The Ledger, every show
Every statement that passed quotation and attribution checks, across all 44 shows. Pick shows below, then mix any filter with any other.
shows 




every show 44 of 44
De la Garza: ChatGPT is 100% accurate at detecting suspicious emails
“To drop a suspicious email into a, into ChatGPT and ask if it's suspicious, and it's like a hundred percent accurate, right? Like if you want to like find sensitive information, you ask the LLM, is this sensitive information? And it's like a hundred percent ac…”
De La Garza: Cybersecurity shouldn't exist as a standalone industry
“There's a really weird thing about information security in that it's an industry that, for the most part, shouldn't exist. If you bought a car and your car dealer made you pay an extra 200 bucks to not have your car go up in flames, you'd be able to sue them. …”
De la Garza: Foreign hackers infiltrate Silicon Valley via remote jobs
“You've got active groups of foreign, probably foreign state sponsored hackers Getting employment at Silicon Valley tech companies showing up for day one and, you know, walking away with all the secrets and then disappearing, right?”
De la Garza: Enterprises are freezing engineering hiring due to AI productivity
“A lot of folks are freezing hiring for engineers because they're getting additional productivity out of the staff they already have, because these large language models through tools like cursor are generating a tremendous amount of code.”
de la Garza: Traditional security industry runs counter to actual security
“So for a long time now, the security industry has existed as kind of an anathema to actually making things more secure, and this has been incredibly problematic with a lot of the things that have happened in terms of the way that the industry has developed.”
De la Garza: Advanced nation-state malware rarely causes breaches
“You don't see sophisticated advanced nation state malware. You don't necessarily see APT in anywhere of the top causes of breaches.”
De la Garza: Security industry spending fails to address root causes
“From a spend perspective, the security industry hasn't done a great job when you look at what we spend all of our money on in addressing the actual root causes of the breaches.”
De La Garza: Arrested malware authors often work for antivirus companies
“There has been more than one malware author that was arrested and actually it turned out that they were working for an antivirus or anti-malware company. It's really common to find people kind of on both sides of that fence.”
De La Garza: Chinese state hackers pivoted to ransomware after Obama's pressure
“Right around the time that President Obama got after the Chinese for their cyber activities against the United States on the intelligence side, a lot of those cyber actors kind of stood down and actually pivoted into cyber crime, right? So you started to see r…”
De La Garza: A Chinese cybercrime group specifically targets hospitals with ransomware
“There's a Chinese group right now that's focused on ransomware for hospitals, because hospitals pay up, right?”
De La Garza: Security will become a feature rather than a standalone product
“And so I think as business models evolve, as we make this transition to the cloud, as blockchain becomes more widely deployed, security starts to become more of a feature and less of a product. And I think we start thinking less about kind of the specific tech…”
De La Garza: Commercial hardware trust roots have serious security vulnerabilities
“Historically, we've had issues, so we've been working with a lot of the commercially available hardware routes of trust, not represented by anyone on the stage, but I won't disclose the vendors, and have generally found that a lot of those hardware solutions h…”
De La Garza: AI models now attempt package takeovers and social engineering
“And it seemed like initially these tools had a very finite scope of techniques that they would use. And it seems like they've expanded. And I think with this test, For us, it was interesting because they now seem to have escaped from just doing things like SQL…”
De la Garza: Security training offers highest ROI in CISO portfolio
“If you actually look at, I spend X dollars and I present Y, prevent Y breaches, training and awareness is by far the best ROI of the entire portfolio that a CISO has.”
De la Garza: Large enterprises report 20% of their codebase is AI-generated
“A lot of their code now is AI generated, that they're seeing probably twenty-ish percent of their code base being generated by AI.”
de la Garza: Ransomware Will Evolve to Target Cloud Infrastructure Data
“On the ransomware space, I think the, one of the interesting things that I've noticed over the last couple of years, we've yet to see a variant of ransomware that modifies your data in the cloud, right? So cloud-aware ransomware it's something that we've heard…”
De la Garza: Phishing and pretexting account for 93% of breaches
“If you actually look at the data and you go to the Verizon breach data, which is usually the basis for a lot of these claims, you see that phishing and pretexting are about 93% of those breaches.”
Joel de la Garza: Most cybersecurity tools solve problems created by other products
“Most products that they build are built to solve problems with other products, right?”
Joel de la Garza: CISOs deploy Chromebooks to eliminate endpoint antivirus
“So when you talk to some of the more forward-leaning CISOs in large organizations, they're rolling out hundreds or thousands of Chromebooks, right? They don't need to run antivirus on those endpoints.”
De La Garza: US gangs use Uber and Lyft to launder stolen credit cards
“You see several gangs in the United States that are doing similar schemes where they take stolen credit cards and then sign up as Uber drivers and run credit cards through Uber or through Lyft or through various other sort of sharing economy type services.”
De La Garza: Enterprise buyer inertia applies to cybercrime marketplaces
“Nobody ever gets fired for buying IBM, right? That same kind of inertia applies to the e-crime world.”
De La Garza: 93 percent of security breaches stem from spear phishing
“If you look at the data for breaches and for security incidents, 93% of all breaches are spear phishing emails, right? 80% of those is just straight credential theft.”
De La Garza: US computer intrusion laws are profoundly broken
“The criminal justice laws, the laws around computer intrusions in this country are really profoundly broken. There's not a lot of sophistication or nuance in them. It's essentially treating every kind of computer intrusion like it was armed robbery.”
De La Garza: Compliance and security are typically enemies
“I'm typically of the opinion that compliance and security are the enemies of each other, but this is one instance where I think it's actually really starting to raise the bar.”
Joel De La Garza: Security training yields highest ROI on security spend
“Where we get our single largest return on investment in terms of security spend is around training and engagement and just helping get people like yourselves to know that you're targeted, how you're going to be targeted.”
De la Garza: Major vendors will each launch distinct request-signing standards
“Every, every large vendor is going to have their flavor. And if you're a shop and you're trying to sell to everybody, you've got to kind of work with all of them.”
De la Garza: AI agents will become primary consumers of web content
“And it seems like we're moving to a world where almost the layer you describe, the agent type activity you describe will become the primary consumer of everything on the internet.”
De la Garza: Leaked AWS credentials led to $500K in unauthorized mining
“There's one company that I heard of that checked their credentials for AWS into their GitHub repo on accident, mistake that people make. Within a couple of hours, they had run up about 500,000 dollars of AWS compute charges as people tried to mine Bitcoin.”
de la Garza: AWS Employee Misconfiguration Caused Hosting Provider Data Breach
“There was a hosting provider that had a breach of their data that was caused by an, it was actually an AWS salesperson, had misconfigured the permissions on their S three bucket and had a bunch of customer confidential data inside this bucket, which then got d…”
De la Garza: Hiring a junior security engineer takes up to 6 months
“In the Bay Area, it can take upwards of six months to find a junior level security engineer.”
Joel de la Garza: Talent shortage prevents CISOs from trying new security tools
“Finally, the other thing that you'll hear is that security skills shortage is a driving force of what most CISOs do. So you'll, you'll talk to them, you'll try to get them to look at new technology, to consider new alternatives, and they just don't have the bo…”
De La Garza: Cybercrime syndicates scaled by exploiting geographic regulatory arbitrage
“The way that we were looking at it back then was that this was essentially a regulatory arbitrage, right? It was, there are these disciplines and practices that you could apply in places where these activities weren't necessarily illegal, and so you saw the pr…”
De La Garza: Cryptocurrency solved money laundering for ransomware syndicates
“Because you've solved, with a bearer asset like a cryptocurrency, you've kind of solved the laundering problem. You don't need money mules. You get the cash.”
De La Garza: Cybercrime attribution is the hardest part of cybersecurity
“Attribution is the hardest part of the whole security ecosystem, like putting fingers on keyboards, that's what governments do.”
De La Garza: Cybercrime represents a greenfield market subject to innovator's dilemma
“Sort of the innovator's dilemma applied to crime, right? They got their incumbency in the rackets that they're running, and they're not really looking to expand. Cybercrime is very much a greenfield opportunity. The same way that technology is, and you do see …”
De La Garza: Consumer electronics will eventually feature standard security stamps
“I think we're going to get to a point where our consumer electronics will have that kind of security stamp on the back. That'll be based on some kind of measurable, meaningful standards.”
De La Garza: Enterprise cybersecurity will shift to risk transfer and insurance
“In 10 years it's all about standards, and then it ultimately becomes about risk transfer, right? Some form of insurance. And it's about leveraging standards to mitigate as much of the risk as possible and then transferring the risk that you can't control throu…”
De la Garza: Traditional bot blocking was driven strictly by scale
“I mean, if I remember back why we made a lot of the decisions we made in blocking bots was strictly because of scale. So, you know, you've got 450,000 IP addresses sending you terabits of traffic through a link that only can do gigabit and you've got to just s…”
De la Garza: NIST identity proofing group has stalled for 35 years
“There's a NIST working group on proofing identity that's been running, I think for 35 years, and like still hasn't really gotten to something that's implementable.”
De la Garza: Venture capital invested $7.6B in cybersecurity in 2017
“Last year there was about 7.6 billion invested by venture capital firms into cyber security alone.”
De La Garza: Cybercrime rapidly commercialized around 1999 to 2000
“Right around 19 99, 2000, there was just a rapid, rapid commercialization of cybercrime. You could go on to online chat rooms and just see people's personal information scale by, tens of thousands of credit card numbers scaling by, And starting to see kind of …”