Fill To Capacity (Where Heart, Grit and Irreverent Humor Collide)
Podcast for people too stubborn to quit and too creative not to make a difference!Join visual artist Pat Benincasa in conversation with a riveting roster of guests to uncover extraordinary stories of everyday people. Listen as they share their quirky wisdom, unlikely adventures, and poignant life lessons! Fasten your emotional seatbelt for this journey of heart, humor and grit!
Fill To Capacity (Where Heart, Grit and Irreverent Humor Collide)
Digital Pickpockets and Ethical Hackers
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Is your inbox a crime scene?
Then comes an email. Urgent. Looks official. Right logo and right name. You click. The frantic call from a loved one. Needs money! The voice sounds right.
What happens when we can no longer trust what we see—or what we hear?
Certified ethical hacker and former U.S. Army Signals Intelligence Analyst Cheyne Taylor takes us inside a digital world where phishing has become super sophisticated, AI can clone a voice in seconds, and information we casually scatter online can reveal far more about us than we realize.
Be informed, not fearful. Hit play- and maybe share it with someone who needs to hear it. And hey—what’s one online habit you’re changing today?
Today's episode is brought to you by the Joan of Arc Scroll Medal, a beautiful brass alloy medal, designed by award-winning artist, Pat Benincasa. This uniquely shaped medal is ideal for holiday or as a special occasion gift! Visit www.patbenincasa-art.com
This brass alloy medal can be worn on a necklace, a keychain, dogtags, on a bag, or in your car.
Disclaimer: This post contains affiliate links. If you make a purchase, I may receive a commission at no extra cost to you.
Please Note: The views expressed by our guests do not necessarily reflect the views of the podcaster.
Follow me on Instagram!
Pat
Fill to Capacity where heart grit and irreverent humor collide. A podcast for people too stubborn to quit and too creative not to make a difference. Hi, I'm Pat Benincasa and welcome back to Fill To Capacity.
So nice to have you here. Episode 143, "Digital Pickpockets and Ethical Hackers. " Like an old time radio announcer, I'm gonna start Ladies and gentlemen, tonight's mystery begins in the most innocent of places.
Your inbox. It arrives at 9. 17 in the morning.
Urgent Your account has been compromised. Click here immediately. You stare at it Looks official.
Has the logo. Knows your name. What could possibly go wrong?
Everything. Welcome to the shadowy world of fishing. No fishing pole required.
It's spelled with a PH and the bait Is you. But wait, wait, wait. What's this?
A text from your bank. A phone call. That looks like it's coming from your doctor.
Or your boss emailing, Pat, I need you to buy six gift cards immediately. Oh, spoofing. The ancient digital art of pretending to be somebody you trust, and lurking somewhere in the darkness, the hacker. No trench coat .No dark alley. No need to jimmy the lock on your front door, because while we may sleep in houses and apartments We live online.
Our banking, credit cards, medical records, photographs, social security numbers, our entire lives Are sitting behind passwords like fluffy one two three And admit it, some of us have used Fluffy123 more than once. Okay. One reused password.
One convincing email. One innocent little click. And suddenly somebody you have never met is rummaging around in your digital life.
And now, artificial intelligence has joined the cast. That frantic phone call from your grandson. It may not be your grandson.
That voice sounds exactly like him. Grandma, I'm in trouble. Please send money.
But don't tell Mom. The emergency fake. But the money you send, that's real. And just when you think, fine, I will be careful.
I won't click anything. The giant mega companies holding our information gets hacked. Millions of names, addresses, passwords, and account information can wind up for sale.
On the Dark Web. The Dark Web. Like something out of Batman. No. Is it hopeless?
No, not even close, because every good mystery needs somebody who knows how the bad guys think And that brings us to the ethical hacker. My guest today. has spent his career inside this world, in the military, in defense contracting.
And now as founder of Black Heron Systems Group and Robot Gecko Labs. His security research division, focusing on emerging threats. He knows exactly how it works.
And he has dedicated himself to making sure the rest of us do too. Cheyne Taylor is a US Army veteran a former S I G I N T analyst, that's Signals Intelligence, and a certified ethical hacker, which means He has learned to think exactly like the people trying to get into your stuff. He's taken all of that and put it to work.
For us, anyone using a computer and senior citizens and veterans, people who have gotten a weird email and thought, wait, wait, should I click that? Cheyne Taylor knows better. And today, so will you.
Cheyne Taylor, welcome to Fill to Capacity. I'm so glad you're here.
Cheyne
Thank you so much for having me.
Pat
Okay, we gotta roll up our sleeves here. Lots of questions for you. Let's start at the beginning.
You were a signals intelligence analyst in the Army. What does that actually mean and what were you doing?
Cheyne
Correct. So, I was trained by the Navy. I like to say I've been trained by the best in this field, and basically, it was uh for lack of better terms, big brother.
So think of someone in the middle of nowhere in a tent with a bunch of radio gear listening into signals, intercepting fax messages, text messages, cell phone communication That's exactly what we did. Then we processed that and analyzed that with all sorts of other intelligence gathering material. whether that's uh geoint or geography intelligence, humint or human intelligence Elint, which is electronic intelligence, we put that all together and then form an assessment.
So my mission was on the SIGINT side
Pat
Now, I'm kind of curious, after doing that work, how did that shape the way you think about information and trust
Cheyne
So it really does make you think twice. It really does make you take a step back and really think, okay, how safe are we? And in this increasingly digital world and this fast-evolving world of technology, Are we truly safe?
Is our data truly safe? The answer is to an extent yes, but for the most part, everything is hackable. Everything is hackable.
When I got out of the military, I didn't get a job with AT&T because they knew what I did. Because they knew that I could possibly be a threat to them hacking into their systems. And I told them that I'm not really that big of a threat.
You know, it was something we did in the military, but it was for national security purposes. to make sure we can intercept communications coming from terrorists and other non-friendly hostile organizations.
Pat
Well that might a that might have put a crimp in your style. I mean, you know all this stuff, but you couldn't get a a job with ATT and communication providers. So when you left the military Where did your career take you next?
Cheyne
Oh, that's a great question. So I was stationed out in Hawaii. I moved over to California and just enjoyed a little bit of my twenties in in Southern California.
And when the 2008 housing financial crisis happened, I moved back to Wisconsin and got my degree. And then later on got my master's degree and decided to go back into technology. So when I got out of my undergraduate program, I started working for IoT companies, which is called the Internet of Things.
I've worked for software as a service provider, so many different technology companies, and that really thrusted me back into the technology industry. To more of a side that I really felt more passion in because when I was in the military, I always tell people I was cyber before cybersecurity became a buzzword. And it really is true because now the training for the people that are in the service now that did what I did. They're now in the cyber arm of the army.
Pat
What does it mean, cyber? What do you we don't know what that is. What is that?
Cheyne
Yeah, so cyber is a broad term that just describes cyberspace or cybersecurity. It's a it's basically a catch-all term for anything online or digital
Pat
Okay, you're heading in that direction. What made you decide it was time for you to build something on your own?
Cheyne
I ended up getting laid off about a month after I finished my masters. And I wasn't thinking about starting anything on my own. I owned a business out in Southern California.
And I wasn't sure if I wanted to get back into the business ownership side of things. But the job market was increasingly challenging and with AI really ramping up I noticed that the job market really became very stagnant in the Twin Cities and it made it really difficult after 2020, at the end of 2024. To really find a job.
I think I'd put in about a thousand applications and only received just under two dozen interviews. And it was extremely tough. And so I had talked to a colleague that I served with and a professor who was my program director in my master's program And the feedback was pretty much similar.
It was you've got an excellent background; you've got a diverse background of different technological concepts and skills. And To top that off, you've got an excellent education. Put that to use and start doing contract work.
Start doing some freelance work. And so I tried that last year and it's ramping up now in a great way. It started really slow last year just to get my feet wet into the consulting field.
And this year it's been really busy
Pat
What did you get your master's degree in?
Cheyne
Yes, so my master's degree is uh is an MS in information and communication technologies with a focus in cyber defense and computer networking.
Pat
You're a business owner now, right? Yes. Will you tell us about that?
Cheyne
Absolutely. I own Black Heron Systems and the Robot Gecko Labs subsidiary.
Black Heron Systems, it's an IT MSP, but it also is an MSSP. So An MSP is a managed service provider and an MSSP is a managed security service provider. But really, I call ourselves just an MSP for short because we do manage IT But we also venture into the cybersecurity side, since that's my background.
We're an IT and cybersecurity company focused on helping organizations build technology environments that are secure, reliable, and prepared for what comes next, right? Because I mean just this week alone, we've we had a handful of major cybersecurity breaches that are in the news. So we really try to prepare for what comes next with small and medium-sized businesses.
We provide managed IT services, network and server management. And of course, cybersecurity consulting and compliance support, along with security assessments, penetration testing, and cybersecurity awareness training. And we bring it all together on the operational side.
And on the IT side to really to take care of our SMBs, our small to medium-sized businesses a hundred percent. Of course, the Robot Gecko Labs is our cybersecurity research and innovation arm where we do a lot of AI research on how to use AI in an offensive manner, but only an aspect of, okay, we know how it's being used in the offensive manner. How do then can we defend against it How can we defend against AI attacks?
Which have been happening even before ChatGPT became a thing, but they're becoming rampantly more used now And so we do a lot of AI research, malware analysis, digital forensics, threat intelligence, and cyber defense research.
Pat
Sounds like Cheyne that you have to be a master digital chess player.
Cheyne
Absolutely.
Pat
You have to anticipate what's coming down the digital pike. Which means, boy, you'd have to be exploring a lot of different venues to be ready for them.
Cheyne
I'm at the point where I need to start carrying a second phone. Because I am constantly glued to different cybersecurity news releases. I'm subscribed to CISA's news releases, which is the Cybersecurity Infrastructure Security Agency.
And then I'm also a part of InfraGuard, which is the private-public partnership between the FBI and private businesses, So I get their alerts on top of other alerts that I get on daily and hourly as well with things coming down the pipe. So I'm always glued to vulnerability releases Do things that are happening when I say it's fast paced, it's head spinning fast paced. Just today alone There was two things that have broken on the news cycle with major cyber breaches.
Pat
Before we go any further, I'm curious Black Heron Systems Group. Where did that name come from?
Cheyne
The Black Heron is a bird that when it hunts its prey in the water, but It creates a canopy with its wings and then it hunts its prey because it's a solid black bird It blends right in when it creates this canopy, so in a sense, invisible and very stealthy, I uh identified with that level of predator mindset and that instinct of of that hunter because I try to navigate in that way, in that same mindset, by blending in and really keeping up with the threats in a very stealth-like manner. Like I said, we're not just cybersecurity, we're also IT. But it's more prevalent to be clandestine and stealth when it comes to the research side.
And the protection side for companies. And I feel like we do a great job with protecting our clients while also recommending different vendors and partnering with different vendors. but to really be the silent warrior on their back-end systems.
Pat
I have to admit, Cheyne, when I saw Black Heron, I looked it up because I thought, where did this guy get this name? And I found that the black heron, as you beautifully described, it's a symbol of mystery, intuition, and instinct across cultures. But it's known for its hunting behavior with that canopy as you described.
And I was thinking about how beautiful it fits In the context of cybersecurity, a creature that understands exactly how deception works, uses it with precision, turns it into protection. Patience, stillness, intelligence, and then it strikes. And Shane, that describes your whole professional philosophy in one bird.
It really does. You're giving us a little bit of an idea. You're running Black Heron Systems Group.
And you mentioned that this news is changing so fast. I was going to ask you, what does that work look like actually from day to day? Help us here.
You're getting all this information These reports, these warnings. What do you do with all that?
Cheyne
Really, the battle is becoming How do you stop the breaches before they breach, right? Before they become effective. How do you detect these threats?
Before they do any sort of damage to the infrastructure or to the public. I mean cybersecurity is a business and a human problem, it not just an IT problem. Cybersecurity isn't just about protecting computers.
It's about protecting the systems, information, money, and increasingly the physical infrastructure that society depends on. I always tell people Physical security is cybersecurity. Some of the pen tests that I've helped with, that I've assisted on, involve penetrating physically into the building to gain access to their systems.
So it's not just an IT problem. It encompasses both the business and the human side. That is the biggest challenge is Being able to detect these threats in a very timely manner before exfiltration of data occurs Data is so valuable now, it's arguably more valuable than oil.
That's how big of a commodity data is on the dark web. Even legally, like when you when you look at data brokers. People pay lots of money for data.
Data is the new oil. It is the new gold. And most of the time That is what's getting exfiltrated if it's not to wreak havoc on a physical system.
It's to exfiltrate sensitive personal data to sell on the black market
Pat
Now you're talking about the human side of people just stealing data. And I was thinking about uh hospitals. I knew someone who was in the middle of chemo treatments in Detroit and they couldn't go to that hospital for the chemo treatment because they had ransomware that everything shut down.
All the surgeries, everything, Shane. Because the hospital had to figure out what they were going to do she series The Pitt handled that. They had an episode where they were the target of ransomware and they showed how all the doctors, everybody, staff, nurses had to go on analog devices and charts and pencil and paper.
That is the human side of it. And it seems like we're so vulnerable, exposed. What do you say about that?
Like the like something like hospital breaches.
Cheyne
It's very sad, but unfortunately, we're seeing it with every industry. Today, we just learned that Boston Scientific is under a big breach right now And they're a medical device manufacturer, one of the biggest medical device manufacturers. There is truly a human aspect to this problem.
You know, people think, well, it's about eliminating risk, and it's not. I I would say it's no longer about eliminating risk. It's how do you manage it?
Because we are so vulnerable, right? Everything is hackable. Probably very few things we can do nowadays that doesn't involve a digital footprint.
So we are all exposed How do you are able to manage the risk so that the risk is at its lowest? That is the name of the game. No security team can guarantee that an organization will never be compromised. If they make that guarantee of their lie.
Pat
You bring me to the next part of what you do. You're a certified ethical hacker. What does that actually mean in practice? And then are you thinking like a hacker?
Cheyne
Absolutely. You really do. So you have different levels of hacking, right?
The ethical hackers are individuals who they practice and practice and drill and practice and train for these different tactics. and procedures that ha that black hat hackers use to penetrate different systems and applications and devices. And the ethical hacking side is a very strict, very restrictive side, but it's a necessary practice.
So I can't just go out and hack a company and be like, oh hey, by the way, I I hacked your company. Here's a list of your vulnerabilities, not pay me. They'd probably be like, yeah, we're gonna call the cops.
That really doesn't happen. So penetration testing is a way of ethical hacking into a company's infrastructure, platform, application, whatever. Depending on the industry, it is required for compliance purposes.
And we start off with meetings with legal getting a very strict outline of the scope of our work, getting a letter of intent, because if we get caught by the cops, we need to have proof that yes, we were in fact hired to hack into this company's infrastructure. But to answer your question It is required to really get into the mind of Black Hat hackers when you see an application and then you look at, okay, what is the purpose of this application? Okay What would a criminal want to exploit this application for?
What are the risks to exploiting? What could be done if they re-engineered this or this and so that is the how we think we try to keep ahead of the black hat hackers it's awfully difficult because Like I said before, they've been using, for example, artificial intelligence models much longer on the criminal side. than before a lot of people have been using ChatGPT.
People are shocked when they learn that cyber criminals have been using AI and ML platforms much, much longer. than the public has with ChatGPT.
Pat
What is ML?
Cheyne
Machine learning. So it's a branch of artificial intelligence.
So that's the requirement to be an ethical hacker is to have that constant curiosity, that curiosity of wanting to break something, but also, okay, now that we broke it, what are its vulnerabilities and how can we improve that? How can we patch up that vulnerability so that can't be an avenue for uh entry into their system? And we take all of that information and we compile it into a report.
We present it to the stakeholders at our clients. And we hope that they take what we find and implement those changes. Again, on the business side, it all comes down to cost, right?
Cybersecurity. And IT is not cheap. It's getting more and more expensive.
So some recommendations don't get put in place But we try to rate things from most important that really can't wait to something that maybe could wait a few more months or the next fiscal year that that really if it got exposed wouldn't open up much damage. So yes, to answer your question, we do think like black hat hackers, we do attend a lot of conferences. You have to be passionate, you have to always be a learner.
You have to want to learn new things because the hacking, the cybersecurity slash ethical hacking field is always changing, if not much faster than People's iPhones are changing.
Pat
One of the tools that you use as an ethical hacker is something called OSINT, Open Source Intelligence. Now, what is that? And honestly, what can you find out about an ordinary person just from public information?
Cheyne
There is so much public information available now. So OSINT is open source intelligence. That really is the first step into the reconnaissance.
That is our first step into information gathering. So really that you can find someone's phone number, address, travel habits, hotel stays. You can find publicly accessible voter information, not who you voted for, but a lot of voter information is publicly accessible You can find a lot of information.
Each state has public accessible court information. You can find that out And there are platforms that I have access to that once I gain enough special information, like maybe a username or an email, I can feed that into a search and find all the usernames that are associated with your specific email and then go in and compromise your social social media accounts Going back to travel habits, I can see travel habits, your search history. Are you staying at a in a location for X amount of time?
Or if I get into your social media, what places are you checking in and out of? Are you checking into a music festival? Are you checking into such and such place?
That is a clear indicator that you may not be home at that time.
Pat
So basically, you're telling folks when you're on the socials, don't say we are in Bora Bora, sitting at the beach with margaritas for the next three weeks. Because people, they do, they like to share, oh, I'm going to visit so and so in what state People are putting their lives more and more on social media.
Cheyne
That is a great point. It's called situational awareness. operational security, right?
Be very situationally aware and operationally cognizant of the information you're putting online. For me, I live in a multi-unit apartment building. multiple stories.
I don't have to worry about someone narrowing down my apartment It can be it can happen, but it's less likely to be successful in my case than someone who lives in a single-family home. Pictures. When you upload a picture, there's a lot of geotagging information available.
So you can go in and see from the picture metadata where that picture was taken.
Pat
Cheyne, let me stop you there. People don't know what metadata is. So they see the picture. They can check out metadata. What the hell is metadata?
Cheyne
Metadata is basically latitude and longitude, the time, the camera information, what kind of phone you have that is recorded when you take a picture from your camera on your phone
Pat
There's so much information that we provide. Really, this kind of boils down to a little bit of common sense. Don't broadcast that you're going away or the weekend or leaving the house on the socials.
Cheyne
Yeah, well and to finish up on that point, so I was in South Dakota this last weekend for a work trip And I had to laugh. I went to a Menards to get some equipment and there was a like a 10-passenger van, you know, one of those like a churchy passenger vans But it was clearly someone who had a large family because on the back window they had those stick figures and they had the name and the stick figure of every family member. And I'm like, oh, interesting.
So that's a good tell, like how Okay, you've got ten kids and one's name is Susan, one name is Kylie. Okay, that's good to know. Thank you for telling me that.
It may seem innocent and it may sound like overly paranoid. But it's stuff like that that clues people in. And you don't have to have a master's degree.
It clues people into What's your family dynamic is like? Okay, you have a big family. You may not be home a lot of time.
Pat
I want to shift gears. You volunteer with seniors and veterans. What does that work look like? What do you?
Cheyne
As a veteran myself, I really take a lot of pride in training veterans of all ages and their families on good cyber hygiene. So I call them my cyber hygiene clinics because hygiene is a is a term we that's used heavily in the military.
And my grandmother was a victim of a really bad cyber-attack and she lost $17,000 in a scam. And so not only do I do my cyber hygiene clinics for veterans It's for seniors, veterans, and their families. Because unfortunately, those are the populations that are on fixed incomes most of the time.
And they have the most to lose. You know, someone like me, if I lose $17,000, yeah, it's a lot of money, but I can make that up. But if you're in your 70s or 80s or even in your 60s and you're retired, you can't make that up.
And unfortunately, it can't lead to people taking their own life. And it has. And so it really does have a big human cost if someone gets caught up in those scams.
And these scams range from romance scams. to fear style scams on the computer. With my grandmother specifically, she was playing her Mahjong like she always does.
And she clicked into a Facebook game and that then opened up the floodgate to fictitious virus pop-ups that were happening and she got scared and her computer froze and then a number popped up so she called the number and that's what led to her sending a lot of money to a scammer in another country. So I do it for those reasons. I do it to hopefully prevent an elderly person or someone who's on a fixed income from getting caught up in these scams.
Pat
Yeah.
Cheyne
Because I know cyber professionals who have been in the IT and cyber industry for 30 plus years who still get caught up in scams. They are very sophisticated and they drive on a lot of psychological aspects. And so it happens to everybody, not just those that aren't working in the industry.
Pat
From all the work that you do, the volunteer work, is there a moment where you help someone, uh a moment that really stays with you, an experience from that? .
Cheyne
I think it's when I do my demos and, because a lot of these individuals read the news headlines and let’s face it, the news headlines can be very overwhelming nowadays and kind of scary. But I feel like when they see the demos that I do in real time. The amount of concern and like the oh crap feeling that washes over their face almost instantaneously, I think, is quite satisfying for me and not in a weird way but in a way that they're getting it like they can see it in real time And I think that is what clicks for them.
Like they can see it, it doesn't take more than 10 seconds of audio to clone someone's voice with AI and to make it believable. And they see that demonstration or they see how easy it is to crack a password and they realize wow, they are vulnerable and its vulnerability that I think people don't realize that is occurring because we all want to think that we're we still have a safety net. We're still in a safe spot, but really, we're not, not on the digital place where that we're at.
Pat
So we keep hearing about AI, and if you use AI as a tool, okay, not as your go-to for everything, it's a helpful tool But we're starting to see browsers that are saying, hey, do you want us to have AI help you with everything? Or do you want to use AI to fill in your forms? We're starting to see this push across applications, browsers.
Hey, let's use AI for this. How about it? Now my feeling is no, I don't want to do that.
But they're kind of sneaky the way they're saying, hey, it can help you fill in password forms or it can help you. Can you talk about that?
Cheyne
Don't get me wrong, there is a lot of good things that AI can help with. It is when you use it to replace certain functions or features in your life And you're starting to buy into the hallucination that it pumps out. So AI or artificial intelligence is only as good as the models it is trained on.
And so like with anything, it makes mistakes. It is a great tool if you want to create a shopping list or a workout routine to help you organize a letter. you know, stuff like that, it's a great tool.
It really doesn't carry too much risk in that realm. Where the risk comes in is like you mentioned a lot of these platforms are incorporating those models into their platforms whether it's a GPT model, Grock, or a Gemini or a Claude model, it depends on what information you're giving it. Certain industries still are highly regulatory and haven't incorporated it fully like finance and banking, although we're starting to see it's becoming integrated more and more in those industries.
But like if you're putting in if you're using AI to watch travel deals or something, just making sure you know like where your credit card information is going. making sure that you're not feeding any sensitive information, personally identifiable information, or anything that can be jeopardized to harm you or your family into that platform that's using AI. Because really it is about streamlining and cost-cutting and making life more efficient for everybody.
And that's how AI is being sold. And there is a lot of truth to that. But AI is also easily corruptible.
Only 2% of the data in the model needs to be corrupted before the model is rendered useless. 2%. That's not a lot when you're talking about millions and millions and millions of lines of code.
Pat
Yeah. Okay, that's the AI, but I want to bring up something that happens to everyone. I get an email.
It has the Apple logo. And it says, hello Pat, the such and such has to be updated. Click here, otherwise we will have to cancel this blah blah Now, I see the Apple logo.
I see it looks official. And I can click it and Before I click it, and I've learned this the hard way, whenever I get from Banks or Apple or anything I use, I always go to the up on the email And it'll say Apple. com, but when you click it, it says so and so, so and so dot gmail so and so That's not Apple.
But if I don't know to check the signature of the bank that's contacting me or the travel agency that I just used I click it and then all of a sudden I'm going down a rabbit hole. What can you give listeners like a couple of tips for that kind of subterfuge?
Cheyne
Number one, always, always, always inspect the sender address. Don't just trust the display name. Those are easily manipulable You always want to make sure, like, for example, if you're using Outlook and you get like an email from Microsoft Security, right?
And it's security at Microsoft dash alerts dot xyz well wait that's not their domain that's a little weird it should be security at Microsoft. com Right, so always check that actual sender address. You want to pay particular attention to misspelled domains, right?
Microsoft for example, but instead of the O if it has a zero in place of the O That's an indicator as well. Attention to detail is very key here because these fishing attacks, as they're called They are getting extremely more sophisticated. And again, going back to artificial intelligence, it's making these attacks more and more sophisticated.
But also check for extra words Subdomain tricks is another thing you want to look for. A subdomain trick is, say you have Microsoft. com, but it's not just Microsoft. com, it's Microsoft. com. attacker dash domain.com, free email accounts being used for business communication is also another indicator And you also want to look for a different reply to address versus the from address. You want to make sure that the from and the reply to are identical. So if you're on a computer, take your mouse and hover over a link before clicking it It will give you the entire link and you can inspect it.
Most importantly, go with your gut. If you just don't think it's not adding up, err on the side of caution. and reported as spam, reported as fishing, and just be very, very cautious because Those are the easiest ways to get people to click on a link and to gain access to credentials or to their account information or communication.
And phishing attacks have been around for many, many, many, many years. they still are very effective. They're one of the most effective ways to gain access.
You're relying then on a human person's human behavior and a lot of cyber attacks rely on social engineering.
Pat
Okay, so I'm sitting here staring at my computer And now I'm starting to look at it. Are you a friend or foe? Okay?
Now, Cheyne, I do not want to be fearful every time I go online. So if you could, just what can people do? Basic steps that are just common-sense moves, like what you just explained, that could really make a difference.
What kind of things would you tell us so we don't have to be fearful every time we look at our screen?
Cheyne
And that's a good question. That's a very important question because It is easy to overwhelm yourself and get scared and paranoid to the point where you're throwing everything in a in the microwave and nuking it and wearing a tinfoil hat, right? But really that is not the step.
That's not where you want to go. But it's easy to get to that point. And just be situationally aware, mindful of what you're putting online Just taking that extra 30 seconds to really look at a link before you click on it.
Check the header, the sender's address. Really just look for flags. Be the grammar Nazi.
If things are just not spelt right and and you're getting a lot of red flags and your spidey senses are tingling. Probably err on the side of caution. But for the most part, when you go to a website, always make sure that you have a padlock icon at the link.
That'll denote that it's HTTPS. It's a secure website. If there's no padlock icon, err on the side of caution and if you know what you're doing.
But when in doubt, ask. Find someone who can answer your question and ask. It's better to be a little bit more cautious than to be in a hurry and then have now months or years worth of financial and legal headache because your stuff got compromised.
Again, everything is hackable, but how do you manage your risk? So that way your risk profile is at the lowest that you can get it to.
Pat
Okay, then I want to bring up a key part of what you're saying. Passwords. Now I joked in the beginning, Fluffy123, okay? People use their pet name their birthday, the street they live on. Will you talk about password common sense?
Cheyne
Never, never, never use complete words and sequential numbers as passwords. Never use password one, two, three. You smile and laugh, but it is common.
I have a client. Who uses the phrase I love and then her husband's name, 1234, as her work password for her uh office It is very concerning because she works in a very regulated environment. I won't tell you the industry she's in, but it's very regulated.
And that is her work password. And I've recommended time and time again to change it, and she just will not, because it's easy to remember I'm like, well yeah, but as an ethical hacker, it's easy for me to remember. And now it's easy for me to compromise.
But always at minimum 12 characters. a good mix of upper and lowercase letters, numbers, and special characters. Special characters are your exclamation point, your at symbol, pound sign, all that stuff I would say if you can get it up to six fourteen to sixteen characters, do it.
Write it down on a separate sheet of paper or a book. If you have a very good trusted password locker, use that and save all your passwords in there. If you have an option for multi-factor or two-factor authentication, take it.
It is a pain in the butt, but it's that one extra layer of security that prevents your stuff from getting compromised. It is a pain in the butt having to, you know, go to your phone and enter a code or, you know, whatever, but it's very tried and true and it's extremely secure.
Pat
So, Cheyne, you've dedicated your career to making the digital world safer for people. What gives you hope in this work?
Cheyne
That is a really great question. I think what gives me hope is that a lot of people regarding artificial intelligence are still very cautious. about it.
And I think that is a good way to approach technology like artificial intelligence, considering how much investment and adoption is going on currently, there are risks with everything and AI is no different. There's going to be a lot of risks to it. And I don't feel like we have adequately put in safeguards and had the right regulatory and governance conversations alongside the rapidly evolving adoption of AI models.
So I think what gives me hope is a lot of people are becoming more and more cautious. with that technology. They acknowledge the positives, but they also recognize the negatives and the and the risks associated.
And I think that is good. And I think one thing that would give me more satisfaction is if more people sought out a community-based cybersecurity awareness training It may feel like something you don't want to do for two to four hours on a Saturday, but those two to four hours, depending on who's giving it, can save you so much headache down the road. So those are my answers to that question.
Pat
So Cheyne, what's next for you and where can people find you?
Cheyne
What's next for me? I will be getting some cybersecurity trainings set up in various communities. I like to partner with the American Legion Posts in different communities because of how veteran friendly they are. I'm also a member of the Military Cyber Professionals Association And partnering with the American Legion helps MCPA sponsor those events. I'm going to be scheduling some of those.
I'm hoping to start doing a regular spot on community media, getting people aware of different threats and doing like a special segment every month on a different topic through the uh a community media program in Rice Lake, Wisconsin. And then yeah, if You ever need to find me or reach out, you can put in blackharonsystems.com and look at our offerings and shoot me an email and we'll get back to you as to what we can do for you.
Pat
One of the reasons why I wanted to have you on, Cheyne, is because you have a way of taking something that's so complex and making it make sense and to be something not to fear but something to be mindful about and how to take steps to protect ourselves I want to thank you for the information that you shared with us today and also thank you for your service and the work that you do. So thank you for coming on, Fill To Capacity.
Cheyne
Thank you for the invite, Pat. I appreciate it.
Pat
Okay listeners, now I know as soon as we're done, you're gonna run to your computers and start checking your passwords, and that's a good thing So thank you for joining us today and take care. Bye