
Loading summary
A
This is Rich Drafalino with the department of no. Andy Ellis, principal over at duha. I have to ask, we're starting out the week here. We're getting close to the holidays. What is your priority this week?
B
Okay, I just have to object because we're in the holidays. I lit Hanukkah candles last night. We didn't actually have any Hanukkah candles left, so we had to use chime candles, which are not the right thing. So today's priority was make sure we got Hanukkah candles. And really it's wrap up the end of the year. Like, there's a lot of people like, oh, I got to get something done. Great. If you've got a line of sight to it, get it done. If you don't kick that out to the next year right now, prioritize actually having successes rather than just setting the stage. You should do some stage setting. But if you're not going to succeed at a thing, your time is very valuable right now. Make sure you hit your wins.
A
My priority is making sure I know when holidays actually start. That goes for Hanukkah and Christmas, quite honestly, for me. But Johnna Till Johnson, the CEO and founder over at Numerators, what is your priority this week?
C
Well, I just want to make sure that none of my clients accidentally hire AIs or North Koreans posing as legitimate IT hires. That's my top priority for this week.
A
Truly, truly a noble one. All right, producer Steve, let's get this show started. From the CISO series, it's cybersecurity headlines. Yes, indeed. Welcome to the department of Know, your Virtual Monday strategy meeting and the one place that definitely knows when Hanukkah starts. Our sponsor today is adaptive security awareness training, built for deepfakes and AI. If you want to get involved in our chat, we're on YouTube, so if you have a YouTube account, I assume you can't do it. Honestly, get involved. We're here Every Monday at 4pm Eastern. Or email us feedbackisoseries.com we have two fantastic guests here. It's an all star lineup here for the middle of December. We're super thrilled. Just a quick reminder for Andy and John, all of their opinions, in fact, are their own, not necessarily those of employers, of friends, of family, of clergy. We've got about 30 minutes, so let's just jump right into here. We are going to start out, as we always do on the department of no with our no or no segment. Here are some stories from the past week. We need to know if These are something we need to know more about or if they're more noise than signal. The first up here is a story super interesting here, kind of a couple of stories here, but AI poisoning this week highlighted the growing practice among scammers of AI poisoning. This is planting optimized text and websites, WordPress blogs, YouTube descriptions, even Yelp reviews, which will mislead LLMs into reading and presenting the false information, including sending people to fake URLs, which I don't know if you know that. Not a great thing. Emirates and British Airways were both mentioned in some of recent occurrences where we've seen this kind of go sideways here. So I have to ask Andy, for you, is this something that we need to know more about or no, thanks.
B
For you, I think this one is a little bit of a no thanks. As long as you're already paying attention to scammers poisoning search results like the AI is just an interesting scale thing. But if you have to worry about brand, you should probably already be worrying about this. If you don't, you probably shouldn't.
A
Jon, what about you? Is this a new spin on an old problem or something we need to know more about?
C
I'm with Andy. Honestly, if you've been trusting AI results all this time, then you're making a huge mistake. The fact that scammers are tweaking things is no big surprise.
A
All right, next up here, humanoid robots go mainstream. This is producer Sib's favorite story of the week and I think because it provides a new definition of the word botnet, but forecasts of billions of robots by 2060 across industries and households, they all have some issues here. Maybe though, because there's research coming out showing vulnerabilities in connectivity combined with AI learning and embedded sensors that could allow for anything from attacks to espionage to out and out hijacking. A recent proof of concept exploited UN Trees robots, Bluetooth interface allowing wormable malware, wormable robots. That sounds very close to Skynet situations here. Experts predict a new sector for humanoid robot cybersecurity will emerge. But right now, some of the reporting I was seeing that a lot of these companies that are developing these platforms don't even know what a CVE is. Jonna, for you, do we need to know more or no thanks on this?
C
I'm going with no. Thanks for. Frankly, this is sort of overhyped. It's certainly a real problem, no doubt about it, but it's been a real problem for 15 years. Robots are a subset of IoT. IoT is very broad. We've known about these issues with IoT. And it just, it's an area where, yes, we need to deal with it, but just because it's robots doesn't make it somehow any more serious than when it happens to be, you know, tools in your manufacturing floor.
A
All right, for you, Andy, I was breathing into a paper bag reading some of these forecasts here. Do you need to know a little more about this or am I hyping this up too much?
B
I think you're hyping it a little too much. Like there's very much a movie plot threat. If anybody remembers Mirai, that was wormable malware on security systems with cameras. So we're in the same world that we have been in for over a decade. I do think it'll be fun and interesting when we have actual walking around robots that might be taken control of. But that's not even what this story is. And we should worry a little tiny amount about that. But we have until 2060, apparently, until there will be billions of these robots, which is like one per human on the planet, which seems a little aggressive. It does.
A
I think now I'm thinking about like robot E waste. And I'm like, I'm very. And then, then we're going to be talking about like h. Waste for humans. It's. It gets very soiling green all of a sudden. I apologize. I don't mean to take us down there.
B
Don't. Don't get me talking about waste management. I'm in the city that is an international laughingstock for arguing that we should go to every other week. Trash pickup.
A
You know, I mean it. I appreciate. Hey, listen, you got to think outside the box sometimes to realize that inside the box is actually really nice. Our next.
C
Wait, you guys have trash pickup? We don't have that.
A
You know, we're all at different stages of, of society here. I don't have trash pickup because I have children. I have trash levers and they're excellent.
B
There you go.
A
Our next story here, Marquee Software. Texas based fintech provider Marquee Software Solutions, which works with over 700 banks and credit unions across the US said they were hacked due to an exploited sonicwall firewall vulnerability. List of remediation efforts include patching firewall devices, changing passwords, and adding VPN lockout rules. In other news, a rancher whose horse just bolted has installed a shiny new lock on his barn door. John, for you. Do we need to know a little more about this? No, thanks.
C
I mean, I do think this is important for people to know about if they happen to be dealing with credit union. I certainly made a note to myself to check with my credit union above and beyond that, though, this is an example of supply chain risks and third party risks that people should be paying attention to. So if you happen to be working at a bank or credit union that has not been worrying about these kinds of vulnerabilities, now is a really good time to start.
A
I'm curious, like, how do you, if you're in a security team working at a, at a, you know, credit union, a lot of them are fairly small. How do you start that conversation? Do you just bring the story and they're like, hey, are we like, like, is that, is that the wedge you need there?
C
Well, it could be, but quite frankly, the sonicwall firewall vulnerability was actually posted as a cve. We talked about it several. Gosh, way back when these things were happening. So if you don't have somebody that's monitoring the CVEs at least every week, you should. It's pretty straightforward. And you should be installing those patches and fixing things before they get exploited. So that's kind of the missing link here. Even if you're a small IT department, you have to have some way to get information about current vulnerabilities, current exploited vulnerabilities, which is different, and plan to have plans to patch them, update them, fix them as you need to hire a service if you need to do that. If you're too small to do it yourself.
A
Andy, what about for you? Do you need to know a little more about this or are you good?
B
So the one thing I'd like to know a little more about is this really feels like perimeter defenses are the one thing they're talking about. And why is that the only thing you needed to fix? Like, are you a Twinkie? A little foamy on the outside, but the cream's all in the face feeling easy to get to, you know, that's. This feels like so 1990s. And it may just be that the look where I think our story. I don't remember who it came from, but maybe that's what got lost in translation, that there was much more complicated things. But I need to know, like, what are you doing to deal with lateral movement? Because at this day and age, it's no longer acceptable to say lateral movement is not something I'm going to worry about.
A
On our last story here in no or no U.S. department of Defense transitioning to post Quantum cryptography. I'm sorry, the Department of warfence. I Think we all agreed on here.
C
Yes, Department of Warfence, we like that.
A
The U.S. department of Warfence has announced plans to transition to quantum resistant cryptography based on NIST approved post quantum encryption schemes approved last year. The transition includes conducting a cryptography inventory and risk assessment, selecting top priority systems for immediate migration, and migrating systems in priority order from legacy protocols with the goal of having everything completely migrated by the end of the year 2030. Andy, I'm going to start with you. Do we need to know a little more about this or no thanks.
B
So I sort of have this mostly in the no thanks simply because it's already been in the news for so long. But like, this is what crypto agility has always been about. Like how do you just switch protocols, how do you switch algorithms quickly? The fact that we still have people saying we can't do that until 2030, honestly, completely unacceptable. I don't care what you want to call your department, but you all should have crypto agility in place and it should have been in place 10 years ago.
A
John, what about for you? Do we need to know a little more about this? Is Andy right with the agility angle? Is this a no thanks for you?
C
No, I think that we definitely need to know more about it. I think Andy is right in theory, but in the real world there really isn't any crypto agility. And let's put this in context. NIST's algorithms have only been out, the ones that actually work. There was a false start in January 2024, but now they've been out since about July 2024. The reason it takes until 2030 is you have to go in and assess exactly where these algorithms are being used, whether it's your vendor, whether it's your in house, or whether it's provided by a vendor. You have to then know what the vendor's plans are, which may not meet your time frame because it might be built into the vendor. So the real reason I think this is a no more is that maybe people have been on top of crypto agility, but I can tell you most of them haven't.
B
No, they haven't.
C
And more to the point, most people will say, oh, that quantum stuff, that's decades out, I don't need to worry about it. And the reality is nation state actors have a technique called, you know, harvest now, decrypt later. So if you're in any kind of an industry that might be a target for nation state actors, and that's a bigger set than you may think you are a target. And if you aren't making that transition now, you're going to be in a world of hurt if and when quantum computers start coming out. So yes, do it now, do it because it's the right thing, crypto agility. And also do it because you're going to need to, because you will be a target. You probably already are.
A
With the NIST standards coming out again, having them for about a year now, a little bit more than a year now, is like, is it, are we in that race now? We don't know when the transition, when the breakthrough is going to come through. I mean, to your point, like we've kind of been saying that as well too, with quantum stories where it's like, okay, they've string together a couple more qubits this time and the error correction got slightly better. Like how, how? My question always is the business is always going to say, oh, see this can here? And then we have this nice long road here and I have these really strong boots that I can deploy on this can here. Andy, for you, like again, how do you start that conversation of we know that people are gathering data, knowing that theoretically it becomes trivial to decrypt down the road? What does that conversation look like?
B
So I think that conversation. And now I'm going to beat the dead horse of crypto agility. There's too many people who are saying I'm going to wait for the standard to start any transition. And so if you have not transitioned and look, with the open SSL breaks that started in like 2014, there's no reason for a business not to have crypto agility. At this point. You should be able to say, that algorithm's dead. This is one we're going to go to. That's a, a pretty easy fix, right? It's a three step jump to move forward. But my big worry is, you know, coming back to the real world comment because, Jen, I got to throw it right back at you, which is 2030 is not a real world expectation. There is no way. No, it's not.
C
No, no, believe me, we cover a lot of quantum computing and no, no.
B
No, not for the adversaries. I mean for the migration. Absolutely no way the DODORW is completing that migration in five years.
C
Oh, come on. You don't think government efficiency is at work here? I mean, man, I got my passport a month early, so I'm sure they can do this.
B
You know, I used to be an acquisition engineer for the United States Air Force and I will tell you this like it is I will hope that high priority systems can migrate, but there's absolutely zero way that we're going to be compliant by that time.
C
I would agree with you, but I think there are other enterprises that are a little bit more flexible and agile than the US Government that I would hope so pray that there are.
B
Yeah. If you're a profitable publicly traded company and you cannot meet this deadline, you have serious issues.
A
Yeah, I like that. I like the US Government as the benchmark for you must do better than this date that they won't hit.
B
Yeah, pretty much.
A
All right, before we move on to our deeper discussions for this episode, we have to spend a few moments and hear a word from our sponsor today. Adaptive Security this episode is brought to you by Adaptive Security, the first cybersecurity company backed by OpenAI. AI is rewriting the cybersecurity rulebook because attackers can now scale persuasion as easily as they can scale code. The real target isn't just your systems anymore, it's human trust. If you aren't actively testing your organization against AI driven phishing, vishing and deepfakes, you're leaving a gap. Criminals will exploit adaptive runs, realistic simulations and delivers tailored, engaging training so teams respond correctly when it counts. Learn more@adaptivesecurity.com all right, we've got some more stories here we need to go deep on here. Our first one up here, MITRE shares 2025's top 25 most dangerous software weaknesses, working with Homeland Security Systems Engineering and Development Institute. And thanks for the shorter name there, the list contains 25 of the most dangerous software weaknesses behind more than 39,000 security vulnerabilities disclosed between June 2024 and June 2025. Topping the list is an oldie but a goodie cross site scripting, followed by, you guessed it, SQL injection, cross site request, forgery, missing authentication and out of bounds write. With new entries this year being variations on buffer overflows. A link to the full list is available in the show Notes for this episode. You should definitely check it out. A list of tried and true techniques here being used by threat huggers. I'm curious though, Jonna, from your perspective, where do we take it from here? We have this list a lot of oldies but goodies on here, right?
C
Yeah. And I think one of the challenges is that it's kind of like, well, be afraid, be very afraid, but it doesn't give you anything that's super actionable. We sat down and scanned through the CVEs for 2025 and came up with a short list of not just vulnerabilities, but exploited vulnerabilities. And then we associated them back with the vendors that had them. And very interestingly, for the top five, Fortinet and Cisco tied for fourth and fifth place with five exploited CVEs. Google and Apple then had six, and then we had Microsoft with 29 exploited CVEs. So these are ones that are exploited and also really a common theme across all these exploited CVEs is talk about oldies and goodies. Remote code execution due to improperly handled input, which is actually what took down the, you know, airports and hospitals a couple of years ago.
B
So.
C
So what I would say is it's a lot more helpful to know who's got vulnerabilities, which of those vulnerabilities are actually getting exploited than what, you know, what arbitrary types of vulnerabilities exist out there. You really want to know, like, where am I likely to get hacked from and from whom? And that would be my take on it.
A
Yeah, the idea of, yeah, who do I need to keep my eyes on versus the type of things. But Andy, I mean, jumping, I guess, what value can we get from these types of lists here other than, hey, that's good to know that.
B
I mean, a lot of vendors are going to love doing webinars about this list, similar to what they always do with owasp. That's your template. This is useful for training your new AppSec engineers to say, hey, here's a list of techniques you should be familiar with so that when you're doing pen tests, et cetera, like, that's basically what it's good for. But this list is going to look the same next year. Maybe they'll move something around similar to the OWASP top 10 that we might as well just have called the OWASP top 12, because only like two things pivoted around across like a decade. So I think this is not really very interesting. I like what Jenna just did with the like, oh, here's the top five vendors. Microsoft, congratulations on being an outlier there.
C
But other than that, almost as many as anyone else.
B
Right. And congratulations, Fortinet, for joining the four that we would have predicted. Like, the four most predominant deployed software owners. Like, we know who they are. Fortinet, you get to be number five. I'm not sure that's the group you want to be in, though.
C
Yeah, and in fairness, I just want to highlight something because, Andy, you and I were talking about this before. There is some correlation between how widely deployed the software is and the number of vulnerabilities. What I would like to point out that, number one, Microsoft's forex factor is really an outlier. And number two, there's an awful lot of vendors who aren't on here, like Salesforce and Oracle and ServiceNow and other really big platform vendors that are deployed across the board that have a lot of products and just didn't show up for whatever reason. Like maybe they have better security.
B
Yeah.
A
So if you want to get started on your MITRE 2026 top vulnerability post, get that draft. You can get that draft in early. Is advice from Andy Ellis here.
B
Yeah, you basically copy the one you just wrote for this and leave space for new to the list is X and dropped off the list is Y and you're golden.
C
In fact, use AI for it and you're done.
B
Yeah. Poison your LLM.
A
Yeah. So what you're saying is I need to start poisoning with fake threat. Okay, that's right. It's threat turtles all the way down. I love this. All right.
C
Yes. Threat turtles all the way down.
A
Next up here, CEO of retail giant Coupang resigns and Chinese national is a suspect. The story of the Coupang hack continues to unfold. We've definitely been covering this on CyberSecurity headlines, with CEO Park Daejun stepping down, accepting responsibility for the incident. An investigation now attributes the attack to a former employee who retained access to internal systems after leaving the company. The Suspect is a 43 year old Chinese national who joined Coupang in November 2022, was assigned to an authentication management system, and left the firm in 2024, which you'll notice was a while ago. So a lot to unpack here. The willingness of CEOs to fall on their sword after suffering an incident doesn't seem to be particularly common in the US necessarily. But do you feel this is an appropriate action on the behalf of a CEO, kind of taking the responsibility to leave the company or. Andy, I'm curious, when's the last time you saw something like this?
B
So this is something that we see very rarely. And so like, there's a temptation to say, wow, this is how it's done and this is what we should be thinking about and like, this is the golden style of what we ought to be doing. But I sometimes do wonder, like, is this just sort of like soda pop that we're all like, oh, this is really good. It's flavorful, but it's not very filling. Like, is this actually the right action or not? Like, I sometimes wonder, like, is there something else going on under the covers, why he's really resigning or and this just gave us a cover. Like, is this some corporate takedown that he lost an internal political fight? Right. So that's what we have to wonder about. Like, you know, but it can feel very freeing that this has happened. And we're like, wow, it's not just the CISO who is taking the fall. Like, it's your idol, it's the CEO actually said, I'm gonna be responsible for security here. So I think it's really good. You know, this is what it sounds like when accountability happens. So I love this. But it might also be unique to the Korean environment.
A
John, I saw you nodding your head here. I mean, any, any kind of thoughts about, like, hey, this is, this is novel to see, to see that, you know, where the buck stops when it comes to these types of incidents going all the way to the top.
C
Well, first and foremost, I just want to highlight, this is why I've been telling my clients to pay close attention to hiring process and processes and background checks and things like that, because you really want to make sure that your folks are, are not in a position to continue to hurt you. And I think, I think the fact that as you pointed out, this guy left in 2022 and still had access to all sorts of things is an incredible operational failure that nobody at that company should be proud of. But I'm going to then go on and say, look, I have a former podcasting partner who used to make the point that all security is simply performance theater. Because basically whenever you get hacked, you look at the companies that get hacked, very few of them go out of business, very few of them suffer even a long term stock hit. So it's sort of, you know, at what point does the performance theater satisfy the shareholders and we all move on. And I think that's the question. And I think certainly here in the U. S we don't require CEOs to leave because that's just how we're put together. We don't need that level of theater. We need lower levels of theater. So, but you know, it really is all in, in that mindset. All, all security spending is marketing spending, which is terribly, terribly cynical, but not crazy.
A
You know, the other aspect of this here is that this is effectively like an off boarding failure, right? Like, or leading to, you know, problems with access control and stuff like that. I'm curious when I, when I see stories like this, you know, offboarding is an HR led initiative usually, right? So like when we know that we're going to have. There could potentially be issues here with, right, with like access, people maintaining access long after they left the company. If you're the CISO or if you're, you know, you're a security leader in your company, like, where do you start? I mean, should you already be having those, those coordinations, those contacts with the other.
C
Very much so. And, and it all should have been automated. If you had Zero Trust in place, this would have been completely automated. Because one of the cool things about Zero Trust is you can configure it so that if is actually completely dynamic. So somebody may have admin access to a system only during the very short period of time when he or she is troubleshooting a problem for a user and then is automatically kicked off admin access to the system as soon as the trouble ticket is closed. That's the kind of setup you should have. So there shouldn't be a big heavy lift when someone off boards. The fact that there is and it wasn't, it didn't happen, as I said, and it's a real operational snafu.
A
All right, our last story here. Ransomware payments pass. $4.5 billion Ransomware payments reported to the US Treasury's Financial Crimes Enforcement Network has now topped US$4.5 billion, with 2023 standing out as the most expensive year on record with $1.1 billion paid. Alf V or Black Cat took in the biggest haul with nearly 400 million in payments and financial services. Manufacturing and healthcare remained the hardest hit sector. No surprise prices there. Most ransom's demands stayed under $250,000. That's where the average was at, obviously. Pretty big standard deviation there as well, I guess. Though ransomware does not seem to be going away. We're still dealing with it. Hey, it was a down year in 2024, so kudos for that, I guess. But I mean, is this now just part of the cost of doing business for these organizations? I mean, we're seeing like in the uk we're seeing an open discussion, right, about, hey, ban, we need to ban ransom payments. It's going, you know, remove the incentive structure for doing these types of attacks. We see other organizations trying to use things like insurance, right, to just roll this into the cost of business. Andy, for you, like, have we just completely normalized this? Can we normalize $4.5 billion in damages from. From threat actors? And that's only what's been reported. Right.
B
You know, I really worry about the normalization here because we've come to accept that lateral movement is a problem. And I hate to like do a throwback to an earlier thing, but. But so much of ransomware is, yes, you got exploited, somebody got a toehold, but then you let them use that toehold to grab everything. And why are we not paying more attention to the lack of phishproof authentication, the lack of controls on admin access, whether it's going to be through Zero Trust or something else, the number of administrative tools that we just install on everything. So, like, own one vendor, you own like your entire space. Like, these are the things people need to do to say stop lateral movement. And how do you get it that your users are in a world like where if their laptop gets compromised, they can walk down to the store, buy a new one and be back up and running. And that should be the world that you're in. And if you're not in that world, then ransomware is going to be a problem for you.
A
John, what about for you? I mean, are you as worried about that normalization kind of process and kind of what that says about where we're at?
C
Well, I don't think we really are normalizing. I just think people don't realize that ransomware is a complete, completely as. As Andy said, it's completely addressable cybersecurity problem. So the takeaway here is, if you haven't dealt with it, make 2026 your year to deal with it. And what does that mean? Regular backups. Make sure your backups, your backup data and apps are scanned on a regular basis to, to detect Easter eggs. Because obviously the ransomware folks are smart enough to put something in that will only explode after, you know, 18 or 24 months and then conduct regular ransomware. War. War Gaming Quarterly is ideal. If you can do it at least twice a year, you're ahead of the game. And this should include both your tech team and your senior executives, because otherwise you're going to have senior executives, as one client of ours did, making decisions like, oh, we should pay the ransom. And then they discover that it's actually illegal to pay the ransom because it's a nation state actor and you're not allowed to give money to a nation state actor. You can't do that. So basically, if you are doing your regular backups, testing your backups for Easter eggs, and conducting war gaming, you're probably in pretty good shape for ransomware. But the sad thing is most companies aren't doing any of those things.
A
So is that just the disconnect, right, of the security folks? Know what medicine we need to take we just can't convince anyone to buy it. That's the most hopeful take on ransomware I think I've ever heard of. We actually can completely do this. We just have no buy in on it. Is it purely just a. No one wants to actually pay for.
B
The medicine and the things we have to do aren't very exciting. Like that's actually a big piece of the problem. This isn't like go deploy the latest shiny things. This is like go do the fundamentals we've all been talking about for a while. We say zero trust and everybody wonders what zero trust is. But the building blocks of zero trust is provable authentication. You know who this person is? Do that so you don't have lateral move deal with remote admin because that's a huge problem. Like admins who can always log into everything on your laptop. That sucks. It's just blocking and tackling. If you are using in this day and age Active Directory on site and you have not implemented multi tier admin access and you don't know what I'm talking about, go figure that out and solve that problem. Either get rip out active directory or implement it the right way. Real quick.
C
By the way, make sure your configurations are not what Microsoft just leaves in the box because that is the source of a lot of the vulnerabilities. But yes, yeah, Andy's completely correct. It's like it's not fun. And the other thing is dragging a bunch of overworked tech people and or too important for school senior executives into a room and doing an afternoon or day of war gaming seems like that's an incredible expense, you know, and people are just not actually doing the ROI on this and saying yeah sure, okay, it's a couple million dollars to get these people in a room for a day, but that saves us hundreds of millions of dollars if something happens to the company.
A
Real quick, we had a question from David Murray in our chat here. John, based on what you said, how do you test your backup for Easter eggs? I can't imagine that's easy. Real quick. I mean can you just kind of.
C
Oh, there's a, there's a ton, there's a ton of products. I don't have a current list right at my fingertips, but there are at least half a dozen products that do that and specialize in it. So you just basically have to go look for it, you know, Google or Chat GPT or whatever you want with, you know, with ransomware search, scan back data backups and you're golden. There's, there's vendors that have like exist.
B
To do this and no AI scammers have poisoned those results on your search engines.
A
However, the Easter, the Easter egg hunting.
C
Service, there's always an easy workaround on that because you, you do an out of band, out of band check to find those vendors.
A
All right, before we close out of today's standup, I guess what piece of advice just kind of based on the, you know, the, the news here. We dealt with a lot of specifics here perhaps, but what kind of advice can we tease out of the news from today that we can share with our audience? Andy, I'll come to you first with this.
B
So I think the simple one is you need to be willing to say what should we have done that we didn't do, that we've accepted for a long time and how do I slowly sell that? Like, you're not going to be able to walk in and say here's 20 things we ought to do tomorrow. Nobody's going to believe you and they're going to be like, oh, you're just itching for more budget, but how do you sell these things and do the slow incremental work to be ready? And yeah, it might suck because you might get breached tomorrow from something you've predicted today. But this is the hard job of security is convincing your stakeholders to be on the journey with you, deliver meaningful wins out of work that is not like super exciting. You're not spending $10 million on the latest shiny toy, but you're actually delivering meaningful results for your people.
A
And Jona, for you. What, what advice do you leave our our audience with today?
C
Well, the only thing you have this exactly the same, same amount of as everybody else in the entire universe is time. You have 24 hours in a day. So spend that 24 hours wisely on the things where you have the greatest risk. Not necessarily, as Andy says, the fun things, the cool things, the thing your CEO happens to be screaming about today. But sit down, figure out what your true business risks are. What you can what, what where you can move the needle and spend your time according to eliminating or minimizing the risk as best you can.
A
I don't have enough chef's kiss for both of those pieces of advice. So I'm not, I'm not even going to offer one because that would be insulting. But thank you both so much for being on the department. Of note, this was phenomenal. Andy Ellis, the principal at duha, where can people find more of what you are up to on the cyberspace?
B
So my latest thing is I've been publishing the how to Ciso volumes which are practical advice for CISOs and people who want to be CISOs. And I just wrote a 28 page ebook on everything you need to know about risk. How to talk about risk, what language to use, how to measure, how to monitor. That's like the best primer you can have at any level if I do say so myself. And it's completely free@howtocso.com and the language.
A
You should use is Classical Latin. Right? That's the absolutely fantastic.
B
I'm a big fan actually of Acadian.
A
But I mean, okay, if you're like the aorist tense, I guess. Sure, why not?
B
Yeah.
A
John Attil Johnson, CEO and Founder at Nemertes where can people find more of what you're up to online?
C
So hit us up on substack nemourities.substack.com Our most recent post is a report that we have for our members that talks about it background check checks, which is why it's top of mind for us and what you can do to ensure that your background checks are actually working and you're not getting deep faked.
A
We will have links to everything in our show notes as well as their LinkedIn if you want to contact them that way as well. All good stuff will be there. Thank you both so much once again and thanks to our sponsor for today. Adaptive Security Security Awareness training built for deepfakes and AI. Remember, send us feedback feedbackisoseries.com, we make it easy to remember and you can join us next Monday at 4pm Eastern for another edition of the Department of no. Just go to the events page@cisoseries.com or subscribe to us on YouTube. We just hit 10,000 YouTube subscribers, so if you have subscribed. Thank you so much. You are amazing. You can join in our chat. You can subscribe. We got a lot of fantastic people in our chat today asking some great questions, hopefully getting some great answers there. Very, very fun. Thank you so much for joining Monday Standup. Have a great week and a super sparkly day.
B
Cybersecurity headlines are available every weekday.
A
Head to CISO series.com for the full stories.
B
Behind the headlines.
Date: December 15, 2025
Host: Rich Drafalino
Guests: Andy Ellis (Principal at Duha), Johnna Till Johnson (CEO & Founder at Nemertes)
Theme: A lively roundtable tackling current information security headlines through candid debate, expert commentary, and practical advice.
This episode features a dynamic exploration of timely cybersecurity topics. The hosts and guests dissect high-profile stories, debate their actual significance, and offer concrete advice on major vulnerabilities, government cryptography transitions, insider threats, ransomware normalization, and more—all while mixing insight with humor and a critical eye towards actionable security strategy.
“If you’ve been trusting AI results all this time, then you’re making a huge mistake.” – Johnna Johnson
"Yes, we need to deal with it, but just because it’s robots doesn’t make it...more serious than...tools in your manufacturing floor."
"If anybody remembers Mirai, that was wormable malware on security systems with cameras. So we’re in the same world..."
“If you don’t have somebody that’s monitoring the CVEs at least every week, you should. It’s pretty straightforward.”
"The fact that we still have people saying we can’t do that until 2030, honestly, completely unacceptable."
"The real reason I think this is a 'know more' is that maybe people have been on top of crypto agility, but I can tell you most of them haven’t."
Key Quote:
"Nation-state actors have a technique called, you know, harvest now, decrypt later. So if you’re in any kind of an industry that might be a target for nation state actors... you are a target." – Johnna Johnson [10:36]
"It’s a lot more helpful to know who’s got vulnerabilities, which of those vulnerabilities are actually getting exploited than what...types of vulnerabilities exist out there."
"This list is going to look the same next year...similar to the OWASP top 10."
[19:55] Andy: Rare for CEOs to resign over breaches; wonders if it’s genuine accountability or internal politics.
"It’s not just the CISO who’s taking the fall. Like, it’s your idol, it’s the CEO actually said, I’m gonna be responsible for security here."
[21:06] Johnna: Emphasizes importance of rigorous offboarding and background checks; views much security response as “performance theater.”
"All security is simply performance theater...very few of them [breached companies] go out of business, very few...suffer even a long term stock hit."
[23:02] Johnna: Automation/zero trust can eliminate persistent access issues:
"If you had Zero Trust in place, this would have been completely automated..."
[25:02] Andy: Laments normalization of lateral movement and poor fundamentals.
"Why are we not paying more attention to the lack of phishproof authentication, the lack of controls on admin access..."
[26:02] Johnna: Ransomware is addressable; calls for basics: backups, Easter-egg testing, and war gaming.
“If you haven’t dealt with it, make 2026 your year to deal with it. ... Most companies aren’t doing any of those things.”
[27:31] Andy: Resistance to fundamental security because it’s not “exciting”:
"The things we have to do aren’t very exciting. ... This is just blocking and tackling."
[28:20] Johnna: Many orgs fail to configure systems properly or conduct meaningful preparation; cost avoidance is shortsighted.
"...it’s a couple million dollars to get these people in a room for a day, but that saves us hundreds of millions…"
"How do you sell these things and do the slow incremental work to be ready? ... deliver meaningful wins out of work that is not like super exciting..."
"Spend that 24 hours wisely on the things where you have the greatest risk. Not necessarily...the fun things..."
On moving past splashy headlines to substance:
"The building blocks of zero trust is provable authentication. ... It’s just blocking and tackling." – Andy Ellis [27:31]
On security theater and corporate incentives:
"All security spending is marketing spending, which is terribly, terribly cynical, but not crazy." – Johnna Johnson [21:06]
On the stubborn persistence of old vulnerabilities:
"This list is going to look the same next year...similar to the OWASP top 10..." – Andy Ellis [16:55]
The episode delivers practical insights into persistent and emerging cybersecurity threats, emphasizing that most breaches and high-profile incidents are failures of fundamentals rather than new or exotic issues. The inertia in remediating well-known vulnerabilities, the lack of crypto agility, and insufficient offboarding/inventory controls remain critical drivers of breaches. Ransomware, too, remains rampant—and addressable if organizations commit to the basics.
Final thought:
Focus your limited resources on real, impactful risk reduction, and champion incremental, meaningful security improvements over shiny, short-term fixes.