Go back

Eward Driehuis - Teach heart, Design mindset

49m 15s

Eward Driehuis - Teach heart, Design mindset

In this interview, A-Warth, founder of Three Eyes, discusses his unconventional career path in cybersecurity, which began in 1995. He started as a software tester and sys admin after leaving university, later joining Fox IT in 2008 where he worked on threat intelligence and anti-fraud products. A-Warth highlights the importance of transparency in handling security incidents, sharing a story about stolen admin passwords that required on-site resets for dozens of clients. He values mentoring others over personal achievements, citing a bartender he inspired to become a top salesman. A-Warth also reflects on cultural differences between working in the US and Japan, and explains his company name "Three Eyes" as a playful reference to the "Five Eyes" intelligence alliance. He recently left Cybersprint due to the challenges of remote work during COVID, choosing to start his own business. Throughout, A-Warth emphasizes a tech-driven, business-savvy mindset and the mutual respect needed for successful collaborations.

Transcription

7966 Words, 42500 Characters

English
This is Lawrence and Bruno and welcome to Cyberscirty Talks. The interview podcast for Cyberscirty professionals and for those who aspire to become one. My name is Laosha and with me is my co-host Bruno Leimbork. Together we interview industry experts and explore what it's like to work in Cyberscirty domain. Join us on our journey and listen to our bi-weekly episodes and learn about latest trends, real life horror stories and everything you need to know about this fascinating industry. Welcome everybody. We're very delighted to have A-Warth 3-House on the microphone. A-Warth is the founder of Three Eyes and describes himself as a Cybers entrepreneur. He's one of the pioneers in the Dutch Cyberscirty industry, starting his career in 1995. Prior to starting his own company, A-Warth gained experience in the Cybers and tech industry, filling in roles of four different continents, all the way from chief research officer to being the head of product. A-Warth's also frequently featured on the B&M News Radio show, and that's why we're even more excited to have him here today. We spoke with him about his first assignments abroad, the state of the Dutch Cyberscirty industry, and the bright future of the Cyberscirty market. What you need to know about me? What's me the year you start your day with? I took two cups of coffee, black, no sugar, and right or iOS? Android. What is your favorite phone app? Google Maps. Working from home, office, or a mix? Office. Are you a gamer? Yes, what games? I played Border, Lange, franchise, like a boss. What is the oldest appliance in your house? That would be my. My dude with your self-hardware, probably. If you can call that an appliance? Yeah, well, it uses electricity as. I like to drill stuff and. sort stuff. Laptop, desktop server, or AVM? Laptop. What is a built-up pleasure, over yours? I love watching fail movies on YouTube, and what is the first word that comes to mind when I say "Cyberscirty"? Shit show. And your email password is? Secret. The beginnings. Maybe an odd question to begin with. Well, what do you think of all these job titles? Because we did some research, of course. You've been a Chief Research Officer, a Chief Technology Officer. You've been the Product Director at Fox IT. You've been a Chief Marketing Officer at Scarelink. And then lastly, you were a Senior Vice President of Strategy. What kind of man are you, everyone? Yeah, I think I do think it's because in the US, if you travel abroad, and there's this standardization of function titles, which go from, "If you're a manager, you don't manage anything. If you're a Director, maybe you have one or two reports. So if you start to become a VP, like you're a proper manager, like he would be in the Netherlands, with some real responsibility. And an SVP would be like a guy that, or a girl, that. So it's standardized across that American thingy, but it's, of course, total BS. Nobody is a Senior Vice President. Like you're not a President, or you're not a spare President. It's just, we agree on. Yeah, so it's BS, but yeah. Yeah, it's something. But you're the first guy that I meet that's been a Chief Marketing Officer and a Chief Technology Officer. That's a crazy combination. Yeah, I know. Yeah, I know, right? So listen, what I sometimes say, and this sounds a little bit like marketing, because I want to see more ones. So I have a TechHeart. I just started out as a Techie, but I have a design mindset. And we can go into that later, what that means. But I always see multiple solutions for any given problem. And many Techies see one solution for a problem. It's called deduction versus reduction. It's a bad point of mind. But I have a business drive as well. And for some reason, if you're kind of understand technology and you're able to elaborate about it, people want to make you a manager or want to make you a marketer or a product marketer. And that's what happened to me. And now you're. Are you a Senior Vice President in the Cybersecurity Domain? But as a kid, what did you want to become? Well, that's a super good question. I totally didn't know. I grew up on a small island called Wauge. So I know that from the early or from the mid-80s, I had been playing with computers. I went to my dad's work, where he was a psychologist. He worked with children. And at his work, for some reason, there was this huge. The cabinet pool of computers like an Amiga and a Commodore. A Commodore Amiga is Commodore. I'm at a Commodore 64. And some other stuff like an Atari. And I always went with him to play with the computers. It just struck me that that might have been where I came from. Yeah. That was the first encounter with computers. What was your first encounter with cybersecurity? So this is maybe digging deep because when I started in computers, of course, cybersecurity was not a field. When I started out with my 1995 with my professional IT job, there wasn't even like an IT training or university or whatever. You could maybe do math or whatever. So back then, I think it was kind of embedded in the job that we did. But of course, we had no idea what we were doing. We were inventing IT as we went. But I think back then, even back then, I was. Cybersecurity was part of the job. And the first real incident that I ever had was when I was working for this company. One one tell who they are, but it's. And we had this remote access to our customers to help them out when they had a problem with their NDS or whatever. And so we kept the admin passwords, of course. We printed them out on paper. We didn't store them or whatever. So we printed them out on papers. The papers went in a safe. So that's cool. Yeah, that's super old school, right? But we needed to do that whenever. So then one time I came to the office and I saw that the door was a jar. And the window was open. And I went up and they had stolen this safe. And the safe really had nothing else. It was like a safe of 150 kilos or whatever. And I looked out of the window and it was this big dent in the grass below it. So the burglar apparently thought, "Oh, there must be valuable goods in here." And well, what they did is they had stolen all the admin passwords for our customers. That was like one of the biggest incidents I ever had. And I probably can't talk about it. You can just Google where I work back then. And that was like the biggest incident I've ever been. That was my starting cybersecurity. What a start. Yeah. And how did you inform the client? It's not a pleasant call to me. No, no, no. And so we needed to call dozens of clients. And what we did is we dispatched, like, we were quite a big company. They still are, by the way. And we dispatched like 30 people. They went on trains, on cars and whatever. And they went on-prem with every single customer to reset all the admin passwords and so on and so on. And we just called them up. And so yeah, we're coming right now. It comes up as we're going in. We're changing all the admin passwords. Oh, well. And how were you able to still make this a success? I can imagine it's a very challenging assignment. And it doesn't have a good feel to it. But maybe if you serve as the client very well and act very professionally, you were able to give it a positive spin. Was the client still happy with the service delivered at the end? Well, of course, no one's excited when you called them up and said, "Well, listen, we had some. " They understand that we did our. Everything we could, right? But of course they weren't happy about it. But I think that's one of the big lessons that many people in cybersecurity understand is that whenever you're hit by something, you're transparent about it and honest and just reflect and take the learnings. And then it's actually OK. You won't take a huge hit on your credibility. And one of the best examples I saw was when Fox IT, they were. Well, they weren't really hacked, but they had some DNS hijack for some of their services. They were turned to the customers, I think it was something like that. And they were totally transparent about it. So they came out themselves, they put blogs and they explained how they found. They also found it themselves, the problem, so that helped, of course. And no one's like, "Oh, I'm never hiring Fox IT again." No, that didn't happen because if you're transparent and honest, that's usually fine. Yeah, that's a great lesson. I would like to jump back to the young A-Wart. So you were studying at the Delft University and then in your spare time we're sitting down at a computer all the time. But at some point you graduate and then what steps did you take then? Well, the assumption there is that I graduated and I did not. Oh, that's new. But when I saw that was one of those things, right? So I started to work and I remember again, I knew my studies weren't ending well probably for me. I tried to do another study as well and that didn't go well too. So I decided I need to do something productive with my time. So I went to this job company and I said, "Well, can I do some work?" So they said, "Well, are you any good?" that picking tomatoes and I said, "Well, I lied that my back was bad." And then they said, "Well, maybe there's this computer job here." So yeah, I would do that. So that little wide lie got me into the computing business and I became a software tester, a beta tester for a software company, which I enjoyed tremendously because it was again software testers. They can, you need to do it was called monkey testing back then. And it's called a doing crazy stuff that software is not supposed to do, but you do it anyway to see what happens. I was very good at that. Maybe that was the design or the hacker mindset, I don't know. So yeah, and then I became their sys admin and I knew a little bit of that. And then I said, "Well, this IT stuff is actually very enjoyable." And then I moved from them to a proper IT company and I became a sys admin there and they rented me to all kinds of companies and that was when my career or my job really took off. Yeah. The career milestones. You became a sys admin and then I think at some point you had an encounter with Fox IT. Can you elaborate on that? Yeah, that was wonderful. It was back in 2008. So I was a manager in that IT company back then. So we were running that company the five of us and my mom was super proud of me because I had a proper job. I had some responsibility. I had 50 reports. And I spent all of my time just, you know, just measuring stuff, KPIs and doing Excel work and working in CRM and just other people were doing the cool jobs. And I was just watching if they did their jobs well. And I thought to myself, "This management stuff is really sucks, man." Wow. And I was thinking those things. And then I had a drink with a few people and there was this very tall, very handsome gentleman. And he had his shirt, very very flowery, colorful shirt. And the third button was open and there was chest hair and the guy was called Ronald. And he said, "Well, what do you do?" And I said, "Well, I'm a super important manager and I have 50 reports." And he said, "Well, that's some super boring man. You want to have a real job?" Okay. On the spot. Yeah. Now I know it on the spot. No. He asked me, "Okay, so, I need technical." And so, "Yeah, I run my own server and my basement." And I said, "Oh, cool. So what kind of open as a cell version do you use?" And I said, "Well, 0.97C was back then, I think." And I said, "Well, I think these just came out." Then you hit it up. And yeah. And then for some reason, he asked me to join this company. But folks I've now known as one of the most successful Dutch cybersecurity companies. But when you joined, what did it look like? I was very impressed. I had a little bit maybe imposter syndrome because I thought I'm doing this, I've been doing this IT stuff for over almost 15 years now. I know my stuff. You know, I know my way around Linux, I compile myself, I build a Linux from scratch stuff, I was Microsoft's MCZ certified. So I thought to myself, I'm pretty technical. And then I met the people working at Fox IT and like, "Oh, they are really smart." I thought I was smart. So luckily I had a management role. So I needed really to abandon all my illusions that my technical skills were good enough for them. So yeah. And so I did that. And then later on became more like a product guy. So I did, I worked for there. They had an anti-fraud department back then. They built a product which was sold to banks and spin off from that product was the threat intelligence part. Because back then, you know, the Russians we talked about, they were doing not ransomware, but they were doing banking malware. Right. So they attacked customers of banks with banking malware. So the department I worked and collected both intelligence about this mainly to see what kind of little mistakes the criminals were making. Because you know, whenever you try to do a web injection or man in the middle of the tech, so the malware intercepts the traffic from the bank going to your browser, changes it a little bit and then renders the new stuff. So you see stuff as it is from the bank, you get your green lock, everything's the same, but it's not the bank, it's the malware injecting some stuff. For example, asking you to type in your password again or whatever, you know, those silly tricks. And we built software to detect that as well. Because the criminals were messing with the HTTP sessions, it would sometimes make little mistakes mess with the headers, for example. So we could build that in software. Whenever the header has, for example, a lowercase letter, this or that or whatever the crap, it's a criminal session. And so that kind of software was a fantastic time. I learned a lot. And but what later, and that was super interesting, it was still like a niche product. You needed to have an online banking channel and that kind of stuff. But the threat intelligence that we collected, that was really what we what we excelled at. And the people, the threat intelligence analysts, some of them still working there, they were so knowledgeable, unbelievably knowledgeable, and also doing, you know, and that threat intelligence stuff we managed to then sell in four continents. And that really built our reputation internationally. And that was, that was really some of the best years of my of my life. Because it was so much fun. Yeah. Yeah, maybe to tap onto that. Is this also the part where you're most proud of in your career, or are there other things that you feel even more proud of? Well, achievements are, they're there on a personal level. They're, they're dubious, right? You do your best, you make some money and that's all fine. But what I myself remember most fondly was, for example, we went to a bar, right? A bar in Delft, you know, because we were working hard, while also playing hard. So we went to the bar in Delft and the bartender there was a very nice guy and he did a study and he, you know, he was an intern at FoxIT. But then his internship was over. And I was talking to him. So maybe you want to have a commercial role in that, in that and the guy started working there in a commercial support role and within three years and everyone was like, this guy is not a salesman, but within three years he was the best salesman of our entire department. And I think maybe even our entire company and it then started, went ahead and worked for an American company. That is the stuff I'm super proud of, right? So that this guy is now, you know, working internationally and making, I don't know, probably making a lot of money, I don't know, but I'm super proud of that kind of stuff. So that you're able to inspire people to take that step and enter the cybersecurity business or the field and excel. Yeah, exactly. I think that's, and maybe that does just of course on what you guys do as well, is that this is your job, right? To spot the talent. Yeah. But this is a great example. But Bruno said, it's not your personal success, the things that you have achieved, but that you enabled somebody to get this career and that he turned very successful. Yeah. Maybe if you wouldn't. Yeah, it was more successful than me. Yeah. But I think it's very humble. That's not me falsely humble then, right? Of course, I'm also proud of some of the stuff that I did. I'm really proud of the work that I did for with securing as well. I'm super proud of that Fox IT, but I got so much from Fox I learned so much then. And it's at securing, I could use that knowledge to really help them build the company and build their reputation. And I'm on a personal level, of course, that's when I'm proud of his well. Yeah. Yeah. And after securing, you went to join Cybersprint. Yeah. Yes, the senior vice president. Yeah, there we go. SVP. But that's now also, I saw last week, a company that's in the top 250 fastest grown companies of the Netherlands. So it seemed that you have a good track record of joining companies early stage and that they turn very, very successful. Would you say that that's also your expertise that has added to that? Well, again, that's not me, you know, that's not be falsely humble. I'm sure it plays a role, right? But you definitely think so. Yeah. And then it's usually, you know, I do think, you know, your contribution to companies like love, right? You're in this mutual relationship. So you give them the love and you get the love back and you notice immediately if it's not mutual, it's not going to be successful, right? So I have been in some fantastic relations with companies where had the mutual relation and the love and then yeah so and I think that mutual stuff is really important. Yeah, for sure and then and you can become successful if everyone feels that if everyone has that yeah. Yeah great and now you recently decided to leave Cybersprint. Yeah and what's the decision? Yeah, it's a super the fastest growing now these these guys are they're wonderful. I had so much fun. It was of course you know for myself just talking for myself not for them it was for myself a rough year because I was supposed to do the international stuff in the stages and so on and of course with with all the COVID stuff that didn't happen. I don't like to work from home particularly. Yeah so for me that was so yeah it was the COVID stuff has been a little bit rough and yeah and I so I decided to to leave. Might be a super decision. We'll see I don't know follow your heart and I started my own little business so yeah there you go. That's the first time I'm I'm mentioning I have a name in a logo. Please drum rolls. Three eyes. Three eyes. Well yeah what's the the reason behind the name? It's like the pun the pun is of course that so my three is like my last name the E is like my first name the letter turning my round but also you know what five eyes is right. Yeah within the intelligence community. Yeah so that's America the UK Canada Australia and New Zealand. New Zealand. Yeah so those are the five countries that cooperate in some way or another and apparently you you are part of the select group of the three eyes. Yeah there's an expendant if you're invited to sit at their table you're part of the nine eyes. There's also an important principle in cyber that's called the four eyes principle so I just thought it would be funny to call myself three eyes. Yeah I've heard it. Yeah. The orange cyber army and you've been on cases from from America all the way to Japan. That's amazing. I think what is it like for for you to work then in the US and then in Japan is a big cultural difference in the the things you see. Oh yeah for sure. Yeah I did I've always loved and sadly of course when I didn't last year and a half I haven't been to the US I love working there and I I love the culture. I would never want to live there I think but I love working there and with all the you know with all the silly senior vice presidents you talk to and senior non-executive directors and what but I do love that and I take their cybersecurity very seriously you know and I remember for example a few years ago I was working with US banks a little bit we were working in threat intelligence back then in Fox IT and we were of course still in in Europe it would be a shock right security operation center and what have you so I went to this bank and I went a little bit outside of New York it was winter and I was with an Uber through the snow and we went to New York somewhere somewhere around there and I was led into the fusion center of this bank and I an fusion center is when the shock is typically you know a little bit reactive if you want to be proactive take threat intelligence in and all that stuff they start calling it a fusion center and I just love that stuff it's probably the marketing part of myself that's going to say that's just if you get an exciting name it will yeah but it works but it was exciting right it wasn't just like operators looking to all the alerts and trying to get their cues down to zero like like many socks still doing today it's was really also being proactive doing threat hunting digesting threat until you know and all that good stuff so and whereas you know Japan is it's a totally different cup of tea I have spent I spend a week there and I think this is public information when well you you guys know what a CA is right a certificate of authority um digginotor yeah exactly yeah that was one famous one where the Fox IT worked on that one as well when I was working at Fox IT and I was working there on the sidelines so I was kind of the guy back then doing the administrative the administrative part of the of the of the project but other guys like Frank Groenewege he went on prem and you know he found that cable running into the safe it it that's a safe again yeah yeah there you go yeah um so that was one famous example but since we did that we we were suddenly we were the guys oh if your C.A. is hacked you should give these guys a call so what do you know a few months later not a C.A. was was hacked so we went to Tokyo and I remember vividly because one time in my life I flew a lot but I never flew like business class you know that's just too expensive I was suddenly upgraded to business class and was that time when I flew to Tokyo I was sitting in the front of a 747 so even that part of the journey I remember vividly but we came in Tokyo and helped them out again I was flown in not because my technical skills are excellent my colleague did that but there's a reputation was tough as well what should we do they ask these questions which I thought were very valid so how honest should we be should we take down surface and so on and so on and this required a little bit more of a business approach and understanding you know being that bridge as you say so I was the guy doing that and it was one of the most honorable weeks in my life we managed to help them out and they're still in business today just check your browser and see see where they're at so yeah what was most surprising for you from the the whole experience well you know it's sometimes it's super strange and even the other day remember when Facebook was down for for a few hours I believe terrible yeah terrible you know I I don't use Facebook myself I do use WhatsApp if I'm honest and that's Facebook too but and that's the same the same issue is that the internet was it's like it's so crappy right it's wonderful right but it's so crappy you know technology level it's like duct tape and chitman bubblegum it's it's you know you can bring it down so easily and it was bgb at Facebook but also like these 800 c a's that we have you know if they're hacked like it's it's it's an enormous impact that it has and there's pretty much nothing we can do right we the technology is there to make it better like ipf6 it's been in existence I believe for over 25 years but nobody uses it right so it's it's what I don't we IP we know ipf4 is it's yeah it's not it's not working it's not working particularly well you know I don't use ipf6 you tell me for some reason we want it to be bubblegum and duct tape and which is one of the reasons why cyber security is so in today that was my takeaway it's it's just the internet is bad on a technology level yeah and then looking at the companies for instance from Japan that then hire Dutch people to to sort of solve their issues what does that tell you about the the Dutch standard of cyber security yeah that is a fantastic question because also when you read the news or if you listen to the radio and what's the V everyone's all the cyber people are always saying oh we don't put in enough effort and the Netherlands is losing their position or we're compared to the rest we do badly maybe that's true in part we can always do better you know if you look at the current government for example it's quite clear that I don't give cyber security any priority but that sets you know the parts of the government that are responsible for some of the stuff they do quite a bang up job especially the services like a you know secret service and the military service do do the fantastic job our police is excellent right so even though the political will is not really there the you know the executive the guys is actually doing the work I actually have a very solid reputation and just the other day I saw on Twitter some some guy who was asked the question who has the best offensive cyber security in the world and he showed a a gift of orange people cheering much for stopper right so we have quite a reputation and I think it's warranted we we do quite well and also when when I travel well I haven't traveled for 18 months of course but when I did travel whenever I came somewhere out there's a Dutch guy you know he's probably knows a stuff so yeah we do have a reputation internationally yeah that's great yeah that's positive yeah because I remember from the the webinar we did I ask you what have you seen changed the last two decades in cyber and I think you mentioned that the hackers are now usually whole countries and very organized organizations and before there was just individuals you They'll agree with that vision. Yeah, I think it's evolving even further. I agree, by the way, what you just said. I don't know if the wisdom is certainly not mine. Do what you're words. Well, yeah, it's probably bored and from someone wiser than myself. That's what I think. But for sure, especially when I started working at FoxIT, I learned the truth that it's in reality. It's not the geeks in their basements with their PCs in front of them. Sometimes that is the way we like to portray them. And the reason for that is if you look at this stuff in the, for example, in the Netherlands, where we're set right now in Amsterdam, is the only time when the police actually catches the cybercriminal is one of those guys who does it in the Netherlands, right? In the Netherlands, there's no way in hell that you can organize yourselves as the Russians do in order to start stealing from people because you will be, you know, the SWAT team will be in your house before you deploy your C2, right? No way in hell you can do that. And that's the difference because the guys that are apprehended in the Netherlands and in other countries, maybe they are geeks in addicts. But these guys are not, they are not the problem, right? They are the people that get in the news locally. But on a world stage, it is really, it's these nation states and their policies. We, you know, many people agree that like 1995 percent of ransomware operators originate from one in the same country, country, which we don't have an extradition treaty with. So yeah, and those internal policies towards these people contributes that they are the problem because if they would enforce some laws saying, "Listen, you can't be criminal, "you can't steal from anyone, including foreign. " No, they say, "Well, you can't steal from Russians, right?" So all those malware's, as you probably very well know, they have subproutines or, you know, that if they detect Russian keyboard layout or whatever, they won't, they won't activate, right? They won't fire. And that's because of their internal policies. They own activate when they find a Dutch or a US keyboard layout and yeah, there you go. And that's how that works. And would there be a solution to this issue, say if you would be the minister of foreign affairs of the Netherlands, what would you advise him? 'Cause I think it's a cat-a-mouse game, but it doesn't seem to be solved anytime soon. No, it's, I don't know, if it's, this is ever gonna be solved, right? Well, not in my lifetime, but, you know, I sometimes said jokingly when Obama was still, Obama should have a cup of coffee with Vladimir. But obviously, of course, they do this stuff. It's called diplomacy. So, you know, it's a stupid advice because diplomacy is all around, you know? Even if you're the biggest enemies on the world stage, the diplomats either, you know, depending on how much friction there is, there are, you know, two, three or four layers down the ladder, but they're still having those cups of coffee. And this is something, of course, you know, that you, that needs to be done. I'd maybe, you know, like the United Nations or NATO, you know, it's always good to organize. I think we should stay very close friends with the US because, you know, they carried the biggest stick out there. And so you should be friends with the guys with the biggest stick. And who knows what happens if someone else has the biggest stick and they're not our friends anymore. You know, that's when. Is there not already happening if you look at Russia and China? Well, Russia, you should not overestimate Russia, right? So, Russia's GDP is distressingly low. They are actually very poor. And that reflects to their capabilities as well, which is why they do this. Many people believe, again, there's no my research, but in my experience is why they deploy these guerrilla tactics. Right? They try to make the most disruption out of a few investments. And that they let the criminals keep earnings is one of those doesn't cost them anything, right? But still the impacts outside of Russia is really big. So this is one of those guerrilla tactics. It's almost the supportive environment if you look at it. Yeah, so. So, and so they're not very big, but China, yes, for sure. China does have a budget. They have a strategy. They have a long-term strategy. They have a lot of people. I think you might be right. Maybe the shift has already happened. And do you know if we have goods bonds and ties with them? If you look at the cybersecurity domain, do you know from a more country perspective? Are we in good terms with them? Well, I'm not super knowledgeable about those diplomatic relations. But of course, what you do see is that. And I think this is just examples from the news, for example, if some poor person, for example, there was this movie guy, the movie star, he said, "I'm going to go to the beautiful country of Taiwan to promote my movie." That's what he said. And then the Chinese became very angry and wanted to boycott his entire movie company because he called Taiwan a country, right? So then he went on and this was a big muscular guy, right? And he said, "Oh, I'm so. I'm going to apologize to the wonderful people of China." And I didn't mean to offend. And it was my ignorance. And he was throwing himself in the dust for them. And why is that? Because they are very powerful. I don't think they are very impressed with anything, the Netherlands, or maybe even Europe has to say to them. Not to say, but I think they are very impressed with the things that we do and build. Our chips in the industry, right? So they are very interested in us and maybe not for the good reasons. Yeah. Well, yeah, for sure. And I think the diplomatic relations reflect this a little bit. They build their economy, of course, on our knowledge as well, which they, let's say, borrowed from us with those set APTs, for example. And without that, that's kind of a. that's a fact. We will never know how much of their economy is built on that. Because, of course, they work hard as well. And they, again, they have a lot of people, a lot of resources. But for sure, that's played a part in their economic growth as well. The future of cyber security. But what would you hope to achieve for the next five years? Is there still a big problem you would try to solve? For sure. Yeah. And that's actually a very good question. So I worked so much in these. like, as luck would have it, at one of some of these amazing companies, like Fox IT, SecureLink and Cypressprint. But I'm well aware that these companies operate in very much in the tip of the pyramid, right? If you're looking at the problems, you know, who does, who works with APTs, right? Who collects threat intelligence about Russian gangshil? That's all. that's all in the tip of the pyramid, right? But cyber security has a very, very broad base, like, 95% of the problems are there because the foundational stuff is not in order, right? And we're all focusing on the posh stuff that happens in the top of the pyramid. Obviously, that's the cool stuff, right? That's what you hear about. Yeah. But people, organizations, mid-sized companies, they have these very tangible issues, just not having the baselines in order. You know, everyone says to them, "Yeah, well, you need your foundation, "you need to be right." And then, "But what do I need to do then?" "Oh, you just saw your patches and do that." And then, "But we're not going to bother you." And I think that is a problem we need to address. You know, we have two little people, two few people, and they all want to threaten themselves in the top of the pyramid. And I'm thinking very hard about how can we make cyber security and the foundational IT architecture that is below that important, again, important enough for the board to care. Because they do care about cyber security. They have their CISOs now, right? CIOs are important people. But the stuff that happens on the network, like the management of the work stations, all that foundational stuff, is still neglected often. And that's why ransomware is now part of why ransomware is rampant. If only they would know the five things they need to invest in, they can prevent a lot of shit from happening, I think. And someone needs to take it down from the top of the pyramid and say, "Well, what are you going to do in the foundation?" So long story short, I believe I might be able to help there a little bit, making sure that IT companies can expand their portfolio to include those baseline solutions again, and make sure that we're really getting more cyber resilient from ground up because the top down stuff everyone's forcing that right now I need I think the foundational upward movement needs to happen as well. And would you then say that if you look at the foundations of said companies and their their infrastructure and their endpoints that you sort of take a step back in time because it's not developed as the fast moving latest and greatest technology is it is it is it all or is it less developed in a sense. So you mean the IT itself? Yeah. Well, yeah. Yeah. I mean, legacy, legacy products are a hassle on a problem. Yeah. Well, I do think that the first just like the internet is a tremendous crap show, technology wise, although everyone does his best at the same amounts for networks and and if they're not born in the cloud, right, like like the companies that were that were created like two years ago and they were born in AWS, maybe or an Azure, whatever they might have the best cybersecurity because they didn't have carry all this legacy. But all the other companies they created their network in order to be available and that's it. And the ability is the only thing that these networks were designed for and confidentiality and integrity was never part of the of the of the equation, right? So if you try to slap that on afterwards, this is why the internet doesn't work, right? Yeah. It's there. It's available, but it's not confidential and the integrity is not guaranteed whatsoever. And the same problem is therefore many networks, I believe. And many companies won't start over at a should really, right? If you talk 90% of the companies that use IT should just start over today and create a completely new network based on today's paradigms, but they won't. But here's the good thing. Three eyes. No, I was going to credit Russians now. Right. That's the opposite. Yeah. So just as much as global warming is now forcing people to finally insulate their old homes, right? And to maybe say, okay, so this home is never going to get insulated. I'm going to build a new one. The same might happen with, you know, we've got to rent some worries now of big epidemic. And it's very difficult to keep them out, right? Unless you start over again. So this might be the incentive. So with global warming, we use that to consume a little bit less energy. Maybe we use the ransomware epidemic to build our foundations a new and rights this time. And then to move to an ending of the conversation, I just want to ask you some questions. What you might advise younger professionals nowadays, because I feel there's also misconception that a lot of people want to enter the cybersecurity market, but they feel they really need a strong technical background. What's your take on it? I, by the way, I agree a little bit. The technical background does help. And I think some of the best people I met were able to, were the best people I ever met were both technical and had some way to elaborate about it. The CDOs and the CMOs at the same time. Sometimes, but also I'm a super big fan of, for example, Bethoe Bear. If you know him, he's the founder of PowerDNS and he also worked for FoxIT. I was always very impressed by his way to elaborate on some of the bigger problems. And also he has worked with solutions on fixing that broken internet with regards to DNS. And he is super technical. But he's also, he's not really fair, by the way, because IQ is just, so, so, so, so, so, he's just at, you know, next level. So a little bit technical is, is, is good. But I, what I do think is a misconception is I, I know there's many people working in IT that believe they can't have an easy start in cyber because they're just IT people. But those are, these people might be mistaken. It might be good enough if you have a solid IT background and some solid based knowledge to transition into, for example, stock position or to work your way up to, you know, I don't know, application security or whatever. I, I think many people, I, I know are actually good enough, probably, but they don't know it. But you're the prime example of this. You also started in IT and then grew, yeah. Gradually into becoming a cyber security expert. Yeah, yeah, probably, yeah, by, by, by luck of the draw, yeah, for sure. Yeah, yeah, yeah, yeah. Yeah, that's excellent. But maybe not luck of the draw. I think, and especially also for young people, you just need to go for it. It's not, it's not a problem to feel we all do. Yeah. But if you don't try, you'll, you'll never exceed. And maybe in, in your example, you just, yeah, maybe you had a, a funny conversation with a guy that's tall and handsome and has a nice bush of hair on his chest, but it doesn't have to be those coincidences. And I think a lot of people, like you mentioned, maybe feel like, oh, whatever job I look at, you need 10, 10 years of specific experience. But it really starts with talking to people, not companies, but people at companies. Yeah, I agree totally. It's like, when I said luck of the draw, for sure, you know, I do believe, by the way, there's one of my philosophies that everything that happens to you is by luck or by bad luck. But the trick is to roll the dice as many times as you can, right? So you can, you can, maybe the, you can't improve your luck, but you can work on how many times you throw the dice. So put yourself out there and I agree with you totally. And that's a conversation here, a conversation there. And even if you're super unlucky, if you have 100 conversations, you're bound to strike five interesting ones, right? Yeah. And that's how it's usually starts. So you need to get off your chair and get yourself out there or get yourself into zoom or whatever or in your community or you join the Dutch Institute for vulnerability disclosure, right? And that's a very, very important thing to do. And that's a very important thing to do. And thank you seriously, right? And yeah. Yeah, that's great advice. Yeah. And do you have other suggestions for IT professionals that want to step into this market? Yeah. Well, I do believe that in my time, when this didn't exist, you could just put yourself go there and try to do the job because no one else would. It doesn't hurt to. I like to. I spend at least two hours per day reading stuff. Just to keep myself. I'm 48, right? I'm not as fast as you bunch anymore. I can't. So I need to take that time in order to keep myself informed. I think it's always good if you're hungry for more knowledge. That's probably not going to hurt. Yeah. So to summarize, maybe one is try to keep yourself up to date, maybe try to get certifications. Yeah. And secondly, roll the dice. Show yourself. There's many times you can't. Great. Keep rolling the dice. Lovely. Okay. I think this was an amazing podcast. I really enjoyed conversations. A lot of wisdom there. A lot of advice for junior professionals. I think we've been to different places around the world, which is also fascinating. But thank you so much. It was really lovely. Thank you for listening to Cyber Scirty Talks. We hope you've enjoyed this episode with the latest trends, more stories and exciting career anecdotes. If you enjoyed the show, please bring to you this podcast, or your favorite podcast app. Also, could you do me one small favor? Could you please share this podcast with one friend that you think would like to show you this as much as you do? Thank you. And for all further information, please go to csrecribment.nl/stalks and subscribe to this podcast. We will be back with another exciting episode in just two weeks. So see you next time, and stay safe.

Podcast Summary

Key Points:

  1. A-Warth (founder of Three Eyes) is a Dutch cybersecurity pioneer who started his career in 1995 and has held diverse roles including CRO, CTO, CMO, and SVP.
  2. He emphasizes transparency and honesty when handling security incidents, citing a past breach where admin passwords were stolen from a safe.
  3. A-Warth left university early to work in IT, starting as a software tester and sys admin before joining Fox IT in 2008, where he contributed to threat intelligence and anti-fraud products.
  4. He values inspiring others' success, such as mentoring a bartender who became a top salesman, more than his own achievements.
  5. A-Warth recently left Cybersprint to start his own company, Three Eyes, named as a pun on the "Five Eyes" intelligence alliance and his own name.

Summary:

In this interview, A-Warth, founder of Three Eyes, discusses his unconventional career path in cybersecurity, which began in 1995. He started as a software tester and sys admin after leaving university, later joining Fox IT in 2008 where he worked on threat intelligence and anti-fraud products. A-Warth highlights the importance of transparency in handling security incidents, sharing a story about stolen admin passwords that required on-site resets for dozens of clients.

He values mentoring others over personal achievements, citing a bartender he inspired to become a top salesman. A-Warth also reflects on cultural differences between working in the US and Japan, and explains his company name "Three Eyes" as a playful reference to the "Five Eyes" intelligence alliance. He recently left Cybersprint due to the challenges of remote work during COVID, choosing to start his own business.

Throughout, A-Warth emphasizes a tech-driven, business-savvy mindset and the mutual respect needed for successful collaborations.

FAQs

It is an interview podcast for cybersecurity professionals and aspirants, featuring industry experts discussing trends, horror stories, and insights into the cybersecurity field.

A-Warth is the founder of Three Eyes, a cybersecurity entrepreneur who started his career in 1995. He has held roles like Chief Research Officer and Head of Product across four continents, and is frequently featured on B&M News Radio.

He began with a professional IT job in 1995, and his first major incident involved a stolen safe containing admin passwords for clients, which required dispatching teams to reset passwords on-site.

He joined Fox IT in 2008 after being recruited by Ronald, initially in a management role. He later worked on an anti-fraud product that detected banking malware, which led to a threat intelligence division that sold internationally.

The name is a pun on his last name (Three) and first initial (E), and references the 'Five Eyes' intelligence alliance, with a humorous twist on the 'four eyes principle' in cybersecurity.

He learned that transparency and honesty are crucial when a breach occurs; by being open and taking corrective action, credibility is maintained.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.