Most business owners think they're too small to be a target. They're not being targeted — they're being selected.
Tables get turned. Host interviews David Dean Mauro about his true-crime cybersecurity trilogy The Moving Target — a book series about online camouflage, small business cyber risk, and the real cost of being visible online.
Built from 400+ investigative interviews with cyber leaders, business owners, and criminal hackers, the trilogy follows Stevie Parker: competent, careful, busy — and breached anyway. No acronyms. No lecture. No IT background required.
WHAT WE COVER:
• Why "I'm too small to target" is the most expensive assumption in business
• Selected vs. targeted — how criminal crews actually pick victims
• Shadow AI: the risk sitting on every employee's phone (we unlock ours 260+ times a day)
• How much criminals already know about you, your bank, and your kids
• Inside a ransomware operation: quotas, shift changes, HR, healthcare, a board of directors
• The bear and the shark — why defense in depth beats perfect security
• Social engineering, plain English: they don't hack systems, they hack people
• Who really pays after a breach (hint: it's not the brand in the headline)
Fewer than 4% of cybercriminals look anything like the hoodie in the basement. Cybercrime is organized crime with an org chart.
CHAPTERS
00:00 Turning the Tables: Why a Cybercrime Trilogy for Business Leaders
01:13 The Real Cost of Being Visible Online
02:56 Meet Stevie Parker: The Competent Victim
04:35 "I'm Too Small to Target" — The Most Expensive Myth in Business
06:52 Selected, Not Targeted: How Criminals Actually Pick You
10:20 Shadow AI: The Risk Hiding on Every Employee's Phone
13:03 What Hackers Already Know About You and Your Family
16:35 The Bear and the Shark: Outrunning Cybercrime
19:25 Inside a Ransomware Gang: Quotas, HR, and a Board of Directors
24:24 Beyond the Headlines: Who Really Pays When a Company Gets Breached
Book three of The Moving Target releases September 22. Links and the data-broker opt-out checklist mentioned in the episode: [ADD LINK]
Brooke (00:00.098)
Just from that question.
Breaching the Boardroom (00:02.381)
No, let's start from the beginning.
Brooke (00:04.64)
Okay, hold on, I need my other documents, sorry.
Breaching the Boardroom (00:07.865)
It's okay.
Brooke (00:10.112)
All right. Hello everyone and welcome to Breaching the Boardroom podcast. My name is Brooke Damonte and I will be your host today. But have no fear, a familiar voice is here with us. We will be turning the tables a bit for today's episode. He has spent over two decades helping business leaders understand cyber risks before they become a crisis. He is NetGames' fabulous vice president of strategic growth.
David Morrow, you know him, you love him. David, how are you today?
Breaching the Boardroom (00:42.969)
Thank you for that ridiculous intro. I very humbled by that. doing well. So looking forward to our discussion today. I'm not usually on this seat, so that's good.
Brooke (00:51.938)
Good.
Yeah, we're changing it up today. Well, we're here to ta today to talk about your book trilogy, The Moving Target. The series explores online camouflage and the art of staying one step ahead of people trying to exploit you. Why write a book, more or less three of
Breaching the Boardroom (00:56.557)
Yeah, I like that.
Breaching the Boardroom (01:13.24)
Good point. So it's about the cost of being visible online that every one of us experiences and we have over time. And so over the last several decades, and in the last five, six years, we've conducted over four hundred investigative journalist projects and interviews with cyber leaders, criminal hackers, business leaders, and we wanted to tie it all together and put it
into a framework or a medium that everybody can relate to and everybody can kind of make it their own. So it's it's not just about raising awareness. It's about literally changing our behavior online and not done in a lecture format and not done through an IT book or a cybersecurity book. This is a true crime story told through one composite character that experiences all of the things.
Brooke (02:10.542)
I know I can really appreciate that as a reader who is not an IT professional and I know that's why a lot of our audience kinda connects with the book because a lot of our leaders listening today are dealing with real versions of what you write about, but not all of them are IT professionals or well versed in technology terms.
Breaching the Boardroom (02:30.282)
Yeah. I mean, and and the whole point is it's not one that is tied around acronyms or cybersecurity talk whatsoever. It is real life business leadership, you know, and it is based on all true stories. It's just the the fictional aspect is we have them all experienced by one composite character, Stevie Bell.
Brooke (02:56.972)
Yeah, speaking of that composite character, Stevie, so you open up with Stevie Parker and she has done all the right things to kind of protect herself, but she still ends up getting targeted. So what made you lead with a character who is competent as opposed to careless?
Breaching the Boardroom (03:13.481)
Yeah, so first of all, we I wanted to make it a character that everybody could relate to. And at first we weren't sure whether to make it a male or female. My wife who helped me kind of develop this story, we decided on Stevie Parker because it is very similar to several professionals that we know. And the name is because it's not about her being a female or him being a male leader, it is more about
A person being in leadership and what they saw. The reason we made them competent is because most business leaders that I know are. They're, you know, a careless victim kind of lets the audience off the hook, right? Everybody thinks that they're smarter than a victim, right? I wouldn't have done that dumb thing or whatever. But the truth is, is in real cybercrime cases, the people involved are very bright. They were just distracted or busy. And so
Brooke (03:50.99)
Yeah, absolutely.
Breaching the Boardroom (04:11.612)
She makes defensible decisions on busy days, right? And I find that the in order to drive behavior, we have to drive the emotional component of what happens to us during these crises. And the shame lands harder on competent people because that's actually who it's happening to, right? And the point is if she got hit, so can we.
Brooke (04:35.958)
Yeah. I think the other side of the scale we see is people who assume that they're not interesting enough to target. So we have the competent side that are preparing and all that. Then we have the other side that just assume they don't they don't need to be careful, they don't need to be worried about this. What would you say to business owners who genuinely believe this?
Breaching the Boardroom (04:57.362)
Well, most business owners I meet are very bright, very good at what they do. They don't necessarily understand cybercrime. You know, Hollywood and the media has created the version of a hacker. When we say hacker, what do we all picture? We picture a kid in a hoodie living in his mom's basement, eat eating hot pockets, cracking code, extremely technically, you know, proficient. And while they do exist, don't get me wrong, they do exist, they are roughly
Brooke (05:14.39)
In the basement, yep.
Breaching the Boardroom (05:27.058)
Based on stats, roughly less than four percent of cyber criminals. and cybercrime is is a big business. It is organized, right? so I think the the point of that is that you're not necessarily being targeted. Your inventory. The the weakness in your security posture is what's being targeted at scale. And that's the good news, right? Because the good news is we don't have to put up that much
friction for them to move on because they have tight tie lines. Just like a big business, right? They have quotas. They have things that they have to hit. They're not going to spend all this time targeting you per se, right? and when we say small, it doesn't it has nothing to do with the size of the organization. We've seen this across every single size. the reason those smaller organizations that get hit and
More than half of all organizations are the ones that are really small. they're just not in the news because they're not household names, right? When Uber gets hit or Target gets hit, it makes news because we all know the brand. But when ABC Company in Little Newport, right, gets hit, it doesn't make the news because it's not a household name. It wouldn't get clicks on the news site.
Brooke (06:52.364)
Yeah, so when talking about getting you use the word targeted a lot in that last phrasing, but throughout your book you use selected, kind of a similar phrasing there. But you you never say hacked, you always say selected. It's a very powerful framing. Walk us through this what the selection process looked like from the criminal side.
Breaching the Boardroom (07:12.953)
Yeah, I mean it's reality. You're you when we investigate and we understand a small business that i undergoes a massive disruption, right, through cybercrime. It could be through fraud, it could be through ransomware, it could be through AI polymorphic attacks. There's a whole bunch of ways that they do it. But the reason you were s you were selected is not because you yourself were targeted. It is because
They have a list, just like a sales team has a list of ideal prospects that they want to call on, they want to mail things to, they wanna stop in, right? Because it fits their profile. These are the type of organizations that would pay should we hit them with cybercrime. These are the kind of organizations that might be a good fit for our services or our products. It works the exact same way. We've interviewed them, like we've talked to them, they have call centers, they have
HR departments, they have they have everything that an organization, a regular business, legitimate business organization has. LinkedIn gives you the org chart. they have, you know, revenue, headcount, industry, vendor stacks, and data brokers, right? We all you know, log in. Most people aren't great about password management. We reuse passwords.
A lot of that data is bought and then they put it in their systems and they go through and they are looking for the easiest house on the street to breach. the best example I can think of is we've all been to Target and we all we all can picture the Target parking lot, right? And all these cars are parked there. And if a criminal is going to break into your car and take something that you left on the back seat or a purse or
Brooke (08:57.538)
Absolut.
Breaching the Boardroom (09:11.789)
Whatever you might have been left behind while you're in shopping, they are not going to smash the window or make a lot of noise or set off the car alarm, right? They are going to walk car by car in between cars so that they're not seen and they are going to pull on door handles. That is what they do. That is what the data shows. And it's very similar to cybercrime. They are looking for people that have been busy and distracted and
Could be very well educated, could be very professional, very good at their job, but they left the door open. And that is understanding that leads to to very simple behavior that we can all learn, and that is to pause and to be a little bit more vigilant, and all those things that are in the in the to-do' of this book series.
Brooke (09:46.158)
Yeah.
Brooke (10:03.788)
Yeah. Yeah, I think I think always always stopping to pause is so important in every aspect of life. And it's something we all need to do a little bit more in today's day and age when we need to be a little bit more careful, especially.
Breaching the Boardroom (10:18.293)
Yeah, absolutely.
Brooke (10:20.054)
So moving on to book two, you introduce AI at adoption pressure from private equity buyers. Are you seeing pressures in real companies right now and what risks come with that?
Breaching the Boardroom (10:33.74)
Well, yeah, shadow AI is a huge concern for organizations, and many don't realize it, right? we pick up our mobile devices on average over 260 times a day. When AI apps are one swipe away from that, I don't care what a leader says, they don't have an AI strategy, they have an AI situation. And
Because of that, what we're seeing in the PE, the private equity, and the mergers and acquisitions is valuation models assume AI use and they are checking for whether you have rolled out AI with the right governance in place. That's really, really important. Because most people never read the terms in service of any app that they do. None of us do really, right? And we have to make sure that what makes
your organization valuable to an investor, right, is your intellectual property. It is your brand. It is the way you do it differently from your competitor. And AI has a very powerful way of minimizing that and making that public. And so really addressing how AI has infiltrated business in a way that business leaders don't see necessarily until they're looking to sell is really important.
Brooke (11:37.442)
Mm-hmm.
Breaching the Boardroom (11:56.717)
And it's because AI itself is not evil. It's just obedient. It will do what we tell it to do. It will also do what we fail to tell it not to do. And that's it. The last part is what gets everybody. And so we walk Stevie Parker through real life scenarios involving AI and how they build up AI, they roll it out wrong, and then they roll it out well. And then they observe
competitors roll it out wrong and then they make tweaks to it. It's all it's all based on real clients that we work with and see, right? It just happens to Stevie Parker.
Brooke (12:31.278)
Yeah, and I think that's
Brooke (12:38.402)
And I think I think that's what's important to realize is Stevie Parker's world is our world. You know, it's not it's not any different, it's not some false reality. AI is here, AI is real, it is a part of our lives and it's not going anywhere anytime soon. So, you know, we need to we need to adopt our our businesses to be able to handle it and keep our keep our privacy there at the same time.
Breaching the Boardroom (12:53.957)
No, not at all.
Breaching the Boardroom (13:02.319)
Absolutely.
Brooke (13:03.948)
So you speaking of phones always being right at our fingertips, you describe the criminals as knowing exactly who SB Parker is. They know who her daughter is, what bank she uses, how much profiling happens before first contact is ever made.
Breaching the Boardroom (13:22.628)
W that's a good question. Way more than people realize. So way more than I realized until I started interviewing all these people and learning about this. And AI, it was good before. So don't get me wrong. It was very good. The amount of dossiers that they have on every American adult is remarkable. But AI has been able to triangulate that.
And look at all the telemetry and put it all in dashboards that are all for sale on the dark web, like it's an Amazon store, right? You can literally get anything about everybody. And I mean everything from medical history to purchasing habits to what technology they use to how they scroll, to what type of things they look for, what their future plan is, because you can see from their searches.
there's a lot of data. Think of it in the legitimate sense. a small mid-sized business has a sales team and they have a CRM and they are using systems, you know, where they are looking like Zoom info or cognizum or applications like that. What are they giving us? They're giving us business intelligence about the prospects that we're looking for, what type of technology they're using, who's in leadership, what their org chart is.
They have the exact same thing for us, except they're not trying to sell them services or products. They are trying to harm us or to get inside the organization. And because of AI, it just speeds up that speeds up that process.
Brooke (14:59.021)
And I think
Brooke (15:04.268)
And I think that's what's so frightening for users is everything is out there for these hackers to go get and to purchase. All the information is there. They do know everything about us and all that occurring before they ever even make contact with us. We never even know that they're they're kind of hacking our circle. They're inside there.
Breaching the Boardroom (15:25.803)
Well, yeah, and all these stories run together because they're all real. They're all r based on what actually has happened in the last year or two. when Stevie Parker gets hit, like a call that's made, an email that's sent, it references things that only somebody inside her circle would know. Right? And that gets to the
Brooke (15:43.883)
Mm-hmm.
Breaching the Boardroom (15:47.799)
belief that's why we made her competent because the people that we meet and are engaged in that get breached are very competent. They are just busy, right? And they think like all of us do, right? Well they must know me if they know my wife shops here and did this, right? Something personal or my child did this, right? They must be legitimate because they're doing the segments and the data points of legitimacy. Except that all of that is purchase
They all of that can be purchased outside. All of that can be compiled through just a little bit of investigation. And again, they're not even targeting me. They're just targeting people like me to see if I will put up enough resistance. If I put up enough resistance, then they're moving on to somebody else.
Brooke (16:35.736)
Mm-hmm. One of my favorite part of the books is your bear analogy. So you say you don't have to
Breaching the Boardroom (16:41.238)
Yeah, it's I I will say I didn't invent it, but a buddy of mine who's a global CISO, former global CISO with Zurich, invented it and I've used it for over ten years. It's absolutely brilliant.
Brooke (16:56.066)
I mean it's awesome and it's true. So the analogy goes that you don't have to outrun the bear. You just have to outrun the person next to you, right? And I think it it does go back to your target analogy in the parking lot. You just you just have to have your car locked and the person next to you has to be unlocked, you know?
Breaching the Boardroom (17:04.694)
Yeah, it
Breaching the Boardroom (17:14.443)
Yeah, and and that's exactly right. And a similar analogy, that person who shared that analogy with me has now moved to Australia. And so he said, Well, the bear in the woods analogy doesn't work, because there's no bears down here. But there are sharks. So he made it the shark in the water, right? And that's the analogy is the same. If you're out swimming just like all of your competitors, just like all of your coworkers, and somebody sees fins, okay, and somebody screams, well, it could be a dolphin.
Brooke (17:27.662)
There you go.
Breaching the Boardroom (17:43.552)
Could be a shark. I know one thing. I'm not sticking around to find out. I'm swimming ashore. Can I outswim the shark? Meaning, will you actually be able to defeat cybercrime if it's actually coming for you? And the analogy works in general, right? And the truth is, is you don't really have to be you you're never gonna be able to outswim that shark, right? A great white shark swims twenty-five miles an hour, a Mako shark.
Brooke (17:48.365)
Yeah.
Breaching the Boardroom (18:11.124)
45 miles an hour, the fastest human on record only swam eight miles an hour. That's been recorded. So we're not doing it, right? But if we're gonna swim faster than that guy, than the guy who just ate three cheeseburgers and jumped in the water, right? Then we're gonna be able to beat them. So the analogy works for that. Where the analogy fails is once they are after you, right? Once the shark attacks you or once the
Brooke (18:18.561)
Yeah.
Brooke (18:24.513)
Ha ha ha.
Breaching the Boardroom (18:39.37)
Bear attacks you, then it becomes a matter of depth, right? Like how much defense, what type of gear are you wearing? What type of of tactics do you know, right? In the bear analogy, do you know to not just fall down and scream and go into a ball? Can you make noise? Can you cause you won't be able to climb up a tree and be dead, etc.? You you have to be able, just like in security, you have to be able to have depth, right? You have to have
Brooke (18:50.305)
Paradily.
Breaching the Boardroom (19:07.379)
different layers because once they get in, it's not necessarily a breach. They're gonna move laterally. Are you gonna be able to catch them before they do it? That's defense in depth, right? That is really the key. And that's why we talk about it like that, because we wanna do it in language that everybody can understand.
Brooke (19:17.228)
Mm-hmm.
Brooke (19:25.537)
Yeah, I like that. So these, yeah, these hacking operations, they run with quotas, ship changes, and what you describe as a board of directors. When most people picture cybercrime, they picture, like we described, the basement guy with the black hoodie hacking. How far is that from reality and what does it mean for businesses when they are these bigger operations?
Breaching the Boardroom (19:27.549)
Makes sense.
Breaching the Boardroom (19:51.09)
Yeah, it's actually quite impressive. we've been involved in some investigations, we've interviewed people that have gone undercover in these operations. They offer healthcare, they offer scholarships, they have HR departments, they have help desks so that victims can pay. They speak in multiple languages. They are located usually in parts of the world where it's not a crime to bankrupt Americans. It's not a crime. Like
Nothing's going to happen to them. And in fact, especially if they operate in parts of the world that doesn't trade with us, right? Bringing in millions of dollars from America is high-fived, right? They are excited to get that revenue in. So they are like little living legends, little al Capones that are kind of celebrated in their villages and in their areas. and that's something that we have to understand, right? they don't have empathy for us. They've
Brooke (20:42.38)
Yeah.
Breaching the Boardroom (20:49.776)
Been raised at the kitchen table next to their grandfathers who have taught them their entire lives that we are the enemy, that we are bad. And so that is their core. And so they still look at everything we say and everything we do without empathy, right? And so they don't care if they're destroying a hospital and hurting organizations and hurting individuals, right? Because we're still the enemy in their eyes.
And so we have to realize that when we get online, we're not in Kansas anymore. We are literally in their world. And so that's where we have to put up enough defense so that the vast amount of cybercrime won't get us. They're gonna go to the groups that are still using password for their password and not doing anything. So we don't have to do we don't have to build Fort Knox, but we do have to do enough, right? And then should we be targeted and should you have real value in your organization?
Brooke (21:24.311)
Okay.
Brooke (21:38.423)
Yeah.
Breaching the Boardroom (21:48.089)
You do need defense and depth. So that should they get in and should it happen, it could be stuck.
Brooke (21:54.315)
I think that makes total sense, yeah.
Breaching the Boardroom (21:56.794)
Yeah, it's it's not it's not the end of the world. I mean, the crimes and the elements that they get in, the way they get in more than any way is social engineering. Social engineering is a fancy you know, cybersecurity has fancy phrases. We talk about exfiltration of data. That means steal. That means I took your stuff, right? social engineering is I tricked you, right? Like it's it's I lied. Like that's it. That's that is what it is. And so
It you know, we use industry terms because it's expensive to do this and people want to feel like they're like they have industry terms, but the type of crimes and the type of tactics have been around for thousands of years. This is crime. And that's why the book series is a crime series, right? It's not an IT book, it's not a cybersecurity book. It could have been written a hundred years ago, the story would have changed, but the crimes wouldn't have. And that's the important thing.
Brooke (22:29.374)
Yeah.
Brooke (22:50.281)
One and that distinction feels very intentional throughout the whole book is it is made for the average Joe. It's not made for the CEO of the tech firm who's got five hundred people as an IT team. You know, I read the book and I was able to get by just fine.
Breaching the Boardroom (22:54.51)
Yeah.
Breaching the Boardroom (23:05.528)
Right.
Breaching the Boardroom (23:09.325)
Yeah. Well, and that's the whole point. And I'm glad to hear that because that is the whole point. You d you don't need to know anything about IT or cybersecurity to learn from the book and to be entertained. Like that's the whole point. And I just think if we entertain people, then like that's how I like learning, right? Like I wanna learn
Brooke (23:29.1)
Yeah.
Breaching the Boardroom (23:30.977)
where I'm learning it and it's doesn't feel like school. Like it doesn't feel like a lecture. I want to be entertained. And then all of a sudden you're like, yeah, because why is that? Because the odds of me changing my behavior are better if I'm voluntarily doing it and not being told to do it. You tell me to do something, I'm not going to do it. If you convince me it's good for me, then I'm going to do it. Right?
Brooke (23:53.866)
Yeah.
Well it makes it easier to implement when it's said in in layman's terms. When you when it's easy to understand, it's easy to do. There's no second guessing it. You just do it. You just stop making your password password. You know, it's not not it's second nature to not use the same passwords all the time.
Breaching the Boardroom (24:00.514)
Yeah.
Breaching the Boardroom (24:08.354)
Right. Yeah, and you don't do it because Yeah, and you don't do it because the IT guy who gave you that security awareness training in a monotone voice with his eighty slides told you to do it. No one's gonna do it. That's why it still happens, right? That's not effective. But if you realize what happens to humans at the epicenter of it, right? Because when you hear about a data breach
Brooke (24:20.128)
Exactly.
Brooke (24:24.726)
Yeah.
Breaching the Boardroom (24:35.569)
in in the news, right? They talk about the company, they talk about the brand name because that's that's clickable. That is something we wanna see about, right? Target got hit, or this big company got it, or instant Young got hit, whatever. But it's the human at the epicenter, right? It's the person who clicked.
Brooke (24:42.617)
yeah.
Breaching the Boardroom (24:55.2)
Who loses their 401k, who might lose their job, who may have to now have years of identity theft and tax problems. All of that is real. All of that actually we've literally talked to hundreds of them. That's what really happens. And so explaining that, now people are like, well, I don't want to be that person. Like, I want to do this, not because they told me to do it. I just want to do it so that I don't have to deal with that.
Brooke (25:22.519)
Yeah.
Breaching the Boardroom (25:22.793)
Right? Life's hard enough. We don't need to deal with that. Yeah, exactly. It's like a it's like a it's like a good cop show when like there's the big crash and they're like, you know how much paperwork I have to do now? Right? Like that's what they don't want. Right? Just avoid the crash. That's good.
Brooke (25:25.581)
Like avoiding the paperwork.
Brooke (25:36.001)
Yeah, exactly.
Brooke (25:42.625)
All right, well David, where does Stevie's story go from here and what are you hoping readers take from the trilogy as a whole?
Breaching the Boardroom (25:50.739)
Yeah, good point. who knows? You know, I'm gonna have like fifty books. No, I'm kidding. it it ends in a trilogy. the book three comes out September twenty-second. she learns to disappear online, becomes a ghost, not totally disappear, but making it very, very difficult to
Brooke (25:55.945)
Ha ha ha.
Breaching the Boardroom (26:12.051)
be found so easily through these systems. And in the book we actually show you, we give you a little checklist on there. So in case somebody wants to do it, it's pretty easy, right? It just takes a little and you don't do it all at once. You just do a little bit every week, you know, five, ten minutes every week, and all of a sudden over time, you don't have so many spam calls and so many, you know, spam emails and you don't get so many attempts on LinkedIn to get you to click a link.
And all this stuff, right? it just makes your life better. you know, what we did is in the story, she built a sealed AI, like a private AI, that P that competitors or threat actors can't poison. she saw a competitor get poisoned, that's all based on a true story. and then
The last three lines really kind of say it all. And that is this never was about cybersecurity. It was about the cost of being visible online. And you don't need to have a YouTube channel or to have a podcast to realize we're all visible online. And so there's
a reason to just reduce the risk. Put up a little resistance for yourself. Protect yourself first and then your family. Like that's what people really care about. Do that for those reasons. Period. Your employers will always benefit. But if you do that for those reasons, then then everybody wins.
Brooke (27:44.119)
Well, I hope we can all learn our lesson through Stevie instead of through our own experiences. And that we can we can take what what she's learned throughout her three books here and and take that with us. I'm excited to read the third book in September. I look forward to it coming out. Thank you for your time, David.
Breaching the Boardroom (27:50.322)
a lot easier.
Breaching the Boardroom (28:03.004)
Great. Well, thank you so much for for sitting down with me and letting me walk through it. I appreciate it.
Brooke (28:08.691)
Absolutely. I appreciate you and I hope to talk to you soon.
Breaching the Boardroom (28:13.266)
Great. Thank you so much.
Brooke (28:15.0)
Have a good one.
#cybersecurity #smallbusiness #ransomware #shadowAI #socialengineering #cybercrime #businessleadership #datasecurity