Access the full text logs of this transmission for compliance and review purposes.
00:00:01:06 – 00:00:07:19
Actual
Welcome to Status Secure, the weekly Cyberthreat briefing for executives who refuse to operate in the blind.
00:00:07:21 – 00:00:20:08
Actual
Hosted by the watcher six collective, uniting former Army Special Forces and Naval Special Warfare communications operators alongside an industry leading CISO nominated for cybersecurity. Woman of the world.
00:00:20:10 – 00:00:27:05
Actual
We cut through the noise and give you the operational intelligence you need for mission success in a hostile digital environment.
00:00:27:07 – 00:00:28:10
Actual
The enemy is listening.
00:00:28:13 – 00:00:32:03
Actual
Is your status secure?
00:00:32:05 – 00:00:54:05
Actual
Welcome to Status Secure. Today we’re covering the landmark child safety ruling against Meda, a nearly billion dollar warning about what happens when bad actors are allowed to operate on your platform. And what it tells us about the ethics and integrity of the systems we’re all on now, building on top of I. Then we’re getting into the big one, the historic wave of layoffs and what that means for insider threats.
00:00:54:05 – 00:01:09:18
Actual
And this is a briefing for both sides and for the companies that have to defend against it, and for the people who’ve been let go who shouldn’t become it. CISO let’s start with Metta. Walk us through this ruling because the headline is a dollar figure. But the security story underneath is bigger, right?
00:01:09:20 – 00:01:33:04
CISO
Yeah. So, you know, this is this is the biggest ruling, you know, ever so far. I mean, the courts are not taking this lightly. So a New Mexico state judge ordered Metta to pay an additional 567 million for failing to warn the public about the dangers its platform poses to children. You know, this is the largest child safety fine against any company.
00:01:33:06 – 00:01:56:18
CISO
And on top of that, they were already he already had 375 million ordered in March. So this is comes to 942 million that now $1 billion. And I just saw that Europe just issued a fine on merit as well. So you can see how this is costing them. You know it’s starting to cost them. Right. So the judge called them a public nuisance.
00:01:56:20 – 00:02:18:03
CISO
Right. Comparing this to like, polluted, you know, a factory that pollutes the air, right? The air that people breathe. And it says that it’s advertising content as the product, the harm and exploitation of children as the pollution. Right. So from a security standpoint, you know, the quote is that bad actors were able to use this platform for illegal, harmful purposes.
00:02:18:03 – 00:02:50:21
CISO
A child exploitation, trafficking, predatory contact, you know, and a company’s response detect and remove them. You know, I can tell you from personal experience, I had someone steal my pictures and then create another account, and I contacted them and they would not remove the other account. Right. So but because his position is this they disagree with the ruling and they say that that it works to keep people safe and has been transparent about the challenges of identifying and removing bad actors and harmful content, and that it stands by its record of protecting teens.
00:02:51:00 – 00:03:09:19
CISO
Keep it neutral. We put both sides right. So that’s, you know, I mean, of course, of course. The company, of course, meta is going to say that, you know, I would say that a lot of companies do the bare minimum, but the bare minimum is not good enough anymore. Okay. And this is fundamentally a trust and integrity failure.
00:03:09:20 – 00:03:36:17
Actual
I got it. Yeah. And that’s the thread we want to pull on. So because ethical use of AI is one of the biggest conversations in security right now. At least that’s what you’re telling me too, right from the conversations you’ve had at the Blackhat conference. And so if the meta case is about integrity at the platform level. Walk us through what that means for integrity at the data level, because in AI, if you can’t trust the data, then you can’t trust anything the system tells you, right?
00:03:36:20 – 00:04:05:09
CISO
Yeah. Security researcher in the CIA triad. Right. Confidentiality. Integrity, availability. Everyone obsesses over confidentiality. Integrity and and integrity is the one that’s quietly breaking in the AI era. You know, fabrication, drift, hallucinations. These are all problems with AI. It even has biases. Right. AI has bias. That’s there’s a lot of integrity concerns with AI because the system tells you what’s true or it tells you nothing.
00:04:05:11 – 00:04:35:03
CISO
It does not make something up to look complete. So yeah, it starts it starts to it’s it doesn’t give you context. Right. And the reason that it matters is because organizations are wiring AI into decisions. A model that hallucinates 820 indicator and attribution or a fact is an integrity failure that propagates into every decision downstream. So if your AI tells you something, right, that that you know, that looks like it’s true, right?
00:04:35:04 – 00:04:58:03
CISO
But when you look deeper, like you have to look where the sources are, where is it getting that tech? You know, that that fact from. Right. And it’s not it’s actually not the complete picture. You know, you may be making decisions based on AI. That’s incorrect. So the four rules of so the four things that you want to kind of stay, you know, look for is, you know, every record carries its source.
00:04:58:05 – 00:05:17:19
CISO
Again, I just mentioned, you know, for saying that seeing timestamps and deciding count, that means you tell the AI, hey, I want I want you to tell me where you got this information from. Right. That’s that should be part of your part. You know, where did you get this information from? When was that information last updated? Nothing invented to fill a gap where there’s no data, the system shows none.
00:05:17:20 – 00:05:33:15
CISO
So tell it. Hey, if you can’t find anything, don’t make it. Don’t. Don’t create something because I wants to make you happy. Just so you know that it. If you give it a if you give it a task or a question, it will give you an answer because it wants you to be it wants to satisfy the request.
00:05:33:17 – 00:05:53:05
CISO
Okay. And then, you know, deterministic scoring score is great. And it comes from stated inputs with fixed weights, same inputs, same output every time. If you ask the same question multiple times and you get different answers, you know that you know you need to do your own research there, right? But you should be able to get the same answer every single time.
00:05:53:10 – 00:06:23:19
CISO
And with every single AI you’re asking, hey, I sound like so. So you know, a lot of what people are doing now is they will ask, they will put a question into multiple multiple eyes, right, to see what the results are. Okay, I summarize it. It never utters no indicator, attribution relationship or range from a language model. What this means is that, you know, it gives you a summary of stuff to make it easier for you, but it should never be the author of content that’s going out.
00:06:23:21 – 00:06:40:13
CISO
It needs to always be a human in the middle. Cool. So those are the four things that you know, everybody should be doing with their their AI usage to ensure integrity. So trustworthy AI isn’t about a smarter model. It’s about discipline on the data. So the machine can’t lie to you even by accident.
00:06:40:15 – 00:07:02:18
Actual
Yeah, and you know what? This kind of reminds me of is when blogging was super popular and in sort of the academic circles. Right. Like in college grad schools, and you’re writing papers and citing sources there, there are were people who would cite information because they found it. And it’s kind of like what we discussed on the last episode about confirmation bias.
00:07:02:20 – 00:07:27:15
Actual
They may have found information online that agrees with their perspective and point of view. And so they cite that as a source, like an academic source or a scholarly source. And it’s just some random person’s blog, right? Like it’s like, how accurate is that? It’s just some guy, some girl talking, you know, just their opinions. And I feel like that’s it’s that’s like that was then and then now we have all this kind of well, we’ve talked about the whole TikTok social media.
00:07:27:16 – 00:07:51:00
Actual
Everybody’s got a voice now and everybody’s an expert now and everything. Everybody says almost as long as it fits into your confirmation bias is a grounded source. And it’s like AI is doing. That is what it seems like, right? It’s like AI is just pulling at all these finding the information, like you said, to satisfy you, finding the information that will give you your confirmation bias, if you will, maybe regardless of the academic source of it all.
00:07:51:04 – 00:08:13:00
Actual
And I think, you know, that’s where we’re getting into trouble, right? And that’s where it’s kind of like how how trustworthy is some of that information. It’s kind of like anything else. Yeah. That is something that we’ve been dealing with for a while, just in a different a different way of accessing it. And so for those listening, what are like what are three things they could do this week to keep both their platforms and AI on the right side of trust?
00:08:13:00 – 00:08:13:19
Actual
Well.
00:08:13:21 – 00:08:39:16
CISO
The first is know who’s operating on your platform, right? When you run a consumer platform or an internal one, you’re accountable for the bad actors inside it, not just the hackers outside it. Detection and removal of abuse is a security function, right? Look at what happened to matter. You know they’re accountable for that. Whoever is on their platform, you put it, you know, your customers on your platform, you’re inside, you know your internal users on the platform, you’re contractors on the platform.
00:08:39:22 – 00:09:01:14
CISO
You’re all you’re responsible for all of that, okay? All of all the users on there and how they use it, because you’re controlling the platform. You put the you put the guardrails in. Basically make sure your guardrails, you know, have been reviewed and are appropriate. Demand a provenance from your AI before you trust an AI output in a decision as to where the underlying data came from.
00:09:01:14 – 00:09:21:03
CISO
I tell you, if you if you have a private like Lem and for you and a lot of large companies. But if you’re a smaller company again SMB, you know, you’re not going to be creating your own Lem. Right? Because that’s a lot of work. You’ve got to train the model to utilizing, you know, public and public on Amazon.
00:09:21:05 – 00:09:43:18
CISO
So they’re looking at all the data. And there’s been way how long is the internet in and have been up and running now. Right. So there’s you know what’s the old adage. Yeah. Garbage in garbage out. Right. So you gotta you gotta remember that AI is not an authoritative source, okay? It’s just pulling stuff from the internet and giving you a summary of it.
00:09:43:20 – 00:10:10:18
CISO
Yeah. So, you know, make sure you know where it’s pulling that source from. Yeah. It might. Your AI usage policy now defines sanction tools. What data can never go into them. And the integrity standard your systems must meet before your people or your vendor is set that default for you. I mean, I’ll tell you, I had somebody who they they wanted to build an AI, an AI assistant for a customer service, and they put it out for their customers.
00:10:10:20 – 00:10:28:07
CISO
And then their customer started asking questions that they never thought a customer would ask, right? Things like, how do I build a bomb? And they were like, they were shocked that that happened. They had to take it down. But you see, they took it down. They didn’t just leave it up right. And then they had to reassess. So that’s your that’s your responsibility.
00:10:28:12 – 00:10:33:16
CISO
If you’re going to, you know, if you’re going to build some type of AI tool.
00:10:33:18 – 00:10:49:05
Actual
Got it. And then, you know, before we move on to our next topic, which is something you you’ve been wanting to talk about as well, is there anything else on the topic of meta and satisfying and this, this, and why write why it’s happening? Is there anything else on that that you wanted to discuss?
00:10:49:05 – 00:11:20:17
CISO
I wanted to say, you know, that’s it’s been a big topic for a long time, but the quartz quartz are always slow. But they are finally saying enough is enough. I mean, I can tell you if you’re in Europe, if you’re if you’re in Europe and in other countries, they take their child safety very seriously. They don’t allow, you know, their children like their children under certain age to have access to certain tools, certain, you know, information like here, you know, you know, here in the US, we’re starting to look at them like very seriously.
00:11:20:19 – 00:11:36:21
CISO
Right. And so if you’re an if you’re a company that has a product, you need to understand that unless you’re taking, you know, really strong measures, which was never required before, it is coming. He says. Better for you to be ahead ahead than behind. Okay.
00:11:37:02 – 00:12:02:06
Actual
Got it. Yeah. I mean, meta was, the problem was trusting the wrong actors inside the platform. AI’s problem is whether you can trust what it tells you. And the other version of that same problem is the one sitting inside every company right now. The people, right, that you’ve already given that information, that IP, you know, whatever, whatever the the secret sauce of your, your organization is because trust isn’t just a data problem or a platform problem.
00:12:02:06 – 00:12:21:14
Actual
It’s also a people problem. And right now there’s this wave of layoffs. Companies are laying off hundreds and thousands of people, and every one of those departures is a potential insider threat, whether anyone treats it that way or not. So let’s kind of get into that topic. Give us the foundational walk through what, what I guess let’s kind of back up.
00:12:21:14 – 00:12:29:04
Actual
What is insider threat? What’s an insider threat program, and why does this layoff wave sort of, I don’t know, make this worth discussing now.
00:12:29:04 – 00:12:54:14
CISO
Yeah. I mean, you you know, this has always been around right. So insider threat is the risk that someone with authorized access, is it knowingly or not, to harm the organization’s systems data or operations? I mean, it says authorized, right? So they’re not bringing in the authority inside. And that’s the you know, and that’s really the concern, right, that, you know, the bad actors are usually I employee disgruntled employees.
00:12:54:14 – 00:13:22:05
CISO
All are trust failures from inside the perimeter. Well so you know CSA in their 2026 report, they said that negligent insiders like that means they have the access. They’re just careless, right. And they create incidents. It’s a roughly about 53% malicious in that insiders who are intentionally doing some harm, you know, they have a like they got mad at their manager or they don’t like, what do they, you know, the direction the company is going, right?
00:13:22:07 – 00:13:48:08
CISO
So they do something malicious, right? They do something with intent. AI is about 27% and compromised exploited inside. So this is where we’ve talked about stolen credentials right through phishing and other means. This is roughly about 20%. So you can see I mean the the insider that’s 53% of incidents are caused. But you know by careless insider that’s that’s a lot.
00:13:48:10 – 00:14:24:14
CISO
Yeah. Most insider is not malicious. Right. And you know, as stated by the report, negligence dominates by volume. Right. So I would say malicious inside the breaches average around 4.9 million. Right. Higher than the overall breach average. Basically what that’s saying is this like, you know, you need an insider threat program, not a tool. You need a combination of policy access, governance monitoring, behavior analytics, right operating process and cross-functional ownership from HR to IT to security working together.
00:14:24:16 – 00:14:48:10
CISO
Right. Because roughly 80% of organizations now have an insider risk management program. But with detected, you know, detection lies, around 90% of security leaders say insiders are it’s harder or harder to detect than external hackers. The problem is some of it is over permission, right? People are over permission. So they do things that and they don’t realize that what they’re doing is creating an incident.
00:14:48:12 – 00:15:11:02
CISO
Okay. You know, so you’ve got to really build that. The other thing is people, you know, I mean, if you only have training once a year, you know how you know how how well, I have folks like remembering what their it’s you know, what they’re supposed to do, right. Or, or what they’re supposed to report. So like, if I, if, how many people say, hey, I have I have too many permissions here, can somebody take it away?
00:15:11:04 – 00:15:32:19
CISO
Yeah. Not right, not very right. But they should the people should be doing that and that’s part of training. But again, if they’re only trained once a year well that you know, people don’t remember unless it’s unless it’s there all the time. So the average inner cost of insider risk hits 19.5 million per organization in 2026 I from 17.4 million the prior year.
00:15:32:22 – 00:15:48:06
CISO
Right. So it’s roughly so North America one’s highest at roughly 24 million. That’s a lot of money. There’s a lot that, you know, that can be that actually can you know that if companies run their insider threat programs, well, they can mitigate and it won’t cost them.
00:15:48:08 – 00:16:04:21
Actual
Yeah, yeah. And so, so insider threats been a problem. We know about that. Right. Like what’s an easy example to give. You know, you have like a company like Lockheed Martin or whatever they are creating like the next jet for the Air Force. And then all of a sudden, six months later, China has a jet just like it.
00:16:04:23 – 00:16:24:12
Actual
How weird. Like, how did that happen? And so it’s it’s something we’ve seen before. And we all know that China is really good at reverse engineering. Other people’s technology. That’s kind of like their shtick, you know, and ours is like entrepreneurial and innovative and creative as Americans. So we make and then they just copy and reverse engineer. But how are they getting the information to copy and reverse engineer.
00:16:24:12 – 00:16:42:08
Actual
And that’s in a normal that’s like a stuff like that happens on the normal day to day basis. So now we’re in this, this time of like, I don’t know, maybe people are disgruntled, right? There’s maybe a more than average amount of layoffs, maybe due to AI. Right? In the tech sector. So you have people with access.
00:16:42:08 – 00:16:52:21
Actual
They’ve had access to this IP. Maybe they weren’t an insider threat problem before. So what’s kind of walk us through sort of that what’s dangerous about the situation we’re in today.
00:16:52:23 – 00:17:20:09
CISO
So you know, I mean it’s it’s scale. So roughly 245,000, about ten, 46,000 tech employees were laid off across 783 companies in 2025. That’s the operating load. It and security have to get right often fast. And but I mean, that’s a lot of people, right, who are who are probably sitting around being disgruntled, right, who have information and are trying to figure out what to do with that information.
00:17:20:14 – 00:17:46:11
CISO
Right. You know, the the tax rate team found that 70% of insider threat incidents involved employees who had already given notice or been terminated. Data theft is the primary objective. I mean, that’s not uncommon, right? You’ve you know, you’ve either you’ve been laid off or you’ve been told that, you know, you know, you’re terminated or you’ve given notice because of something happened.
00:17:46:15 – 00:18:03:19
CISO
And, you know, the first thing people do is they think, well, hey, I’m just going to take, you know, I’m going to take things that I worked on with me, right? Because, hey, I worked on it. That was that belongs to me. No, it does not belong to you. It belongs to the company. Right. And so so you cannot take it.
00:18:03:19 – 00:18:19:09
CISO
But a lot of people feel that I like they’ve been at the company a long time. They did all this work for the company. And, you know, this is their work. So they want to take it. Most insiders who steal IP do so within roughly 30 days of resigning. The window around departure is the highest risk period, right?
00:18:19:14 – 00:18:40:05
CISO
So when you have both layoffs, this makes it worse. Yeah. Messed up wording. You know a well a manual process actually access gets missed HR IT security ups in silos. The bigger the layoff the more likely something slips. Hey because if you have 1 or 2 people you know, you can monitor them pretty easily when you’re laying off like 100 people.
00:18:40:05 – 00:19:03:14
CISO
200. Right. You know, manual manual monitoring of those folks is not is not going to work. There’s too many you need automated methods for monitoring mass are going around speed. So they don’t just create access risk they create grievance. A normally loyal employee becomes a disgruntled one overnight. The human factor is now in play. This is I mean that’s that’s human nature.
00:19:03:16 – 00:19:18:19
CISO
Okay, I’ve seen that. I’ve seen a really great employee get terminated. And the next thing I know, I’m hearing them complain and just just, you know, just say how company’s tower. One day the company was awesome. The next day the company is the worst place ever.
00:19:19:00 – 00:19:37:16
Actual
Yeah. So what are some things that maybe what are the handful of areas where you know, there’s like cracks in that, that process, at least within the companies control. Right. What are those areas where, hey, you’re you know, I’m we’re notifying you you’re being terminated to the day you’re actually, like, not here anymore. Where are those kind of spots?
00:19:37:16 – 00:19:42:14
Actual
I guess that you’ve you’ve seen the, the cracks in in terms of this conversation.
00:19:42:16 – 00:20:09:08
CISO
Yeah. So I mean they’re the main thing the main off boarding process is to disable email. Right. That that was like traditional, but but disabling the email isn’t I mean isn’t enough anymore. And your, your employees have access to a ton of SaaS applications, cloud apps, AI tools, remote systems, personal devices with data, you know, forwarding world API keys, I mean, share credentials.
00:20:09:08 – 00:20:26:18
CISO
I mean, the list goes on and on now, right? Especially the longer they’ve been in a company, the more access they have. Right? So the retained and I can tell you a lot of companies don’t do a great job at let’s say I’m at a company and I move from one team to another team, and now I do something different.
00:20:26:20 – 00:20:42:06
CISO
I still have the same patches I had before when I was in the old team. Right. And and that hasn’t been removed. That happens a lot in companies and there’s a reason for it. That way I can quit. I can continue to support the old team if I need to. Right. If they need me to until they find someone.
00:20:42:08 – 00:21:03:12
CISO
But that could be a while. And then they forget. They forget I still have access. You know, 83% of former employees admit they still had access to at least one account after leaving. 56% of those admit they use that lingering access with intent to harm their former employer. That’s a lot. That’s a lot. Especially SaaS applications, right? Because staff, you can you can access that from anywhere.
00:21:03:12 – 00:21:26:15
CISO
You do not need to be in the company’s network to access that applications. Okay? 74% of managers do you see their company was negatively impacted by a former employee breaching security? You know, dormant accounts are also external attacker targets. A forgotten former employee log in is a compromised insider incident waiting to happen, and cyber insurance claims have been denied when the breached account belonged to someone who’d already left.
00:21:26:21 – 00:21:47:11
CISO
So, I mean, that’s an important key, right? You think? Oh, well, we have cyber liability insurance. Like, they’ll, you know, they’ll pay for the damages. Not if they and they will they will go investigate. Why did this happen? And if they find that it was an account from a former employee, they will pay because at was negligence on the company’s part.
00:21:47:13 – 00:22:07:15
CISO
It wasn’t. It wasn’t due to some malicious actor. It was due to negligence on their, you know, on the companies they have their process. So all forwarding has to be documented, immediate, centralized across HR, IT and security and come with a full access footprint, not a memory based checklist. I can tell you I’ve worked in big companies and they’re the worst.
00:22:07:21 – 00:22:16:02
CISO
You know, you would think that they would be better, but the bigger the company is, the more systems, the more complex, the harder it is for them to actually know all of the accesses.
00:22:16:05 – 00:22:34:19
Actual
Yeah, yeah. And you know and it’s important that and obviously we’ve this is you know, companies have known about this and it is an important topic to make sure that the, you know, to be aware of the insider threat problem and make sure that, you know, you’re paying attention to what could happen. And then we have the other side of this, which is the people that are getting laid off.
00:22:34:19 – 00:22:55:19
Actual
And so that’s something we wanted to touch on. And, you know, this happens all the time where people are great, like, they’re not bad. They’re not bad people, they’re not even bad at their job. And, you know, they get laid off sometimes and and that sucks. And depending on the situation, depending on your managers, maybe your supervisors, whatever, this could make you upset, which is completely fair.
00:22:55:19 – 00:23:20:19
Actual
And understandable. And, you know, and so it is something to think about, you know, before maybe the idea comes in your head before doing something, you know, it’s it’s you have a choice. Do you become do you now become the threat when you know. And so it’s I guess what we’re getting at is like, hey, you know, don’t don’t like information because you’re mad, you know, maybe give yourself that window to be to allow your emotions to do whatever they’re doing, but don’t take actions you might regret later because of it.
00:23:20:19 – 00:23:39:01
Actual
And this can follow you, too. You know, you spent your career being a person who’s responsible for protecting data, and that shouldn’t just stop or disappear because you got let go. And so that’s that’s the side we want to kind of touch on too, is going, let’s not become the threat. You know, let’s not become the bad actor.
00:23:39:04 – 00:24:00:16
Actual
And you know, so and this is something you brought up while we were talking about this, this episode and you specifically actually, when we first started talking about this topic, we do the majority of what you wanted to talk about was this side of things. So and you’ve seen this, so why don’t you go ahead and and talk to us about, you know, your thoughts on on being the individual in this situation.
00:24:00:17 – 00:24:29:09
CISO
Yeah, I mean, I, you know, like I said, I’ve seen people get upset and angry, right? I mean, and it’s valid. You know, you have feelings. Everybody has feelings, you know, and and you can be upset about it. Right. You can be upset about it. But the action is what’s important. You know, don’t take any like don’t take action that out of anger like that is the worst because you know, you regret it because things like that, you think you’re going to you’re good, you’re going to show them right.
00:24:29:11 – 00:24:47:04
CISO
But in the end it’s only going to hurt you. You know, you are on the other side and you know, like when they find insider threats like that or, you know, people retaliating, there is no we feel bad for you. We’re not going to take, you know, we’re not going to call law enforcement. We’re not going to, you know, take you to court.
00:24:47:04 – 00:25:09:02
CISO
There is none of that. There is. We we discovered this. We’re going to now take you to court eight, and that’s going to be on your record. And what is a moment of anger now turns into a lifetime of, you know, it’s hard to get a job when you have a record that you, you know, that you retaliated against an employer because they let you go.
00:25:09:04 – 00:25:19:21
CISO
Companies have to let people go. Right? And so just keep that in mind. I don’t like to see good people make mistakes. And it happens. But don’t don’t let it be you. Yeah.
00:25:19:23 – 00:25:42:06
Actual
Yeah. And that’s the human side of, of, you know, this conversation and it matters. You know, unfortunately the companies, they still have to plan for this. Unfortunately, sometimes economic plays a role. Economics are just just whatever the business is at that current point in time, how whatever the market’s doing, who knows? You know, sometimes you have organizations get put into a pinch and they don’t want to let people go, but they have to.
00:25:42:06 – 00:26:02:09
Actual
And so we just, you know, let’s just not like you said, I like what you said about not taking action while you’re in that that state of mind, that kind of the frustration in that anger, the hurt or whatever it is. And so while, you know, we’re here now, we’re at the tail end of this, let’s discuss our marching orders for those that are listening that this maybe relates to.
00:26:02:14 – 00:26:15:12
Actual
So we covered the matter ruling, talked about the AI integrity. We covered insider threat, the layoff wave. So what are three things that every company should execute to close the gap this week, this month maybe this quarter.
00:26:15:13 – 00:26:40:03
CISO
Yeah. The front is 50 off boarding process right. You know you need to identify everything that people have access to. That’s really important. And how do you revoke those access. Right. Centralize when documents analyze immediate access revocation checklist covering the full footprint I hey don’t miss anything because that’s that one thing you miss is what’s going to be you know that’s it’s going to create the problem for you you know access review.
00:26:40:03 – 00:27:04:21
CISO
It’s a single control that would have stopped a meaningful share of insider threats. So you need to make sure that your access management controls are really strong. Second, stand up or formalize an insider risk program. Do it together with HR on it and security. Don’t don’t have three silos of, you know, looking for things. You know, you need to build a single cohesive cross-functional a program, okay.
00:27:04:22 – 00:27:28:07
CISO
Add behavior analytics on the high risk window around a pie chart. Again, just turning off the email is not enough. And then write an AI usage policy and set your data integrity standard. Okay. That’s it. That’s what our AI is. You know, the shadow AI stuff from the users. You know, that’s really important because you if you don’t have an AI policy, you can’t tell people, hey, you can’t do this.
00:27:28:12 – 00:27:59:23
CISO
They’ll be like, where’s the policy? Nobody ever told me, right? So you have to start with that, and then you have to put controls around, make sure that the policy is being being followed and that it’s at, you know, compliant with your own policy. Tie back to the executive accountability. You know, like what happened with meta, you know, I’m pretty sure like because they’ve been around for a long time, I’m pretty sure that they did not they did not have any policies around like integrity and and you know, and they’ve been and they’re on the forefront of AI.
00:27:59:23 – 00:28:22:02
CISO
They could have used a AI to help them identify, you know, abusive insider users on their platform, but they they they opted not to. Right. So again, you know, take a look at that okay. Take a look at that at your AI usage policy. Make sure you’re covering you know, ethical use. Make sure you’re covering, you know, data integrity.
00:28:22:04 – 00:28:37:13
CISO
They you know, they’re you’re training confidentiality integrity availability. Who’s it who’s it availability. Yes. And because it says availability doesn’t mean available to everybody. You know, it has to be available to appropriate, appropriate authorized users.
00:28:37:18 – 00:28:55:20
Actual
Well got it. Yep. So everything we covered today comes down to one word trust. So the meta ruling is what happens when a platform fails to control the bad actors operating inside it. AI integrity is whether you can trust what your own system is telling you. No fabrication or drift, no hallucination. An insider threat, the oldest version of the problem.
00:28:55:20 – 00:29:18:22
Actual
The people you’ve already trusted with the keys. The fastest growing version of that isn’t an outsider breaking in. It’s the people leaving your building. You know, a big layoff wave means more access to provoke, more grievance and play and a narrow margin for the off boarding mistakes that turn a former employee into a breach. Right. And we have the other side of this, you know, off boarding is a security function.
00:29:19:00 – 00:29:38:02
Actual
It should be treated like one. And anyone who just got let go don’t become the threat you spent your career protecting. Data like don’t stop being that person now. Redirect that energy into the next mission. So who you are doesn’t end here. And you know, when we were talking about this, it actually made me think. I was thinking about a conversation I had with my youngest son and his cousins the other day.
00:29:38:04 – 00:29:52:13
Actual
They had a little moment where they were kind of going at it with each other, you know, saying mean things to each other, and then one of them like, hit the other one. And in this conversation, it it was interesting because it was like, well, well, he did this or he did that and he said this and he said that.
00:29:52:13 – 00:30:11:08
Actual
And it’s like, the problem is now because you hit him like all the focus is now on you right now, it doesn’t even matter what anybody did or said because you kind of took it to that next level and you did something that you should not have done regardless of how you feel, regardless of like what someone said to you, all this stuff that doesn’t give you the right to put your hands on somebody, right?
00:30:11:08 – 00:30:29:01
Actual
And now instead of actually looking at what happened and going, you know what, you over here, person number one, that wasn’t cool. We shouldn’t do that in person number two, I get it. That wasn’t cool. What he did. But your response blah blah blah, whatever, right. Instead of having that conversation now it’s going well. Unfortunately, you you you put your hands and you hit him.
00:30:29:01 – 00:30:44:05
Actual
So like now you’re what we’re talking about and it’s almost like everything they didn’t said doesn’t matter anymore. Nobody cares because you did that. You took that bad action. It’s kind of how I feel about this. It’s maybe the company is wrong, right? Maybe you’re justified in the way you feel. We can look at that. People can look at that.
00:30:44:05 – 00:31:02:16
Actual
They can have a conversation about that. The as soon as you take that next step action of exposing data, stealing data, whatever it is, it’s all on you now. All the focus is on you, and now nobody’s gonna care about maybe how poorly were treated. Right now your your defense is gone and you’ve kind of taken it to that next step and taken actions that weren’t okay.
00:31:02:18 – 00:31:04:07
Actual
Yeah. Well we may.
00:31:04:09 – 00:31:12:12
CISO
Yeah. Well, you’ve turned it from, you know, agreement to a, like a, you know, a grievance over the company to a criminal act. Right?
00:31:12:14 – 00:31:32:08
Actual
Yeah, exactly. And it’s I mean, it feels good, right? Yeah. I will get back at them, but let’s just let’s keep our cool, you know? So. Yeah, you know, mission back to our ending mission success starts with closing the gap before someone walks out the door with with your information. Trust, but verify your own posture, fix your offering, stand up your insider risk program.
00:31:32:12 – 00:31:38:07
Actual
Hold your eye to the standard, execute the standard, and we’ll see you next week.
00:31:38:09 – 00:31:42:02
Actual
Mission. Success isn’t about luck. It’s about preparation.
00:31:42:04 – 00:31:45:03
Actual
You’ve heard the Intel. Now go put it to use.
00:31:45:05 – 00:31:52:13
Actual
If you need to verify your security posture. I’ve established a secure line at watcher 6.com/secure.
00:31:52:15 – 00:31:55:15
Actual
Go there to get the briefing the enemy doesn’t want you to have.
00:31:55:17 – 00:31:58:23
Actual
We’ll see you next week. Until then, keep your head on a swivel.