A Zero Trust Leadership Podcast

The Human Attack Surface: What Cybersecurity Can Learn from the Secret Service | Hazel Cerra
Season Four
· Episode
12

The Human Attack Surface: What Cybersecurity Can Learn from the Secret Service | Hazel Cerra

Hazel Cerra, a 25-year veteran special agent of the U.S. Secret Service, joins to explore what protective intelligence can teach cybersecurity about defending the human attack surface.

Transcript

Raghu N  00:00
Welcome back to The Segment. When we talk about cybersecurity, we tend to focus on systems, networks, applications, and infrastructure. But what if we've been thinking about the tax surface too narrowly? Today's guest, Hazel Serra, spent more than 25 years as a special agent with the U.S. Secret Service, protecting high-risk individuals and investigating complex cyber-enabled financial crimes. Today, she serves as director of digital security convergence at Black Cloak, where she works at the intersection of cybersecurity, executive protection, and threat intelligence. Long before zero trust became a cybersecurity framework, Hazel was operating in a world where trust itself could be exploited, and where understanding human behavior was just as important as securing technology. In this conversation, we'll explore what modern security leaders can learn from protective intelligence, how attackers identify and exploit human vulnerabilities, and why the future of cybersecurity may depend on understanding the human attack surface as much as a digital one. Hazel, welcome to The Segment.

Hazel Cerra  01:02
Hi, Raghu. Thank you so much for having me here. It really is an honor to speak to you and to your amazing audience.

Raghu N  01:10
Well, it's amazing to have you. And if I think about Secret Service, I think about Clint Eastwood in in the Line of Fire, right? So, could you just tell us about sort of the journey into the Secret Service and kind of your experience there.

Hazel Cerra  01:24
Well, it's so funny that you bring up Clint Eastwood because we had a poster of him in our lunchroom. So he's definitely what you consider, what you think of when you think about a Secret Service agent. But being a Secret Service agent is really about protecting and serving, and really giving back to your country because we are the guardians of democracy, and we all take that very seriously. We are not looking at who's holding office because for us it doesn't matter. For us, it's all about protecting our government, and our president represents our country, and we don't want anything to stand between that. That could really change the trajectory of our history if our presidents aren't protected, and there were to be some, you know, some terrible situation of an assassination. So we are all very dedicated and committed to our zero fail mission.

Raghu N  02:23
Awesome. I mean that. I think just what you described there, right? I don't think anyone has joined this podcast and said my role was to protect democracy. I mean that's when you talk about big picture. That is super, super big picture, right? But like ultimately, fundamentally, what it what it came down to-you've kind of just touched on this-is protecting a incredibly sort of high-risk but high-value individual or collection of individuals. So, what did that teach you about how adversaries think?

Hazel Cerra  02:55
Well, adversaries are only thinking about what they have to gain, and they're very focused in their goals. It could be financial goals. It could be, you know, an activist. It could be nation-state actors that are just looking to embarrass our country, or just or to really seriously hurt our country. So adversaries are not playing by the rules. They play dirty, and they're out to get what they need to get, and they work together really, really well. I mean, talk about partnerships-they've established it. They have a very strong community that supports each other, and we have to try to replicate that as best as we can. But adversaries are-you know-I always say like if there's something they want to do, they're very motivated to do it, and there's going to be very little you can do to stop them because it's what they're thinking about day in and day night, and every night they are not thinking of anything else. It's almost like a squirrel outside. What do they think about every day? They think about how they're going to get that acorn, that nut every day, all day long. That's all they think about. And are we putting that same mindset into protection the way that they do? We're not. We can't. We get pulled in so many different directions. So when you think about adversaries, I I have to say that they're just very motivated to an extreme level because they have a lot to gain.

Raghu N  04:23
Yeah, I think that's so beautifully put, right? Because it's the advantage of the adversary, particularly if they are there's a particular mission that drives them, is that the motivation high is high, and the persistence is high, right? So those two things. But also, I think what you listed there, right, is that when you, in terms of your role in the secret services, is that the challenge is that you're not just trying to essentially stay ahead of one particular adversary, right? There's a whole raft of different adversaries with, often with different motivations and different sophistications, right? Right. From essentially just like an activist who kind of just wants to run onto the street and sort of shout their slogan out to something more like make nation state etc. How do you effectively plan so that you you kind of have the right coverage for all of those types of adversaries? Because that must add such a degree of complexity.

Hazel Cerra  05:20
Yes, it does. But we've learned that over time, we cannot allow to disregard any kind of threat. So every threat is investigated to the best of our abilities, and we have an army of people that do this. And the way that it's it's it's it's very interesting because it's spread out in a sense that every threat is categorized, and when we send our agents to investigate that type of threat, there's a criteria that they look for. So, you know, we know that many of our people in our society they suffer from mental health issues, and largely that population is are the ones that are making threats to our president or our protectee. So that's a category, right? Do they have any type of mental health, you know, situations? So that's one. Do they have the means to really carry out that threat, right? So if we're going to go and talk to someone and they're committed in a mental institution, they obviously don't have the means, or perhaps they're disabled; they're not going to have the means either. Do they have access to weapons? So are they in the military, and are they proficient with with weapons? That's something that we're going to categorize as being very risky because that's very potential, especially if there's a mental health background associated with that. And if do they also have the means as far as financial stability? Can they just jump on a plane and make it to an event where our protectees are, so we take all of this information and we categorize the threat level and see if that is a you know we look to see if that's something that can materialize now. And at the same time, we never say that it can never happen. We just say that at this time we don't believe that this is a plausible threat, but we look at all of those threats because there's different categories as far as like what their motive is. It could be that their motive is to really harm one of our protectees. A majority of time, it is that just because they disagree with their political views, or it could be an activist. You know, they they they do not agree with drilling oil somewhere. It could be so many things, and sometimes it's just that they're dealing with something personal, and they just go straight to the top. The president's going to solve my problem. It's it's that simple, and we see that a lot with our executives in in the in the country, where when people have a problem in their lives, and you know they they don't know who to go to, and if you're suffering from mental health, you're just you think that you could just go to the CEO's house and have a conversation and get what you want, and that that happens in the White House every day. Every day, someone will take a cab from some strange place and want to talk to the president. I had a situation where someone came and wanted to give the president a puppy. Just came and just wanted to give the president a puppy, and you know, in their mind, they thought that they were just being kind and friendly, and it's it's a very common thing. So yes, there's a lot of different types of threats, but we have to look at them in different manners. And it is being proactive as opposed to just waiting for the incident to occur and just waiting for them to show up at the White House. We want to minimize that. So if we could prevent someone from driving to the to the White House and creating some kind of incident, we're going to do that.

Raghu N  09:05
By the way, next time someone wants to give a puppy away, our exec producer loves dogs, so I'm sure they'll happily accept the the the the puppy. So I see like what you describe. I've heard this term protective intelligence, right? So, is like everything that you described there, which is essentially when I when I heard that, I was like thinking, well, the parallel to that would be essentially threat modeling in cyber, right? I model the threat, I determine whether this is actually well, first this is threat plausible, but then is it actually realizable, right? So, do they have the motive? Do they have the means? Do they have the opportunity to go and carry it out? Like, but but so if everything that you describe there, that is that the protective intelligence that you build in order to then make the decision as to whether action is taken or it's or it's not.

Hazel Cerra  09:56
That would be a little bit different because we don't create intelligence. We're. We are consumers of intelligence.

Raghu N  10:02
Okay.

Hazel Cerra  10:02
So the intelligence that comes in, we evaluate that intelligence, and that determines how we're going to design our security plan. And it it really depends where we're going, especially if it's like overseas, that plays a huge role. But what we essentially try to do is we replicate the security of the White House everywhere the president goes. So yes, that intelligence does come into play as far as what events he's going to do. Most of the time, we we want to secure every event that he goes to and support it. But sometimes the threat that that intelligence is is so it's just so risky that it's that we can't do it or we just will we not going to say we can't do it but we're going to advise strongly that we shouldn't do

Raghu N  10:51
it. Yeah, yeah, understood. So actually, you you talked about how how sort of like what you said was that how do we replicate the security of the White House around the president wherever the president goes, right, so that that that the level of security around the president is never compromised. And actually, so John Kindervag, our our chief evangelist, who you know well, actually tells sort of one of the analogies that he uses when describing essentially zero trust is the protection around the the president. So, like, I mean, obviously, you probably don't use you you didn't use that term, but just sort of describe sort of what that means in the context of security around sort of those high risk individuals.

Hazel Cerra  11:37
Yes, so I love John Kindervag. He is an inspiration to me. As a matter of fact, it was during a class that I took on cybersecurity that I heard him speak, and he made that analogy, and it was like a true light bulb moment for me because I completely understood what he was talking about, and I started taking like a real deep dive into John and his background, and how in the world did he come up with this analogy? I thought that was so awesome, and I wanted to replicate that same analogy in some of my speaking opportunities because you know I had the background and I could understand it, and I that at the time I didn't have the cyber security training. It was maybe halfway through my career that I got into the cyber. I got into like cyber investigations. We didn't always have them, and once I started learning more about them, actually conducting those investigations and getting some of the training, that's when I ran into John Kindervag and saw this analogy, and then I could speak to it. As a matter of fact, every time I would do a presentation, I would reach out to John Kindervag on LinkedIn and say, "Hey, I'm speaking. You know, I maybe you could log in because I think some of them were webinars. And of course, he was always busy, but he was so great. He was very always very supportive, but his analogy is zero trust is a same analogy that I use in the Secret Service, which is zero fail.

Raghu N  13:10
Yeah, right.

Hazel Cerra  13:11
So we everything is about perimeters. We have that inner perimeter where it really is your last recourse that people on TV think that that's the most you know that that's all we do, and they have no idea how many more layers of security that are involved. There are so many, so many layers, but in the outer outer perimeter, if you're trying to get into that perimeter, we're going to ID check you, and it doesn't matter, you know, if you have a pin because most of us are recognized by a special pin that we wear. But I mean, that could have gotten, you know, you could have gotten that anywhere. Could it, you know, maybe somebody lost it? And for the most part, if a pin is lost, it's a big deal. A message is sent out to every single agent that's working that day, letting them know. So you know we are aware of these things, but but still, we're not just going to let you in just because you have a PIN. We're going to check your ID, and once you get into the first layer, you're still going to get checked again in the next layer, and it really is that no trust, like it's that zero trust, like I still don't know you. Not obviously, if I know you, I'm going to let you in, right? Like I could recognize what my director looks like, so I'm not going to stop him at the gate. Although, even if I did challenge him, he would say thank you because we are in security, and as and the one thing is, as long as you're professional, you know that's totally fine because we are supposed to be challenging people that are coming through our security perimeters. So, all of those layers are are meant to keep everyone safe. And you know, if if something went wrong in in a site, we always say multiple layers failed here. It wasn't just one layer. Was more than like something happened, and that's when that analysis comes in, and we start looking at our structure and the causes for that. So, and that comes out in a in a debrief. But for the most part, just like you do in micro segmentation, it's that zero trust, you know, perimeter where you have to verify, trust, and verify. You can't just let everybody right through.

Raghu N  15:27
Yeah, and constant monitoring, of course, as well. Right, you're constant. Like every layer in that defense is constantly being observed and validated and and strengthened, so that the integrity of it should never be compromised.

Hazel Cerra  15:42
Correct, correct.

Raghu N  15:44
Yeah, yeah. So it's funny about the pin because I know John has been. I think it's got like a like a souvenir pin or something that, and he's very proud. He always shows it off, right? But it's good to know that if he came up, right, you'd say, ah, ah, that's not enough, John. You can't hear him for the Secret Service. That's a different pin. It's a totally different pin. I know what you're talking about because it's a flag pin with our star in it. But now our protection pins are completely different, and yeah.

Hazel Cerra  16:10
Yeah, they change. So it's good for a couple of months, and then there's a new a new one that comes out, and it changes colors. It's a whole system. Yeah, we we do security. It's pretty intense.

Raghu N  16:19
I know. Hey, John, if you're listening to this, right? Yeah, you're not in the Secret Service. You've just got a souvenir. So you you you mentioned like about sort of go like going and then and then having been in sort of like executive security, but then going and training in cybersecurity. Like, what was the like what was the crossover that you saw that said, "Hey, I should go and study this because it's important. Like, what was the motivation behind kind of going into cyber?

Hazel Cerra  16:48
So that's an excellent question. When I was an agent in my first phase, so we have three phases of our career. The first phase is that you're in a field office, you're conducting investigations, and you're supporting the major protective details. My first phase, most of my cases were counterfeit cases, treasury check fraud, credit card fraud, identity theft, and skimming was had just started to come out. So there was a series of gas stations that we would identify where there was an employee who had a skimming device, and you would give the gas station your credit card, and then they would swipe it with a skimmer. And those skimmers were then, you know, that information was then sold. So we were able really easy easily to identify the gas stations and basically do an operation and then arrest the people there that were involved in the in that that scam. So when I went to my second phase of my career, you're not really doing many investigations. You're not actually you're not doing any investigations. You're strictly protection, and I was on the the Clinton detail. So for that period of time, it was about four four years. I spent traveling everywhere President Clinton went, along with his family, and no investigations. So during that time, you start thinking, what am I going to do when I go back to the field? Because everything's changed. So I was always I always kept like my finger on the pulse, kind of keeping in touch with what things you know what things what things were trending in investigations, and I saw that there were more cyber investigations. So when I came to the field, I saw that those same skimming investigations they were next level. There were no longer were we looking for a person at the gas station. The skimmers were now inside the pumps, and then there was Bluetooth that was added. So we couldn't just go and do an operation and arrest a person. It was very challenging, and then also with the skimmers and the ATM machines, that was a big thing. So when I started learning about these things and learning what you know the role that cyber played in these investigations, I said I need to put myself in some kind of training that will help me get better because I I saw the writing on the wall. Everything was shifting to more of computer fraud, so I was able to get training in network intrusion, and I I did that, and that was exciting because that was now transitioning me from working the you know credit card fraud and counterfeit investigations, all that, and now I was working more of the skimming investigations, and we saw a lot of the network intrusion investigations, which were basically very similar to the Target breach. But during that time frame, what had happened was all these small mom and pop stores, they wanted to take credit card. Transactions, so they were getting the infrastructure built inside their stores, but not the security. Yeah. So, you know, back in the day, I know I didn't. I didn't go to the grocery store and charge my groceries. Like you pay cash.

Raghu N  20:18
Yeah.

Hazel Cerra  20:19
Right, and that's like unheard of now. But when when everyone started, you know, making these transactions more convenient, credit cards. If you didn't take a credit card, you were going to lose business.

Raghu N  20:33
Yeah.

Hazel Cerra  20:34
So that meant that you had to have that infrastructure in place. So because it was expensive, and all you know, these restaurants and mom and pop places wanted to take credit cards. They weren't thinking about the security piece of it, so they were taking credit cards. And then that same computer that was doing the transactions, they were on on the web. Employees were going there, checking their emails, downloading stuff. I mean, all the things that you shouldn't be doing. And then there were there's also legacy systems, you know, that they were using as well that weren't being upgraded. It was a hot mess. So we would go and and and go to these supermarkets, and then we would just say, "Okay, who did your IT here? And they'd give us the name of the person, and sure enough, we would go, and all of their systems were configured the same way. So we were very busy with network intrusions, and what I saw was that there was a wave of different types of industries that were getting targeted at one time, so I saw the supermarkets. Then it was car washes. Then it was wineries and ice cream parlors in the summer. It was anywhere where there was like a high amount of transactions that that were just targeting and getting credit card numbers like very easily. So they didn't need to break into, you know, Bank of America. They could just break into all these other little places and get what they needed.

Raghu N  22:09
I love that story. So you're kind of getting your cybersecurity training, and as you're getting that, given that you came from essentially the exec security, the like the the human security sort of discipline, what were the parallels that you were seeing between sort of the exec security and the cyber security disciplines?

Hazel Cerra  22:27
You mean like when I was on the detail, or yeah? Well,

Raghu N  22:31
whether that's like when you were at sort of when you were on your cyber security sort of training courses, or like there there must be you must have kind of gone through that and saying, "Oh God, like that thing that we're doing on computers or in networks is that's quite similar to kind of how we approach like this part of the president's security detail, right? Like, what the did you were there any interesting parallels that you observed?

Hazel Cerra  22:55
Oh my gosh! So the Secret Service was already doing these things back in 2001 we were already doing these things, and what they were doing was that they were started to utilize our forensic agents, and they were using them to enhance our protective methodology. At the time, I didn't know what they were doing. It was very kind of like, okay, I don't really know what you're doing. I didn't really understand it, but yes, after I had the network intrusion training, the next level was critical systems protection, and it was that. So I did throw my name in the hat, went to the training, and the training had us look at all the different critical infrastructures, and it was about looking at a site advance where the president was going to speak, and looking at it in the lens of what can a hacker do to the network that will impact the visit. So very, you know, lot lots of things. Like, for example, we didn't want to get trapped in an elevator. All these elevators are configured on the network, so if a bad guy wanted to hack into a building that had very poor security, we could get trapped in an elevator, and that could be really bad for us. Especially some of these, you know, large, you know, high rises. But that's just like a very small example. But cameras were really a big deal because if you can get access to a camera, it's like having open surveillance to everything that's happening. So if you wanted to plan an attack, it's it you know getting access to cameras is is is not something that we want. And also you could get access to the cameras and see our security measures and how we operate. We don't want that as well.

Raghu N  24:46
Yeah, yeah.

Hazel Cerra  24:46
That's another thing. So that was one of the more critical ones that are or more common ones, I should say. But things like just the phones-they're connected to the network. So a VoIP phone could be a really bad. Thing if someone grabbed the phone and said, "There's a fire, and we have a building full of like 5000 people in it that are just going to scatter and and and run somewhere. That could impact our evacuation. So there's so many things that can happen when you really think about what is connected to a network and how easily could break, you know, hack into one and control that site because more and more we were seeing these like smart homes, smart buildings. The lights are connected to the network. We have sound. We have blaze displays could be hacked into, and you know, could say something very negative, or it could be embarrassing too if they're hacked into when the and the president is speaking. So there are there's definitely that relationship with with cyber, like the the physical and digital convergence that happens in protection. And now is when we're we're seeing it with our executives.

Raghu N  26:02
I mean, everything you described about, like, you know, like the president is going to visit a particular location, let's say a hotel, and you need to go and secure the hotel's network, etc. Right? Kind of, as you're describing that, to me, it's like a sort of scene out of something like 24 or or some other sort of high tech drama series where they sort of show, oh, and then someone's taken over the lift and etc. That that's that's fantastic. So this this this is a good point for us to sort of start talk a bit about like what you're doing today because in your role at BlackCloak, it's like you're you're definitely at that convergence between sort of executive protection, physical security, cyber, right. So, talk to us about how all those things kind of very naturally come together.

Hazel Cerra  26:49
Yeah. So you know, as security improves with the organizations that the cyber criminals are increasingly targeting individuals that have access to high value confidential information, and you know, and they're attacking not the corporation; they're attacking their home networks. And you know, they're compromising on secure devices that have malware and ransomware. And over the years, we've seen a number of successful attacks on executives like Microsoft, Dragos, the United Healthcare, Twitter, Amazon, Meta. I mean, you know, there's there's just so many. It keeps on and on and on. The last one was with Kash Patel. They didn't they didn't hack his work email. It was his personal email.

Raghu N  27:34
Yeah. So, what are the lessons to be learned? Right. What are organizations still maybe getting wrong when it comes to managing executive risk.

Hazel Cerra  27:44
Well, you know what they need to realize is that the bad guys are targeting the path of least resistance, and you know, like we talked about earlier, that motivated threat actor-they're going to figure out a way to reach their final target, and looking at the individual to protect them and not just the corporation. Because as you could see with my background in the Secret Service, we didn't protect the White House; we protected the president, and we didn't just protect the president when he left the White House. As far as like all the sites, we also protected his personal residence. Like every president, like for example, Trump, we protect Trump Towers because that's also something that threat actors are going to gravitate towards. Not just going to be the White House. If they're going to protest about something, they're going to go there too.

Speaker 2  28:38
Yeah.

Hazel Cerra  28:38
So it's taking a holistic approach to protection, not just the the enterprise. It's beyond that corporate perimeter, and looking at the other 12 hours of the day that the executive is not in the office. Because executives they go home and they think, well, I'm here, I'm home, I'm safe. But if that network isn't protected, you know, you have your kids that are on Xbox and they're gaming away, downloading all sorts of things. You have shopping activity. There's IoT devices that are possibly not configured correctly. The same thing with cameras and everything that you connect to the network that's making your life easier, which is great, but there's a trade-off to that, and we often trade off, and you know this, we often trade off security for convenience. Yeah. So, looking at it in a sense of protecting the enterprise, you have to protect that that that path of least resistance, which is going to be the home of the executive because that is the new battleground, and we know from research that executives are 12 times more likely to be targeted than any other individual of the company.

Raghu N  29:55
Yeah, absolutely, and a lot of what you described there is, and I kind of drawing my parallel. With cybersecurity, right? Because if we think about again, the president is, let's say, that critical asset that you're protecting, right? But you don't just wrap a bubble around just that asset. It's again that like where all the places that asset could move and live. You want to ensure all those things are properly secured to the right level at the right times, but it it's because like one of the things that I'm trying, I guess, like drawing parallels between executive security and cyber security is that one of the challenges that it's always the case is that there's this perception that adding more security creates more friction, right? And in the case of protecting, let's say, an executive or the president, you're always trying to ensure that there is the right level of security, but also something that is doesn't impact their ability to sort of go and participate, like go and see, wave at crowds, etc. Right? Yeah. So, sort of, what are the learnings about adequately getting the right balance between security and I'm going to call it, let's say, productivity or agility, which is which is more of us like relevant to technology. But like, how do you not get in the way of the present being able to be effective, but also keeping them secure?

Hazel Cerra  31:17
Yeah, that so lots of negotiations. So we have very, very strict standards, and the nice thing is, is that like we don't just go in and select the site and say, "Hey, here's how we want where we want the president to come in, and this is where we want him to talk. We don't do any of that. We are literally there to support the staff and their vision of how they want the event to flow, and it's a it's a it's a conversation between the team, the the Secret Service advance team, and the staff. Now, the good thing about us is that we have 125 years of protection experience. That's a long time that we've done things well, and we've made some mistakes and learned from them. So security is something that has to continue to evolve, and as the threat landscape evolves, you have to do your best to catch up with it. And and and we have, we've had some struggles, but you know there is a standard that we have, and the staff that works with us-they understand what that what that standard is. A lot of times, they they know, and they're not going to push their limits with us. But there are times that we have to get creative. Yeah,

Hazel Cerra  32:35
we don't have all the resources in certain areas, especially in certain countries, there's a lot of negotiation that takes place when it comes to those things. So you have to give a little and take a little, and sometimes it's about okay, we're going to have to maybe not have get everything that we want on this list, but that just means that we have to shrink our perimeters a lot tighter, so we get close, really, really, really close to that those other layers, right? So sometimes it's just a matter of that flexibility and adding more resources that maybe that you can't see, because a lot of times you know we we do have to work with the staff in the sense of they're trying to videotape this, and they're they're trying to make it so that the president is with the people. The people want to see president. We can't just keep him in the White House and not let him go out. So there are there is that balance, and it it is a challenge every single time. So to answer your question, it is challenging, but we have to adapt with the times, and we have to be flexible. And a lot of it is just having very strong communication and negotiating, and being able to to to draw that hard line in the sand where we're not going to negotiate. Like like the president is not going to be walking through the crowd if we don't have to do that.

Raghu N  34:04
Yeah, yeah, absolutely. That that's, I I kind of love the way you express that, right? And because everything you've expressed there, I can draw a direct line to sort of what good looks like when in applying security to technology, right? Because I think essentially what you described is, is that ultimately we want to ensure that whoever is organizing the event, right? Whether it's like a the president visiting a school to open a school or opening up a hospital or whatever, right? Like you you want to ensure that they kind of get that sort of the the event that they want, right? The the prestige of the president. Open it, whatever it may be. But it's like, okay, well, that's the outcome we're driving to now. Let's work with you to ensure that we're able to. You're able to get what you want out of it, but also we ensure that the president is properly protected. So we're working hand in hand from the get go, and of course. Right, these are the things that we are non-negotiables, and these are the things that we flex on. But if we do this, then there's going to be this trade-off, etc. Right, and I think that's a that's a great lesson for how we should think about applying security to technology, to applications, etc. Right, bringing the security team early into the development process, right, so that they can understand what we're trying to build here, right. They can say, okay, here are the guardrails, right. Here are like kind of like the minimum things you have to do. Here are the things that we can think about, sort of adapting, right, so that you can build the application, build the customer experience you want, but also it's done in a safe and secure manner, right? Rather than coming in right at the end of the process and say, "Ah, ah, sorry, you can't do that, right? And everyone's like, "Oh my god! And I kind of I think what you describe there is there's so many things to learn to to be able to learn when it comes to sort of cyber cybersecurity and securing applications. So, kind of like with that, right? Like, what do you do at like your role at BlackCloak? So, what is it that you do today?

Hazel Cerra  36:11
So, I love my role at BlackCloak because it is the cyber piece that I used to do for the on for supporting the president's detail with the critical systems protection, and I still get to do it, and that was the fun part because at the end of my career with the Secret Service, I was a leader, and most of my time was spent coaching and mentoring the new agents that are going to continue to run the mission, so I didn't get to do the cyber stuff too much. So now I'm back at it. I love the way that we view the digital executive protection program because it's a holistic approach. It is protecting the networks of executives. So I went from protecting the president to now protecting our, you know, the leaders that run our economy. So I feel I still feel like I have that mission of protection and serving, and our executives are kind of just left out there, like they're not being protected, not when it goes to the digital space, because we know that a lot of these physical attacks they start with someone doing research online. I mean, I could be in a whole other country, other side of the world, and I could find out where you live, who your kids are, what school they go to, what religion you are, when you're on vacation, and if you have a poorly connected network, I could probably see inside your home. I can tap your phone. I could read your email. I could find out where you're traveling to, because if you're traveling personally, some but there's going to be an itinerary somewhere, and I'm going to stay in your system long enough to plan an attack and show up when you are at your most vulnerable moment. So, what we do at Black Cloak is basically preventing that kind of scenario. Now, obviously, I think like the bad guy because that's how I've been trained to think, right? But what I'm learning is that a lot of our cybersecurity professionals, like you're, there's just and and and for good being, right? You're you're focused on the enterprise, but that's not enough. You have to protect individual. It's that individual represents your organization, period. Okay, it it we back in the day. Who was the person who was the most visible? It was the president of the United States because he was the one that was on TV, on the media, on the radio, in the newspaper. But that's why there were so many assassination attempts, because people will disagree with unpopular decisions. You could have half the population that would love it, and the other half will hate it. And the ones that hate it are going to be vocal about it, and they're going to again. They go straight to the top. They have a problem. They go straight to the president's house and let him down, or try to harvest. I mean, that's what happened with Abraham Lincoln. That's what happened with President McKinley. They were assassinated because of you know political extremism.

Raghu N  39:26
Yeah.

Hazel Cerra  39:27
So what we need to realize is that we live in the world where our executives are just as visible as the president was years ago. Our executives are on social media. They're on the news, they are on podcasts, they are very, very visible. And the more visible they are, the more of a target that they are. And now with with deep fakes and AI, it's easy to clone the voice. It's easy to clone the image, and you could do so much. Harm, and by the time people realize that it's fake, it's too late. It's just too late because most people they don't fact check anything. They see one thing, and that's it. It's it's it's it's true. It's true. So protecting our executives is very important for for this, you know, for for our country because they run our economy, and they're extremely vulnerable right now. You can't just you know they're they're going to go home and if you think that they they they stop working all of a sudden, no, they don't. They're connecting to that same network and they're going to continue to push through and and do more work. And now you have information that's enterprise related information that can also be accessed by a threat actor. So, keeping them safe and also keeping the enterprise safe and protected, it has to go beyond the corporate perimeter.

Raghu N  40:54
Yeah, yeah, absolutely, and particularly now that a lot of like the the CEOs of of the sort of the the Fortune 100 right are not that they are personalities. They are they are celebrities in themselves right. Yeah. If you think back 2025 years ago and you said, hey, can you name me the CEOs of these 10 companies? People would be scratching their head. Now, right, you say, can you name the CEOs of the top 10 companies by market cap? And people like will just literally rattle them off, right? So it's just like they're there, they're known. People want to see them, hear them. But then there is also that all the responsibility that comes to sort of securing them. So just kind of before we before we wrap up, right? There is of course, right, like AI as a prevalent technology that's accelerating, right? And there are so many other forces at play, social media, etc. How do all of these developments change sort of the challenges when it comes to securing execs and securing sort of high high risk individuals?

Hazel Cerra  41:54
Yeah, well, that that is definitely what Black Cloak is doing. We do have impersonation protection through the actual platform that we use. We have a unifying a unified platform, and there's a way that you could verify someone else who's reaching out to you, and that is excellent when it comes to an internal type of conversation, right? Like you have a board member that is like, "Hey, are you sending me a million dollars? Was that you asking for it? And you can verify that, so like an outside channel. But when it comes to a deep fake that is out on social media with an executive, we need to find a way where we can work better with some of the social media platforms that are going to be able to take things down much quicker, because that is a huge challenge. I think that they they are able to work with us and other entities that are asking for things to be taken down, but it's it's too slow. I mean, things are screen captured and sent up, so that's a challenge. But I will say that if it's someone that's communicating with you, that it's some things that you can do. If you have, you know, maybe it's a color. Hey, if you say that the word, you know, orange, I know that it's really you when you're reaching out to me, even if it's like a phone call or some type of, in case someone tries to clone your voice. But if it is a video call, the best advice I can give you is ask that person to open their refrigerator. And I'm serious because if they're in another country, you're going to see different things in the refrigerator that are in a different language, and worst case scenario, they might just hang up on you, right? But you know, we are we live in a country that we are used to responding to emails, text messages, and now deep fakes are just going to be added to the category, and it is and it is very scary.

Raghu N  43:58
That's a pro tip right there, right? Check check like look out for their refrigerator. So, okay, before we wrap up, Hazel, this has been this been fantastic. Hey, maybe a a fun question to to end with, right? You spent 25 years in the in the Secret Service, right? And of course, the Secret Service is represented in so many different sort of ways in popular media, right? What is one maybe myth about the Secret Service that you want busted?

Hazel Cerra  44:30
Oh my gosh! Well, first we do have women. I'm an example of that. Yeah, exactly. You know, we do have women. I I would often get, oh, you don't look like a Secret Service agent. I'm like, oh, really? What do they look like? Tell me.

Raghu N  44:42
Clint Eastwood. That's what they look like.

Hazel Cerra  44:44
Exactly. That is what they look like. So when I when they would when you know they'll never tell you that they're like, oh no, we just didn't know. You know, they're so everyone's really polite because you don't expect a female, right? That's just how how it is. But I would always say, you know what? What makes me a really great agent is the fact that I'm very unsuspecting. So if I saw something that was strange, I could take my time and pull my gun out and kill you, as opposed to someone that really does look like an agent. So it does have its advantages.

Raghu N  45:12
Yes, absolutely. I love that. I just want to know: Do you have a pair of those sun like glasses that you're all wearing? The sunglasses, where so that we can't see what you're doing with your eyes.

Hazel Cerra  45:21
So the sunglasses, you know, it's it's dependent on the agents. But because we spend so much time outside, especially in airports, that's where you see a lot of the those those shots is is out in airports when the president is arriving.

Raghu N  45:36
And just do that thing with your sleeve, please, so that you can you can talk into the bike.

Hazel Cerra  45:42
Yeah, we have our yeah our microphones in our sleeves, and we and we talk in code, so you can't even hear us. Again, layers of security.

Raghu N  45:49
Love it, love it. Well, Hazel, thank you so much. It's not every day. In fact, I don't think we've ever had someone who's kind of been in that particularly unique position of Secret Service and the role that you play. So thank you so much. And I again, right, I loved your opening when you said, "Our role is to protect democracy. That's that's a pretty powerful statement. So Hazel, thank you so much for your time.

Hazel Cerra  46:11
Thank you, Ragu, and thank you for having me. And again, to talk to your amazing audience. Thank you so much.

Raghu N  46:17
It's been a pleasure. Cheers.

Hazel Cerra  46:18
Cheers.

Raghu N  46:21
Thanks for tuning in to this week's episode of The Segment. For even more information and Zero Trust resources, check out our website at alumio.com. You can also connect with us on LinkedIn and Twitter at Illumio. And if you like today's conversation, you can find our other episodes wherever you get your podcasts. I'm your host Raghu Nandakumara and we'll be back soon.