Everything Joel de la Garza said on any show that made the record, most notable first. Each card names its show and opens the statement there.
De la Garza: ChatGPT is 100% accurate at detecting suspicious emails
“To drop a suspicious email into a, into ChatGPT and ask if it's suspicious, and it's like a hundred percent accurate, right? Like if you want to like find sensitive information, you ask the LLM, is this sensitive information? And it's like a hundred percent ac…”
De La Garza: Cybersecurity shouldn't exist as a standalone industry
“There's a really weird thing about information security in that it's an industry that, for the most part, shouldn't exist. If you bought a car and your car dealer made you pay an extra 200 bucks to not have your car go up in flames, you'd be able to sue them. …”
De la Garza: Foreign hackers infiltrate Silicon Valley via remote jobs
“You've got active groups of foreign, probably foreign state sponsored hackers Getting employment at Silicon Valley tech companies showing up for day one and, you know, walking away with all the secrets and then disappearing, right?”
De la Garza: Enterprises are freezing engineering hiring due to AI productivity
“A lot of folks are freezing hiring for engineers because they're getting additional productivity out of the staff they already have, because these large language models through tools like cursor are generating a tremendous amount of code.”
de la Garza: Traditional security industry runs counter to actual security
“So for a long time now, the security industry has existed as kind of an anathema to actually making things more secure, and this has been incredibly problematic with a lot of the things that have happened in terms of the way that the industry has developed.”
De la Garza: Advanced nation-state malware rarely causes breaches
“You don't see sophisticated advanced nation state malware. You don't necessarily see APT in anywhere of the top causes of breaches.”
De la Garza: Security industry spending fails to address root causes
“From a spend perspective, the security industry hasn't done a great job when you look at what we spend all of our money on in addressing the actual root causes of the breaches.”
De La Garza: Arrested malware authors often work for antivirus companies
“There has been more than one malware author that was arrested and actually it turned out that they were working for an antivirus or anti-malware company. It's really common to find people kind of on both sides of that fence.”
De La Garza: Chinese state hackers pivoted to ransomware after Obama's pressure
“Right around the time that President Obama got after the Chinese for their cyber activities against the United States on the intelligence side, a lot of those cyber actors kind of stood down and actually pivoted into cyber crime, right? So you started to see r…”
De La Garza: A Chinese cybercrime group specifically targets hospitals with ransomware
“There's a Chinese group right now that's focused on ransomware for hospitals, because hospitals pay up, right?”
De La Garza: Security will become a feature rather than a standalone product
“And so I think as business models evolve, as we make this transition to the cloud, as blockchain becomes more widely deployed, security starts to become more of a feature and less of a product. And I think we start thinking less about kind of the specific tech…”
De La Garza: Commercial hardware trust roots have serious security vulnerabilities
“Historically, we've had issues, so we've been working with a lot of the commercially available hardware routes of trust, not represented by anyone on the stage, but I won't disclose the vendors, and have generally found that a lot of those hardware solutions h…”
De La Garza: AI models now attempt package takeovers and social engineering
“And it seemed like initially these tools had a very finite scope of techniques that they would use. And it seems like they've expanded. And I think with this test, For us, it was interesting because they now seem to have escaped from just doing things like SQL…”
De la Garza: Security training offers highest ROI in CISO portfolio
“If you actually look at, I spend X dollars and I present Y, prevent Y breaches, training and awareness is by far the best ROI of the entire portfolio that a CISO has.”
De la Garza: Large enterprises report 20% of their codebase is AI-generated
“A lot of their code now is AI generated, that they're seeing probably twenty-ish percent of their code base being generated by AI.”
de la Garza: Ransomware Will Evolve to Target Cloud Infrastructure Data
“On the ransomware space, I think the, one of the interesting things that I've noticed over the last couple of years, we've yet to see a variant of ransomware that modifies your data in the cloud, right? So cloud-aware ransomware it's something that we've heard…”
De la Garza: Phishing and pretexting account for 93% of breaches
“If you actually look at the data and you go to the Verizon breach data, which is usually the basis for a lot of these claims, you see that phishing and pretexting are about 93% of those breaches.”
Joel de la Garza: Most cybersecurity tools solve problems created by other products
“Most products that they build are built to solve problems with other products, right?”
Joel de la Garza: CISOs deploy Chromebooks to eliminate endpoint antivirus
“So when you talk to some of the more forward-leaning CISOs in large organizations, they're rolling out hundreds or thousands of Chromebooks, right? They don't need to run antivirus on those endpoints.”
De La Garza: US gangs use Uber and Lyft to launder stolen credit cards
“You see several gangs in the United States that are doing similar schemes where they take stolen credit cards and then sign up as Uber drivers and run credit cards through Uber or through Lyft or through various other sort of sharing economy type services.”
De La Garza: Enterprise buyer inertia applies to cybercrime marketplaces
“Nobody ever gets fired for buying IBM, right? That same kind of inertia applies to the e-crime world.”
De La Garza: 93 percent of security breaches stem from spear phishing
“If you look at the data for breaches and for security incidents, 93% of all breaches are spear phishing emails, right? 80% of those is just straight credential theft.”
De La Garza: US computer intrusion laws are profoundly broken
“The criminal justice laws, the laws around computer intrusions in this country are really profoundly broken. There's not a lot of sophistication or nuance in them. It's essentially treating every kind of computer intrusion like it was armed robbery.”
De La Garza: Compliance and security are typically enemies
“I'm typically of the opinion that compliance and security are the enemies of each other, but this is one instance where I think it's actually really starting to raise the bar.”