A (63:06)
Nope. All right, hey, let's holler. We had 400 people in chat. Really quickly. If you're here, stay tuned because we're going to be melting your face. What? How do you melt faces? Oh, don't worry. We got you covered for days. I'm Jerry from Simply Cyber. That was your Simply Cyber Daily Cyber Threat Brief podcast. Shout out to all the first timers, long timers, shout out to the mods. If you got value from the show, let us know in chat. We'll be back tomorrow at 8:00am Eastern Time to do it again. But know this, we're about to run another show called Jawjacking. You don't have to go anywhere. I take care of all of it. I cannot mentor one on one. People want me to mentor one on one. I do not have time for that. But what I can do is give you half an hour and I will answer all the questions that appear in chat to the best of my ability. If I cannot answer the question, I will get somebody who can answer that question. Let's mentor at scale. I'm Jerry from Simply Cyber. Until next time, stay secure. Ever wonder what it takes to break into cyber security? Join us every weekday for Jawjacking, where industry experts answer your burning questions about the cyber security field live, unfiltered and totally free. Let's level up together. It's time for some Jawjacking. Yo, what's up, everybody? Welcome to the party. My name is Jerry Guy. I do Jawjacking as the host. Coming hot off the heels from the Daily Cyber Threat Brief, hosted by that nerd, Dr. Gerald Ozier. Hold on, I gotta get. I gotta get more comfortable here. I do declare, there were infographs. You guys can't really tell, but my studio is an absolute hot trash garbage dumpster fire back here with all the gear I'm trying to get prepped for Zero Trust World. Are we doing bingo on Friday? Unlikely. Roswell uk, I'm going to be live from the Zero Trust World conference floor. Already going to be complicated. I will say Wednesday, Thursday and Friday shows of the Daily Cyber Threat Brief will be special only because, you know, we'll have multiple hosts because, you know, I'm bringing my big mixing board with four inputs and stuff like that, so. Good question. Thank you very much. All right, if you got questions, put them in chat with a queue really quickly. I do want to point out again the that LinkedIn quad code video I released is blowing up. I am so excited because it helps people. It's not just like, oh, I made a video, go check it out. Like, literally, it can help you. Which is the thing Razo UK says, why the pick on the monitor back there? I Wish it wasn't there because I have deleted that graphic file from my computer. And yet somehow it's retained. So I have released. Excuse me, that is a display of a Mac Mini. My Mac Mini has been hardened, wiped and hardened. And I run Open Claw on it. My AI bot is called Karn. K A R N Karn. Karn was the servant of a planeswalker in the Magic the Gathering universe called Urza. This is where Urza lives. So essentially this is like where Karn lives. So it was a picture of like his house and stuff. I, I would prefer it be the Simply Cyber logo, but I literally cannot change the background. And I've had people tell me how to do it. I've done it. It doesn't work. So that's why this is that it, it all ties into the identity of the Open Claw AI bot that I've built. Shall we play a game? Random skill says, do you use blue light filtering? Either glasses or set your monitors to filter all blue light? Which is the best? Or has it worked best for you? So interestingly, these glasses are blue flight blue light blocking. I do wear prescription glasses now to read, but these are not prescription. Dude, you know, I don't know what's up with these blue light things. I, I don't wear these except for messing around as Jerry guy on Jawjacking. I haven't noticed any material improvements of wearing blue light blocking versus not so to me. I don't know. Maybe I'm just old and grizzled and like, But I don't know. I haven't, I haven't noticed any benefit from blue light blocking. Can you make a Grc Mafia shirt? Soul Shine? Sure. Soul Shine. Here you go. Done again. I'm terrible at like marketing, so, like, I don't tell people about the merch. I don't tell people about projects I'm working on. I forget to tell people about Simply Cyber Academy. This is my online school with all the courses to help you crush life. Like, I forget to tell people all the stuff all the time. I'm not great at business. I, I, I'm, I'm passionate about helping people and in cyber security. All right, here we go. Cyber Shimgami says ran those prompts from the video in chat. GPT Notebook. Gemini Claude thoughts on Career Span app. It was blowing my mind. Cool, dude. Thank you, Cyber Shin Andami. So Cyber Shin Andami did my video. Hold on one second. So again, if you haven't seen this yet, I released a video yesterday at 4:00pm that is taking The Internet by storm. Okay. I show you how to use Claude code and LinkedIn data to absolutely discover unbelievable hidden value in LinkedIn. Okay. So sick. Look at this. Look at this. I have told you guys before, personal branding. Personal branding adds value. You want to guess when I started doing personal branding? This is my LinkedIn profile. You'll notice this ridiculous hockey stick. That's me starting simply Cyber. All right, come on. Bruising hacks is excited. Nice. All right, continuing to look. Yes, Bruising hacks. I have tried turning it off and on again. Oh, Michael Fink with a deep cut. Urza's glasses. I actually used to run that when I was 14. All right. Real Bilbo is going to be there, I think, at Zero Trust World. Try Trini Heffy. Are we able to receive CPAs for watching on replay? Yeah, I don't see why not. I mean, if you watch. Here's my thing. The Daily Cyber Threat Brief is essentially an instructor led webinar. So if you watch it on replay as an instructor led webinar, why wouldn't it be valuable? Yep. Yep. Sean Washington, who's also in my one an upcoming YouTube video, which is pretty cool. Thank you, Jenny. Jawjacking question from Oscar. Is it smart to get into entry level? I t helped us to have a real shot at getting into cyber. Nowadays you can get into cyber without going through help desk. You can get into cyber by going through help desk. Having IT help desk experience certainly can help you. So I. I mean, is it smarter? I mean, that question has a lot of dependencies, right? I mean, what have you done before? Like, I was a software engineer, so I wasn't, you know, I didn't do help desk. I was developing software and then I got into cyber out of pure spite. If you. If you don't know the story, I was very spiteful because my code got audited by security and failed. And I was pissed. So I was going to prove them wrong. In reality, I found my. My passion for cyber. I don't know. I guess for this question, is it smarter to get an entry level IT help desk? I would say this. If you have an IT help desk job opportunity, take it. IT will. And then start migrating towards, like, either going higher up in IT or transitioning over to cyber. Let's see. All right, so Michael Fink has some source material, I mean, some statistical information around using blue light blocking and having benefits from it. So there you go. A lot of talk around the blue light blocking. Sasha M. Is it reasonable to have to pay for an internship or mentoring. No, absolutely not. That's absurd. The. To me, that is predatory. You should be paid for working an internship. That is predatory. All day, every day. That's vile, dude. Now I will say paying for mentoring, okay? If, if it's like a formal coach or you know, work like, like, if it's a formal coaching thing where it's very clear that this is time for money etc, then I can say that paying for that kind of mentoring is fine. You can get mentoring for free. You can get mentoring paid. Paying for an internship is absurd. Being able to pay so you can work on for someone, that. That makes me mad, man. So with the AI being so hot, is GRC the new in? I don't understand the question, but we will say GRC is hot. Little doubled shock here. All right, Jerry. Going viral. Thank you legrat. A lot of people commenting on blue lights and help desk stuff. Are many home office GRC work available? Sure, yeah, yeah. Home office or travel. Right? I mean Eduardo, when I was a GRC auditor, I would travel quite a bit to go to remote locations to audit them for, you know, whatever I was auditing them for. So, you know, you didn't have to go to a home office because you were traveling. Hey Jerry, how's that vulnerability management class coming? I talked about this last week. I have all the lectures recorded. I need to record the labs, which is difficult for me to find the time to do so. It's in progress still. Justin says I have four years of help desk and a dozen certs not even getting rejection letters. All right, so Justin, maybe take a look at your resume, see it, maybe get that adjusted a little bit. Maybe spec. Have your resume adjusted for the specific job or. Hey, even. Sorry, one second. Justin, check out this video here. I just. This is the video that I was talking about earlier that I just released. You might be able to use this video to kind of help mine some value out of your LinkedIn connections and network that can help you. Let's see. Continuing to look through chat right now. This is simply Cyber's jawjacking. So if you have a question, just put it in chat with a queue up up front and I will answer it. Looks like we are caught up right now. So any questions that come in the queue, I'm happy to answer. If you did ask a question and I didn't see it, write it again in chat with a queue up front and I will answer it. We're going to go to 9:30, so 15 more minutes with the GRC Master Class. Pair with a SEC plus portfolio and a cyber degree. Yeah. Oh, dude. Yeah. I mean that's like a freaking full boat right there. Also want to say really quickly, I got a really nice letter from a woman. Again, listen, really quickly, I cannot promise you a job, okay? Like, that's not how it works. I can't promise you a job. But what I can tell you is my GRC Analyst master class is definitely designed to be practical and get you the skills you need for a job. And several people in simply Cybers community have gotten jobs after taking the Analyst master class. But there's a whole bunch of like prior experience and other things I just want to say quick shout out and I'm going to play a wrecking ball for this one. This woman, Rachel Holmes right here, she emailed me and told me that the GRC Analyst master class was the pivotal thing that changed for her to allow her to get a job as a GRC person. She was in it for 10 years and now she's pivoting. So way to go, Rachel. All right, continuing to look through chat here. Thank you, Jenny. Do you think there's a possibility for the junior and entry level positions in cyber disappear because of AI and MSSP will require less people? No, I don't. So I mean, obviously every industry is going to be disrupted by AI, but one of the cool things about cyber is that your threat actors are typically doing things and using tools in a way that they're not designed, which requires humans to detect that anomalous behavior and be able to kind of identify false positives from true positives. So you're definitely going to need humans in the loop on that one. As far as entry level positions, I'd like to think that instead of being like Soc Analyst Tier 1, it's SOC Analyst Tier 1.5. This is a, this is a perspective from a woman at Cisco named Kirsty Payne, who I'm a big fan of. And essentially it's like AI enabled entry level analysts to be able to move faster, do better. So I think that's what's up. Where's the best place to start to crack into auditing? Are there particular industries? Okay, so hey, healthcare for sure, but goats since Yost, go look up cmmc. Charlie, Michael. Michael, Charlie, cmmc. Because a lot of businesses that do business with the US Federal government are going to have to be CMMC compliant. Getting into the CMMC ecosystem as an authorized auditor is total trash. Like it. It is a good old boy pay. You got a pay to play system. But. But you can get work as a readiness assessor. And the big fir, the big firms, Booz Allen, Deloitte, Accenture, Capgemini, even the smaller ones that are more focused on cyber work, like coal fire risk,360, things like that, they are going to be doing CMMC readiness assessments, which is basically audits for businesses before they go pay to get audited for CMMC compliance. This is where I would look. Get familiar with NIST Special Publication 800 171, get familiar with CMMC and what it requires and go find those jobs. I'm telling you, there's going to be a huge cottage industry around cmmc. Audit experience. Mike. Mickey. Mickey says I'm about to finish my bachelor's in cyber. I'm looking at a master's in cyber. Should I wait a few years and get experience? I'm transitioning from the Air Force. Yeah, I mean, honestly, Mickey, if it were me, okay, and this is not for everybody, okay, because your life has to support it. But like, if it were me, I would work full time and get the masters at the same time. Because I mean, think like, listen, again, I am not. Everybody's got their own journey, everybody's got their own thing. I got two masters and a PhD all while working full time. And during my second masters, we had it. We had our first child and during my PhD we had our second child. So I'm telling you right now, it is completely feasible to do these in parallel while working full time. That's what I would recommend. I. You know, honestly, Mickey, professional experience or not honestly, but like in being fully transparent, professional experience, practical, hands on experience, weighs very heavily. If you have a bachelor's and a master's in cyber and no experience, when you go to apply for a job, it's like, that's great, but. Right. So I'm thinking if I look at someone who's got no experience, but they got a bachelor's and a master's and someone who's got a bachelor's and then two years of professional experience, I might, I might lean on that bachelor's two years of experience candidate if the experience is directly related to the work that I need hired for. So there you go. All right. Continuing to look through chat. Thank you for dropping these in mod chat. It's easier for me to find any new hype for SC Con in November. Alternately, since it's the con of the week, anything you're excited for at0Trust World 26. So Justin Gold is helping with Simply Cybercon. Get it stood up. The CFPs the registration. Kimberly's on the, the website. So we, the big update is there's going to be a big, a big amount of information coming out in the next couple weeks, Ryan. Secondly, zero trust world. I'm hyped, honestly, to see all the folks and I'm trying to put together. I'm having dinner with James McQuiggin tomorrow night, which I'm super excited about and honestly, I'm looking forward to a little bit of a potentially informal, simply cyber community meetup Thursday night. So stay tuned for that. That's what I'm excited about. Obviously, you know, the conference is fun and learning a bunch of new stuff is fun, but hanging out with the community is always, you know, the best part. Real Billow says please post behind the scenes of AV setup at the con. Love seeing those. Yep, yeah, I will. I mean, honestly guys, yesterday I spent a bulk of my time just getting the audio pieces right because I need four microphones, four mic flags, four XLR cables, four headphones, one mixing board, all the, you know, all the wiring, the power supplies, all that stuff. And that was just the audio I haven't even done. I'm doing video today in software today, which is like. Do you think cover letters actually make a difference? No. Can you paste the URL for the SCCON 2025 Mercury? Yeah. Is Kimberly in chat? I don't see Kimberly in chat. Mods, can you help me? The merch for SC 2025 was on Cyber Security central. Kimberly did it through her, her, her, her, her site there. So if, if you can, um, if you can pull that up, please, Mods, we'll get it for you. All right, continuing to look really quickly. Did you forget to turn on the stream to LinkedIn today? No, I don't know. Did I? Says I'm streaming to LinkedIn right now. Oh, I don't know. Come on. It's weird. I'm looking right now. Roswell uk. Unfortunately, Restream failed. I guess that's wild. If we're. If, if, if I'm on LinkedIn right now and it's not live. Yeah, I guess it didn't. I don't know what to tell you. I mean, it says that it's enabled and everything, so I don't know what's up. Let's see. Continue to look through chat. I see Kyle, Kyle has a question. I'm just looking for it so I can bring it up on stream wearing two hats. Since we lost our physical security and access control person, any advice on dual wielding cyber and physical Security? Not really. I mean, physical does fall under the purview of cyber when you're doing audits and stuff like that. I mean, I mean, I guess you could. It's possible since you have the physical security realm now. You could feed in, swipe access logs into your sim, be able to look for weird stuff. Okay, no problem. All right, one second. Yeah, I mean, that's it. Obviously, you know, get, get to be friends with your data center people. Right? If you have a data center. Kyle, Kyle, be friends with them because you know, who, who's accessing the data center is super important. How often do they have physical security controls in place? Like just go look at the PE control family in NIST 853 and that'll give you a pretty solid starting point. Cyber Security Central. Kimberly can fix it. Non profit. Hold on, I'm trying to find. All right, hold on. Where's the merch? Oh my God. All right, hold on. Cyber Security Central Merch store. I mean, it shouldn't be hard this hard to find these things. Yeah, there is a. There is a way to get it, but Kimberly has it. I can't. I can't find it right now. See, it's 9:26. Continuing to look through chat. Was there an attendance certificate for SCCON last year? Yes, Michael. Kimberly sent an email out to everybody with a link. You would go in and download it. So connect with at. Kimberly can fix it on the Discord server. She should have a link for you. Actually, that's a good point. Spam musubi. Spam musubi. Go on the Discord server. If you go to Simply Cyber IO Discord and then ping at. Simply ping at. Kimberly can fix it. She's got the link for the merch. Yeah, I don't know why it's not on LinkedIn today, which is wild because we had 400 people, which we haven't had in a minute. Yeah, I mean, Roswell, uk. The thing is, once I go live, I can't like go live on LinkedIn. Like it's supposed to be like, literally if you look at. I mean, check this out. I know it's going to do like an infinity thing. But look at on LinkedIn right now. Do you see up here on the top? You see on the top right here where it says LinkedIn and YouTube? This is telling me that we are live on YouTube and LinkedIn right now. But when you do this, you see how it says streaming on YouTube but not on LinkedIn. However it is enabled. You see this toggle on so it's a restream issue. I don't, I don't know what it is, but I can't fix it, so. Sorry. All right, continuing to look at chat here. How's the thumb? Oh, yeah, thumb's pretty good. I. I can actually show it on stream now because it's not disgusting. So it's almost back to normal. The nail still looks all janky. So thank you for space tacos, for following that. Took about a month to heal. Let's see, 928. Any questions, I'm here for you, Roswell. I remember when the CC used to call her department Two hats, which I thought was reference to our ability to do multiple roles. Turned out they just didn't like us. All right. Oh, there you go, Kyle. Kyle found the 20 controls in the PE family. Yeah, don't sleep on this documentation. It is some good stuff, man. All right, So the question is, where is it? I don't see where that question is in chat, but like, basically, did I watch a YouTube video about how Israel became a cyber power and how USA pays for their learning? I don't know what YouTube video you're referring to, but Israel is. Israel is a super cyber power. You know, here's the thing. A lot of cyber security product comes out of Israel. It just, they don't, they don't come out and be like, oh, it's Israel. Like Palo Alto is Israeli based, right? I mean, XM Cyber, like there's a ton. Israel's got like, dude, here's the crazy. Not crazy, but here's an interesting thing. Like when a security product comes out, if it's Israeli based, it automatically gets treated like, okay, like this is super legit because they have a track record of making them incredible software. Like, you know, say what you want. I, I don't like that it's been weaponized. But Pegasus Spyware is Israeli based technology for the new video. Aren't you concerned about uploading your entire data archive to Claude? No, I'm not. I mean, first of all, it's like locally on my system, so it is, it is taking some information and pushing it up to Claude. But it's my LinkedIn data. I don't care. Link. LinkedIn already has my data. Microsoft owns LinkedIn. I'm sure Microsoft took all that data and shoved it into Copilot. So, like, no, I, I'm not super concerned about it. Good question though. Kathy Chambers is in the house. Okay. Soul Shine, I don't think you can. Oh, I don't think you can drop links in YouTube chat because we're. It's a control we have in place to prevent people from putting malicious links in the. In the chat. All right, guys, it is time. It's 9:30. Thus completes jawjacking, your Simply Cyber bonus content. We'll be back tomorrow at 8:00am Eastern Time to do it all again live from Simply Cyber, Buffer Osier Flow Studios. But for now, we're gonna put a pin in it. Go check out that YouTube video. I'm super proud of it. I think it's very helpful. If you think it's helpful, share it with your. Your network. Share with your friends. I'm telling you, there's mad value in this video, 100%. And I. I actually show you step by step how to walk through and run it. Like, how to build it, how to run it, all those things. Okay. It does take 24 hours to get the LinkedIn data archive. So go. Go request it today. All right, I'm Jerry from Simply Cyber. Peace out, Boy Scout. Until next time, stay secure.