Darren James with Specops Software

Darren James Graphic

Industrial Talk/BCC is talking to Darren James, Head of Internal IT at Specops Software about “Zero Trust, Identity First Architecture”.

Overview

The conversation explained how Specops helps organizations verify identity and secure cloud access against AI-enabled attacks.

Identity Security

  • Darren described service-desk identity verification using government-issued identification, selfie checks, and biometric liveness detection rather than knowledge-based questions or voice recognition.
  • Verification can be enforced before sensitive actions such as password resets; unsuccessful verification prevents the service-desk agent from proceeding.

Cloud Protection

  • Strong passwords and MFA do not fully prevent attacks involving social engineering, man-in-the-middle phishing, information stealers, or stolen session cookies.
  • Specops, part of Outpost24, emphasizes device trust and identity-first, zero-trust access while minimizing user friction through self-service remediation and grace periods.
  • Open question: How can organizations close security gaps between cloud point solutions while preserving productivity?

Outline

Company And Expertise

  • Darren discussed his 15 years in cybersecurity and prior IT experience.
  • Specops specializes in identity verification and access protection within Outpost24.

AI-Enabled Threats

  • Attackers can use publicly available information, voice samples, deepfakes, and social engineering to impersonate employees.
  • AI-generated phishing can capture credentials, MFA responses, and session cookies through proxy attacks.
  • Information stealers can extract passwords, usernames, and session cookies from compromised devices.

Security Approach

  • Government-issued ID validation is combined with selfie matching and liveness checks.
  • Device trust limits access to approved devices, shifting the security perimeter from the network to the endpoint.
  • Self-service fixes and grace periods are intended to reduce operational friction.

Industry Context

  • The discussion promoted the Barcelona Cybersecurity Congress and referenced BCCPodcast26 as a discount code.
  • Darren and Scott planned to continue the conversation at the event.

If interested in being on the Industrial Talk show, simply contact us and let's have a quick conversation.

Finally, get your exclusive free access to the Industrial Academy and a series on “Why You Need To Podcast” for Greater Success in 2026. All links designed for keeping you current in this rapidly changing Industrial Market. Learn! Grow! Enjoy!

DARREN JAMES'S CONTACT INFORMATION:

Personal LinkedIn: https://www.linkedin.com/in/darren-james-91055310/

Company LinkedIn: https://www.linkedin.com/company/specops-software/

Company Website: https://specopssoft.com/product/specops-password-policy/

PODCAST VIDEO:

THE STRATEGIC REASON “WHY YOU NEED TO PODCAST”:

OTHER GREAT INDUSTRIAL RESOURCES:

NEOMhttps://www.neom.com/en-us

Hexagon: https://hexagon.com/

Arduino: https://www.arduino.cc/

Fictiv: https://www.fictiv.com/

Hitachi Vantara: https://www.hitachivantara.com/en-us/home.html

Industrial Marketing Solutions:  https://industrialtalk.com/industrial-marketing/

Industrial Academy: https://industrialtalk.com/industrial-academy/

Industrial Dojo: https://industrialtalk.com/industrial_dojo/

We the 15: https://www.wethe15.org/

YOUR INDUSTRIAL DIGITAL TOOLBOX:

LifterLMS: Get One Month Free for $1 – https://lifterlms.com/

Active Campaign: Active Campaign Link

Social Jukebox: https://www.socialjukebox.com/

Business Beatitude the Book

Do you desire a more joy-filled, deeply-enduring sense of accomplishment and success? Live your business the way you want to live with the BUSINESS BEATITUDES…The Bridge connecting sacrifice to success. YOU NEED THE BUSINESS BEATITUDES!

TAP INTO YOUR INDUSTRIAL SOUL, RESERVE YOUR COPY NOW! BE BOLD. BE BRAVE. DARE GREATLY AND CHANGE THE WORLD. GET THE BUSINESS BEATITUDES!

Reserve My Copy and My 25% Discount

Industrial Talk/BCC is talking to Darren James, Head of Internal IT at Specops Software about "Zero Trust, Identity First Architecture". The conversation explained how Specops helps organizations verify identity and secure cloud access against AI-enabled attacks.
Transcript

SUMMARY KEYWORDS

Cloud security, Identity, Cybersecurity, Cyber threats, Cybercrime, Cyber defense, Network security, Network protection, Access control, Access management, Identity verification, Identity proofing, Biometric liveness, Biometric authentication, Device trust</

00:04

Welcome to the Industrial Talk podcast with Scott Mackenzie. Scott is a passionate industry professional dedicated to transferring cutting-edge, industry-focused innovations and trends while highlighting the men and women who keep the world moving. So put on your hard hat, grab your work boots and let's go!

00:21

All right, once again, welcome to Industrial Talk. Thank you very, very, very much for joining the number one industrial-related podcast in a universe that celebrates you, industry professionals all around the world. I say it once. I say it a million times. You're bold. You're brave. You dare greatly, you innovate, you collaborate, you're solving problems each and every day, and you know what? You're making the world a better place. That's why we celebrate you on Industrial Talk. That's why you are the heroes in this story. As you can tell by the back, it's another Barcelona Cybersecurity Congress podcast. We're featuring a gentleman by the name of Darren James talking Specops, which is a cool name, by the way. Specops software, and how that is going to be protecting you, and how you are going to succeed using that platform and connecting with Darren. Let's get cracking. That's right off the bat. You connect with him because in the conversation, Darren has a high beer factor. That means he's fine. He's a great hang. Yeah, you know he's. You just got to do it. Yeah, and he'll and and and definitely has a passion. I always I always struggle on video to create a heart. He's got a heart for your success. I can never do that real well. It probably could. Anyway, yeah, Darren Specops Software. It's part of a company called Outpost 24. All the way in Europe, but they're big footprint. They're fantastic, and they're going to be at the Barcelona Cybersecurity Congress. And as you can tell by the promo in the beginning, it's right around the corner. You need to definitely put this one on your calendar. Make it happen. You can. You get a flight. You go there, you you stay in a place, and then you you get to interact with all of the great cybersecurity professionals around the world. Yeah, try to pull coals in that. You can't. It's an exceptional time, and I'll be there, and I'll be broadcasting. I'll have my podcast booth there, talking, chirping, and having great conversations, and if you're there, follow the lights. I'll be right there. All right, there are a couple of things that I want to make sure that you put on your calendar, not calendar, on your to-do list. We want you to succeed. Industrial Talk wants you to succeed. Yep, we do. It's a, it's a, it's a must. You have to, you just have to, and there are four things that I always like to make sure that is on top of mind, and as you think through it, and why this is important. First off, you need to figure out how to podcast, tell your story. You need to get that face, you need to get that personality out there, and why people want to connect with you, create that friendship. That's what this is all about. I have stories upon stories of why this is a great platform and how it has helped, how it has helped companies open up opportunities. It's amazing. That's one. Two, you get a podcast, and then you just have conversations with your clients. How about that? Everybody wins in that one. They they talk about why they're they're wonderful. They like that. They talk about why they have a relationship with you, and that's always positive. That's it's win win. That's the second part of the stool. The third part of the stool is that you have prospects. Yeah, there's there's somebody I want to connect with. Right now, the only way you have a way of connecting is I walk up. Hi, I'm Scott, and I am blah blah blah blah blah. How about changing, being disruptive, and have a podcast that you can go up and say, "Hey, Joe, I see that you you guys have great product. We need to get you on the podcast and have that conversation, knowing full well that you want to create that relationship because you see it as an opportunity for your company. It's that easy. That's the third. The fourth, you go to conferences. I go to conferences, Barcelona Cybersecurity Congress. You know what I'm going to be doing? Talking to people, creating relationships, creating friendships. And you know what else? If you have a podcast that you have at events, it's. Just creates one great will. They love it.

05:02

Whoever's talking on it, they love it. So that's good. That's positive. That's optimistic. Two, everybody wants their podcast. You know, you have a podcast. When is it coming out? When will I hear myself? When will I blah blah blah? That's two. So there's stickiness. But three, you get better traction from prospects that you have created as a result of going to that conference, which is why you go to conferences and create relationships and connections so that there's opportunities in the future. You put podcasts in the middle of that, yeah, you're rocking and rolling-that's disruptive. That's what you need. Trust me. And then, the icing on the cake-you have content. You don't have to struggle with what kind of content. You have it right there. It's all ready to go. You backlink. You do everything. It's-it is off the charts a positive experience. Go out to industrial talk, have a conversation with me. At a minimum, just figure it out. We need you to succeed. Here is, here it is. If you're out on the video, I have a key, key to your success. Ah, that's pretty, that's pretty cheesy. Anyway, hey, let's get on with conversation because I certainly want you to hear him again. Hi, Beer Factor. Darren James knows what he's talking about. It's a must connect. He's with Specops Software again. Great name, and we're going to be at the Barcelona Cybersecurity Congress. Everybody, all of the cool cybersecurity kids are going to be hanging out at that event, so put this one on your calendar. All right, here is Darren. Darren, welcome to Industrial Talk. How are you doing today?

06:52

I am amazing. All the better for talking to you. It is

06:56

a highlight. It will be a highlight of your day, but it's at the end of the day. But I agree with you, and and and have to you know, truth be told, I'm pretty doggone excited about having this conversation. You know why? Because we're part of the BCC, the Barcelona Cybersecurity Congress. This is what this conversation is all about. We're going to be diving into cybersecurity stuff, specifically cloud security. This is his form, by the way. Just FYI, I'm not rattling this off. I'm I'm looking at it and reading. So yeah, cloud security, zero trust, and identity first architecture. It's a mouthful, but we're going to be talking about it, and we need to talk about it. And you, industrial professionals, need to take your cybersecurity to the next level. It's happening, whether you like it or not. We want you to succeed. Here's Darren, and he's going to share pearls of cybersecurity wisdoms. Okay, there you go. I'm all worked out now. I'm exhausted, but we're going to be in Barcelona, and we're going to have a couple of adult beverages, and we're going to have a good conversation. Specifically, there's like a plan. Yeah, Star Wars, and then complain about Star Wars. All right, yeah. Before we get chirping on the subject matter of cloud security, we need for you to give us a little background on who Darren is and why you're such an incredible professional.

08:20

Well, I've been in well cybersecurity industry for 15 years, but prior to that, I my roots have always been in IT. So I've come up through the ranks from service desk agent to desktop support, server support, running entire Active Directories for all sorts of global companies, and I bumped into Specops 15 years ago at a Teka conference in Berlin. Asked them a difficult question that they couldn't help me with, but at the end of that conversation, they said, "Hey, if you're ever thinking of changing, looking for a new job or changing roles, give me a call. And here we are, 15 years later.

09:02

That never happens. Never. That happens.

09:05

That happens.

09:07

Wow. I just wish I lost some more

09:10

money at the time, but but never mind.

09:13

So you've seen some changes being in the IT world. You've seen some changes. So when you were when you were answering phones, were you answering phones? Were you were you trying to field questions of people who were having a hard time in IT?

09:27

Yeah, yeah.

09:30

Was it?

09:31

Yeah. Well, yeah. Well, we you know the the perennial question. I forgot my password. You know, and that's one of the one of the things that we do at Specops is, you know, how do you how do you know how do I know it's Scott that I'm talking to you today, and not some deep fake Russian version of Scott that's pretending to be Scott? So it's all those sorts of things.

09:52

See, that's really interesting. So yeah, that was a nice segue, and I was I was getting ready to wrap on some people. Complaining about being on, you know, listening to calls on IT, and then you just brought me back to what the call. This conversation is all about. Appreciate it. That was very skilled.

10:10

There you go. Anyone think I've been doing it for 15 years?

10:13

So, give us a little, just an overview of what Specops does, which is pretty cool, doggone name. Just FYI.

10:24

;ve been going since:

11:13

I, I don't know how you do it, quite frankly, and it's getting more and more challenging to do that. I, I suspect I can't. Here I am, way out. I'm way over the skis, but I'm just sort of you know thinking about it. I'm going okay because I'll just. I don't trust anybody out there other. I don't trust because I I know that it could be you know some ugly guy like me coming across, like you know, and and just I just don't trust. So you ensure, if that's a a word that I can use, you ensure companies understand that you know Darren's Darren, Scott Scott, you know Joe blows Joe Blow, and so on and so forth on the network, and and it's and that's where they need to be. That's what that's what I hear. Is that correct?

12:07

Exactly. Yeah. I mean that that's the that's really what the nuts and bolts of what we do, because it's so easy, as you say today, to steal someone's credentials or even steal their even steal their session token. I know we're getting complicated straight away, but attackers they attackers have evolved. So you know we come up with stronger passwords. We deploy MFA, but attackers don't just oh say oh we'll give up we'll go and we'll go and do proper jobs. They find other ways of of compromising you. So whether that's social engineering or or whatever. Whoa, whoa, whoa, whoa,

12:46

whoa, whoa! I got to back up. Social engineering. What do you mean by that? That sounds cool. Well,

12:52

I don't know. Well, let's say let's say I'm let's say you work for for I don't know, but but industrial time. Yeah, go ahead. Let's say you work for a bank, any bank.

13:07

Yep.

13:08

And and you you're you're a you know on the road. You're traveling around seeing customers and clients.

13:16

Yep.

13:16

And and me as a bad guy, I've looked you up on LinkedIn, and I know I know what you do. I know who you work for. I might know your bosses. I might just ask AI who is Scott Mackenzie. Give me some background on Scott Mackenzie, who he works with. I can find all of that out really easily today.

13:36

Yeah, you can. And then

13:37

maybe and then maybe you know I've watched a couple of your presentations, and I've I can get a sample of your voice, or even I've just ring you up. I find I find your mobile phone phone number. I ring you up, and then I start building this profile of you. And again, but again, this isn't a this isn't something that's nation state. You know, you have to be a you know the Russian or the US or the British or the North Korean government to do this, anyone can do this these days with AI. I build up this profile, and then I ring your service desk up, and I say, "Hi, it's Scott here, and I say it in your voice, with your mannerisms, and then, oh yeah, yeah, yeah. It's Dave, isn't it? You work on the service desk. Yeah, I used to work with your boss, Jim. And

14:26

then, what?

14:28

Yeah. Oh, and then, and then, you know, in the background, the service desk agent can hear like a kid crying. Oh, yeah. Sorry, it's my daughter. She's she's crying. I've forgotten my password, and I've got this really important customer meeting. I've got to. Can you help me? Can you sort sort me out with a new password, please? Yeah, sorry, darling. I'll be with you in a second. You know that that kind of thing. The poor service desk agent is now stuck. You know they're they're programmed to be helping their their callers. They're not security experts. They they they don't they need to help you close the call, move on to the next one. So you've just given that guy loads of of assurance. Yeah, he knows that he knows you. He knows your boss. He's described how he works, what he does. We know he might he might have even known you. He might say, well, yeah, I know he's got a daughter who's who's young. Look, okay, no problem. I can see you're under a lot of pressure. I'll just reset your password for you. But it's not, of course, it's not you.

15:30

No, it's

15:31

me.

15:31

No, my my head is about to explode. That is incredible.

15:38

Yeah,

15:39

dude. And it's holy cow. Take note. Okay, we're we're gonna have this conversation offline just because my voice is always out there. Now I'm now now I'm all nervous and skittery. You know, I don't want that. It's me. It's me. That so industrial. If I'm not call it, I'm not calling you. Let's put it that way. So don't listen to anybody that sounds like me. Okay, so here you are. You've got that particular. Let's say that use case.

16:08

Pretty,

16:09

pretty compelling use case. That's amazing. What does Specops do to ensure that that doesn't happen? That that's protected. I I need to hear exactly because that that's all doable.

16:23

Yeah, absolutely. So, I mean, we have solutions that allow the service desk agent to verify who you are. And don't get me wrong, some some companies or a lot of companies kind of do this already, but they probably use knowledge based factors like what's your date of birth? You know, how many times have you rang up a a company and they said, "Okay, we just need to check who you say you are. Can you give me your zip code or postcode in the UK, and then give me your date of birth?

16:54

Yeah. How

16:54

how difficult do you think it would be for me to find out your your postcode and your date of birth.

17:00

Yeah, you you run an AI agent. Boom, done. Scrape. Done.

17:05

Exactly. So, yeah, great. If you're relying on knowledge-based factors, that's terrible. If you're relying on the sound of somebody's voice, no chance. So we have a solution that can doesn't rely on any of those sorts of things, and one of the things that we're we're doing recently is using a government issued ID. So things like a driving license or a passport.

17:32

Yeah,

17:33

we can check the validity of that driving license or a passport, and then we do a selfie, and we make sure. So you see me moving my head around and with this background here. So when you deep fake a face, it it gets jagged, like like like the background is as I'm moving around here.

17:54

Yeah, it's not

17:55

perfect. So when we do the selfie, we ask that ask the user just to move their head around in certain directions, and then we compare that face to the face on the driving license or the mask. So we make sure that you've got a valid document, and we make sure the person holding that document matches the face on that document.

18:14

And and no matter how much technology can be deployed, there will always be inconsistencies with the face, right? Let's say I'm an AI generated face of me. Yes, your your solution says no, that's not exactly just a scott too close or whatever it might be. Whatever.

18:36

Yeah, yeah. Or or again, the dimension, the the way the light falls on the face as you're moving your head around, it can tell that it's a a flat photo rather than someone wearing a mask rather than than an actual real live person. So yeah, this biometric liveness plus an identity, amazing way of doing it.

18:55

So I I have to digress here. I use a solution or a service called clear. Get through. Yeah, and and it has evolved. I was I was all in when I first started and came out. I said I'm in, and then we just get it. Just gets to a point where we just walk up to the gate, bam, hits the face, done, validated, move on.

19:19

Yep, it's essentially the same, the same solution that Clear uses, but we we do it for workforce everyday transactions.

19:29

So if I'm a if I'm calling in and I'm a fake person, I'm calling into the service desk. How do you validate that scenario? I'm not on a video. I'm I'm just it's my voice. I'm just and my kids crying in the background, all fake. Yeah, but it's. I'm trying to create that. How do you validate something like that? I get the face thing. That's cool.

19:50

Yeah. Well, again, it doesn't need to be on a video. So all we do is we we send a link to the user via well anybody's phone or an email address. Yes, it doesn't really matter because it's not the sending. It's not the actual sending of the link that matters. What matters is that they they're in possession of a driving license that's that's legit, or a passport that's legit. Plus, they are that person on the driving license. That's the important bits.

20:17

So the process says, "Yep,

20:18

it's all matched. You're good.

20:20

So the process is: is if I call in and then you say, "Hey, that's great. It's great talking to you, Scott. Here, here's a link. I'm going to send it to your cell phone right now. Bloom, take care of that. And then we'll have you know when when you validate whatever whatever that takes a few seconds. Boom, there it

20:37

is. Yeah.

20:38

How do you what what do you do in a situation a scenario to say, hey, I'm Scott, and you send that link to my whatever cell phone, and it's not me. What type of data document? What what do you pull in and say, hey, that something's wrong. There's something going on that's not legit. What do you do now?

21:01

Well, we enforce that control, right? So, so let's say you were asking for a password reset. We wouldn't. The service desk agent wouldn't be able to get to the password resets point until we've got a successful verification. So, at that point, all they can do is put the phone down.

21:21

Shit, that's just yeah.

21:22

So you've got to be able to enforce it. You can't you can't leave it optional. But I mean, that's just one way of doing it. We've got a whole host of others as well. Yeah, that's that's

21:31

an incredibly visually stimulating use case. I mean, it's just that's that's pretty amazing. And again, I'm going to digress again. Going off on a tangent here, it's it's becoming more and more challenging because of AI to be able to recreate my voice or my mugshot or whatever it might be. You being in the industry for 15 years with Specops, have you seen that escalate, or has it always been? You've just seen a. It's changed.

22:11

Yeah, absolutely. I mean, if you go back what five years, it was it was you had to be a nation state sponsored threat actor to to do stuff like that, but with the advent of AI, it's kids in their back bedrooms can do it now. We saw it last. Well, I guess you you heard of the MGM attack, right? That

22:35

happened

22:35

back in:

23:23

Yeah, I I don't know how you keep up with that. Yeah, and it's and and the proliferation of of individuals that have that capability just it's going through the roof, right? It's just and it's

23:37

you can. I mean, there's control. There's controls in you know the the well known AI solutions out there. Your Claude's and Open Teams, OpenAI, those sorts of things. But there are plenty of dark web AI resources these days that don't have guardrails that you can do whatever you want with, and it costs pennies to to buy those solutions.

24:03

Yeah, yeah. I I I I. So we have what we had was we had a use case. Great, that was fantastic. Darren got it. Now we have a solution that absolutely ensures that I'm not going to be penetrated through this sort of, you know, nefarious methodology. What keeps you Specops, you, Darren, up at night? What, what, what are we missing as an industry? What, what do you see? What is that? Not, not. I don't want you to, you know, giving me anything that's like not. I just I'm interested. What do you see?

24:45

I mean, the thing that worries me the most is lots of. So I mean, that's just one use case, right? Oh, yeah. I would talk use

24:53

cases all day long. If we had beer, I would talk about them all the time. What about this? What about that? Yeah,

25:00

but I mean, one one thing I speak to a lot of customers or prospects, companies in general, and whether it's you know face to face or on Teams calls or whatever it might be, you know we we often hear that you know they think they've done everything right. They've got strong passwords. They deployed MFA, but they've still got all of these cloud systems they log into, and they still see people getting attacked. They still get see other companies or even themselves getting attacked, and they wonder how it happens. You know, they've put all of this technology, all of this money in place to make these things happen.

25:41

Yeah.

25:41

What's what? How are these guys still getting in? And it's these gaps. It's the gaps between these different point solutions that you need to plug. And you know, a typical one where people think, no, I've got MFA, I'm good. I'm I've got it covered. I've got my you know Microsoft Authenticator, and I've got my strong password or I've got my passkey. I'm good. The problem is is that attackers have involved. So social engineering is one way of gaining access to your servers, but another way is stealing things like session cookies, and that can be done through phishing. So do you know what session cookie

26:21

is? You're going to have to explain that to dumb people like me.

26:24

All right, so you know, so you go to a website, you type in your password, and you go, "Yep, here's my password, and then it says, "Right, we've now sent you a text, you know, an MFA, and you type in the one-time password from your text, or you put your UB key in, or whatever it might be, and then you're in. Brilliant! You've got to your, you've got to your your website that you want to access. The reason you're in is that though your password plus that UB key or one-time passcode that's been sent to your phone, that's created something called a session cookie. All right, that says, "Yep, Scott has just authenticated successfully with both of these things, and now he can carry on through that website, whether it's watching Netflix or buying something from Amazon or accessing his Gmail or whatever Office 365, whatever it might be. So, if I'm a bad guy, I could spend loads of time trying to guess your password or get you to get you to pressure accept on your on your MFA token, or I could just steal your session cookie. And you might think, well, how do you do that?

27:33

Yep, I mean I am thinking that you're absolutely right. How do you do that?

27:36

So there's a couple of ways. So first of all, I can send you a phish, you know, phishing email or a text, or get you to click on a link somehow. So you know, Microsoft.com with a zero instead of an O, that kind of thing. Yeah, and and you might think, well, I'm not going to fall for that, Darren. You know that you know I've seen a million phishing emails. Yes, but the AI, but they used to be full of really bad English or spelling mistakes, or they get stuff wrong. AI creates a really good email that looks just like the one that your boss might send you, and then yeah, there's a link in it. You click it, and you're done. And and the reason you're done is that it takes you off to a man in the middle attack, a proxy, so it looks like Microsoft.com. You type in your password, you type your username, type your password in. It then sends your authentication request actually to Microsoft, and Microsoft says, "Oh, I can see Scott logging in. Scott, can you can you do your your MFA factor? And you go, "Yes, and then your session cookie is sent through that proxy, and the bad guy grabs it, and then he logs in as you from his machine with just your session to with just your session token. Another way of doing it, which we've seen a lot of recently, is info stealers, and there was a great example where a guy was playing Roblox. You heard the Roblox, the kids' game, video game. Oh, oh yeah. Oh, oh yeah.

29:11

Ah, yeah.

29:13

So playing playing Roblox, downloaded a cheat for Roblox off some dodgy website. Didn't realize that the cheat included something called the Illuma Info Stealer, and that info stealer was was taking his passwords, his usernames, his session cookies. Tell it anything he was typing into any other website was being captured and sent back to the bad guy. So the bad guy once again gets hold of the session cookie, logs into the guy's workplace, jumps on their network, pivots to their customers' network, and then compromises their customers. So this man in the middle and this info stealer plus social engineering, MFA's been used. You've gone. You've done everything right, but you're still getting attacked. It

29:59

sounds. To me, Darren, like it's a human equation. I mean, I get again. I'm. I don't click on anything. I have my step. I click here. I click there. I try to as much as I possibly can not to do that. And you're right. Some of those emails, they they they're amazing. They're amazing. They make

30:22

you think, don't they? They go, is that really from from the government from the you know the the IRS or HMRC in the UK?

30:31

Exactly.

30:32

Yeah,

30:32

and and if if if I'm bad person and I've got this and I fire it out, right? There's going to be a percentage, whatever that is, that's going to say, "Okay, click and go, boom, done.

30:50

Yeah.

30:51

How, in in the world of business, in the world of these companies that you deal with, how do you continue to be nimble enough to take into consideration all of these things that are taking place, how it changes all the time, Darren.

31:09

Well, exactly, and and and you're you're 100% correct, Scott. So, and when it comes to cybersecurity these days, AI has fundamentally changed the economics of it, so the bad guy only has to get, only has to find one person, right? He might send a, he might send a million emails out. He only has to find one. Yeah, but you, as the cy as the cybersecurity guy in the in the company, you've got to protect yourself from all 1 million attacks, so it's a it's a huge disparity in in in in in attack methods or being able to control that those that kind of that kind of a threat attack vector, I should say. Yeah. So, so you know, the way that we look at it is that you can't just take the user on their own anymore. You can't just accept a username and a part and a MFA token. That only proves the user. So, if you want to combat these other threats, you really need to look at the device that they log in from as well, right? So if I say Scott's username and password, MFA token, session token, session cookie, whatever, only work from Scott's MacBook and Scott's personal iPhone, then it doesn't matter if they get stolen, and I try to use it because I haven't got access to your devices, and that's the key. This device trust-that's where the zero trust solution comes into play.

32:52

Yeah. See, I, I just, I, I, I think it. Here's a company. I'm a company, and I always and I and I know that there's an adoption roadblock, and I just it's just noise, and I I want to continue to manufacture whatever I manufacture, and what you're talking about is interrupting my, you know, productivity. But the reality is that you, Scott Mackenzie, me right now, I have to find Individuals, people, companies that I trust that will handle this-you know-stuff that that I can continue to focus in on what I do best, and that's manufacture. When I have a, you know, a Sherpa, a cybersecurity company, Sherpa, to be able to help me along on this journey, that's the key, because you listen to me, industrial professional. You don't want to be alone in this. No,

33:50

and and that's and and that's the thing. If you make something that's awkward and clunky to use and puts up barriers, people won't use it. People won't buy it. You know, because as you said right the way at the beginning, you're you're you're manufacturing something. The cyber and that's how users think as well. You know, when they log into stuff, they don't like oh, not another password or not another security thing I have to do. Yeah, it's got to be it's got to be simple. So again, one of the things that we've always done at Specops is made sure the user experience is as slick as we possibly can, because the moment the moment it becomes painful is the moment that it all falls down. Yeah, right on the money.

34:36

Right on the money.

34:37

Exactly. Don't

34:39

create friction for me. I don't want friction.

34:42

Exactly. So things like self remediation, right? So you know what it's like. You get fancy new iPhones comes out. You get one of those fancy new iPhone duos that's about it at the market. Right? No, you're not an Apple man.

35:00

No, it's just one. It's the price tag. Two, it's just something more to sit there and you know agonize over. I dropped it.

35:09

All right, just go. Just help me out here. Yes, just say yes, please. Come on. Yes. Yeah, I'm all

35:15

in.

35:16

Bad boy open.

35:17

;re probably using a Nokia:

35:28

bike, Barry.

35:32

But every now and again, people change their device. So make it easy for them to self serve. So prove who they say they are. Log in and say, right, I'm swapping my device over for a new phone, or maybe their device hasn't got the latest patches on. So rather than having called a service desk, they they can click a fix now button, so that it just fixes it for them. Yeah. So there's no, and it's all done just in time. So rather than having to go on the phone, wait, and improve your identity, and then wait for the the patch to come out. Give them a button, fix now, bang, done,

36:07

yeah, yeah,

36:09

or even a grace period. That's another nice option as well. So look, device doesn't quite meet the posture requirements. It's it's the right device, but it doesn't quite. You know, hasn't got the latest patch on it. But we'll give you to the end of the week, or we'll give you two more logins, and then we're going to force you to do it. But that just keeps it keeps the you know the business working, you know, generating the money that pays through all these IT solutions.

36:34

So

36:36

yeah, one last thing before we wrap this up, I think I think organizations, companies have just got to recognize the fact that this exists out there. There, you know, it just is. And I know back when I was running around, everybody is sort of pushed to the side. I got a firewall. I got this. I'm, I'm airgapped. I'm whatever. Everything's really connected. If I want data off of my operations, if I'm, if I if I have a pop, I'm pulling data, and it's going to the cloud. There it is. Potential doesn't have the patch. Just the recognition that, and having that conversation internally to say, hey, we want you, you know, team to be a part of the cyber solution here. That means we got here's a little education, here's this, and do it consistently. I I believe that it's imperative for organizations to do that to really cement the necessity that you team member are part of the overall solution because it can be challenging. I don't want yeah.

37:42

Well, I mean, you're quite right. You know, you save a bit of data now. It probably goes up to a cloud somewhere to be stored. Yeah. So it's not beyond a firewall. It's not in a nice secure office or a data center anymore. It's somewhere that you've got no visibility or control of, really.

37:59

Yeah. So

38:00

so where, so where is your security perimeter these days? It's not the network; it's your laptop. It's the device that you log in with.

38:07

Yes.

38:08

So, so matching, pinning the user to the devices that they use-that's the only way you can really secure or identify that person in a secure way, and that's exactly what we did. And it will continue to evolve. the The whole situation will continue to evolve. But that's why you. That's why you pay for you know guys like us to come up with smart solutions.

38:35

So if an if I'm an industrial guy and I'm listening to this conversation and I'm hyperventilating now, my blood pressure has gone through the roof a little bit just because I'm listening to Darren and recognize the necessity that I have to contact Darren. How would I contact Darren? What's the best way to be able to do that?

38:52

If you head on over to www.specopsoft.com, it's 2s's in the middle, no zeros or fives. Watch out for fishing, or or look me up on LinkedIn. Yeah, I'm the guy with the stormtroopers in in the banner. So so yeah, you'll you'll know him. I'm a big Star Wars fan as well. Yeah,

39:15

you made it easy for me. I'm gonna I'm gonna make sure that that is all out there, just because you, industry professional, need to up your cyber game, here's Darren. He's available. Specops's company. You are fantastic.

39:32

We had a

39:32

great we had a great conversation beforehand. By the way, just FYI, great conversation. It wasn't in the podcast, but it was great nonetheless. We were solving the world's problems. Well, thank you again, Darren. And we're going to be seeing you at in Barcelona, right?

39:47

Yeah, absolutely. Yeah, I'm definitely. We're definitely going for that beer or two, hopefully.

39:51

Shut up. That's going to be great. You going to fly over to Barcelona? You fly, right?

39:56

No, I'm going to walk. No, I'll fly.

39:58

Hey, hey. He's also here till Friday. If you want to catch his comedy act, outstanding, my friend. All right, we're going to have all the contact information for Darren out on Industrial Talk. Once again, you need to be a part of the Barcelona Cybersecurity Congress. Everything, everything that you need to go out there, and I believe, because of Industrial Talk, we have a discount. It is BCC Podcast 26. Don't if you have a problem getting that discount, just just let me know. I'm I'm so lousy at this stuff. So the details, it is what it is. But you get a discount. You need to be a part of it. You get to meet great people like Darren. Have a cup of coffee, maybe a couple of adult beverages. You will not be disappointed. All right, we're going to wrap it up on the other side. As always, stay tuned. We will be right back.

40:53

You're listening to the Industrial Talk Podcast Network.

41:04

Yeah, you're saying to yourself, "Woo, man, Darren's got a high beer factor. He does. And you're saying to yourself, "I'd like to have a beer with him. Yes, you do. And you're saying, "Well, how can I have a beer with him? And you're saying to yourself, I need to make it to the Barcelona Cybersecurity Congress. Yes, you do. You get to hang with Darren and all of the other incredible-I'm telling you- incredible professionals in the cybersecurity space because you need to protect your network. You need to protect, and we need for you to succeed and to succeed as you need to protect. There you go. Here's a correction for the BCC, the Barcelona Cybersecurity Congress. The code for your discount to connect with Darren and others at BCC is BCC Podcast 26. You see how I screwed it up on the interview? That's that's how I roll. But now you know, you know, you have to put it down there. BCC podcast 26, easy peasy. Now my intro definitely was on a soapbox. We want you to succeed. Industrial Talk wants you to succeed. That means you got to tell your story. That means you've got to be able to get out there and do it and do it in a way that is consistent. We're here. Industrial Talk is here. We want you to succeed. We're passionate about that. I say it all the time, and I mean it from my heart. So anyway, reach out. Go out To industrialtalk.com, connect with me, like you're going to connect with Darren, because all his contact information is out on Industrial Talk. So let's just let's just leave this conversation and say you're going to connect. You're going to connect with me. You're going to connect with Darren. You're going to be able to ensure that you succeed going forward. Go to the Barcelona Cybersecurity Congress. It's a great event, great people, and again, you will not Barcelona. You're not going to be disappointed with that one. All right, people, be brave, Derek Greatley. Hang out with Darren, change the world. We're going to have another great conversation from BCC shortly. So, as always, stay.

Leave a Comment





This site uses Akismet to reduce spam. Learn how your comment data is processed.