Christian Reinhardt with SoSafe
Industrial Talk/BCC is talking to Christian Reinhardt, Director Human Risk Management at SoSofe about “Cybersecurity psychology”.
If interested in being on the Industrial Talk show, simply contact us and let's have a quick conversation.
Finally, get your exclusive free access to the Industrial Academy and a series on “Why You Need To Podcast” for Greater Success in 2026. All links designed for keeping you current in this rapidly changing Industrial Market. Learn! Grow! Enjoy!
CHRISTIAN REINHARDT'S CONTACT INFORMATION:
Personal LinkedIn: https://www.linkedin.com/in/dr-christian-reinhardt/
Company LinkedIn: https://www.linkedin.com/company/sosafe-cyber-security/
Company Website: https://sosafe-awareness.com/
PODCAST VIDEO:
THE STRATEGIC REASON “WHY YOU NEED TO PODCAST”:
OTHER GREAT INDUSTRIAL RESOURCES:
NEOM: https://www.neom.com/en-us
Hexagon: https://hexagon.com/
Arduino: https://www.arduino.cc/
Fictiv: https://www.fictiv.com/
Hitachi Vantara: https://www.hitachivantara.com/en-us/home.html
Industrial Marketing Solutions: https://industrialtalk.com/industrial-marketing/
Industrial Academy: https://industrialtalk.com/industrial-academy/
Industrial Dojo: https://industrialtalk.com/industrial_dojo/
We the 15: https://www.wethe15.org/
YOUR INDUSTRIAL DIGITAL TOOLBOX:
LifterLMS: Get One Month Free for $1 – https://lifterlms.com/
Active Campaign: Active Campaign Link
Social Jukebox: https://www.socialjukebox.com/
Business Beatitude the Book

Do you desire a more joy-filled, deeply-enduring sense of accomplishment and success? Live your business the way you want to live with the BUSINESS BEATITUDES…The Bridge connecting sacrifice to success. YOU NEED THE BUSINESS BEATITUDES!
TAP INTO YOUR INDUSTRIAL SOUL, RESERVE YOUR COPY NOW! BE BOLD. BE BRAVE. DARE GREATLY AND CHANGE THE WORLD. GET THE BUSINESS BEATITUDES!
Reserve My Copy and My 25% Discount
Transcript
SUMMARY KEYWORDS
Cybersecurity, Human side, AI scams, Phishing attacks, Psychology, Behavior, Awareness, Training, Digital safety, Risk management, Data privacy, Employee education, Cybercrime, Security habits, Social engineering
All right. Before we get into the conversation, I want you to be aware of a conference that you need to put on your calendar, and you have time. It is the Barcelona Cybersecurity Congress. It is necessary. You need to up your cybersecurity game. You're connected. You need to make sure that you're protected right here. This event, Barcelona Cybersecurity Congress. It is November 3 through the fifth. You have time, November 3 through the fifth this year in Barcelona. And I'm telling you right now, the team at Farah who put this particular Congress on the best. You will not be disappointed, and you know what else you get to do? You get to network with some of the best cybersecurity professionals from around the world. You need to do this. You need to put this one on your calendar. All of the contact, all of the information is out on Industrial Talk. I'm going to be there. I'm going to be broadcasting. I'm going to be talking cybersecurity with the best in the world. So be there. Put this one on your calendar. That is November 3 through the fifth. I'll see you there.
Welcome to the Industrial Talk podcast with Scott Mackenzie. Scott is a passionate industry professional dedicated to transferring cutting-edge, industry-focused innovations and trends while highlighting the men and women who keep the world moving. So put on your hard hat, grab your work boots, and let's go! All
right, once again, welcome to Industrial Talk. Thank you very much for joining the number one industry-related podcast in the universe. It celebrates you, industry professionals all around the world. Yep, you're bold, you're brave, you dare greatly, you innovate, you collaborate, you're solving problems each and every day. You are making the world a better place. Thank you. You are the heroes in this story. As you can tell, if you're out on video, there it is, the Barcelona Cybersecurity Congress. We are doing podcasts and highlighting cybersecurity, and it's going to be an incredible event. If you can tell something's happening with my voice, yes, I got a little bug, but it doesn't stop me from celebrating you because we need to get this message out in the hot seat. A gentleman by the name of Christian Reinhardt, so safe is the company, and you know what we're going to be talking about-the human side of cybersecurity. He's all in. What's great? His background is sports medicine, sports psychology, if I remember correctly, yeah. Sports, sports psychology. Yes. Yeah. Paper pencil. Let's get cracking. Yeah. I'm sorry about my voice. You live and die by your voice, and then all of a sudden you wake up one morning and you say, "What's going on with my voice? But here it is. I persevere, just because you deserve it. So anyway, we're going to have this. This is another installment in this series, Barcelona Cybersecurity Congress, and I got to tell you, the conversations that we've had all out on industrial talk, we just keep on rifle them off, have been just absolutely wonderful, and and something like cybersecurity, where you're probably telling yourself, I don't want to, I want to stick my head in the sand or not really address it. The reality is, you need to, and we have great professionals all going to be at this particular Congress, focused on being able to deliver solutions that protect your business, protect your operations, protect your network, and they're just an open book. And it and I believe, in my heart of hearts, that it's imperative that we have this conversation. We can't just operate in a vacuum. So the more conversations we have in the world of cybersecurity, in the world of industry, the better. All right, here's here's a little nut. Let's see. Let me go over here. I'm looking at my calendar, or not my my computer. This is what we have. We need for you to be in Barcelona, and the the the way you want to do that. There's I have my newsletter here. You should go out to the Barcelona Cybersecurity Congress. It's next month. It's the first part of November, and I want you to enter in BCC Podcast 26. Yep, you need to do that. Get a discount. You need to do that, and you need to be a part of it. And all you have to do. I'm going to be there. Going to be talking. You need to be there, and you need to follow the lights, and let's have a conversation. We want you to succeed as always. Industrial Talk is here for you, and your cybersecurity conversation has to happen, and you need to find those Sherpas, those individuals that will help you succeed and protect your business. That's the Barcelona Cybersecurity Congress. Enter in the code BCCPODCAST26 and get your discount. All right, let's get on with the conversation because my voice is giving out. He was great, and and you know it's one thing to have the technology in cybersecurity. It's out there. Don't get me wrong. It's it's it's pretty phenomenal. It it's all out there, but to have that, it's it always gets down. And I always say this: the human side. It's always around that individual or team or whatever to be able to properly secure your network and have it. It just is, and here is Christian, and here is so safe, and we're talking about that. It's it's a great conversation. So as always, enjoy. All right, Christian, welcome to Industrial Talk, aka Barcelona Cybersecurity Congress podcast. It's great to see you. Great to have this conversation, I can't believe it. You you've got a what is that green stuff behind you? What is that? Is that a is it a green screen? What what is that? It
is like like the very very early version of a green screen, like back in the days, like when Teams and and Zoom and Skype couldn't really separate you from the background. Yeah, was my my past. Also, like if if you jump between tools and like one tool doesn't have a virtual background in them, so nobody sees the mess behind me. So kind of like data privacy and also mess protection screen.
Yeah, see, it's all wisdom. That's what it is. You bring to the table all that wisdom. Now, listeners, we're going to be talking a little bit about cybersecurity. We're going to be talking a little bit about AI scams. Yes, Christian brings a psychology associated with that, and yes, I know that you have received emails that look legit, but they're not, and you know it, and you're afraid to click on it. Christian's going to bring some real life examples and real life insights into how we can protect ourselves, specifically from your perspective as well as company's perspective, that's what I think we're going to have a great conversation. But before we get into that conversation, we need to know a little bit about Christian Reinhard. Tell us a little bit about your background.
As as you said, I'm a sports psychologist, so I didn't start off in IT, and I I would say I'm pretty far away from being IT expert, and I look at cybersecurity from the perspective of psychology. So, like from behavior, like how are we being manipulated? What tricks are attackers using? And it might sound surprising, but I believe it's also the view that the attackers have because because they are these days very sophisticated psychologists. And if you look at the recent attacks, you can see they're improving.
See, here's the problem, there, Christian. I just want to. I'll be up front.
Yes.
Again, and I think I mentioned this offline. I don't click on anything. I don't look at anything. I don't. I. I. I just always approach my emails, my you know, connections of people outside with high skepticism because I just don't know. I don't know. In fact, I get to the point, Christian, where somebody reaches out and says, "Hey, Scott, we want to have a conversation, and I'll say, "Hey, that's great. I'll look at it, and I said, "Before I have any, before I do anything, you better get on a video. You better have a conversation with me. You better be legit.
So you are at quite some level of awareness. The the the problem for me is like it it makes life difficult at some point. It it really can can isolate you, and at the same time, if you say let's jump on a video call with somebody, you right now couldn't really be sure that it's me. It could also be a good mistake. So that doesn't end with the email. That's the problem.
Now you just now I'm all called into question. Now again, I'll step back and not respond to anything. My business just stands still. It doesn't move forward. There's no progress. The thing
here also is, and that's probably the important question that you can raise in here. Like, what will this do to us as in a as a society?
Yeah.
If we if we are a zero trust society, remember how how horrible going to be!
I I got to write that one down. Zero trust. Yeah, I don't want that. That's why we're talking to you, Christian. You're going to keep me from curling up in a ball in the corner and just and just like shaking and quivering. And I thank you very much. Hey, before. We do get in that conversation. I'm really interested in SoSafe. Like, give us sort of what's the secret sauce with SoSafe. Talk to us about that real quick.
Well, we're firm believer that actually people empower security. So, based on on your well skepticism to the world, I think it's the the solution that we have these days is not to crawl up in in a corner, but to to empower people to to enable them to withstand all this this threats right now. So what we're doing is basically we have a very sophisticated psychological e-learning and combine this with a equally personalized phishing, and have a also very thorough AI application to it to support users. So what we basically do is like we train people for the for the real thing, and we have a phishing that kind of like helps people test themselves. Like will they spot the email? Um, in in your case, like is this really something you shouldn't trust, or is this actually trustworthy? How do you spot these things? And at the end of the day, and that's that's the important thing for us. Most of the attacks we see these days are psychological attacks. So if you make people psychologically strong, they'll be safe.
Yeah, that's that's that's very interesting, and I agree with you on that. So, listener, where this is this is the topic. I have a form. Every everybody who gets on Industrial Talk fills out this form, but this one, this topic jumps out, and I'm going to read it because I'm not going to do it any justice here. Why AI scams? Yep, work on smart people, and how you can stop the mechanism. I want to know briefly what what do we mean by that?
It's the there's a misunderstanding, misconception. I believe that we think it's all these only stupid people fall for cybercrime, which is like 100% incorrect. It's actually not about intelligence. Most of the attacks are successful not because we're too stupid, but it's because we're very emotional. So the the trigger that the attackers use is emotionalizing us. Like if you think about latest mails you got, they were probably very scary or cannot tell you you want something like they they use very very strong emotions, and the problem with our brains is that if we trigger very strong emotions, extremely strong emotions, some kind of a well emotional system which is very far away from the rational, so we tend to do things, even though we might be very smart people. That is very irrational, and that's why you have a lot of victims of of cybercrime. I talk to them per my job, and there's a lot of people that are actually very smart people, but they fell for a rather stupid email, or a stupid sounding email, but it it came to them in the right time and it it put the right trigger, and and then it just worked.
Why? See, here's and I'll I'll go off on a tangent right here, just because I I'm always wrestling with this. Here's the deal: I'll send an email. Some of the times it gets into junk just because I don't have an idea. I don't know what the deal is, and so it get it disappears. How do these scammers? How does the system just allow it to get through? I don't understand that. How come it just it doesn't automatically say, "Whoa, junk! Whoa, a problem! You know how?
Yes. Well, that's that's more of a technical side of things. First of all, there's there's a game of chances. Like if you send out like a certain amount of emails, some of those will go through. And and secondly, and that's probably even more important due to to a couple of ChatGPT's criminal cousins, so like AI versions that are out there that can use these emails are very close to the original thing, so it's it's it's even more difficult for our filters to to protect from those. And most of the filters they learn on what they've seen. So whenever you have something new, they haven't seen that. There's a chance you you walk through. So I think there's actually a couple of billion phishing mails sent out every day, and over the last 10 years, we we could see like there is a more or less steady rate of 15 to 18% that bypass the filters. So it's it's almost like a kind of a race. Like we we up the filters, they up their game. We up the filters, and it will go through. So that my point is, at the end of the day, like we need to have the best filters in place, no worries. But there's also there will always be a human involved in this. So if you have people that are able to detect what's happening, you're a lot safer than if you have people that don't know what to do with the emails.
So it's still if I have 18 or if I have a billion emails going out. A day and 18% make it past whatever wall I have. That's still a large number. It quite
is. It quite is. And if you think it is, it's a horrific number all over the world. This is due to like, for example, the geopolitical situation. So there's like yeah, you know, if if you're a cybercriminal in some countries, the fear of being caught is pretty low, so you can do these things. AI helps you to to do this quicker and and on a very scalable level. And the very important thing lately is if these emails arrive, like what do people do with it? So are you like I don't know? I'm getting into shock because you don't want to open any of these emails. Yeah. Or or are you able to detect the ones, or will you just be like clicking on everything that you find? And the the problem is because AI makes these attacks so cheap. We also see this on a private level, so it's not just on a company level. Also, employees get attacked on a private version, and and sometimes even targeted. Like if you look at executives, we know they are well protected in their companies, but we also know they might have a kid that uses their iPad or their smart home is not really secure, so there's a ton of ways to attack people, and I think, and that's the the good thing about awareness. I believe it's not only helping employees to get more safe, but also helping people to get more safe in their private lives. What we desperately need these days.
Yeah, it it seems so daunting, Christian. It seems so big, and it seems-it's not just-it's not just the size; it's the speed at which things are happening, right? And for me, I'm too busy living my life, whatever that might be, and to to stop, to beware, to understand. There's there's got to be a a an easier way to knowing how you protect. So, a part of the forum that we always say, "Hey, what do we need to do to solve this problem? Because we've already painted the picture. It's happening. It's happening fast, and it is both from a from a personal perspective as well from a company perspective. And there's always, and it's relentless. It just is. I mean, there's no holiday for cyber attacks. Like, hey, we're taking this off. No, it doesn't work that way. Give us some sort of general guidelines on how to protect ourselves from this particular challenge.
Let me jump on something you said. Like, there's no holidays for, for for cybercrime. Actually, very interestingly, cybercrime uses holidays. They love to use holidays. I see. We've had tons of attacks this year, especially in those short weeks. You know, like when when the Monday is a bank holiday or something, people know. Like if there's like let's say the short week, let's it's a four days week or maybe three days week. That's actually a lie, like because you you don't have less work, you just have less days for your work.
Yeah,
and so the the attackers know like in these days, like you'll just be crowded in work, and maybe on the on the Thursday or the Friday before the long weekend, you try to get like everything done so your head can rest in those three or four days off. And they know that's actually a very good time to send your phishing email because like you'll be fast on the emails. You'd probably be like thinking about oh it's going to be like cool three or four days, and if they are lucky, and you click on them on the link, then they probably have three or four days to just infiltrate the company, and nobody will know. So there is, in that sense, there is actually all it is for cybercrime. They are very aware of this, and how to protect from this is actually a rather simple move. Whenever you have an email where you're not 100 certain. Make a break. Get yourself a cup of well, lock your screen and then get yourself a cup of cup of coffee because the mechanism I explained earlier on is this emotionalization through through the context in the email that normally like goes for like 25 maximum seconds. So if you read an email and you're very shocked, after 25 or 30 seconds, like your your level of emotionalization goes down. So if you just get up, get yourself a cup of coffee, sit down again. I actually we have like I think four and a half million people in our phishing simulation, and of the people that fell for a phishing email, and I am admittedly one of those, we see that 95% of those fell for it within the first 25 seconds. So the curve is actually really going down afterwards. So and there's hardly an email that you have to remarkable.
That's a remarkable stat. I just okay. Continue. I'm sorry, man. That's remarkable.
Oh, good. But so that for me, the basic advice, like whenever you have an email, you're not 100 sure. Again, lock your screen, get yourself a cup of coffee or whatever drink you would like to have. And if you're very lucky and you like, if in a company and you find somebody at the coffee machine, like let that person have a look at the email as well, because like if you're not the the recipient, the designed recipient of the email, you'll read it less emotional, and then so the the four eyes principle has like quite some value, and and the third step, and then you mostly save, do research. So if you're not 100% sure, then like verify through other channel, not one that you find in the email, like but a channel that you know has been established, and then you actually have a very good chance of of being safe. And it doesn't really cost you much to do this. Like, and and you can use at home as well. By the way, like I have my wife look at stuff. If I say this is very sensitive, can you please check this as well before I send stuff out.
Wow, how how do you do that? And I understand this. There's a there's a lot of education that has to happen. Where do we start? Let's say I'm an organization.
Yes,
I recognize the same. I I've talked to Christian, and Christian has just sort of you know through a tsunami of information communicated. What what could happen? How do I take a company and then be able to through change management or something to be able to educate and say, "Hey, it's just FYI. This is the because it's a big deal. It's a big deal. How do you do that?
It's it's like the the biggest threat that we're facing this time, like really, like we see 90% of the attacks are focusing on humans. Yeah. So we close this door. If we enable the the the the people to be safe, it's not only that we kind of close this door. We also have kind of a alert system for what's happening. If people very early say, "Hey, we we see something that's fishy that gives you the time to to do the measures and to to apply whatever you need to apply to to stay safe. So for me, the the thing is before like before we go to the employees and say, hey, we got like tons of information for you. As you said, like this is what we need to do. Like you'll just scare them away. So I think the the first step should be like winning them over, like create some desire from them to jump on training because our work life is a different one than it was before Corona. So it's it's it's more crowded, it's faster, it's more speeded. And if you say, hey guys, I got one more topic, even if it's a good topic, people will not really start cheering. So they need to to see it has an advantage for them, and it's to some extent it's even fun. That that's important for me because like when we learn, we also learn with the emotions that we're having. So if people learn why they're scared, they will only have this in a very one-dimensional way in their brains. So, to give you a practical example, I was at a company last week, and they did a family day. So basically, they said like, "Hey, we have a event together. Please bring your kids. We'll do some stuff on like how you make your kids safer in the digital space, and so we had talk tracks. They had talk tracks for kids of certain ages and for the parents, and it was like a huge success. I think everybody who's a parent and who can make it in time will kind of jump on that train and say, "Hey, thanks. And you could also have like this is how you protect yourself from from criminals. So make it about the private life, and people see oh this is interesting and this helps me. And then on on the second note, once you spark some interest, I normally like to go in there with like something that has does create some fun. Let's have a cool story or do some true crime. Talk about like I don't know, like a prominent hack, and what happened really, and how people could have prevented it or did prevent it at some point. And then afterwards, say, hey, no, we we see this box interest. We actually have something that will make you and us safer, and we'll start this I don't know next week with this e-learning and this phishing combined, and you have to make sure that people know we're not testing you. So it's not like we want to see what's good, and whoever clicks on it goes out. It's a learning solution. It's not a test.
So what I see, this is sort of this is this is the aha moment that I and if I'm in a company, there's always a conversation around. Here's an IT group. IT group is here. We're going to create a firewall. We're going to do this. We're going to we're going to prevent that. We're going to you know, and it's very it's it's it's it's it's like an affront on productivity. You know, we're not going to do this. We're not going to do that. We're going to lock it down. We're not going to blah blah blah, and it just goes on and. But to your point, here's the stat. The stat is 90% comes through sort of penetration through a human interaction, some way, shape, or form. So all of this over here is fine, maybe needed. I get
it. Is yeah,
but you can definitely have a conversation that's not this, and it's like, hey, we get this. What this is what happens if things come in. We want to make sure that you're educated and aware, and it it all. You can you can do this. You can be a part of you know that cybersecurity strategy.
You you need to be a part of this. This is this is very important. Like you you need to be that, and when it comes to IT, of course, all the technical solutions they are necessary. I don't want to take anything away from them. No,
absolutely not. Agree.
Psychologically, we sometimes run into a problem that psychologists call learned helplessness. So we think somebody does this very well, so we don't have to focus on the technical side. They are so good, anyways. I would never understand it. So, let's just leave cybersecurity to them, and that's not going to work. And in your terms, like we all have to be a part of this. I love to give, of course, my background's in sports. I love to give like football examples, and and it's
sure
I do, especially if you get like in a production setting, like you ask people about football, that normally resonates to some level, and I love to ask them who in football is responsible for fair play, and if you let that question sink in, you have kind of like the reflex. Some of the people will point to the referee, which is a very logical and plausible answer because you see the referee with the red and yellow cards. It's, however, also a very wrong answer because like a referee can never guarantee that a game gets fair because there's 22 players and you know the the reserves and stuff. It's just too many people who want too many. A game gets fair if every player sees being fair is his or her own responsibility, and they'll accept it. And you can kind of translate this to cybersecurity, because like afterwards, I like to ask the question like, "Who here is responsible for cybersecurity? And the people that have pointed at the referee before will then point at the CISO or whoever is in charge in their company, which is the same thing. It's also logical, but but also not entirely true. As much as a game gets fair if every player accepts this responsibility, a company gets safe if every employee accepts this responsibility. So they have to see. Yeah, they are a part of it. Like the the IT people, they can't do it on their own. It's it's impossible to do. It
is.
It is on them. It's on on everybody.
See, and what what I I see the benefit. Let's say I go to work and I'm on the the computer and I'm doing my thing, and then I had this education opportunity to say, Hey, here's some here here's an example of something that's not good. It is it's it's a it's an email, whatever it might be, something simple. I can wrap my arms around it. I can understand that conversation, but the benefit is, when I go home, I have a computer at home.
Yeah,
I'm I'm I'm smarter. I'm a little bit more savvy when it comes to these these you know phishing threats or whatever it might be, and I and I see that's the benefit, and and it doesn't have to be. And correct me if I'm wrong. It doesn't have to be a hammer over the head. It could be just saying, "Hey, here's an example. Boom, and you can just sort of create that that very easy conversation with these individuals, and then and just keep at it. Keep don't don't say one and done. It's just keep just going. Hey, here's another one. Here's a new threat because it's it's always changing, right?
That's the thing. You actually, this is like the one of the the topics where you never learned everything because they are constantly evolving, and I'm completely with you. We we should not scare people. In fact, the opposite is very effective. If people see like people that probably like me, I actually I'm not an IT guy, and I think I was like extremely far away from being an IT person. At least that's what my IT people tell me. But but the thing is, like when I learned to spot the first email and say, "Oh, this is actually a mechanism. Okay, this is how I'm triggered. This is what's happening. You like feel the self-efficacy in this. Like I say, I can do this, and and you you you learn. This is a field where I thought always thought I'm not really a skill at anything there, and you say, okay, like I'm improving, I'm getting better, and this is very motivating. If you just throw stuff at people and drown them, it's extremely unmotivating.
Yeah,
you just lose them. So like build them up slowly, and and also very importantly make them aware of their progress because sometimes we we tend yeah that's a good
one yeah
yeah because cybersecurity is very much focused on the catastrophic narrative like like how many billions of dollars have we lost like how big is the threat like what happened how many jobs have we lost. But if you see, like, hey, we we tested this email and actually like 80% spotted it. Maybe maybe 60% reported it correctly to us. So it's like focus on these things. There's, I'm a very big fan of these cyber hero stories. So if you find an employee who sees something and and reports it, and then everybody else can be protected because IT knows it. Then don't just like say okay that was good, but like highlight the person. So there's there's a person that people see as their colleague, not an IT pro probably, and that person's done something very well. So show everybody this is doable, and we improving because when we do training, no matter how good the training is, we'll ask people to do something on top of what they are doing, so we also have to give them the the feedback of how how they are performing. Is there time for one more sports example?
Yeah.
Okay. Then this is
my podcast. I can do whatever I want. Nobody's breathing down my back. I just
want to have your permission, Christian. No, give me
another sports analogy because I'm I'm eating this up.
So the the there's a study I guess by the way of a whole of Europe and it's very much the same. If we sign up for a gym to go there, there's a there's an average of three months that we actually go there, and then we separately end. Yes, we we we still pay our our fees, but like we don't really go there regularly anymore, to to very large extent. And there's a there's a very simple reason for this is because like most people start a gym with a very well unrealistic idea or expectation of what's going to happen. So
yeah, we
go to the gym and think we'll be Arnold in three months, and then after three months we look into the mirror and we don't really see the progress we've expected. So we lose the motivation and we leave. And that's by the way why people that have personal trainers they stay a lot longer for a very simple reason because they make it visible to them what happens. Because if you stand in front of the mirror after three months, there's like tons of very good improvements. Just some of them are not visible to you, or not in the way that you expect them. Your cardiovascular system, your your neuromuscular effect, everything is improved by by quite some margin. You'll be a lot healthier, but it's probably not what you expected in terms of improvements. So for me, it's very important to not lose the people in awareness, like we normally lose people in the gym, by by making them aware of the progress. Like show them how much they have improved, like where they started, where they are now, and how we are going forward. It's very important because, as you said, like the field is constantly evolving, so they need to learn basically for the rest of their lives, as as far as it looks right now, and that's only going to happen if it's to some extent enjoyable for them. Otherwise, you lose them somewhere along the way, and then it's it's done.
See, I'm back to the gym analogy, right? I go all the time. That's my B. I do it
all the
time, but it was a starting of okay. Set the expectation. 10 minutes. I'm not overwhelmed. I'm just
yeah.
I'm just looking for success at getting there for 10 minutes. Just 10 minutes, and then I would tell myself, done. I'm out of here, right? And then you just progressively evolve over a period of time, but really, you set it's like it. It the analogy is that let's say, hey, we're just going to have a cyber minute here. This is the latest phishing. This is Joe Blow caught this in his inbox, put it, brought it to our attention. FYI, good job, Joe. Way to go, team.
Yes, move
on. And I can I can put my arm around that.
That's perfect.
Yeah.
That's and as you said, like the the we we build habits not through like a spectacular gym day where we like completely kill ourselves.
Yeah.
But over the consistency, like so. So if you're listening to the podcast right now, and you think cybersecurity is cool, but I also want to start over with our fitness program. Don't go all in, but like do it regularly and and and be persistent. And then it's easy to kind of upgrade it, but like make it make it a part of your life.
Yeah, and
it's the same with cybersecurity. If it's there at some point, it's easier to to like say okay we need to do more or a different version, but it it's gotta be like a regular part of your being. Like let's say in terms of habits, if you stand up from your computer, the pressing the the button to lock your screen, for example, that should just be like a reflex. It's like I don't know if you do that, but like if I leave the house. I check my pockets for my my mobile phone, my my purse, and my my keys. And normally, if something misses, I turn around. It's problematic if if I miss the key. But but the thing for me is, you have these habits, and you can just develop them by just doing it again and again and again. And it doesn't have to be like the very big change. So don't scare.
No, yeah, I think you're onto something here, and I think that it's it. I believe, done right, I believe big dividends are waiting. Doesn't have to be, you know, talking, you know, zeros and ones over here in the tech world. It's really that human component that we really need to be able to educate, and I and I I always have a what's the biggest roadblock? This sounds great. This seems very doable. This is achievable for organizations and personal safety. Why do we still struggle with this?
Exactly. There's this. I see exactly the point that you're having. We actually, to be very honest, I don't think we're struggling that much because we're very much improving. I can see, like when when I started in this field like six years ago, it's. I talked to companies, said like, "Hey, do you know what phishing is? And people go like, "No, explain to me to get you know these kind of emails. Ah, yeah, let's talk about it.
Yeah,
these days when I go to companies, they are aware of the threat. They they know these things. Some of the companies are actually pretty mature in in this in this field. And I see in in I think in Netherlands and in some countries it is even a subject as school. So we we are improving. We're very much improving in the field, but I think just we need to to take up speed, and especially those companies that have not yet started. They they need to to do it right now, or they'll be left behind. Left behind. I mean, really, in in these terms, at this time, it's not a question whether you you'll be attacked. It's just like when, and so so it it I don't want to bash anybody if they haven't done it. There will be a reason, but I would like highly recommend starting right now, starting with like these little steps that we talked about, like win people over, give them the first good experiences, and then like kind of like slightly upgrade it, and you'll have like very big effects in a couple of months. And so the the thing for me is, if you've missed the train, there's no reason to not chase it.
Yeah, go after it. I agree with that. That's why. That's why that was a great segue, Christian. The Barcelona Cybersecurity Congress. You get to meet people like Christian and others. That yeah, I like that. Just just move forward. And and and honestly, Christian, we we do talk. There's a lot of conversations when we start talking about cybersecurity, what to do, the challenges, the threats, whatever, and and it and it can be quite technical. This is a great conversation because this is consumable. I can, I can, I can handle this. I understand. I can be a part of the success, and I think that that's just a wonderful message, Christian. Excellent job. See, now I'm not going to curl up in the corner and be all wimpy about the whole thing. I'm not going to be able. You are absolutely wonderful. How do people, if they're saying, "Yep, I like what Christian's talking about, how do people get a hold of you? What's the best way to get a hold of you?
Well, first of all, it's obviously the the cybersecurity congress where I'll be like all day for for every day. That's probably the easiest way, and I have a couple of colleagues there with me as well. They are equally deep in in the topic. Otherwise, like you'll probably leave my LinkedIn somewhere here or develop your dissociate homepage. There's a couple of ways to to reach out. I just want to say, like the the topic that we're talking about today, for like for me, is is incredibly rewarding because it's it's not just it's not just making the company safe. It also makes the people safe, and our world is getting more more and more digital, so if people are not safely navigating through this space, they will lose access to so much life quality. So we also need to make them better place.
See, I can. I'm, I'm ready to tackle this day, and and because of you, that was great. Thanks so much, Jack. Thank you for being on the podcast, that was an absolutely wonderful conversation, and I will see you at the Barcelona Cybersecurity Congress. I can't wait to meet you in person. Are you tall or short or big?
I, I think I'm like 100% average.
Okay, here comes average guy. You see, average guy.
Guess what?
good, man. All right, listeners, we're going to have all the contact information for Christian out on Industrial Talk. This is a must connect. This is doable. This will help you succeed, both from a company perspective and a personal perspective. It it it's an. Absolute must. This was great. BCC, Barcelona Cybersecurity Congress. All of that information is out on Industrial Talk. We're going to wrap it up on the other side. Stay tuned. We will be right back.
You're listening to the Industrial Talk Podcast Network.
Yes, you need to get your cybersecurity house in order. You need to attend the Barcelona Cybersecurity Congress that is November 3 through the fifth, and meet the best cybersecurity leaders in the world to help you along on your cybersecurity journey and who are protecting our future. Enter promo code BCCPODCAST26 and get your discount. I will be there. I would like to see you there. Talk soon. There it is, Christian. That was an outstanding conversation. Really enjoyed that nuts and bolts about the human side of cybersecurity. You know what's weird? Just I'm going to share this with you. I have a clogged ear, and I live with sound. I live talking about industry, cybersecurity, of course, and I can't hear out of one of my ears. It's weird. I'm off balance. If you're seeing me on videos, I'm off balance. But again, we persevere because the story needs to be told. So safe is the company. The event that you need to put on your calendar is, of course, the Barcelona Cybersecurity Congress put it out there. You got a month. You got time. Make it happen. Come visit me. Look. Follow the lights, and I will be there. And I want to meet you. Let's have a conversation. All right, Christian Reinhart. Reach out to him. All his contact information. You need trusted individuals to help you along on your cybersecurity journey. Goes without saying, make it happen. Anyway, again, Barcelona Cybersecurity Congress. This podcast. We're going to have more conversations about cybersecurity because you need to be bold. You need to hang out with Christian. You need to be brave. Hang out with Christian, and you need to be able to handle your cybersecurity challenges. And you need to be able to talk to Christian. All right, we're going to have another great conversation coming to you from the Barcelona Cybersecurity Podcast, so always stay tuned.
