Antonio Delgado and Ruben Domingo, BCC Global CISO Roundtable
Industrial Talk/BCC is talking to Rubin Domingo and Antonio Delgado, about “CISO Roundtable, Real Threats and Real Decisions impacting the market”.
If interested in being on the Industrial Talk show, simply contact us and let's have a quick conversation.
Finally, get your exclusive free access to the Industrial Academy and a series on “Why You Need To Podcast” for Greater Success in 2026. All links designed for keeping you current in this rapidly changing Industrial Market. Learn! Grow! Enjoy!
RUBEN CORTES DOMINGO'S CONTACT INFORMATION:
Personal LinkedIn: https://www.linkedin.com/in/rubencortes/
Company LinkedIn: https://www.linkedin.com/company/consorci-aoc-2/home/
Company Website: https://www.aoc.cat/en/
ANTONIO DELGADO'S CONTACT INFORMATION:
Personal LinkedIn: https://www.linkedin.com/in/antoniodelgadociso/
Company LinkedIn: https://www.linkedin.com/company/affinitas-education/home/
Company Website: https://www.affinitasedu.com/
PODCAST VIDEO:
THE STRATEGIC REASON “WHY YOU NEED TO PODCAST”:
OTHER GREAT INDUSTRIAL RESOURCES:
NEOM: https://www.neom.com/en-us
Hexagon: https://hexagon.com/
Arduino: https://www.arduino.cc/
Fictiv: https://www.fictiv.com/
Hitachi Vantara: https://www.hitachivantara.com/en-us/home.html
Industrial Marketing Solutions: https://industrialtalk.com/industrial-marketing/
Industrial Academy: https://industrialtalk.com/industrial-academy/
Industrial Dojo: https://industrialtalk.com/industrial_dojo/
We the 15: https://www.wethe15.org/
YOUR INDUSTRIAL DIGITAL TOOLBOX:
LifterLMS: Get One Month Free for $1 – https://lifterlms.com/
Active Campaign: Active Campaign Link
Social Jukebox: https://www.socialjukebox.com/
Business Beatitude the Book

Do you desire a more joy-filled, deeply-enduring sense of accomplishment and success? Live your business the way you want to live with the BUSINESS BEATITUDES…The Bridge connecting sacrifice to success. YOU NEED THE BUSINESS BEATITUDES!
TAP INTO YOUR INDUSTRIAL SOUL, RESERVE YOUR COPY NOW! BE BOLD. BE BRAVE. DARE GREATLY AND CHANGE THE WORLD. GET THE BUSINESS BEATITUDES!
Reserve My Copy and My 25% Discount
Transcript
SUMMARY KEYWORDS
Cybersecurity, Barcelona Cybersecurity Congress, CISO Roundtable, network protection, third-party risk, AI threats, ransomware attacks, cloud resilience, regulatory compliance, cyber insurance, public sector, private sector, cybersecurity framework, data protection, cybersecurity awareness.
Welcome to the Industrial Talk podcast with Scott Mackenzie. Scott is a passionate industry professional dedicated to transferring cutting-edge, industry-focused innovations and trends while highlighting the men and women who keep the world moving. So put on your hard hat, grab your work boots and let's go.
All right, welcome back to the another installment of Industrial Talk, but this one's a special one. As you can tell from the back, if you're out on video, we're talking Barcelona Cybersecurity Congress. We have a Roundtable, CISO Roundtable, and we're talking about pretty much everything associated with cybersecurity. It is a great, great conversation, paper and pencil. It's vitally important that you protect your networks, especially going forward. Big things are happening. You need to you need to protect, and you're joining the number one industrial related podcast in the universe that celebrates you, industry professionals all around the world. You're bold. You're brave. You dare greatly. You innovate. You collaborate. You're solving problems each and every day. That's why we celebrate you on Industrial Talk. Let's get cracking with the conversation. Barcelona Cybersecurity Congress. So I have two screens because I I can. Some of you probably have more screens because you're that that important. I just I just need two screens, and I over here and I have everything that I need, everything that I need to be able to share with you. One, this one needs to be put on your calendar. Cybersecurity, you know as well as I do, it's everywhere. People are talking about it. You need to network. You need to collaborate. You need to be able to have conversations that are truly important to your organization. That resilient business that comes with protection. That comes with adequately being able to discourage and capture threats before they really impact your business, we need you to succeed, and that comes through having proper cybersecurity, not the cybersecurity. And you're saying to yourself, Scott, they always slow things down. No, they don't. They're smart. They they understand what you need to get done, but you need to do it, and you need to do it now, and you have to have that conversation. So, the Barcelona right there, Cybersecurity Congress, it is in Barcelona. How about that? november 3 through the fifth. You got to check it out, the contact, all the information, the little URL. It's out there. We have a discount code. Of course, I'm not prepared to share it with you, but it's out there. And if you you sign up, you get a discount. Put in. I want to say. Don't hold me to it. Just go out to Industrial Talk. But I think it's BCC podcast 26. Put that in there, get your discount, and be a part of it. And have and and come buzzing on by. I'm going to be broadcasting there, so come buzzing on by and have a conversation with me. I'm always an open book. I'm I'm like this all the time. I'm always happy to have a conversation with anybody. All right, this one, of course, I have I have the next thing. This is the Global CISO Council. This is the Spain chapter. We have two gentlemen in this Roundtable, and again, I'm going to try to keep this relatively short. Antonio Delgado, and then the other one is Ruben Cortez Domingo, and you understand right off the bat that they know a lot, and they're there to help you, and they're they they have they've been around for a long time, and not they're not you know age they're they're just smart and very capable individuals and professionals that you need to connect with, and again, as always, all the contact information for these two gents and everybody else that I ever have conversations with are out on Industrial Talk, and everybody on Industrial Talk wants to collaborate, wants to help you succeed. Yep, especially these two because it's it's amazing again. Before we get in the conversation, your your call to action is the Barcelona Cybersecurity Congress. You need to sign up. You need to be there. And yes, it's a great place. Yes, great people. And yes, you get to meet me. I would like that. All right, let's get on with the conversation. This is a Roundtable, CISO Roundtable. Real threats, real discussions. This is what we're having here because you need to be protected and you need to succeed. Enjoy the conversation. All right, Ruben, Antonio, welcome to Barcelona Cybersecurity Congress podcast. This. This is a Roundtable listener.
We're going to be talking about the the global. This is with the global. I got it right here. Just FYI, I'm looking at this piece of paper. Global CISO Council. This is the Spain chapter. They're cool. They have a good head of hair. And we're going to be doing a Roundtable, and we're going to talk a little bit about cybersecurity. So that's what we're all about. How are How are you doing today, Reuben?
I'm doing well, thank you.
All right, and Antonio, how are you doing?
Doing great, thank you.
Yeah, don't don't come to me and say I'm not doing my shoulder's a little sore. I don't want no. You're not going to do that because because on the podcast everybody's happy.
Of course. All right.
So so that we have this Roundtable flow. What I'm normally doing, I just you call me out. If I just throw a question out and I don't say, "Hey, Reuben, tell me a little bit more about that, or "Hey, Antonio, and if I don't call your name out and I just throw it out there, I'm sorry. I I apologize in advance because that's just not fair to you guys that I would do that, huh? There anyway, let's get rolling. Okay, Reuben. First question. Here it is. We need to know who you are. Can you give us a little background on on who Reuben is? A little about this this CSO council. Just just help us understand who you are.
overnment as well. It's about:Yeah, yeah. How how long have you been in the world of what we're going to be talking about cybersecurity? How long how long you been there?
Well, I've been there for for a long time, working in the technical part, especially 20 years, 25 years, working with with different aspects of cybersecurity, especially time the technical ones. But from the last 10, I've been involved in in the creation of the new unit of a new direction of cybersecurity, a new department of cybersecurity in my company, and then we have been working this well, the cybersecurity as a as a complete aspect inside the company. Not only not only as a technical as a technical thing, but a governance thing inside the company with different with different aspects of the cybersecurity technical one, the governance one, the participation of the board of directors, the compliance part of cybersecurity, and all of that.
See, you've seen a lot of changes. Yes. Yeah. Things have to do. I can only imagine, and we're going to dive into that in our conversation. But before we do that, Antonio, you need to be better than Reuben in your explanation. Just kidding, man. Ruben, you knocked it out of the park. Let us know a little bit about who Antonio is. Yeah.
.S. So we protect the data of:So here's here's my challenge: is that because I see it, I I have conversations with many, and the changes that are happening are rapid, and I think okay, so maybe I'm interested in getting involved, me young guy, getting involved in cybersecurity, and and I go to the university, I go through all of that, and and it before before I get out, everything has changed. I don't know how you keep up with it. I don't know how you keep current. I don't know how you keep learning. I don't. I don't. But that's why you guys are in the position because you you guys bring that mad skill of of capabilities there. I got that off my chest. It was causing me issues. Now we're going to go down to, and we have some conversation points, and I want to make sure that you you both sort of touch upon. I'm going to say, hey, Reuben, blah blah blah, whatever it might be, and then I'll say, hey, Antonia, give us yours, or and vice versa. It's just sort of, and and it's a it's a pretty pretty flowing conversation. But so I'm out here as we begin. I'm out here, and I and I hear it all. I am involved in a lot of manufacturing and industry, and everybody everybody wants to collect more data. Everybody wants to continue to drive and have insights into that data, and I want to be able to do whatever it takes to get data so that my operations run efficiently. In that whole diet, in that whole conversation, I didn't hear one thing about security. I didn't, and it happens over and over again. My question to you, Reuben, to start this off, with all the changes that are taking place in the world of cybersecurity and and all, we'll touch on AI. What are the real threats versus, let's say, the noise? Because I'm just listening to it, and I can't me, I can't decipher what is real and what is just noise, and I don't have to think about that. Help us understand that.
we are providing services to:See, because of the speed at which industry is moving forward, and the the I feel I feel like it's not uncommon to always look behind, like I'm. I'm already. I'm. I'm late. Like it's already happened. It's hard for me to wrestle with and reconcile the fact that we're trying to protect against these threats going forward, but we're already behind the eight ball. It's just. It's an interesting time. Antonio, do you have anything to add to that? That real threat versus noise, because again, as a as a professional, if I'm confused, I'm not making any decision, which is not good either, right? Help us understand a little bit about what you think about the real threat versus noise.
Yeah, I mean, I mean, for me, what is I mean these days, what is overhyped? I mean, even to some extent, is AI AI attack scenarios, no? That you're reading on the on the news all the time, no? That the artificial intelligence are going to hack systems completely by by itself. That and this is actually, I mean, at least right now, is not not what we see in our in our real incidents. No, yeah, I think we underestimate something that is way more simple for us, at least in the educational sector, is ransomware against schools and universities is still a trend that I've been seeing lately. That is that it doesn't get the same attention as an as an attack, no, on a on a bank or maybe an attack using AI. A DMA sector has been one of the most attacked in the world for the for the for for the recent years, and especially ransomware and phishing attacks. No, so for us, the email is one, if not our main attack vector. No, other important real threat that is not very trendy or fancy is the third part third party risk. No, so because we're working all the time with many many providers, and many some of the providers don't they don't manage their services, their infrastructure, or the data with enough security, no, or enough make care, no. That's actually one of the main attack backdrops that we find constantly, no third party, and that's why it's also very important the third party risk management, no, and well, in our in our in our case, our main. Customers are are schools, no. So we're talking about we need to deal with budgets, different different IT teams. Maybe the maturity in the educational sector is not as good as financial or industrial or or military sectors, no. Of course, no. So yeah, there are many threats that we need to that we need to care, no. And for me, that's the real threats. Other things like very complex artificial intelligence attacks or or topics about geopolitics, no, military attacks, and so on are not a reality for my for my sector, no. So I prefer to focus on on real threats and facts.
See, you bring up a good point. There, there's still, you know, you've got the the conversation that exists out there today, and it is AI. What does that mean? It's it's it's like an easy easy topic to discuss because it's in the news. It's everywhere, right? And everybody's trying to use it, and so on and so forth. But the real challenge that that I've seen over time, and it doesn't change. And to your point, Antonio, there's it's just these nefarious, these problem people who want to penetrate networks will always go to what is the easiest. And if the school is easy, well, I'm going there. And is there a rich source of information that I can do whatever I need to? Yeah, it's there. Is is the vulnerability within the education system, Antonio, more people related? Why is there a vulnerability there? What's going on?
Oh, absolutely. I mean, social engineering is is very straightforward in schools for a simple reason. I mean, schools are built to build to be to be open to help teachers, the students. I mean, a school is not is not a a bank. No, I mean, teachers want to help parents. Staff wants to to to to answers quickly. No, so everyone is is is is trusting each other, no? I mean that culture is is beautiful, but it's exactly what an attacker uses, no? For example, simple as as a phone call saying, "Hey, I'm a parent. I forgot my password. Can you help me establish my my password? Or maybe some kind of email that looks like a from from a teacher. No, I mean it works much better in in in schools. That for example, in a yeah in in a bank. No, how do we fix it? I mean simple simple habits. No, things like training and awareness for teachers very important having the proper strategy to cover all the human risks. No, having very solid identity controls, doing siber exercises, phishing simulations. Very important. This is how you measure if people when they receive official, if they're gonna click or not, the best way is is is to do this kind of campaign. Have a multi-factor authentication. It will reduce the the risk surface in schools. I mean, there are many things that you can do. So different layers of control that you need to to implement. But yeah, the human factor is probably the weakest in in our sector. It
is, and and we all get it. I, you know, I'll get emails saying, "Hey, here's your bank. Your bank is saying you need to do X, Y, Z. It looks legit. That email looks. It's got everything. They do a good job, but I know that that's not the case. So you know, I I pretty much don't click on anything because you know that's
a problem right now.
That's my policy. Don't click. Okay, so Reuben, I come to you, and I give you this situation. I I am, and I look at your your public sector technology, cybersecurity, cloud resilience-that's that's under your name, by the way. Just a why I didn't I didn't rattle that off. And I come to you, and I need help. I'm a business. I am, let's say, a public sector. I I am a business. What what is your approach? What if everything is if everything's critical, and you look at me, and everything's critical. How do you prioritize and say, Scott? Let's do this first. Take us through what that looks like. Help us understand.
Well, when an incident comes, everybody gets. In panic, so it's the most typical situation. But we have to tweak out and establish some some steps to manage this incident. I think the first thing that we have to do is to contain contain the incident. Just look at what's happening. If we have a problem with a system, then we will have to stop that system because it's probably there's a lot of it's very probably that old data has has been stolen and and maybe we we will not be able to recover them, to recover that. So we have to contain the system that is affected, because if not, it the ransomware or whatever is whatever is happening can affect all other systems. So the first thing is to contain the incident. The second thing is, Well, if you have a crisis committee, you have to to establish all the all the communication that you have to do. If you are a public body, you have to communicate very well because the data involved there are the citizen data. So you have to be very careful communicating, and after that you have to you have to try to to recover the service, but not to recover the same service that you are having running. That if you've done your homework, you should have another instance of your service in another in another place, and then you will be able to restore the service as soon as possible. If not, you have to you have to well, you don't have a backup. You don't have another another system to replace the affected one. Yeah, then then they will have a real problem, and we have to to start away. So
here here's a scenario. So I just heard what you said, Reuben. You're telling me, yeah, we'll we'll look at this. The challenge I have for me is to think that this can be done quickly. Are there tools that you can, Reuben, say, "Hey, let's get a a general assessment of your network, and then be able to say, here here it is. We're just going to have to, you know, just something that you can go in and say, nope, here it is. This is this is what it looks like, and we're going to do X, Y, and Z.
Yes, but you have to be prepared before the incident, and and that's the important thing. You have to be prepared before the incident because if you are not prepared, the the recovery will not be fast. Yeah, you will need time, and you and you have a real, real, real problem. That's why I think that regulation helps a lot. Regulation helps a lot with that because regulation obliges you needs to the issue 27,001. All of this, the needs in the case of USA, of the states, all of these regulations oblige you to prepare your systems for in case that the system fail. It doesn't matter that this cyber attack of maybe you have your cloud provider falls down and you need another cloud provider. So the key here is to to be prepared before the before the incident. That's that's the key.
Yeah. Here, Antonio. Here's a scenario for you. With that said, what what Ruman said, I'm I'm a manufacturer. I'm I'm a company, and I, and I, I, I have an obligation to deliver a product. That's what I do. I'm a manufacturer, and every time I listen and I hear the the the need for my network to be protected, it seems very difficult to get to the point where I feel comfortable, or I can get back to what I do and I manufacture. How do we, and how do you, be able to communicate to me before I have a real problem? Which I think that's the best way. Have a problem before it happens, and and talk to me about that so that I can prioritize and make sure that my network, my business, is protected.
No, it's a it's a interesting interesting question, and it's also. A good question for me because before working in the educational sector, I worked in an industrial company, so I'm familiar for with the with the OT and the and the and the manufacturing. No, it's a word that is is is familiar for for me. I mean, when we're talking about you know factories, plants, operational technology, IoT. It's it's a similar world, but at the same time, it's a different challenge, no? Because in this case, we're not talking about just the usual the kind of of network you will find in in an office because now we are dealing with factories, so we are talking about not not just protecting the assets and protecting the the confidentiality of information, but but guarantee the production, protecting the production, no, because that's the availability is everything, even more than the confidentiality. No, so because a machine that that stops will cost real money. You know, every every every minute. No social security has to to to to fit every every every operation, and you need to take many different layers of complexities into into consideration to have the proper manage of the audio operation. I mean, how do you approach? I mean, I mean, first of all, visibility. No, you need to know. I mean, I mean, in most factories, maybe or nobody have a full map of what is connected. What kind of system do you have? So one of the other future steps is to have full visibility of the IT infrastructure, the network, understand what what what is talking to what? No, I mean second is separation. That's very very important in the in the OT world. No, separation between the office network and the fact and the factory network. No, the IT and the and the OT. You should separate and you you should not treat this as the same thing. No, because it's something that happens via email, for example. Someone clicks in a ransomware. We're not talking about that. That computer is going to be locked. We're talking about maybe this reach the protection line, and then you are really, really, really in trouble. No, that's why segregation of networks is probably the most important control in the manufacturing sector. No, well, there are many things that you need to take into consideration. Plant managers will need to deal about vulnerabilities, weaknesses of the of the of the industrial devices like PLCs, like Scala systems. Usually, many of these devices are legacy systems. That's very common in the industrial world. Maybe some machines are still going for more than 20 years, and they are still working. So you need to take care of legacy systems, and then you will need to define an action plan, no, to understand this world and to to make things even more complicated these days. OT is becoming IoT Internet of Things. That means that every OT OT hardware device is going to be connected. So it's not OT anymore. Now it's like a like a mix between IT and and OT. That that means many advantages, but at the same time means many new witnesses that we need to take to take into consideration, no? So yeah, it's a it's a very interesting world, and it's actually it's like a parallel world when you compare this with the with the classic IT infrastructure. There are many risks and many things that we need to take into consideration for the
yeah this whole IoT, this this whole push for getting those devices out on those pieces of equipment, pulling the data, connecting it to the cloud, doing everything-it's like I see these little penetration points of maybe vulnerability. If I if I'm not up to date, if I you know I just let's say I don't know. I don't know. It's just things are happening. Things are moving forward. Hey, Reuben. With that said, I I I see this. I'm I'm going to digress. Here it is. So let's say I'm a company. No, let's say I'm a public entity. All right, like you, and I have vendors, and I'm ordering cups and ordering whatever street lights, whatever it might be. But I'm going to some company to order that equipment. How do you, in the old public space, know? That that company that you're ordering lights from is protected.
Well,
because I don't know. It's a tricky
question because sometimes I have to well, I have to to to think what I what I say because
no, I don't want to compromise. But that's no,
no, no, no, no, no, no, no. I I will be honest. I will be honest because there's a there's not a this is not a problem only for the public administration. It's it's a it's a problem for all the companies, that yes yes for the companies the third party the third party third party companies are one of the biggest threats that we that we have. Why? Because when you, in the case of the public administration, when we contract any service to to a private company, we ask them to be certified to comply to be compliant with some regulations and to be certified in in our case in our national security framework. With that, we think that they are protected, but sometimes cyber incidents happen, and and when it happens again, as a client, as a customer, as a client, you have to be prepared. You have to you need to have alternatives, Alternative services, yeah. Because when your provider fails, you will have to wait until this provider recovers their systems, and you will have to deal with with their incident as well, because you are responsible of your own data that is managed by your provider. No, so you have to be prepared, having two minimum a minimum of two providers of each of each of the services, just in case one of them fails. I mean, for for for example, in the case of cloud computing, we are working with multi-cloud because if Amazon fails, we have Azure. We are working at with with another concept that is a sovereignty cloud that is a cloud based in Spain and especially in Catalonia. Yeah, just just in case geopolitical threats become true and maybe it happened for months ago. U.S. President Donald Trump asked Anthropic to stop giving service of the new model Mythos. And imagine that you are company, you are working a European company, you are working with Mythos and somebody a Political, the most powerful man of the world decides that this service cannot be given to Europe. But all of our cloud providers are Americans, so we have to be prepared for that as well.
You're you're hitting on on a lot of very important topics. I agree with you 100% which makes your job, Reuben, even more difficult. It it means that you have to. It's it goes beyond saying, "Hey, here's a network. Let's protect against that network. You have so many other layers that you have to, and risks that you have to consider to make sure that my business, my public sector, you know, services don't get interrupted. You just, you just do. It's, it's so dynamic out there. You agree? It
is. Yes, it is very dynamic, and it's not easy. But we do it. We do that. So our providers are. I think that we have very good providers. We are very strict when we contract those providers. There is a very, very, very, very, very strong national security framework for public administrations in Spain that is called Schema Nacional de Securidad, National Security Scheme, and I think it's one of the most powerful one of the most powerful national security frameworks in Europe, because it it covers a lot of aspects in in the in the company, not only again, not only the technical part of the of the of the serviceability world, and and when we contract, when we talk with a private company, we ask, we require, we don't ask, we require them to be certified in that. National security framework. So we have a level of security of assured, an assurance level that is is what is is what it is. Then companies can fail as we can as well.
Yeah, and and Antonio, with that, let's say we're looking at the education system. Education, there's a lot of things going on. There's a lot of movement of of stuff. How do you, in the world of education, given the reality that I might be buying books over here, and then I might be, you know, pencils over here, whatever it is, I'm I'm oversimplifying it. But I, how do you ensure that these vendors comply with what you expect? Like, do you validate that prevent prevent them from island these these people from island hopping and get into places where they shouldn't be? Do you validate that?
Oh yes, it's actually one of the parts of my of my job, no? Because I mean, as you say, no education we depend on a huge number of of providers, no? Many many many of them sometimes are small providers, no. I mean, talking about things like a learning platform, maybe tutoring tools, applications for for parents. Sometimes we need to deal with with maybe with small companies or even startups, no? And they all are going to touch maybe student or personal data, no. So the reality is that our risks are not all inside our own our own systems, but is also sitting with our our external providers, no? And is it? I mean, it's something that you need to deal with, no? Maybe a small educational company maybe might have a they might have a great product, no, or service, but they don't have security at all. So they, so they need things that we need to to validate with them. Okay, what kind of policy do you have? What kind of of controls do you have? Do you have some kind of basic incident response? How do you harden your system? How do you protect your what? What kind of cloud are you using? That where is this cloud base? Is in is under the European Union or is in other part of the world that is not complying with GDPR? So usually my my approach with third party risk is very practical. I try not to make it very bureaucratic, but basically, what we need to do is a proper third-party rich management, and to to to think. Okay, are this provider going to touch data? Yes or no? Is this application? What kind of connection are you going to have with them? Is an appy, is an interface. How is this protected? How they implement the access control? Do they have some kind of monitoring tools in place? Everything is logged and registered for future audit. I mean, there are many questions that you can ask providers, and usually we have procedures. It's actually a very standardized practice, and you will have. By the way, you can use. It's very good because AI. If you feed AI with the proper information and prompts about how to do third-party risk management AI is very effective if you train properly AI. It could be very effective, and it can it can save lot of time doing third-party risk management when you have hundreds of providers. It's something that could be very nice to to have, no, properly trained and properly protected. That's that's very important too. Yeah,
that conversation is happening quite a bit. How do we take AI, whatever it might be, and be able to enhance the cyber side and protection using the efficiency of what AI can bring to the table, yes, I I hear it, I see it. Here's the challenge, Antonio. One, again, I I'm I'm in a school, and I'm doing my school stuff, and I've got all this focus on school things, right? And how do we, how do we keep moving forward? And it just doesn't get to a point where I just shut down and I say no. I'll just keep doing my thing. I will ignore this. It's more important to move forward. How do we make this whole conversation around AI? Cloud, all of these vulnerabilities that I can keep on still doing my work. How do we? How do we? How do you make me feel at ease at that, Antonio?
I mean, sometimes it could be so. Sometimes no, it's most of the time it's it's a challenge, and there could be some. It is, yeah. It is. It could be some tension in in schools because because AI arrives faster than than than anyone was was was prepared? No, I mean maybe teachers or students they want to use it, or probably they are they are already using it, but they don't disclose it. They don't use it in a with security in mind. So also we can just stand in the door and say no, you can use AI. No, because if we say that, they're going to use it anyway without telling us, and that happens all the all the time. So it's you need to be you need to be prepared to have a proper AI policy, to have proper procedures in place to have a conversation with the educational community. We have already many workshops with parents, with students, with IT personnel, explaining how to use AI in a secure way. We are just prepared. I mean, right now we are just working in so many projects that are using AI, but we are trying to implement security in the early phases, you know, and having everything going through the proper channels and procedures. But yeah, this is going to get bigger and bigger and bigger, and it's something that we need to define clearly with policies, with procedures, but also with the proper training workshops and communicating this to all the stakeholders that are involved in the in the conversation.
Yeah, here's the funny thing, Reuben. One day, we didn't have AI. We were talking AI. We were having that conversation. The next day with ChatGPT, it just it just exploded. Right? It just happened. And then, just like anything else, We people, we just went all in, and we were just hitting it. How do you, in this world of AI, in this world, cloud's cloud? Got it. We need cloud. Got it. That's where it resides. Important conversation, but it's gonna it's gonna be there. But how do we Manage this market, this world, and not just shut it down and come to a crawl. We have to still move forward. We we we have AI. We have what it takes. We have to protect, but we have to continue to move forward. That's just what we need to do? How do we? How do we? How do we do that?
I don't know if I have the the correct answer for that. In Spanish, we say that Siro pues con tu en amigo alia te con el. You know. if you don't, if you can't beat your enemy, then it's better to be with him. Yeah. So in the case of of AI, I think that we have to understand that it's a thing that will stay forever, and it will be bigger and bigger and bigger, and it and it will do more a lot of more, many more things that it can do right now. So we can we have to embrace we have to embrace AI using it properly inside our companies and our governments with some scopes and some regulations that that allow an awareness to people just to understand what you you can put inside ChatGPT or what and what you cannot because you cannot put inside GPT personal data or critical data or whatever that is critical because they use your data to train their models, but it's a fact that everybody will use AI. So let's just raise it. And I like that. And on the other side, we have to be protected against cyber threats that we have with artificial intelligence that are very sophisticated and they. New and we don't know still what are these these new threats that will be here in some days, not some weeks or some months. In some days,
see, I like the fact that you embrace it. I think to your point, Reuben, it's here. Nobody's going to stick that genie back in the bottle. It's it's out, and that thing is is out and ready to go. Either you have the mindset of saying, "Okay, I embrace it. I need to do it. I need to figure this out. I need to have the conversations around that. I need to find individuals to be able to have a meaningful conversation, or you don't, and you you stick your head in the sand, and you and you don't. And those individuals, and those companies, and whatever, they're not going to be around for long because, just to your point, yes, it's happening. You might as well just embrace it, figure it out, and see how I'm protected, and I'm leveraging the tools that are necessary for my organization to be optimized. I just I don't see any other a way around it. Here's a question. Yeah, here's a here's a question. I'm in leadership now. I'm I'm a I'm a big thinker.
Oh yeah, a very good leader.
Big. I run this company. How do I, how do I, develop trust? How does the board? How do we how do we message all of this cyber conversation, and how do I, me big thinking, you know, head guy, begin to agree and and say I got to do it? How do we do that
for me?
Yeah, Reuben. Sorry, I'm sorry. Did I did I just do that? I was
maybe I was distracted. I don't know. Maybe it's my fault. Maybe it's my fault. No worries. All
on my side.
Okay, all understand. That's okay. Well, trust. I'm lucky because I'm part of the board of directors in my company for a lot of years because I was managing all the technology for 20 years ago, from 20 20 years old in my company, and then when cybersecurity was a big topic, then I I was the I was the one that could communicate with the board of directors, and I said that this is important. We have to we have to invest in cybersecurity, and we have to dedicate resources because it's mandatory. It's not it's not a it's mandatory. So, but I'm lucky. Some people are not. Some Caesars are not as lucky as me because they don't have access to the board of directors, and they should have. They should have access, and they have to develop some abilities that maybe Caesars are not used to have one. The main the main ability is is communication. You have to be you have to communicate very well to the bottom of the electorals because you don't you cannot talk about firewalls or do networks about whatever. You have to talk about business. You have to talk about impact. You have to talk with if we do not if we do not invest. I imagine 1 million euros in cybersecurity. We can lose 50 million euros if in our business. So this kind of communication is very is very effective, and another another thing that, sorry,
no no no. I agree. I'm I'm shaking my head in agreement with you.
Okay, another thing that is very good to communicate is to to understand to to make the board or the directors understand that there are a lot of fees that the company can be can have to pay will have to pay if they don't have a cyber security model. Here in Europe, we have a new directive that is called NIST too. That if you are not complying with with this directive and you have an incident, you can have a fee of millions and millions of you. Yeah. So this is a very good argument to invest in cybersecurity and to believe your your CISO and to trust him because what he wants is the best for. Once is the best for for your company and for your business.
Okay, couple of things that I I really agree with you. Yes, there's there's a risk for not being properly protected. Got it. Risk. That's a motivator too. I think communication is is key. I I I don't see how you cannot get around those conversations and say, "Hey, this is it, Antonio. One other leg of the stool, and I think this is important for big thinkers to think about is insurance. Right? They've got to insure, and I and I just say, hey, how do you bring about the proper insurance around your network to and say, hey, I'm an insurance company. I'm insuring this business. This business is top level from a cyber point of view. I will then, you know, my my rates are lower. Is that even happening out there?
No, absolutely, absolutely. I mean, what they call it is cyber insurance. Cyber insurance is very important for for for for us. I mean, yes. Is is I mean the I mean, I mean, let's say insurance doesn't protect you from from an attack. It helps you to recover after after one, because you transfer the the maybe the risk or the or the or the cost. No, when you buy insurance, is I mean sometimes instead instead of doing the I mean because this is a, I mean, it's a very interesting, it's a very interesting conversation. I mean, because I mean, these days usually insurance will ask for for that you reach some a maturity a maturity level, or they are not gonna give you a good insurance coverage or prime. I mean, many years ago, maybe it was a little bit more flexible. Some sometimes they ask you for passive controls, but these days they will do a complete audit and they they want to see real maturity. I mean things like you have implemented MFA for all accounts, backups, a good incident response plans, training platform. They will ask you for for marketing, for EDR deployed in the machines, vulnerability management, and many controls that they will ask. If not, they are not going to give you a good a good coverage. Very important is to find a good broker that will matters a lot because good brokers will be transparent and honest. They will say, okay, if you want to to have a good coverage, you will need to provide this evidence, this kind of documentation. You will need to show proof that you that you that you deserve this kind of coverage. No, because many years ago it was it was a different scenario, and now insurance companies are getting very getting very clever, and they know what they're asking. I mean, during the last year, many many civil insurance, and whoa, it's like an audit. I mean, they will ask for many evidences and a solid proof that you deserve their coverage. If not, they just don't give you a good cyber insurance, or they offered you a very bad, a very bad deals. Did change a lot in the last 10 years. It was different. More flexible, not not these days.
See, I I think they're part of your team. They're going to go in and they're going to assess the quality of your, you know, your network. They are, because I if I'm, I want you to, you know, that's how I make money. So I am going to make sure that you're properly protected, and I'm going to give you the policy. And I, I think working with them too as well to come up with something that makes sense. I think it's a good deal. I think it's not bad. I think it's a. I think it's ideal. Anyway, all right, Reuben. I need for you ever so quickly to give me what companies need to stop doing in their world of cybersecurity. Just stop. Just hey, Reuben says stop doing it. Listen to Reuben. Stop doing
it. Stop thinking about that. Stop thinking that cybersecurity is a technical question.
Yes,
because. Because it's not, it's not the technical part. It's only 10% of the of the problem. Normally, you have incidents with related to fishing, with other things that are not CDB problems. That have to be these incidents have to be with awareness of your yes of your people of your citizens of your workers. So stop thinking about cybersecurity. That is only a technical question and start investing in building a cybersecurity model inside your company. Just to manage Java Java awareness to just put cybersecurity in the world in the world of directors. Talk talk about risks. Do not talk about firewalls. Talk about business and do not talk about networks.
::See, I like that, Ruben. See, that's going to be a clip. I'm gonna I'm gonna make sure that that gets out and it's a clip, Antonio. And I know Reuben sort of mentioned it, but I, I need from you. Give me that. I'm a company. I've got a network. I'm doing whatever I need to do. What is that one investment that I need to make?
::The one investment, I mean, probably probably the most important investment is to change your mindset,
::yeah,
::and understand that that security is not an IT problem; it's a business decision, and the important choices. I mean, how much risk are we going to accept as a company? What are we going to protect first? Those are not technical questions. They belong to the to the to the board, to the to the leadership, not only the security teams, not only the CISOs, not only the infrastructure teams, no. When the board threats the cyber risk, like financial risk or legal risk or compliance risk, everything gets better because sometimes in the past I realized that many the leadership they think this is an IT topic, and it's not an IT topic. It's a business. It's a business topic, and it's a business problem. No, it's not just the the the the problem of the of the IT team. No, of of these nerdy guys that we don't know what they're doing. No, no, no. It's it's business as for me, that will that will that will be the the most important change that that we need to have is a is a change of the mindset.
::Yeah,
::this is that's my my opinion.
::See, what's interesting is that it this is not uncommon. Whenever I ask those questions, it's always it's always goes back to people. It goes back always. It's always people and communication. It has. It never has anything to do with the technology. I got it. The technology's over here. It's always people and and conversation. Everything. Yeah, you you two were absolutely stellar. I really enjoyed this conversation. If I was someone that was listening to this particular conversation and said, "Yeah, I I'm all about people. I'm all about conversations. I'm all about talking about how I can protect my network, Reuben, how would somebody get a hold of you, saying I want to talk to Ruben.
::Well, I think
::go out to LinkedIn. Can I just go out to LinkedIn and just say, yeah, there's Reuben. Let me contact Reuben that way.
::Well, I think that building collective resilience about all the ecosystems is what we have to do, and trying to make the maturity of just to manage the different maturity of different companies, and trying that the less mature can be more mature with time. And another thing that I think it's very important in serviceability is the relationships between the private and the public sector. For that, we have we have different organizations. For example, the Global CISO Council, that is a non-profit organization, and it aims to to to make this more dynamic, to make events, and to join people that is interested in cybersecurity, and have interesting conversations like like this
::one. Are you both out on LinkedIn? Like, if I wanted to talk to you, I can connect with you guys out on LinkedIn. Yes. Okay. Very good. Well, again, you guys were absolutely wonderful. Thank you for being on the Barcelona Cybersecurity Congress podcast. It's been great. All right, listeners, we're going to have all the contact information for Ruben and Antonio out on Industrial Talk. So fear not, you'll be able to connect with them. We're going to wrap it up on the other side. Stay tuned. We will be right back.
::You're listening to the Industrial Talk Podcast Network.
::through the fifth,:
