaviors and build a positive cybersecurity culture. With a background in psychology and extensive experience leading security programs at Chase Paymentech, Vistaprint, and DXC Technology, Craig specializes in incident response, governance, and compliance. A CISSP-certified professional since 2001, he is a recognized thought leader, public speaker, and advocate for making cybersecurity training engaging, fun, and effective.

00:00 Introduction

02:00 Our Guest

02:42 Human Behavior in Cybersecurity

08:32 Understanding Learning Taxonomy in Cybersecurity Training

10:18 Non-Deception Based Phishing Simulations

20:02 The Evolving Threat Landscape with AI

31:02 The Psychology of Behavior Change

38:00 The Human Element in Cybersecurity

43:49 More about Craig

Transcript

Manoj Tandon: Hello everyone. This is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security’s Security Confidential. You know what I’m about to say next. Please hit the like and subscribe button because the algorithm wants you to do it. So just help us out and click the damn thing, and we’ll keep bringing you great guests. Today, we have a Security Confidential veteran, Mr. Craig Taylor. For those of you who don’t remember him, Craig is a cybersecurity expert. He’s been in the game for over 30 years, worked with Fortune 500 companies and SMBs, been around the block a few times, and has been helping businesses eliminate risky behavior and build a positive cybersecurity culture. We’re going to talk about all of that today because he has taken on the hard problem of human behavior change. Welcome back to the show, Craig. Glad to have you here.

Craig Taylor: Thanks, Manoj. It’s great to be back. I really appreciate that introduction.

Manoj Tandon: I tell you, you guys at Hootphish have been working on probably one of the most difficult problems in cybersecurity, and that is the human aspect of it. I’ve said personally on this show that cybersecurity is not a technical issue. It is primarily a human behavior problem. If we don’t address the human side of this, it doesn’t matter what kind of vault we build out of unobtainium. If people just walk the bad actors into that vault, it’s kind of irrelevant. So you’ve chosen the hardest topic, and it’s the one that is least addressed. What’s changed since you were last on the show? Let’s start there.

Craig Taylor: What’s changed since the last episode is that we’ve been granted our patent. We made 19 claims. The primary claim is that we have a non-deception-based phishing simulation performed in the browser. That was what the patent was granted on, and there are 19 claims around all of that that have been granted as well. It’s what I believe to be a disruptive force in the cyber literacy arena of human behavior and trying to get employees to understand and learn the common sense and the modicum of inside knowledge around how phishing works in order to prevent breaches from happening, and to show that it works over a longer period of time. You’ve heard that old phrase, feed a human a fish, F-I-S-H, and you feed them for today. They’re not hungry today. But if you teach them how to fish, F-I-S-H, you feed them for a lifetime. If you just take that F and change it to P-H, that’s essentially what our patent and our approach hope to accomplish. We want to teach people how phishing works, right down to all the minutiae of domain typo squatting without explaining that it’s typo squatting. Just say, you need to look at the letters in this sender because good hackers change one or two letters. That’s what you have to pay attention to if you want to spot and avoid phishing. Then go on from there around urgency, emotionality, authority, and secrecy. Those are all triggers that should make you PAR, P-A-R, pause, assess, report, because something’s amiss. Those four emotional triggers in human psychology are reactionary. It’s like someone cutting you off in traffic. What’s your arm out the window about to do? We want you to PAR there too. Pause, assess, maybe call the police because the person is driving like a maniac. The idea here is that humans learn and change behaviors in very predictable ways that psychology has known about for decades. Since Pavlov, B.F. Skinner, and operant conditioning, we’ve known that rewarded behaviors are repeated. The flip side of that coin is not true. Punished behaviors are never extinguished. They’re reduced for a short period of time, but they’re never extinguished. The only way to change behaviors for the long term is to positively reinforce the good behaviors you want to see more of.

Manoj Tandon: That’s fascinating. So negative reinforcement, or the threat of a negative consequence, does not have the same effect as positive reinforcement?

Craig Taylor: Reinforcement, yes, but I’m going to call you out on one misunderstanding that is very common in the industry. Punishment and negative reinforcement are very different things. Negative reinforcement is a fire alarm. It reinforces you leaving the building because it’s splitting your ears with a loud noise. That’s a negative reinforcement to do some behavior. Punishment is sending you to jail for committing a crime. Those are two different things. Positive reinforcement is saying, when your child has a temper tantrum, let’s calm down, talk about your feelings, and talk about what led to that temper tantrum. Next time when you start feeling that way, let’s use our words instead of throwing yourself down on the ground and beating your fists on the floor. Then, the next time they say, “Dad, I’m getting frustrated. I’m going to scream pretty soon,” you say, “Well, that’s great that you talked about it before you screamed. Let’s talk. Wonderful. Let’s go do something fun instead.” You redirect them. Then you’ve reinforced the good behavior, and that behavior will be repeated down the line because good consequences come from it. That’s where I think the cybersecurity industry has failed for 25 years, Manoj. It’s been trying to find bigger clubs, bigger sticks for clicks, to punish people for making mistakes, when in fact the norm of the industry is deception-based emails to the inbox that are meant to educate. No, they’re meant to assess what people know and don’t know. When they fail those tests, you’ve identified your perpetrators who are going to click on other links, so let’s assign them a 45-minute video. Then you ask yourself, is passive video consumption a good training mechanism, especially when someone is frustrated at failing something? No. Black Hat last year presented a case where people spent 10 seconds on average watching their 10-minute or 45-minute video training on how to spot and avoid phishing because they had failed a phishing test. People don’t want to learn when they’ve just been caught or scolded or shamed or embarrassed. They’re not in a frame of mind to learn.

Manoj Tandon: Explain the taxonomy of learning then. What’s the hierarchy, and how should we progress through it to actually deliver meaningful change in behavior?

Craig Taylor: I think we’re getting into a couple of different psychology phenomena. One is Bloom’s taxonomy of learning. Passive consumption of something is like reading the manual to change the oil in your car. When you read the manual, you still don’t really understand how hard to turn that nut or how physically stuck it could be, and all the nuances of changing your oil. But if you read about it, it’s like watching a video. You get a little bit of a basic understanding. Catch the oil in a pan, put new oil in the top, don’t leave the plug on the bottom off because it’ll just pour out, get a new filter, et cetera. But then if you have to interact with it, that’s like changing the oil yourself, doing it or being shown by your parent. “Let’s change the oil in the car, son or daughter. Here’s what you do. You’ve got to watch when you lift the hood because you could drop it on your finger and it’ll cut your finger off. You’ve got to watch out for these things.” You get this deeper understanding and appreciation of what changing the oil in your car is. That’s interactively doing it, so you get a deeper knowledge base of all the ins and outs of changing the oil in your car. Then if you want to actually learn it to a deeper level still, write about it and teach others about it. Become the parent and show your children. Then you have to learn, “My goodness, I just took all these things for granted. I put gloves on because I didn’t want my hands to get dirty with oil. Now I have to explain why you do that to my son.” You have all these deeper knowledge points around how to do something. That’s another level up on Bloom’s taxonomy of learning.

Manoj Tandon: How are you going to bring that to the world of phishing then?

Craig Taylor: We’ve gotten it to the second level, where we’re doing a non-deception-based simulation. That’s the patent that was granted for non-deception-based phishing simulations in the browser.

Manoj Tandon: Explain “non-deception” in that phrase. What does that mean?

Craig Taylor: The industry as a whole has decided for 25 years that the only measurement we can get out of our users that we can bring to the board of directors, C-suite, or CISO is a click rate. Because that’s technically what we can do, we’ll send a fake email to the inbox because that’s what hackers do and measure how many people in our organization click on that fake email that says, “Reset your password. It’s a Microsoft request,” but the domain name was from something like account-resets-r-us. Who discovers that, who looks at it, and who doesn’t? That’s our click rate. That’s deception-based phishing training, as they call it. But when you fail that test, you get assigned some video remediation program that could be one, two, or more videos, five minutes to 45 minutes of training. It’s still passively consuming how not to make that mistake and how to learn what phishing is by watching a video after the fact, after you failed. A study last year at the Black Hat Conference involving 10,000 users at a healthcare provider in the United States concluded that the average person who failed that deception-based phishing test and was assigned video training afterwards spent 10 seconds watching the video before their attention wandered. They got up and left their desk. They started a phone call. They were chatting on a Slack channel. They were doing anything but watching and listening to the video. It’s almost like they were being punished with this video, and they just pushed it away. They didn’t want to learn from it. So it doesn’t work. The control group, by the way, in that entire 10,000-person study did only 1.7% worse at spotting and avoiding phishing than all the controls and mechanisms of training.

Manoj Tandon: Wow. Statistically not relevant.

Craig Taylor: Right. What is non-deception? It’s sending you a note, Manoj, that says, “This is your phishing test for the month. We want you to go through this email. It is a fictional email that has six or seven components that you need to inspect and label as safe or suspicious, individually and independently of one another.” We’re teaching you a rubric on how phishing works. Let’s say it’s Netflix. Here’s an email from Netflix. The very first question in the easy version of our Hootphish interactive non-deception-based phishing simulation is: is the sender of this Netflix email safe-looking or suspicious-looking? In our database, we have two examples. We have netflix.com, the correct domain for the safe version, and we randomly assign that to each person. Then we have Netflix with no “i” in the middle of it, so it’s netflx.com. That is meant to hone people’s skills at looking at domain names and saying, “Does this make sense?” If they’re not sure, they can look it up, Google it, or ask AI, “Is Netflix spelled N-E-T-F-L-X, or is something wrong here?” They decide and choose safe or unsafe. Then the wizard moves on to the next thing, the subject. In subjects it’s kind of hard, but sometimes there’s urgency, emotionality, secrecy, authority, or spelling mistakes. Those are giveaways that something might be amiss and would be a suspicious indicator. If it’s just a calm statement of fact, it may be indistinguishable from a safe email, so we would mark that safe. They choose again. Then the greeting: is the greeting generic, or is it using your first name? Do they know your first name? All of that gets played in. Then there’s the language quality. Are there any spelling, grammar, or graphical mistakes? Next is the psychology of the email. Is there secrecy, urgency, emotionality, or authority baked into this email to get you to react or do something without thinking through it, without pausing, assessing, and reporting? Then there are links to external websites where it might be a typo-squatted domain or a legitimate domain. Finally, there’s an attachment. Attachments are tough to do because it’s so hard outside of context. Does this attachment belong with this email chain? Those are the six or seven questions we ask in our Hootphish exercise. There’s no deception to it. It’s strictly aboveboard. You know you’re in an exercise. You’re learning a rubric. You’re doing these once a month in our automated Hootphish deployment. Because we’re not sending a fake message to the inbox that purports to be from Microsoft but isn’t Microsoft, we’re just sending an assignment link that brings you to a website branded for your company or your IT provider. There are no holes to punch in the infrastructure. There’s no allow-listing. The only thing you might have to do is turn off URL defense because that can interfere with getting to the assignment on the CyberHoot website where you do this interactive exercise. There’s no deception, and it teaches each individual user how to phish and creates muscle memory. When you know the rubric, you can do these in 30 seconds or less and practice that muscle memory so that when you’re going through your 200 messages a day and something’s off on an email, you just go sender, subject, greeting, spelling, urgency. “Yeah, look at all these indicators here.” Delete it, report it, and move on with your day.

Manoj Tandon: I would bet that 90-some percent of users don’t even know how to view the source of their email. They don’t even know how to find the header, much less find that it’s a bad domain because you have to look at the—

Craig Taylor: We’re not expecting people to go into the headers. You could go deeper and look at headers, but that’s not the exercise here. We’re asking you simply to hover over the sender so that when it says it’s from Microsoft but it’s actually being sent from a Gmail account, you know that’s a fake impersonation attempt. You can delete it right away. It’s much simpler than that. Yes, you can take it to the 11th-degree black belt of phishing identification, but that is not the norm for any of our users. We don’t expect that.

Manoj Tandon: I guess the one question is, everyone has deployed phishing detection tools, especially in the Fortune 500. SMBs, maybe not so much. Are you seeing, as a percentage, any indication of how many legitimate phishing emails can bypass those protections and still land in somebody’s inbox?

Craig Taylor: We’ve got the maximum security turned on in our Google Workspace with the highest level of assignments. My personal experience is that I get two, three, or four of these a week that are legitimate phishing attempts. They are very sophisticated. I think they’re AI-driven because you and I are both public personalities. We go on podcasts, you run the podcast, people know about your likes and dislikes from social media and conversations with the internet research machine. You can look at SPF records and DKIM records and see that CyberHoot uses Brevo because it’s in our SPF record. Why don’t we pretend to be an emergency notification about a campaign that didn’t go through Brevo, that got stuck, and send it to Craig saying, “Your campaign failed. Click here to proceed or investigate.” I’ve gotten those. I look at it and my first instinct is, “Not again. I’ve got to go fix that.” But then the muscle memory kicks in and I go, “Well, who sent that?” It’s not coming from Brevo. I’m like, “Those sneaky devils. Those hackers. They’re trying to catch me,” and I delete it. But I share it in our internal Slack channel and say, “Hey, look at this. This is a good one. It got through our filters. Watch out for it.” I could go on and on with examples, but every week there’s something new.

Manoj Tandon: What you just described would require actually casing out Hootphish and understanding how you guys do business. Do most bad actors have that much time? Do they actually put that much effort into it?

Craig Taylor: It’s no longer the bad actors doing it, Manoj. We live in a world where AI has the task, “Go breach this company.” AI knows that if you have a non-guardrailed frontier LLM from China running on sufficiently powered hardware, you can do anything you want. It’s the AI doing the research online. In an instant, it knows everything about CyberHoot, my company. Hootphish is the exercise, and it can target us based on what’s in the public domain registrar and what’s known about our public personalities. AI has turned what used to be known as spear phishing and whaling into an everyday, industrial-strength process: do it as many times as it takes to breach that company. That’s why I’m seeing an increase in two things: emails that are very specifically targeting me, and emails from people I know who have been breached and are sending things like “DocuSign this” or “Invoice for that” because the number of people falling for these things has gone up. I’m getting all kinds of BEC attacks coming in, so much so that we’re adding a level to our Hootphish. When you answer safe, safe, safe, safe, safe, safe, safe through the six or seven indicators of a phishing email, you get a new pop-up that says, “Yeah, everything in this email is safe. What do you do now? Would you do it? Or do you have to call to verify the change of financial information in this email? Do you have to call to confirm the CEO wants you to buy gift cards?” Everything is legitimate here. It’s indistinguishable from a legitimate email because there are no indicators, but the request itself is bad. So you need to go out of channel and verify. That’s our newest BEC edition that’s coming into Hootphish.

Manoj Tandon: Those are actually things we recommend as part of policy enhancements, especially when it comes to financial transactions. You do not change bank accounts or vendor information unless you’ve physically gotten hold of that vendor on the phone, talked to somebody, and confirmed it. We do that. A lot of our OEMs change bank accounts or whatever, and they say, “Our new information is this.” We contact them and say, “Is this legitimate on your invoice, or what are you doing here?”

Craig Taylor: You have to call them.

Manoj Tandon: Exactly. If they can’t verify it, we won’t send the money.

Craig Taylor: Yep, exactly. That is the future we’re in right now. This is the state of AI and attacks today. You asked the question, can hackers really do it at scale? The answer is no, individual hackers can’t create all of these things manually, but they can task AI to do it, and AI will do it for them.

Manoj Tandon: That’s the thing I really wanted you to bring out, and I’m grateful that you did. What used to be spear phishing and whaling took time, especially on someone like me, where there’s so much personal data out there just because I do this show and I’ve done a lot of talks. They can very easily tailor something, and they do. I get some of those all the time.

Craig Taylor: I do too. Here’s one other tip for your listeners. You get a change request and then a phone call right away afterwards from the same vendor saying, “Hey, yeah, Manoj, I just wanted to let you know we changed our bank. Apologies for being last minute, but I’m calling to confirm you got that request. I know you have a policy to call to verify, so I’m calling you proactively.” You can’t trust that phone call anymore.

Manoj Tandon: You cannot trust that.

Craig Taylor: It could be vishing, or in a worst case, it could even be a video call from someone who looks like the person responsible for making that change and sounds like the person responsible for making that change. That’s called a deepfake. AI is so powerful today, it can take my voice from this podcast and impersonate me with any of my vendors. It can take your voice and do the same. You have to say, “Yes, thank you, but I cannot accept your phone call. I have to call the actual originator back on a known-good number that you did not provide in your email update to me. I will go look at my personal phone numbers for my vendors and call directly.” Just be aware that those deepfakes, whether over the phone or video, can also play into these financial fraud arrangements. That’s what we’re teaching. That’s what our videos call out. That’s what our governance policies in our platform address. We have a whole governance policy section in CyberHoot where you can define your wire-transfer process and get everyone in the finance department to sign off on it, with legally binding signatures. You can have an acceptable-use policy, and we even have an acceptable-use-of-AI policy to govern employees who are wondering, “How the heck do I operate my day-to-day with AI? What am I supposed to do and not do? What am I allowed to do? I need help here because it’s confusing.” We have all of that built into our platform at CyberHoot to help govern, guide, train, and hopefully, with interactive phishing training, address the number one way most mid-sized companies and smaller organizations are breached today: social engineering delivered by phone, email, QR code, SMS, video deepfake, and everything in between.

Manoj Tandon: QR code is a personal favorite. People so blindly get those QR codes and just follow the process. I’ve got a couple of cases where that ended in disaster.

Craig Taylor: Yikes.

Manoj Tandon: You’re absolutely right. I was smiling while you were talking about the phone call because that personally happened to me. I got a call from PNC Bank. It’s a bank we do business with. Same thing, saying yada yada yada, and I said, “Well, that’s great. I’m going to dial the 800 number for customer service and verify what you’re saying.” I just hung up. When I called back, it was all BS. There was no problem with our Zelle platform.

Craig Taylor: Right, exactly. What the hackers are banking on is that they’re going to pick vendors whose customer-service queue is a 30-minute wait with 12 different button presses to get to a human. They’re going to bank on the fact that, “We practically called you. You don’t want to go through that misery of calling this vendor. It’s going to take you 30 minutes to verify this.” But you know what? You still have to do it. That’s the reality.

Manoj Tandon: At least these guys implemented, “If this is the number you want us to call you back on when you’re up in the queue, just hit one and hang up.”

Craig Taylor: Beautiful. That’s the best.

Manoj Tandon: Then the guy can call me an hour later. I don’t care. I’m not going to sit on the phone for an hour. But you’re so correct. I had not thought of that. Especially these home warranty companies, man, they make it impossible to get hold of a human person. If you want to scam somebody, the best time to do it is when their water heater, microwave, or something else blew up. Then you can get them to give up the goods. You can get them to give up their bank account information or whatever and say, “Yeah, we’re going to reimburse you. We don’t have a vendor in your area, so go buy yourself a new microwave.” Meanwhile, I’ll take that money out of your bank account. Thank you very much.

Craig Taylor: Right. It’s all financially motivated. That’s the bottom line. Anytime there’s money involved, you have to be extra vigilant because the internet has basically put every huckster, hacker, and miscreant on our doorstep looking to make a buck off of you. You have to be extra careful. If we can turn this back into the psychology we started on, another analogy to think about when you’re applying behavior change to your organization, if you’re responsible for training employees and want to change behaviors, remember the dog-training analogy. You can try to train a dog with a shock collar or with food treats. Which do you think the dog would prefer? Which, as the owner or trainer, do you prefer using? Which has the longer outcome of behavior change that ultimately leads to successful training of that dog? It’s not the shock collar. I promise you. In every case, the best you can do is maybe modify the dog’s behavior for a short period of time. It’ll stop barking when you zap it, but it’ll start barking again in a few minutes. When you treat it, when you give it treats, it’ll bring you the leash to go to the dog park because it’s having so much fun. The engagement goes way up. The dog is happy, you’re happy, and the training sticks. When that dog goes outside and you call it to come in at night after doing its business, it’s going to come and sit down and wait for its treat. It’s going to say, “Yeah, yeah, yeah, where’s my treat?” It’ll come wicked fast. If you do an intermittent treat schedule where you don’t give it a treat every single time, it’s going to speed up how fast it comes to you because intermittent rewards are better than consistent one-for-one rewards. The dog might go out sometime after eating a huge meal. Maybe you had people over for dinner and gave it scraps from the roast beef. It’s not even hungry. It may not be interested in a treat at that moment and might come slowly. But intermittently, that’s the most powerful reward you can do. It’s like a slot machine. That will change employee behaviors and it won’t leave a bad taste in their mouth.

Manoj Tandon: That’s the biggest thing, and you’re making it interactive. They’re engaging in their own change process, if you will. You see a lot of people just give up. You want to teach them something new, but then they’re just like, “Yeah, I checked the box, I watched the video,” and then they go on with their day.

Craig Taylor: Exactly. It’s a checkbox exercise. That’s why there’s so much more psychology to what we do at CyberHoot, and what the best vendors on the market are doing, than just positive reinforcement. That is just one part of it. The other part is gamification. Many vendors are now gamifying things. We have anonymous leaderboards in CyberHoot. One of the most interesting side effects is that senior leaders of companies started doing their training when they saw they were at the bottom of the company’s anonymous leaderboard in terms of ranking because they didn’t do their assignments at all. They were afraid of somebody finding out they were dead last, or HR looking at them and saying, “Not only are you dead last, but remember that link you clicked last month that almost led to financial fraud, and you’re not doing your training? You’re dead last. This is bad. You’ve got to do it.” Before that happens, they get in there and get busy and do their training because you don’t get into a position of authority by failing at everything. Typically, you’re a highly competitive person. You want to succeed and do well, so you get your stuff done. This just made it happen. It’s another psychology hack to getting compliance. All of these things are baked in together to reward the good behaviors that we want to see more of. Truthfully, it’s working. We have that first initial study proving it. The University of Colorado and Tennessee combined to do a study, and they compared Hootphish, this interactive version of phishing simulation that’s not deception-based, against a video on phishing and how to spot phishing. The initial outcome showed higher curiosity and more interactivity, obviously, with the Hootphish exercise than with the phishing video. The performance on spotting a phish immediately in the aftermath was about the same. So what does that tell you? One was at a higher level of depth of understanding because it was interactive and building a rubric, versus passively consuming a video and then immediately measuring recall. Then we measured how curious people were about the exercise, how long they spent, whether they were willing to retry different things. The curiosity factor is way higher for Hootphish than for the passive video. So that begs the question in our next study: can we measure how long that equal performance lasts? Does it taper off for the video where people remember it in the moment, but then it wanes over time because it was passively consumed versus interactively consumed? That’s a level up on Bloom’s taxonomy. One would think the behavior change should be longer-lasting in Hootphish. If we can practice it multiple months in a row, does it then become a habit versus something you have to consciously think about? When do I apply this in my inbox? Is it a manual process where I have to think hard to apply this rule, versus a habit, muscle memory, or reaction? I’m reacting to an email by using my Hootphish knowledge. There are so many more studies to do, and I think there’s going to be a paper published that might get us all the way to France for a NATO summit to present the initial findings.

Manoj Tandon: Please tell us about that. What are you guys doing with NATO?

Craig Taylor: It’s not me. It’s the security researchers at those two universities. They’re tied into that. They believe they have enough material from this initial study to write a paper that might be presentable at a NATO summit that France is hosting next spring. During the time leading up to that, we’ll be starting another study that looks to prove even more around curiosity, depth of understanding, and the duration of the behavior not extinguishing over time. That’s where we think the interactivity will help with remembering these skills into the future. That’s the big thing we would like to prove because there’s so much evidence right now that passive video consumption and fake-email deception-based phishing just don’t yield the results we want in behavior change. There’s no better evidence than what happens every day in the news media with this breach and that breach. Something has to get better.

Manoj Tandon: It’s fascinating that these studies are happening because behavior change, Craig, has been the crux of why these guys keep having successful ransomware attacks, phishing attacks, and BEC. At the heart of it, I have to say it again, cybersecurity is foundationally a human behavior problem. The technology is there to support the human behavior. Even when you do everything perfectly, will you be 100% secure? Absolutely not. That’s not going to be the case. But making these kinds of insightful changes in human behavior that are permanent and lasting would have a dramatic impact. I’ve never seen a study, so I’m going to make up some numbers here, take it with a grain of salt. For example, you could buy a new firewall and that might make your organization 3% more secure. But if you can change employee behavior, that might make your organization 40% more secure. I think it would be a much bigger number. Anecdotally, from years of experience in this, that’s what it looks like. Behavior change would yield a far larger return than implementing some kind of technology.

Craig Taylor: I agree. Anecdotally, we know that to be true, Manoj. You’re absolutely right. There’s another human behavior improvement that comes when you leverage non-deception-based phishing simulations and phishing training, and that is a culture in your business that is not afraid of reporting mistakes. When you do deception-based phishing, people become afraid of making mistakes. Some companies, in the most extreme cases, are three strikes, three failed phishing tests, and you’re fired.

Manoj Tandon: That’s going to be a terrible cybersecurity program.

Craig Taylor: It is, but it’s the norm at some bigger Fortune 500 companies, some that I’ve even worked at. They justify it by saying the cost to our goodwill, our brand, and the cost of a breach justify terminating anybody who doesn’t treat this with the utmost seriousness. But in reality, in those organizations, people are afraid to report a mistake because of the consequences and punishment that get meted out. When you have a non-deception-based educational program where people are rewarded for good behaviors and not punished for bad ones, they are more likely to report a mistake more quickly. That allows intervention more expeditiously to prevent damage from an errant click. When someone makes a mistake, they immediately think about their training, call IT, and say, “Hey, you know what? This happened.” Recently, a CPA firm got an inquiry on their website: “Hey, I didn’t file my taxes. I was sick. Can you help me file them late? Can I meet with you to go over my situation?” Of course any CPA firm is going to say, “Absolutely, that’s what we do. Here’s a Zoom meeting link.” “Okay, I’ll be there Friday at noon.” Friday rolls around, it’s noon, the person doesn’t show up. Five minutes later, you send an email: “Hey, we were hoping to help you out today. You’re not on the Zoom meeting.” Five minutes after that, they respond, “I can’t get Zoom to launch on my computer. I have a Teams account. Would you join my Teams instead, please?” Then they send a link. It says teams.microsoft.com and then a bunch of obscured content after it. It was an attack. When they clicked to join the Teams meeting, it downloaded an RMM tool, which then downloaded a ScreenConnect tool, a tool to hide mouse movement on the screen, and a bunch of other things that started to breach the company. But because they were on a positive reinforcement tool like CyberHoot, they thought about this failed connection. No one got on Zoom, no one got on Teams, and then they looked at the link and saw that something was wrong. They had been convinced to click a Teams link as a Zoom replacement at the eleventh hour of a meeting with someone they thought needed help, but nothing in the scenario was working right. Something felt wrong. They checked the machine, saw downloaded files and installations happening, and put a stop to it. We did a deep inspection of the machine and some forensics. We discovered we caught it in the nick of time to prevent what was probably going to lead to a ransomware breach. They had been cased for three weeks while this person negotiated the time of the meeting, got everyone scheduled, and then set the bait: “I can’t get into Zoom. Zoom is trying to update. Could you join my Teams meeting?” They had trust and authority. “I’m a customer and I’m trying to get you to help me.” Everyone wants to help, so they clicked without doing the proper due diligence. But the positive culture is what saved the day there. They reported it immediately. They could have shut their computer down or gone to lunch and said, “You know what? I guess we missed that one. We’re not going to land that client,” and gone about their day. But they were smart enough to say, “Something didn’t add up here. We better check my machine because I did click on something maybe I shouldn’t have.” It saved the day. These things happen, and you need a culture that isn’t afraid to make mistakes and can report those things immediately. If you see something, say something, and avoid what could have been a major disaster.

Manoj Tandon: That would have been a disaster. Think about it. They could have had to inform every single client by mail if records were stolen.

Craig Taylor: Depending on whether the data was stolen, yes, exactly.

Manoj Tandon: Paid for their credit monitoring.

Craig Taylor: Credit monitoring and everything else. There are all sorts of hidden benefits to doing a positive-rewards, gamified behavior-change program and teaching people how to phish instead of feeding them a fake deception email today.

Manoj Tandon: Craig, is Hootphish a platform that a small business can afford, or are you mostly geared toward enterprise?

Craig Taylor: Absolutely. No, we cut our teeth in the SMB space and the MSP mid-market and smaller. But I’ll be honest, enterprises need our product just as much as the smaller fish. We serve all the different business types and sizes.

Manoj Tandon: Fantastic. We’re pretty much at the hour. We want to give you a couple of minutes to plug whatever you’d like to plug and let our audience know about it.

Craig Taylor: The best news I can share with your audience is that you don’t have to believe me. You can see it for yourselves for free as individuals. You can register for a CyberHoot account at cyberhoot.com/individuals. We give it away free for life. You can have that training for yourself and your loved ones and put them in as individuals. If you like it and believe in the positive reinforcement approach, the culture it creates, and the behavior change it leads to, then sign your business up. Send an email to sales@cyberhoot.com. We can get you in there, or we’ll reach out to your IT provider to sign them up and go from there. Ultimately, we want to help reduce the scourge of ransomware, business email compromise, financial fraud, and wire fraud through education. The cybersecurity skills we’re teaching, thank the Lord, are not rocket science. They’re common sense with a tiny bit of knowledge built in that teaches you to go, “Huh, I better PAR this. I better pause, assess, respond, or report carefully on this thing.” There are just so many attacks going on, and AI is making them more believable, more frequent, and more damaging.

Manoj Tandon: Well, ladies and gentlemen, that’s Mr. Craig Taylor. Please reach out to him and reach out to Hootphish. Good group of people. Craig, it was an honor having you here. When you get some word on the studies and whatnot, please share the knowledge. We’re more than eager to understand.

Craig Taylor: I would be happy to. Thank you, Manoj. You’ll be on the top of my call list, to make sure it’s really you and it’s not some other person.

Manoj Tandon: Thank you, Craig. This has been phenomenal. Take care, and I look forward to the next time.

Craig Taylor: Thank you, Manoj.

Read more about Craig on his LinkedIn

Learn more about CyberHoot

Access FREE Training with Cyberhoot

Check out the vCISO bot we created

Check out the other episodes in Season 20:

Ep. 0 Dale Meredith Jr – Everything the Internet Knows About You

Ep. 1 Chris Nyhuis – Compliance Won’t stop the Next CyberAttack

Ep. 2 Dr. Blake Curtis – Are We Measuring Cyber Talent Wrong?

Ep. 3 Craig Taylor – Are Phishing Tests Actually Helping?

Craig M. Taylor is a seasoned cybersecurity expert and entrepreneur with nearly 30 years of
experience managing risk across industries—from Fortune 500 corporations to SMBs. As the
Co-Founder and CISO of CyberHoot, he has pioneered a positive reinforcement approach to
cybersecurity education, helping businesses eliminate risky behaviors and build a culture of
security awareness.


Craig’s journey began with a Bachelor of Arts in Psychology (Honors) from the University of
Guelph in 1994, blending an understanding of human behavior with the technical rigor of
cybersecurity. Over his career, he has led enterprise security programs at Chase Paymentech,
Vistaprint, and DXC Technology (formerly CSC), where he developed cutting-edge risk
management frameworks, compliance programs, and cybersecurity roadmaps. His expertise
spans incident response, governance, and security program development, making him a
sought-after leader in the cybersecurity space.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top