CYBR.Minded

Busy is the New Stupid with Ross Young

CYBR.SEC.Media Season 1 Episode 4

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 36:04

Why do organizations keep investing in cybersecurity without feeling more secure? In this episode of CYBR.Minded, Dr. Dustin Sachs and cybersecurity executive, educator, and CISO Tradecraft co-host Ross Young explore why bigger budgets, more tools, and expanding control frameworks do not always reduce risk. They discuss threat-based planning, stronger metrics, tool sprawl, ineffective risk registers, outdated compliance requirements, and how leaders can focus limited resources on the threats and safeguards that matter most.

Things mentioned: 

Do you have a question for the host? Reach out to us at media@cscgroupllc.com 

In this episode:

 Produced in partnership with Psybercog Labs

Keep up with our Conferences and Events:

 Keep up with CYBR.SEC.Media:

Learn About CYBR.SEC.Careers Non-Profit Efforts

 Subscribe to the podcast: 

Listen to our other shows:

SPEAKER_02

Welcome to Cyberminded, where cybersecurity, behavior, and leadership meet. I'm Dr. Dustin Sachs, and this podcast, co-sponsored by CyberCog Labs and Cyberspec Media, asks a simple question. What if the biggest risks in cybersecurity start with how we think, decide, and respond? Each episode is a chance to pause, reflect, and see security through a more human lens. Let's take some time and look beyond the controls to the human side of cybersecurity. Today, we're exploring a problem cybersecurity leaders have wrestled with for years. Why organizations can spend more on security and still feel no more secure. Organizations often respond to new threats by adding tools, expanding controls, and asking for bigger budgets. Yet, leaders still struggle to explain what is improving, where the program is brittle, and whether spending is actually reducing material risk. The issue is not always underinvestment. Often, it's that leaders are making security decisions without a clear, shared model of the threats that matter, the safeguards that matter, and the human or organizational conditions that shape whether those safeguards work. As with every episode, we always start off with a question to just think about while we're talking about our conversation today. Today's question is: what happens when cybersecurity mistakes visibility visible activity for meaningful protection? You know, the behavioral science answer is that people default to what is legible, urgent, and easy to justify. In cybersecurity, that often means buying another control, counting another metric, or treating tool coverage as proof of resilience. But secure outcomes depend on judgment, prioritization, incentives, communication, and whether leaders understand how risk actually moves through people, systems, and workflows. That's the space this podcast is built to explore. Cybersecurity, as we always say, depends on controls, tools, policy, and governance. But again, as we also always say, it also depends on attention, judgment, incentives, trust, communication, and behavior. Welcome to today's episode of Cyberminded. What would change if cyberleaders stopped asking first what to buy and started asking what threats matter most, what safeguards actually change outcomes, and what leadership decisions make those safeguards succeed or fail? My guest today is a legend in the podcast community for cybersecurity. My guest today is none other than Ross Young, co-host of CISO Tradecraft. Uh, for those of you who don't know Ross, uh, first of all, shame on you. Second of all, uh, Ross is a cybersecurity executive and educator whose work sits at the intersection of threat modeling, cyber leadership, executive communication, practical risk guidance. His background includes serving as CISO of Caterpillar Financial, leadership work at Capital One, teaching through Johns Hopkins and Sands, and creating the OWASP threat and safeguard metric matrix, excuse me, framework designed to help organizations connect major threats to meaningful safeguards and metrics. He has also been publicly active on AI governance, security budgeting, and the problem of tool sprawl, all things that we here at uh Cyberminded and at CyberCog Labs love talking about. That makes him an ideal guest for today's conversation on why cyber budgets fail when leaders are missing the right mental models. Ross, welcome to Cyberminded. And before we start, I do want to us to take a moment and just pause and give just a moment of reflection because I know that within the last couple of hours, uh 24 hours or so, we lost a very big giant within the cybersecurity community. And I know with your involvement in SANS, can you know want to obviously make uh note of and send our best wishes and thoughts and prayers to the family of Dr. Eric Cole. But uh would love to, you know, have you maybe say a few words at the beginning and then uh anything else you want to share with the audience?

SPEAKER_01

Yeah, you know, each of us stands on the shoulders of legends before us. And, you know, certainly I wasn't the first person in cybersecurity. There's been many great people before me. And one of the influencers who helped me a lot was Dr. Eric Cole. When I was first starting to learn how to be a CISO, I was listening to Defense in Depth from Alan Alford. I was listening to CISO series, uh, you know, which had Mike Johnson and uh who's the host of CISO? David Spark. That's who it was. David Spark.

SPEAKER_02

A very, a very good, by the way, very good friend of mine, somebody who was responsible for helping me get my role as deputy CISO at uh my last company and getting to work with the incredible Sean Bowen. Uh, but David Spark, Alan Alfred, all that that whole team over at CISO uh series, phenomenal. Check them out for sure.

SPEAKER_01

Yeah, and one of the ones who was also extremely influential for me was Dr. Eric Cole. You know, I used to listen to both of his podcasts. I've listened to every episode on a weekly basis for years. And what I liked about his was it wasn't just the technical, it also brought the business side of here's what the C-suite thinks about the nerdy CISU in the room who can't explain anything and in board language. And he brought that perspective. So I got smarter every week by listening to him. And I'm just grateful that he took the time to share a podcast for free. And it was like paying for a sands, you know, conference every week, right? So I really appreciate all the work that he did. I would not be where I'm at today without using some of his viewpoints to make me smarter.

SPEAKER_02

Yeah, and I'll say I think listening to his podcast, as you said, about you know, the connection between cybersecurity and business really drove me to realize that I needed to go get an MBA. I needed to go like truly understand the business side of cybersecurity and the business side of business in general, so that I could communicate things better. And I, you know, obviously, one of the things that you know I'm very passionate about and that our listeners know I'm very passionate about is bringing elements that are not necessarily at first glance the things you would connect to cybersecurity, but connecting those and making those really intertwined. And and yeah, everything we're going to talk about today, I think, as well, really helps drive that point home. So before we get into the deeper parts of the conversation, I want to start with your perspective. It's starting to become very fun to ask this question. Uh, in one of our previous episodes, um, Dr. Calvin Noble's explained that he's asked this question of people and gotten some really interesting responses. So I'm interested to hear your response to this one. Uh, when you hear the phrase the human side of cybersecurity, what does that mean to you and where do you think the industry still misunderstands it?

SPEAKER_01

I think we have to understand that I can write a cybersecurity policy that says you shall patch in one day and it's going to fail miserably. Because I need to actually go beyond anything in policy to say what's the process and what's just how people work. How do I make cyber really, really easy for them to do the right thing? Because it doesn't matter what's on paper, it doesn't matter what tool does something, it matters how the people implement the tool, what is the daily practice of things, what is the tradecraft of the organization because that is where the rubber meets the the road. We all have been in a fishing training simulation, we know not to click the fish, but someone's gonna click a fish. And how do we make sure we're we're a good organization despite knowing we're gonna have human failures?

SPEAKER_02

Yeah, I mean, and as good as you can be, the right timed fish email will get you every time, you know, and I've got stories that I I'm not gonna share here because now this is gonna be uh, you know, out there for posterity purposes. But let's just say I, you know, I've certainly been the victim of of fishes, fish simulations that I actually created because the timing of it was just so perfect that I didn't even that I wasn't even paying attention and um made a mistake that I otherwise wouldn't have in that split second of just being very busy and making a bunch of decisions.

SPEAKER_01

So yeah, you know, no one wants to click on the hey, you have a FedEx package, click to see where it is. Yeah, on that day you're really expecting a FedEx package, and you know you're you're just one moment away from that, and you're on your phone and you're being bothered bothered by your kids and the neighbors while you're sitting at a game and you're not paying attention, like life happens, right?

SPEAKER_02

I plead the I plead the fifth, Ross. That may or may not be very close to what actually happened for me, but I'm gonna plead the fifth for my own safety and security. Before we go further, this episode is supported by Cybercog Labs. At Cybercog Labs, we help cybersecurity and risk leaders look beyond control design to understand where human behavior is shaping cyber risk. Because the issue is not that a control does not exist, it's that the control breaks down when real people encounter pressure, ambiguity, competing priorities, unclear incentives, or decision fatigue. Cybercog Labs helps leaders identify those breakdowns and turn behavioral cyber risk into practical, board-relevant insight. Visit us at cybercog.com. That's P-Sy B-E-R-C-O-G.com. Now, with that in mind, let's get into the problem beneath the problem. Ross, the topic for today, and I know one that you're very passionate about, is why cyber budgets fail without better mental models. So I want to start with the distinction itself because many organizations uh still treat security investment as a tooling coverage or budget size question. Questions that, you know, and these these elements are things we bring up in every episode, um, but always from a slightly different perspective. When leaders feel exposed, why do they often misdiagnose, or what do they often misdiagnose about the problem they're trying to solve?

SPEAKER_01

I think the biggest problem that we have in our industry is this concept I call busy is the new stupid. And you just think about it, there's so many things we do.

SPEAKER_02

T-shirts coming, t-shirts coming soon on uh Ross's new website. Um they'll be available at Black Hat if you find him, just you know, berate him until he gives you one.

SPEAKER_01

So so the idea is we do a lot of things because it's expected of us. And I think we often put our hats on to say, is it actually securing the company or is this compliance or security theater? Look, there's some things I have to do, like I just don't look good in an orange jumpsuit, so I have to, you know, make sure I document how we meet regulations. But then there's other things I really need to do that lower the risk of the company, like having unpatched vulns internet facing just never ends well for any company. So we got to fix that. But then how do I make sure I'm not doing enough of the things that steal my resources from the things that are really important? And so as I started really thinking about that problem space, I decided to write a book called Cybersecurity's Dirty Secret, Why Most Budgets Go to Waste, that really explores this perspective of how do we find and build the right budgets that are zero-based reviews? How do we actually figure out what to prioritize the right projects? And how do we do things like murder boards to figure out what things in our program we should kill because it's stealing our resources that should be in other places?

SPEAKER_02

Yeah, and we'll put a link to the book in the show notes, but uh I will say, as somebody who has had the opportunity to read it, um, because I always read books that are given to me for free, um, but no, uh it was a phenomenal book. It's uh it you know, must must read for any cybersecurity professional, especially uh as you, you know, growing your leadership opportunities, you know, definitely worth bringing out. And, you know, you brought up the concept of security theater, which I think uh kind of ties well with the concept of what you were saying earlier, which is we stand on the giants, you know, Bruce Schneier, who's the one who came up with, you know, the who really was talking about uh security theater often. So uh, you know, love that we're we're kind of weaving in some of the legends of the industry. Um, so you know, your work, your public work around the threat and safeguard matrix, you know, that suggests leaders should start with material threats and then map safeguards with more discipline. So, what does the model reveal that a typical kind of shopping list approach to security misses?

SPEAKER_01

Yeah. So if you were to go into 99% of Fortune 500 companies, what you would find is a risk register that documents the material risks that can pose harm to the company. Hey, we carry about business email compromise, we care about insider threat, we care about ransomware. And usually what you're gonna find is like a three-sentence thing that says, here's how we're gonna, you know, mitigate the risk. And what I just kept thinking to myself when I stepped in the role of CISO at Caterpillar Financial is I think if it's a multimillion dollar threat to harm our company, what I would call a material threat, putting only a three-line sentence in a risk register is just negligence. It just doesn't do enough to say we're thinking about how to solve this problem, protect our our customers, our shareholders, our IP, all of these things.

SPEAKER_02

So yeah, I think I think the point, you know, to the point that you're making, you know, I would, I would, I would frame it this way as well. I mean, would you, would you, you know, your your spouse, your significant other, whatever, would you go to the store and just buy a generic birthday card and not write anything you know targeted to them in there? Or are you going to take the time to actually write a heartfelt note in addition to the card? Same thing. If this risk is so important that it's got the ability to, you know, take your company down or lose cost significant amounts of money, writing a three-sentence, the risk that is blah, blah, blah, blah, blah, blah, blah, blah, blah, blah, blah, blah, blah, is not going to be the most effective.

SPEAKER_01

Yeah. And so as I started researching, one of the things that really struck out to me was the cyber defense matrix by Sunil Yu. And in it, on one side, he puts technical layers like identify, uh, I'm sorry, like the uh let's let's call it the asset layers of what is an endpoint, what is a human, what is, you know, a network device and different things. And then on the columns in the matrix, he would put identify, protect, detect, respond, recover. And I looked at that, I really liked that breakdown. But what I saw was he was putting technology layers in there, like, hey, we have to secure everything at the network layer. And I and I kind of challenged it a little bit because I'm like, if I have perfect app sec and everything's encrypted, why do I even care about the network layer? Uh, and so I and at the end of the day, I didn't need to be talking, you know, detail network layer with the risk committee because that's too, you know, CISO and nerdy for them, right? I need to bring it up to this business uh level. So what I thought we would put is the threats on the left-hand side. And by doing that and taking a threat and breaking it down between identify, protect, detect, respond, recover, what we actually create is a defense and depth approach. So, whereas a risk register may say the way we stop business email compromise is we just buy an email security gateway and leave it at that. What our framework does in this matrix is we say, how do we identify who the VIPs are and the network admins and domain control uh admins are? Because they need to be really, really secure. And once I have identified those and the systems where they touch, how do I protect those things? Maybe I still use an email security gateway, but I also might have SPF, DKIM, MFA, other things there. And then, you know, how do I detect if I couldn't stop that attack? You know, do I have impossible travel rules? Do I have forwarding rule alerts and things like that? And then how do I respond and recover? You know, do I do a global sign out on those accounts, an account reset? How do I do, you know, different types of uh policy updates or training to the help desk, or they're not resetting those accounts, right? All of these things is what I would call as a comprehensive defense in depth plan around business email compromise, which I think is if you get this right, now you can actually build a really good cyber strategy more than two, three lines in a risk register.

SPEAKER_02

Yeah, and you know, that matters because a security program can look busy, it can look mature, it can be well funded, but still be conceptually confused or conceptually confusing. If the team, as you said, if the team has not agreed on the few threats that truly matter, it can become very easy to overspend on what's visible and underspend on what actually changes the risk profile because it the visible stuff is easy, you know, whatever's on the top of the water is easy, but it's the you know, it's easy to see the iceberg uh, you know, above the water once you get close. What you miss is all of the water, all of the ice underneath that's ultimately going to sink your ship. Um, so you know, where do people, processes, and organizational conditions usually break the link between a safeguard on paper and a safeguard that works in reality?

SPEAKER_01

So I actually pull this apart really in detail in my murder board. And I'll just give you some examples. Let's say you're installing a data loss prevention agent on every one of your laptops, right? We don't want people to upload sensitive IP to websites where we would just lose it. If you buy the tool and on paper, you bought the tool, you're covered, you're 100% secure. But anybody who's bought any cybersecurity tool knows buying the tool only means you have shelfware. It means nothing more than that. You have to go a couple steps deeper. So the the first metric I like to use is called coverage. And just think if I have an agent for DLP, is it on 20% of the endpoints or 100% of the endpoints? Not only is it on, but is it actually on the latest version? Is it actually not blocked by a firewall? Is it uh actually running on that application? How do we measure that coverage of those applications? And this is key because by the time you have a firewall, by the time you have Intune running, you know, MDM, by the time you have you know CrowdStrike doing an EDR, you're actually going to figure out that between your six tools and agents on each one of those endpoints, you have a totally different number of count of how many endpoints you have. So you even have to figure out what's the real number, because that one tool alone won't tell you that true number. Yes. The second thing that I always like to do is what I would call a utilization metric. And I'll give you maybe a different example. Let's say you have a WAF, a web application firewall in front of your application. And let's say you could turn on 10 rules for the OWASP top 10. Did you turn on all 10? Or did maybe it turned some of those off because it breaks the app? And you know, I learned this lesson when I was at a large bank, which is they turned a lot of them off. And so you think this firewall is working, but it's actually a Swiss cheese firewall with lots of holes because, well, if we had the SQL injection on, it would it would stop the website from working. So we turn that off. So now this CISO doesn't know it's not deployed everywhere and has coverage, it's actually you know poorly implement uh configured and is missing some of the utility. And that is the key. You have to know both of those things to know when you have paper compliance and real you know security in your organization.

SPEAKER_02

Yeah, and you know, if there's one takeaway for leaders in the first part of this conversation, I think it's that more security activity is not the same as more security effectiveness. You know, I think we've talked about is without clear threat framing and honest thinking about how your your controls perform, extra spend is just going to amplify confusion instead of reducing risk. Okay.

SPEAKER_01

I love that point. And and I think one of the things that we do wrong in cybersecurity is if we go in and we say, Hey, I have 20 controls, and let's call it the CIS top 20 or CIS 18, then we say, well, going to 500 controls must mean better security. But in reality, if you didn't actually increase your resources, your tools, your processes, all you did is dilute it and you made yourself even less effective at more controls. And and so and and and not all the controls are equal, right? I'd rather do the 10 most important controls amazing than do 500 controls poor, right? And and so that I think is the important thing of how do we focus on where the real material impact is at.

SPEAKER_02

Yeah, and I mean, and and and in any of those frameworks, CIS, NIST, whatever, you can implement there are certain controls you're never gonna want to implement in your environment because for your environment, they are gonna break it. And the last thing you want to do is say, we're 100% compliant with CIS level one for Windows 11. Uh maybe not. Do you have coverage? Sure. Can you explain it? Sure. But there are going to be controls you're never going to want to implement. So you very valid point. This episode is brought to you in part by Cybersec Media, a cybersecurity media and community platform built for practitioners, leaders, and innovators who want sharper conversations about the human, technical, and operational realities of security. And if you want to be part of that community in person, get your tickets now for CybersecCon, happening September 15th and 16th, 2026 in Houston, Texas. Join cybersecurity leaders, practitioners, researchers, and innovators for two days of insight, connection, and actionable strategies. Secure your spot today at cyberseccon.com. That's cyberwithout the e at sec.com. So I want to move from the conceptual distinction to what leaders can actually do with it. You know, as we always say, most organizations can measure security metrics, ticket counts, tool coverage, vulnerability volume, project completion. But those metrics don't always tell whether decision quality, resilience, or even risk posture is improving. So if Ross, if a leadership team wanted to know whether its security spend is producing better outcomes, what would you want them to measure differently than they currently do?

SPEAKER_01

I think the first thing is I want them to measure, right? I don't even think we're doing that. And I'll just give you the example of hey, we buy 80 different cybersecurity tools in an organization. We buy email security, data loss prevention, endpoint protection, firewall sim. The list continues, right? What's the metric behind each one of those 80 tools that you measure to show me that's producing value? Because I mean, is it the number of alerts? Well, we can crank the number of alerts up. That's probably not the real answer. Maybe it's the number of attacks stopped by this traditional tool. That might be a really good metric. And then once you dive into that metric for each one of those tools, maybe you have to have a clarifying metric that says, is this the only tool that would have caught this attack? Or is it a redundant tool? Maybe it's one of five tools that catches the same thing. And now you don't actually need all five tools. Maybe you only need two of the tools that cover all of those same things. So I think that's the first thing. Peeling back every tool to say, how many attacks last year did this tool stop? And not everything is is going to stop an attack. Like a GRC tool, probably not going to stop an attack. But I think that's a really good one for a lot of tools.

SPEAKER_02

Yeah, and I think to the point that you're bringing, and this is definitely something that we're we're grappling with and trying to help with at CyberCog Labs, is you know, the idea that there's the tools that you buy because they're they're of price concerns or whatever, because they're the they're the the cheapest price tool out there that will do what you need. But there's a whole different set of analysis that needs to be done is is this the right tool for my organization and for the goal I'm trying to achieve? Because while, yeah, you may the tool that may be the best for your organization and is going to have the highest level of adoption may not necessarily be the cheapest tool, but it's going to, in the long run, save you money because you're not going to have to buy five different tools to try to get it to work. So I think your point is really well taken. And you know, the practical shift here really is that you know, governance, tool management, tool sprawl, it's not just about approving a budget. It's not just about saying, how can we save as much money as possible? It's about creating shared language for the threats, assisting us, assigning ownership clearly, testing what safeguards are going to work when you know the pressure is up, and funding what improves decisions and improves approaches rather than simply what looks modern, what's the new cool, shiny tool. Um, and you know, for CISOs and GRC leaders, that can that changes, you know, what shows up in risk committees in the board reporting and roadmap prioritization. Um, you know, and and and I think everything you've said really uh encapsulates that. So, you know, given everything we've discussed about cyber spending, about threat framing, safeguards, governance, I'm gonna close with the question that we ask all of our guests on Cyberminded. What is one place where the cybersecurity field needs to slow down and think more carefully?

SPEAKER_01

Honestly, I think it is compliance. I think if you look at the way we do compliance, what do we do? Every year we add more standards, more controls, more things to ask, more things to fill out because there's a new attack this way. And we never really take anything off the plate. And so, you know, there's a lot of standards that go in and say, hey, are you doing encryption at rest uh in your cloud data centers? I mean, at face value, that sounds kind of smart until you realize that look, I don't even have access to this AWS facility that has my data. It's probably being striped and mirrored across dozens of machines. So good luck. Even if they image one machine, you know, it's it's it's fragmented, it's it's encrypted by their standard, not my standard, right? So a lot of these controls and things we've asked for decades are not as relevant as we think. And and I'll just give you another example. This one blows my mind. You look at most of the standards, and you say, What do we do about phone management? They care more about you having a policy on vulnerability management than are you actually patching in five days or 30 days or whatever that number is. So most of the standards outside of things like PCI, you could go in and say, I patch in 300 days and still meet that general control as long as you have a patch management program. And I think we all know that a 300-day patching program is just not going to do well. And so I think that's the problem is like these standards that were written a long time ago, like SOX, SOX was written, you know, in like 2002, if I remember right. And that's the one everybody has to do as a publicly traded company. And just think there were no mobile devices, cloud wasn't invented then, AI wasn't really as popular as is today. Yeah, there's important controls there, but how much has changed and how much are we still you know dragging legacy controls into how we build our programs?

SPEAKER_02

Yeah, I have to be careful uh when whenever you bring up socks, because one of the uh cases, one of the obviously very famous uh corruption uh corporate corruption cases happened very close to where I'm very close to where I am right now. And the last thing I want is the uh Blackhawks landing at my house and saying you're talking bad about a former company uh that funded the baseball stadium and a number of other things here. Um uh and and yeah, so I'm gonna I'm gonna I'm gonna let you make the comment about that, but I'm gonna leave that one as is. I, you know, and and I was laughing earlier because you were talking about, you know, what what I'll call vanity metrics, you know, or vanity things. Um, and you know, the one that always that always was funny to me was, you know, I'd get asked as you know, deputy cease of grc was was what's our what's our fish simulation fail rate gonna be this quarter, do you think? And I go, Well, what do you want it to be? Because if you give me the number, I'll make sure we hit it. We're either above or below wherever we need to be.

SPEAKER_01

Because the easy exercise or the hard exercise, let me know which one to pick for next month.

SPEAKER_02

Yeah, like like if you want a specific number, I'm I'll hit it every time. I'll knock that number out of the park. Uh, is that going to show whether or not we're secure? That's a whole nother story. So, you know, today's conversation uh challenges a familiar cybersecurity assumption. If the budget grows and the control stack grows, well then security maturity must be improving. I think Ross has helped us examine the deeper issue beneath that assumption. You know, do leaders truly under threat, understand the threats they're prioritizing? Are they prioritizing threats in the first place? Uh are the what safeguards are you funding? Um, and what organizational conditions will determine whether or not those safeguards are going to work? You know, the human side of cybersecurity is not just about user behavior, it's about leadership judgment, governance, design, incentives, communication, the quality of the decisions sitting underneath the controls. As Ross said, you know, we can write a policy that says thou shalt not, andor thou shalt do this. And that policy may meet what our company can do, but is that really creating a secure environment or are we doing it for compliance's sake? Uh, my thanks to Ross for joining the conversation, to CyberCog Labs and Cybersec Media for supporting the show. Um, I encourage everybody to check out the show notes. We're gonna have a lot of links to all of the things that Ross is doing right now, uh, specifically around some of the open source things that he's released. Follow him on LinkedIn if you're not. He's always out there talking about things. He's a great guy. Uh, I will also share if you're a CISO or a deputy CISO. Um, I'm gonna give Ross just a minute here to share a little bit about what's gonna be going on out in Vegas at uh Black Hat or Black Hat adjacent. Um so Ross, you want to share a little bit about what's going on that Thursday?

SPEAKER_01

Yeah, so it's it's actually gonna be on Monday, August the third, and we have something called the CISO retreat. And so if you're a deputy CISO or a CISO and you want to learn from some of the world-class instructors, this is the place for you. The whole thing is designed on this idea I learned from Boy Scouts, which is you know, you can ask a bunch of boys to plan a camp out and they will come back with nothing in 30 minutes. Or you can say, here's a template that says who's bringing in, you know, meat, drink, water, veggies, planning certain things, and they can fill that out very, very fast. So we're having world-class experts share their one-page templates of how they built the cyber threat intelligence program at a top five bank, how they, you know, think about things. And Dr. Dustin Sachs is also gonna be sharing some of his expertise too. So I I really think this is gonna be the one place where if you're sick and tired of going to conferences because you didn't learn anything, come to the CISA retreat. I promise you're gonna learn something that you can take back to your team and do amazing things with.

SPEAKER_02

Yeah, it's definitely world-class experts also starring, um, all also featuring, you know, and then there's those of us in the also featuring uh section of things. And, you know, it's interesting that you bring up the, you know, the connection to the Boy Scouts because um I I just released an article on LinkedIn a couple weeks back that actually discusses you know a connection to some of the some of what Boy Scouts and Scouts now um, now that it's uh kind of reimagined as a uh co-ed uh opportunity, um, some of the the behavioral science behind some of the stuff that they do around merit badges and what have you. So check that out. That's on uh my LinkedIn. It's also on uh Cybercog Labs LinkedIn. But as always, until next time, look beyond the controls and pay attention to the human side of cybersecurity. Thanks, everyone. We'll see you again on the next episode.

SPEAKER_00

This has been a cybersec media production recorded in partnership with CyberCog Labs. Cyberminded is hosted by Dr. Dustin Sachs. It's directed by Bill Brenner, produced by Lauren Andres, and edited by Ivan Basconcillo. The views and opinions expressed in this show are those of the speakers and do not necessarily reflect the views or positions of any entities they represent. This show is for informational purposes only and does not render or offer to render personalized advice. Subscribe now so you never miss an episode. You can find all our podcasts, articles, blogs, and conference talks on cybersecmedia.com. That's cyberwithout the e. And follow cybersecmedia on LinkedIn, X, Instagram, Facebook, TikTok, and YouTube. You can keep up with our conferences by following us on LinkedIn, X, Instagram, and Facebook at Cybersec Events. And you can learn more about our events or buy tickets at cybersec.community slash cybersecurity.