Glitch: Welcome to NPC Grade Security and Architecture Episode 10. We are the Champions Security Awareness Programs. I'm your host, Glitch. Cypher: And I'm Cypher and today today we're gonna commit what might be considered a career killer in some security circles. Glitch: ⁓ ooh, you got me excited because I am always willing and eager to commit career killers on a daily basis. So we're gonna do something exciting, right? Like create the next advanced agentic AI to hack all the crypto wallets in the world? Cypher: ⁓ close, but no. I was I was thinking more like questioning one of sub cybersecurity's longest running sacred cows. Glitch: Shoot. ⁓ finally. So we're finally gonna get rid of Bob's twenty eighteen iPad? Yeah? Or is it gonna be Daryl's iPhone seven? W one of ⁓ please. Cypher: still no, but your optimism is cute. Yeah. No. I am I'm talking about security awareness training. Glitch: ⁓ dog it. Okay. Well ⁓ wait a minute. Whether we should do it or not? Cypher: No, not whether we should do it, not whether phishing exists and you know, not whether users need education. Those are obvious. I think it's more the question of whether we've fundamentally misunderstood what we're trying to accomplish because somewhere along the way we stopped trying to educate people and we started grading them. Glitch: Okay, so we need to talk about the human risk. Cypher: ⁓ actually can we can we retire the phrase human risk? Glitch: Hm. all right, you know what? That is a good point. Because it is kind of absurd, right? I if I walked into HR and said, We've identified a management risk or or finance and said, There's an accounting risk, or even engineering, and said developer risk continues to increase, I would absolutely get laughed out of the building because those are amazingly ambiguous blanket statements. ⁓ would now be the appropriate moment for me to be snarky and say we should just get rid of the humans. Cypher: You're on a roll today. Glitch: Yes, I am. I am fired up. Cypher: Yeah. Okay. So maybe not time to get rid of humans, but but with what you just said, somehow we have become perfectly comfortable describing those people who actually keep the business alive as the risk, you know, and not the behavior, not the exploitable processes, not even poorly designed systems, but the humans. Glitch: Hm. Y you know, that is a fascinating worldview. So what you're saying is you can lead a horse to water and you can't likely make them drink, so we need to change their reasoning for wanting to drink. Cypher: Well, I mean okay, so it's partly because I don't like the phrase human risk, because I think that's incredibly disrespectful because people aren't vulnerabilities. Glitch: Ha ha ha. So you're saying HR says no patching deployed across your enterprise staff? All right. Cypher: Legit. yeah, that because people are people are operating inside of systems that we've built. And if someone keeps making the same mistake, our first question shouldn't be, what is wrong with that goob? Glitch: You're right. It should be what we have. What have we failed to teach? Yeah. A little tongue-tied. Cypher: Yeah. Easy easy for you to say, but okay, but even better though, maybe we should say what have we designed that makes this mistake so easy? Because security people, we love talking about zero trust and defense in depth. Glitch: Until the last layer of defense is Karen and accounting, and then apparently it's all her fault. I'm sorry, I couldn't help it. But you're right, you're right though. Security awareness has a bit of an identity crisis going on, right? Let's be honest. Most awareness programs aren't really education. Cypher: Clutch. You're not wrong, you know, they're aimed around compliance and that's the difference. Education changes how somebody thinks. Compliance changes what someone clicks. Well ⁓ at least while somebody's watching. Glitch: And most annual trainings look the same, right? Year over year we got forty five minutes of PowerPoint that people power click through, a quiz and a c certificate of completion. ⁓ we'll just call that done. Cypher: Yeah, congratulations. Yeah. And that means that we have officially met the definition of meh, we tried. Glitch: ⁓ yeah, yep, yep. And that failure to make a material difference is apparently a tomorrow problem. And apparent and that's a tomorrow that never comes. ⁓ tomorrow never dies. Yeah, James Bond, double O seven, eleven. Yeah, that nope, you're all good. Cypher: Is that a movie? ⁓ Okay. My bad. My bad. But you know, because for starters, real education, like you just said, real education doesn't happen once a year. Imagine, imagine, if you will, teaching your teenager to drive exactly only on one afternoon, maybe for 45 minutes during your lunch break. And then six months later, you know, they already have the keys and you just point at them and say, hey. Good luck on that interstate. Glitch: ⁓ yeah, I see what's com I w see what's happening now. You got the no coaching, you got no practice, no continuous feedback and no reinforcement. ⁓ hopefully you won't act surprised when they hit something. Cypher: Yeah. And I mean it's a shame, right? Like but it's it's insane. That is somehow exactly what the world security awareness strategy has become. Glitch: Okay. All right. So I'm inclined to poke another sacred cow. Simulated fishing. Yeah. Cypher: Mm, well, I will say before all of those LinkedIn in la la LinkedIn influencers start typing Glitch: Wait, wait, wait. I thought you were a LinkedIn influencer. Cypher: I don't even know what the heck the qualifications are to equate to that. Yeah. But anyhow, so I am not saying simulated fishing has no value. It absolutely does, but only if we understand what it actually measures. Glitch: ⁓ okay. Alright, I think I'm picking up what you're laying down, sister. Most organizations treat phishing simulations like an exam. We teach indicators, hover over links, check the sender, look for spelling and grammar errors, but thanks to AI, those indicators are quickly disappearing. Hell, voices and faces are even cloned, so soon there won't be any tells that we can teach. Cypher: Mm-hmm. Mm-hmm. Mm-hmm. Mm-hmm. Right. And that's why I think it should be treated more like more like physical therapy. You know, the point isn't proving that somebody's weak, but the point is actually in building strength over time. Glitch: The problem is though that we have accidentally turned the rehabilitation into public humiliation, right? Congrats, you clicked. Here's your mandatory training. Everyone will know, your manager will be notified, badge of shame unlocked. You have officially been ostracized. Cypher: Mm-hmm. Glitch: Hoo wah you like that? Yeah. Cypher: Wow. So we have sound effects now. Look at us. Episode 10, like it's a milestone. Now we have sound effects. Yeah. So that was that was fantastic. But so but so now what have we done? We have successfully taught our employees one thing. Hide your mistakes. Glitch: We've we've grown up. Thank you. And if there's one thing we definitely don't want during an actual security incident, it's people hiding mistakes. Cypher: Right, right. But part of the problem is that security loves those few easy metrics that we can point at. You know, measuring things in security is tough. Like no lie. It is absolutely it is tough. So that's the story of half of cybersecurity over the last twenty years. We have become phenomenal at measuring what we're doing instead of whether we're actually changing anything. Glitch: Okay, so if I'm picking up what you're laying down, so you're saying we measure clicks because thinking is hard? Cypher: I'm I'm saying executives love dashboards. Vendors vendors love creating dashboards. Everybody freaking loves dashboards because numbers, right? And numbers feel objective. Glitch: Okay, that's about the same thing. ⁓ yeah, click rate, report rate, failure percentage, repeat offenders, beautiful graphs. I can totally see the appeal right now. Cypher: Mm. Yeah, but the problem isn't that I mean, again, we're talking about humans. The problem is that behavior is not linear. Glitch: ⁓ because humans aren't dashboardable? Cypher: Good new word. Dash. Yeah. I mean, so the the point is somebody who clicked today might actually be the person who stops a ransomware campaign tomorrow, you know, or somebody with a perfect fishing score may ignore a phone scam and pony up all their credits and and hey, here's my MFA just for fun to shiny hunters. Glitch: ⁓ thank you. Yeah. ⁓ yeah. Our favorite group. Shiny Hunters. You need to come up with a theme song for them. and and someone who reports fishing every week every week may just be overly paranoid. Cipher. ⁓ cypher. Sorry, I got I got a thing. It's it's there, the thing. Yeah. Cypher: Mm-hmm. I'm I'm not paranoid. Okay, okay. Well I'm not I'm not paranoid much. Maybe. Maybe. Meh okay. Well but the point is that metrics metrics can be useful, but they are absolutely terrible substitutes for actual understanding. Glitch: A wee bit. ⁓ Well, that's because we've become absolutely obsessed with measuring outcomes and trying to justify spends. Cypher: And and instead we should be understanding how decision making happens. Glitch: Cipher. That's like measuring hockey players exclusively by overtime shootout success percentage. Turns out there's apparently a lot more to hockey. Right on You're welcome, you're welcome. Cypher: Preach, preach. I love hockey. We brought hockey into a podcast. That's beautiful. But okay. But here's thank you. Yes. But here's the part that I think we've we've really gotten backwards. The objective isn't don't click links. Like don't click links, really. Like that's ridiculous. Glitch: O of course it is, because the business literally depends on our ability to use hyperlinks. Cypher: Right. And the objective can't be to never trust an email or an attachment, right? Glitch: ⁓ once again, also impossible because businesses literally run on email as a primary communication and information sharing mechanism. Cypher: Exactly. So the objective can't be that. So it has to be to pause, think, evaluate and decide. And that is a completely different set of skills than teaching avoidance. Glitch: For real, because you're teaching judgment at that point, right? It sounds like you're saying security awareness should have less in common with driver's ed and have more in common with philosophy. Cypher: Yeah, seriously though. I mean, think about what attackers exploit. They they they exploit urgency, authority, curiosity, fear, empathy, greed, like things that are not technical weaknesses, these are cognitive shortcuts. So instead of asking, How do I identify phishing, maybe we should be asking more like, you know, what decision is that email trying to rush me into? Glitch: Alright, so Cypher, so why in the hell's bells are we responding with videos about suspicious hyperlinks? It sounds like you're saying that attackers study psychology and we respond with clip art or or clippy from office. ⁓ yeah. Cypher: ⁓ my god, you see it's a shame that ⁓ that that twenty eighteen iPad isn't a Windows machine 'cause it would probably have Clippy on there. Glitch: He had the best sound effect of him like moving. I loved that sound effect. Cypher: Yeah. But I mean literally like responding with clip art, that is it, that is a good one, dude. Yeah. Yeah. But here's the uncomfortable truth. Behavior change, ⁓ it's funny how often this comes up in my old education as well. Behavior change is one of the most expensive things an organization can attempt. And I'm not talking financially, I'm talking psychologically, because changing a habit is brutally hard. Glitch: Thank you. Thank you. ⁓ you are absolutely not wrong. Ask anyone who's tried to quit smoking or lose weight or try to exercise consistently or even just to stop checking email every six minutes. Cypher: Yeah, exactly. People don't change because information exists. People change because repetition rewires their behavior. Glitch: Hundred percent. Yep, and and habits beat knowledge almost every single time. That's neuroscience, it's not cybersecurity. Cypher: Yeah, and that raises an uncomfortable question. If we know that behavior change takes repeated practice, why on this green planet do we expect a yearly awareness course or even those monthly gotcha fish to permanently reshape decision making? Glitch: Well nobody believes that's how fitness works either. Nobody believes that's how leadership works. Nobody believes that's how parenting works. Yet somehow, somewhere, some place, that's exactly how the world has structured security awareness. Cypher: Yeah, and here's where I think the conversation gets interesting. Glitch: I already thought this was interesting. I b I'm I'm interested. Cypher: ⁓ I mean, yeah, it is. But okay, so but organizations they love accountability, you know what I mean? Glitch: Mm. Na ⁓ yeah, yeah. You clicked, you failed. You should have known better. Maybe. Cypher: Yeah. But but here's the thing. Accountability without capability is just punishment. Glitch: For starters, that was poignant and absolutely beautiful. You're welcome. In response to that, well ⁓ yeah, if you've never invested in helping someone develop better instincts, what exactly are you holding them accountable for? Cypher: Thanks. Yeah, but us security types, we just love, love to say how our users are our last line of defense. And then we treat them like that instead of coaching and developing and practicing and investing in them at all. Glitch: Yeah. So what you're saying is you don't build elite firefighters by ea emailing them a PDF with a picture of a fire and a human holding a hose to it once a year and expecting perfection. Cypher: Well, mean, you just you just emailed him a PDF. Dude, I don't want him to even open that. Like that's Exactly. But you know, that that sounds like what I'm saying, yeah. Glitch: Alright, let's be fair then. This isn't this isn't the platform's or the vendors' fault, right? Most awareness platforms do exactly what customers ask them to do. Send training, launch phishing campaigns, generate reports, track completion, check compliance checkboxes. So the yeah, check so the platforms aren't broken. They're solving the problem we purchased them to solve. Cypher: Mm-hmm. Mm-hmm. Mm-hmm. Mm-hmm. Yeah. So so here's the fun part. Ready? So the real issue is us. It's us. I yes, the real issue is us. We have made Glitch: Yeah. I knew I was a problem. My mom always told me I was the problem. Cypher: that's a conversation for a different for a different day. But that is not the same thing now. So but yeah, but legitimately the real the real issue is us. We have made that age old mistake of confusing activity with progress. Glitch: ⁓ okay. So it's not the same thing. All right. Okay. Yeah. I if your awareness strategy is to buy a platform, send phishing emails, watch dashboards, rinse and repeat, you don't have a culture strategy. You have an automation strategy. Those are absolutely not the same thing. Cypher: No, they they are not. So imagine, sir, if you will, if awareness, if it looked different. Glitch: ⁓ or I gotcha here. So like the elephant man with wax lips wearing a pink tutu with orange stilettos. Yeah? ⁓ yeah. Cypher: You are so weird. In a good way, I think. I think. I think. But no. Yeah. But no. So no. Imagine though, if you will, all right. Imagine if fishing simulations weren't exams and they were actually discussions. Imagine if failure wasn't embarrassing because it was normalized and it was expected. So the Glitch: Yes I am. Why thank you. I I take I take that as a compliment. Okay. Cypher: then imagine if people reported mistakes immediately because they knew that security's first question is gonna be, okay, what can we learn? Instead of, okay, who clicked what? Like imagine those really, imagine if awareness became something employees actually wanted, not because it was mandatory, but because it made them safer. You know, it made them safer at work, at home, protecting their grandparents or parents or kids, or protecting their bank account or their retirement savings. Just everything because that's when awareness becomes personally valuable and organizational value just flows naturally. Glitch: Okay. I so I think the idea you're trying to leave our listeners with is that security awareness isn't about making our employees more suspicious. It's about making them more thoughtful. Cypher: Exactly. And that that is a profound difference. You know, suspicion suspicion creates fear and critical thinking creates confidence. Glitch: And fear doesn't scale, but confidence does. Cypher: Yep, yep. And people are not our weakest link. They're actually they're our only adaptive layer in our entire security architecture. Glitch: You know what, that is a good point because firewalls don't learn. EDR doesn't develop judgment and sims don't build intuition. People do. That completely flips a decades old narrative on its head. every other control we deploy behaves exactly it was ⁓ it was programmed yesterday. People can learn, they they can recognize new patterns, they can adapt to a brand new attack they've never seen before. That's not a weakness. Cypher: Mm. Mm-hmm. Mm. Glitch: That's the only part of the defense that can evolve in real time. Cypher: Yeah. And maybe, just maybe, the future of security awareness isn't teaching people how to spot a fish, but it's teaching them how to think. Because attap th think about it. Attackers adapt and evolve. Technology evolves. AI evolves. The only defense that has any chance of evolving at that same speed Glitch: Is a human mind that has learned how to question what it sees. Cypher: Exactly. So we need to stop treating people like liabilities and start to develop them like the assets that they are. And that's not just better security, that's better leadership. Glitch: You know, I wanted to kick to the outro right there because it seemed like it felt like a natural segue, but I think this lands on a stronger philosophy that the typical security were awareness episode. instead of debating products or phishing templates, we've reframed the entire discipline around psychology and and learning science. It also deliberately avoids the humans are the problem framing while still making the case that accountability does matter. Cypher: But but only after organizations have invested in capability. You know, I think I think it really gives our listeners something to think about long after this episode ends. And that's kind of cool because that's usually what separates like a memorable CISO conversation from just our, you know, our technical podcast. Glitch: ⁓ a hundred percent. So Cypher, maybe we shouldn't even call it security awareness. ⁓ I mean, think about that phrase. What does it actually mean? Cypher: So you didn't wake up this morning being like, Hey, I wanna be security aware today. Glitch: Of course not. No. I wanted to be harder to manipulate and a a better decision maker, more resilient, more confident, better at protecting myself and my family and my friends. Cypher: Okay. So the goal was never security awareness because awareness is just knowledge. The goal then that you've just described is discernment. You know, it's that the ability to slow down and question assumptions and recognize that manipulation and make good decisions in cases of uncertainty. Glitch: And that's not cybersecurity, ⁓ really. That that's just wisdom. Cypher: Right. And that that's perfect. Glitch: Okay, so now I feel like we're at that good segue unless you have anything else you want to add to the episode. Cypher: I'm pretty sure that I beat that dead horse to a bloody pulp. So ooh, so on that note, thanks for listening to us rant for a few. I'm Cypher. Glitch: And I'm glitch. Remember, if your awareness program ends with a pie chart, you you measured participation. Cypher: ⁓ and if it ends with better conversations, you changed culture and that is a world of difference. Glitch: It w once again you just had to get the last word in, didn't ya? Okay. All right. Well we'll see everyone next time. ⁓ and by the way, I win with the last word. Cypher: It was an effort.