Dana Mantilia on Why Humans are the Weakest Link in CyberSecurity
In this episode, Frank and Andy interview Dana Mantilia on Why Humans are the Weakest Link in CyberSecurity.

Hello and welcome to data driven.

The podcast where we explore the emerging fields of data science, machine learning and artificial intelligence.

In this episode, Frank and Andy speak to Dana Mantilia about cybersecurity and why companies are not investing their time and attention where they should be.

This episode was originally recorded on a live stream and this was the first time we had a guest join us on the life stream for a show.

Season 4 just keeps the innovations coming.

Without further ado, here are your hosts Frank Lavigna and Andy Leonard.

Alright, thanks for tuning into data driven. If you're watching this live, thank you for taking time out of your day. I realize this being the lead up to the Holidays. Things are kind of hectic. I know in Chateau Lavigna things are very hectic today.

Andy and I are happy to announce a new guest that we have with us. I first saw her on LinkedIn when she would do these really cool training videos.

On basically security topics.

An with with Black Friday, literally a week from now Cyber Monday and the just the The Creativity alarmingly creative and flexibility of scammers that we've had in light of the kovid, pandemic etc etc.

I figured it would be worth having kind of a good discussion about just the basics of cyber security and why it's important my wife happens to be in the cyber security field, so I'd like to think that I'm better prepared, but I know if you think you're better prepared, that's probably a vulnerability.

So welcome to the show, Dana.

Well, thank you for having me nice to be here.

So this is you are actually the 1st guest. We're going to have on the show that we interviewed live on a live stream first on video.

Very honored, very.

Honored so awesome. We're trying to push the boundaries for season four, so tell us a little bit about you and your company for those that haven't seen your videos on LinkedIn.

OK sure yeah. My name is Dana Mantilia an I am the founder of identity Protection Planning an we tried to help educate people in very layman's terms on how they can protect themselves from identity thieves and cybercriminals. And so we have a variety of different kinds of training. Either you know, training data, webinars, some videos or we have an on line.

Platform that's short little videos that everyone is required to watch.

And just to kind of start spreading the word, I mean cybersecurity is not going away and unfortunately the the frontline workers are the people that really are maybe not educated on it and they also are the ones that are clicking on things they shouldn't be clicking on so.

No, so that's a good point. So one of your most recent videos, and this is the one that made me think we should have her on the show.

Was the one the gift card scam and how?

Somebody in your organization got snared up in this.

Yeah, I mean it's.

It's crazy, I mean that the way that I did that little video is how exactly how it happened. She came to my office door with her codon and I said, well, why do you have your code on and she said, oh I'm going to get that stuff you need and I said well, what stuff are you talking about? And she said this stuff, we were just messaging back and forth about. I said I was. I've been sitting here at my office just doing work I didn't.

Message you about anything.

So then she showed me and they they person initially sent an email that looked like it was kind of from my email very similar, which is always usually what they do. And then you know the urgency factor. I always tell people when there's a sense of urgency. We have to stop and say, is this really a big big emergency here to go buy gift cards? But people want to please their boss so they get these emails and they act upon them.

So she then then the person said, can you give me your email? I mean your cell phone. I wanted to text you this. So then the conversation jumped over to her cell phone and now they're texting back and forth and she said, well, how am I going to pay for these?

And then he said, well, you know what? Just when you get to the store, read off the numbers in the back of the card and then when you get back I'll reimburse you. So they were. I mean, it was just back and forth and back, but anybody would have fallen for this anybody.

Wow, the thing that struck me is the most insidious part.

It's how they moved away from email pretty early in the process, because maybe I mean it was a good. I mean, there's a I don't know. As a data scientist, I I hate giving out statistics, but let's say it was a 5050 chance that that person had your cell.

Phone number.

Millimeter like an an. It's a good gambit for them because I guess they didn't have your number already saved in their phone, so they could have this whole conversation with you, right? Yeah, an I would assume that folks in your organization are well trained.

Well, we're at least talking about this stuff right times. That's that's a startling factor, is that?

You know we're talking about all these things all the time and we we totally almost fell for it so.

Well, I never disclosed this publicly.

Until I'll do it now is that one time Microsoft? I work for Microsoft, they they pay the mortgage, they pay for the electricity and it goes through the my little monitor display there.

But they will routinely send out kind of phishing emails.

And it will be like urgent you have to, like, you know, do this because your expense report or something like this. And I shouldn't admit this publicly, but I did I was driving. I see this like emergency thing come through. I'm like the screen and I'm like.

So I didn't think I clicked on it and it it got it. It it it got a there was there was there should have been an animated GIF of like somebody?

At the company doing this, but it was like this. It was this like badge of shame of like hey you fell for this uh huh.

You know, and I was like crap and I was like I learned. 2 lessons one.

Pull over first.

If I can't mouse over the link.

Probably shouldn't click on it, right?

And three is just.

That sense of urgency.

Um was what really like, and maybe there's a psychological thing to this where it just tricks off like this. The primordial brain, or I know there's the three brain model and Andy and I go off on tangents a lot. Dan, I should warn you, but not us. Ultimately the idea is that once you're kind of anxious about something right, your higher brain functions are going, if not shut off kind of be pushed aside.

And all you have to do is click the link to get your answer or whatever I mean.

It seems like these folks are well versed in this type of psychology.

Yeah, and they also know too that you know every when you're on your mobile, everybody is rush rush rush rush rush for rushing on the mobile phone all the time and that is a little scary because sometimes even when you look on the mobile you can't even see who it's from. It'll it'll you know. Just say a name or something like even some of the Apple ones that come out. Don't say oh it's from Apple, but that's not the exact. Doesn't show you the phone number or whatever it is. It's just.

Summer has put up there. As you know The Who it's from kind of thing, so yeah.

There's a lot of things we need to all.

Start doing or not doing.

Right, it's it's an interesting. It's just fascinating that with all this advances in cybersecurity, and I've seen a lot of the things that the technical we're not going to go into.

Humans are like the weak link.

00:07:18 Frank

00:07:20 Dana

00:07:29 Dana

00:07:49 Dana

00:08:00 Dana

00:08:20 Dana

00:08:30 Dana

00:08:50 Dana

00:09:00 Dana

00:09:11 Andy

00:09:25 Dana

00:09:46 Dana

00:09:46 Dana

00:10:10 Dana

00:10:20 Dana

00:10:37 Andy

00:10:45 Andy

00:10:58 Frank

00:11:06 Andy

00:11:08 Andy

00:11:31 Andy

00:11:39 Andy

00:11:55 Andy

00:12:08 Dana

00:12:20 Dana

00:12:21 Dana

00:12:24 Andy

00:12:30 Andy

00:12:33 Frank

00:12:39 Frank

00:12:45 Frank

00:12:46 Andy

00:12:48 Frank

00:12:55 Frank

00:13:01 Frank

00:13:15 Frank

00:13:20 Frank

00:13:40 Frank

00:13:47 Dana

00:13:51 Dana

00:14:16 Dana

00:14:17 Dana

00:14:34 Dana

00:14:46 Dana

00:15:04 Frank

00:15:13 Frank

00:15:16 Frank

00:15:35 Frank

No, it's not. It doesn't have to be. I mean, there's a....




