Listen to this episode

The REAL Reason the US is Behind the Curve in Cybersecurity

0:0049:58

Recorded May 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this episode, Erin and Blake of Petronella Technology Group discuss why the United States lags behind in cybersecurity. They reference the Colonial Pipeline attack, the Equifax breach, and, at the time of recording, renewed warnings about Russia targeting American critical infrastructure.

Blake argues the country is an easy target because the rapid digital shift of the past two decades outpaced security, while Erin contends that trusting defense industrial base promises without verification, including NIST and DFARS requirements, was a misstep. Blake compares cybersecurity to health insurance, saying people prepare for visible risks but rely on a perception of digital security he calls fictional. They discuss the shortage of cybersecurity talent, the analytical personalities drawn to the field, and the difference between reactive IT work and proactive security. Blake advocates teaching children rudimentary cybersecurity, such as using a VPN and avoiding strange links, while Erin suggests school lessons on social engineering. They close by arguing the country is reactive where it needs to be proactive.

Worth remembering

Key takeaways

  1. Blake argues the rapid shift to digital records, cloud tools and employee devices over two decades left the United States unable to keep up.
    “Obviously it has a lot to do with I think personally the digital push, within the past 15 to 20 years, all businesses for the most part have been storing records digitally.”
  2. Erin argues that, at the time of recording, NIST and DFARS requirements were treated like a wink and nudge, trusting supply chain promises without verification.
    “I think one of the problems that we had was the fact that we relied on. Promises from the supply chain from the DIB defense industrial base. And it wasn't even trust, but verify, it was just trust”
  3. Blake compares cybersecurity to health insurance, arguing Americans prepare for visible everyday risks but lean on a perception of digital security that he calls fictional.
    “how everybody strives in America to have health insurance. Not because you want to use it, but because you hope you don't have to use it.”
  4. Blake questions hiring managed service providers that do not prioritize cybersecurity, arguing data should not be trusted to providers without a security background and defensive mentality.
    “But I can't understand why you would go to and trust your data with somebody who doesn't have a security background and somebody who doesn't have that defensive mentality.”
  5. Blake suggests children old enough to run apps on an iPad are old enough to switch on a VPN and learn basics like not clicking strange links.
    “if your child is old enough to click on an application and running an application on the iPad, and they're likely old enough to click on a VPN application and turn on a VPN,”
  6. Blake urges continuous fortification and improvement, warning that the moment you stop pushing the envelope is the moment somebody can catch up to you.
    “continue working with those individuals to continue to push the envelope because the second that you stop pushing the envelope is the second that somebody can catch up to you.”
  7. Erin concludes that the root of the United States' cybersecurity problem is being reactive instead of proactive.
    “Really what it boils down to is that we're reactive as opposed to proactive.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

Sometimes it seems as if America is ALWAYS the target of cybersecurity attacks. And that's because it kinda is! But what remakes the US such an attractive target? It's a complicated answer with multiple reasons - some that aren't too surprising, and others that may be harder to spot.

But one thing is for sure: We in the US, collectively, need to take cybersecurity more seriously and make it a priority, rather than something at the bottom of our to-do lists.

Listen in as we deep dive into the REAL reason the US is behind the curve in cybersecurity!

Hosts: Erin and Blake

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.