
Loading summary
A
I am on an ISIS kill list. Not because of being a security person or anything else in my background, but because of a data breach. Years and years ago I was placed on one of those ISIS kill list.
B
Welcome to the ThinkAI podcast. Each week we talk about the most exciting AI research tools, case studies and more. I'm your host, Dev Goyer and I've been working behind the scene in data and AI for over 30 years. Whether you are an AI expert, skeptic or something in between, this podcast is for you. Today I'm sitting down with Tom Kirkham. Tom is the founder and CEO of Kirkham Iron Tech, a cybersecurity firm that has been defeating organizations security issues for 25 years. He is recognized as a top 250 managed security provider in the world for four years running. He's also a two time Amazon Best selling author of Hack and Rich the Cyber Pandemic Survival Guide and a frequent keynote speaker. Tom, welcome to the show now.
A
It's good to be here.
B
Dave, anything you want to add before I get started with it?
A
Oh, well, I think you, you covered the high point. The only other thing about my bio that some people find interesting is that I'm on an ISIS kill list because of a data breach. Not because of being a security person and or anything else in my background, but because of a data breach. Years and years ago I was placed on one of those ISIS kill list you remember about let's say. Well, it's been 11 years ago, so there was a bunch of kill lists that came out and I was on one of those. So only reason I want to mention that is because majority of small to medium sized businesses, they don't realize, you know, they think that, that it can happen to me. I've got a small law firm practice in the middle of nowhere and I do family law. Why does a hacker want to attack me? And that's not what's happening for the past many, many years. And something as simple as just being on the wrong database, you never know. Not only can you have your identity stolen, but it actually has caused life or death issues. And so consequently that made me a lot more passionate about it than what I was even before.
B
That's very amazing and that's why I gave you a chance because I would have butchered what you just said. And it's an interesting profile to begin with and I have just a minute tiny similarity there. Not that, but I used to be a white hat hacker in my past and that was a fun job and we used to run into a lot of these things, but yours is much better and interesting. So let's, let's get on with it.
A
You know, you get into that, I'm working on a Hollywood project, a TV series right now where you get into that. You know, White Hat, Black Hat, Gray Hat. So the name of the series is the Last Gray Hat. And so Gray Hat hackers, for those of you that don't know, gray hat hackers kind of live in this, this gray area. They have a moral compass, so to speak. And they are commonly the hacktivist like Anonymous. Everyone's heard of Anonymous. I would consider Anonymous a gray hat hacking organization. So the black hat guys are the ones that do it mostly for money, but it can be, you know, nation state like China and the United States and Russia and all of this. But most of the black hat guys are strictly in it for the money.
B
Yep, that's very true and thanks for explaining it to our audience. They are generally focused on AI, but they do not focus on the threats that AI is bringing, which is where we going to get into a little more details. And that prompts me to the first question, which is what is the single AI powered threat that you see every day in your work? Which is what's the most common threat is what I'm trying to ask.
A
Yeah, it's the use of artificial intelligence to develop highly targeted phishing emails and other vectors is what we call it in our business. It's a vector of the, the hack. But commonly it's emails and what they can do is they can establish in your organization relationships. So like who's your immediate, who's your CEO, who's your boss, who's the president, who's the owner, who's, you know, depending on what department you're in, AI can just go out and harvest LinkedIn data for the company. And so now instead of getting a generic email, it can very easily appear like it's from your immediate report. And then on top of it, what most people don't realize is this is a high volume game. Right. It's not, you know, you shouldn't be asking yourself why would anybody want to attack me? Well, you're just in a database. They don't really care who you are. They, most of them don't know who you are. They don't care who you are. They're just trying to mostly extract money from you. So a imagine if they had, you know, all of the attorneys that are registered with the Texas Bar association, okay, they got all the members of the Texas Bar and let's say it's 100,000 attorneys. I don't know how many it is, but let's, I know the math for this, it may even be more, but 100,000 is probably not too far off. So they've got this list. Well, they develop a phishing email either to get you to open a file attachment or who knows what the actual scam is. But very commonly it's to open a file attachment. And now with artificial intelligence, instead of that email coming from a generic vendor to the law business, it may look like it's coming from the managing partner or whoever your direct report is. And they can make it much more personal. And they're personalizing each one of those emails for those hundred thousand people. Now in the past, as little as five years ago, that wasn't possible. I've been personally and the company's been targeted. If they can get to our company, they got keys to allot kingdoms, right? So obviously they were willing to commit time, money, human capital to breaching either me or the company. And they wouldn't do that for a list of 100,000 people. Well now with AI, they can make those emails much more targeted and much more likely to convert. So they think in terms of marketing, right? So how good is my email marketing going to convert? How well are ads on Google going to convert? So once again, they don't really care where you are, who you are, they're just looking for a payday. Now with AI, they can also go out and look and see how big your law firm is and then customize the ransomware demand. So let's say they're deploying ransomware and automatically on the fly. If you're a three person law firm, it may ask for a ransom of $5,000, you know, to unencrypt your files. That's the way ransomware works, right? It just goes in and encrypts it and then you got to pay a ransom to get your data back. But if your law firm has 50 attorneys, well then it may ask for 50,000 or I would ask for more than that. I'd probably ask for 200,000 on a 50 person law firm or maybe even a half a million. And those, all of those things are done at scale, high volume. And so let's say they collect an average of $10,000 per victim and only 1% of those hundred thousand become victims. Your conversion rate was 1%. An average ransom collected of $10,000 is a $10 million payday for about a week's worth of Work, take another, take a week off, go to the beach and then come back and do it again.
B
We are all in the wrong business, I suppose.
A
Yeah, well, there's a price to be paid for crime, right?
B
Of course, of course.
A
That's what separates the white hats from the black hats. Right? You know how to do all of these things. It's like any good attorney knows how to bribe a jury, but you know, you don't do it. But it's not personal. You can't think of it like that. You know, even some of the big hacks like Colonial Pipeline disrupted distribution on the east coast for weeks. And it was a four and a half million dollar ransomware attack. The hackers didn't know what the company did. They had no idea. And when it hit the news, you know, when it's all over CNN and hitting the global news networks that the eastern seaboard can't get gasoline to the stations, they all of a sudden communicated, said, oh, we're sorry, we didn't mean to shut you guys down. Still want our four and a half million dollars, but these guys don't want to. It's especially profitable to go after the smaller businesses, the ones that they're not going to show up on CNN because that increases the likelihood they're going to get, somehow get caught.
B
And yeah, it's a scare and collect technique, I suppose, because they're not going to hire lawyers, they're not going to hire attorneys, they're not going to do a lot of things. They'll be scared for their life, business and their family and they'll just give in to it, I suppose.
A
Well, it's a business decision. Some people are like, don't pay the ransom no matter what. And I'm a little more practical. Well, first of all, before I even get into this discussion, it's a whole lot cheaper to prevent it from happening in the first place because if you don't do anything, it's going to happen. It may happen, it will happen eventually. And if you've got the right technical and the right culture and the right other protections, chances are it won't affect you. It'll be caught and mitigated and remediated if necessary. And because you've done what you should be doing as a CEO, being responsible to the organization and all your other stakeholders. But whether you pay the ransom or not, that's way too personal. You know, if you ask the FBI, never pay the ransom. But just like kidnapping, you never know. That's a very personal decision. In spite of sanctions Many of these hackers are under sanctions and it's a felony to pay them. But I have yet to see any kind of charges brought up on somebody that paid a ransom for their data. I just think that would be foolish.
B
Yeah, I have a parallel story. You know, back in my days when I was a white hat hacker, we were only looking at, you know, the algorithms for cell phone as an example for encryption, A5, A8. And our job working with our scientists to make sure that, you know, it has a life expectancy based on how long this algorithm can last. And that's what we used to do, simpler things, right. Nowadays, you know, and we've been getting these spams and phishing emails for a long time now, but the signal to noise ratio is getting worse. I talked to a lot of security security vendors and every week there is a new tool. And so there are more styles and types of phishing things. But then there are a lot of lot more tools also. And those tools are buggy. So now how do you really make a decision between the tool and the different ways people are phishing? A good example, somebody called my mom in India in my own voice because they can get my videos and audios from anywhere and they can just train. Hey Jen. And you know, there are so many other technologies where you can train them and they can speak as if it is you. And how do you not really differentiate? So my mom knows better, came from old school. She says he's not going to ask money just like that. So I will talk to him and pay whatever he's needed. And the guy says he's in big trouble. He says that's okay, I will talk to him. And then that was the end of the story. But interesting, very scary story there.
A
Yeah, you kind of touched on this. People seem to think that the solution is technical, right. And that they need better firewalls and all of these. And I'm not saying you don't need all of the technical, you know, the firewalls and all these other things, but what most people don't understand is well over 90% of successful breaches are because of human failure. In other words, they got conned. It's just a scam. It's similar to con jobs from the 60s or 600 years ago. It's a con job. The difference is instead of it being a one to one con job on the street or whatever, you know, the fax cons, the Nigerian 419, you know, in the fax days, but now it's a million to one. Or 10 million to one. And that's what I mean by these hacks are generally done at scale and they're very high volume. And that's why no one is immune to these. And so if you understand that over 90% are the result of human failure, the very first thing you've got to do is to make security job one. That's got to be part of your culture. It's not a hassle, it's just what you have to do. It's kind of like I'm old enough to remember when the government forced everybody to wear seatbelts. And I know it seems ridiculous now, but, oh, it's a freedom thing and you know, all the other arguments around it. But now what, what happens? You just get in your car and you put the seatbelt on. You don't even think about it. And if your company or any organization is not baking it into the culture and you're complaining about password complex requirements and skipping things like sharing credentials because you don't really take it serious, you're weakening your own posture and defense against these attacks. And it's just not adequate anymore. And I would go so far as to say it's irresponsible for anybody in a leadership or management position, anybody in the company for that matter.
B
True. It's as if leaving a password on a small note and leaving it in a marketplace so that anybody can pick. And not that they also know your home address. So it's not the password, but who you are, what you do, how you do it, so that it's just something on a platter to come and steal it, I suppose.
A
Yeah, yeah. But we do a number of things. You know, we do multi factor authentication for support calls. I can't remember how it exactly works, but it's something similar to where if they initiate the call, then we ask them for a code and I think we may push it out to their phone and so they give us the code and vice versa. They can do it to us, you know, if we initiate a support call out. So that helps on the voice cloning scams. And it also protects them, you know, protects us if it's somebody impersonating an employee. And it protects them from just somebody calling up and saying, hey, this is Kirkham Irontech support and it's not us. Right. And our clients are. Fortunately, they're smart enough and they're bright enough to understand these things aren't hassles. It's just what we have to do today to protect everybody.
B
Yeah. And you know, one of the question I was meaning to ask. And we are already there, so I want to share a story and get your opinions to it too. So we had a manufacturing client where an account payable person stopped a wire transfer because the request felt off. Now they do this kind of large transaction. So no security tool that they have detected it. And one person's instinct saved over $2 million. It's like five years ago. And obviously the tools and technologies have changed and a lot more threads. And the email was completely spoofed. It looks as if it came from that company, from that person. Everything was matching. I don't know whether their information got stolen or whatever the case may be, but you know, it was just his gut feeling, like he had certain things in his mind and he just checked on it. So back to your human story. In this era, how a human can help when AI can spoof in so many ways, what would be just basic three to five principles. You would give it to them like do this so that you can at least catch something, maybe 90% or 95% of those, not 100% maybe.
A
Right? Okay, what's the low hanging fruit? And what we're talking about is gaps that exist in your current security posture and the lack of governance thereof. Right? So the very first thing we address is what's the most likely vector? Well, it's going to be a con job, right? It's going to be human. And it doesn't matter what your industry is, that's the number one thing that's going to fail. So what we know this isn't Tom Kirkham making up numbers or anything. The research tells us that if you do nothing but implement continuous cybersecurity awareness training, that cuts your risk in half. Right? Then, okay, that'll cut it right in half. Then the next thing is you've got to quit using these consumer grade Internet protection suite things or antivirus. Anything you can buy at Office Depot or Best Buy is not good enough. There's a whole different class of products out there that yeah, it does cost more, but it's not outrageously expensive. Anybody listening to this that has a business, you can afford this Department of Defense level protection. And it's a class of products called edr. It stands for Endpoint Detect and Response. And even better, it needs to be managed edr. And it goes by a bunch of different names. Which leads me to the other deal. Like you need to engage a professional to do an assessment of what all your gaps are. But you've got to have that EDR Like a common brand names that some of your audience may have heard of is CrowdStrike. And we're a Sentinel One partner. But either one of those I consider best of breed. Right. You want to make sure you're using best of breed tools and both of those. We think Sentinel One is the best. We have never had a breach of any significance since we implemented Sentinel One and it's required for our clients. You can't be a client of ours if you don't get Sentinel One and other things. I think awareness training is required now. Multi factors required. That's another thing. You should always have more than just username and password. So you want to implement multi factor authentication. It's that third piece of data that only you would have access to. And typically it's got a time limitation on, you know, that six digit number. Is it good for 30 seconds or five minutes or whatever. There's no way, if somebody compromises your credentials, they still don't have that third piece of information. Right. But yeah. And then once you get past those three things that I mentioned, awareness training, EDR and mfa, it's really more that you need to bring in the professionals. This is not do it yourself anymore. I mean, if it ever was, but it's certainly not today. People said, oh my gosh, we're putting in the same stuff that the Department of Defense uses. Yeah. And you know how I was talking about earlier that the bad guys do things at scale? Well, we do things at scale and our vendors do things at scale. And 15 years ago, this was expensive. Only Fortune 1000 companies could afford this technology. And this technology uses artificial intelligence and has for years and years. You can afford it and it's the only way to defend against modern ransomware attacks. It's a different technology and I don't want to get too far in the weeds on this, but it looks what we call the storyline in the industry. So basically a storyline is what's the attack vector, what's the method of deployment, what's the result? And EDRs, good ones, monitor storylines. It's monitoring what the user on the computer is doing and what the computer itself is doing. So it doesn't need a virus signature to know something's wrong. It knows the storyline of that attack and it stops it before anything bad happens. Yeah, that's what you're going to get whenever you engage with a professional. And I want to talk about that a little bit more too. We do a lot of IT work in addition to the security stuff, but there's a Lot of specialties in this industry. You were once a white hat hacker. Well, we've already talked about black hat and gray hat. And there's people that do incident responses, their specialty. That's not us. We do incident response for our clients. But if you're under attack and you're not a client, we're not going to take it because we don't know the network. You know, we certainly do a great job on the ones that we protect and we do know the network so we can do it. But there's so many different specialties in this industry that especially between IT specialists and cybersecurity and the good IT people, they know their limitations and what's in their wheelhouse. And cybersecurity is a specialty in and of itself. And if you're part of a larger company, you know, a medium sized company or an enterprise level, cybersecurity and IT have two completely different reasons for existing and they are typically at odds with each other when it, especially when it comes down to money and risk. So that gets into governance issues and, and as a leader, understanding what your risk is and not relying on your finance. First of all, if you've got your chief financial officer over it, your org chart's messed up. That is, you do not do that. And I don't care if you've been successful doing that in the past. It is a huge, huge mistake if you don't treat it as an investment. And if you don't treat security seriously, saving that money is going to cost you your business or at least something very, very bad, including earnings and company valuation. You know, it exists to increase productivity, increase earnings, EBITDA and all of these increase shareholder value. And so that gets into basically using technology to reduce friction. And security is about protecting all your data, your vendor's data, your customer's data and your company's data from a possibly catastrophic event. 40 to 60% of businesses that suffer a serious breach are out of business within two years. That's a fact. That's what the research says. It said that for years and it hasn't changed. And if you're not having these C levels discussions and board discussions around IT and cybersecurity, well, you're not truly looking at all of the systems. And I see it. I've been working with companies of all sizes, everything from Fortune 10 companies to mom and pop law firms and accounting firms and things like that. And IT and cybersecurity is delegated and it's treated as its own little thing. And you hope that you've hired the right people for it, whether it's outsourced in house or combination. But you don't do that with finance. As a CEO, you may have a cfo, but if you're CEO and you're not looking at the financials at least once or twice a month, how do you talk to the board? Well, you need to treat it that CIO or even better, a chief Information Security officer needs to have a direct line of communication to you as the CEO. And touching on that, your security officer should be in charge of it, not the other way around. You don't want to plug better security into it. You need to flip that on its head. You need to plug it back into security and make security job one. And these are a lot of discussions that we have with small businesses and medium sized businesses that. And the reason I'm on your show is about educating around governance and treating it serious, you know, and building those policies and procedures and best practices around making your company more profitable, more valuable and secure.
B
This is an amazing discussion. Just to make that point, I want to pick back on the IT versus security groups and in my past I'll share a quick story, but I want to double down on the CFO part that hit me hard. Which is CFO always looks at whether it's a profit center or a cost center, it's a profit. I did CFA back in my life, so I understand their mindset. But then that mindset also needs to look from opportunity cost, risk assessment and things of that nature, which unfortunately they are also not trained for that. Right. So they are trained for really making the company's top line or the bottom line. Good top line growing through and bottom line keeping consistent and going lower in terms of expenses and then, you know, getting better. EBITDA here the risk is you can lose the whole business. So that's the opportunity cost. If they are not paying attention to these, not learning through what's happening again because of AI, because of the explosion of data which is fed to AI, which is going in the benefit of these intruders. How do you really like you and I because of your business? And then I do it for my clients as well. We pay a lot more attention to what's going on. And every day the threats are changing and that they need to pay attention to. So they cannot be just unaware of what's going on and just take as one cost element and say, hey security, we'll just put let's say $10,000, $5,000 or $1,000 and that's it. It's not about the budget, it's the amount of risk you are taking and what is your willing to bet which is your business, maybe in this particular case. So I admire and appreciate your point. I want to go back to IT versus security. So back in my life without naming names, I worked with a large healthcare organization, really large Fortune 50, and they introduced the CISO role back then. And the problem with because I was working with it and MIS is what is being named back then or information management. We were resisting. When I say we, the whole group from it was resisting. And the reason being the security officer wore the hat of security. But then they went into compliance, which is also a big animal by itself, especially in healthcare business. But how do you train your clients on differentiating between it and security and why security has a higher value in terms of securing your business, saving your business. What's your take on that?
A
Well, because it is all about increasing productivity and security is all about secure the company no matter what. Now we live in a real world and we've got all of these wonderful policies and we've got these state of the art tools, best of breed all over, but there's not a single client that uses everything we have. We don't even use everything we have. And the reason for that often is because when you look at the risk, and it's not always the expense either, but when you look at the risk, it introduces so much friction that the risk is so low that it's not worthwhile to implement that procedure. But because we understand the threat actors, we understand the client profile and there's a lot of difference in client risk levels between say a patent law office or intellectual property law office versus personal injury. Now they both, well, personal injury's got HIPAA and you know, like you were alluding to, they got HIPAA requirements and other compliance with insurance and things like that. But generally speaking, they're only going to be targeted by the criminals. But patent attorneys have to worry about countries like China stealing their intellectual property, you know, their patents that they filed on behalf of their clients. So you got to understand all of that. But the long story short is we have to understand the risk, who's attacking us, have a really good idea of all the different vectors and other ways to pull off the attack and then balance the protecting of those things against the friction of implementing them. Okay. Now generally the human thing is pretty easy. You're going to use mfa, we're going to have these complexity requirements and you're going to Use a password manager. And that's going to lower it down. But you're going to do those things. You're going to get over the fact that you can't use the same password every time. And we try to minimize the friction we introduce in that. But it doesn't mean that that discussion is not open. Tesla, as a car company, they value everything that goes into manufacturing their cars around what they call battery bug bucks. Okay, so many years ago they had a vendor come to them and say, hey, we've got these wheel bearings that cost twice as much than what you're paying right now, but it reduces the friction. Well, if that same vendor had approached Ford or General Motors, the drivetrain people would go, well, that's efficiency, that's the engine. Guys, that's not in our wheelhouse. I don't care. We want the cheaper bearings. Tesla, the whole thing is holistic. They're looking at the car, the efficiency and getting the maximum range or saving the most money on the battery pack because that's the most expensive part of the car. Just by switching to the new wheel bearing, they got another 15 miles of range. And what a lot of people don't realize is that the first car, first Tesla that they made themselves, the Model S in 2012, I think had 265 miles of range on the one with the biggest battery and the, you know, the, the best one you could get. Well, today that Same car has 410 miles of range and the battery did get a little bit bigger, but not nearly that extra hundred and something miles it was through looking at every single thing they could do to either save battery bucks and increase efficiency and reduce friction. Literally reducing friction gave them that car another 15 miles of range. And so there's a trade off in all of this stuff. And the secret is to make sure as a CEO that you understand what the risk remain.
B
Right.
A
And if you don't have a direct line of communications to the security officer or to just security, then you don't know what the risk is. And if you're in a size of a company that if you have a major security breach, say you live in a town that's got a big school system or hospital system or something like that, is the TV station or CNN going to go to your IT director or your security officer to ask them what went wrong? No, they're going to go to the owner, the CEO. What do you mean you don't know? How do you not know this? It gets back to not compartmentalizing it and security because that's not your specialty. Well, your specialty may not be understanding financials, but I'll bet you understand it. I'll bet you understand sales and marketing. The industry and people still, they put it and security in this nerd category that they still struggle with not understanding that it's an integral part of their company. And I know it's not as bad as it was, but it's still happening way too much out there, especially the smaller organizations, even mid sized organizations. But the bottom line is it is balancing the friction against the risk. Right. And you do that in everything. Insurance, the whole, that's what you do in your life.
B
Right.
A
And I like to think that we've got a good handle on it. Our clients are informed, you know, and so they, yeah, I get the risk, you know, we're not going to get attacked by China because we don't really have anything China wants. So we don't need to protect to
B
that, you know, so that makes sense. And I like where this conversation is heading. So we did talk about security, risk and leadership. One more angle. And I think you wrote an article, I think the name of the article was Leaders face Major Ethical Questions on AI. And I really want to touch upon AI and ethical question because there are like some hazy lines there and leaders are getting mostly wrong on it. What's your thinking, why you wrote that article? What do you think about AI, ethics and leadership in terms of security context?
A
Well, first of all, you've got to address it.
B
Okay?
A
And I don't care what kind of business you're in, you've got to wrap policies, procedures and governance around artificial intelligence. You've got to understand how the vendor is going to use the data because you don't want to have everybody just implementing their own. And if you haven't thought about this as a leader, people in your organization are implementing AI. We call it shadow AI. And you've got to get ahead of it. You've got to vet your vendors, you've got to have policies and procedures around the use of AI and what you're going to use and everything that you're not. And what is the limitations, if any, on what you use it for. So we first implemented it around sales and marketing, messaging. So our firewall with our clients is once you become a client, we don't talk about who our clients are, we don't name them. You go to our website or anything like that, you'll see testimonials, but we won't name the client. Now up until they become a Client, the prospecting side of it, we do gather intelligence using AI and see who is looking for our services and products. And then we analyze them. Okay, are they a good fit? Are they in the right industries? Can we truly help them? And on and on and on. You know, the qualification part of it, if you're not thinking about any of those things, there's people in your company that's using AI and you don't know why, how and what kind of data they're shoving into it. And I don't want to get on a soapbox here, but privacy is security. So the reason we don't name our clients and people can't talk about it, you know, when they're outside of work, they, they, well, they can't tell anybody who our clients are, not even other clients. And it's okay if clients do it, but we can't discuss it. Well, that protects their privacy. It protects us. It protects them so because they may have a different risk profile than we do and they can use us as a vector or use them as a vector to come into us. But if you buy into that concept that privacy equals security, then you have no choice but to apply that same principle to the use of artificial intelligence and start wrapping that up into governance. There's no doubt you can't be a Luddite and just say, well, we're not going to use artificial intelligence. Well, I can tell you it's a huge productivity boost for many, many things, all sorts of things, workflows and you know, it would help you discover frict in your company.
B
Right, yeah. In fact, that does prompt me a question I was meaning to ask and I think it's the right time, so I'm kind of interjecting there. Sorry about that. I see two kinds of clients in AI. So I've been doing AI since 1994, 95, 96 and back then for algorithms and other things. But now for a lot of other reasons, I see two buckets. So one set of clients who treat AI as a tool of two argument, human judgment, and then the other ones who treat it as a replacement for thinking. And that group scares me. While I'm a huge AI enthusiast, I don't want to replace my thinking with AI. What's your perspective in your line of business and the type of clients you talk to?
A
That's a great question. And I think it's more of an evolution of the user and learning how AI can benefit. Or at least it was for me, and I hope it is for everybody in our Companies. I hope it is for everyone. This is how I think it should be. I think that when you first get into it, it's about the time saving, but really and truly it's about clarifying your thoughts or connecting the dots in your brain processing ability. But at the end of the day, it's just another tool in the toolbox. Right. I have a friend that is a professional writer and he is all in on AI and he goes, it helps you flesh out things and discover bottlenecks and friction and maybe more markets. And it's more of a brainstorming tool that takes sometimes what would be two or three hours of manual data gathering and organizing and strips it down into two minutes. But at the end of the day, that's what you saved. It's how you apply the results of AI is where you're going to see the multitudes of your gains. And that is one of the things you want to wrap into the governance. I think, from a leadership perspective. You know, a friend of mine calls it the last mile. I call it the 90%. It gets you 90% there because I do a lot of marketing with my uses of it and, you know, presentation development and things like that. And for me it's more about connecting these disparate thoughts and how best to make the presentation have more impact and how better to word things and say things. But at the end of the day, number one, it's my output. You know, I'm going to tweak a script for a presentation, it's still going to be my voice, it's going to be my thoughts. But AI helped me get there. It's that final mile or final 10% that really produces the report or the presentation to a client and things like that. And I think that the people, the individuals and the companies that treat it like that are the ones that are going to get the maximum benefit from it. I don't know if I answered your question, but that's, that's kind of what it is for me. I haven't been doing it nearly as long as you have, except from the EDR perspective. But actually using it, it's only been three years. Yeah, yeah.
B
Your perspectives are amazing. And I think that does answer my question back to what I was asking. I do want to switch gear back to cybersecurity and we did talk a whole lot on leadership, security, AI and ethics. And now this time how AI needs to be taken by different CXOs or leaders. But let's, you know, I'm very good on strategy and A lot of times I miss basic execution. My business partner says so too. So I generally go into those things. So what if you have to give one actionable item in terms of cyber security recommendation to the CEO watching right now? What should he be doing this week and what would that be?
A
Well, if he doesn't have someone on staff that's a true cybersecurity expert and they've never done an assessment, that's the very first thing you've got to do. I iterated, you know, you got to implement continuous training, get an EDR multifactor authentication. But if you've never had an assessment to really get down into the weeds of your business and understanding what your gaps are, and I want to add the productivity gaps in it, and you haven't analyzed that, especially with a third party independent. Even your staff, if you have IT people or security people, if you haven't had that analysis done, independent. That's the first thing you need to do regardless. And you've got to quit. If you've outsourced that or hired people to do that and then you ignore it, then you need to look within. You need to really look within. Because I know you're looking at sales figures and I know you're looking at finance and I know you're looking at the production runs if you're a manufacturer and other or other OP KPIs, you're looking at all the dashboards out there, but you're ignoring the IT and cybersecurity. Do you know how many threats were responded to in the last month? Was it one? Was it a thousand? If you don't know that, you need to start thinking yourself about. You've got a blind spot and it's costing your company a lot of money. And I don't want to beat a dead horse on this, but I still see in many companies that it is put in a box and set on the side. And then even worse, finance is running it. But really and truly, it shouldn't be run by anybody. It should. They should be a direct report to the CEO. And like I said earlier, security needs that direct path of communication to the CEO. And if your company is set up in any other way, you're making a big mistake. And someday you're going to have to answer to the board or the local television station or the New York Times for why something broke in those two different areas because you didn't know. You got to get clarity and understand it.
B
That makes total sense. I think the approach of fake it till you make it will not work on security. And if you have not thought of security as an overall department and a strategy in your organization. So starting with strategy, that would start from assessment to strategy to a plan of action to measure how and what is happening and make corrective actions. If you don't have that whole thing in place, I think you are bound to be doomed sometime now or in near future.
A
Yeah, yeah. Well, it's like that. You know, I've got my specialties and superpowers, but I'm not going to pretend that I'm the best person to run the support department or operations or marketing, but I know what's going on and that I do. The way our incident response plan works is if we or a client, we have a response plan. Right. And if you can't explain this and you've already got a problem, but the way ours works is when it, when it's an actual response and it's being actively investigated, then it elevates to me. And the very first thing I ask is what was the threat vector and who do we think the threat actor is and what's the status of mitigation? And so if you don't even have an escalation level for those things, then you can't answer that question of how many threats do you. Your department stop last month.
B
True. A decent sized organization makes like a disaster recovery plan. Essentially. What you're saying is if you have a disaster recovery plan, consider this as one of the biggest threat in terms of your disaster. Not like I live in California, so earthquake. Right. But just like an earthquake, this is also something that will come on to you and you do need to have a plan in place. Otherwise, you know, just like your building will be on fire, you will be on fire in terms of your business.
A
Well, that's all about business continuity as well. Right. That's another thing. If you do have a serious breach, well, how are you still going to run the business? That's in our wheelhouse too, but it's also in ops and it's in finance and all of those. So the takeaway from my soapbox that I was standing on there was you got to really look at everything and you've got to have a high level understanding so you can take it to your shareholders, you can take it to the board and you've got those answers in case the worst case scenario happens. Regardless of whether it's a natural disaster or it's a major cyber attack or whoever knows what, you're informed, you're planted and grounded and that will give you the path forward. You know, the obstacle is the way ultimately. And the more you understand the condition of your ship as the captain, the better chances of success on your voyage.
B
True. And, you know, just mentioned cyber, and I want to go back to what I said in the intro, the cyber pandemic survival guide that you wrote. Do you still believe a widespread cyber pandemic is coming, or we are already living, which we don't know today, or we are in the early stages?
A
That's a great question. And, you know, the answer may be as simple as it's already happened. Like you said, it's troubling. Right. I think that a major one is still coming and mainly from a military perspective. You know, it's kind of the Wild west of military attacks. There's no Geneva Convention around cyber warfare. And I think that it's yet to come to where a major skirmish breaks out and one nation actually uses these tools to shut down another nation. And actually that has already happened. That happened between Russia and Ukraine.
B
They.
A
And a lot of people don't know this because we were busy with, you know, the tweet of the minute here back in. I forgot what year it was, but it's been, say 10 is before all the kinetic warfare that's happening right now between Russia and Ukraine. And Russia, they shut down so much stuff through cyber attacks that they didn't know if their planes were going to fly. They didn't know if the trains were going to run. You didn't know if there was going to be food in the grocery store. They went all out, cyber war on Ukraine, and they stopped just short of killing people in the wintertime. And a lot of people think it was just a test run to see how far they could take it. And of course, United States would be the biggest attack for that. But this kind of stuff is going on all the time right now, and it doesn't even make the news. But it's not to that extent. It's not all out cyber war. You know, I'm sure Iran and United States are doing things right now to each other on the cyber front. Well, what. We don't even care, right, that average Joe is wondering how many missiles and this, that and the other. Well, that's kinetic warfare. Cyber warfare is. It's hidden and nobody's dying from it. Well, people have died from it.
B
At least we don't see them in front in the news on a daily basis is what you're saying.
A
Right, Right. But if you shut down enough hospitals, you Go out and attack all the robotic surgical equipment that's around the world. You can kill a lot of people in a very short period of time. Not to mention tinkering with nuclear reactors and shutting off the electrical grid, tinkering with water supplies. And the way I think of that book is I think it has yet to happen. But if you ask Ukraine, it's already happened to them. Their seminal event in the modern history of that country, it was called Not Petya. Petya? Yeah. At first they thought it was a normal ransomware attack called Petya. I believe I have that right. And then, then they found out it wasn't and so it's not Petya. So to Ukraine there was kind of like the United States pre 9 11, post 9 11. In Ukraine it's pre not Petya and post not Petya. So they know, they know what it feels like. And I think that Western world, if I were to be so bold as to not include Ukraine with western, but they really think more like Western Europeans, but that was their seminal event and I think it has yet to happen to us.
B
Yeah, very true. And you know, I think about this a lot. We're now bringing back to the perspective on the small and mid sized business owners. One of the things we all end up paying and we really cry about it, is high insurance premiums. So cybersecurity, we work with a lot of, of public sector government organizations as well. So very high insurance premium. We pay on cyber security, we happily pay, but it's a big pain. What's your take on that? So there is a human aspect you talked about, there is a technology aspect, but now there is a safeguard aspect like the insurance. What do you think about that?
A
Well, I think if you have to pick between better protection or insurance, I would do better protection first. And now fortunately in the cyber insurance world they have compliance. If they write you a policy, there's, you've got to have this and this and this, or they won't even write it. Two or three years ago, or at least the last time I had some research on this, it was something like 40% of cyber insurance claims weren't being paid because what they thought was covered, they weren't in compliance and they didn't have their security expert, whether it's a company like us or on staff, they didn't go through to make sure that on the application they had all the things that they said they didn't. And then there's other reasons why they don't pay. But I think it's a Necessary evil. The insurance companies that have really good compliance and really good applications are going to do an audit. And those premiums usually are cheaper. Now our clients, we have, it's not our policy and we don't make anything off of it. But there's a division of Lloyd's of London that says, oh, if you're a Kirkham Irontech client, you can buy our insurance without any questions asked. So we kind of pre qualify our clients for this particular insurance policy. So I want it, but you better make damn sure you're in compliance to being paid.
B
Yeah. And like you said, read the fine print, see what you are covered and not covered. So you know better. Also, don't take it as a blanket policy. Just like, you know, you take a home insurance policy here in California if you are, most of the time you are not covered on the earthquake. And what they cover is very bare minimum. So you have to figure out on your own what you're going to do when the major earthquake event happens, which did happen, like a fire happened and now most insurance companies are crying about it and they're suing Edison and some of the other issues are happening. Same thing you have to pay attention to cybersecurity, I believe is what you're saying in terms of insurance, like protect yourself first, then see what you're covered. Are you okay to pay that kind of money to cover to get an additional coverage for the things that you're not protecting? Probably using your own tools, right?
A
Yeah. And what price do you put on the success of your company? Right. You know, I mean the numbers tell us 40 to 60% are going to go out of business in a couple of years after attack. So you can't forget that. So yeah, it's a risk deal, you know, so.
B
So I want to change gears because we talked a lot about risk, a lot of dark issues that we talked about and we both have that kind of mindset. So let me bring it to. I'm a disabled entrepreneur and I've struggled all my life in doing different things, but I have always have gone through and done things based on my positivity and willpower. So question back to you in that same thinking, what gives you hope? Plain and simple.
A
Wow. That's what gives me hope. Well, I guess if it's hope for society, what gives me hope I think is really around technology. I think that. And we can argue about how successful it's been, but you know, we've been through so many seminal events in human history in my lifetime, but the spread of Knowledge is even bigger than it was with the invention of movable type, you know, Gutenberg and What was that, 1400s. And I can't help but think that as human knowledge is spread more and more and more that it's, that it can't help but make us better humans and, and happier and, and I know the negatives, I know social media is a, is a, not only is it a time suck, it's a bunch, it's a lot of negatives about it. I know it's creating silos in our world where, you know, Everybody's going to iagree.com and they're in their own little silo of people that it's an echo chamber and they're all saying the same things to each other. I see the faults in technology, but at the end of the day, practically the entire wealth of knowledge of human history is available to each and every one of us. And I think tools like AI and who knows what else, it's driving down the cost of everything and it's advancing science and that's driving cost of energy down and making cleaner energy available and reducing the expense of batteries and all of these things. I just can't my hope and I think we're in the right direction with the negative baggage that comes with it. You know, cars over horses, cars kill people too. But overall you hope that we're all advancing in the right direction. And I guess that's my hope. You know, I don't know how else to say it.
B
That's beautiful. And let me put into perspective of people into, you know, different job professions and yours being security as the main thing. I have a 15 year old son and he is motivated for different things and I try to help as much as I can. So from his perspective, what do you tell young professionals, someone like him entering security, the optimism or realism? And you know, there is a balance between optimism and realism. And what should he be motivated knowing he's a, you know, past millennial, what Gen Z is, what he is. And you know, they have a lot of negative thinking right now and you know, you have to give them positivity at the same time, give them some realism. So what would be your thing if he asks you this question?
A
Well, if he's actually going into cybersecurity, you've got to know the weeds. I mean you got to know the technical stuff, be a good red team member, blue team member, all of this nerd stuff, you've got to know all of that. But if you can't apply it properly if you don't have that solid 50,000 foot view of what's really going on in the world and you can't communicate your job in language that the finance guy can understand, that your CEO can understand, or even your direct report, your security officer, if you can't communicate that in a language they can understand and make it relatable and make your opinion have impact, then you're really not doing the best job you can. So one of the things that surprises me when we hire these top tier security experts, they have no idea the sheer size and scale of the hacking community. Did you know hacking right now, if it was measured as a gdp, like a country, it's the third largest country in the planet.
B
I didn't know that. That's something new.
A
Yeah, it's around, it should be around 10 to 12 trillion dollars a year right now. Now that's the whole GDP of all of cybersecurity, good guys, bad guys, what's stolen, and other productivity impacts. But yeah, it's United States, China, hacking in GDP size. And if you can't relate to that and understand the scale, you don't understand the enemy. And if you don't understand the enemy, you're going to lose a lot of battles and probably the war. So don't underestimate the talent on the bad side or the dark side. Like I say, sometimes
B
that's amazing, Tom. And I can't believe we've spent more than an hour talking about here. Anything you want to say before I wrap?
A
I think we covered it pretty well. Yeah, we went over our time slot, I think, but it's been a great discussion, you had some great questions, so I've thoroughly enjoyed it.
B
Tom, thank you for being here. And if people want to learn more about your work, they can find Hack the Rich on Amazon. Visit Kirkhamirontechircumirontech.com I'm butchering the accent, so I know Tom. Or follow your speaking schedule and I will put links in the show notes. And thanks for being here. And thank you, Tom for being here.
A
Yeah, well, it was my pleasure, Dave. I really, really enjoyed it.
B
Thank you so much. You have been listening to Think podcast with Dave. Take one idea from this episode and turn it into action.
This episode delves into the intersection of artificial intelligence (AI) and cybersecurity, highlighting how AI empowers both defenders and cybercriminals in today's threat landscape. Guest Tom Kirkham shares expert insights on the latest AI-driven cyber threats, practical defense strategies for businesses of all sizes, the evolving roles of IT and security leadership, and the immense scale of global cybercrime—now rivaling the combined GDPs of major nations. The conversation blends technical advice with leadership, strategic planning, and ethical considerations.
[00:00], [01:13]
[02:59]
[04:15–08:53]
[09:02–10:17]
[13:25–15:48]
Over 90% of successful breaches result from human error—con artistry, not technical exploits.
Continuous, organization-wide security awareness is crucial.
Security must become "job one," embedded in company culture.
"You just get in your car and you put the seatbelt on. You don’t even think about it...If your company...is not baking it into the culture...you're weakening your own posture." – Tom Kirkham [14:29]
[18:29–27:39]
Continuous cybersecurity awareness training: cuts risk in half.
Endpoint Detection and Response (EDR) software: CrowdStrike or Sentinel One recommended.
Multi-factor authentication (MFA): essential defense; combine with EDR and awareness.
Professional security assessment: go beyond consumer-grade tools; involve independent experts.
Treating cybersecurity as strategic investment: not a cost center but a business enabler.
"Anyone listening...can afford this Department of Defense-level protection...And it’s the only way to defend against modern ransomware attacks." — Tom Kirkham [22:47]
[27:39–34:49]
Security and IT have fundamentally different objectives and often clash.
Security’s mandate: Secure company at all costs.
IT’s mandate: Maximize productivity, minimize friction.
CFOs or IT shouldn’t oversee security; CISOs (Chief Information Security Officers) should report directly to CEOs.
CEOs must understand their security risk just as they review finances.
"If you've got your Chief Financial Officer over it, your org chart's messed up...It is a huge, huge mistake if you don't treat it as an investment." — Tom Kirkham [25:43]
[34:49–36:16]
[36:32–39:58]
Leaders must proactively address AI governance; employees may already be using unvetted AI (“shadow AI”).
Privacy is foundational to security, and AI policies must reflect that.
"Privacy is security...If you buy into that concept...then you have no choice but to apply that same principle to the use of artificial intelligence and start wrapping that up into governance." — Tom Kirkham [38:24]
[39:58–43:23]
Companies should use AI to augment—not replace—critical thinking.
The best results: treat AI as a brainstorming partner; humans finish the "last mile" with judgment and context.
"At the end of the day, it’s just another tool in the toolbox...it’s that final mile or final 10% that really produces the report or the presentation." — Tom Kirkham [42:32]
[44:15–47:11]
CEOs must get independent security assessments—know your vulnerabilities.
Security and IT must not operate in a silo; leaders need high-level understanding and reporting.
"If you've never had an assessment to really get down into the weeds of your business and understanding what your gaps are...that's the first thing you need to do regardless." — Tom Kirkham [44:22]
[47:12–49:40]
[49:40–53:23]
Tom references the Ukraine "NotPetya" attack as a watershed cyberwar event: shut down infrastructure, sowed chaos—analogous to a cyber pandemic.
Western countries likely face a major attack risk in the future; many organizations underestimate the threat.
“In Ukraine it’s pre-Not Petya and post-Not Petya. So they know. And I think that Western world...it has yet to happen to us.” — Tom Kirkham [53:01]
[53:23–56:44]
Modern cyber insurance policies now require security controls as compliance.
However, lack of compliance or misunderstanding policy details leads to denied claims.
Always prioritize actual protection; insurance is for catastrophic losses.
“If you have to pick between better protection or insurance, I would do better protection first...But you better make damn sure you’re in compliance to being paid.” — Tom Kirkham [54:10]
[61:49]
[59:34–62:32]
| Segment | Timestamp | |------------------------------------------------------|--------------------| | Personal “ISIS kill list” story | [00:00], [01:13] | | AI-powered phishing explained | [04:15] – [08:53] | | Human error as the root cause of breaches | [13:25] – [15:48] | | Essential cybersecurity steps | [18:29] – [27:39] | | Leadership and governance mistakes | [27:39] – [36:16] | | AI governance and shadow AI | [37:13] – [39:58] | | AI as a judgment tool, not a replacement | [39:58] – [43:23] | | Assessment as the first action for CEOs | [44:15] – [47:11] | | Incident response and business continuity | [47:11] – [49:40] | | The Not Petya cyberwar event & cyber “pandemics” | [49:40] – [53:23] | | Cyber insurance pitfalls | [53:23] – [56:44] | | What gives Tom hope | [57:13] – [59:34] | | $12 trillion GDP of hacking, advice to Gen Z | [61:49] – [62:32] |
Tom Kirkham left listeners with optimism about knowledge, technology, and the potential of the next generation—if paired with practical realism and ongoing vigilance.
For more, check out Tom Kirkham’s books (“Hack the Rich”, “Cyber Pandemic Survival Guide”) and KirkhamIronTech.com.