Lessons - The Man Who Protects Millions of Dollars Online Every Day | John Downey - CISO at GoFundMe (Fmr PayPal)
➡️ Like The Podcast? Leave A Rating: https://ratethispodcast.com/successstory
In this "Lessons" episode, John Downey, CISO at GoFundMe and former PayPal security leader, breaks down why cybersecurity threats continue to thrive and how human behavior remains the biggest vulnerability. He explains how most attacks aren’t sophisticated break-ins but simple, opportunistic attempts that exploit weak passwords, lack of multi-factor authentication, and poor security habits. John highlights practical steps organizations can take—like enforcing strong password hygiene, enabling MFA, and securing devices—to dramatically reduce risk. He also emphasizes the importance of building a culture of trust and psychological safety, where employees feel empowered to question suspicious activity and speak up, ultimately strengthening the organization’s first line of defense.
➡️ Show Links
https://successstorypodcast.com
YouTube: https://youtu.be/Rv6oHZno4Ik
Spotify: https://open.spotify.com/episode/3knf32b2M5sLIwLPETZQaP
➡️ Watch the Podcast on YouTube
In this lessons episode, explore why cybersecurity risks persist and how human behavior remains the weakest link. Discover how most attacks exploit simple vulnerabilities. Understand why awareness and strong habits prevent costly breaches and uncover how a culture of trust strengthens organizational security. I've seen that a lot, but that means that there's a lot of vulnerabilities and liabilities in the nonprofit sector. So maybe speak to some of the things that you see as attack vectors that could be a major issue if these are not more addressed and if people don't put more of an emphasis on information security. Because I feel like to your point before, private industry is taking it more seriously than they did before, but I feel like nonprofit is potentially still lagging. Now, I think that that's very true and I think one of the things I always recommend to folks is you know, you have a couple different types of attackers who may come after you, right? So you have people who are doing it just because they don't like you or they don't like what you stand for or they don't like someone involved with you, they kind of hacked us. You're going to have a hard time defending against them. And you know, if you're a nonprofit, like they're nonprofits that are politically motivated and they have and therefore they're going to have someone with the opposite persuasion attacking them. But the vast majority of people that they're probably going to deal with are people who are financially motivated. So financially motivated attackers are, you know, they're usually at the at the lower levels at these kind of smaller companies. It's more of a drive-by issue unless of a targeted issue, right? So I always describe it to, you know, it's not Tom Cruise and Emission Impossible, like breaking into the facility and like dropping down, you know, and like stealing the information. It's someone walking down the street and juggling the handles on the car doors, right? Like that's the kind of person. They're just looking for a car that was left unlocked that they can rob. And so what you need to do as an organization is do the things you have to do to lock your car doors and make sure that your employees are doing it. So that's things like good password hygiene. So, you know, having strong passwords, unique passwords per website, using a password manager, turning on multi-factor authentication, and probably the best thing you can do is enable MFA everywhere you can. And then last thing is patching. So like patching your software, patching your phones, encouraging everybody to make sure like, hey, keep everything up to date. And you're going to be at that point, you're going to be pretty close to being the one who's had their car door locked. The one I've added that we're very recently is just double checking that all your laptops are encrypted. So this is something that, you know, is starting to come more of a norm out of the gate, but like if you get a new windows or Mac laptop, just make sure that it's the encryption's enabled. And this is where it kind of, you know, helps to have a partner to do this, right? Like if you're a nonprofit, if you can partner somebody, because I don't expect an executive director at a local foundation to be an expert on technology, you know, how to turn on Bitlocker. But hopefully there is an organization they can work with an IT consultant or someone who can do that. And the reason I kind of go into the laptop thing is because people like any mobile device, the mobile phones are very good. Like, you know, mobile, modern mobile phones are pretty, are pretty secure. It's the mobile laptops just because you do lose them, you leave them in cabs, you leave them, you know, restaurants, like things happen. And when that happens, you want to make sure that you have a fairly high confidence that the data on it is safe. So you're saying like from what I'm hearing that the majority of problems still, the majority of potential attacks are still human, are still focused on the human, are still focused on the human screwing something on basically or getting fished or losing something. Yeah. So the, you know, Verizon every year publishes a great report that kind of outlines data statistics. And it's something like 80 plus percent of attacks that are, you know, going to be like really wildly successful, start with known credentials. So they start with someone, you know, it's not that like someone hacked the matrix and kind of broke in. It's like, no, they got scots using them in password and they logged in a scot. And I'm assuming actually, if you're, if you have a workforce that's not working from home, which is a reality post COVID, then you to your point actually. So you don't have, you don't have the proper encryption on the devices that people are working off of because they're taking something home or they're combingling the files from their work with the files on their personal computer at home. And every all the, all the security requirements that in office, you could sort of control. Now it's like the Wild West. It's like craziness because everybody goes home and they can use whatever device they want and using their personal device, using their work device, using personal phone, work phone. Is that what you're dealing with right now? I mean, I think so. And I think a lot of folks have been dealing with it since 2020, you know, March of 2020. I remember talking to competitors at the time when I, where I was, where they were sitting people home with desktops because it was all they had. They didn't have laptops for these people. You couldn't buy a laptop. I don't know if you, if you were in the mode of trying to buy a laptop in August, or sorry, in April, you know, it's like it just sell it panic. Yeah, you couldn't like, and like, because all the students were going to remote learning, all the employees were going to remote. If they didn't already have these, the supply chains were immediately jammed. And so because of this, things were skipped, you know, efficiency was needed to get people up and running. And so I think a lot of companies in places are dealing with the fact that they kind of, you know, there's still this COVID fog of like, you have this technology out there. Now, fortunately, unfortunately, you know, it's a couple of years old. So maybe it's you know, entering the place where it's going to be replaced. But you have a lot of technology out there that was kind of like rushed into production, if you will. And these kind of early days of COVID that maybe, you know, didn't get, you know, the firewalls didn't get configured or the laptops didn't get encrypted. If you're not a sophisticated organization, then, you know, has the remote management capabilities, like a small nonprofits, you may have this risk out there. And so, you know, kind of going back to what I mentioned a little bit earlier is partnering with someone who can help you out with this, like, I don't expect people to have this, you know, these people on staff at that level, you outsource it, you know, just like kind of how a startup would for, you know, for things that aren't going to be core to what they're trying to build, you kind of have to outsource it to someone as an expert. But also, like, so you're saying that a lot of this comes at, yes, so you're outsourcing some of the actual very technical items. But there's a lot, I'm sure there's a lot of education that can be built into an organization that probably also isn't there that could mitigate tons of these problems. So, I mean, let's talk about the human component and these breaches because the human, that's the fallacy, that's the weak point, right? That's the Achilles heel. So outside of pure technical, what are the, for us, for any, I was going to say small business owner, but for any business owner that doesn't have this knowledge in house, what are the like the best practices that you would teach over to your team or your employees so that they don't fall victim to this stuff? Because I'm even spouting off stuff like don't get fished. Okay, maybe people don't even know what that means. You know, I, I get the dude, I get these like scam emails all the time. They're getting actually quite complex and I can see it because I'm a technical person and I'm not, I'm not oblivious to this, but I get emails from my own team where they've like changed the name of the, of the email, but this, if you actually go into, or they change into the sender, but the email is this weird obscure email and it's like, hey, Scott, like, you know, oh, it's Patrick and it's like, change my banking information on my payroll. And I need my ACHF. Yeah, exactly. So it's like, he wants to pay me in iTunes gift cards. Right. Exactly. And it's like, oh, don't, don't, don't, don't call me. I'm in a meeting, just do this urgently, like stuff like that. So I mean, not everyone's going to fall for that. Yeah, no, so you say that, you know, the recent, so a few days ago, the FBI released their 2022 cybercrime statistics. And so they categorized that under kind of this thing called BEC or business email compromise. And it, for years and years and years was the number one thing on their cybercrime, always a, you know, a couple billion lost reported to them. Wow. This year actually dropped number two. The number one is now investment scam, so the crypto scams. But it's still number two, it's still a huge deal. And it takes the form that you mentioned, which is, you know, often somebody will reach out, usually they'll impersonate an executive or CEO, CFO, president, someone, they'll send, we've been, we've actually been seeing a lot more text messages than emails recently, where they'll text or email and say like, hey, I'm the CEO, I have something really important. You can't reach me, but I need you to do something and it always involves like wiring money or changing in an ACH information or buying gift cards or something for some reason. Anything that you can do to extract value out of the person or the organization. And you know, they're playing to a couple things, right? They're playing to urgency. They're playing towards people's sense of wanting to help out, especially like the CEO, you know, hey, like I, you know, I'm special. They reached out to me because they thought I could handle it. I want to let them down. And, you know, and people unfortunately do fall for it. And that's the, you know, to the tune of a couple billion a year that we know of so far, at least from the FBI and in the US. And like that, I think a lot of that kind goes back to creating a foundation of trust inside the organization to, you know, no, you know, basically you have to make people where these are big things. So, you know, awareness and security, awareness and training is a big for organizations of all size. You know, make sure people have the feel, feel comfortable to kind of stop and say like, hey, this is weird. Like, maybe I should like validate this. And so, yeah, how would I go about validating that the email that the email I just got from the CEO isn't correct? Like, is the CEO even approachable at my company? So, you know, I'm very fortunate at the place where I work at GoFundMe. Our CEO is actually like, you know, come out in town halls and say like, I will never text you. I will never email you and ask you to do this. We will always use proper channels. And that's helpful. But for organizations that are a little bit smaller, they haven't seen this before. You know, I, I, I'm involved in an organization where they, they have this and the person actually kind of went along with it for a little bit. And this is at an organization I've consulted with in the past. What do you mean they went along with it? They, they, they were like down the street about to buy gift cards for long rains. When they stopped and said, wait a minute, this makes no sense. Why should I be doing this? Yeah. And they felt super embarrassed as you wouldn't. They like didn't want to report it. Didn't want to talk about it because it's very natural. You know, you, you, you can be embarrassed. You can, and you know, you can find yourself like feeling like a fool. And that's why it's important to always create this like, you have to lead with empathy. You have to say like, look, this happened. It could have happened to anybody. I would feel embarrassed too. Here's what we can do to like make sure that we, you know, we're resilient to this in the future. And just sort of, you know, focus on improving the situation. There's, there's an aspect in security, we call the human firewall, which is, you know, knowing that we could have the best security in the world. But we, you know, if we don't have humans out there kind of helping us out as well, like we're going to miss things. And the example I always go back to with this is the SolarWinds breach from a few years ago. So the SolarWinds got compromised. You know, the U.S. has blamed the Russian government for doing this. And they, they were in organizations like Microsoft and the State Department and they come to call it fire. Fire is a very famous security company. It was actually an employee at FireEye got a multifactor authentication reset email reached out to their security team said, I didn't do this. This is weird. Launched investigation found that they had this breach that had stemmed from SolarWinds. And that's how the whole thing was uncovered. If they, if this human hadn't kind of been aware, it felt comfortable going to their security team with this that the whole SolarWinds incident may have lasted for another few months of nine years. That's wild. That is absolutely wild that like such a, it's such a, somebody who needs to feel psychologically safe to speak up. And that's really what stopped this from going on. Actually, I was just thinking, you know, as you're telling me that story, I actually do have a friend who ran a very large business. And I think, I think it was just under 500,000. And it was a payment. It was a payment for a service. And basically, there was an email sent to change the wire information or the ACH information. And it was gone. But that employee in particular felt embarrassed while I spoke up immediately. And the founder and CEO of the company was like a very good friend. And he's a good person. So like obviously not, not an ass about it. But yeah, I could see that. And I could actually see this is almost like a leadership lesson can do more for reinforcing the security of your organization than anything, really, because if you create a psychologically safe environment and somebody's going to be willing to speak up and like raise their hand when they screw something up, that's great. That's a very healthy organization. If somebody screw something up and you reprimand them and you fire them, that is actually potentially going to do more harm to your organization in the long term. Because everybody who saw that action is going to be like scared out of their mind to ever say anything if they ever do anything wrong. And that's going to cause more repercussions. Yeah, it's very similar to in the DevOps world coming up Etsy. There's this thing called Blameless Post Portems. I don't know if you're familiar with it, but the idea is, you know, so if you haven't incident the site goes down, there's an outage. Somebody, you know, somebody maybe misconfigured something. And there's this idea that we can kind of get together to talk about what happened and find the improvements going forward that you do in a blameless fashion. So you don't say John pushed this update and John caused the site to go down. You'd be like an update was pushed to site went down. Here's what we're going to do going forward. You don't, but not attaching blame, you're creating this, you know, this environment in which you can kind of lead with empathy, create this space for people to, you know, kind of, you know, be safe to share these things, own it, not, you know, you kind of create this, you, you know, actually create a situation which they won't try to cover it up ideally. Like they, if you do go with blame first, maybe somebody's like, okay, I messed up, but like I can fix it really quickly. I don't need anybody else to help me. And then nobody will know. And then I'll be, I'll be fine. Nobody. I won't get fired. Instead, you can kind of stop and say, oh, I messed something up. I need to ring the bell, call for help because I can't fix this on my own. Thanks for tuning in. If you found this valuable, don't forget to hit that subscribe button so you never miss an episode. And if you want to dive deeper into this conversation, check out the links in the description to watch the full episode. See you in the next one.