James McQuiggin (79:33)
Everyone loving the dad joke that I dropped. Good. Good seeing the laughs in there. Working my way. Yep. Work Mr. McQuagan on the cruise ship. Yeah, sorry there, Ben. Yeah, you know, hey, I, I can, I, if I can, as long as I've got a good strong Internet connection, I can get the work done. Looking forward to coming out to Ben's event there in out west later on this year. It's going to be a lot of fun. Kyle, Kyle's got another question. Got any tips for getting buy in for multiple department leaders for tabletop exercise? Besides going thou shalt participate in the exercise? One of the things that we, we talk about is making it important for them, figuring out what they care about, what's keeping them up at night, you know, in those department leaders, is it legal, is it hr, is it finance, is it your R D team, your developers, the different business folks when it comes to those different departments, find out what it is that's important, important to them and then target it for them specifically. So if you've got your finance folks, they're going to be considered and they're worried about business email compromise or they're worried about having their, you know, credentials stolen or whatever else. Then you cater the tabletop exercise to include that. So then they understand. Well, look, let's, you know, let's go through this now. That way we understand what everybody's roles are, we might be able to find some things that were missing and we can fix those. Now when there's no problem versus when we're in crisis mode and we're dealing with a breach or an incident or credentials or business email compromise or whatever your exercise is going to be and then we can address them now versus later when a crisis mode's happening and we're all losing our hair and trying to figure things out then. No, let's figure it out now, but figure out what it is that keeps them awake. Figure out what's important to them and cater the table to top exercise around that or include that particular item in there. So then they get engaged and they care and that will go a long way. They may push back on it but you know, if you've got buy in from the top and this is something, everybody's got to participate. You may not want to participate, but trust me, you're going to want to know what to do. We're going to be there to guide you, but you're the ones that are going to be following through on the actions that come out of it as out of the exercise and the results of it it that. And you know, if they like dnd tell them it's a giant cyber security Dungeons and Dragons game, you know, that's always a lot of fun to do it. Let's see. Oh, Kathy Chambers. Hello. Kathy Chambers, good to see you. Looking forward to see you I think next week at Hack spacecon. Just joining and already jealous of James. Well, you know, I, I, I aim to please, I guess but very fortunate, very blessed to you know, get these opportunities to go out on these cruise ships that and playing in the adult arcade and getting offers that way. So. Question coming in from Gibwat 6012. I'm going through SZA study guide and just wasted yesterday installing stacks. What should I be using for threat intel? Just Alien Vault manually. So one of the things that I do with CTI Cyber Threat Intelligence and also wade through location blogs is another great resource as well. But I came across there's several sites out there where some folks do a really good job with threat intel. If you hit me up on LinkedIn, give what I can give you some resources that I've got with regards to cti, some folks give me a couple days because I got to pull it together. There was a website I visited the other day where somebody had a great listing of current threats and then align that with sticks to one that you could download. I, I saw stacks and I was thinking of messing around with it but it seemed really complex. I'm working on an exercise right now for my students really for dealing with sticks and taxi and going through and getting some threat intel and dropping it into the taxi a taxi environment, whether it's with Alien Vault or a standalone. I'd really love to try to leverage yeti, but that's me personally because I can load that locally and be able to bring in the the sticks data that way. So you can try Alien Vault manually but, but hit me up and we'll see if we can't get you some other resources as well. Can't wait for my cruise in 90 days says FedEx. Yeah, I've been away from GRC and Info6 since 2023 and I'm keen to get back. This is coming from AD Kunty. Hopefully I said that. Right. What would be your advice on how to proceed, especially if one is a bit rusty? You know, we, we always think we leave, but we never really do. You know, it always pulls us back in. Just when we thought we were out, GRC pulls us back in. You know, a lot of the times people think, oh, I got to learn everything, I got to do everything. I've got to, you know, just pick up right now. Take what you've learned and just kind of pick up and, and, you know, keep going. What's happened in the last two to three years is kind of what was happening before that, just without the COVID you know, organizations still being breached. We're dealing a lot more with AI now. AI governance is kind of a big area. So if you're getting back in, start picking up on the AI governance stuff, looking at the different standards, the different, you know, whether it's NIST, whether it's ISO, whether it's CSA's got guides, OWASPA's got guides. But start looking at AI governance and looking at how to govern, you know, provide the governance and the compliance for AI software tools, chatbots, large language models, agentic, you know, whatever that may be. But AI is, is the hot one, AI governance. There aren't a lot of tools. A lot of people are coming out saying, oh yeah, we got AI governance tools, yeah. But, you know, definitely get on that, that would be where I'd start looking right away. Also, depending on what industry you're in, will depend on how integrated they are with AI as well. Space Doc was dropping in. A question. If presented the chance, would you live on a cruise ship for one to three years? If I could bring my own Starlink and have my own 200 megabit down connect downstream connection, I think this one I'm running on about 5 to 10 right now. If I could bring my own Starlink and I could have, you know, a decent sized room and my wife and I didn't feel like we're on top of each other. Have like a junior suite or something. I, I think I could, I'd want to make sure my kids are a little more squared away. But the wife and I were talking about it. We, we met a couple that were on a cruise ship for 274 days and they absolutely loved it, you know, but there were, there are some things you Got to think about like medications and you know, and how healthy you are and the fact that you could, you know, you'd be away and missing birthdays and, and anniversaries and parties and whatever. If I was on a cruise ship for one to three years, there's a. Ironically within, I think it's the Royal Caribbean line. There's a guy named Super Mario. He spends 50 weeks on average. 50, you know, 50 weeks a year on a cruise. On a particular cruise ship with Royal Caribbean, he gets off for two weeks every year and that's when he's doing all of his doctor's appointments. But he works from the ship. He's in financials. But yeah, that would certainly be interesting if I could, if I could do it, that'd be great. The kicker would be is if I had to get off the plane and fly somewhere to deal with something, I'd have to be able to get back on the boat as well. KG I have a blog I post on GitHub about my home lab as well as my accomplishments on LinkedIn. Good, great start. Keep that going. Diagrams, you know, writing about what you've experienced, you know, lessons learned. That goes a long way as well. Packing for my cruise with my mom setting. That'll be a lot of fun. Let's see how we doing it? Holy cow, it's 928 already. Dang. Time flies when you're having fun. Let's see. Any other fun questions in here? Why who's this? FedEx is asking me. Why are you looking the most? Oh, what am I looking forward to the most for HSC and hacker space kind of B side Stampa. FedEx has asked me. I'm guessing that means what am I looking forward to the most? Definitely networking. I am definitely looking forward to getting out, meeting folks. I will have stickers with me. I. I'm hoping I. I gotta see if I get him in time. I may have my new apparent security stickers but I'll have my James McQuiggin 35000ft stickers and my I spotted James Quiggin at 35000ft simply cyber tickets. Jesse Johnson says is anyone interested in meeting tech ricky9 denver and then road tripping to Wild west hack and fast in Deadwood? No deer allowed. Well, hopefully not because we know the story. If you know, you know with Jesse Johnson and dealing with deers drive riding on the road. So yeah, if anyone's in the Denver area or wants to fly to Denver and then road trip with tech Ricky and Jesse Johnson, I can assure you any car trip with those two guys is going to be a lot of fun. A lot of great discussions in that car, a lot of great bonding if you get the opportunity I, I would take. I'm already got my ticket. I'm already booked for Wild west, so I'm good there. James Grigan is at sea level. Yes, I am just slightly elevated above sea level, but yep, you can see the island behind me. Not a backdrop that is really out my window here on the cruise ship. Working from the cruise ship is a lot of fun. Kind of still treat it like I'm at home. Except instead of being at home and all the distractions there, it's, you know, all the, all you can eat buffets, the, the, the game shows that go on all the time, the pools that readily available, the bars that are readily available. Yeah, a lot of good stuff. FedEx is looking forward to HallwayCon. Yep, exactly. Let's see, let's see if there's time for, we got time for one more question. I'm looking through seeing if anything. Well I'm, hang on a sec. Let's see. One of the things need to see this afternoon. What is our good friend Mr. Ozier got planned because it's Thursday and I know on Thursdays. Let me see if I can share this screen here. I know on Thursdays this is going to depend on how well our Internet works. But I know that we have the fireside simply cyber. I know that we have the fireside that happens on Thursdays. Trying to bring up the high. There we go.