Uncloaked: A Cybersecurity Podcast
Uncloaked: A Cybersecurity Podcast by BlackCloak takes you inside the world of Digital Executive Protection and personal cybersecurity.
In today's hyper-connected world, corporate leaders and high-net-worth individuals are prime targets for sophisticated cyber threats. But the weakest link isn't at the office—it's in their personal lives. And the line between digital and physical risk continues to blur.
Discover practical solutions, expert analysis, and behind-the-scenes stories on the unique and evolving security challenges faced by C-suite executives, board members, high-profile individuals, and their families.
Uncloaked: A Cybersecurity Podcast
Ep. 34 | AI, Deepfake Scams, and the Executive Attack Surface Nobody Owns
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Ed Amoroso, former AT&T CISO of 20 years, professor, author, and current CEO of TAG Infosphere, unpacks why executives' personal digital lives have become the softest target for attackers. He breaks down how AI is reshaping both sides of the cyber battle, why deepfakes hit hardest with senior leaders, and why too many companies can't even name their own security vendors.
If you're interested in learning more, you can contact BlackCloak here, or visit the BlackCloak website.
Welcome to Uncloaked, a podcast series brought to you by Black Cloak, the pioneer in digital executive protection and leader in personal concierge cybersecurity. I'm your host, Dan Basco, and today I'm joined by a special guest. He's a cybersecurity professional, author, professor, member of several boards, spent 20 years as the CISO of ATT, and currently the CEO of Tag InfoSphere, Mr. Ed Amaroso. Ed, thank you so much for being here today.
SPEAKER_01Thanks for including me, Dan.
SPEAKER_00Absolutely happy to have you here. Uh today we're talking about a topic that uh resonates greatly with us here at Black Cloak. It is our mission. Uh, we're talking about the attack surface that is largely unmanaged. That's the personal digital lives of executives, board members, other company leaders. And really, we're seeing more and more that the personal lives of leadership is the main breach path into the organization. Um, can you explain why this attack surface is so much more attractive nowadays to cyber criminals than going after the company infrastructure and going that route uh instead kind of taking this backdoor in?
SPEAKER_01I think it all comes down to one word you used a minute ago. You used the word personal. And for most executives, that is a very blurry concept. You know, the the distinction between personal life and kind of work persona becomes very blended, you know, as one uh steps into an executive role. It's something that you don't notice until you do it. Um, you may be warned about it, but you don't realize the intensity of the responsibility when you step into uh an executive role. And increasingly that doesn't mean just the CEO or the direct reports, it can mean you know, department heads and VPs and others. We are busy human beings nowadays, you know, despite all the AI that's floating around. We're all quite busy. So what happens is your personal life, your your sort of your digital persona as a um uh say non-executive, you're what what it is to just be you uh really gets very blurred. Um so that's why you become pretty attractive because an adversary, whether it's a nation state or uh someone committing a crime, or even uh you know someone doing competitive analysis, um, will find that a soft spot into the the corporation or whatever organization, could be government agency, usually a corporation. That soft spot may not be through the gateways or the normal attack surface of the company, it might be through the people that are the stewards of such. And if they're sloppy about how they manage their personal digital uh setup, their accounts, their social, but that may be the way in.
SPEAKER_00Yeah, that well, you said it right at the end there, too, about being you know, uh intentional about how you use those personal devices uh when you do have so much responsibility and ties into the corporation. And I think that it's something where in a perfect world uh there would be that clean separation using corporate-only devices for work and personal devices uh for personal stuff, but that's really not the case, is it? I mean, I would imagine the majority uh of executives uh today do use their personal devices to send work emails and and conduct some work because that's just the nature of uh you know life today.
SPEAKER_01I mean, if majority of means 100%, then I'm I'd imagine somewhere, maybe Warren Buffett doesn't. I think he I think he's retired now, right? So you know, um I I think that the era of someone not doing that as Wayne. Now, what I I do think is happening is that we're entering one of these weird phases where there's the presumption that by giving you and I digital assistance that are powered by some frontier model, that it will sit next to you and I, you, Dan, me, Ed, and be Dan's helper and Ed's helper, the AI agent helpers. And maybe these will be like having a uh executive assistant that lives somewhere in uh you know in the AI land. The qu the I'm look, there's still a question as to whether that works. I I don't think it, I don't think it makes the problem any less. It might change some elements of the problem. Like um, if I'm using Black Cloak, for example, it may be that Black Cloak will need to coordinate with some future agent that's doing my email or something. Who knows? But I think we are getting to a point now where the digital persona could be to some degree assisted, probably not fully managed for some time, but assisted by an AI. And that's still a wild card. I'm not sure whether I'm excited about I'm I I think I like somebody doing my email. That sounds pretty good, Dan. Yeah, I'm okay with like if you if AI is gonna take over our lives and put us in a zoo, start with email, like start there.
SPEAKER_00Exactly. Right.
SPEAKER_01I'm good with that. Just kidding. So just saying no, I I think that there's a portion of this problem that will change because of um you know, some sort of AI assistance. It's gonna be interesting to see. Well, what I've noticed is we always tend to overestimate when there's new technologies, we overestimate what the implication is in the short term, and we tend to underestimate what the implication is in the long term, you know, like uh so with AI, uh it's it reminds me of alchemy and chemistry, you know, alchemy was magic, or numerology and math, numerology was magic, or you know, the occult in physics, or astrology and astronomy. There's always sort of this magic spooky part to a real science. Artificial intelligence is probably that to computing. There's this idea that human beings, these new species of AI, will come along and be um, you know, we assign this anthropomorphic kind of characteristic to them. We've been doing that for since Newton, you know, Newton mixed potions between the calculus and and uh Newtonian physics. He was an alchemist. So it's not surprising that we're all kind of freaked out about AI taking over, um, you know, becoming this new species. I don't buy any of that. I think that that's way overestimating. So executives will still, human executives will still have jobs, will still be doing what they do, and they'll still be making sloppy decisions. But for you and I, it'll it'll probably be a little bit of uh some assistance with AI. And I would imagine from a black cloak perspective, that's welcome because there'll probably be a lot more you can do with a uh assistant than with a human being that's very imperfect and busy and can't do a lot of the things that need to be done. So I think probably good.
SPEAKER_00Yeah, it can optimize and and certainly hope with efficiency and and all of that. Yeah, there's there's a lot of good to it. Um, you know, and then obviously there's you know the bad aspects, um, deepfakes, uh for instance, which are becoming more and more um harder to spot. And we've seen some pretty high profile instances of like CEOs and CFOs um being impersonated and then it turning into a uh you know multi-million dollar cost for some companies uh from you know signing off on wire transfers that um you know was uh was not the person. It it's a it's interesting, it's an interesting dilemma for a lot of the corporations here when we talk about that you know, personal life and and protecting the corporation, wanting to secure their executives, but they don't have a line of sight into the personal digital lives of their executives. They can't touch that that aspect of it. So it's um you know, it is a gap there. Are you seeing this as possibly being a growing concern or at least something that's on the radar for a lot of organizations as kind of a gap that does need to be addressed?
SPEAKER_01I mean, it's no question this gap. That was a very pro big proponent of what Black Cloak does. I've been you know friends with CP for some time and they think it's a fine idea. It's not that it's getting better or worse, it's changing. Like the demographics change. You and I are are are two people that probably you know uh are not as facile with say deep fakes as a young person, let's say someone under 10 right now who grows up with this will be. Do you know what I mean? Like a child growing up, even my my my youngest daughter is a few years out of college. She and I'll look at the same thing, a picture, and I'll say, gee, look at that nice picture. And she'll say, Dad, that's so obviously AI generated. And and it'll take me a minute because I I still speak with an accent on that. I didn't grow up with that. I grew up with, you know, you can get images and magazines and you know, and television and the internet. But my daughter grew up with this. So she is it, it shifts. So things that you guys worry about now appropriately, like executives like myself, you're making some dopey decision, yes. But that's not always going to be the case. When my daughter at some point is in one of those roles, you're not gonna have to help her with a lot of things, but it'll be something different. There'll always be fraud, and it'll be her AI assistant being hacked, and yeah, you guys will be probably be in that business. I bet in five years you're in a totally different business. But but um, but I think that's the nature of this, that it's not really that this is getting better or worse, it's just changing. You've always had executives at risk. It just we would always say executives in the past were more physically at risk. And I'm not saying that's gone away, but that doesn't scale. Like if you want to do some kinetic, engage some kinetic problem against an individual, you have to be there. Whereas the kind of thing you and I worry about, like virtual, you don't have to be there, and I can scale it and I can you know make it continuous and make it pretty relentless. So to me, the the the digital threat is way more frightening than kinetic, but we've always had physical uh threats to executives as long as there have been people in charge. I mean, kings used to get their head chopped off, right? I mean, so so you you always had the problem, it's just different now.
SPEAKER_00Yeah, and unfortunately now we're kind of seeing that the digital threats are bleeding and feeding the physical threats as well. So it's even you know, it's where they start. Yeah, absolutely.
SPEAKER_01Definitely definitely intertwined. There's no no question about, but again, to me, the physical threat feels more tractable, not not you know, not put everybody in a you know in a box and you know, with with bulletproof this and that, that seems kind of um insane, but in in the digital world, that's where everybody lets their guard down. To your earlier point, take an executive who's coaching soccer and you know, might be in a church group or whatever, you know, just you know, on Netflix, you know, well, ordering movies. You you have your life, and what passwords are you picking, and who are you sharing it with, and what data did you give away, and what did you reuse? Probably bad decisions. If you're my age, you've probably made a lot of shortcut decisions. If you're my daughter, no, my daughter is a digital native, she knows not to do that.
SPEAKER_00Yeah, yeah, it's the those uh the individuals who are kind of wired to to detect certain things, and yeah, yeah, it's uh every generation has has that next iteration, you know.
SPEAKER_01Young, younger, uh again, we I I couldn't do I can do things my mom can't, you know, with technology because I grew up with what I grew up with, but it's just like an accent, you know. When you're born in France and you speak French, it sounds just great. When you're born in Brooklyn and then you move to France when you're about 12, you never speak it right. You just it's never gonna be the same. And it's exactly like that with um technology. So an executive that grew up in the 70s, 80s, 90s and sits on some boards now or say that person is not um speaking natively. They're speaking a foreign language, metaphorically speaking, in terms of uh technology. So that's why I think it's so essential that executives have some sort of assistance and protection, um, you know, whether it be a service. I guess you can do it yourself, but not all that effective if you're gonna do it yourself. It's um I guess that's why we have gyms and exercise classes because it makes it easier to get it done.
SPEAKER_00So exactly, exactly. Need that little push for sure. You know, along the lines of you know, the adaptability and uh evolution of of people in general uh over time, I I you know, I've seen in a couple interviews that you've mentioned that corporations are maturing when it comes to their security strategies, and you have to, um obviously. Um I I would love to hear you expand a little bit on that, especially as a former CISO yourself, how you've seen this landscape uh evolve over time. And do you envision companies uh being a little bit more uh proactive versus reactive when it comes to you know cybersecurity measures and things like that for um you know considering it an imperative versus a luxury?
SPEAKER_01I've devoted my whole life to that, so I'd like to think that that you know that that's the case. You know, if you devote your life to something and it seems like there's nothing but headwind, then you you know you got some maybe made some bad decisions along the way. But no, I think things are are getting better. Here's what I do think happens. If you if you think about cybersecurity as something that doesn't necessarily have to be around forever, you know, it's not something that is just a given that we always have this discipline. For example, if I said to you, um, who's in charge of reliability in your company? You would go, like, what do you mean? Everybody. But there was a time when you had reliability engineering groups. We had it at ATT. And then if you were around in the 90s, might remember we were all getting black belts and quality, and you had somebody who's in charge of quality in a company. And then we all realized how silly that was. So just like you wouldn't have anybody in charge of dependability and so security that's an engineering word with ITY at the end, like all those other words. Well, why do we have this department of security? Well, because we've lived in that era, but it would be awful nice if we could get to the point where security just becomes this embedded thing and a requirement in everything we do. Certainly can still be coordinated by a team, but um there's no reason why. And and AI might help because what happens with active defense is that if your offense is using AI, the defense can use AI. And before you know it, it's like a humidifier and a dehumidifier fighting it out in a room. You know, we all watch from behind the glass. Like who's gonna win? Maybe nobody, maybe we've got a nice balance there. So it's entirely possible that at the enterprise level, and we're not talking about human beings or human attack surface or somebody making bad decisions on social media. I mean like a bank that's dealing with inbound cyber threats from an adversary, those are gonna be lobbed in by AI and it's gonna be forever and continuous and ongoing and relentless and all these terrible things. But if I have AI against your AI, it's rock'em sock'em robots, man. It's let's have at it, my tech against yours. And that sounds good to me because the defense is likely to have better data, better contextual data about their environment. And they can classify that or make that secret. And then the data powering their AI, the defense, will be better than the data that's coming inbound from the offensive AI. And it's the first time I've ever in my career heard of the defense having an advantage over the offense, it's always the reverse. So this is good. This is a good thing. Now, it's somewhat orthogonal to the executive problem because I'm I'm not sure that that wraps entirely into one's personal life. You know, you might work for a bank that is just rock solid against nation-state attacks, and you go home and you're helping out at the local community theater that's wide open to attack your persona might be breached there. But I do see a very bright future for larger enterprise using AI to protect themselves. I like that. That's one of the most promising themes that I've seen in our industry. I I almost want to say in 40 years, I think I might go out on a limb and say that. From 40 years of doing this, it's um the most promising development I've seen.
SPEAKER_00That's great. I mean, I think we do need a little bit more optimism when we're talking about uh these topics because they can get so dark and and grisly pretty quickly. And um, and and there's uh there's an aspect of um understanding and contextualizing, you know, that that this technology is at the fingertips of uh both the good guys and the bad guys.
SPEAKER_01Let me give you a little more context about AI. Some I grew up with it. My dad was an AI researcher in the 50s and 60s. So I grew up a dad that taught them carburetors and fixing cars. My dad taught me neural networks, so little dude.
SPEAKER_00There you go.
SPEAKER_01Grew up with this, and it was a long period from the time it was first conceived, and we were playing like Conway's game of life. If some of your listeners want to look that up, it's a fun little game where you have all these little things, bots that are doing things and they follow instructions. A long period of dormancy in the technology where we didn't make much progress, and then a gigantic ramp in the last few years where generative AI and LLMs have made a spectacular leap. That does not mean that the next 40 years or even the next four years will the same see the same level. I remember uh Walter Cronkite when we landed on the moon in 1968, you know, the guy we all trusted when we were little, Walter Cronkite, he leaned forward into the TV and he said, you know, here we are in 1968. We got men on the moon. If you just go back 50 years, we were first flying. So from there to commercial aviation to now, we'll be flying back and forth to the moon in another 20 years. By 1988, we'll be running shuttles. By 2008, we'll be going to Mars and back. Now, did that happen? Absolutely not. So you can't just take a ruler and look at the direction of innovation and then say, here's where we were, here's where we are. Take the ruler and go, I can extrapolate out. Wow, AI is gonna put all of us in cages. Because if I extrapolate out, it's terrifying. I wish technology was that predictable, it's not. Again, we overestimate in the short term, but we underestimate in the long term. I think long-term AI has a deep impact on our society. Short term, we've spectacularly overestimated how we can save money, introduce new products. Does the ketchup company have 30 more flavors of ketchup because of AI? I don't think so. Does an airline offer me 10 different new ways to fly to St. Louis? I don't think so. Now, maybe you know, customer care and things can be improved, but you always had automation you could do with automation anyway. So we overestimate in the short term, underestimate in the long term, and you can't just extrapolate and say, this is the ramp we've been on, so therefore this is where we will be. That is absolutely wrong, and that's not the way it works. So it's an it is possible. I just gave you an example of one for cyber offense, defense, go team. Um, but for you know, changing the nature of how executives do their day-to-day work, manage companies, run organizations, create vulnerabilities that have to be fixed with black cloak, I think I think we're still humans around, and I think they're still going to be pretty flawed, unfortunately. That's probably good for you guys, but bad for everyone else.
SPEAKER_00Well, it's uh it's a good point because while um a lot of these advancements are making daily life a little bit more convenient, um, and certain things are tweaked to make um things more tolerable or easier. It's not catapulting into the stratosphere of what you know was thought of 20 years ago or anything like that. So it is a good point to to keep that level head about it as we uh continue to evolve in this space. And you know I I think that's why um you know the mission uh that we're on is an important one too because um you know this this is uh still going to be a reality of daily life for quite some time for executives and uh and for corporations uh alike and you know that's why we're we're big proponents of of that proactive stance but also having a a row a reactive strategy being prepared um for when something uh does come your way and uh because it is more of a a when than an if nowadays and uh so you know going back to our our earlier points about uh that that kind of gap between the the corporation and the executive's personal life um can you speak to the impact of time when it comes to responding uh to attacks and and how important that is because obviously if there's a a breach at the corporate level um the detection can occur much quicker or at least they're aware of the impacts um much quicker whereas perhaps uh a breach in the personal life of an executive that response may take a little bit more time uh because the corporate uh environment just doesn't have uh access uh to that uh until perhaps it's a little bit too further or too late uh in the process or much further down the road so i was just curious your thoughts uh on that and and how that may delay efforts and why uh a middleman to kind of take care of that um could be beneficial.
SPEAKER_01In this area you almost have to be able to think of two things at the same time meaning on the one it's like an accordion like on the one hand everything is smooshed in like you're pushing the accordion in things happen faster attacks happen faster the impact is faster the follow-ups faster like all of that has been squashed in so that's the first thing you have to keep in your mind but the second thing you have to keep at the same time is that the accordion gets stretched out which means that sometimes when campaigns are launched you have this concept called dwell time which means if somebody's gotten really good man they can hang out in your knickers a long time you know so so it's those two things that are happening at once it's not it look man if life was only simple right I mean it's just not it's not you've got things happening quickly and also this elongation of campaigns. So time is a much more complex issue than just you know you and I might be watching a podcast somebody goes oh everything goes faster faster faster well yeah but but there's other things that have been happening it's not that they're happening slower it's that they're happening longer um so and more intentionally yeah it's so it's neither of those things I guess are good you know I I I I know when I first started doing the CISO job you could you'd have an attack and you know like a bunch of old men sitting around the breakfast table you know stewing for two hours about the same topic we could do that about an incident for six months we can talk about it and just keep stewing the internet worm of 1988 which was launched by uh Robert Mars Jr. who worked in Bell Labs in one of our labs his dad was my boss um right before that all happened we talked about that damn thing for three years yeah so now you know attack happens you know by the time the ink dries you're on to the third one since the one you were talking about so it just it's just all happening all a lot more quickly.
SPEAKER_00For the enterprise as well I I I know um I I'm failing to remember which interview it was but I it you had mentioned you that companies nowadays many of them are experiencing vendor fatigue and you know with that in mind I would love to you know um hear your thoughts on the importance of maybe minimizing things like tool sprawl consolidating third party relationships were applicable I mean how how much vetting would you say is required of a third of third party vendors today as opposed to what was required 10, 15 20 years ago?
SPEAKER_01It's not even what was required it's what's been done. But one of the greatest disappointments I've seen in uh the way CISOs operate today is that they don't know who the hell their security vendors are. They just don't and and that sometimes they can't even pull a spreadsheet from procurement. So in my practice you know I compete with Gartner and Forster we're kind of a research and advisory company a tag first thing we do when we get a client is we sit down well what do you got? Let's learn let's see what you have send us your vendors and we noticed two, three years ago that that casual request didn't seem like as casual a task as we had presumed. That show us your vendors meant well let me see if I can build that or I might have that on a PowerPoint somewhere or let me go ask procurement if I can have that data. And then once we get what comes from procurement it's this big laundry list of space junk in there we're going you're getting charged for this and this you got Jira and you got all these Microsoft charges and you've got all these like are they legitimate charges and who's acme enterprise gee I don't know well you may be able to look they're charging a million bucks a year for that so like they don't have any clue you know where the vendor came from they inherited it it's got two more years so we actually characterize vendors as investing in using tolerating eliminating or trialing those are the four states that one vendor can be in your security vendor. And it's amazing how many of them are in that tolerating category meaning I'm just using it because what am I supposed to do? I came to work here this was running we had blah blah blah on OR endpoints I hate the damn thing but I got another year and a half and you think that's not a good way to run a railroad you know we we should be managing that much more effectively so that's probably the I spend the majority of my time at tag now working with uh CISOs on who are your vendors do you have the right ones do you have you optimized your setup and it's like being a general manager for a football team like imagine if I go to a general manager I'm a New York Giant fan if I go to Joe Shane their general manager and I say hey who we got on our team this year and he goes it's a great question. I'm not really sure you know let me go see if I can pull a spreadsheet and see could you imagine? And yet I find that nine out of 10 CISOs they might argue with you over a beer but then when you sit down and say show me they realize well maybe I don't have as good a view. So I think it's one of the biggest gaps and again with Black Cloak you guys are an example of a company that doesn't need a whole heck of a lot of vetting you know you you we know who you are you've been doing this for a while a good company but think about all the MSPs out there all the solution providers that might be someone's cousin there's a company I just looked at I was looking at a bank asked me look at this thing and I go okay it's a regional bank and I look and I'm thinking gee I wonder why they picked them and I look at their headquarters and they're located across the street from the bank and I go look there's nothing wrong with that but you obviously picked them because it's there is like your cousin is your brother right I'm not sure they want to tell me yet but you get the point that that that's not a great way to manage vendors and you get you know that there's some something that's not not exactly right but it it is what it is. So yeah so I would say that that is um the ability to manage your vendors and know who you've got is a is an art that needs to be uh sharpened in the in the coming years and that's what I spend most of my that's I'm more or less devoting my time on right now.
SPEAKER_00It's almost like uh like those commercials for the budgeting apps where they say are you aware of all the subscriptions that you're paying for every month and the amount of people that have no idea what they're paying for every month uh it's out of sight, out of mind a lot of times.
SPEAKER_01Tip to any CISOs watching if you've got a budget cut if the boss says we got to cut five percent and you don't have a good finance manager who understands internal corporate finance get one even if you have to move out an engineer and bring somebody in that person will get you the five six percent you won't have to get rid of anything you'll just the corporate finance mechanisms are so complex that just by understanding what you're being charged for, understanding your contracts understanding your vendors just learning that you'll find so many places that you can cut and consolidate and simplify yeah you won't have to fire anybody you maybe even have some money to go buy new tools. So that's why I get so excited about that we call that cyber vendor management attack attack. I don't know anybody doing it other than the big big four will come and consult with you on that. There's a couple of my friends independent consultants are out doing it but I think I'm the only one that's got a platform to do it right now.
SPEAKER_00Well I greatly appreciate uh your insights and and discussion here it's uh it's you know super important you're you're very passionate you've got uh uh such a great uh perspective and I appreciate the sobering perspective as well because uh you know as we talked about there's there's a lot of doom and gloom out there and there's it's also good to be aware of uh a lot of the bright spots and the optimism the optimism for still the roses a little bit right there's stuff the roses out there absolutely we can have a little fun as well right so uh at emro so really appreciate your time thank you so much for being here with us my pleasure you can listen to all episodes of uncloaked at blackcloak.io slash podcasts or on your platform of choice and if you're interested in becoming a member or want to learn more about how to protect your digital life visit us at blackcloak.io thank you for tuning in and we'll see you next time on uncloaked