Go back

How Do Cyber Criminals Really Operate Against Banks? Future Secured Ep 50 with Sandro Bucchianeri.

50m 13s

How Do Cyber Criminals Really Operate Against Banks? Future Secured Ep 50 with Sandro Bucchianeri.

Sandra Bookian Airy, the Chief Security Officer at National Australian Bank, shared insights on her extensive career in security, emphasizing the importance of collaboration and information sharing within the security community. She stressed the significance of prioritizing foundational security measures to ensure compliance and enhance overall security posture. Sandra also highlighted the essential role of building a strong security culture within organizations through continuous education and engagement with employees at all levels. Additionally, she discussed the need for promoting cybersecurity education from a young age to develop a talent pipeline for the future workforce. Sandra's holistic approach to security underscores the importance of addressing both technical and cultural aspects to enhance cyber resilience and protect organizations effectively.

Transcription

9430 Words, 51131 Characters

Today on Future Secured, we're joined by Sandra Bookian airy, Chief Security Officer and National Australian Bank. Sandra has more than 25 years across global financial institutions and advisory roles with a world economic forum centre for site security, BCI Board of advisors and so many other places. Sandra has a reputation for bringing in pragmatism, calm and strategic focus to high stakes environments. And when you're defending one of Australia's biggest banks, you're not just protecting your business, you're protecting national confidence. Thank you so much, Sandra, for joining us on a 50th episode of Future Secured. We're really happy to have you here with us on that celebration. Thank you, Jason, as always, for joining and helping me as my co-host. So, let's dive in and hope you're doing well. Thanks for having me. Thanks, Sandra, for coming. Yeah, well, 50 years I was expecting big blooms in the background or something like that, but I know you've sucked up most of the dad's side of the budget, so there was never going to be that. That was never going to happen. Exactly. We really do appreciate you coming on there. There's so many different things we want to cover, but before we do, for those who don't know you, can you give us the journey as far back as you want to go on sort of how you ended up where you are now with now and how that journey followed and how you got to where you are now? No, that's a great question. I'm really going to need to rack my brain. No, so I was interested in security from a very young age. I shared the story before. I used to live with my grandparents and on the weekends my uncle would used to bring me home to where my parents were living. It was in a poverty-stricken area and we were crossing the field. They were gangster standing on the right-hand side. They called him over. He left me on the one side. I was five at the time, and then the robbed him of his watch and his wallet. I still remember it like it was yesterday, but that left me with this impression that I would love to protect him in that situation, to protect people from bad things happening. That kickstarted my love for security and wanting to protect that innate ability to protect. I was always at a love for technology and to give away my age, but I had a Natari 2600 and a Commodore 64. My grandfather gave me that he got from somebody, and that started my love for computers and technology at a very early age. I then just grew into where it finds itself now. Where I find myself now is having traveled to about 100 countries, lived on five continents, all through the journey of being in security. It's taken me all over the world, so we've been very blessed to live everywhere. That's brought me to Australia. From South Africa to the US, to the UK, to the UAE, back to South Africa and now to the wonderful continent of Australia. That's how my journey has taken me throughout these 27, 28 years now. And so far, I've been in Australia for about four and a half years at the biggest business bank in Australia. I have the absolute privilege of leading a wonderful team over here, protecting the bank both from a security, information cyber security perspective, but also physical security. That's why I'm the Chief Security Officer. So that's been my journey over the last couple of years, and hopefully long made continue. No, well done. So you would have come here, what COVID would have been in the groups of COVID? Second of July. Second of July 2021 is when I landed on the beautiful shores of Brisbane, was the only flight I could get into Australia. Was the only flight I could myself and my family could get into Australia, was Brisbane, quarantine there for two weeks and then came to the most lockdown city on the planet, which was Melbourne. But it was great. That was a terrible time for the world, but lots of lessons to learn through that period and there's no such thing as failure or it's always time to learn and we learned a lot through that time and how to be resilient, even more resilient than we were. So we'll take those lessons and learn and apply to the future. Yeah, one of the good things I think is I, you know, the four, I mean four big banks, we've got some very sizable banks, you know, in comparison when you compare them across the globe. And, and you guys work fairly closely together, you know, with Nicola and Maria and, and yourself, I remember being on, yeah, and being on a pod, sorry, it was a webinar recently with Michelle McGinnis, you know, and it was interesting some of the stuff that came out there about how you're having your own sort of chat group and different things and how you sort of support each other. That's, I don't, I know that's not unique to Australia, but I think for the people listening, it's actually really good to hear how closely aligned and linked you are. Because, yeah, obviously, having similar challenges, how does that sort of work and, and how do you find that as being one of the members of that group and, and how you sort of assist each other? No, look, I think it's a great thing that we have with just not, not just in Australia, but globally in the security community at large. We all facing similar challenges. Yes, we may be competitors, but when it comes to security, there's no, there's no such thing as, oh, no, I'm going to go solo. So that's why we operated this team mentality. And it's been great because if some, if Nicolas finds something in her world or Richard or Maria, they'll give me a call or they'll, they'll, they'll shoot me a text message saying, hey, we've seen these IOCs or these indicators of compromise. You guys might want to check your environment to see if anything's going on. And so on and so forth. And then broader and in the international markets, we have great relationships with CIBC and Canada, ITAO in Brazil and Northwest in the UK. We've got what's called the Strategic Banking Alliance. That's been really good in helping us understand the threats from further afield. And that community is really, really strong. So if you ever have a challenge, you could be guaranteed to phone any one of them or message any one of them and they'll answer 9 to 10. So that's the wonderful thing about this community that we've built over the last few decades. It's, we always willing to help each other. We're not looking to pull one up on the other. It's just how we can help the grades are good because at the end of the day, it's the nation that's important. It's every single customer of every single organization out there. That's the ones we are trying to defend. So I think it works really well. And have you seen in that time you've been here, you would have seen I've noticed. I'm hoping it would be the same for yourself. A greater interaction, especially between the Knox or home affairs and having Michelle McGinnis in the role. And just that connection for our critical infrastructure in the country, it seems like there is a real finger on the pulse now with regard to that. From a government, there seems to be a lot more focus and a lot more action happening in there. How do you see that and what major changes have you seen that obviously benefit you, but that we could learn from for the rest of the community and how they could apply some of the knowledge? No, look, I think it's been great. I mean, over the years, there's been some terrible things that's happened, right? The thing that accelerated was obviously the major breaches that happened a few years ago with the Talko provider. This is Mediband. You could call that I'd like to. Exactly. So with those, it's accelerated the interest in this topic specifically. And the absolute focus that we've needed for so long. And that's why it's been great, the interaction between government and industry and academia has been phenomenal over the last few years. I think Australia is leading in this in this space. And other countries are looking at us with envy to say, look, are they doing it? We should do it like that. And I think that's been really, really good. We've had some great relationships with ASD, we Australian Signs Directorate and the Australian Cybersecurity Centre. And we continue to have this open conversations. And that's really helped us improve the overall security of the nation. But there's still lots more work to do. And I think that's where we all work together to get to the next step. So Cyberresilience in one of our major banks, it's a highly regulated environment. How do you kind of look at things like risk-framing, uplift and readiness and stuff like that? So from a security perspective, in my organization, any one of the organizations, we don't think about when I think about criminals or cybercriminals specifically, they don't respect boundaries, they don't respect legislation. They've got no regulated to answer to. It's very simple for them. They move fast. I lost Jason, Jason, hey, Jason, I've got a target. Your take of the cut is 20%. Are you interested? Yes or no? He says, yes, great, we go. If you say 25. I've got to talk. There's no room for negotiation. But I'll go to talk with him. Tom, are you interested? 20%. Yes or no? You'll say yes and then we go. That's it. That's a simple as it is. Actually, Tom will say 15 and I'll say 25 will balance it out. Then Tom is definitely the guy I'll be going to because I'm going to a much greater profit margin. But that's a simple as it is, right? When you come to our side, we've got lots and regulations exceptionally important. So I don't want to make it sound like I'm digging regulation anything like that. But it's exceptionally important in our world and how we have to comply to the standards that we set to protect ourselves from ourselves and also to the greater risk and threats we face out there. So it's important that we are collaborating. That's why I mentioned industry and governments collaborated greatly over the last few years. Intelligence sharing is of utmost importance. We share freely. There's no competitive advantage for me keeping it to myself. And that's been our greatest defense as a nation. And that's why we continue to do so. And when we collaborate, we multiply that impact across our different industries, different organizations. And we can respond to threats more effectively than we have in the past. Think of the DDoS attacks that we've had over the last couple of months, funny that we still talking about DDoS in 2025. But those things that are happening, we can help each other defend much faster than we had in the past. And that's really helped so I think that's how we take the resilience to the next level by helping each other to better defend our organizations because there's an old African proverb. If you want to go fast, go alone. If you want to go far, go together. And I think that's that couldn't be more true of how we are coming together as a nation on the different industries, whether you're competitive or not, to improve the overall resilience of the of the organizations you're working and the wider community at large, which is why the Suckey Act is so important on how we come together as a nation. Yeah, and I think you've made it. You raised a really good point there, Sandra, with regard to regulation. Some people can apply a regulation and be good from that sense or look good from that sense, but that doesn't mean you're secure. So having that balance between making sure that you are compliant and complicit with a regular regulation is different to being secure, right? And that you want to do that, yes. And also you want to make sure that you put other security measures in place because just doing that often is not enough that people think, well, if I do ISO 27,0001 on this framework or essentially whatever the case may be that I'm looking after security, but that's not always the case. So again, any clues on how to fill gaps or how to best look at that because we do want to be compliant and complicit where we need to be. We also want to be as secure as possible. How do you find that balance from your organization and how can we apply that as well? So the reason I was smiling is because I've got to say that compliance is a byproduct of good security. And if you do all your security controls, your basics right, you'll automatically get compliance. However, if you just tick the boxes on the compliance front, you may not necessarily be secure. So how we do it and how I've advocated over the years, it's about security and the basics. Yeah, I am 2025 still talking about something that should be relatively straightforward is the basics. Every breach that has happened over the last 20 years has come down to one one potential issue, which is the basics wasn't performed. You didn't patch your system, the privilege access wasn't where needed to be. You opened up a development access to production environment like you shouldn't have done. So all those basic controls that you would have, you were supposed to have done, you didn't do and that's why most organizations fall file to that. So we put a lot of focus and attention on those basics. And when you think of security, we've spoken about this multiple times in the past. We talk about breaks on a car or breaks on a Formula One car. I made this example last week. Oscar Capiastri can zoom down the straight in Melbourne because he knows that he can stop if he needs to at the stop on a dime because of the breaks on his Formula One car. No, he's not doing so well, like he was supposed to, like he started the season, but hopefully that will change shortly in Vegas. But I think that's where people misunderstand security, it's all about making sure the basics are done right and well. And then you can go much faster with all the other cool stuff that's coming, whether that's quantum, AI and the like. It was actually really interesting today in the mail. I got an envelope with a lovely brochure for a holiday and two scratches. Stamps from the Philippines. One of those scratches, one two hundred and eighty eight thousand US dollars. I was just kind of struck a tactile scam. I don't know why I'm here. In a world of kind of digital scams and stuff. But the conversation we had in our house is that my wife and my son, they were asking questions about this right in the very beginning before we even opened the thing. So that culture played a huge role. But you know, you spend a lot of time building security teams in NAB and other places. How much and what, how do you kind of focus on that cultural aspect in order to kind of help people move at speed because they can kind of be, you know, friction points against each other that you need that speed and agility to be able to defend against all these kind of scams coming in today. Yeah, now look, I think that's a great question. I think the challenge you have, if something is too eat, if something is too good to be true, it's definitely too good to be true. When it comes to culture, we've heard the old clichés of culture eat strategy for breakfast and blah, blah, blah, those things, it's more than just box sticking. So we don't try and tick the compliance box. Do you have it on your annual security training? Yes, tick, okay, move on. But did you actually learn something through that process? Trying to make something and training specifically around culture much more tangible for something. If you walk across the street, you look left and right, right? None of us think about breathing, but you're breathing right now. When you have to stop and think about breathing, it's like, oh, the mechanics of that, your lungs and everything going up and down on your chest, you don't think about those things, but the moment you think about it, it's like, oh, actually, that's happening. So that's where security needs to get to, especially when you're going online. It's great that you're getting the tactile scams now. They're getting old school for a reason because the new school's not working. But how we do it, we try to incorporate cyber education training into everything we do. You asked me earlier before we started recording, what is this pin? So this is just cyber security month for 2025. I get a lot of questions about it. What's that? It's like, that's exactly why I have it. I'll stand in the lift and I'll get to ask a question about it. And then it's an opportunity to talk about security. We have over 800 security champions globally at the bank. So other people in other parts of their business, not necessarily in security, to talk about it and to be our advocates and to be our promoters on security as a whole. We do lots of customer training. We've done over 50,000 customers attend our webinars that we've had. We do cyber security month. We are one of, I think, the only bank that rocks up at the cyber conference every year, like clockwork, for a good reason. People ask why are you? Yeah. It's because it's not about us. It's not about showing Navi's secure. It's about this is our contribution to the wider community. So it's understanding our wider role we play in the community and taking the conversation all the way from the top, from government through to our board, through to our CEO, all the way down to our contribution services, to my 12 year old who loves asking me questions about security every weeky, every day actually asks me the same question. So dad, any secret squirrel meetings today, and when I do say yes, like I did last week, was that meetings last week with ASD, he says, great, what can you tell me what you talked about? And I said, no, I can't. Unfortunately, not you, not security clear. And then he goes on and says, no, I can't tell you. And then that's great. And those conversations around security as the why it's important helps change the culture that it's a bunch of security people sitting in a dark room somewhere hacking away was security so much more than just that. So and making sure you can have a highly engaged workforce enables all of my workforce yet at the bank to help our customers be more secure. And there's been some great stories over the years on how some of our branch staff has stopped fraudulent activity happening at the branch where somebody may be under duress. So I think that's how we move things forward from a culture perspective. In terms of talent, I love helping young people understand and opening their avenues to learn. So bringing security as far down the food chain in the in the schooling system is exceptionally important starting at extramural activities. Like if you imagine if you were in grade 10, 11 or 12, you get an extramural activity just like you have with music or cricket or footy. And you are now learning about cyber introduction to cyber in year 10 and year 11, you learn about more advanced cyber skills like learning about Python. And in year 12, you then specialize and you do a fantastic certification or architecture or something so that when you're done with school, other than going to uni just like we would do with with trading school, you're now ready to hit the workforce really willing and able. Now you've got 10,000 students that are ready to hit the workforce without having to do anything. That significantly bolsters the cyber reservists that we ultimately would need for the future. And that's how you build your pipeline of talent. And again, security is not just about the technical components. It's very, very broad and you can come from any industry and bring that skills and learn. So it's this continuing to have this conversation and this debate and making sure that there are options and opportunities for kids change of work individuals, etc. to learn about cyber and help move the dial forward. It's an interesting topic because obviously the new legislations coming in obviously Sandra with regard to the Australian government, you know, with access to certain sites. And you raised some great points here because this is something that I've been quoted in, not just media, but with government going back to the schooling system and saying, we need to learn these skills a lot earlier. So they're great skills at the back end, but also we're throwing devices of childrens in their hands before they can even speak often. And you talked about the basics of cyber. We don't even teach the, you know, and Tom and I have banged on about the slipstop slap of cyber, you know, and making it like a car, you know, having the, having it that we've got, you know, the password is, you know, as, what do we say? It's on the password. I'll go there. The seatbelt is the multi-factor. Password is the airbag or the other way around and then, you know, updates on about what's servicing the vehicle or something. But having the kids have the knowledge a bit earlier is that we tend to be giving these devices parents in particular to children because they haven't been trained and they don't understand and they get anywhere on internet and, you know, we need to sort of bring that forward. And then exactly that too is the career pathway then at year 10 is saying, you know, what are your career opportunities here? You know, with the skill sets that sounds like your son's developing at 12 years of age, you know, they might start to say, oh, you could work in IT generally. You could maybe work in, you could be a lawyer or you could be an accountant. It's the same sort of job. They're not preparing them for the roles of what we're requiring. And, yeah, if we could sort of change that and bring that into the schooling system, it would make a big difference, wouldn't it? You know, we're like occupational health and safety's second nature. We need that with cyber security as well. Yeah. And I think it's always difficult to try and change the curriculum. That's what I learned before. So that's why doing the extramural activities much easier for me to get set up than trying to actually change the curriculum. And we've tried to do this in South Africa specifically. I managed to set up a cyber academy. I don't originally started internally, but we managed to grow and we partnered at the time with a free free university called the Maharishi Institute and took a marginalized youth through a program of education and upliftment. And that program is still running today. They've trained over a hundred kids. All of them have gotten one of the top scores in industry certifications, AWS, Microsoft, Google, Cisco, et cetera. And they both got cyber roles, whether that's an absurd in my previous company or in the multitude of organizations out there. And then we then bolt further because I firmly believe in helping marginalized youth. I firmly believe in helping our gender diversity challenges that we have. And then also whether it's neurodiverse or disabled. So when you look at blind kids, I've got a very good friend. His name is Haind Wachner and he runs an academy called the Haind Wachner Academy for the Blind at South Africa. We had a chat a couple of years ago and he said it would be great if you could take your cyber academy concept and apply to my kids at the blind school. And we did exactly that. And 15 of those kids graduated last year. Every single one of them got placed. Nobody sees their blindness. They now see skilled individual who can help them foster new avenues for cyber security, et cetera. So I think there's lots of opportunity out there. It's just the willingness to go. I can do it. Yeah. And look, if we're honest, parents give an iPad to a baby as a replacement for a dummy. So it's just happening right then. And so taking social media off kids is one thing, but there's still got devices. And if these core basic things, I think when I met Jason and I was cyber, it was one of the first conversations he had with me about this just need. And I've seen him get frustrated. It's fantastic to see all the great work that's being done. But what do we need to kind of shift this at a government and educational level? And are you talking about becoming a extra part of the curriculum? Is it challenging? And so it's like an add-on. But I mean, it's happened in our house. It hasn't happened at school with my voice. Look, everything that I've seen so far, there used to be a great academy back in the day that did this in Australia because I pre-recorded a message for one of those academies. And they were going around to different schools and showing about security. And my son actually came home. This was like three, four years ago. I saw you at school today. I said, really? I said, why? I said, oh, no, you were on a video talking about why cyber security is important as a kid when I'm playing roblox. I remember that video. And I said, oh, that's great. And that brought a smile to my face because they weren't showing those kind of things and that educational uplift. But again, it's not built into the curriculum. What I would say is let's start first with the extracurricular activity. Let's get that done first. And then we'll bold eventually getting to the curriculum because other countries around the world are starting to bring AI as mandatory learning in the classroom. Likewise with cybersecurity or cybersecurity, we should be moving at much greater pace when it comes to those new industries. Otherwise, we will be left behind as a nation. And how have you just out of interest, what can you share about tackling shadow AI at a large bank? I just recently have done some work for not for profit. And one of the first things they wanted was some processes, a training program. They sat there for a while. And then I just watched everyone use their own personal free AI's in the background as I wandered around the office. So they had the idea that they needed to do this. But then they were just unable to kind of, even with the processes and plans and training. There was just not the will to do it. How do you make that challenge at a bank? Yeah, so look, the fortunate thing is, so I'll say this, AI is great. It's exciting. It's also scary. It's a double-edged sword. So we are very fortunate in that we've been here before, something called the cloud, right? 10, 15 years ago, cloud came out and it just exploded. Everybody would whoop at a credit card, set up their own tenant and then just start doing things because it was quicker to do that and get your kit up and running then ordering your your your hardware from a dollar and HP, etc. Waiting for the kit to be delivered and then setting up, etc. And what we learn through that experience to what we're applying to AI now is that if we don't give them a safe and secure environment to operate in, they're going to go and do it on their own. So have that pragmatic conversation up front and that's exactly what we've done. So when this Gen AI thing exploded, we did exactly that. We put guardrails in place right in the beginning that these are the safe ways to use AI in the organization and then take it from there. We've got AI we have an AI governance forum which security and privacy is an integral part of and everybody goes down that journey. And the most important thing out of everything is basic hygienism of the utmost importance. So you can do what you want, provided you've patched your systems, you've backed up, you've got your privileged access sorted, your access control is working, all the normal things. And if that's done, then yeah, we can safely use AI for the ones that we can control and we block the rest. So that's essentially our weave approach this so that we can make sure that we are still giving our developers, our rest of our colleagues a competitive advantage and a competitive edge, but by doing so safely and securely. I'm interested to in your views on the impact on AI, both on cybersecurity products and also on the bad actors using it. I think 2024 when we were at RSA was agents 2025 was agentic. And both of those conversations almost seemed ahead of the reality, you know, there's Jason so a lot of wrappers around just LLMs and stuff like that. So how do you see that impacting and then you know potentially also moving on and thinking about quantum coming down the barrel as well? So as I mentioned before, look from a basic perspective, if you add the basics right, you'll defend against most of these things. So quantum is coming down the pipeline, make sure you've got quantum resistant cypher's in place. That's the only defense we have. Any of us have right now. AI, the same thing. If your basics is applied correctly, you're in a much better position than most people. So those are the two key things. In terms of how we use it and how we are using it to defend ourselves is exactly the same with the bad actors would. We've had a challenge. I've set up a challenge and an immersion day for for my team to say bring bring out all the cool stuff that you've been building on side of desk at home on weekends on public holidays and come in showcase it. And some of the stuff that's been coming through is for absolutely phenomenal on how we can actually defend the organization. The challenge you have now is bringing that same energy, innovation, etc. to the organization and using our current platforms around AI, etc. and applying that to what the teams have built. And so far we have some good success that we have and hopefully in the future we can share some more about that. But that's how you have to do it. You have to make sure you're building a very good sandpit, really good security guardrails that everybody can play within. And that's what I will say that you can have any color of security you would like as long as it's blue. You can have shades of blue, light blue, dark blue, whatever as long as it's blue. And that way I've got the guardrails. Everybody knows that they can play around in that. The moment they need to go outside of that, that's when they can have a conversation with the security team. And so actually I'm trying to do A, B, and C. The controls of the policies are not fit for what I'm trying to do. Can we look at a better way of doing it? That helps me and my team also to uplift ourselves to say actually there is a better way to do it. We may need to adjust the policy accordingly. But that's a much different conversation than before when somebody was just paying for a new tenant in AWS on their credit card. So that's the conversation we are trying to have. And that's an interesting one isn't and trying to be innovative within the bank is often a challenge as well, isn't it? Is allowing within such a secure environment with so many people using it customers and both customers and internally, tens of thousands of people from an internal point of view and then hundreds of thousands external of that or millions of customers in the case. With you guys, how do you keep that balance to have the innovation and the look forward and how do you apply that and how do you access tools or look at tools and say that they should come into the system? What do you know on your roadmap going forward that you're looking for and how you're filling those gaps at the moment? Because as you say, Sandra, things are changing so quickly. It's sort of, I can imagine it being quite challenging but from sitting in your seat, how are you assessing that at the moment? So look, the good thing is we are all technologists at heart and I think that helps and we have very ambitious leadership, which is fantastic because I'm a very ambitious individual and I want to move things forward as fast as possible and give the teams the freedom to operate within those boundaries of control without losing it. So like I said, if they want to, if they find something that's out there that we haven't even considered, we invite them to come and talk to us and they do that all the time so that we can raise our overall security posture but also not allow them to go as fast as possible and they know that security is not a blocker. It's actually an enable to the business and because of that, they can move as fast as they can. In terms of the wider ecosystem, developers will be having different conversations to what the architects would be having and so on and so forth and we come together to have those conversations so we can work together to move things forward faster and having those brown bag lunch and learn sessions, whatever you want to call it, that's how we also improve our collective knowledge. I think the last thing is we spend a lot of money on training in terms of providing access to whether it's you to me or plural side to whatever the case may be, where people go and can learn and we are a massive advocate of always be learning. It's exceptionally important so that's what we hope the teams to understand so that they can better educate themselves. What do you see as this next phase, just in a more general sense and probably not so bank-specific? From a security point of view, Tom mentioned previously about how on the attacking side they're using AI quite collaboratively but besides that, what else do you say and you did touch on quantum, but how do you say this next period up to say 2030 or next four or five years? What are you sort of seeing as the main transitions or things we should be looking out for or trying to adjust for it realistically? I think some of the things that's already started happening is have you ever found a bad fishing email in your inbox recently? Probably not because it's all AI and Hans, all generated, it looks perfect, it's very difficult to detect so that's going to continue. Deep fake social engineering is definitely coming to the fall. Using AI to to doctor official documents, if there's no verified ID check on the back end of that, we just do it on face value, you can't really tell the difference so that's going to come through and we've seen that with North Korean IT worker challenge globally. That's synthetic identity generation, that's been an issue and then influence and disinfluence campaigns are going to come to the fall as elections come up and so on and so forth. So those are the main key challenges that we see. We're going to see attacks that are going to be just go at the other end of the scale from exponential growth and attack perspective, but with all those negative things, I think we were at a great crossroads for the blue teams and the defenders on the white hats to equally move as fast and defend us against those kind of attacks and I always use this analogy, it's too super compute is playing chess against each other. I think two Magnus calls since playing chess against each other, they'll probably cancel each other out because I think that's where we will get to and we just need to continue to stay ahead of the curve. Always be learning, exceptionally important, stick to the basics and communicate with each other. It's probably the three most fundamental tips that I could give anybody, keep those open lines of communication because we sometimes as people we forget communications actually vitally important because you'll have two people working on the same problem sitting next to each other and they never talk to each other until four, five, six hours later in the incident and then they'll just glance at each other's screens or say something and it's like, oh, I fixed that problem five hours ago. Why don't you say anything? That type of thing. So that's over the years that that has happened. So that's I think where some of the challenges can be staved off if we just start communicating better than we have in the past. And what do you do outside of cyber? And I know that you get quoted in books and David will love me for popping the book. There's a little plug there. And we do have Sandro's lovely face on here and actually inside the book as well. But what are you doing from a, you know, I know when we spoke to Dan Mezzlin, he's big into F45 and you know, say he's really, he's adjusted his life. I know you're a professional powerlifter and stuff like that. You know that a lot of people wouldn't realize Sandro, but what are you doing like from a reading point of view or relaxation point of view or a hobby point of view that you can sometimes bring some of those things outside because sometimes we do get stuck in our little little cyber bubble or cyber world. But often we learn a lot more from from outside of it. And you've quoted some really good quotes during this talk. And I think and Tom, he's favorite one got pulled up there as well that he'll be loving that you did. Yeah, that's he's that's he's catch power up. But what is it that you're doing outside that you find really helps you internally because you're dealing with a lot of people. You've got a large direct team and then you've got, you know, the to deal with boards and you've got to deal with you've got family stuff. You've got so many different hats you have to wear. How do you as a person sort of manager like that? That's of interest to us and obviously our audience as well. How are you? Because you know, looking at a role that you have at such a large institution, there's a lot of pressure there, but also you've got to be a dad and you've got to be a husband, you've got to be all the different things and hats. So what do you do to actually keep on top for that? So a couple of things, right? So I'm really just I go to church. I have a strong faith-based moral center and that helps and that drives everything in my life. Family is always first and then work because work will replace me tomorrow, but my family can't. So I have a strong family belief. Yeah, my family has tried a few times, haven't been able to. So that's true. I drop my son off every day at school. That's the time that I can carve out of my day to drop him at school, catch up with him, to the Finland and journey to school, but it's probably the best time that you can get to spend trying to get quality conversations, to get the car. Locked in the car. Yeah, locked in the car, driving the 40-50 kilometers an hour, he can't drop. So I think and those are their great great conversations. So I try to keep that time safe. I try to lock my time away between 6 p.m. and 8 p.m. So that's family time. I've tried to have dinner on the dinner table and I have catch up about the day and then I can always get back online late at night. So those are the things I keep I keep sacred. I love giving back. So there's lots of mentorship stuff that I do just to help young kids or whatever the case may be. I do a lot of work still inside Africa with with non-profit organizations just to give back as much as I can and do some guidance, etc. And then I try very badly, very poorly to try and exercise. I need to continue to keep that. That's the only way I can get get through all of this. People ask me the favorite question I keep getting is how do you sleep at night doing what I do? And I love what I do. To me, this is not a job. This is I don't want to say a calling, but I love absolutely love what I do. I don't see it as work. And which is why it's very difficult to try and separate work and home life. So you have to find a balance. There's no such thing as a work life balance, but you need to find balance regardless. So I'll exercise and I love playing badminton. So those are the three couple of things that I do and spend a lot of time with the family. But for the most part, I don't take life too seriously. I've had tragedy very early on in my life, which just taught me resilience that I use in my day today. I lost my first wife when I was 25. She had cancer. And I had one of two ways I could have gone. I could have gone, oh, woe is me? Why has this happened to me? Or I could lean into my faith and lean into the I've got two young kids to support. Just buck up and suck it up and move forward. And that's what I've done. And that's helped me be the type of person I am today. So when people say, oh, you don't get stressed, you don't. Why are you so calm in a difficult situation? It's because nothing's going to compare to that. So with those things, that's how I've managed to be successful in what I do right now. And the book. That was good. And yeah, the book, that's what I was going to say with David. But the book that's David nagging me for a long time. He died a whole day. He's a good nag. He is. He's very good at that. But it was great to just collectively dump my knowledge and then try and craft it to hopefully something that some one person on the planet will find useful. Yeah, now we appreciate sharing that and being vulnerable because it's important to know because I think people do sometimes look at the top and think people are super, super human and all those sorts of things. And we all feel and feel the same thing. And it's good that you're sharing, you know, that your faith has been something you've been able to lean back on as well. And I think something you said earlier about. And I think that's why cyber has sort of I caught that bug too is almost like emergency services or medical people, you want to really be there for the greater good and help people and protect them from the cancer that you sort of mentioned for, which is in some way cyber security, you know, a cancer online in a way in the way that attacks people and takes people in many ways. You know, not just in financial sense. There are people that have been in cyber attacks and actually taking their own lives and things of that nature as well. So there's a lot of things that happen up there, Sandra behind the scenes that a lot of people don't realize the impacts of what happens with these online crimes. And the fact that you're leading the way, I think I'm a nab customer in part as well. So you know, that thankful when you meet the leaders who look after you, you know, and you feel a lot safer from actually meeting someone who's actually trying to protect your interests, you know, whether it be online or other ways. So yeah, I really thank you for sharing that because that's that's a hard thing to sort of talk about. But it's also something that I think people need to realize is that, you know, we are all human beings behind the computers and in these roles and that needs to be understood. So the fact you cover that time for your kids and you've sort of spoken about them so glommingly is something we appreciate in here as well. So, you know, besides cyber stuff, thank you for sharing that. The last thing that I'll add is none of this is possible without a strong partner. So I did remarry and I've been married for almost 20 years now. My wife, I think this before, my current wife, my wife, she's been a phenomenal rock and and source of strength and, you know, pillar of guidance because your wife and your, you know, you're better off as always the person that tells you don't be dumb, don't do this, don't do that, et cetera. And you don't listen initially, you start your toe and you realize, oh, I should have listened. So she's, she's been phenomenal in helping me be successful and try to stay grounded. And I think there's none of what I am is possible without her. So I'll just send that. Good news to her. Yeah, excellent. Thank you for that. Tell me if you got another question I sort of took us down different path, but I love to kind of steer back here. You mentioned North Korea and IT workers, but I think it's a really interesting challenge now. We've got these globally diverse dispersed work courses. And I remember speaking to another cybersecurity leader a few months ago, and she was telling me how she's trying to go and encourage everyone to get all the managers and leaders to actually get in the room with their staff around this idea of insider threats. So, I mean, how do you kind of handle that? In some ways, it's a simple solution in NAB or is it, yeah, I'm just curious because you know, lo and behold, you discovered this person is a North Korean IT worker. It's not just NAB. It's global. Microsoft, where there are 300,000 people had this problem. Everybody's going to have this problem. So it's not just NAB. It's it's it's it's it's everywhere. You hit the nail on the head. It's about knowing your people, right? How many times? Because you have to rely on your leaders to know who's working for them. And if you're a leader that doesn't know the people working for you, there's a bigger problem that you need to go and solve for return to the office, which is a very visceral topic. I mean, nobody wants every time you bring this up, it's like, no, no, no, I need to work three days from home. I need hybrid. I need coming back to the office is actually exceptionally important to understand who's working with you. Will you working with? Not just for that. Just for collaboration in general. But we will be fortunate to organize it at the back. We have a hybrid work policy. The difference is we make sure that video is always on. It's important. And then when it comes to the insider risk, making sure your probity, how many times is you as a CSO or CSO thought about probity? Oh no, that's a people in culture issue. You should worry about that. But from an insider perspective is that have you checked the passport details that were sent through? Have you only visually checked it? Or actually have you confirmed it and verified that the picture on there matches the picture you see, that the name, etc. So all those little components at 100 point check is actually exceptionally important. And then how do you go down to your third, fourth, fifth, sixth parties that must do the same thing? Because what you'll find is people I'm looking for somebody. I'll go to a third party who doesn't have the person. But they'll say, yeah, yeah, we'll get it for you. And then they go to their third party who goes to the fourth part, etc. And then eventually you hire somebody which you thought is the person. It was Jason, but it's actually Tom. And that's where you know that was Texas. You know what that was. I think that's it just completely depends. And this is just like we work together much better now at an industry level with government, etc. Your own internal divisions need to work closer together. Whether it's your people and culture business, your security business, your tech business, business itself all needs to work closer together so that you can stop this incoming threat that we are now faced with. And there was an extra step to that. We had a Canadian police officer who's based in Australia as a cybersecurity expert in cybersecurity, chasing down cases. And he was actually talking about a case study in Canada. And he said one of the things is that you're not actually often sitting in the room and asking them, you know, why have you got this job? What is your motivation for being here? And that answer can often be an incredibly telling way of uncovering someone that, you know, maybe isn't there for the right reasons as well. So do you kind of see that happening as well as the kind of identification piece? Physical security is exceptionally important. So how often have you, when have you ever challenged you to ask you, hey, I haven't seen you before, no, where's your badge? It's in your policies. You've been wearing your lanyard in your badge. That's it. That's in our policy. So if you don't have one, it's like, I get to ask the question, sorry, it doesn't matter who I am. I get asked the question, oh, sorry, can I see your badge, etc. And I'll show it to them. Those little, little, since checkpoints is very, very, very important to help the broader security ecosystem now. It depends on where you are in the world because some cultures doesn't like the challenge, etc. It feels like it's you offending them. But again, you just have to weave your policy around those distinct differences and culture. But yeah, it's important to check faces, names, etc. badges. It's a part of your defense overall strength and depth strategy. I think that has been a weakness in the past. I think Australia too being very, very trusting and very friendly will shoulder surfing or people just opening a door for someone who may be carrying a ladder. Looks like they're going to be doing some work and just letting them come straight through the office, you know, and into the cupboards and doing all the different things. So yeah, it's a, it is something that, yeah, when we look at security, when people get pen testing done, sometimes they'd pull up proof online, but it's as easy as just sliding through into the office. Yeah, yeah, yeah, correct. So yeah, I think, look, I love what you covered. I know we're sort of coming up to time here, but yeah, we've really appreciated and thank you for coming on as, as number 50, the 50th guests. I'm super surprised that Tom didn't organize those blooms in the background or anything for you, Sandra. I'm sorry. This isn't your background. Yeah, it's a great background. I'm sure you can do lots with it. Yeah, well, a lot of the superimpose something in there. So Tom's an expert on Riverside FM now. So I'm sure you'll be able to make something done, but I really appreciate it, and I really appreciate how open you've been, the work that you've done in industry and and keep up the fantastic work you're doing here and overseas as well, because you know, it is appreciated, and yeah, we just want to thank you wholeheartedly for everything you're doing, and keep up the great work. And hopefully you do get a little break over Christmas, and there are no silly little cyber criminals trying to bust into the system where we've got, yeah, less of a team running through Australia. This seems to be the time we get targeted, you know, like and all. There seems to be some sort of little, little hiccup that happens, you know, just before Christmas. So hopefully we, uh, log for Jay's, uh, log for Jay's exactly what I was thinking back in my head, when I was saying that. And, uh, you know, let's just hope we don't get those gifts for this Christmas. Yeah, well, I thought a good sorry on log for Jay when that came out. It was two weeks before Christmas. Yeah. And I was the one that I did decide whether everybody gets a Christmas break or not. Fortunately, we managed to get everything sorted before the Christmas break. So I didn't have to turn into the Grinch, uh, but yeah, now those, that's his Christmas Easter, all the big holiday periods. Yeah, it's always. Yeah, we do get tired of it. So, yeah, keep on your toes gang out there. Um, made all the best for the, the festive season, which you married Christmas and all the best for 2020. Thank you for everything. I'm sure we'll cross paths. It's good. Uh, appreciate it, mate. Thank you. Yeah, thanks for sharing all those stories. And look, listeners, you can find Sandra on LinkedIn. Every time you're at using your Nav account, you can be confident that, you know, he's got everything working in the background, all the security sort of outside. Thank you so much for joining us. Thank you, Jason, as always. Thanks, aye. Thanks. Thanks, bye. [Music]

Podcast Summary

Key Points:

  1. Sandra Bookian Airy, Chief Security Officer at National Australian Bank, has extensive experience in global financial institutions and advisory roles.
  2. Sandra emphasizes the importance of collaboration and information sharing in the security community.
  3. She highlights the significance of focusing on foundational security measures and building a strong security culture within organizations.

Summary:

Sandra Bookian Airy, the Chief Security Officer at National Australian Bank, shared insights on her extensive career in security, emphasizing the importance of collaboration and information sharing within the security community. She stressed the significance of prioritizing foundational security measures to ensure compliance and enhance overall security posture. Sandra also highlighted the essential role of building a strong security culture within organizations through continuous education and engagement with employees at all levels.

Additionally, she discussed the need for promoting cybersecurity education from a young age to develop a talent pipeline for the future workforce. Sandra's holistic approach to security underscores the importance of addressing both technical and cultural aspects to enhance cyber resilience and protect organizations effectively.

FAQs

Sandra's interest in security was sparked at a young age when she witnessed a robbery and felt the desire to protect people from harm.

Sandra's journey in security has taken her across multiple countries and continents, eventually leading her to become the Chief Security Officer at the biggest business bank in Australia.

Sandra highlights the importance of collaboration in the security community, mentioning relationships with other institutions globally and the sharing of threat intelligence to enhance overall security.

Sandra views compliance as a byproduct of good security practices. She emphasizes the importance of focusing on security basics to ensure compliance and security.

Sandra focuses on incorporating cyber education into everyday activities, engaging employees as security champions, providing customer training, and starting cybersecurity education at a young age to build a strong security culture.

Sandra sees a crucial role for young people in cybersecurity and advocates for integrating cybersecurity education into school curriculums to build a pipeline of talented individuals for the future of cybersecurity.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.