Ep. 164 - Security Awareness Series - Metrics and Empathy the Answer To Cyber Breaches with Kate Mullin

Published: Feb. 21, 2022, 7 a.m.

b'

This month Chris Hadnagy and Ryan MacDougall are joined by Kathleen (Kate) Mullin. Kate is an influential information security practitioner with over 30 years of experience. Kate currently is CISO with Cancer Treatment Centers of America.\\xa0 Kate has been CISO at various organizations including start-ups, publicly traded, private equity, not-for-profit, and governmental entities. Throughout her career, Kate has volunteered and participated in maturing information security as a profession. She volunteers with ISC(2) and ISACA and has been a member of the ISACA CGEIT Certification and Credentials Committee and a chapter president. Kate serves as a featured international speaker and panelist. She has a BSBA from St Joseph\\u2019s College and an MBA from Florida Metropolitan University. Kate is also certified as a Master Level Social Engineer. [February 21, 2022]\\xa0

00:00 \\u2013 Intro\\xa0

03:09 \\u2013 Kathleen Mullin intro\\xa0

04:25 \\u2013 How did you get started in Information Security?\\xa0

06:39 \\u2013 What are some indicators that tells you something is ineffective?\\xa0

10:21 \\u2013 Do you think the \\u201ccookie cutter\\u201d type of training is a reflection on the security awareness team itself?\\xa0

12:16 \\u2013 How can you offer the more personalized training to a company that is spread out all over the U.S. or the globe?\\xa0

16:31 \\u2013 Is having someone in this position who is focused on the people and the results the way to go about having the program be successful?\\xa0

18:09 \\u2013 What are your major security concerns being in the healthcare industry, and how are you dealing with those?\\xa0

21:08 \\u2013 We are seeing SMishing attacks becoming more prevalent in general. Are you seeing that happening in your industry?\\xa0

22:47 \\u2013 Caring about employees\\u2019 security outside of work as well\\xa0

23:35 \\u2013 What are some action steps that any company can start doing right now?\\xa0

  • Have metrics and measure training effectiveness\\xa0
  • Humanize your training\\xa0
  • Incremental steps\\xa0
  • Care about your users for real\\xa0

26:11 \\u2013 Demoralizing phishing techniques\\xa0

28:15 \\u2013 Book Recommendations:\\xa0

30:13 \\u2013 Who would you consider your greatest mentor?\\xa0

34:27 \\u2013 Finding Kate on the web:\\xa0

35:17 \\u2013 Guest Wrap Up\\xa0

36:00 \\u2013 Outro\\xa0

'