Go back

Santiago Aragón - You try, you fail, you try again

53m 47s

Santiago Aragón - You try, you fail, you try again

In this episode of Cyberscirty Talks, host Lawrence and co-host Bruno interview Santiago Aragón, a 30-year-old tech lead at X-Ving with a rich background in cybersecurity. Santiago recounts his path from studying telematics in Mexico to pursuing a master's in cybersecurity in Europe, where he initially focused on theoretical cryptography in academia before transitioning to industry for its faster pace and complexity. He highlights that cybersecurity is a game of effort and money, where both defenders and attackers optimize their resources. When asked about hacking, Santiago explains that cybercriminals target organizations based on their capabilities and potential profit, with ransomware being a common tool for targeted attacks. He also touches on cryptocurrency security, noting that protections typically emerge after significant problems arise. The conversation shifts to organized cybercrime, with Santiago acknowledging that professional groups like mafias and cartels are now heavily involved, as they naturally innovate into illegal sectors. Throughout, Santiago stresses the value of a university education for developing problem-solving frameworks, despite its limitations in preparing for corporate dynamics. He concludes by emphasizing the growing importance of cybersecurity for individuals as digital perimeters expand beyond traditional institutions like banks.

Transcription

7739 Words, 41609 Characters

English
This is Lawrence and Bruno and welcome to Cyberscirty Talks. The interview podcast for Cyberscirty professionals and for those who aspire to become one. My name is Laosha and with me is my co-host Bruno Leinborg. Together we interview industry experts and explore what it's like to work in Cyberscirty domain. Join us on our journey and listen to our bi-weekly episodes and learn about latest trends, real-life horror stories and everything you need to know about this fascinating industry. Welcome back to another episode of Cyberscirty Talks. And let me introduce you to our next guest, Nobody Less than Santiago Aragón. Over the past years he has traveled and worked in different countries. He's the author of some well-known industry publications. He wasn't invited to speak in China and he's currently working as a tech lead at X-Ving. When you hear all this, you probably think he's close to getting retired. But no way. He's just 30 years old. I'm super excited to do a whole lot more. So get ready, buckle up as we're going to have an exciting episode where we will talk about the start of his career. What he would do if he would be a hacker and why Cyberscirty will have an impact on all of our lives. Today we have the honour of having Santiago Aragón with us. Welcome to Cyberscirty Talks. On your LinkedIn it says "Talk to me about technology, cybersecurity, entrepreneurship and business strategy." But first I would like to ask you some short questions and have your opinion or your thoughts. What do you need to know about me? What meal do you start your day with? Well thanks for the invite first of all. I'm very honored to be here. I'm directly into the first answer then. My first meal of the day. Coffee. Always. Just coffee. Just coffee. Okay. Android or iOS? iOS. What is your favourite phone app? Lately I'm a lot into home automation. So I'm trying to make a lot of things efficient. So I have a couple of meters that tell me efficiency gains and changes of trends. So I will go for them. Cool. Work from home. Office or a mix? I think it's a mix for me lately. My gig parts as a work from home. I actually build a very nice office/stream now. And I enjoy a lot to be there. There is a lot of focus time. I have blackboard behind me. But at the end of the day, I think business is done between people. And a lot of great ideas and spark of new crazy things is done. Well, we have these kind of chats. So I also enjoy a lot of human contact. Are you a gamer? I was. Not anymore. I used to have a roommate. She was allowed into call of duty. I tried to get back, but I think I'm too old. That's too old. What is the oldest appliance in your home? Well, all these relatives, I would say. I don't think there are that many old gadgets. I think all these appliance will be a fridge that came with my flat. That cannot really enough connect it to my Wi-Fi. That's right. That's right. Laptop desktop server or virtual machine? It depends for what? For my personal stuff. I always do laptop. Actually, I try to move to iPad because I can draw a lot that helps me to visualize and to get my creativity flowing. For when there is some coding need, I definitely go for my laptop with a big screen. A virtual machine when we need to do some cyber security crisis stuff that needs to stay there. So crazy stuff. Let's get into it later. Tell us about a guilty pleasure of yours. I don't believe in guilty pleasures. I'm very proud of all my pleasures. If you ask for a weird one, I would say lately big data and artificial intelligence. Cloud or on-prem? Cloud. What is the first word that comes to mind when I say cyber security? Me being ages old and saying to my dad, I want to be a hacker. Can you tell us what your password for your email is? Of course. 1-3-4-DUT. I'll try that after the recording. The beginnings. So the algorithm is super excited to have you. Thanks for joining us on the show. We were introduced by a mutual friend and she said you were one of the most brilliant security professionals that she knows. However, she also mentioned you are a big mess call connoisseur. Is this correct? I don't think she knows a lot of cyber security professionals. Thanks for the compliment. I love my school. That's true. I actually went a couple of weeks ago, I think more like a month back to Mexico. I was visiting with my girlfriend and my family Palenque. That is where you actually produced my school. So we went through a my school cat of 13 different my school was fun activity. Santiago, if I would run into you in the elevator, besides you telling me your mess call connoisseur, what else do I need to know about you and your impressive career so far? Hi Lawrence, nice to meet you. I am Santiago. I am actually 30 years old. Some people say young, some people say old. I don't know. I'm just 30 years old. I grew up in Mexico. So 21 years of my life, I spend them in Mexico City. And in the last nine, I have lived in seven different cities. Actually, Mexico City plus six European cities. I studied engineering. Then I went into a master's of cyber security, privacy and innovation. I have an entrepreneurial heart. I love cyber security and tech. Currently I am platform tech lead for crossing. I think there is a scale up slash startup that is trying to change how software is developed in the financial industry. Amazing. Very exciting to have you on the show. Welcome. Thank you. Before we jump in a more serious part of the podcast, could you quickly walk us through your career up on this point? Well, I'm a bit old, so that's going to take some time. But I can start very high level. So I am a telematic engineer. My first education was into telematics. So what is that? A lot of people ask. It's not telepathy. It's not any other magical artifact. It's just the intersection of telecommunications and informatics. When I decided to jump into telematics was already because I don't want to be a hacker anymore, but I want to be a good hacker. So I decided to study something that could allow me to enter into the cyber security world. And for me, back then, cyber security was about communications and was about informatics. So for me, it was a good click. In my four years of engineering, I actually find a scholarship to go to Germany. I decided to go there for a year to Sarland University. Some people will consider this one of the best cyber security universities in Europe and some other in the world. But that's for the rankings. There, I actually start with theoretical cryptography. So I spent a year doing theoretical cryptography courses. Really weird mathematical stuff. And at that point, I was about to say, "Okay, I'm actually not going to go back to Mexico." I was writing a paper with one professor there and he said, "Yeah, why do you want to go back if you like it so much here?" I said, "Well, those make sense, right? Let's start my bachelor from scratch again." That was not well perceived back there in Mexico. So I actually went back. So my habit of the analysis of my friends and my family was, "You are one year before graduation of engineering." Come back, close it and then go. So that's what I did. I went back to Mexico. I started my thesis. And at the same time, I started a small company with a couple of friends. Very young, my co-founders were two of the most clever people I ever met, I think. But we still kind of missed the size of what we were doing. I think undersold a couple of projects. And then everyone started to have another kind of ambitions. So I went to the top five for a PhD in Berlin. I was waiting until the department got some budget for a new student. And in the meanwhile, I got this scholarship to come for cyber security privacy and innovation. It was masters that I ended up doing in a lot of universities. At that point, I was, well, a couple of years ago. years forward in my career. I was about to graduate from my cyber security privacy and innovation degree, a really fancy name for what it actually is. Well then the question was do you want to stay in the academia or not? The academia was a lot of what I knew by then, so I had around I believe seven years of studying universities and doing research. That's also an interesting choice because you mentioned that you went from wanting to be a good hacker to now joining the dark side again. So there's a difference in looking at the profession maybe that you want to join or be part of. Yeah, in my eyes academia was about the pure knowledge and the love of knowledge by itself. You basically do research because you love knowledge and you want to know more and you want to go forward in the state of the art technologies and methods, etc. That is one of the reasons I actually decided to go to the industry because the more I asked, the more I realized that was a platonic idea of myself rather than the truth. I always enjoy the speed of development that I will have between years or between jumps, professional or personal doesn't matter. So I like how fast I can become better. In the academia was also something that would not be for me satisfying in that sense. Even when you are talking about innovation and the state of the art, in general, the field, I think there is a lot of things that move very slow. So I decided to go to the industry. The dark side as Michael is will tell me back then, it's not the dark side, it's just it has different optimization functions if you would like to think about it. So in the academia, you don't necessarily need to make money in the industry you do. And you have end users and you have a couple of things that you need to always think before making a decision that makes things and decisions more complex and I like complexity. So, and was it difficult to switch from the academic world to the business side where a lot of companies interested in your background? That's a good question actually. I think this is something that every university graduate will say, you know, I study theoretical cryptography for one, two years or I did calculus for three years and I know how to derivate or integrate the most complex function I have ever seen. Then I got to my work and you know, I used 10% of that. How do you put it into practice? Yeah, how do you put it into practice? And the more I go forward in my career, I actually realize that what you learn in university, it has value in different ways. Not necessarily in the content always, right? But it university gives you a frame of thought and it gives you the chance to understand that if there is a problem that you can frame in words or in any semantic, right? It can be maths, it can be IT, it can be data structures, it can be maybe logical statements, you can solve it, right? So, the jump was big on the people's side because university doesn't prepare you to deal with hierarchies to deal with reasons because it's a corporate strategy or because you need to do it because somebody else said it. Okay, and I want to go back quickly to the young Santiago, because what was it like for you growing up in Mexico? Because you're now only 30 years old and you already worked and lived in Germany, Sweden, Poland, Singapore, and now the last four years in Amsterdam. But you were born and raised in Mexico, but what was it like growing up there? Well, it was 20 years, 21 years of a very happy life, I think. It is a big city. So, that's one of the biggest difference with Europe and Mexico or Europe and maybe the rest of the world. Cities are very condensed here, very small, makes the city and their metropolitan area is 25 plus minus million people, right? So, dynamics a lot of dynamics are about scale, right? And when you have 25 million people moving around, having dreams and stress and rush, right? It's a bit different. That's actually something good for my cybersecurity skillset. I think that I learned to be aware from very young in my life. So, I learned that you need to double check who is in your right, who is in your left. And I also learned that there are certain institutions that give you safety, right? Like your family, your friends, and that's also something very important in at least in Mexican society. Yeah. And did you grow up in an international environment? Was it always pushed like this? Is the dream? You can also work abroad. No, actually, I didn't know anyone that moved abroad, right? You have people that go to the United States, right? And you have of course low-skilled migrants that go there, but also high-skilled migrants. So, there is especially from good university in Mexico, there is a lot of work for it going to the US because there are better chances there. Yeah. And how was it then for your parents when you sort of drop the bomb? Okay, I want to move to Germany. I think at mixed feelings, so they always support all my dreams. They always said, you know, you need to go where your heart tells you to go and where you can do the best out of it. I think they never thought that would bring me to Germany. So, there was a big bomb for my mom, especially in the first years. But then they got used to it. And I was it for you, like you're probably still a teenager or close to 20 and then you go to the airport with just a suitcase and then you have to go to the other side of the Atlantic. How were you feeling? I always, my mom always tells me this story when I was going to cure in the garden for the first day, first time. I just took my small lunch box and I went down of the car and I went straight into the door. I didn't even say goodbye. My mom was crying and I think I took the same approach when I went to Germany. So, I look back. No, I don't look back. I take a decision and I go for it. Sometimes you figure out, okay, maybe I should have done it differently or not. But that's also what helped me to fail fast and learn a lot. If I would be a hacker. And to hit you with a trick question, if you would be a hacker, which country would you target? Or maybe if you say it doesn't differ much from country to country, but from company size, what do you think is the sweet spot for hackers to target a company? Like banks are maybe impossible to penetrate through. Talking about why I learned university, right? I think one of the most interesting courses I had is the Economics of Cybersecurity in the 20th University. For me, it sounds really fancy. That's the reason why I took it. But then, at the end, this really helped me to understand cyber security as a business also. And both sides of cybersecurity, bad guys and the good guys. And it's a game of effort and money. In the good side, you don't want to put more effort or money than the value of the things that you are protecting or the impact of something wrong, of something that goes wrong will have, right? For example, reputation damage. I will never put a $10,000 billion security program on a website of a single month person. It doesn't make sense. On the other side, the bad guys are also very clever, right? So, they aim high, of course. They aim high, but they will aim for the best company that they can target with the resources. So hackers and all these cyber criminals are just businessmen, right? Of course, not necessarily the technical hacker in a hoodie, but cyber criminals as a group, right? They will target the ones that they can target with the tools they have, right? So, if you tell me I am leading a 10-month cyber criminal operation, and They are, for example, a really good Chinese hackers or Russians hackers. I might be able to target a big company, right? And what big? The ones that will make me the bigger profit. >> Yeah. >> And maybe then a follow-up question on that. Would you say that you would be applying ransomware to maybe get the money that you'd be after or would there be a different approach that you would maybe use? >> It's the question between B2B and B2C, right? So one of the questions is, do I want to go for a scale or for targeted attacks? They give you different returns. For example, the typical scam. I'm a prince from Nigeria and I need to take out X amount of money. Please put some money in my bank. That goes for a scale, right? So what's my effort to send an email close to nothing? If I want to go to a targeted attack, then I will definitely do ransomware. I think that as an industry, there are a lot of challenges there that we have to be able to defend from targeted ransomware attacks. And maybe I will do some mining of crypto in some distributed way, I don't know. That seems a very vulnerable industry. I think it's very interesting to target there. You see this crazy hex that a lot of bitcoins are disappearing. From an financial institution perspective, what's your take on that? On the cryptocurrencies and how safe are these mining facilities? Well, that's a very tricky question, Lawrence. I cannot say about from a financial institution perspective, because I think I and you have their own policies around the position of a run crypto, right? What I can tell you is what I know in the personal level of mining facilities and wallets that are also very popular now and how is that progressing? I think as any technology moves faster than regulation, right? And what we are seeing is a different way in which we can move money, right, or something that we consider to have some value. And just as bank accounts and all the stores of value that we had, all the protections came afterwards. Why do we have bills that cannot be just putting a copy machine and duplicate it? Well, because there are some technology that forbids you to do that. Why? Because maybe it happened a couple of times and we don't want it to happen again. Until we start seeing that there is an actual problem there and it's evident and so painful for big amount of people to put some constraints. I think we will see some actions because if you are interpreting more in Bitcoin, maybe to make it 100% secure is not one of your first objectives. Maybe it should, right? But maybe you are into another things that depends on the entrepreneur. Yeah, because it could be that investors are still reluctant to buy cryptocurrencies because there's always that safety issue. Even though you have a wallet, you can still open your account one day and poof, everything's gone. You can argue the same with a lot of stores of value, I think. Yeah, maybe. That's one nice connection to why it's important for us to have a good cybersecurity understanding, not necessarily as businesses but also as individuals. If we are moving into digital and a lot of this digital perimeter is not anymore in extremely well-guarded institutions like banks, right? Then you need starting about, oh, I am storing my wallet in my laptop. Is my laptop a secure place to store my wallet? I don't know. You could say the same. What if your bank will give you the chance to store your money in your laptop? Will you store it there? Yeah, so it's also the responsibility of us individuals. Yeah, and I want to jump back to these more organized criminal institutions because we've also been organizing webinars for cybersecurity talks during COVID. And then one of our guests, he negotiates with hackers about ransomware. And he said that lately they see they've just been dealing with really big professional organized clans such as the Italian mafia or the Mexican drug cartels. But he said that's really scary because they're so professional, they're really capable of what they're doing. What's your point on that? Well, criminals and mayfias, they are going to be there. Because they innovate as well. This is probably a good way to. I really believe they are businessmen in the legal sector. So we as a society decided that these three sectors are legal. These 80 sectors are illegal. And I do agree with that, by the way, just for the record. But when we legalize a sector, they will jump to the next one because they are not into legal businesses, they're into illegal businesses. And Cyber Mafia is one of the things that are illegal. For example, ransomware attacks is. I don't know if you have the chance to go into the dark web, I'm sure you did, because you are also almost a hacker. You can get. Comments. You can get very good client service on the NL of service attacks. So I want to bring down your website, because I have a competitor, business. I want to recruit more cyber security professionals in you. Well, I know that one of your assets is your reputation. And it will not be nice to have you down for a couple of weeks. Well, I go to the dark web, I get a DOS attack. These guys have 24/7 customer service. They have cashbacks. They have cash guarantees. If you are not satisfied with the result, you get your money back. So that's the level of professionality you have on these kind of things. And this is a very. This is one that is really in the service, right? But you can think about this level of professionality in each of the sectors of cyber criminals, right? So the people that long-term money, the people that take out money from the ATMs, the people that steal credit cards, the people that work for new exploits to get the ransomware in, the people that develop ransomware. They are all very. Plus, they are very detailed into what they do. They have very well-defined interfaces, and they cash for what they actually provide in the value chain, right? And then you have the cartels or the organizations that are the ones that organize. That's why they are called organizations. All these tiny pieces and bits. So the professionality you will see is extremely high, right? It's a very well-developed business. It has been running for years, and it will be running for a couple of other hundred years, I think. So we need to start thinking that we are not dealing with a guy in a black hoodie sitting in a remote place trying to steal our money. We are dealing with organizations that know how to do business. They know how to extract value, and they are targeting certain weak points that we have as an organization or society to get what they want. The tricky part is also they seem to be very successful because these organizations are growing and growing. Are we losing the war? I think it's an infinite game, right? So there is this concept of finite and infinite games in game theory. If you perceive it as a finite one, you are always going to lose, right? I think that as an industry and as a society, we need to perceive it as an infinite game where the aggregate of results should be positive on our side. There will always be battles that we win and we lose. The battles that you win, you cannot see them. So you will never be claiming the news. You know, Lawrence, you got the best ever security professionals. That's why we didn't get hacked. But you working for financial institution, I think you guys should be in a position that you also see that you prevent a lot of bad things from happening. Of course. You left maybe the celebrations. You don't disclose those. No, I get it. I think that One of the interesting of CyberSec is a very dynamic industry. So you will never see an attempt of a 100 record state bridge. You cannot celebrate it like this. You see some discovery tools here and there, you see, "Oh, I blocked a bot that was scanning all my parts. Was that going to be the next bridge?" You cannot know. Very interesting to hear about this. I was wondering because you also did a lot of work and research on IoT devices for the Internet of Things. How does it work in this sector? It's more hardware driven. How do you go about protecting those devices? And maybe already a follow-up question on that. What's the funniest IoT device that you know that got hacked off? Sex toys and these kind of things are extremely insecure. But I think that's in general. Home automation is not necessarily extremely secure, right? At least now. Not all the protocols that are being used are hacker proof. And that goes back to, "Okay, what is the security of your home network?" If you're maybe using the password that is coming from the telecom provider and that's computed by an algorithm that is in the Internet, well, maybe that's not something that you want to run home automation. And at the end, it's not only toy producers, right, in this case, but it's also the users of this toy. But are these parents thinking twice, "I'm filming my kid, I'm connecting the device to the Internet, nothing is going to go wrong?" Well, I don't know. Because for me, the home automation is really where I draw the line. I think it's quite safe, but to have everything connected in my house, I think there's always a bit of danger there. And you work in security, but in the beginning you mentioned, "I do like this home automation, I like to play around with it, but I feel you can only be 99% sure and saying what sex toys that are connected to your phone, for instance." I think it's important to understand that there's always a risk that there's data collected and perhaps shared. So I think for every person you have to decide, "Okay, am I willing to take this risk and do I let this risk really inside of my house?" At the end, the most secure system is the one that doesn't exist. Every time you have a system, you will have the chance that is misused. It doesn't matter what it is. And if toys are going to be also systems because they have a processor and are connected to the Internet, well, I will assume that you are owned by default and then you need to prove it otherwise. Yeah, very true. And we cannot step away from using all these devices because I think these devices are just stacking up and more and more products are being built that are running on the Internet or have a processor. Yeah, we have some challenges ahead of us. My advice to young professionals. But since you've seen so much, still at a relatively young age, but what advice would you give junior cyber security professionals or maybe also the people that work as a developer on the IT industry and want to enter this field? I think that everyone is in the field if you know it or not, right? So the first thing is to acknowledge it, right? What do you mean with that? We're already in it. You cannot escape and it's actually the same with any new business that runs somehow on our website. You cannot say, I am not a tech business, right? I am not using digital. There is no more not digital now. So we are all in a digital world and the digital world has different risks, right? If you are a small entrepreneur that sells something offline, you might argue maybe, but I don't know how do you make your payments? Oh, you have a phone that is connected to your bank account and you receive money through that. Oh, maybe then you are actually digital, right? So you are in a digital world and the digital world has a cybersecurity concern. That's something that we need to acknowledge. When people don't like technology, right? And some people delegate their tech decisions to whatever that is not business. I will actually argue your business has a driver, so I will not put it in another room. And also our lives, right? Our lives are highly digitalized even if you don't have IoT device at home. So the first thing is acknowledgement of this digital world and cybersecurity risk, right? And the second one is just start learning, right? Just go to the internet and look for if you are a developer and cybersecurity development practices, right? So you have OASP. You have a lot of material already written down. You don't even need to be an expert in cybersecurity hacking. Hacking is not something for hackers, you know? Can you explain that? Yeah, in cybersecurity you always make the difference between scriptkitties. In cybersecurity you measure the power of your adversary depending on their capabilities, right? And that can be a scriptkitty, so me being an 8 years old, I was a scriptkitty, right? So basically what does a scriptkitty do? Go to a GitHub repository, copy the code, put it in the terminal, try it yourself. Does it work, right? You don't know if it works actually, right? So it's really, if you have the awareness of a script working or not, you are maybe an expert level of scriptkitty. But everybody can do it. You don't even need to have technology to do that. So for me, if you think about it, this can actually cause a big problem for a company that was vulnerable to this script. Let's say this Santiago of 8 years old happened to target a company that was having a vulnerability except exactly with this script. I could have caused downtime in their applications. I didn't know, right? I just maybe saw some error or my computer got blocked or something. Be careful, maybe a mom saw some. And at the end, I'm not a hacker, I'm a scriptkitty. And the company went down for cybersecurity attack. So there is a disconnector. Everyone that is not a hacker is can also be a have hacker consequences, right? So from that perspective, you don't need to be an expert also to be aware that there are certain things that you need to think when you are developing software, right? Or when you want to go into cybersecurity as a field, right? For developers coming back, I would suggest to look at the OWASP website. There are open source projects. They list the attacks that are the most common in a year. Successfully being exactly. And then you can learn about what is a cross-site scripting, what is SQL injection, what is actually what is your software not doing as it should be, right? And as I think someone writing software, that's something that you want to make sure. So if I want my software to do A, well, when I'm running software, my software should do A, no A plus B. And any cybersecurity problem is actually a deviation from this behavior that you wanted. Now in the cybersecurity only world, right? So if you want to become a cybersecurity professional, cybersecurity is so extensive. Like there is people that do social engineering. That's all cyber seconds. They don't even need to know how to turn a computer, right? There is people that do certifications. So they are teachers. They don't need to be a hacker. So the first thing that a new comer in the field should do is to understand what are all the multiple opportunities that cybersecurity offer you. Regulatory, how it did, software development, people security. There is really a lot of areas where you could add value. And since there are so many areas where you could add value, you don't need an specific background to say, I want to become a cybersecurity professional. Do you feel you have to be technical to jump in this field? have a technical background but I think for certifications or audit or awareness you might not need such a technical background. I don't think that for every field in CyberSec you need to be technical. I think that everyone that is into a business that has to do with digital needs to understand the basics of digital. So not necessarily because you are going to be as every security professional, but because you are in a digital business. So even for awareness you need to know why are you sharing this awareness and it end up being at some point a technical reason because maybe if you don't update your device pointing to my phone now, I can get hacked. Or maybe I should not trust someone that throws a USB on the floor. Why? Because a USB might have a virus and then you very quickly need to explain why it's a virus and these kind of things. The certification world actually started from a workforce that was not technical and needed to become technical enough to understand cyber security. So that's a very nice example of retraining your workforce, so CISSP and all these kind of certifications. Try to end up with more cyber security professionals without a technical background. So if you go into the curriculum of CISSP, you learn from a very high level what is for example on network. And you don't need to be a computer science to have CISSP. Yeah. Now I think this is very valid point that you're making just to say don't have all your security people very technical because they're not that many technical people out there. I run a recruitment agency around cyber security professionals. So I see that the supply and the man is grown further apart. It's kind of crazy. I think this is going to be a global problem. So I really like this idea that maybe not focus only on the technical professionals, but help others also enter this field. And to come on that note, I know you're also a mentor for a Hello mentor where I think it's a very interesting organization where you help students guide them sort of through their career or not a true career, but through their university studies, how to enter the working field. What is exactly a role in that? And is it specifically focused for security or is it a well I. Well, that's a good question. That's something I really like. I have two roles. So in my free time on Sundays like today, I try to advise them as a company. I like this entrepreneurial vibes a lot. So I try to give them some advice on business development, how to move to the next step investors, etc. So that's a bit more the innovation part. And on the part of their target group, I'm a mentor. Right. And what does that imply is basically every six months that is normally what a mentorship last. We make some matchmaking between students and mentors and based on the interest that the student have. And they will choose mentors or top three mentors. And then you allocate basically your mentors with your students. And we were discussing at the beginning is that the university doesn't really prepare you for your actual work. And that's what he'll mentor tries to do. So you bring people from the industry and try to show to them mentees what is actually like to work. Right. And why are the things that are maybe nice to develop before entering the workforce or the industry or the academia does it make sense to study a master's or it makes sense to go from bachelor to the industry and then to a master. So all these kind of questions that we might have had back in the days, we try to bring people that went through these questions and have developed over the years and are able to reflect on, okay, what's the decision? Why maybe I could have explored this and this and that's what we try to do with the mentees. What I love my field, so I love cyber sec, I love tech. How would you pitch the cyber security world to young students? You know that the nice thing is that you don't really need to pitch it. Everyone thinks that it's a cool field. So I think we were discussing at the beginning how different facets the cyber security world has and that's also appealing for students, right. And sometimes for technical students, that is the focus of hellow mentor, the hacking part is more cool and you know it's like, okay, what is it like to be a hacker and the discussions I had with for example, mentees is, yeah, but okay, you know, I know that cyber security is like hacking and so on, but what is actually it until so I always start with, okay, you know, there is a mind map of cyber security concepts and areas and we go through this mind map and they say, oh, it's bigger than I thought, so it's not only hacking. Is this the CISO mind map? Yes, it's very good. It's a really good one. Talking about broad moments, one of the mentees I had was in between Shilai Dwa Masters. I kind of like cyber security because he's on school, but I'm not sure. So I always share ideas with him and it's more like a conversation, right. So for me, it's someone sitting in the same table at the same level and I just think that I'm older than them and that's my only particular skill I have. And within these conversations, we discuss about the cyber security mind, mind map and he ended up saying, you know, it's a very exciting field. I apply to an internship in ABN because he knew what was cyber security better than everyone he got picked by the CISO as his intern, kind of mentee and trainee. And he got from the CISO, a path that he will follow because he knew what he wanted, right. And that's something really nice because a couple of chats that we had together end up being a very nice outcome for him because he actually knew what was the field about. He knew what he wanted. And then somebody else had more experience. Oh, I know that you're a brilliant, a brilliant guy. You know what you want. You know how it works. I'm going to take you under my wing and help you to develop. Yeah, but it also says a lot about you that you're one of your proudest moments in cyber security is actually helping somebody enter the field and maybe pivoting his career. So you're actually the second guest on the show that gave this example as being one of the proudest moments in their career. So I think that that's very special. It's also helping others get sort of in your footsteps in a way. At the end, that's more scalable contribution you can do, right. The moment you help someone into the field or you spark a thought that helps someone into the field, then you are basically doubling the workforce in cyber security. And you mentioned earlier that Hello mentor is also an entrepreneurial group of people. What happened with the young entrepreneurial Santiago? The young entrepreneur Santiago is there. Hello. Welcome back. You're listening in the corner. And I am an entrepreneur every day. I think that's of course is part of starting a company trying here and there. So you try, you fail, you try again. What does the name stand for? I was curious. And that's a very nice story. Actually, it's is X link is written X link and it's about crossing borders and linking people. So it's about how what is the effect of actually having the proper software businesses on society. So that's a bit of the ultimate vision that we have. And it is we have been called also for both admissions before, but I also believe that if you don't have a ball of ambition, it makes it harder to wake up every day and fight difficult fights. So that helps a lot. And that's part of entrepreneurship, right? So you don't want to reach the next step. You want to reach the next 10,000 feet. And that's what keeps me a lot of energy. Since that day that we were five, now we are 22, right? And we keep growing. And we are actually looking for clients now. So we are able to go outside to pitch our product to outside people. So it's a very exciting innovation entrepreneurship world where I am into. On the other side, I am in the compliance work in a compliance regulated environment. So we develop financial applications and that has a very big component of cybersecurity and risk management, et cetera. So that's where I also add a lot of value. - Come. - It sounds like you guys on the great journey. You're already with 22. - It's a very exciting journey. So every day is a unique day. - Yeah, and it's indeed very entrepreneurial, but you're still an entrepreneur in a company. - An entrepreneur. - An entrepreneur, yeah, yeah, correct. But do you still aspire to become an entrepreneur yourself? - Yeah, I think that the end game for me is having a company, right, in tech, of course, because everyone does tech these days. Maybe in some cybersecurity aspect, I don't know, I still find it too exciting to say no. So that's something that I wanna do. And also, is what gives me energy now, right? So what gives you energy changes over the years? For me, that has been the case since 10 years already. And maybe if it changes later, I will say, okay, I wanna be a corporate worker now. But for now, entrepreneurship is, you try to make it work, and if it doesn't work, you'll afford the next one, and you try again. - Yeah. And is there still a big problem that you would like to solve? Maybe with your own start-up? - There is a lot of problems that. - But what keeps you up at night, whether you're most afraid of, or a problem that you would really like to solve? - I cannot share that. - Okay. - That's IP. - Yeah. - If not, you will need to disappear. - No. I think that there is a couple of ideas I have, but you know, ideas doesn't have any value until you execute. And then for me, that's, so I will be happy to share these kind of things, but it's not really something that I have taught through to sound clever in this podcast, and the second one is, even if I tell you, it doesn't have any value until I actually execute. - And in how many years do we have to invite you back again to tell us about it? - Well, in five years, you can invite me back and see who I am. I think that we are in a very exciting journey with crossing, and either we are extremely big in five years, or I am doing my next start-up zone. - Amazing. - Yeah. - Thanks a lot. - Yeah. - Which was great. - Thank you, Santiago. - Thank you, nice, very, nice to be here. - Let's see each other in five years. Hasta luego. - Hasta la próxima. (laughs) - Thank you for listening to Cyber Scurdy Talks. We hope you have enjoyed this episode with the latest trends, war stories, and exciting career anecdotes. If you enjoyed the show, please review this podcast on your favorite podcast app. Also, could you do me one small favor? Could you please share this podcast with one friend that you think would like to show just as much as you do? Thank you. And for all further information, please go to csrecruitment.nl/stalks and subscribe to this podcast. We will be back with another exciting episode in just two weeks. So see you next time, and stay safe.

Podcast Summary

Key Points:

  1. Santiago Aragón, a 30-year-old cybersecurity professional, shares his career journey from Mexico to Europe, including academic research and industry work.
  2. He emphasizes the importance of adaptability, fast learning, and treating cybersecurity as a business decision involving effort and money.
  3. Cybercriminals operate like businessmen, targeting companies based on resources and profit potential, with ransomware being a key threat.
  4. He discusses the evolution of cryptocurrency security, noting that protections often follow widespread problems.
  5. Organized crime groups, such as mafias and cartels, are increasingly involved in professional cyberattacks.

Summary:

In this episode of Cyberscirty Talks, host Lawrence and co-host Bruno interview Santiago Aragón, a 30-year-old tech lead at X-Ving with a rich background in cybersecurity. Santiago recounts his path from studying telematics in Mexico to pursuing a master's in cybersecurity in Europe, where he initially focused on theoretical cryptography in academia before transitioning to industry for its faster pace and complexity. He highlights that cybersecurity is a game of effort and money, where both defenders and attackers optimize their resources.

When asked about hacking, Santiago explains that cybercriminals target organizations based on their capabilities and potential profit, with ransomware being a common tool for targeted attacks. He also touches on cryptocurrency security, noting that protections typically emerge after significant problems arise. The conversation shifts to organized cybercrime, with Santiago acknowledging that professional groups like mafias and cartels are now heavily involved, as they naturally innovate into illegal sectors.

Throughout, Santiago stresses the value of a university education for developing problem-solving frameworks, despite its limitations in preparing for corporate dynamics. He concludes by emphasizing the growing importance of cybersecurity for individuals as digital perimeters expand beyond traditional institutions like banks.

FAQs

It is an interview podcast for cybersecurity professionals and aspiring ones, featuring industry experts discussing trends, horror stories, and insights into the field.

Santiago Aragón is a 30-year-old tech lead at X-Ving, author of industry publications, and a cybersecurity professional who has lived in seven cities across Europe and Mexico.

He studied telematics engineering, focusing on telecommunications and informatics, then earned a master's in cybersecurity, privacy, and innovation, and briefly pursued academia before moving to industry.

He preferred the faster pace of development and complexity in industry, where decisions involve end users and business needs, unlike the slower, knowledge-focused academia.

He sees it as a business of effort and money, where hackers target companies they can exploit with available resources, aiming for maximum profit through ransomware or scale-based scams.

He notes that technology outpaces regulation, and protections for digital assets like wallets depend on user responsibility, similar to how bank security evolved after past issues.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.