Empowering Cybersecurity: Insights from Caroline Wong – Tech.Strong.Women. EP 32
Join Jodi Ashley and Tracy Ragan for another episode of Tech.Strong.Women, where we dive deep into the world of cybersecurity and beyond with Caroline Wong, chief strategy officer at Cobalt and trailblazer in the field. In this episode, we explore the fundamental principles of cybersecurity, highlighting the critical need for proactive security measures in an era of constant cyber threats.
Caroline shares invaluable insights on offensive versus defensive security strategies, emphasizing the importance of prioritizing limited resources towards offensive testing to uncover vulnerabilities. We delve into the transformative potential of AI in cybersecurity, discussing its ability to automate tasks while underscoring the indispensable role of human oversight in setting security goals and processes. Additionally, Caroline shares her inspiring journey in tech, shedding light on the importance of encouraging diversity and creativity in STEM fields to cultivate innovative problem-solving skills essential for the future of technology.
Tune in for an enlightening conversation that combines cybersecurity fundamentals with empowering narratives from one of the industry’s leading voices.
Transcript
Hi, everybody. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jody Ashley, executive producer at Techstrong, here with my co-host Tracy Reagan, creator, and CEO of Deploy Hub and Linux Foundation enthusiast.
Before I introduced today's guest, I wanna give you a quick update about what's happening here at Textron. Be sure to register for Textron Con 2024. It's happening on April 3rd, so you can still get in there if you wanna, if you wanna attend.
Um, also, we are launching a really cool and exciting virtual event called the Artificially Intelligent Enterprise on May 21st. It's going to be a 24 hour global event, so you won't wanna miss out. com and register for all of our events.
And we love sponsors, we love speakers. So keep your eyes open and you'll be able to sign up to do that stuff. And be sure to te tune into Techstrong TV every day for amazing content shows and interviews.
Hey, Tracy, what's on your mind today? Well, I think a 24 hour kind of follow the Sun conference on AI is pretty interesting. I know it's Gonna be fun.
I'm looking forward to it. Absolutely. So, you know, today I wanna talk about, I often talk about Jenkins, but I'm gonna talk about it again because it continues to be a prime tool that companies, enterprises around the world have used.
And this happened in late January. Um, about 45,000 Jenkins instances were exposed to an online vulnerability, uh, that allowed them to get remote code execution, or depending on your, your security settings, basically gave you a, uh, access to the command line and to be able to get access to certain, uh, files, 45,000, um, servers. We, we, everybody has to stay diligent, right?
Um, and tools like Jenkins, while everybody works really, really hard to make sure they're secure, you never know when a vulnerability's gonna pop up like that. So, I just wanna put it out there. It was out, you, you might, uh, look for it.
It's, uh, it was published back in, um, late January, and it really talks about the exposure and why it's important to fix it. So I'm putting it, putting it out there for all you Jenkins users. Look to see if you have that particular version and if you have an issue.
All right. Thank you, Tracy. All right.
I am so excited. I've been trying to wrangle this lady for quite some time, but she is very busy. Um, our, our guest today is Caroline Wong.
Caroline, tell us about yourself. Thank you So much for having me. I am delighted to be with you two today.
My name is Caroline Wong. I'm the Chief Strategy Officer at Cobalt. We're an offensive security testing company.
Um, I've been working in cybersecurity since 2005, starting off on security teams at eBay and Zynga. Um, in 2011, I published a book called Security Metrics, A Beginner's Guide, uh, in 2022, that book was inaugurated into the cybersecurity Cannon Hall of Fame. Um, I teach courses on LinkedIn Learning, and I host a podcast called Humans of InfoSec.
Very interesting. And I know that you are passionate about, uh, teaching and talking about security and cybersecurity at work, uh, which is a really interesting topic because no matter how, how hard we all work to secure the supply chains to secure our environments, somebody can put an use there. Pet's name, which we probably all do for, for, for a, a password, and all of our hard work is gone.
So why don't we talk, start today about talking about, you know, cybersecurity at work and, and how people should approach cyber, what we should know as we we do our daily work. Yeah, first I just have to say, Tracy, I love that you opened up today's session talking about a vulnerability in Jenkins. This is something that I get really excited about because the thing about software is that it's vulnerable.
And unless we're proactively security testing it, unless we're proactively installing fixes, the vulnerabilities are just sitting there waiting to be exploited. And I think that the thing, the, the main concept that I try to communicate in cybersecurity at work is simply that everyone's getting attacked all of the time. All of our organizations are under attack right now.
We're just all being attacked, you know, and if folks could understand this and understand that it's something that happens all the time, every single day, and not just sort of a random occurrence, or if you're doing something super important or if you have some sort of super confidential restricted information, everyone's getting hacked all the time. And that being said, my sort of, first I would say there's really three things for most people to keep in mind. And this is what I say.
If I'm talking to my 8-year-old daughter, or my 7-year-old mother-in-Law thing, number one, look out for fishing. And if something seems too good to be true, it very well might be. And just take a screenshot and send it to me and I'll check it out.
Um, but whether, whether or not you're my literal family member or not, you know, send it to someone you trust and just ask them to take a look at it. Um, and make sure that if there's an opportunity to verify it via some other route, for example, you know, you get a text message and it claims to be from a shipping company, you know, go online, go to their real website, call them up and ask about it. Um, so number one, we are all getting phished and social engineered all of the time.
Uh, learn to expect it and learn how to, uh, question it. Thing number two, use multifactor authentication. I'm not saying that it's okay for all of our passwords to be our dog's names, but if it were, and we had to factor authentication, authentication, then we'd be in such a better spot.
Um, and these days, you know, that kind of thing is really so easily accessible. Um, so definitely for online banking, definitely for email, really for anything that you really care about, just turn on my multi-factor authentication all the time. Do you need to do it for Netflix?
Maybe not. Do you wanna do it for Amazon? Probably.
Um, and then the third thing, and this is really geared toward sort of everyone, all of these tips are geared toward everyone. Update your software. I know how annoying it is, and when it takes me 20, 30, 60 minutes of time where I am unable to access my laptop because Apple has released yet another OS update, by the way, is it just me?
Or do they seem to be coming in really, really frequently? But you know what? I don't care how frequently they come in, you gotta prioritize it because hopefully, even if you don't prioritize it, your organization's, it security team is actually making it happen.
But what's gonna happen if that's the case, is it's gonna be a Friday morning and you're gonna be on an important call, and all of a sudden your computer is just gonna start installing and updating, and then you're, and then you're, you know, it's gonna be really inconvenient. So just pick a time, you know, maybe it's the end of a workday. Um, and, you know, you're about to go take a walk.
You're about to make yourself a cup of tea. Just install the update, do it for your os, do it for your laptop, do it for your smartphone. I really think that between those three things, if I could only tell folks three things, uh, those are really it.
Um, but I will give a little plug for my cybersecurity at work course on LinkedIn Learning. Um, if anyone's interested in viewing that course, uh, you can find me on LinkedIn and on my feed. I've actually got a featured post, uh, where you can watch that training, uh, at no cost to you, even if you don't have LinkedIn learning.
Um, and one of the things that we did that was really fun was we did a couple of scenarios. Um, so we tried to make it fun. We tried to make it engaging.
Uh, I like to think that it is, uh, pretty engaging and pretty fun as far as cybersecurity training goes. I'm absolutely gonna go check that out. Um, and you know who my husband is.
So the two factor authentication thing has been a thing that I hate and drives me crazy, but nobody makes me do it. So it's attached to everything in our house already. But getting younger people in their twenties and thirties to update their computers is such a nightmare.
Like, we have kids that are working and they have a max, and my daughter doesn't, how often she'll be like calling, like, I can't, my, I can't work today. And Mitch will be like, well, do you need to do some updates? And, you know, it's six months old and you're like, so I have another question though.
When you talk about, um, companies trying to hack and security breaches, you said that a lot of 'em sit there waiting for the moment. How much of that happens and how long, you know, how many people create stuff and it just sits there for three, four months waiting? How long, how often, how common is that?
So here's the fundamental problem. Software and the internet, the power of software and the internet, mm-hmm. Is connectivity.
The internet started out universities trying to share information with each other. We had atmospheric scientists trying to share large amounts of data. The internet was not built to support global electronic commerce.
It just wasn't. And so security is not inherent to software. Security is not inherent to any internet protocols.
In order for something to be secure, it has to be secured on purpose. And the best way to ensure something is secured is to test it, go after it with an attacker mindset, the offensive security mindset, test that software, find the vulnerabilities, fix the vulnerabilities. Um, it's really the only way.
And what happens is if you're not even looking mm-hmm, the vulnerabilities are just sitting there. If you are looking, then at least you know where some of it is, and you are in a position to address it if you choose to. Now, there are trade-offs involved, right?
Because security testing costs money and addressing security problems, cost, resources and money. And this trade off is where sort of the security complexity lies, Mm-Hmm. Um, but on one hand it's actually simple, which is to say, do technical security testing, go and find those vulnerabilities, and then work with development teams to go and get it addressed.
And that is part of the bigger problem because we are finding vulnerabilities. Vulnerabilities are now being founded at, at a, uh, a rate that we are, are not used to, because now we have vulnerability databases. We have tools that are scanning for vulnerabilities, we're reporting them.
Um, and you know, of course, Jody said, I was gonna talk about s function. I'll have to, I have to kick this one in. Um, if you don't have an S bomb, you don't necessarily know the, uh, vulnerabilities of blast radius, and you don't know what the remediation steps should be.
So I often, uh, talk about the, the future where we have a FEMA like response for vulnerabilities. I don't have to wait. If somebody's found one, get it, get it communicated.
We lack collaboration in this area at a global level. And I've spoke to some people that says, well, we don't want people to know where those vulnerabilities are, because then hackers will know about it too. But the sooner we know about 'em, the sooner we can shut the door.
Oh, they already know. They already know. They already know.
That's what I, and we don't, vulnerability Database is public to everyone, Everyone, Everyone, you're a good person or a bad person, you know, it is equally accessible. And the bad person is probably more likely to be hunting around the vulnerability database to find out the ones that they want to go and attack. And the good person is the one trying to get software out, right?
They're the ones working and trying to get their software out. They're not thinking about looking at the vulnerability database every day. And if you don't, if you, if you don't know where those vulnerabilities are in your, in your, your software supply chain it from this, from a coding perspective, it's hard.
It's hard to get those fixes in. And then the remediation is not shared. So somehow the industry's gonna have to get to a, thinking about this in a FEMA response.
Now, you talked about it, you, I think you talked about it, uh, um, you said two terms. One was the hacker's mindset and in offensive mindset. Why don't you talk a little, get get a little deeper into that so maybe we can better understand how to solve the cybersecurity problem?
Yeah. In my experience talking to hundreds, thousands of security and development practitioners throughout the year 2023, there was a really big theme which emerged. And the theme which emerged is everyone's experiencing layoffs and everyone's experiencing budget cuts.
And what does that mean for cybersecurity practices? It means there's simply less to go around whatever limited resources we had before to allocate towards managing different risks that's now smaller. And so I would like to put out the idea that when thinking about a cybersecurity program, you can think about two domains.
One which is defensive security controls, and one which is offensive security controls. Multifactor authentication is a perfect example of a defensive security control. One that I think is really important to do so is updating your software.
But an offensive approach says to your point, Tracy, about attack surface. Do I even know what my attack surface is? You know, am I aware of any sort of shadow domains, dangling domains?
You know, what's out there that actually belongs to me that I'm responsible for, that I may not be looking after? And once those assets are identified, security testing, whether that is scanning, data scanning, whether that is manual penetration testing, taking a look at your organization's digital assets and considering what it looks like to an attacker. Um, and, and, and my thought is by doing this, organizations have an opportunity to focus their very limited resources on addressing the items that come up in that offensive security analysis.
Cobalt actually just published a report called the SEC Shift report. Uh, and it contains a bunch of data, um, from thousands of, uh, security and development, uh, practitioners, uh, that talk about how budgets are shifting and organizations are investing more in offensive security for exactly this reason. And, you know, this concept is new to me.
This a concept of offensive. I think most of the things that I think about are, are defensive, right? Beyond just knowing what digital assets you have to manage.
Is there other ways? You know, I think offense, I'm a hockey person, you know, we have a goalie, we have, you know, we have defensive players. Who are the players in that kind of, that offensive world?
Hockey feels like the right analogy, very physical, you know, boom, boom, right? It's not subtle. We have forwards and we have our wingers and what are our forwards and wingers doing Right to go and score?
What are they up to? I think, you know, you've got sort of a few classic categories of attackers. You know, you've got sort of the really big scary ones, you know, nation states, um, but you've got others.
You've got potentially, um, you know, competition, um, search, searching for intellectual property. Um, you've got your sort of typical, um, you know, spray it all type of scammers who are just looking to make a buck any possibly way they can. Um, certainly ransomware, uh, is a big way in which people and organizations are being exploited.
Um, and these days, the thing about being a hacker is that hacker tools and approaches are not that expensive. You can buy a password cracking system and, and the storage required for it for less than $50. Um, it's just not that hard to do.
The bar is just not that high, so it doesn't require a lot of money. If you've got an internet connection and some know-how, um, then, then there's a lot of power, uh, on the attacker side. Um, and I think as organizations, what we really need to do is we need to say, okay, what does our attack surface look like?
What is our critical data, our critical systems that absolutely need to function? Let's do a bunch of security testing and let's make sure that the vulnerabilities that are found are fixed. And depending on how frequently we're updating our software and everyone's updating their software all the time, we need to be testing those deltas on a regular basis.
Um, this, I think is a very effective, uh, and efficient way, uh, to, to spend cybersecurity resources And boy, in our, uh, kind of our geopolitical environment right now. This is really important. Uh, absolutely topic in Russia and North Korea and Iran, right there, those three countries are, you know, they are spending, they're paying people to spend time to hack all of us.
They're serious about it. This is a serious game to them. It's not just a, uh, a discussion we're having about trying to secure our environments, right?
They're serious. Yeah. We're not doing this for kicks, you know, we're not doing this 'cause it's a nice to have.
We're doing this because attacks are happening all the time to all of us. You know, I think it's so interesting, um, some of the most recent SEC, um, you know, activity with regards to SolarWinds. Um, and while I don't personally, uh, know that I would go about it in exactly the same way as the SEC is doing, you know, I do have a belief that what they're trying to accomplish is they're trying to put more of an emphasis on the idea that security is really not optional these days.
It's really not optional. It really should not be optional. Um, and I, I, while, uh, there are specifics, uh, about, uh, what's going on, uh, that are not again, necessarily the way that I would personally go about it, um, I do see it being elevated, uh, to a different level of conversation.
And for that, I think it's very, very appropriate. Yeah. And I think that the Biden administration, it made the right move to at least have the SBO m discussion started saying, Hey, if you're gonna do business with the government, you better report to us what open source packages you're, you're consuming.
Because we may not wanna trust those packages. But I don't find that that kind of data, even though we have it, is being consumed and acted upon. Yeah.
I think, I feel like, I feel like it's still fragmented, still not, um, it's out there, but, but, you know, uh, great. You know, sbo m's, so far so good. So what, right.
The, the, one of the really interesting things that we have not figured out as an industry is how to effectively communicate technical security posture to each other and even SBO m information to each other in a standardized format. Every organization does it in a different way. And that means that every time you interact with another organization and any given organization has got to have probably like 75 vendors, you know, larger enterprises are gonna have hundreds, thousands of vendors.
Um, but without any sort of standard, um, or, you know, in the case of our industry, actually too many darn standards to choose from. Um, you know, the, the reality of, you know, a person on that security team who's in a vendor risk management role, you know, they've gotta, they've gotta sort of sift through and figure out and interpret, you know, each and every single one. Um, so there ends up being just a tremendous amount of manual work involved, uh, if folks wanna do it, right?
Yes. There is a tremendous amount of toil right now in that, in the, in solving the cybersecurity puzzle, a tremendous amount. And I think we will face that for the, at least the next five to six years.
Even in, you know, my world, you're, you're kind of, you're in the, you're in the pen testing business and I'm in the DevOps side. If we think we go back to our Jenkins, um, I, I repeat this many times 'cause it's a good thing to remember. According to CloudBees, they track about 90 million workflows a month, Uhhuh 90 million.
Now, I don't know if those are a duplicated workflows, so let's just say it's, you know, it's 9 million workflows a month even so, even being executed thousand of times, right? Even there even, yes. It's, it's a humongous number of DevOps pipelines that need to be updated to have security built into it.
And this will be a challenge for us because there's a, an extreme amount of toil in being able to achieve that. So that, uh, being offensive one way is to build it in there, right? The other way is maybe we talk about zero trust.
So will zero trust get us out of this problem and saying, we're gonna start blocking anything that comes from Russia or North Korea or Iran. We're gonna just block them completely. You know, where are, where are some big wins?
Do you have any ideas or have you thought about that? So I do think that there is a lot of value that comes with zero trust, but I don't think it's possible for zero trust to be fully automated. And what happens is the manual work just gets shifted.
Mm-Hmm. From my perspective, in an ideal zero trust model, you know, the most important stuff has a really big fence around it. And if someone tries to get in some human with their judgment and their opinion is coming in and saying, yes, let them in or no, do not.
Um, and that times 9 million ends up being, again, an extraordinary amount of work. Um, I have a kind of a crazy idea that it would be fun to, uh, share with you, uh, on this, on this, um, session today, which is, I happen to have a garden and I observe the cycles of that garden throughout the season, you know, and there's times when, uh, the seeds are just in the ground and there's times when the plants are growing and there's times when they're blooming and there's times when they're wilting and it's, and it's fall and it's turning to winter. You know?
And I actually think that software has this sort of cycle that it goes through as well. And there's a time when if software is not being looked after properly, maybe it should be sunset. But what we do is we treat all software all the time, like it's in full bloom.
And I think that's actually just not appropriate. I think it's, I think it's actually just a fundamental misunderstanding. You know, when we work in tech, right?
People who don't work in tech, they just assume that everything software works is supposed to work absolutely perfect all the time. And the reality is, some of us know that some software is being paid an incredible amount of attention to, and a lot of other software people aren't paying attention to it. It's not being updated.
All sorts of legacy stuff, all sorts of old integrations. Um, and so I think it would be really interesting, uh, if we had a way to evaluate, is it time to sunset this particular piece of software because it's actually introducing more risk than value. Really?
Interesting. That's a really interesting thought. You know, what can replace it?
What's, what's new out there? And boy, is it hard being from a having a software company, it can be really hard to get customers off of old versions. Totally.
Coming back to your point to say, upgrade your software, please upgrade your software, because we may know there's vulnerabilities out there, but we can't get them get, you know, get folks to update their software because it, it, it may take some time. It may bring down, you may, they may need to do a freeze for, you know, an hour and a half and may deny service for some period of time. But boy, isn't it, IM important.
And I think the better we get at from a software perspective and who does as a, a commercial vendor of software, the better we get at being able to have SaaS environments where we are managing the platform and updating this stuff for them. Yep. Uh, is ultimately going to be, you know, another way to be offensive in our, our approach to cybersecurity.
Because what we're doing, it's not necessarily defensive. What we're doing is we're pushing away. We are, you know, we are going out after our criminals, right?
We're going out after them and saying, no, no, no, no. Yeah. It's really, it's really, it's really a proactive approach, you know?
Um, I think that businesses have an awful lot of decision making power that affects an organization's security posture. Um, a funny little analogy that a friend of mine used to talk about was, he would say, you know, if you have a toddler and that toddler is running around with a pair of scissors, the best thing to do is to take the scissors out of the toddler's hands. You know?
But how often do businesses and organizations just to allow toddlers to run around with scissors? Because there's a lot of Toddlers running With scissors. There's just a lot, there's a lot of toddlers and scissors, you know, and, and, and, and it, and it is a business decision.
And there are gonna be trade offs. That toddler is gonna throw a big temper tantrum and you're gonna have to deal with it, you know, but you're gonna have mitigated the risk. And so I think this is both the complexity, um, as well as what makes cybersecurity super fun, uh, is all these different trade offs and, and really having a lot of the time no right answer.
So when you talk about zero trust, um, just to backtrack a tiny bit, and you talk about all those, these instances, whether it's 90 million or 9 million or whatever, how much of, of all of this we're talking about, I'm just gonna throw it out there, is AI going to help with 'cause Right. One person can't say, let this person in block this person. How much, I'm sure companies are already doing it, but I would assume AI is gonna play a huge part because it can do all the massive work and then a human can evaluate a smaller subset of that, right?
As far as being able to manage it, I just, another amazing, you know, application for ai. Absolutely. I, I completely agree with that concept.
I'm actually currently working on a new LinkedIn learning course that I believe will launch sometime around August 20, 24. And this particular topic is about artificial intelligence and application security. And I do think that we have an opportunity for any bit of manual work that we do, whether it has to do with software development, whether it has to do with cybersecurity activities, there's a spectrum of how much can be taken on by ai.
And at each stage of that spectrum, there's gonna be an associated confidence level with how well we think they're gonna do it, it's gonna do it, you know. And so there are gonna be basic, very well, well known, often observed, often repeatable patterns that can be detected. And AI can even get to a point where it's making this the decision, choosing the next action.
You know? But as, as soon as we move farther down that spectrum and things get to be a little more unusual, a little more customized, a little bit more of an edge case, that's where I think we have an opportunity to focus more of the manual effort. Um, and so I don't happen to think that, um, you know, AI's gonna take all of our jobs.
I I do think that it, that it will dramatically change the way in which we work. You know, I said to, um, my 8-year-old and my 11-year-old niece the other day, I said, here's an AI application that I want you to download on your iPad, because I want you to get used to using AI right now. Right away.
I said to them, anytime you would go on Google and ask Google a question, ask AI instead, because I would love for them to sort of naturally develop this capability for writing AI prompts. Absolutely. I think it's a really, really good skill to learn how to, you know, chat.
GBT is teaching us all that. And I, I keep telling the story. I, I was waking up with my eyes totally swollen for like three weeks in a row, and I couldn't figure out what was going on on.
So I was working and I just asked, give me a diagnosis for swollen eyes and what's the symptoms? And the first thing that came up was dehydration. Wow.
Yeah. And so I was like, okay, I'm gonna drink 60 ounces of water a day. And in three days my eyes stopped being swollen.
So I actually used it as for a medical condition. Well, Tracy and I have this conversation all the time because AI terrifies me. And she's like, AI is the coolest thing ever.
It's awesome. So I'm, she's helping me. Like today I am like this, you know, another example where AI is gonna be really helpful and yes.
Another reason humans aren't going away. You know, the whole, the whole concept that it's gonna, you know, there are gonna be some shifts. There's everything with, you know, with progress comes change, right?
There's always gonna be a shift. And that's why people have, we retrain entire groups of people to do different things. But it's, it's that way with everything.
AI isn't any different, but it's cool to, I'm trying to find the good, find the good. I'll tell you what, Bad this way. Think about it this way, Jody.
We, I was raised with encyclopedias. Well, I'm not Looking. Encyclopedias went away.
Encyclopedias went away when the internet became popular. 'cause you could find answers through the internet, but people's jobs didn't. Yeah.
AI is the same thing. It's just a different, we have a different relationship to data and it's going to be displayed to us in a different way. It's a complete shift, but it's the same thing, right?
It's just, it's the modern day encyclopedia. Well, and Jody, I'll tell you what, there are two fundamental reasons that I believe AI will not and cannot take over all of the work that we do. Thing number one is garbage in, garbage out, right?
AI works on data. And unless you have an enormous perfect data set, your results are never gonna be exactly right. Um, our data sets are biased.
They're too small. They're, they're wrong and They're shifting. Yeah, exactly.
Exactly. So that's thing number one. The other thing is AI requires processes and algorithms.
The AI does not know how to choose which process or which algorithm to run unless a human tells them. So, right. And if, you know, because I work in the area of application security, I think about things like static testing and dynamic testing.
I think about the differences between network security vulnerabilities and application security vulnerabilities. And if I have an ai, and that AI is designed to work through a workflow, having to do with finding network security vulnerabilities, and I point that at an app, it's not gonna gimme the results I want. We need people to dictate what type of process, what type of algorithm.
You know, it's like saying, um, you know, to an automated, uh, you know, chef robot, uh, you know, make me a pumpkin pie, you know? But if you, if you put in the cheesecake recipe, you know you're not gonna get a pumpkin pie. Um, and so there is, that Is an amazing analogy.
That is the best analogy ever. Maybe you'll Get a, you'll get a cheesecake, pumpkin pie. There you go.
A cheesecake. You'll probably get something delicious, but you're not gonna get a pumpkin pie. You'll not get pumpkin.
If there's no pumpkin in their recipe, you're not gonna get a pumpkin pie. Come On. That's amazing.
I'm sorry. That was a great analogy. I love that.
I'm gonna steal it. So before we run out of time, this is a question I really love to ask our, um, our guest, and tell us what brought you to technology. You're passionate about it as I am and as most of our, our guests are.
You know, how did you get started? Was there a woman in your life that said, Hey, you need to go into tech. Give us, give us a little bit of insights about your background?
It was my dad. I am the daughter of Chinese immigrants to the United States. When I was a little kid, my dad said, you know what, I'm gonna buy you Mavis speaking, typing software, because my dad was an attorney, you know, and he had a really great secretary who typed on his behalf, you know, but he was one of those one finger typers and said, Caroline, in your lifetime, it's gonna become really valuable for you to learn how to type quickly.
And so I learned how to type quickly at the age of, you know, 10 or something. Uh, and when I was about to go to college, he said to me, Caroline, what do you wanna study in university? And I said, well, I love dance, so I'd love to study dance.
And I think psychology is really interesting. So I'd love to study psychology. And he said, you're gonna study engineering and you're gonna study the hardest engineering at the top school that you can get accepted to.
And so I went and I studied electrical engineering and computer science at uc, Berkeley. And that was that, you know, and I, it was just, it was just the culture of the family that I happened to grow up in. Um, and while, um, you know, I had all sorts of, I would say behavioral and psychological responses to my father's, extremely high expectations of me, um, he did instill a confidence, um, and a kind of like, maybe, I don't know how to do this right now, but I can figure it outness about it.
Um, and now at this stage in my life, you know, as a mother and I'm looking at my kiddos and their lives are filled with technology, and I just want the world to be a safe and a happy place. Mm-Hmm. I just want my kids to be able to use their computers and go on the internet and play their games and be safe and be connected and create without having to worry.
That's what I want. You know? And so, um, I feel so grateful, um, that I'm in this field, uh, and that I get to do this type of work.
It's interesting almost all of us that we, none all of us that are in this field, we had a parent or someone who really was forcefully directing us into it. It wasn't something that we saw that we should do from naturally, like a little boy might. Right?
And it's different now. We had know somebody to say, go for it. It's different now.
You know, these days, you know, I don't know exact statistics, but when I studied computer science in college, it was not typical. It certainly wasn't typical for a woman, but it kind of wasn't typical anyway, you know, these days I think there are so many more computer science graduates than there were at that point in time. Um, and so these things do change.
Um, but I am, uh, I'm extremely grateful to my dad, uh, for, for pushing me in that way. And I hope that the STEM programs that are, you know, starting to really flourish throughout the u the us in particular, uh, can serve as your dad did to you can serve to other young girls who may not have a parent that said, you know, like my mother did, Tracy, you can't draw a straight line. You do math like crazy.
You probably should go into some field of engineering. You probably shouldn't do, you know, history is great, but it's not gonna get you the job you want and go do math. You know what else is crazy though is we've had these conversations and Tracy, how many times have we asked this question?
And it started out with, I played an instrument. I, I like to do drama. I like dance.
So much of what we don't acknowledge is that the arts are so important. Um, just as an example, my daughter's now an actress. She went to the Denver School of the Performing Arts here in Denver.
It's a public school open to any kid who auditions and gets in 12 different majors. We also have a STEM school, the School of Science and Technology. Do you know which school is on the, uh, US world and report top schools and gets the best standardized test scores.
The School of the Arts beats the science and technology school every year. 'cause they have art in their curriculum every day. And the kids that just go to the, the science schools don't.
But I hear so many of, so many of the, of you guys who, who we've interviewed have an art artist in them of drawing or dancing or music. And it so stimulates everybody. And it's so important and Needs to be there.
I think you, you have to have both, right? You do. You have to, you have to, you, you can't just copy everything got, you have to have Both sides of your brain working.
You Have to have both sides of your brain working. So I think that that is why women are so, uh, perfectly kind of positioned to be in technology. And one area that if you're listening and you're a young college student and you're a woman, think about going into cybersecurity.
It is going to be a hot space and it's gonna be around, it's gonna be, everybody's gonna be pushing it for at least the next five to eight years. So consider going into cybersecurity or any area in defense. Yeah.
Get your, get your daughters in coding classes. Our granddaughter's middle school. And she, she loves it.
She thinks it's fun and they do it in school. And she, she thinks it's the coolest thing. Her brother not so much, but you know, that's okay.
Good. That's great. Exactly.
Well, I think we're like right at the end of our window here, but Caroline, thank you so much for being here. I am so excited that, um, you got to join us. Um, I can't wait to see you at RSA in May.
And um, we just really appreciate you taking the time. We know you're a busy lady and your time is super full, so we appreciate you being here with us today. Trace, you got anything?
No, but thank you Caroline, for a fabulous journey into the world of cybersecurity. This Was so fun. Thank you both.
Great. Well thank you for being with us. Hey everybody, that's, uh, a wrap on today's episode of Text Strong Women.
Be sure and stay tuned. There's a lot more great content and programming today, so be sure and watch and we'll see you next time on Techstrong Women. Bye.

