EP 175: What’s a “Hacker”?
Our bi-weekly Inflection Point bulletin will help you keep up with the fast-paced evolution of cyber risk management.
Sign Up Now!
About this episode
January 14, 2025
What’s a “hacker”? Are they good or bad? How do they think? Can their thinking help us in other problem spaces? Let’s find out with our guest Ted Harrington, who’s dedicated his career to ethical hacking in order to help organizations build better, more secure systems. Your hosts are Kip Boyle, CISO with Cyber Risk Opportunities, and Jake Bernstein, Partner with K&L Gates.
LinkedIn profile — https://www.linkedin.com/in/securityted/
Website — https://www.tedharrington.com/
Episode Transcript
Speaker 1: Welcome to the Cyber Risk Management Podcast. Our mission is to help executives thrive as cyber risk managers. Your hosts are Kip Boyle, Virtual Chief Information Security Officer at Cyber Risk Opportunities, and Jake Bernstein, partner at the law firm of K&L Gates. Visit them at cr-map.com and klgates.com.
Jake: Kip, what are we going to talk about today on episode 175 of the Cyber Risk Management podcast?
Kip: Jake, we are going to look at something that, at first glance, people might think, oh man, we've talked about that so much as an industry, but yet there still seems to be some persistent misunderstandings. I'm talking about, what's a hacker? Yeah. That's what we are going to talk about. We've got a guest, his name is Ted Harrington, and he has dedicated his career to ethical hacking, and he told us he's on a mission to help organizations build better and more secure systems, so who better than a hacker to tell us all about what is a hacker? At least that's what I thought-
Jake: Yeah, I think this will be great.
Kip: Ted, welcome to the podcast, we are really glad that you agreed to be our guest, we'd love for you to introduce yourself, so take it away, tell us who you are and what you do, and feel free to embellish or give us some more details.
Ted: Yeah. Well, thank you guys for having me. I like the permission to embellish, it's like, just make stuff up, do what you want.
Kip: Yeah, maybe consistent with the hacker ethos.
Jake: That's social engineering, I mean, that's what it is.
Ted: Yeah, we are all going to go around and just state some of our mothers maiden names and other pertinent information, which may or may not be true, but that's for you to find out. Yeah. Well thanks for having me. As you mentioned, my name is Ted Harrington and I get to be in a position to live on the front lines of ethical hacking, I'm one of the partners at an ethical hacking company called Independent Security Evaluators, and basically their concept is, companies hire us to hack them, to find the problems before the bad guys do.
I've just been so passionate about this field once I found it about 13 years ago is when I first entered security and I was like, this is for me. I've just really been so fascinated and passionate about, and interested in this concept, and it's gone beyond just running a company of hackers, I've written a bestselling book called Hackable that talks about how companies get security right or get it wrong, and I gave a TED Talk about some of the things we are even going to talk about today, I imagine, and I'm working on another book right now that talks about these ideas. That's me, I live amongst the hackers.
Jake: I love the name of your company, I think you are doing some brain hacking of insurance companies. They are really going to be drawn to independent security evaluators. That's a very insurance friendly name, I like it.
Ted: I appreciate you like it. I may be not as much of a fan of the mouthful that it is, but there is a strategy behind the idea of like, well, what do people want? What are they looking for? What's the problem we are trying to solve? People are saying, well, we need an independent view of our security, we want someone independent to come evaluate our security. It's like that.
Jake: Yeah. You could have called it Ted's Hacks or as in used a bunch of lead speak, but I don't think you would have gotten any real traction with certain types of people.
Kip: No, I like your Soviet aesthetic.
Jake: Yes.
Kip: Yeah, that's funny. In Soviet at Russia, a computer hack you.
Jake: Yes, that's right.
Kip: There's some other things that Ted's done that I think is noteworthy before we really start diving into answering the question, what's a hacker. For example, last June, Ted was a guest at a dinner that I moderated and which is where we met, and I really enjoyed that experience and I have read his book, Hackable, and I really enjoyed the book. This episode has its origins in part, in our meeting up about six months ago as we record this, and then beyond that, you are a keynote speaker. Tell us about the IoT Village, that's interesting to me.
Ted: Yeah, for anyone who's ever heard of or been to DEFCON, the largest hacker conference that exists, they have this concept there, which is, villages and villages are, I think of it as almost like a conference within a conference in that each village focuses on a particular subject matter. Many years ago, actually approaching 10 years ago, so next year is going to be the 10-year anniversary of IOT Village, we started this concept to focus on connected devices and how can we, thinking about that as a security challenge, how can we advocate for change?
How can we train people, give them hands-on opportunities to hack things? That's really what IOT Village has become. It's this sort of hacker carnival, in a sense, where we get a bunch of connected devices and give people opportunities to hack them. The event travels to a bunch of different events. It started at DEFCON, but now we go to RSA conference, many of the editions of B-sides and just a bunch of other places. It's pretty cool, it's a way to both engage and give back to the hacker community that we live in, and that has given so much to us. It's a pretty fun thing to do.
Jake: We say that word a lot. Ted, what's a hacker?
Ted: I've been asking that question of people for a long time, and I think it's important that we ask that question and we answer it because there is rampant misconception about what a hacker is. A lot of people think a hacker is bad, and that's not true. A hacker is not bad. A hacker is not good either. The term is neutral. What a hacker is, a hacker is a curious, non-conforming, committed, creative problem solver. They are the kind of person who looks at something and says, is there a different way? That's what a hacker is. Now, the difference between a good hacker and a bad hacker is motivation.
When we read headline news, it talks about hackers attacked company blank. That is a type of hacker, but that's not all hackers, that's malicious hackers. A malicious hacker is defined by the motivation to attack an organization in order to obtain some benefit. Maybe it's money or maybe it's notoriety or geopolitical advantage or whatever. That's a malicious hacker, but there's an opposing force as well, and that is ethical hackers, and that's the world that I come from.
Ethical hackers use all the same tools and techniques, approaches, methods as the bad types of hackers, but we do so in order to improve the security of a system, we want to find those same flaws, we want to find those same exploitable vulnerabilities, but we are not trying to exploit the system, we are trying to improve it. It's really important, I think, that we understand that distinction that when we refer to someone as a hacker, we are not saying that they are good or they are bad.
We just talked about DEFCON, if you go to DEFCON, I would probably be wrong if I said that 100% of the people there are good, but most of the people there are the good types of hackers, they are trying to learn the skill, the profession, this is what they do for their company. If you were to say, hey, the 25 or 30 or 40,000 people come to this, I don't know the exact number, but it's a lot, the 25,000 people come to this, they are all bad because they are all hackers. They'd be like, that's not me, I'm a hacker because I'm a creative problem solver, I look at things differently than other people. That's what a hacker is. It's the application of the hacker mindset that makes someone good or someone bad.
Jake: Yeah, I think that's really important to discuss. I think pop culture has really changed. Lifehacker, isn't that a website or it was a website? Lifehacks, that's certainly something that people will share and talk about these days. I have a random question for you, because why would I stick to the script fully? There's these terms, black hat, gray hat and white hat. Do you like these terms? Do you dislike them? Do they have any value? What's your opinion on that phrase or those three words?
Ted: Yeah. Two of those terms are valid and one is not. Black hat and white hat are valid terms, and I argue that a gray hat hacker does not exist. The term doesn't make sense. Let me explain briefly what each of these are and then we can talk about why gray hat doesn't make sense. I've found this particular topic to be quite divisive, so there might be people calling into this, not calling in literally, but commenting on the show that they maybe have a different viewpoint. Here is the difference between these types of hackers. We talked about motivation a moment ago, and we are talking about motivation here. A black hat hacker is someone who is the bad kind of hacker, their motivation is to harm in some way, I shouldn't say to harm, their motivation is to obtain some benefit and the byproduct is usually harm.
These are the companies who are organized crime, who are trying to obtain profit, nation states who are trying to gain a geopolitical advantage, even hacktivists who ostensibly have a cause they're advocating for, but they do so in some malicious ways. That's a black hat hacker. A white hat hacker is an ethical hacker, someone who tries to find those same flaws but does so in order to improve the security of the system. We've kind of already talked about the distinction between good and bad, and that's the distinction between black and white. As a fun aside, if people don't know this, where that comes from is, classic western films, that was literally in a black and white movie, how they differentiated who was the good guy and who was the bad guy in the movies. The bad guy wore a black hat and the good guy wore a white hat. In the recent editions of Westworld, they use that same archetype that's kind of a western film, and the bad guys are wearing black hats and the good guys are wearing white.
Jake: Right, and literally the cowboy hats too. Those big-
Ted: Literally cowboy hats, yes.
Jake: The set scenes, yeah.
Kip: Nothing like mixing metaphors. Okay, now you assert that gray hat is a false distinction. What's going on there?
Ted: Gray hat in my estimation is not a real thing. The reason for that is that we are talking about motivation, so when people say a gray hat, they are like, a little bit good and a little bit bad. I argue. You really can't be a little bit bad and still be good. You can do bad guy things for a good motivation. That's what a white hat hacker is. A white hat hacker says, I'm going to use the same tools, techniques, methods, approaches, I'm going to think exactly like the bad guy thinks, I'm going to take it right up to the point of exploit, but I'm not going to exploit, I'm going to say, if I took the next step, this is how this system would be harmed. When people say gray hat, it's like, well, how can you be a little bit bad?
How can you be like, well, I'm only going to exploit things that don't have a huge impact, or I'm only going to exploit companies that are greedy, or I'm only going to exploit the government? It's like, you are exploiting, so this idea that we are going to say gray is the combination of white and black, and to say that once you put even a drop of black in there, it's not that it's gray, it's black. That's the way I think about it, and I think using this idea of color mixing as somehow a way to talk about moral spectrums, I have a hard time with it. Now, there is an argument that someone has made to me recently that I've been noodling on, that I still don't fully necessarily agree with their point, but there is an argument here because it goes to the discussion about ethics. They say, well, what about someone who works for a nation state attacking another nation state, depending on your context, they are good or they are bad? That's kind of gray-
Jake: I would say, we can haul out the Obi-Wan Kenobi quote from that, he said that the truths that we cling to depend greatly on one's point of view. I think from their perspective, they are white, from our perspective, they are black. We could also look at this in terms of legality. Are you operating within the law or outside the law? What does that even mean? I tend to agree that gray hat is a very difficult line to walk. I don't know what it means, which perhaps is the greatest indicator that it may not exist.
Kip: Yeah, distinction without a difference.
Jake: A distinction without a difference. Before we move on to the next kind of how hackers think and all that stuff, I also want to ask another kind of dichotomy question. Hacking versus pen testing. Let's assume white hat hacking, is it the same thing? Are they synonyms? They're related, but I'm curious what your, as Kip knows, words and definitions matter to me as a lawyer, so I'm curious from your perspective, if someone is like, oh, you, you are a pen tester, do you say, no, I'm a good hacker, or do you say, yeah, that's right?
Ted: Yeah. That's a great question, and even the few ways that you asked it, you would answer slightly differently. The two ways you asked it were, first, what's the difference, are they the same? The second was, when someone asks you are you a pen tester, do you correct them? The reason that that's a notable difference in those questions is that pen testing is a specific thing, it has a literal definition, but security marketing has absolutely abused that term and it has come to mean something else.
In fact, it's come to mean everything, basically. People use pen testing now as the same as security testing, which security testing is the umbrella term for any testing of security, and people use pen testing to describe that. An example of that is where you look at people call a pen test what it is, which is looking at a built system and looking at a particular, clearly defined, clearly scoped attack scenario, and then answering the question, did you or did you not breach the defenses within that context? I'm looking at this built system and I want to say, can I escalate privileges? People are also using pen testing to talk about running an automated scanner, and those are really, really different things.
The metaphor I sometimes think about this is like, it's a real problem. The term matters, it's a real problem. It's like, let's say you go to the doctor and the doctor is like, oh, you need a knee replacement, and you are like, all right, I'm going to get a second opinion. You go to the second doctor, and the second doctor is like, yeah, you need a knee replacement, but that doctor is not talking about replacing your knee, they are talking about, you need to fuse your spine, and it's like, well, no one would do that, those are two remarkably different things. Why would anyone use the same term to talk about two different things?
That's exactly what's happening in security is this term pen testing is become this catchall. Are they the same thing? Pen testing is a type of hacking, so there's overlap. Pen testing is a subset of the profession that is hacking. The second way you ask the question, when people say, are you a pen tester, do you correct them? No. The reason is, well, first of all, we are pen testers, so there's that, but even if we weren't, unfortunately, despite my vehement argument about the problem that is this term, the horse is out of the barn and there's just no way, even if this podcast was heard by literally every single person who touches security, it still wouldn't change enough hearts and minds for everyone to be like, okay, got it, I now know what pen testing is. In a way, we almost have to accept like, okay, this person said pen testing, they are talking about security testing. I now have to ask a bunch of clarifying questions to get to the heart of what they think they are talking about. The answer is yes, I'm in that genre of what you are asking about.
Jake: To move us to the next topic-
Kip: I'm not ready to do that yet, Jake.
Jake: Okay. Well then here's what I was going to say is that, and maybe this doesn't move us then, but it seems to me that another way to think about it is that pen testing is a job or a function, hacker is a mindset. Go with that.
Kip: Or an identity.
Jake: Or an identity.
Ted: Wow, that's really good.
Jake: You can use that for free.
Kip: Yeah. While you think about that, Ted, I want to share an experience that I went through. This is in the late-nineteen-nineties, and that's when I first noticed that we were losing control of the word hacker. What I saw, and I think is kind of the origin for how hacker-
Jake: I'm not confident Ted was alive in the early nineties.
Kip: No, that's okay, this is good history, let's bring him then. What I saw was that the news media struggled to put a label on all this malicious behavior that was happening on the internet. Some bright wiseacre reporter decided that they were hackers, and that was the end of it. I mean, that's kind of how the horse got out of the barn on this one. Somebody stole our word, the word from our subculture, and they twisted it and released it into the mainstream consciousness. I agree with you, Ted, we are never going to get that word back, it's gone. Everybody else seems to own it, and we have to spend our lives clarifying it when it's absolutely necessary and otherwise just grinning and bearing it.
Ted: Yeah, I agree with you. I mean, it is an uphill battle. The way I think about it is, let's say you go to a wedding and you meet some random person who sits at the table and they are like, oh, what do you do? If you start talking about hackers to them, nine times out of 10, they are going to be like, well, that's bad. You are a bad person? You are telling me you are a bad person?
Jake: Why are you admitting your criminal behavior to me
Ted: I'm not. It's reinforced by security markers. I mean, I was in Boston recently and I was in the main train station in Boston, and it's pretty cool the way that some of the marketing activations they have there, it's like there's this main atrium area and there's a bunch of places that have signage and all this stuff for all these different brands. The day I was there, there was a security company who had bought all of them. It was actually really powerful as a marketing technique, it was really powerful, because literally everywhere you looked, it was the same message for this one company, but it ticked me off because it was a security company and the message they were making was literally equating hackers and cyber criminals.
I'm like, some hackers are cyber criminals, but not all hackers are. I'm like, from our own space, we are perpetuating this nonsense. That's why I find it to be important to come on shows like yours and talk about this. I mean, this next book I'm writing is teaching people what the hacker mindset is and how to apply it. It's kind of funny to me that in it, several places throughout, I have to be like, and remember the hacker mindset is not good or not bad, apply these for good, do not apply these for bad, I'm not saying be bad. I have to literally say-
Kip: That's a great segue, right?
Jake: It is. It is a great segue, although Kip, I was going to segue myself because I'm so engaged with this conversation, which is like, I think it would be fair to say, going back to that pen tester thing, I think you could fairly say that not all pen testers are hackers, right? Because if it is a mindset, I think maybe 10 years ago, I think all pen testers were hackers, I think as a general matter, but I think nowadays you could almost get a technician pen tester, right? Like an x-ray tech, right? They're not a doctor, they know how to use the machine and they go and do it. I think what's going to be interesting going forward, particularly as cyber security as a profession grows and expands is you will have a difference. Maybe not in title, maybe not anywhere, but people will know, those people who are hackers are going to have a different career path than those people who aren't.
I think what's fascinating about this is that we need people to understand that this isn't a label, a moral label, it's really a label about skills and thinking. Think of it this way, you've ever seen the paper chase, the whole famous line is, we are going to... Well, I don't even remember the famous line now, but it's about taking your minds full of mush and turning you into thinking like a lawyer was the idea. When someone says, oh, you are just being a lawyer, they don't mean necessarily you are literally an attorney at law. They might mean that you are engaging with me in a way that a lawyer might think and act. I think hackers are the same way. It's a way of thinking, a way of looking at the world. I think that this is another way that we can push back against this idea that hackers are bad. No, it's a way of thinking, a way of being. To that level, how do hackers think? What sets them apart from that hypothetical pen tester who is a technician who is just kind of like-
Kip: Running an SOP.
Jake: Yeah, running an SOP, that's exactly right. They are running a procedure or protocol, they're not a hacker. Why would we say that?
Ted: Well, I think we could zoom even a little further out to answer that. Let's not talk about necessarily the mindset of someone whose job is to work with computers, because the hacker mindset is not about computers, it's about life, it's about how you approach anything. As I've been working on this book idea, I've been interviewing hackers, I've been of course observing hackers, which is what I get to do with the people who work for us. I mean, I go to hacker conventions, I go on vacation with hackers, hackers are my friends, I'm around hackers all the time, and I started thinking about, well, how do they think and what do they do or how do they react in certain situations? Of course, I started extending that by interviewing other hackers. These four themes really became apparent through the process of researching this question, what is a hacker? How does a hacker think?
I would literally sit down with prominent hackers and say, what does it mean to you to think like a hacker? That was those four C's that I already mentioned before, these themes are what came out that hackers are curious, they are non-conforming, they are committed and they are creative. What's interesting about that is, you look at those four things, those are the themes that I've identified across most hackers that I've been interviewing or observing, but none of those have to do with computers, those all have to do with how you think about a problem and how you attack it, and what makes a hacker, whether a good kind or a bad kind so good at what they do is that they have all four of those attributes working in harmony.
They are curious about how a system works, they want to know why the system exists and what are the components. They want to know. They're not willing to just follow along with the way that everyone else does it or they are supposed to do it just because that's what they are supposed to do, that's the non-conformity, they are willing to invest the time and the effort and the money and the resources to pursue their targets. That's them being committed, and they're innovators, they come up with new ways of attacking old problems, and that's the creative part.
Jake: Yeah, I'm totally a hacker.
Ted: I love that.
Jake: Nobody I work with that would not say that's true.
Kip: Okay. Can you proclaim that you are a hacker or is that something that other people have to tell you?
Ted: That's a good question. I haven't pondered that particular question yet, but I think maybe inherently I have pondered it, without expressly asking it. The reason I say that is that towards the end of this book that I'm writing, I actually describe in there, if you do these things, you are a hacker. It's not my role, it's not even my responsibility, I don't even have the authority to say who is a hacker and who is not a hacker. I think there's a hacker in every single one of us. I think every person, the book is literally called Inner Hacker, because I'm like, there's a hacker in you, and my job is to bring your inner hacker out.
Jake: Interesting.
Ted: There's a hacker in all of us, the question is just, are people willing to let that hacker out? A great example of where that is difficult for probably most people in fact, when we think about non-conformity, that mindset, being non-conforming is risky. It's like-
Jake: Definitely.
Ted: Rules exist for a reason, the tribe operates away for a reason, for safety in numbers. On a sports team, you wear a uniform so you look like everyone else. It's like, conformity is really powerful, it's safe.
Jake: It's safe.
Ted: That's exactly right.
Jake: Yeah, it's a powerful force.
Kip: Yeah, it is. I think there's an irony in all the non-conforming people non-conforming in a conforming way.
Jake: I totally agree with this.
Kip: Yeah.
Ted: It's so funny you've said that. I remember the first year we were doing DEFCON and I made up a bunch of t-shirts for our team, and the T-shirts were white, and one of the people, he goes, he's like, Ted, we don't wear white t-shirts here, we are hackers, we do things a little differently. I'm like, what do you wear? He's like, we wear black t-shirts, I'm like, wait, isn't that just conforming to a different norm?
Jake: Yeah. I'm now realizing that if I want to go be a non-conformist at a hacking convention, I'm just going to wear a suit.
Ted: There you go.
Jake: I bet you I'll stick out.
Ted: That would be very non-conforming, yeah. It's like, the person with a Mohawk wearing a utility kilt, everyone is like-
Jake: I literally was thinking someone's wearing a utility kilt, I'm like, in a group of hackers, that utility kilt is not non-conformist.
Kip: Yeah.
Jake: It's very conformist.
Kip: It's very conforming in my nonconforming subculture.
Jake: Very funny.
Kip: Yeah, it's pretty funny. I love these four dimensions, curious, non-conforming, committed and creative, and I think you are right that the non-conforming bit is probably psychologically, emotionally the hardest thing for the inner hacker to overcome in order to truly embrace this ethos or possibly as an identity, because I definitely know that when you go to DEFCON, you see the people who have turned hacker into an identity, that is who they are, that is how they live their lives, that's the oxygen they breathe, but then you walk across the street and go to black hat and it's like, well, we are talking about the same stuff, but these people don't really identify as a hacker in the same way, it's a very different vibe, atmosphere, everything, even though we are having pretty much the same conversations. I think that's really interesting, and I'm looking forward to your book. When do you think it's going to come out?
Ted: It will be out in the summer of 2025.
Kip: Nice. That must mean you are close to declaring a finality on your manuscript then, because I know-
Jake: It's feature-complete.
Kip: Yeah, there's a long lead time to turn a finished manuscript into a printed book.
Ted: Yeah, I'm getting close to submitting the manuscript for editorial review. Yeah, I am aiming to have this books in hand by DEFCON in summer of 2025.
Kip: Nice.
Ted: Yeah, we are coming up against a timeline to get it finalized.
Kip: Are you working with a traditional publisher?
Ted: Not the same publisher that both Kip, you and I worked on the last go-around. Actually, I have your book, you can't quite see it because of the shallow depth of field, but your book is right behind me on the bookshelf right now.
Kip: That's super kind of you. I've got your book sitting right here as well, but I don't have any flair
Ted: I see a bookshelf with space right there.
Jake: Bookshelf.
Kip: Don't have any flair.
Jake: What I'm curious about is, what are the ways that, I mean, the way I think about it, and one of the reasons I know I'm a hacker is that my hackles go up when people are like, you just have... I am non-conformist in a way. It's so weird. I have a-
Kip: You mean in your attorney culture?
Jake: Yeah, I'm like an inveterate rule follower, I get really annoyed when people speed on the freeway. At the same time though, I push back against rules, so there's this paradox of hacking, and I think that paradox is probably to some degree within everybody, but I think from a security standpoint, I do want to get to the last question here, but before we do that, particularly from a security executive standpoint, how would you advise them to embrace their inner hacker in order to bring a different perspective and really improve their organization's security by doing just that, by embracing that inner hacker?
Ted: Yeah, I love that question. There's this story that I came across as I was interviewing people for this next book, and it is exactly the question that you are asking. I was talking to this CISO who had just joined, she was working at one public company and then had moved to this other public company, so this is sort of her getting her feet on the ground, first board presentation, and she was going to be asking for funding for a large security initiative. It seemed like a no-brainer, right? Because the company obviously needed this, she had demonstrated why it was effective, had all these metrics from her previous company, it was like, going to be a slam dunk. She went in, she gives this really well-thought-out presentation, it was succinct. She visualized things where she needed to. The call to action was simple and straightforward, and it was something the company needed.
It seemed like an easy thing to do. Unfortunately, she ran into this major buzzsaw that many CISOs run into, which is that the board who was tasked with approving this initiative, they just didn't get it, it didn't resonate with them, they were like, I don't see the point, why would we spend money on that? Blah, blah, blah, blah, blah. She walks away kind of bewildered, and she's like, what happened there? I thought this was going to be a slam dunk. This seems so straightforward, they need X, here's X. What happened? As she was pondering that question, she started implementing some of these concepts that we described where she was like, there's got to be another way. Most see CISOs run into that at some point where it's, the business doesn't understand security, they don't understand how to spend money, they don't understand why it's important, and that makes sense because most people who serve on boards didn't come up through the security profession.
Security is hard to measure, there's these misconceptions that security is expensive, all this stuff. Where most see CISOs have to just sort of accept it, that that's the way that it is, she was like, no, there's got to be another way. Ultimately, what she wound up doing was she realized she'd made this assumption that was flawed that these board members understood the problem and understood how solving it would directly benefit them, and so once she realized that flaw, she realized, oh, here's the new pathway. The new pathway was, she first reached out to one board member who she had a pre-existing relationship with and had a one-on-one conversation to figure out what does this person care about? What is their level of understanding of security? How do I make it clear that this initiative aligns to what they care about and their area of expertise?
By the time that conversation was over, that person said, oh, we absolutely need this, how can I help you? She said, well, can you help me with person number two? Systematically, person by person, she went one by one through the board, and the pitch, I guess you could say, was slightly different to each of them because they had different backgrounds, different understanding of security, they had different tolerances for what to spend money on. When she had all that, then she came to the next board meeting and now knew exactly what to say, how to say it in ways that would resonate with these people. She really displayed that certainly the commitment, the curiosity, the willingness to be creative and how to approach it, and certainly the non-conformity too. In a lot of companies, the CISO is not welcome to speak directly to members of the board, they have to go through the CEO or things like that.
As a result, in that next meeting they opted to fund this really big, really important initiative. I love that story when she told me that because there's no part about this that has anything to do with hacking a computer system, it's more about, there is a system involved, the system is how our budget is approved. She certainly looked at that like a hacker, and as a result, found a new pathway to achieve her goals.
Jake: I mean, it perfectly encapsulates an example from the talk, sorry, at Secure World last week, Kip, that we went to, there was a panel there titled Hacking the Board, and it took me a minute to realize what they were talking about, but that's what they were talking about. It was literally about-
Kip: It wasn't on carpentry?
Jake: It was not on carpentry, it wasn't on hacking-
Kip: Getting into their mobile phones?
Jake: No, not the motherboard either, it was hacking the management board, the board of directors. That's a really good example of doing just that.
Kip: Well, of course, hackers are practicing in all kinds of different skillsets, right? In areas. I mean, one time I did a deep dive and I was like, well, where did this hacker term come from originally, because it was here before I showed up on Planet Earth. In the United States, it came up in the Massachusetts Institute of Technology. There was a model railroad club, and they talked about hacking power supplies and things like that. This is like 1955, but I went back even further, and apparently hacker is also a description of a carpenter who does quick and dirty work with an axe, like a hatchet. Right?
I can take a piece of wood and I can hack at it, and I can make a chair really quickly. It's not going to look good, it's not going to be all polished, and neat looking, no one is going to want to buy it, but it's going to work. Right? It's really interesting to see how language evolves over time, but even today, people are hacking in all kinds of different situations, so I think that was a great example that you brought up, Ted. It doesn't have to be about technology.
Ted: I think that story also reveals something important to this conversation that we haven't talked about yet, which is, why would someone want to think like a hacker? Let's say someone is listening to this right now, they're not in security at all, and they are like, well, why would I want that mindset, how does that help me? How does it help me to be curious or committed or non-conforming? Well, what the hacker mindset does for us is, it helps us think about the situation differently. When you can think about a situation differently, that reveals new pathways to accomplish whatever it is you are trying to accomplish. That's why hackers are successful, right? They are told that, well, only this type of person can access this type of thing, and it's like, well, is that true?
What if we did something else, can someone else escalate privileges, etc? When we can do those things, when we can think about our situation differently so that we can find these new pathways to achieve our goals, now all of a sudden the outcomes are amazing. We can achieve our goals bigger or better or faster, or maybe there's certain goals that would be impossible to achieve if we hadn't adopted this revolutionary mindset. When people think this way and they can apply this attribute, this hacker mindset to other things, it works for everything. We talked about how it works for getting a board to approve funding a security initiative, but it works for personal things too, like maybe how you get promoted into that next role or how you get funding for the company you are trying to start-
Kip: Fix something that's broken, and you don't want to go out and buy a new thing, so you are going to hack it so it keeps working somehow, right? You are going to pull it apart, you are going to figure out, oh, it's just this capacitor, I just have to swap that out, or whatever. Yeah, I think you've done a really good job of explaining the hacker mindset and why it's useful outside of the context of ethical hacking and with computers. Well done. I like that.
Jake: That's excellent.
Kip: Well, listen, we are just about out of time for this episode. We are really glad that you agreed to join us as our guest, Ted. Now, if people find what you are talking about really interesting and they want to know more about you and your work, how should they do that?
Ted: The simplest is just my name, just tedherrington.com, you can find on there where to find me on social media, on LinkedIn, Instagram, whatever. Of course, there's a way to contact me directly. You can find information about our security testing services, about my existing book, about my forthcoming book, about my TED Talk, everything we talked about today, just go to tedherrington.com.
Kip: Lovely. I'm going to put that in the show notes, I'm also going to put your LinkedIn profile URL in the show notes just to make it easier for people to reach out and hack you, I mean, say hi. Yeah, that's wonderful. Jake, any last words?
Jake: No, this has been great, thank you so much for joining us.
Kip: Yeah. We are wrapping up this episode of the Cyber Risk Management Podcast. What did we do today? Well, we talked about what's a hacker, and I think we did a great job of unpacking that. Thanks again to Ted Harrington, our guest. We'll see you next time, everybody.
Jake: See you next time.
Speaker 1: Thanks for joining us today on the Cyber Risk Management Podcast. If you need to overcome a cyber security hurdle that's keeping you from growing your business profitably, then please visit us at cr-map.com. Thanks for tuning in, see you next time.
Sign up to receive email updates
Enter your name and email address below and I'll send you periodic updates about the podcast.
YOUR HOST:
Kip Boyle
Cyber Risk Opportunities
Kip Boyle is a 20-year information security expert and is the founder and CEO of Cyber Risk Opportunities. He is a former Chief Information Security Officer for both technology and financial services companies and was a cyber-security consultant at Stanford Research Institute (SRI).
YOUR CO-HOST:
Jake Bernstein
K&L Gates LLC
Jake Bernstein, an attorney and Certified Information Systems Security Professional (CISSP) who practices extensively in cybersecurity and privacy as both a counselor and litigator.