This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes James Azar. James is a CISO (Chief Information Security Officer) who works, leads, and is dedicated to the security and business mission to ensure the continuity and fluidity of cybersecurity within the business. In his experience, James has served as CTO, CIO, and CISO’s. But his passion is the intersection of Security and Business where innovation and out-of-the-box thinking are needed to succeed. James is the host of the cybersecurity podcast The CyberHub and CISO Talk, and a new and noteworthy privacy podcast called Goodbye Privacy. He is a public speaker and event host that hosts the annual CyberHub Summit in Atlanta. He has spoken in events across the globe from CyberTech Israel, RSA, and Data Connectors. James has also been published in Fox, OAN, AJC, ABC, and many more publications. On top of all that, James has served on the Board of Advisors for the NTSC and currently serves as Vice President of Programming for AFCEA Atlanta Chapter, IAC (Israeli American Council) Eitanim Mentor, and works with the Veteran community as well as supports several Non-Profits.
Chapter Titles:
00:18 Introduction to James Azar
02:26 Whiskey and Bourbons
03:50 What changed with Covid
06:09 Percentages of Home Computers with Anit-Virus Software
07:48 Minus the people what are the new challenges with Covid?
09:39 Has Covid accelerated its cloud strategy?
12:15 What is the cybersecurity risk in moving to the cloud?
15:22 The cybersecurity risk in small and medium businesses
19:23 How a small innovative cybersecurity company can do business with a big company
24:08 Do companies understand cybersecurity is a business problem and not an IT problem?
25:35 How Smart CISOs monetize cybersecurity
28:09 How to measure cybersecurity awareness
31:03 Should the CISO be an independent function?
35:28 The Chinese cybersecurity threat
40:15 The dangerous precedence of the Equifax settlement
45:09 Managed detection and response
47:35 Vendors vs partners in cybersecurity
48:40 Jame’s CISO Talk Podcast
Audio:
Important Links:
Transcript
Kevin Casey: Good afternoon and welcome to another podcast of Security Confidential. Today we are honored to have James Azar, who is a successful entrepreneur. He’s also a nationally recognized speaker and thought leader in the fields of cybersecurity, blockchain, Internet of Things, and fintech. James is the co-founder and host of CyberHub USA, which operates CyberHub Summit and CyberHub Academy, where Azar serves as Chief Marketing Officer. He also serves as the president of BHNV Ventures, which oversees a private fund that invests in early-stage innovative companies in cybersecurity, blockchain, and fintech. James, welcome to Dark Rhino Security Confidential.
James Azar: Thank you. That’s a very old bio, Kevin. That’s a very old bio. I’m old. I am. I’m so old.
Kevin Casey: Hey, you know what? This is the beauty of editing. If you’ve got a newer one, what would we do with that? That’s why I’m never allowed on these things. That’s why the CEO is never allowed. I’m like, “Wow, that’s like a 2017 bio.” It’s all good. It’s probably the last time I did something. So James, I really am relegated as the CEO to very seldom participate in these things. One, Manoj tells me that there’s not enough light that they can put on my face to get rid of all the imperfections that are in there. And I say, “Manoj, it’s nothing more than experience that shows in this face.” You really can’t hide all that.
James Azar: [Laughter]
Kevin Casey: The second thing is, James, I loved your bio on LinkedIn, where you enjoy several coffees a day as well as a very good bourbon. So in your honor, I decided to have a 15-year-old bourbon in your favor. So James, welcome to our show.
James Azar: Thank you for having me.
Manoj Tandon: Well, let’s just get the most important question out of the way then, James. What’s your favorite bourbon? What do you like to drink, or scotch, or Japanese whiskey, or juice?
James Azar: I can’t pronounce my favorite Japanese whiskey, and I can’t insult the great people of Japan by trying to say it. I have never gotten it right. I will tell you, I’m a Macallan guy. I’m a Macallan 15, Macallan 18. That’s been recent; that wasn’t the case before. So it changes. I think I had a Four Roses little issue, like a little thing. As any scotch lover, you’ve got your go-to stuff, but then your drink of choice is seasonal.
Kevin Casey: It’s true. Or mood. It depends on your mood.
James Azar: Sometimes you want something rough that burns coming down, and in cyber, we have a lot of those days where you want something that burns when it comes down.
Kevin Casey: And then you have another one just to kill the pain from the first one.
James Azar: And then you need another one to kill the pain from the first two, and then another one to make all the pain go away so you can actually go to sleep.
Kevin Casey: So to our audience, if you haven’t decided, we’re talking about bourbon right now.
James Azar: Things really changed. From a security perspective, we used to think our address, our building, our floor, our departments, and our divisions were our networks and those were our endpoints. COVID upended that. COVID really did change that. One of the very interesting aspects to me was in the immediate aftermath of COVID. If we look back a year ago, this time we were all at RSA. It was unbelievable. We were all sanitizing our hands, but we were still hugging and seeing each other and hanging out and eating together. People were a bit worried, but not so much. I remember at the time, one of the people I flew with was wearing a mask the entire flight and I was like, “What are you doing, weirdo? Take that off. This isn’t a big deal, man. Why are you wearing a mask?” But he did. I think that’s one of the things that really changed: the endpoint discussion and then the BYOD conversation. We think of BYOD, we think of someone bringing their own phone to use work email or a CRM tool like Salesforce or HubSpot within the environment. Well, now we’ve introduced two new things in our environments that we have no control over. One, most people that had to stay home rarely got a chance to take home work equipment. I know a lot of companies… we were always virtual, meaning we have a workforce that’s spread across the entire world. So everyone always had work devices. We had a process for mailing people work devices and getting them secure and sending them instructions on how to set up their home networks. We had a help desk role to help people in specific roles really divvy up their home networks so that we have a little bit more defense in depth in that kind of area—a little bit better cyber hygiene. But think of all the people that went home and had to use their home computer that didn’t have antivirus, that didn’t have a VPN. They had to log in and do work.
Kevin Casey: As a percentage, do you think that’s significant? The VPN part I would agree with. Antivirus, I would hope most people had.
James Azar: You’d be surprised how many homes and how many computers don’t have antivirus. Heck, man, your ISP gives it away for free.
Kevin Casey: Some ISPs do; others don’t. Most people don’t know about it because the ISP doesn’t advertise it.
James Azar: There were some statistics that were put out—I think it was Sophos or someone that brought it out—that said on the BYOD devices that were home in the initial stages of the pandemic, 70% of them didn’t have any EDR or AV on them. These were personal devices, not company devices. See, we think like cyber people. So we go, “All of my devices have EDR and VPNs and they use all these different things,” but that’s not the case for your marketing person in a company or your HR. Their home devices? They don’t use that stuff.
Kevin Casey: I would agree with that. Yeah, they don’t use VPNs definitely. If I were to re-ask that same question: how has COVID changed, from your perspective as the global CIO or CISO of a large organization? Take the end user out of it, which is a huge component. But when you think about some of the challenges that you face on your level and that your other regional CISOs and directors of infrastructure and directors of security face, what are some of those challenges that exist now that didn’t exist prior to COVID?
James Azar: When you look at a hybrid infrastructure and architecture, the challenge of having someone go into an office building wasn’t a challenge until COVID happened. A lot of landlords in a lot of office buildings shut down the building and wouldn’t let anyone come in or out. If you’ve got to go in and do maintenance on one of your servers, you’re screwed. It took a lot of phone calls and a lot of conversation and setting a process for someone to walk in to hit a reset, which then brought up the conversation from the executive leadership of, “Well, how do we make sure that if this goes on for longer than 15 days or a month or two, that we don’t have to go through this every time?” That brought up the cloud migration and cloud conversation, because now you’re looking at on-prem solutions and you’re going, “How do I take this on-prem to the cloud?” I love some of the conversations where people go, “Well, it’s pretty easy. Just send your servers to a data center somewhere and you’re done.” And you’re like, “No, that’s not how that works.” This isn’t pizza; you can’t just order it in.
Kevin Casey: That actually brings up a good question. In your case, and again if you can share without naming names, has COVID increased your adoption of a cloud-based strategy versus what you had historically?
James Azar: We were about 20% on-prem and 80% cloud. But we had to switch. We had to take the other 20% to the cloud. I think a lot of people know that you’ll leave some stuff on-prem because it’s strategic. It’s either your Achilles’ heel, or it’s stuff where you want to have a little bit more oversight or more physical control. We had to change that and we had to change our thought process around it. It required a lot of thinking and looking at it from a perspective of: how do we move this stuff to the cloud in an environment where we feel comfortable from not just security, but also operational integrity? That this is still going to operate the same way we’ve built it on-prem. Those conversations in our organization involve all the stakeholders at every single one of those conversations: engineering, architecture, and security. It’s a very thorough process of doing something like this where you can’t just say, “All right, move that to the cloud, let’s go.” It’s: how do we move it to the cloud? What are the stages? What needs to go? What isn’t going to be there because we’re transitioning to the cloud from a DevOps perspective and an AppSec perspective? There are things that you’re using in the cloud and cloud services that don’t exist in on-prem solutions. Then you’ve got to pick the cloud provider you want to work with, and you’ve got to understand their vulnerabilities. Most people have a hard time wrapping their heads around from an organizational perspective, if we look at this from a pure business standpoint, how do you enhance security in the cloud which is, in a lot of cases, an issue of maturity and knowledge. With cloud being so new, it’s a problem.
Kevin Casey: Well, that was actually going to be my last follow-on question: how much, when you were getting together as executive teams, did risk come up? The likelihood of risk if you move versus its magnitude if you didn’t.
James Azar: There wasn’t an issue of risk. We view risk as being a part of doing business. We have a risk appetite, but for us strategically, it’s business continuity. We know that if we can’t get to our servers ever again because of whatever reason—this time it was COVID, tomorrow it could be a snowstorm, the next day it could be tornadoes, hurricanes, terrorist attacks, or a military coup. Or you could just get booted off of Amazon.
Kevin Casey: That too.
James Azar: I’m not saying that that would happen, but in the realm of a risk register, I mean… I’ll tell you that COVID changed a lot of our thinking with cloud providers, and then the aftermath of January 6th did as well.
Kevin Casey: Yeah. I would hope so.
James Azar: From our end, Kevin, to look at it from a risk perspective, we looked at it from a business operation. Then we said, “What’s the risk?” We know business has to run a specific way. Now, in order to do business this way, this is what we’re going to have to do. Now, is that risk any different than the existing risk that’s in place with the way we operate today? There’s no zero risk. I know people talk Zero Trust, but there’s no such thing as zero risk. I want to write a book that says “Zero Risk,” and then the whole book would be blank pages. There’s no such thing as zero risk.
Kevin Casey: There’s no such thing as Zero Trust either, although the Zero Trust crowd category is doing awesome. Their stocks are doing amazingly well in this environment.
James Azar: We looked at it from an operational perspective. If the risk outweighed business operations to a point where it was significant for a long period of time, where the risk became unacceptable, we had to find other ways to get more creative in how we were going to make that transition. There was no option for us to simply not do it. I think the option was: how do we do it in a way where business continuity is maintained and revenue is still streamlined? How do we not increase our overhead cost by doing this? This investment has got to be able to repay itself. Then how do we integrate all the different aspects of the business, and primarily security, into this so that we as a business can continue to operate? Because unfortunately, customers who pay you for something aren’t going to sit around and be like, “Hey, sure, take three months. It’s okay.” That’s just not reality.
Kevin Casey: One of the things at Dark Rhino, a lot of our customers are in small-to-medium businesses—the sub-2,000 employee market space. James, what we encounter quite a bit in that segment is that companies struggle with the definition of risk. They just struggle with understanding it. As a prime example, when you ask folks, “What do you need to guard the most? What do you want to protect the most?” a lot of times they don’t have a very concise answer. Do you have any suggestions for those folks? Is there a framework, methodology, or approach that you would suggest they adopt that would further their maturity in that arena?
James Azar: I think risk is a very interesting concept for small businesses and mid-sized companies because when you operate in an environment like today where everything is SaaS, a lot of these businesses operate on a multi-SaaS model. That’s why Okta is Okta. Okta wouldn’t be around if it wasn’t for all the SaaS products that different departments within a business use. You don’t want to have someone have 17 different logins and passwords; that’s just unhygienic. Thus comes Okta. When you talk about risk, it’s hard for those companies to identify that as a risk because, as far as they’re concerned, “We’re diversified.” Put yourself in the head of a small business owner. I have a lot of friends that own small businesses that are marketing firms, accountants, or lawyers. Whenever they talk to me about security, they go, “Who’s going to want to hack me? I’m on Office 365 and I use QuickBooks and Word and the courthouse system.”
Kevin Casey: James, you get that same opinion even if the company has 500 or 600 employees.
James Azar: Some of my friends do have those kinds of businesses and I look at them and say, “I get it, I understand that. But I think the one thing you have to pay attention to is it’s not really you they want; it’s your customers that they want.” So if you value and you want to keep your customers going, what’s the risk if you were shut down for four days to your customers and to your business? I hate to use FUD—fear, uncertainty, and doubt—but I go: “What’s your hour worth? $1,000? Okay, wonderful.” So you charge $1,000 an hour; you’re a really high-priced, very good lawyer. You work how many hours a day? Let’s say 10 hours a day. You make 10 grand a day. That’s a lot of money. You have paralegals; you charge for them $150–200 an hour. What does your business stand to make every day? Now, if your business shut down for a full day because of a cyber incident, how far back does that set you? Now, if you made this investment in security, that would just be basic blocking and tackling. We’ll take the CIS Top 20. Let’s look at the top seven or eight of them and let’s just put those controls in place.
Kevin Casey: Well, you know what, James? You may be the exception, but when it says “Kevin at McKinsey.com,” people return my phone call. When it says “Kevin” or “Manoj at Dark Rhino Security,” they go, “Who?” So I guess my question to a person at your level—at a global CIO level—we have found that it’s very hard not only to get to you, but when you get to an individual like yourself, it’s difficult to get you to think outside of your own paradigm. So my question to you is: how do CIOs and CISOs in your role in a global organization look for companies that are innovative, creative, or doing things that are outside the box that actually can make a difference during these difficult times we’re facing right now?
James Azar: Are you talking from a technology perspective or a knowledge perspective?
Kevin Casey: Knowledge. Let’s start with knowledge.
James Azar: Knowledge is a little bit more challenging. We from a global perspective have a list of authorized vendors that can come in from a consulting perspective. Like you said, if it were a McKinsey or a PwC or any of those big names, they’re on the list. When you talk about the smaller organizations, it’s a bit more of a challenge. The way we leverage some of that power, though, is if we find a small company that we like to do business with, we’ll go to the big name and say, “We don’t want to work with any of your people; we want to work with these people. So you go do what you’ve got to do with them and engage them to engage us.” Unfortunately, it’s the politics of working at big corporations. When I hire a company that’s unknown, the risk of a project failure and the risk to my reputation and the internal politics is greater. It’s unfortunate; I wish that wasn’t the case, but it’s the absolute truth. So you kind of have to go about it politically. Lawyers do this all the time. Let’s say they’re not in the bar in a specific state, but they’re really smart and they understand the law. Someone says, “I want to hire you to represent me in this case.” He goes, “Well, I can’t argue in front of the judge, but go engage a lawyer in your state that’s in the bar. Have him engage me, and then I can consult on the case.”
Kevin Casey: Which is, by the way, very common. The issue with that is, and you and I know this from being in the industry for so long, the risk is always shifted downhill. Nobody wants to take the risk. Nobody wants to say, “Hey, I found this boutique company and I think they’re fantastic and I want to engage them.” If it fails, you’re the guy that brought them in. If you bring in McKinsey, PwC, Deloitte, or KPMG and it fails, then everyone just shrugs and says, “Well, it was Deloitte.”
James Azar: Exactly. That’s exactly right. It’s a lot easier to blame a brand than it is to blame yourself for bringing in someone unknown. That’s why for a lot of boutique firms, relationships become absolutely critical. Your network matters. Your reputation matters. Your references matter. When a large enterprise hires a smaller consulting firm or boutique organization, it’s almost always relationship-driven. Someone internally has to trust you enough to put their own name and reputation on the line. That’s why relationships are everything in this business.
Kevin Casey: Which, honestly, is probably how Dark Rhino grew. We were fortunate that people trusted Manoj and trusted the team we had assembled. The reality is, in cyber, reputation is everything. You only get one shot at your reputation.
James Azar: Especially in security. Because if you think about what you’re doing in security, you’re asking someone to trust you with their most critical assets. You’re saying, “Let me into your environment. Let me see your weaknesses. Let me understand where your gaps are.” That’s a very intimate relationship from a business perspective. You’re not selling office supplies. You’re literally dealing with the nervous system of a business. So reputation matters a lot.
Kevin Casey: It really does. So let me ask you another question then. One of the things we’ve seen because of COVID is a tremendous acceleration of digital transformation. Companies that thought they had five years to modernize suddenly had five months. Do you think that’s been good overall for cybersecurity, or do you think it’s introduced more chaos than opportunity?
James Azar: Both. I think it’s accelerated innovation, which is great. I think companies became far more agile. A lot of organizations discovered they could move faster than they thought they could. Bureaucracy disappeared overnight because it had to. But with that speed came technical debt and security debt. A lot of organizations implemented things quickly without fully understanding the implications. They said, “We need Zoom. We need Teams. We need VPN capacity. We need cloud collaboration. We need remote access.” Great. But in the rush to enable business continuity, security sometimes became secondary. Now, over a year later, organizations are going back and trying to clean that up. They’re saying, “Okay, we deployed this in two weeks. Now let’s harden it properly.” So I think it accelerated both innovation and risk at the exact same time.
Kevin Casey: Which is honestly very consistent with technology history in general. Every major technological leap introduces risk that we later figure out how to manage.
James Azar: Exactly. Security historically follows innovation. Innovation happens first because business demands it. Security comes in afterward and says, “Okay, now let’s make this safe.” That’s the cycle we’ve always been in. The challenge now is the cycle is happening faster. We don’t have five years between innovation waves anymore. We have five months, six months, a year at most before the next shift comes along.
Kevin Casey: So with all that happening, and with organizations moving so quickly, where do you think the biggest gap exists right now from a cybersecurity standpoint?
James Azar: People. Still people. It always comes back to people. Technology is great. AI is great. Automation is fantastic. But at the end of the day, security is still fundamentally a human problem. It’s humans building systems, humans configuring systems, humans using systems, and unfortunately humans making mistakes. Attackers understand human psychology extremely well. Phishing works because humans are emotional. Social engineering works because humans are trusting. Ransomware works because humans panic. So if organizations don’t invest in educating their people and building a security culture, all the technology in the world isn’t going to save them.
Kevin Casey: I couldn’t agree more. We say all the time at Dark Rhino that people are either your biggest vulnerability or your greatest asset depending on how you engage them.
James Azar: Exactly. And I think companies still approach awareness training the wrong way. They make it a compliance checkbox instead of building an actual culture. Nobody learns security from watching a 30-minute boring video once a year while clicking “next” 47 times. That’s not culture. Culture is leadership talking about security. It’s making employees feel like they’re part of the defense. It’s rewarding good behavior. It’s making it okay to report mistakes quickly instead of punishing people for them.
Kevin Casey: Which, by the way, is one of the hardest things to build inside an organization: psychological safety around mistakes.
James Azar: Absolutely. Because if employees are afraid of getting fired every time they click a phishing link, they’ll never report it. They’ll hide it. And the longer they hide it, the worse the incident becomes. So organizations have to create an environment where people feel comfortable raising their hand and saying, “Hey, I think I messed up.” That’s maturity.
Kevin Casey: So James, before we wrap up, if you had one piece of advice for organizations heading into the next few years, what would it be?
James Azar: Simplify. I think organizations have overcomplicated security. They buy too many tools. They create too many dashboards. They have too many alerts. Security teams are drowning in noise. Simplify your architecture. Simplify your processes. Focus on fundamentals. Patch your systems. Use MFA everywhere. Train your people. Segment your networks. Have good backups. Test your incident response plans. The basics still stop the majority of attacks. We keep chasing shiny objects while ignoring the blocking and tackling.
Kevin Casey: That is probably one of the best summaries I’ve heard in a long time. Sometimes the fundamentals really do matter more than the latest buzzword.
James Azar: They absolutely do. Most organizations don’t fail because they didn’t buy the latest AI platform. They fail because someone reused a password, MFA wasn’t enabled, or a server wasn’t patched for six months. That’s the reality.
Kevin Casey: Well James, this has been an absolute pleasure. I appreciate your time, your insight, and honestly just the conversation. It’s refreshing to have real discussions about cyber instead of just buzzwords and marketing.
James Azar: Thank you for having me. I appreciate it. These conversations are important because people need practical discussions about security, not just hype.
Kevin Casey: Well said. James, thank you again for joining us on Security Confidential. To all our listeners, thank you for joining us, and we look forward to seeing you on the next episode.
To learn more about James Azar visit his LinkedIn
Check out the other episodes in Season 3:
Ep. 0 Tyler Smith – Cyber Basics: Training the End-User
Ep. 1 Manoj Tandon – Was it worth it? Lessons Learned
Ep. 2 Chenoa Moss – Healthcare IT: Innovation at the Speed of Life
Ep. 3 Karla Reffold – Do Women make more Money in Cyber?
Ep. 4 Nick York – How the OITA is helping Tech in Ohio
Ep. 5 Dr. Calvin Nobles – How Human Factors Can Impact Cybersecurity
Ep. 6 Karl Sharman – How to Hire and Retain Cybersecurity Personnel
Ep. 7 James Azar – How Secure is Your Organization?
Ep. 8 Jordan Graham – Business Lessons from a Bowhunter
Ep. 9 Chris Auger – Why Microsoft 365 is difficult
Ep. 10 Jeff Manhardt – The Power of Why
About James Azar

James is a CISO (Chief Information Security Officer) who works, leads, and is dedicated to the security and business mission to ensure the continuity and fluidity of cybersecurity within the business. In his experience, James has served as CTO, CIO, and CISO’s. But his passion is the intersection of Security and Business where innovation and out-of-the-box thinking are needed to succeed.
James is the host of the cybersecurity podcast The CyberHub and CISO Talk, and a new and noteworthy privacy podcast called Goodbye Privacy. He is a public speaker and event host that hosts the annual CyberHub Summit in Atlanta.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
