From Math to Cybersecurity: Tiffany Shogren on Awareness, AI, and Optiv’s Core Four Principles
Tiffany Shogren highlights the importance of Cybersecurity Awareness Month and shares her transition from teaching math to cybersecurity education. She outlines Optiv’s role in client security and emphasizes the Core Four principles: strong passwords, phishing awareness, reporting, and software updates. The discussion includes the evolution of phishing attempts and the dual role of AI in cybersecurity, stressing the need for AI literacy among end users.
Transcript
Hey everyone. Welcome back here to Textron tv. I wanna introduce you to our next guest.
Her name is Tiffany Sjogren. Tiffany's with Optive, where she is the Director of Services, enablement and cybersecurity education. Tiffany, welcome to Tech Drunk tv.
It's great to have you on. Thank you, Alan. Absolutely.
And, uh, you know what, for those of you who don't know out there, October is Cybersecurity Awareness Month. I used to think it was one of these made up Hallmark holidays just to sell more cards, but we've, it's been going on for a couple years now, and I think it's kind of generally accepted that, at least in our world, October is Cybersecurity Awareness Month. So happy Cybersecurity Awareness Month.
Tiffany, thank you for joining. Absolutely. Absolutely.
Absolutely. I didn't be here, Uhhuh, Tiffany, I, I gave them your title, but you know, a title can cover up a lot or not. Give us an idea really though of your journey to, to, you know, being here with Optiv today.
Absolutely. I have a pretty unique background. Uh, once upon a time, I was a middle school math teacher and I entered into the corporate training world over 12 years ago, and, um, started with Optiv, um, in one of the companies that formed Optiv in 2015.
And you know, right now I'm responsible for the education of our services organization. Uh, so all of our analysts, engineers, uh, customer success managers, all of them. So I've had the opportunity to work with them and grow alongside them, understanding what they need in order to make our clients secure.
Absolutely. Very cool. What a great story.
I, I, I got a confession to make. I'm doing interviews here 12 years or more. You are the first former math teacher who's made the crossover in a tech like this I've ever interviewed, so, congratulations.
What grade math did you teach? I taught middle school, so, um, seventh, eighth grade. I forgot those.
Those are the wonder years. Those are bad. Those kids, man.
Oh man, I love God bless you. Em, I Love 'em. Did you?
Oh yeah. Good for you. No, they're amazing.
And honestly, uh, they're very similar to the professionals, and I mean this in the best way possible, very similar to the professionals that I work with now, because in cybersecurity, many of the people that we're working with are hungry for more. They're hungry for understanding how to address the next threat. They're hungry for, um, you know, understanding the new technology.
You know, we're talking about AI every day right now, and similarly in middle school, they're just starting to get into that content where they're figuring out themselves and you know, what they wanna do in life. And so there is that bit of energy that is synonymous with both groups. Um, so I find it, uh, it is interesting, but, uh, I find it fulfilling working with these professionals.
Very cool. So I would've compared cybersecurity professionals to middle school kids with a different sort of analogy, but I like yours. It's okay.
It's okay. Uh, great stuff. Tiffany Optiv.
Mm-hmm. Some of our folks out here are probably familiar with Optiv, but I'm gonna bet a lot aren't. How would you describe Optiv to them?
Optiv is a cybersecurity solutions advisor for clients of all different sizes, all different industries. And really our focus is doing what we need, um, to help our clients secure greatness, whether that's through technology partners that we have, um, within, uh, all the different industries touching cloud, um, touching network security, touching ai, um, you know, whether it's a technology or a service. We have a large services organization of consultants and manage services, uh, where we can meet clients where they're at, um, you know, not being reliant on a specific, um, approach, but finding what works best for them and helping them secure greatness.
I love it. com. O-P-T-I-V?
That is correct. Excellent. Alright.
Tiv, if you don't mind, I, I'd like to return to this Cybersecurity Awareness Month theme and, and talk a little bit about the Core four. Mm-hmm. Right.
And again, some of you out here may know what we mean when we say the core four as it relates to cybersecurity awareness, but some of you don't, if you don't mind, Tiffany, why don't you, you know, refresh those who maybe forgot. Absolutely. So the reason we're calling them the Core four now is that Cybersecurity Awareness Month used to have different themes every year, and they would have different areas of focus.
Um, but over the last several years, those areas of focus have remained the same. They are the core four strong, unique passwords, phishing awareness, reporting, it, multi-factor authentication, and keeping software up to date. And the reason that those four became the core four is that no matter the technology in the environments of our customers, or even in their personal lives, it's that human behavior.
You setting your password, you opting into multifactor authentication, you recognizing a phishing email, and you taking a little bit of a pause and letting your software update that's going to keep you the most secure, both you and your organization. So that's why we call them the Core four. Excellent.
You know, taking a little bit of a pause, I came, came into the office early this morning. I, I use a Mac and a iPhone, and I, I logged into my Mac and I got, you know, the, the little, you know, the gray thing with the red number one, meaning there's a software update out there. I said, all right, let me update my Mac and while that I'll just work on my phone while it's updating and I update the Mac and, you know, it goes blank and I get the Apple logo and the, and the bar.
Yep. And, uh, I open up my phone and what do you think I got Update The same number one update, because now they update across the entire portfolio and I'm on the beta releases nonetheless. So now I had to hit, hit update on my phone.
Now I'm stuck here without any devices, right? Mm-hmm. And I'm twiddling my thumbs going outta my mind, but, so lesson, you know, but you're right.
It, it was just a few minutes and I felt better that, you know, I updated that it said Chrome needed an update. I did a quick relaunch of Chrome. Mm-hmm.
And I'm up to, I'm up to speed and, and as a security person, you know, that made me happy, I guess at some level. Um, looking at the Core four for this year, what, what, what's optos advice, best practices for our folks at home? Yeah.
So, you know, you, you had mentioned that not everyone is aware that this month is cybersecurity awareness month, really for Optiv. What we're trying to instill with our clients is that cybersecurity awareness month is a time where we celebrate, but it is all year round. And making sure that our employees and our business leaders who are in charge of the initiatives that, um, they're rolling out within their organizations, that they understand the human element of that and the importance of having a plan.
Because again, like I mentioned earlier, no matter what software or technology is in your environment, it takes one person entering their password into a malicious site that they got to through a phishing email to make you sit back away from that technology a lot longer than a couple minutes. Right? Um, the impact of those decisions and the impact of those behaviors, it's just making sure that you're covering all bases when you're in the middle of a new initiative.
If you're trying to turn out a new product that has technology involved in it, maybe it's coding, taking time to do the threat modeling, oh, you want to incorporate ai, AI threat modeling in front of that so you understand the risks. So it is that investment of time upfront, um, that you kind of mentioned, you know, gotta gotta push that update out, gotta sit here for a little bit, but it pays dividends on the backend to be more methodical and, uh, approach it the right way. Uh, agreed.
Absolutely. Um, you know, it, that, that whole idea though of I don't have time, I don't have time. Mm-hmm.
It is pervasive in, in fact, cases where you see security breaches. Mm-hmm. Right.
It's the same thing. The developer says, I don't have time to test for security. I gotta push this code.
I gotta push the code. I don't have time, we're on deadline. Mm-hmm.
Or, you know, I, I gotta spin this up there. There's a deadline and, you know, at the ops level and, you know, time time's not the enemy necessarily here when it, when it, when it comes to cybersecurity. So that, that's definitely a, a thing phishing.
Mm-hmm. I wanna talk a little bit about phishing. You know, it used to be so easy to spot phishing because most of the time it came from, you know, places where English was the second language and, and you know, Microsoft or Apple isn't writing things with like, uh, terrible, you know, grammar and stuff like that.
Of course with ai now, some of these phishing males are works of art. Yes. I mean, I, I sit here and I, 'cause I, I've taken the phishing classes.
I, I actually helped design a phishing course and, um, you know, I go into the headers and start looking at the reply tos and the, and the real names and where those links are going and everything else, URLs and actual link. Um, but for the average person, it's become a real challenge. A real challenge.
Absolutely. Um, like many of the people who are probably going to watch this or listen to it, um, I am my grandmother's IT help desk. Yes, We all are.
We All are. Right. And I wish my grandmother, but the whole family, yes, the Whole family.
But those phone calls when, when she is distraught, because it is so believable, it is from her bank, it is from her, um, you know, investment portfolio people. And she's like, I, but I don't, I haven't done this. And I'm like, I know you haven't.
So what does that mean? If you have thought about the context, the content of that email, and it's not legitimate, what does that mean to you? And that's kind of the mindset shift that I'm trying to teach her rather than, and, and honestly more than just my grandma, our cybersecurity education, um, team that provides services and and training to our clients here at Optiv, we are talking about slowing down, thinking through, um, evaluating the content.
And if something seems off, if just one piece of it doesn't seem real, there are things that you can do to validate, uh, that email there are other than just technology, right. Um, you know, you can send an email separately, you can report it for evaluation. Doesn't mean that it goes away forever, but have someone look at it, a professional before you're clicking anything, opening anything.
I mean, the best thing that they can do is reply and say, that wasn't a phishing email. You're like, okay, good. Now I'm safe to proceed.
Um, you know, so it is a, it, it's more of a mindset shift from being tactical, looking at the misspellings, looking at the domain, looking at, um, you know, the, the urgency or formatting, uh, within the email. And instead it's almost more of a strategic look at communications, if you wanna think about it that way. So moving from tactical to strategic and thinking, is this something that I should be getting?
Is this, um, you know, relevant? Um, or is there something just a little bit off? Fair.
Excellent. Um, you know, I, I mentioned AI with the phishing, but AI is having an effect up and down here mm-hmm. With all of our security and, and you know, at the same time, it's also a force for good, right?
We, a lot of companies are building AI into their cybersecurity protection, right? 'cause it can, sometimes you need AI to fight ai, Right? Absolutely.
And I think cybersecurity awareness month is one of those times where you can start the conversation. Um, I think for, uh, for most of the organizations that celebrate Cybersecurity Awareness Month, it's more about the individual end users. There may be some initiatives corporate wide, but kind of the focus is on the people aspect of it.
And when it comes to ai, AI literacy is really important. Uh, so having your general end user understand what an LLM is, what it looks like when an LLM is poisoned by a threat actor, uh, what bias looks like on output, um, what prompts you should be using or can use that still protect the information that you are handling. Um, rather than using that information to train an LLM, um, open, you know, public or open AI versus closed ai, um, being able to understand those terms so that when a policy comes out or when they see something in the news or an alert from it or the security team, it makes more sense.
Uh, I think the literacy piece of it, really understanding all of the nomenclature and how they're intertwined is critical. Agreed. Agreed.
Tiffany, we're about outta time. I want to thank you for coming on. Keep up the great work at Optiv.
Thank you. Um, there are a lot of middle school math kids who are missing out with you over here now, but their loss is our gain. So thank you very much for what you do there and come back and keep us posted.
Appreciate it. Thanks for having me. Alright, we're gonna take a break here on Techstrong tv.
We'll be back in just a bit.