Building Your Strategic Human Firewall with Robert Siciliano
About the Guest(s):
Robert Siciliano is a cybersecurity expert with over 30 years of experience in personal and corporate protection. He is a security analyst, bestselling author, and the architect of the Strategic Human Firewall. Recognized for his educational efforts in personal security, Robert has appeared on major platforms such as CNN, Fox News, and CNBC and has been published in the Wall Street Journal, the New York Times, and Forbes. He has contributed significantly to the Identity Theft Resource Center and the Realtor Safety Initiative. Robert's practical approach to cybersecurity includes notable demonstrations, such as purchasing a working ATM to illustrate vulnerabilities in systems.
Episode Summary:
In this enlightening episode of Money Roots, hosted by Amy Irvine from Rooted Planning Group, guest Robert Siciliano delves into the complexities of personal and cybersecurity. As an established security analyst and educator, Robert shares his journey and vital insights into how individuals and organizations can protect themselves against the ever-evolving threats of digital crime. Through a mix of personal stories and professional wisdom, Robert illustrates the importance of proactive security measures, especially in today's organized cybercrime landscape.
Robert discusses how the nature of cyber threats has evolved from individual hackers to sophisticated organized crime syndicates. He emphasizes the importance of shifting one's paradigm from denial to proactive risk management, introducing the concept of the Strategic Human Firewall. This episode is rich with actionable advice, including the adoption of preventive tools like password managers and two-factor authentication. Robert's message underscores the need for financial service professionals to extend the definition of financial security to include these contemporary digital threats, aiming to protect clients holistically.
Key Takeaways:
- Strategic Human Firewall: Robert introduces this concept highlighting proactive risk management and preventive cybersecurity measures.
- Evolution of Cybercrime: Cyber threats have evolved from individual hackers to organized crime operations, making vigilance essential.
- Preventive Measures: Essential tools like password managers and two-factor authentication are key to protecting personal information.
- Cultural Shifts in Security: Changing belief systems from denial to proactive engagement with security practices is crucial.
- Security Appreciation: The paradigm shift from awareness to genuine appreciation of security roles and their importance in personal and professional settings.
Notable Quotes:
- "I can make every single person sitting in the chair listening, make them part of the top 10% of secure Americans, just like that."
- "We're an interdependent species...and what that fundamentally means is we are dependent upon each other for our survival."
- "Hackers don't necessarily hack anymore...what they really do is they just log in."
- "The strategic human firewall is someone who effectively recognizes risk...a mindset that turns us from passive targets into active detection."
- "We achieve what I call security appreciation...where successful training ends with the employee teaching the concepts to their family at home."
Resources:
- Robert Siciliano's LinkedIn
- Robert Siciliano's Instagram
- Robert Siciliano's Website: Protect Now LLC
- Book: "Identity Theft: Privacy, Security Protection and Fraud Prevention" by Robert Siciliano
Join Amy and Robert in this compelling episode, as they equip you with invaluable insights into personal and corporate cybersecurity. Listen to the full episode to ensure you're one step ahead in safeguarding your digital footprint and stay tuned for more captivating discussions on Money Roots!
Transcript
Hello podcast listeners. Amy Irvine, CEO and founder of Rooted Planning Group here today. And I have a special guest that I'm going to be doing this podcast with.
Robert is going to be talking about his background, history knowledge when it comes to personal security. He's a security analyst, bestselling author, and architect of the strategic human firewall.
As one of the world's most recognized educators in personal and corporate protection, he is the, I guess you want to say, straight talk voice for the digital age. You're going to hear us talking about personal security as well as cybersecurity in this podcast.
He's appeared on CNN, Fox News, CNBC, the Anderson Cooper 360 show, and he certainly has been published in the Wall Street Journal, the New York Times and Forbes. Robert has served on the board of Identity Theft Resource center and is a core contributor to the Realtor Safety Initiative.
He is a man who literally goes to the extremes to prove a point and you'll hear this in the podcast once even being buying a working ATM on Craigslist just to demonstrate how easily it is to secure a system and how such a secure system can be cracked. So I hope you all enjoy this podcast and that you'll enjoy hearing our rather long conversation.
A bit longer than I normally do, but if you get as interested as I was in the conversation, then it won't seem as long. And we appreciate you listening to this thing.
Maybe it's in parts, but again, hopefully you'll walk away with something very helpful and useful in your lives.
Amy Irvine:Hi, I'm Amy Irvine, founder of Rooted Planning Group and this is Money Roots, a podcast where my team and I explore the real conversations behind financial planning. Because life is about events supported by your dollars and cents. Let's get started.
Amy Irvine:Well, today's guest, Robert Sicily Amio, as I mentioned in the intro, is got some interesting Did I say it right this time? I always like to double check.
It has some interesting background that I'm going to let him give some information about the book that was that he wrote and has published, but is a security analyst background again.
I know I already gave some bio information in the intro, but I was so interested in the idea of creating this book called the Architect of the Strategic Human Firewall.
Given all of the cybersecurity breaches that have happened, all of the identity theft that is happening, I'm actually doing I don't think we talked about this, but I'm actually doing a presentation to other financial advisors about protecting anybody over the age of 60 with regards to like identity theft and financial abuse that's happening, which is more and more and more in our world. But, Robert, give me a little background of what took you on this journey about, you know, to write this book. I'd love to hear that.
Robert Siciliano:So I've been speaking and training service professionals revolving around finance and healthcare and real estate for over 30 years. And I've truly been doing what I do for 40 years, really, since I was a teen.
And I started off in the world of personal protection as it relates to violence prevention. You know, I started doing what I do early on, you know, from a lot of life situations.
I'd been involved in a couple of different multiple attack situations myself. I met a young woman when I was in my early teens that had been sexually assaulted.
And all of that kind of, you know, provided me a focus because I did not know that people were like that to each other until I did. Right.
And so I started to speak and teach personal protection primarily to real estate agents back in the early 90s, because, you know, in the US realtors are sometimes murdered because, you know, they're soccer moms and NASCAR dads that don't have any formal security training, meeting people at, you know, open houses and vacant properties with, you know, no clue as who they are. You know, when we say don't talk to strangers, well, they talk to strangers all the time.
I bought my first computer in:And I had an IBM PS1 consultant, which is a make and model of a Windows 3.0 operating system. We're at 11 now, and it had 150 megabyte hard drive. And I had to buy a separate card to connect to AOL for dial up. You know, it didn't come standard.
And so after about a month of connecting to the Internet, I had the ability to accept credit cards via my computer as a point of sale. I got hacked in 95, and I lost thousands of dollars in credit card fraud. And I didn't understand what was happening to me.
And when I talked to the bank and I talked to the credit card company, they were like, yeah, this is a problem for us too, and you're still responsible for those funds. And as upset as I was, I wanted to understand what happened, you know, and how it happened.
Because at the time, and still today, my process has always been reverse engineering the bad actors and how they choose Their victims, what their motivations are. And back then it was just like, you know, personal security being, preventing physical violence and theft in the physical world.
Now at that time was, okay, well, I was just robbed via aol. How does that play into all of this?
And as I began to study it and understand it, I realized like, wow, if this can happen to me, this can happen to anybody. And I said, this is right now the easiest crime possibly to commit financially and very hard to get caught for. And it's going to be a big deal.
And look where we are today.
Amy Irvine:Yeah, yeah, yeah.
Robert Siciliano:So for 30 plus years I've been talking about this issue and what hasn't, what has changed is that back then criminals hacked for fun and fame and of course for financial gain. But it was like a kid sitting in his mom's basement, you know, hacking somebody. Today it's organized crime.
And that those organized criminals are making billions and billions of dollars every single year. And they're doing it off of you and I, our clients, regular, everyday people.
In the 30 plus years of doing this professionally, I've never seen more financial fraud happening in such a concentrated period of time. And the dollar amounts being high, six in seven figures, happening to everyday moms and pops, happening to baby boomers and there's no end in sight.
So that's changed.
It used to be like, you know, they'd, you know, breach data records and universities and hotels and municipalities and, you know, in here and there, financial institutions and they'd sell those records to others who would use it to, you know, create identity theft. Today that's small potatoes.
Today they're engaged in frauds that, you know, you get this wrong number text message and before you know it, three, four months later, you've lost $3 million because you've voluntarily sent that money to somebody who you thought had your best interest in mind.
Amy Irvine:Right, right.
Robert Siciliano:That's what's changed.
Amy Irvine:And the way that they're, right, the way they're going about it, like with, and they're still doing this, like it's your grandkid that needs money or it's, you know, that kind of thing. There's the funeral and obituary scams, like after somebody loses a loved one. Scammers say, you know, your loved one owed us money.
I mean, these are all the things that are happening, right? These are, and they're getting them via text messages or emails or phone calls. It's pretty, it's pretty significant. Yeah.
Robert Siciliano:What that is, is it's organized crime. It's organized fraud, cybercrime, is treated as a business. It wasn't like that 15 years ago. It wasn't even really like that 10 years ago.
Now it is a full scale operation and each business might have hundreds of employees.
Amy Irvine:And so that led you to the book. I mean, that's what led you to like writing the book of, you know, the strategic human firewall.
Robert Siciliano:So I've been doing what I do, like I said, For 30 years and this has been an evolutionary process for me.
And all of this has accumulated in a methodology, in a philosophy, in a strategy for consumers and financial service professionals and chief information security officers. In any organization that intends on reducing risk, there's a certain strategy that needs to be executed in order for that to happen.
So right now, as a financial service professional, I'm sure like occasionally a parent company that you might work with, like they might engage you in what we call phishing simulation training, right? Which is necessary, it's required, it's, it's, you know, it's compliance training. But that doesn't necessarily teach you about personal protection.
It doesn't necessarily teach you how to protect your own identity. It doesn't necessarily teach you how to effectively manage risk every single time the phone rings or you get an email or you get a text message.
Heck, it doesn't even teach you how to manage your security if somebody knocks at your door.
And so most security awareness training that they call it, which I don't consider it security awareness training at all, I call it phishing simulation training.
Most security awareness training today is compliance based training that doesn't necessarily affect the individual and their own concerns, the reality of the risks that they face on a regular basis.
And so this methodology that I've developed over the past 30 years is designed to affect the person that sits in the seat who's engaged in those phone calls, those emails, those pop ups, those text messages. Because 30 years ago people didn't engage in cybersecurity at all.
Like antivirus is a relatively brand new thing and we adopted it because we heard that you were supposed to still to this very day, many people don't have antivirus, especially on a Mac. And you need antivirus on a Mac. It doesn't come pre installed. We only pre, Microsoft only pre installed antivirus less than a decade ago.
It's a relatively new thing. And so 30 years ago people had passwords in. Today people have passwords.
And when I get in front of a live audience, I could tell you straight up, I asked the entire room how many of you are using a different Passcode across multiple accounts.
Amy Irvine:Yes.
Robert Siciliano:I get 15% of the room to raise their hand. That's amazing. Which means 85% of the room are using the same passcode everywhere or some.
Amy Irvine:Very close variation of it. Right.
Robert Siciliano:And that hasn't changed.
So the consumer and the way they approach risk, the way they look at cybersecurity, they don't engage, they don't do it because they don't think they need to. They think that their government or Microsoft or Apple is going to protect them. And they often function in denial. It can't happen to me.
Why would they hack me? Why would they steal my identity? Why would they go after my accounts? Oh, well, Fidelity is going to protect me anyway, so I'm fine.
And so none of that has changed.
We as consumers, clients, are as vulnerable today as we were 30 years ago because we don't look at cybersecurity personal protection risk effectively. We don't look at it as my responsibility, we look at it as somebody else's responsibility. They're going to take care of it for me.
And then we function in denial and say, well, why would they hack me anyways? And we justify that denial with fatalism. And what does that mean? It means that why would I install a password manager?
If they can hack a password manager, why would I do that? So we justify not engaging in basic one on one security practices, using fatalism.
And all of that prevents us from essentially becoming a targeted attack, targeted by an attacker and thwarting that attack. Because we don't have the first understanding of risk, most of us.
Amy Irvine:Right, right.
Robert Siciliano:And it's not about, this is what scams look like. This is like how to dissect the scam. This is how we, it's not about that at all.
It's about understanding us and our resistance to security and our own biology and why we trust by default and why every single time the phone rings and an email comes in and we get a text message that revolves around what we call manufactured urgency and why that works so effectively in what we need to do and who we need to become and how we need to think and how we need to emotionally and intellectually react and respond to fraud, none of that is described in any of the training that we receive today.
Amy Irvine:Yeah, yeah. And that slowing down process, Right. That's so critical in any situation where there's a financial request that comes in.
I mean we, we have a process at our company that intentionally slows that down. We get a call from a client, we get an email from a client. We get a, you know, we get a text from a client. It's okay.
Step one is, you know, were we expecting this kind of thing?
Step two is physically calling the person and having a conversation with them and finding out what's not like prohibiting them from getting their money in any way, shape, or form, but just building in those protections. Like, what's, you know, what is it that. That you needed this unusual amount of money request for, you know, talking through it with them.
And one of the things that we've talked about at our firm is now, even if somebody calls you, is it the person like. Or is it AI like? I mean, what are we developing now?
How are we getting into this new generation to make sure that it's actually the client that's requesting the funds be transferred? And there's limitations of where, you know, where we can transfer money anyways. But. But still, it's making sure that it's the person that we.
That is actually requesting it and that it's not, you know, somebody else requesting those funds. It's. It's a scary side of our business. And it is expected, as you just said, it is expected from clients that will protect them.
Robert Siciliano:Your clients are looking to you for financial security. And today, financial security means a heck of a lot more now than it did even five years ago.
And I don't know that most financial service professionals look at themselves as someone who is providing security to protect the actual finances in any way. I think they look at themselves as custodians of that money to grow it and build it and provide financial security for the future.
But financial security to the client means preventing harm today. But most financial service professionals don't see that at all.
But they're fielding calls and emails from their clients in that regard, and they don't know what to do. And I know this because my own financial service professional calls me.
He's like, I got a client on the phone right now, literally right now, that I want you to talk to.
He's talking to the Department of Homeland Security right now as we speak, and he's telling me that the Department of Homeland Security has reason to believe that all of his money is at risk.
And as much as I try to tell him to hang up the phone, he won't hang up the phone because he is convinced that it is the Department of Homeland Security. And he won't listen to me.
Amy Irvine:Right?
Robert Siciliano:What do I tell him? Or what can you tell him? Right, because the scams today are so con.
Amy Irvine:Oh, yeah. Oh, yeah.
Robert Siciliano:That they get you and because of the way in which you and I have been raised in a culture where we show respect to authority, we trust by default. We just want to believe that those who are responsible for protecting our critical infrastructures and who are in charge of got this right, We.
We provide them with all of that weight and responsibility.
Well, if the DHS calls you, if the IRS emails you, if you get a text message from your registry of motor vehicles, because of what I call the human blind spot, right? And the human blind spot is a methodology that I've developed over 30 years.
And the human blind spot is basically our want, our need, our biological and psychological instinct to trust is what it is. We are what is considered an interdependent species. That's what humans are. We're an interdependent species.
And what that fundamentally means is we are dependent upon each other for our survival. We just are. Like man needs woman, woman needs man to survive. In order for the species to essentially procreate, we need each other. Right?
And it always has been, is, and always will be like that. And the basis of this interdependence is that we need to trust each other. We have to. That is our default.
And so the human blind spot, truly, from a security perspective, is the psychological and biological instinct to trust, especially trust what's familiar to us. Your bank is familiar to you. Your email provider is familiar to you. Amazon is familiar to you. Your financial service professional is familiar to you.
Your loved ones are familiar to you, Right? And as a result of this human blind spot, we have this cognitive gap where biological trust overrides suspicion.
And that leaves the door wide open to all kinds of fraud and deception, especially AI deception.
Amy Irvine:Think of it as a big scary thing for me. I mean, that's one of the scary sides of AI for me personally, and how it's going to impact people in the future.
Robert Siciliano:And think of it as biological default to trust. And the psychological shortcuts or the heuristics that criminals use to bypass human logic and human emotion.
Think of it as biological impulse versus intellectual understanding. And ultimately, there's like this internal conflict between our survival instincts and our modern knowledge, or lack of knowledge of digital risks.
Amy Irvine:And how do you even come back from it? Right, so we had a client that was actually. Their email was hacked. I mean, hacked. And so all of the emails were completely, like, gone.
Everything in their saved folders, everything in their inbox, everything in their trash, like, contacts, completely gone. And, you know, so all of that data was extracted, Right. Where do you like the notifications from your bank. Like, hey, you have a secure message.
The notifications from your investment firm. Here are your notifications. Like, yes, there, you know, like, all of that information, all of the contacts that sent emails were hacked.
And the, the, what they did was they took all of the contacts and sent out an email that said, a reply email to something that, like, let's just say I sent something to this person and the, the, the hacker responded back to an email that I had sent that said, hey, I was wondering if you use Amazon. That was the response.
And then from that point it was like, well, you know, well, yeah, I mean, there were people that responded and said, of course we use Amazon. And then it went into this other, like, process of, well, I was wondering if you could help me with this.
You know, hopefully nobody fell for it, but it was, that situation was so stressful to the client because now the client has to go through and they have to look at, okay, what are all my, like, this person got into my email account, what password did I use? And now I have all of these other things that they can get into because they got into my emails. Are there any other passwords that are similar?
Because you know they're going to go through that. So you need to go through and change every single password that you have.
The stress that that causes is so significant because now they're worried, like, what is, what else is going to get hacked? How do you come back from that? How do you prevent that? The first question and how do you come back from that?
Robert Siciliano:If it happens, preventing it is relatively easy. And that's the real, like, that's, that's the ironic part about this whole thing is that, like, this is so easy.
I tell my audiences that I can make every single person sitting in the chair listening, make them part of the top 10% of secure Americans, just like that. And the way you do that is you engage in basic security practices. And most people don't engage in 101 security practices.
So what does that actually mean? It means, like, I, you know, get in front of a live audience and my job is to change the security culture.
My job is to, to affect them so that they look at security differently.
And I start that process by asking them challenging questions, questions that are designed to make them look at themselves and how they look at risk, because I can tell them all day long, look out for this, do this, don't do this, or else. And they don't care about that. They're not going to do any of that unless they look at this and doing this and not doing this as their decision.
Security as something that was born from their choice. People will not act or react to a security vulnerability unless they have decided that it's something that they want to do or need to do first.
That's how security is. It's kind of like health. People will not engage in eating healthy, healthy lifestyles unless they make a choice. Security is no different.
And usually when it comes to healthy lifestyle, people don't usually engage in it unless something bad happens, unless they are faced with risk, unless they get a diagnosis that they're not happy with or.
Amy Irvine:They see somebody else like that. Right. It encourages them because they witnessed it. Something like that, yeah.
Robert Siciliano:We won't engage in a healthy lifestyle, both physical and mental health, unless our life is becoming manageable as a result. And when it comes to security, it's the exact same thing. We won't engage in security practices unless we decide to do so.
And often it's due to trauma, harm. That's the problem. That's the issue that we all face. Now, I know how to do that. I know how to get people to make that decision for themselves.
That's what I do for a living. That's what I've been doing for 30 years. I understand that process.
And once I get them over that hump, like whenever I do a security awareness presentation, I walk into the room and.
And I'm hired because the chief information security officer from the company has said, listen, we've been providing phishing simulation training now, and it's working pretty good.
Like, our metrics are kind of really good, you know, but we still have, like, a certain, you know, portion of our, you know, employee population that's still clicking the link. They're still engaging in the fraud. They're still at risk. And no matter how much we tell them, they still do it.
How do we get them to care about security? And so I get hired, I walk in the room, and I'm introduced, and I'm looking at 100 people, right? And these are all employees of this company.
And they're looking at me with a scowl on their face, literally.
Amy Irvine:Because they don't want to be there.
Robert Siciliano:Because they don't want to be there, right? And they're all, like, their arms are crossed with a scowl on their face. They're looking at their watch, they're checking their phone, right?
And they don't want to be there. And so I start asking them all these challenging questions. We're getting into a dialogue now.
And in that process of Asking them all these challenging questions, you know, they're. They begin to kind of like, you know, answer me and kind of like get into, like, this dialogue with me.
Because that's what security awareness training is supposed to be. It's supposed to be a dialogue. And none of the security awareness training that's provided today, Zero, is a dialogue. It's always a monologue.
It's always being told what to do.
And so as I'm asking all these questions and we get into this conversation, which is what I do, they begin to, like, loosen up a little bit, because now they're starting to see that what this dialogue is about is not necessarily what they thought they were getting themselves into. And so at the end of the presentation, I got a line of people coming up to me, and they're like, listen, I got to tell you something right now.
I didn't want to be here today. I came here because I was told to be here. But I got to tell you something straight up. Like, I'm so glad that I came. You know why?
Because this is nothing like I thought it was going to be. And I really wish that my spouse was here because he or she would have loved it. That's what it's supposed to be, but that's what it's not.
And so as I am asking them all these challenging questions and they're providing answers that those answers that they provide begin to make them look at themselves and the answers they provided and my response to those answers, and they start to look at that going, oh, huh. I didn't realize that's what this was, or that my answer was so, like, remedial or kind of ridiculous, actually.
And they begin to see that their belief systems have been flawed because they've been sold a bill of goods over the course of a lifetime in regards to what's what they thought security actually is, versus truly what it's what it really is. And so it's that process that you engage in that allows them to actually see security for what it actually is.
And it actually allows them to look at the features and the benefits of security and how it truly is a game changer for them.
Amy Irvine:And you actually wrote a book about this.
You wrote the Identity Theft, Privacy, Security Protection and Fraud Prevention book that for people that are listening to this podcast, I mean, if they're, you know, if they're not fortunate enough to attend one of your speaking events, there's some good information in that book that could get them thinking along some of these lines. You know, it's it's so important, I think, to me, I think it's so important for people to be thinking about it, like so skeptically. Right.
I think that we need to come out. And you mentioned, when you were talking just a moment ago, you said it's, it's easy to, it's easier to prevent.
Like, it's easy to prevent if you do a couple of things, right. So there's a few things that you do.
Like, would you say, you know, like password managers or, you know, not having the same password for any one thing. Like, what are some of the, let's just say three things.
What are the top three things that you would recommend to somebody that if they, if they did look at it from. And I think of it also just to sidebar on this, I also think of it from a standpoint of like, we have insurance to protect our home.
Well, the value of our home. Right. Should something happen, we. The value of our car and liability associated with that. You know, we have insurance for health insurance.
Like, we're proactive at going out and getting that kind of coverage and protection in place.
But one thing that a lot of people don't think about is how do I, I have the insurance, but how do I start with the simplest thing of, you know, being a better driver, making sure that my house is, you know, I don't put my house in too much of a risk for certain things to happen. And the same is true behind cyber security. Thinking of it from, from prevention.
Robert Siciliano:Yeah. So, like, look at. Hackers don't necessarily hack anymore. I mean, they do, but what they really do is they just log in.
Over the past 20 years, there have been thousands and tens of thousands of data breaches. We average like 3,000 data breaches every single year. There have been tens of thousands of data breaches.
Some sources say that there has been as much as 300 billion with a B of our records compromised. Okay, so of that 300 billion records, about 20 billion billion of those records are passwords. So they're not necessarily hacking any longer.
They're just taking the known credentials and just logging in. And once they log into your email, they own you. Bad actors say, own the email, own the person. So to be in the top 10%, what do you do?
I can give you more than three things. I can give you five things right off the bat.
Amy Irvine:Fantastic.
Robert Siciliano:But to get your clients to do these things requires challenging your belief systems. You can't just tell them, do this and you'll be fine.
They have to do it and understand why they're doing it, but they have to make the choice to do it because they want to do it. And that's the hurdle. That's where 30 years of experience comes in to understand the human psyche and why they resist security.
That said, you mentioned insurance, right? So, couple things, right?
So when I get in front of a live audience, one of the first questions I asked him is like, how many of you lock the doors to your home?
Amy Irvine:That's a prevention.
Robert Siciliano:Depending on where you live in the country, depends on whether or not you lock the doors, right? And depending on the type of person you are, depends on whether or not you actually lock your doors because of your belief systems. Belief systems.
Human belief systems in locking doors are 100% related. So when I ask people, why don't you lock your doors? They're like, well, I live in a safe neighborhood. As if every neighborhood is 100% safe.
There's no such thing as a safe neighborhood. And I don't say that because there's like, you have to worry and you have to live in fear because there's risk.
I say that because if you read the local police blotter, in every single municipality in the country, there are burglaries every single year. So even in safe neighborhoods, bad things happen, but people just choose to ignore that.
And then I say, well, okay, so how many of you have a home security system? If I get 15% of the room to raise their hand, that's a lot. Which means 85% don't have a home security system.
So those two basic things, not locking your doors and not having a home security system, they tell a lot about a person. And if you're not locking your doors and you don't have a home security system, it means that you truly don't believe in security.
Because, look, in the US every year there are between 1.5 million and 2 million homes that are burglarized every single year. That is between 15 and 20 million homes burglarized in the next decade. It is just a matter of time.
And so when I ask the question, okay, so why don't you have a home security system? The hands begin to go up. They want to tell me, and you know what the most common answer is? We have insurance.
As if insurance is going to protect you at 3am Which I find to be so unbelievably comical.
And then the next answer is, well, we don't have a home security system because my husband says, if they're going to break in, they're going to break in what are we going to do? The husband is engaging in fatalism. He's given up. He's already said, the bad actors are more powerful than me.
I can't protect you, so why bother with the home security system?
And I say to her, yeah, you might want to rethink that husband, you know, but truly the most revealing answer that I get, the most revealing answer, which really tells the whole complete story, is we don't have a home security system. Because I don't want to live like that. I just trust people. I don't want to live in fear.
I don't want to have to worry every day as if installing a home security system is going to be a constant reminder that bad things happen. That's how we are as a culture. We look at security in engaging in security practices as worry and fear. That's what we do as a culture.
We've been raised like that. We treat the world like that. And nobody is going to engage in locking doors or installing a home security system because you tell them a statistic.
Nobody. They don't do it. They engage in power. They engage in denial is what they do. They engage in fatal is what they do.
There's only a few ways to change that paradigm, and that's by engaging in a dialogue. And so when they say, well, I don't want to live like that, I don't want to live in fear.
I just want to trust people, what they're truly saying is, I prefer to live in denial. Denial is a lot more comfortable than recognizing the reality of the world that I live in. I would rather do nothing is what they're truly saying.
And that's most people.
Amy Irvine:And so if we can shift the client's thought process to more in that line of. I want to do all of the steps so I don't have to use the insurance. Right. I want to lock the door. I want to have the security system.
If we can get them to think like that. What are the tools? What are the security systems? What are the doors?
You know, the locks on the door that they can use when it comes to their protection.
Robert Siciliano:So look it, number one, lock your doors. Number two, home security system.
Amy Irvine:Right.
Robert Siciliano:Number three, never use the same password twice.
Amy Irvine:That's it.
Robert Siciliano:Never use the same password twice. Like, you truly shouldn't know your passwords. Like in your head, intellectually, you shouldn't know what your passwords are.
I don't know my passwords.
Amy Irvine:Mission accomplished here. I have no idea. They're all characters and numbers. Yeah, I don't Have a clue.
Robert Siciliano:You know, look at, I don't know my mother's phone number. I don't know my father's phone number. My phone knows the phone number.
Amy Irvine:Yeah.
Robert Siciliano:I just never committed it to memory. I just never did. I probably should know it, but I don't.
The only reason why I know my wife's phone number is because I met her at a bar 25 years ago and I didn't have a pen.
Amy Irvine:And.
Robert Siciliano:So I wanted to remember her number and I committed it to memory.
Amy Irvine:That's it.
Robert Siciliano:That's probably the only phone number that I know. Literally, a password manager is basically the fourth thing.
In order for you to maintain all of those different passcodes, you need a password manager. And I know that less than 10% of all of society uses a password manager. And then the fifth thing is two factor authentication.
Amy Irvine:Yeah, that's huge, right? It's such a barrier.
Robert Siciliano:It's huge. There's no such thing as 100% security. There's vulnerabilities everywhere.
Amy Irvine:Right.
Robert Siciliano:But between or on top of a password manager and adding two factor authentication, not only do they need your passcode, well, they need your phone in their physical possession in order to get in.
And I know that most people, and I would say less than 15% of all of society, engages in two factor authentication because I know this, because I speak to them on a regular basis.
And if less than 15% of society is engaging in two factor authentication and less than 10% are engaging in a password manager, well, then all you need to do is lock your doors to engage in a certain mindset. Install a home security system so that security is part of your lifestyle.
Set up a password manager so that every website that you log into, you are using a tool that essentially is facilitating the best security that you can get, starting with never using the same passcode twice, because there are 20 billion of our passwords on the dark web layering that with two factor authentication. So even if they get your password, they still need your phone in their possession. You do those things, you're in the top 10%.
But it's getting them to that point, it's making them want to do that, it's making them see why that's important, which is truly what I do. And what that, what I call that, what that process is and what they ultimately become is what I call the strategic human firewall.
And the strategic human firewall, and I'm betting already just through this conversation is that's something that you already possess, like I already possess being a strategic Human firewall, which basically means that, like, throughout the day, week, month, year, every time the phone rings, every time I get a text message, every time I get an email, I am looking for what's wrong here. Right. My BS meter is on high alert all the time.
Amy Irvine:All the time. All the time. Yep. It's exhausting to a certain extent. Yeah.
Robert Siciliano:And you'd be surprised how many people don't have that radar even turned on, never mind possess it. It's not even turned on. They don't even think they need it. And so a strategic human firewall is someone who effectively recognizes risk.
The firewall itself is designed to block deception. It is a proactive governance. It's a mindset that turns us from essentially passive targets into active detection.
Layers we're looking for is the shift from by default, because of the human blind spot, I trust what I see.
Amy Irvine:It's the offensive side. Right. Instead of being defensive, it's the offensive, it's being proactive.
Robert Siciliano:It's the shift from I trust what I see to two. I verify everything.
Amy Irvine:Yeah.
Robert Siciliano:Going forward, I verify everything. The key is, in order to get people to do that, they need to want to do it on their own.
And that's a difficult hill to climb unless you know how to do that. And as a result of this, we achieve what I call security appreciation. So most security awareness training today is just that. It's awareness.
It's knowing. It's being told. These are the risks. This is what to look out for. This is how you respond. That's knowing. That's awareness.
That's security awareness training to appreciation. Security appreciation is caring. So awareness, again, is in your head intellectually. I know appreciation is in your heart. It's caring.
It means this means something to me. That's what I do. I do security appreciation training.
And so when employees, consumers, your clients, appreciate how security protects their own lives first, their own lives, that's when behavior changes permanently. I call it the security appreciation gap.
It's that chasm between person's intellectual understanding of risk, which again, is awareness, to the emotional commitment to act on that knowledge, which again, is appreciation.
And ultimately, they achieve what I call the kitchen table effect, which is the multiplier effect, where successful training ends with the employee teaching the concepts to their family at home around the kitchen table, cementing those lessons for life.
Amy Irvine:Yeah.
And when somebody, you know, when you see the impact that that takes to somebody, I mean, it's like the health thing that we were talking about, right?
If there's a health event that you See, in your family, it makes you more aware of your own health, or if you have a health scare, it makes you more aware of your health care. This is the same kind of concept.
If you see this happen, I mean, the ideal, ideal situation would be, I want to prevent this, and I'm aware that I want to prevent it, and I don't actually want to see it.
But if, if you do see something like this happen, you know, taking it and really turning the page a little bit and saying, okay, we're going to make sure this doesn't happen to us, and I'm going to make sure that we become appreciative of the tools that are there and that my family doesn't have it happen to them either. And that's a really important lesson. To be in passing it from generation to generation is really critical. I've.
I've had, you know, some folks say, like, I don't. It's. It's not about if it happens, it's. It's gonna happen, and I'll just, you know, deal with it.
At that point, I'm like, well, let's try to not think that way. Let's try to be one of those people that doesn't actually have it happen.
You know, I mean, yes, there's all sorts of breaches that you don't have any control over, but this is, you know, there are things that you can do that are preventative. I, I tell my clients, don't give. Like if you're.
If you're going to a new doctor on your doctor's forms, they often ask for your Social Security number. You don't actually have to give that. There's actually nothing that requires you to give your Social Security number to your doctor.
If they press you for it, give them the last four digits. Yeah, but there's a way to be preventative. It's a way to lock your door. Right. Instead of just assuming that you have to give that information.
I don't even know why they put it on the forums anymore, because I've asked most of the doctors, like, do you actually need this information? If you do, I want to know.
Robert Siciliano: Why today, in: Amy Irvine:I understand that, but it's still a preventative measure.
Robert Siciliano:Sure, but the reality is they already have it. I've had criminal hackers email me my own Social Security number. Hey, security guy, here's your social. Ha ha. Basically flexing their muscles.
Show me how cool they are. There have been 300 billion of our records compromised. Social Security numbers in the hands of.
Amy Irvine:Criminals check all the time.
Robert Siciliano:You know, passwords in the hands of criminals check. Like, the data is out there and it's in the hands of the criminal. It's about, at this point, making the data that they have useless to the thief.
That's the key. And most people aren't engaged in even that, those best practices because they don't want to, because they don't think they need to.
That's where shifting their paradigm, changing the security culture, making them believe differently in regards to what security is versus security isn't, is a big deal. Like, I'll ask you a quick question, and this is what I ask my audiences. I'm a guy that has 20 plus security cameras.
Maybe a little excessive, but, you know, I've been collecting them over the years. I got a good size problem between inside and outside my house. I got 20 security cameras.
When you hear that, when people hear that, what might their first response be? When I say that? Like, what might my. What might be My belief systems, my worldview. Like, I wake up every day, I got 20 security cameras. I must be.
What?
Amy Irvine:Well, I. You don't find that. No, I don't find that abnormal in today's world. Yeah. Like, I just don't find. I. And I don't know if it's because I think that way.
I don't have that many, but I don't find that abnormal.
Robert Siciliano:What do you think they said?
Amy Irvine:Well, I think there's people that probably use the word paranoid.
Robert Siciliano:They all say that.
Amy Irvine:Yeah.
Robert Siciliano:I'm in front of a hundred people and I asked that question. I get a hundred people that look at me and they go paranoid. Like, literally, like, out loud. And they kind of like, oh, we just called them paranoid.
They kind of look at each other and giggle. Like, oh, we just called them a bad word. You know, like, it's kind of funny, actually. Right.
Amy Irvine:Yeah.
Robert Siciliano:I did that in front of 100 something Chief Information security officers. These are people whose job it is to engage in security practices for a living. And they called me paranoid.
Amy Irvine:Yeah.
Robert Siciliano:Okay. And when we as a culture, when we as a society, when we look at security as a mental health disease, which is what paranoia is.
Amy Irvine:Yeah.
Robert Siciliano:Why the heck would you ever want to engage in security?
Amy Irvine:Right.
Robert Siciliano:And that's what we do. That's how we look at security. And so unless you can change a person's belief systems.
Amy Irvine:Mm.
Robert Siciliano:Which is what I do in regards to what security is, Risk management versus what it isn't, which is paranoia. They're never going to take your advice.
Amy Irvine:Yeah. And I want to accentuate that point that you just made. It's about risk management. And that's, that's why we think it's so important.
You know, here at Rooted Planning Group, it's about risk management. Our job as financial planners is, is about. A component of our job is about risk management.
And, you know, that's why we talk to our clients a lot about this and, and this particular podcast session.
I know not all of our clients listen to our podcast, but I definitely will be sending it out in our newsletter for folks to listen to because I do think it is important and we stress this all the time with our clients about being aware, being, you know, putting this as a priority, making it about risk management.
But many of the listeners of this podcast aren't clients and I want to say thank you so much for taking the time to share your thought process, you know, to, to get people thinking about how important it is to shift their paradigm, their paradigm about this particular topic to a risk management mindset and, you know, not, not think about it like you said in that word, paranoid perspective, but really about protecting me as a, is a, a family member, an entity member, a person. So thank you so much for all of your time today and being on the, being on the podcast.
I'm going to put a link to your book in our show notes as well as there was a couple of YouTube videos that I came across when I was doing research. I want to put those links in there so folks can listen a little bit more to you and your contact information as well.
For link then for folks that might be, you know, interested in listening to you more, learning more about you and reading, you know, more about what you do, not just as, you know, individual clients, but also as other planners in our world that might be interested in hearing you speak or participating and being protective of what is out there. So thank you so much for, for, for being on the show and we really appreciate your time.
Robert Siciliano:My pleasure. Yeah, just, you know, look, I give it away for free every couple of weeks via my LinkedIn like you mentioned. You know, it's. It's all right there.
Right?
Amy Irvine:Yeah.
Robert Siciliano:So. Search Robert Cicilano via LinkedIn. Connect with me.
Otherwise, my website is protectnowlc.com and thank you so much for your generosity and your time today.
Amy Irvine:Yeah, thank you.
Amy Irvine:That's it for today's episode of My Money Roots. I'm Amy Irvine from Rooted Planning Group.
If you found this conversation helpful, we'd love for you to share the podcast with a friend, family member or colleague who might enjoy it too. And if there's a financial question on your mind, send it in.
Your question could be the topic of a future episode, because at the end of the day, life is about events supported by your dollars and cents. Thanks for for listening and we'll see you next time on Money Roots.
