1
00:00:00,000 --> 00:00:09,000
[MUSIC]

2
00:00:09,000 --> 00:00:11,800
Welcome to the Executive Connect podcast,

3
00:00:11,800 --> 00:00:14,480
a show for the new generation of leaders.

4
00:00:14,480 --> 00:00:18,280
Join Melissa R. Skog as she speaks to a wide variety of guests

5
00:00:18,280 --> 00:00:23,760
that bring new insights into leadership, prosperity, and personal growth.

6
00:00:23,760 --> 00:00:25,640
While now it has all the answers,

7
00:00:25,640 --> 00:00:29,240
by building a community of open-minded and engaged leaders,

8
00:00:29,240 --> 00:00:33,720
we hope to give you the tools you need to help you find your own path to success.

9
00:00:33,720 --> 00:00:38,960
[MUSIC]

10
00:00:38,960 --> 00:00:42,360
Hello and welcome to Executive Connect podcast.

11
00:00:42,360 --> 00:00:46,800
I'm so excited to have Cecille Mengay here with me today.

12
00:00:46,800 --> 00:00:52,680
She's a Cybersecurity Professional and Hacker at IBM XForce Red.

13
00:00:52,680 --> 00:00:58,440
She got there by actually experience a personal cyber attack,

14
00:00:58,440 --> 00:01:03,600
and it ignited her drive to get into the field of digital security,

15
00:01:03,600 --> 00:01:08,280
and publish her own book called Digital Security Overhaul,

16
00:01:08,280 --> 00:01:11,720
which equips individuals with knowledge and strategies

17
00:01:11,720 --> 00:01:14,320
to enhance their online security.

18
00:01:14,320 --> 00:01:16,960
Cecille, thank you so much for joining us today.

19
00:01:16,960 --> 00:01:20,360
I'm so excited to have you on the podcast.

20
00:01:20,360 --> 00:01:21,320
Yes, yes.

21
00:01:21,320 --> 00:01:23,400
Thank you so much for having me.

22
00:01:23,400 --> 00:01:28,200
Cecille, can you share the specific moment that was a turning point in your career

23
00:01:28,200 --> 00:01:32,760
and tell us a little bit about how you got into the field of cyber security?

24
00:01:32,760 --> 00:01:37,200
What can I start?

25
00:01:37,200 --> 00:01:41,880
I actually went to school and got a Bachelor of the Great Incriminal Justice.

26
00:01:41,880 --> 00:01:44,080
I always wanted to go to law school, right?

27
00:01:44,080 --> 00:01:48,400
So my path has always been in some kind of liberal arts area,

28
00:01:48,400 --> 00:01:50,560
nothing technical.

29
00:01:50,560 --> 00:01:54,960
But after graduation, I just kind of find myself online,

30
00:01:54,960 --> 00:02:00,160
just, they had this revolution of make money online,

31
00:02:00,160 --> 00:02:01,640
do things online and make money.

32
00:02:01,640 --> 00:02:03,880
I was like, OK, I could figure that out.

33
00:02:03,880 --> 00:02:07,520
So I find myself spending a lot of time online,

34
00:02:07,520 --> 00:02:13,640
just trying to be an entrepreneur and just create different avenue to make money.

35
00:02:13,640 --> 00:02:15,480
So I started doing event promotion.

36
00:02:15,480 --> 00:02:19,240
So I did a lot of event promotion online.

37
00:02:19,240 --> 00:02:23,200
So one day, I get back to my computer,

38
00:02:23,200 --> 00:02:27,320
and I have like a Ramson note on my laptop.

39
00:02:27,320 --> 00:02:29,800
And I was like, wow, how did that happen?

40
00:02:29,800 --> 00:02:37,280
So there was kind of like requesting for a $500 fee in order to release my computer

41
00:02:37,280 --> 00:02:39,280
if I needed to get my computer back.

42
00:02:39,280 --> 00:02:43,920
Would have it absolutely no clue of what actually just happened?

43
00:02:43,920 --> 00:02:46,840
I stopped panicking.

44
00:02:46,840 --> 00:02:51,280
So the only thing was now try to pay the money

45
00:02:51,280 --> 00:02:53,640
so that I could get access back to my computer.

46
00:02:53,640 --> 00:02:55,600
I didn't really think twice about it.

47
00:02:55,600 --> 00:02:59,160
And then I went ahead and paid the money.

48
00:02:59,160 --> 00:03:04,520
But one thing actually happened in that process as I paid the money,

49
00:03:04,520 --> 00:03:08,520
I thought that was going to be the end of my nightmare, right?

50
00:03:08,520 --> 00:03:14,400
But no, my attacker had already kind of like took over all my accounts,

51
00:03:14,400 --> 00:03:17,240
was kind of reaching out to multiple other people.

52
00:03:17,240 --> 00:03:24,280
And because I had such a poor cybersecurity, I would say,

53
00:03:24,280 --> 00:03:28,760
like I pretty much used the same password in every single card I had.

54
00:03:28,760 --> 00:03:31,880
So that allowed them even into my bank account,

55
00:03:31,880 --> 00:03:34,800
which they also ended up transferring that money.

56
00:03:34,800 --> 00:03:38,680
So I started dealing with like all my money being transferred,

57
00:03:38,680 --> 00:03:45,000
the money that I sent myself, my friends getting like different email,

58
00:03:45,000 --> 00:03:49,080
different information and it was all supposed to be coming from me.

59
00:03:49,080 --> 00:03:52,120
Then I kind of got interested.

60
00:03:52,120 --> 00:03:53,440
I was like, huh?

61
00:03:53,440 --> 00:03:58,200
I wonder how a complete stranger was just made it.

62
00:03:58,200 --> 00:04:03,400
I wonder how easy a complete stranger was able to just get into my life.

63
00:04:03,400 --> 00:04:06,240
And just almost pretty much take over it.

64
00:04:06,240 --> 00:04:12,000
Then I kind of became intrigued with that whole aspect.

65
00:04:12,000 --> 00:04:13,600
Then that kind of triggered me.

66
00:04:13,600 --> 00:04:16,440
I was like, I wonder what did they do?

67
00:04:16,440 --> 00:04:17,600
How did they do it?

68
00:04:17,600 --> 00:04:20,480
Then I started really studying.

69
00:04:20,480 --> 00:04:22,960
My very first question I remember in this place,

70
00:04:22,960 --> 00:04:29,280
like how do computer work, network communication, how do we come across this?

71
00:04:29,280 --> 00:04:31,640
So I started looking into it myself.

72
00:04:31,640 --> 00:04:37,360
Little by little, that passion of trying to figure out how I became,

73
00:04:37,360 --> 00:04:43,520
what I became the chosen one, because I didn't feel like I was that interesting, right?

74
00:04:43,520 --> 00:04:46,800
Of the billions of people online that you could have picked,

75
00:04:46,800 --> 00:04:48,640
I didn't think you would have picked me.

76
00:04:48,640 --> 00:04:54,080
So when I started to understand that it probably was something about me

77
00:04:54,080 --> 00:04:56,320
that made it easy for them to come after me.

78
00:04:56,320 --> 00:04:59,760
So I started trying to figure out what that thing was.

79
00:04:59,760 --> 00:05:07,600
And what I was kind of like, I got myself into this space of trying to figure this out.

80
00:05:07,600 --> 00:05:10,560
I really grew an interest of now.

81
00:05:10,560 --> 00:05:13,040
I wonder if I could find my attacker.

82
00:05:13,040 --> 00:05:18,720
Now, if I'm learning all these things and put in much the system that they use,

83
00:05:18,720 --> 00:05:23,520
and I start trying to start understanding how the whole thing worked,

84
00:05:23,520 --> 00:05:25,680
then I kind of set to myself.

85
00:05:25,680 --> 00:05:30,400
I was like, let me try to see if I could track my attacker down.

86
00:05:30,400 --> 00:05:35,920
Which, oh my god, it took me a while, but just kind of digging too.

87
00:05:35,920 --> 00:05:41,280
One of the big things that I kind of came across that changed my life was

88
00:05:41,280 --> 00:05:47,920
the Ocent framework, which kind of showed you different aspect of open source intelligence

89
00:05:47,920 --> 00:05:51,120
on the internet and finding information.

90
00:05:51,120 --> 00:05:55,120
But this attack on me was actually very elaborated.

91
00:05:55,120 --> 00:05:58,640
It was just not a one person thing.

92
00:05:58,640 --> 00:06:00,720
It was almost like a corporation.

93
00:06:00,720 --> 00:06:02,320
It was very elaborated.

94
00:06:02,320 --> 00:06:06,000
And it took every step to cover themselves.

95
00:06:06,000 --> 00:06:08,720
Right.

96
00:06:08,720 --> 00:06:09,360
Right.

97
00:06:09,360 --> 00:06:14,800
So, but one thing with the internet, like everything just kind of get interconnected.

98
00:06:14,800 --> 00:06:21,840
So the only thing I really have was the destination where I sent the physical money

99
00:06:21,840 --> 00:06:25,280
and first and last name.

100
00:06:25,280 --> 00:06:28,560
This particular person can find them nowhere online.

101
00:06:28,560 --> 00:06:31,200
I mean, I tried everything that I could.

102
00:06:31,200 --> 00:06:33,600
They were pretty much ghost, right?

103
00:06:33,600 --> 00:06:38,320
But I had an idea and I was like, let me step back.

104
00:06:39,280 --> 00:06:41,920
They had to put a unique last name.

105
00:06:41,920 --> 00:06:50,400
So I started thinking of ways of any kind of other connection outside of self.

106
00:06:50,400 --> 00:06:51,520
So I stepped back.

107
00:06:51,520 --> 00:06:56,160
I used, I called the city where my money was sent to.

108
00:06:56,160 --> 00:07:00,480
So they sent me a phone book and I saw like three other people with the same last name.

109
00:07:00,480 --> 00:07:03,760
So they was one lady that was in that phone book then.

110
00:07:03,760 --> 00:07:08,240
I went back online with what I knew at this point, but not she was helpful.

111
00:07:08,240 --> 00:07:09,600
Her footprint was everywhere.

112
00:07:09,600 --> 00:07:12,480
Her footprint was everywhere.

113
00:07:12,480 --> 00:07:22,400
Come to find out she kind of had she had a relation with the person that I sent my money to.

114
00:07:22,400 --> 00:07:27,040
So eventually, just going through her social media and different things,

115
00:07:27,040 --> 00:07:35,280
I find out that she had a brother who had the same name as the person that I sent the money to

116
00:07:35,280 --> 00:07:43,520
and who was in a band. I was able to find his phone number, her physical address,

117
00:07:43,520 --> 00:07:49,920
just enough information to build a pretext on what my conversation would be with her.

118
00:07:49,920 --> 00:07:56,560
So once I did all that, I eventually just picked up the phone and called

119
00:07:57,920 --> 00:08:07,360
and directly was just asking for her brother, which she kind of was upset and was like he doesn't leave

120
00:08:07,360 --> 00:08:12,720
here. I said, well, he just gave me this number. We playing on a band tonight and I need to get in touch

121
00:08:12,720 --> 00:08:17,840
with him. Do you know how I could get in touch with him? We went back and forth and she eventually

122
00:08:17,840 --> 00:08:25,920
gave me his cell phone number. So I called him and I'm like, hey, you know, I want no problem,

123
00:08:26,560 --> 00:08:33,600
but I sent you my money. Is that a way I can get the money back? And his first question was,

124
00:08:33,600 --> 00:08:40,880
which one are you? And I was like, hello. So this is not just me. So this is like,

125
00:08:40,880 --> 00:08:49,120
and come to find out he was just a middle guy and between a bigger scheme, right? So he really wasn't

126
00:08:49,760 --> 00:08:58,160
anything or he wasn't even my target. So I spoke with him. So his job was to pick up to pick up

127
00:08:58,160 --> 00:09:04,880
transaction, which he told me he picks up hundreds of times transaction a day. And then he forwarded

128
00:09:04,880 --> 00:09:12,880
to the next person. So he was through talking to him and trying to get all the information. He was

129
00:09:12,880 --> 00:09:20,480
able to give me the information of all the all the information he had because I just for he didn't

130
00:09:20,480 --> 00:09:26,240
even know what he was doing, right? So I got that information that was a little more information

131
00:09:26,240 --> 00:09:34,720
than I had. They went back online, you know, trying to figure, but the time I got to the very top person

132
00:09:34,720 --> 00:09:40,560
because the operation was actually out of London, but it's not like I got to the very top person,

133
00:09:40,560 --> 00:09:49,680
I've learned so much about computers at this point, networks, malware, build them, buy them, anything,

134
00:09:49,680 --> 00:09:58,000
anything you could think of like fishing. And I end up having to like send an efficient email to like

135
00:09:58,000 --> 00:10:07,120
the the the the top person in the operation, right? End of having to send a fishing email. That

136
00:10:07,120 --> 00:10:12,560
pretty much was very precise with all the information that I have on cover at this point. And

137
00:10:12,560 --> 00:10:22,800
then they called me and so they called me and they didn't do anything. They called me and we went

138
00:10:22,800 --> 00:10:30,320
back and forward. And they was very interested on how I was able to track them more than, you know,

139
00:10:30,320 --> 00:10:36,720
what they're doing wrong with me on the internet with everybody. So I kind of negociate. I was like

140
00:10:36,720 --> 00:10:43,920
if they return my money, I'll talk to them and I tell them like the clues and how I got here. So eventually

141
00:10:43,920 --> 00:10:53,680
they told me they promised me that was going to return my money, but they didn't at that moment.

142
00:10:53,680 --> 00:11:03,840
So I have another email now with more information on it and I sent it directly to the to the to the person

143
00:11:03,840 --> 00:11:12,800
over the operation and then he and the main guy the main guy. Yes. So he ended up finally clicking because

144
00:11:12,800 --> 00:11:18,880
it was more information than what I led on earlier, right? And he ended up clicking. So I ended up

145
00:11:18,880 --> 00:11:28,480
kind of like taking over his whole desktop like his computer. So now at that moment, I see all my money

146
00:11:28,480 --> 00:11:33,760
kind of like just transferring back into my account at this point. So they give me my money. So they

147
00:11:33,760 --> 00:11:39,360
give me my money back. Then I just kind of went to my bank and and kind of like settle with my bank

148
00:11:39,360 --> 00:11:46,080
and everything. But after that point, I never like had any other communication with him. And that kind

149
00:11:46,080 --> 00:11:55,680
of like got me interested. I was like, oh wow. First of all, I felt like I had at least like a skill

150
00:11:56,240 --> 00:12:01,360
or a passion. Where's not talk skills because I guess when I didn't think it was skill just yet.

151
00:12:01,360 --> 00:12:08,720
I had a passion. I always had a passion of kind of like protecting a good guy and like going after

152
00:12:08,720 --> 00:12:17,360
the bad guy, hinted my original, what is it called? My original degree in criminal justice because I

153
00:12:17,360 --> 00:12:22,880
always had a thing about going after the bad guy, protecting a good guy and all that. That's always

154
00:12:22,880 --> 00:12:30,080
a role that I play. But I never really saw myself. I never really saw myself play that role within

155
00:12:30,080 --> 00:12:38,320
like computer, like dealing with computers and not until that actually happened to me. And I feel

156
00:12:38,320 --> 00:12:43,280
like that's kind of what I kind of almost find my destiny in that.

157
00:12:45,600 --> 00:12:54,800
That story is so amazing and just perseverance and persistence and digging in to find your money.

158
00:12:54,800 --> 00:13:02,080
And because I would imagine I've not had an experience with this, but I've been part of multiple

159
00:13:02,080 --> 00:13:10,240
engagements where similar people have been taken advantage of or taken for ransom. And it almost

160
00:13:10,240 --> 00:13:19,280
feels like your identity is gone. Everything about you, you have no control. And it's interesting that

161
00:13:19,280 --> 00:13:27,600
you have this experience and it pivoted you into a completely different feels from criminal justice

162
00:13:27,600 --> 00:13:35,920
to cyber security, which is non-technical, to very technical. So what are some of the challenges you

163
00:13:35,920 --> 00:13:44,720
faced at the very beginning when you switched from into the cyber security industry without

164
00:13:44,720 --> 00:13:52,960
technical background over some of the challenges? Well, let's just kind of go back into,

165
00:13:52,960 --> 00:14:02,240
I think I was my biggest challenge, right? I was in my head a whole lot. There was so many

166
00:14:02,240 --> 00:14:08,240
times where I'm like, okay, I'm going to do this. All I need to do is go back to school and just do

167
00:14:08,240 --> 00:14:13,760
this. Then I will go on Google and do my research and it's kind of like, I almost felt like everybody

168
00:14:13,760 --> 00:14:18,960
had the same story, right? It's like, yeah, I was five years old, my daddy gave me a computer,

169
00:14:18,960 --> 00:14:24,480
and ever since then I'd be like hacking away. And I was like, at this point, I'm like 20 some years

170
00:14:24,480 --> 00:14:31,920
old, right? There's nowhere, there's nowhere I could compete, right? So I started at start pulling back

171
00:14:31,920 --> 00:14:42,320
and to me at the very beginning, I was my biggest threat, I would say. I was the biggest, I was

172
00:14:42,320 --> 00:14:50,160
the biggest thing that held me back because I feel like the industry could be very intimidating

173
00:14:50,160 --> 00:14:59,040
when you're on the outside and is, and we start thinking, oh, okay, then come then you,

174
00:14:59,040 --> 00:15:05,360
then you, all these technical verbiages, like, English is like my third language. Now I need to

175
00:15:05,360 --> 00:15:10,400
pick up another something else on top of that. I don't think it's going to work, like, you know,

176
00:15:10,400 --> 00:15:18,560
getting my head, talking to myself into it and out of it every day all day. So once I was able to

177
00:15:18,560 --> 00:15:24,880
just, and it just didn't happen that I'm just like, oh, I could, all of a sudden, oh, I could do this.

178
00:15:24,880 --> 00:15:31,760
It was somebody else who actually saw it in me, you know? Just kind of like, I'm having a conversation

179
00:15:31,760 --> 00:15:38,560
with you right now, and I just told them, and I told them how I kind of like, build my own hacking skill,

180
00:15:38,560 --> 00:15:46,880
just working on myself. Like, I spent a lot of time building like a virtual machines, like different

181
00:15:46,880 --> 00:15:54,480
ones with, with exploitable system, and I would exploit them myself and just trying to like, kind of

182
00:15:54,480 --> 00:16:01,280
go back and forth and figure out, just understand how things work. So I started doing my own personal

183
00:16:01,280 --> 00:16:08,080
project, but even then, I still didn't think I was good enough because I just felt like I needed to

184
00:16:08,080 --> 00:16:15,680
start at five, and it's just way too late. Until I met this person, and I was talking to them, and

185
00:16:15,680 --> 00:16:21,520
they was like, you put it smart, you could do it. I don't know what they put in those words, but that

186
00:16:21,520 --> 00:16:27,680
did something to me, right? To that person, to tell me that I was smart. And then I was like, you know

187
00:16:27,680 --> 00:16:34,720
what? I could do this. Then I went back and like, find my, find a school and went back and just kind of

188
00:16:34,720 --> 00:16:40,320
took like, a cyber security program in a university.

189
00:16:42,720 --> 00:16:50,320
That's amazing. It's amazing how words from people can positively or negatively affect us and

190
00:16:50,320 --> 00:16:56,320
literally change the trajectory of our life. And I think that's a true testament to you and your

191
00:16:56,320 --> 00:17:06,080
mindset. It's really key when you enter and switch from field to field. Could you share some, maybe some

192
00:17:06,080 --> 00:17:14,720
insights on the shift that you had and how it's helped you thrive in a cyber security field? Because

193
00:17:14,720 --> 00:17:19,920
as you mentioned, you know, there was, it sounds like some imposter syndrome right out of the gate

194
00:17:19,920 --> 00:17:25,840
and wondering and questioning yourself, could I do this? Can I do this? How do I do this? Who's supporting

195
00:17:25,840 --> 00:17:32,960
me? Talk us through some of those shifts that you had to make in your own mind to thrive like you

196
00:17:32,960 --> 00:17:42,960
are right now at IBM. Right. The first thing I really got was really good advice because

197
00:17:42,960 --> 00:17:49,920
and I see that in a lot of like people like career change or you just even people that want to come

198
00:17:49,920 --> 00:17:58,560
into the industry. It's like we all, we tend to want to be open because we feel like if we are open,

199
00:17:59,360 --> 00:18:07,440
we have more options and sometimes I feel like that open the openness, it could be contradictory,

200
00:18:07,440 --> 00:18:13,280
right? Because I was the same way. I was like, you know what? I just need to get in, get me anywhere.

201
00:18:13,280 --> 00:18:22,080
And it took me forever to even get anybody to sit down with me and talk to me about anything.

202
00:18:23,920 --> 00:18:30,160
It wasn't until my mentor at that time just was like, you know what? You should specialize in the

203
00:18:30,160 --> 00:18:38,800
area and become really good at every single aspect of it. And that would be also easier for you to

204
00:18:38,800 --> 00:18:48,000
like to like to grab on into something versus just being open, right? And I felt like that helped a

205
00:18:48,000 --> 00:18:54,800
lot because you know hacking was my thing. So I just kind of started you know learning methodologies

206
00:18:54,800 --> 00:19:00,480
that are being used in companies to be able to like make this happen. What kind of tools are they

207
00:19:00,480 --> 00:19:07,280
using? But you know trying to see how I could better myself in whichever area. So once I would ever

208
00:19:07,280 --> 00:19:16,240
understand the methodology, the tools and just pretty much like the outcomes that needed to come in each

209
00:19:17,440 --> 00:19:26,400
aspect. And also very, what's very interesting is once I understood, there was another thing,

210
00:19:26,400 --> 00:19:33,280
when I understood my why, why I wanted to do this, that completely changed my life. That was a game

211
00:19:33,280 --> 00:19:37,840
changer for me actually. Because at the very beginning, it was like, oh, what are you on this?

212
00:19:37,840 --> 00:19:43,040
Also, they paid, they paid really good money, you know, very, I can just go in for the money, but

213
00:19:43,040 --> 00:19:49,520
I could make money anywhere as far as I was concerned. It wasn't until I was like, what do you want to do

214
00:19:49,520 --> 00:19:55,040
that? And I had to stand back. I'm like, yeah, that's true. But why am I working so hard to get in this

215
00:19:55,040 --> 00:20:03,280
industry? Once I understood why and it goes back to like, I've always been a person who wanted to like

216
00:20:03,280 --> 00:20:09,440
protect the good guy from the bad guy, go after the bad guy. And that just kind of fell naturally

217
00:20:09,440 --> 00:20:14,560
in that thing. And I was like, this is why, this is why because that would give me a lot of,

218
00:20:14,560 --> 00:20:24,640
that would give me like a lot of joy that I am saving good people against the bad guy. And once I

219
00:20:24,640 --> 00:20:32,800
understood that, that mindset shifting that we were being talking about, that's really when it happened

220
00:20:32,800 --> 00:20:38,560
for me. Once I understood what that was, my mindset changed. And then at this point with the

221
00:20:39,360 --> 00:20:47,200
with the tools that I had and the advice that I have from my mentor of like really focusing on

222
00:20:47,200 --> 00:20:54,800
an area, working, working hard to learn everything that need to be, that I could learn in the industry.

223
00:20:54,800 --> 00:21:01,760
And then get some hands-on experience. You don't have to wait for a company to hire you before you

224
00:21:01,760 --> 00:21:10,160
could start practicing and getting your experience. And I'm going to tell you one thing,

225
00:21:10,160 --> 00:21:18,080
while I was still in school, there's this small TV station that streams online. There was a TV

226
00:21:18,080 --> 00:21:26,480
station within the city where I lived in. And I would always go there to stream. And one day I just went

227
00:21:26,480 --> 00:21:34,480
and I was on the website. The website just looked, it was just strange, right? I was like, that was

228
00:21:34,480 --> 00:21:41,360
with my small education or like going into like taking these classes. So now I could see things

229
00:21:41,360 --> 00:21:48,320
differently than before. So I reached out to the, the website was just missing, it was just missing

230
00:21:48,320 --> 00:21:55,680
an SSL certificate, right? So I called, I called the company and I was like, hey, did you know that

231
00:21:56,560 --> 00:22:01,920
you don't have a certificate in this area and then people are filling out the form to get to you.

232
00:22:01,920 --> 00:22:08,240
That could be a security problem and thing. And I asked to speak, because it was a fairly small company,

233
00:22:08,240 --> 00:22:16,000
so I asked to speak to the manager of the company. And they allowed me to go in. So I went in,

234
00:22:16,000 --> 00:22:22,560
I was like, hey, I'm in school, I'm studying cyber security. I would be glad to, you know, to try to see,

235
00:22:23,680 --> 00:22:31,120
what you guys have in place and trying to help you in the air because I only find that they have one

236
00:22:31,120 --> 00:22:38,400
IT person. And nothing was, I mean, they, they was not security focused at all.

237
00:22:38,400 --> 00:22:46,080
Yes, yes. From somebody who would just learn you security too, I could see it straight up.

238
00:22:46,880 --> 00:22:56,880
So when they agreed to like work with me in like trying to help them kind of like create like a system,

239
00:22:56,880 --> 00:23:02,960
a system in place so that, so that the system could be more secure. I have no clue what I was about to do.

240
00:23:02,960 --> 00:23:11,120
I was like, oh, so I was like, oh, you want me to do it? Now, I don't, you know what I'm talking about.

241
00:23:11,120 --> 00:23:17,200
So, but I went back to my teacher at that time and I kind of explained to him and he was like, yes, you

242
00:23:17,200 --> 00:23:22,240
should, you should absolutely take it. And what he did at that moment was kind of just give me like a,

243
00:23:22,240 --> 00:23:28,080
he put him, I did most of the work as far as putting all the framework in place. And I just kind of like,

244
00:23:28,080 --> 00:23:35,680
I was the hand and, you know, and the body doing the activity, but he put him much help by putting all

245
00:23:35,680 --> 00:23:44,640
that together. So once I was able to do that and there was very happy. They gave me a recommendation later.

246
00:23:44,640 --> 00:23:51,040
So once I was there with that and I contacted the next, then I contacted a church, then I did it with a

247
00:23:51,040 --> 00:23:55,760
church, then I did it with another church. So I kind of like went out there and find my own

248
00:23:55,760 --> 00:24:04,720
experience like to build my own skills. And then of course, and my own home build the network. And

249
00:24:04,720 --> 00:24:12,720
like I was saying, like, uh, uh, uh, uh, download many different, um, machines and try to attack them

250
00:24:12,720 --> 00:24:18,960
and between to figure out just so I could get a hands-on experience, build my own network, secure it,

251
00:24:18,960 --> 00:24:26,160
and things like that. So that really, uh, helped me to that when I was able to like come in front of

252
00:24:26,160 --> 00:24:34,240
somebody for an interview. And, and by the way, IBM was like my very, the very first job I had as

253
00:24:34,240 --> 00:24:44,000
coming into the industry. Right? That's amazing. I love you. Use one of my favorite words, the M word,

254
00:24:44,000 --> 00:24:52,640
mentorship. It's such a big word that sometimes we find mentors, sometimes they find us. I feel like in

255
00:24:52,640 --> 00:25:00,640
my life so many of my pivot changes came from somebody saying something to me or somebody saying,

256
00:25:00,640 --> 00:25:07,120
hey, you're good at math, you should look at engineering. But you really followed through. And I think

257
00:25:07,120 --> 00:25:14,000
it's one thing to be mentored. And it's a whole nother thing to follow through, to listen to your

258
00:25:14,000 --> 00:25:20,560
mentor, to ask for their help. And for them to hold you through that process and having somebody that

259
00:25:20,560 --> 00:25:26,400
you can bounce things off of, like it sounded like you were able to say here, I have this thing, I need

260
00:25:26,400 --> 00:25:33,600
your help, here's what I'm thinking. They made suggestions to you and you went and then had the

261
00:25:33,600 --> 00:25:41,120
confidence to go do something, which says a lot about your personality and you were able to leverage

262
00:25:41,120 --> 00:25:47,840
them as a resource while you were building your own skills. And I love that because it's one thing to

263
00:25:48,560 --> 00:25:55,040
to have somebody give us advice. And, but it's a whole nother thing for somebody to take it back and say,

264
00:25:55,040 --> 00:26:01,840
okay, what's my why? Why am I doing this? How can I make this better? How can I learn? How can I help

265
00:26:01,840 --> 00:26:09,120
others? And you really took that directly to heart and made those changes. So for our listeners,

266
00:26:09,120 --> 00:26:16,400
what advice would you give them if they're contemplating a career change in

267
00:26:16,400 --> 00:26:22,400
decipher security or any other technical field, especially if they lack technical background,

268
00:26:22,400 --> 00:26:28,240
like what would you suggest to them? Well, the first thing I would say you could do it.

269
00:26:28,240 --> 00:26:35,440
Like believe in yourself, like that will take you a long way. Believe in yourself,

270
00:26:35,440 --> 00:26:41,760
do not listen to that, that little voice that will come. And trying to tell you other things,

271
00:26:42,640 --> 00:26:52,800
the second thing is, I mean, understand, I always say like, know your why, right? Sometimes we want to

272
00:26:52,800 --> 00:26:59,440
jump into things because it's the hard thing to do, right? It's training. It's what's going on.

273
00:26:59,440 --> 00:27:04,640
But then we find ourself in it and it's just kind of, you know, I could have done something else.

274
00:27:06,480 --> 00:27:14,960
Knowing why you want to do this will really give you not only the passion that you need to get

275
00:27:14,960 --> 00:27:21,280
this through. It will give you the conviction. And it will also allow you to be able to talk

276
00:27:21,280 --> 00:27:35,680
about yourself in a more convict, like you could be more convicting when you speak or when you

277
00:27:35,680 --> 00:27:45,600
try to sell yourself to even a company to hire you because you will be so solid within yourself

278
00:27:45,600 --> 00:27:54,480
that the skills, we could always learn the skills, right? A lot of time, I say, right now I'm working

279
00:27:54,480 --> 00:28:00,640
for this company. Like now if I go and I've been doing this for a while, and I leave and then go

280
00:28:00,640 --> 00:28:04,960
to another company, guess what? I would have to be trained over there or another system for other

281
00:28:04,960 --> 00:28:12,640
things. So the skills are always, you could always learn them. And just as the industry kind of just

282
00:28:12,640 --> 00:28:23,680
always moving forward, always stay up to date. Pretty much, I will always say focus on the area

283
00:28:23,680 --> 00:28:29,600
at the beginning. I'm not saying that this is if you starting here, if I'm starting as a hacker,

284
00:28:29,600 --> 00:28:36,400
this is where I'm staying, but focus on a particular skill set that that would really be that you

285
00:28:36,400 --> 00:28:45,280
could be able to sell yourself on. And that would make it a lot easier to get into the industry.

286
00:28:45,280 --> 00:28:51,120
For example, when I was, let's say applying for jobs at the beginning, it would just like whatever

287
00:28:51,120 --> 00:29:00,720
job I put out so many resumé, so many resumé and nothing was almost coming back at me. And then when

288
00:29:00,720 --> 00:29:05,040
I had to, when I died back and I was like, you know what? I don't want to do just anything in

289
00:29:05,040 --> 00:29:10,880
cyber security. I know exactly what I want to do. Ethical hacking is my space. This is what I need.

290
00:29:10,880 --> 00:29:18,800
And then when I kind of just focused on that, every other resume that I put out there was coming back

291
00:29:18,800 --> 00:29:23,600
with a hit. Hey, we want to talk to you, right? If you know that I was brand new and I would just come

292
00:29:23,600 --> 00:29:33,760
in into the field. And by the time I actually got into a company, I had couple offers. And that,

293
00:29:33,760 --> 00:29:42,160
that flip just changed. It just wasn't any believe that, you know, the direction of like being, being

294
00:29:42,160 --> 00:29:49,200
an expert in a certain area versus like kind of just trying to like know, know everything and not

295
00:29:49,200 --> 00:29:56,240
master a particular thing could play against you if you're trying to get into the field, especially

296
00:29:56,240 --> 00:30:02,880
if you're coming to a, what from a place that would know technical background, right? Somebody who's

297
00:30:02,880 --> 00:30:09,040
been doing, who been having multiple technical skill, oh, I know network, I know this, I know that

298
00:30:09,040 --> 00:30:17,360
they probably would be a lot better for them to be open to the aspect, but especially with time

299
00:30:17,360 --> 00:30:27,200
constraint and you trying to make it, make it happen is to me, it is very, very important that you

300
00:30:27,200 --> 00:30:36,240
that you choose an area, a niche where you actually going to shine and learn everything that you

301
00:30:36,240 --> 00:30:43,840
need to learn, know your why, practice, practice, practice and practice and stay up to date with everything.

302
00:30:43,840 --> 00:30:54,000
I love it. Cecilia, you are such an inspiration. There's so many people in cyber security and as a

303
00:30:54,000 --> 00:31:03,120
woman in STEM myself, I am so happy to have you on the call today. You motivate me to re-look at my

304
00:31:03,120 --> 00:31:10,000
why for so many things and look at the mentors that have come into my life and how I can

305
00:31:10,000 --> 00:31:15,840
be a support and you mentioned ethical, have it be a good guy be one of the people that helps to move

306
00:31:15,840 --> 00:31:22,320
communities forward. I love this about you and it's your third language, English, unbelievable,

307
00:31:22,320 --> 00:31:27,840
your third language, your non-technical and you've done, you've been able to shatter all these

308
00:31:27,840 --> 00:31:34,160
ceilings and I just love your energy and I think one last question for you if I can,

309
00:31:34,160 --> 00:31:41,840
what are your future goals and aspirations in the cyber security field and what do you hope to

310
00:31:41,840 --> 00:31:49,440
achieve in years to come? Oh wow, my aspiration within the industry

311
00:31:51,760 --> 00:32:02,160
since working as a hacker and having to get into a company system in many different ways

312
00:32:02,160 --> 00:32:09,520
than companies who would like to and this also kind of touched back to like

313
00:32:09,520 --> 00:32:18,000
Kaga here in the beginning. Personal data is like a big deal to me, right? I feel like

314
00:32:20,240 --> 00:32:26,080
it is not giving enough attention especially with so many data breached that are going, that are going

315
00:32:26,080 --> 00:32:34,320
out out there and just how easy it is for people to collect people personal data and which is

316
00:32:34,320 --> 00:32:39,040
that information that nine times out of ten end up getting companies

317
00:32:41,760 --> 00:32:50,480
a breached so it is very, we've been on the internet for so long, a lot of us, the majority of us

318
00:32:50,480 --> 00:32:56,640
have been on the internet for so long, we have shared so many things online and it's just not about

319
00:32:56,640 --> 00:33:01,600
just what we share, what the third parties are sharing, what the data breaches are saying about us

320
00:33:01,600 --> 00:33:07,760
and everything is just all over the place and now attackers including myself understand the value

321
00:33:07,760 --> 00:33:14,160
of this information and we are actually not using that information to attack companies whether

322
00:33:14,160 --> 00:33:20,080
it's through phishings, whether it's through credential stuffing, whether it's through you know

323
00:33:20,080 --> 00:33:27,600
vishing over the phone like I remember when the MGM attack happened and somebody and I read a comment

324
00:33:27,600 --> 00:33:32,960
and somebody was like now who gonna give that information over the phone I say do not end on

325
00:33:32,960 --> 00:33:40,800
the estimate, a hacker with the right information you just cannot, that could be anybody so I'm very

326
00:33:40,800 --> 00:33:48,480
passionate about just bringing the education to the average person to the everyday users people

327
00:33:48,480 --> 00:33:56,240
that are on a computer, people that sit behind your organization, behind your network, a lot of

328
00:33:56,240 --> 00:34:03,840
time to authenticate most of us in a company, companies use a personal data so if that personal data

329
00:34:03,840 --> 00:34:11,680
is not protected outside of the workspace that could turn around and become an issue and I just

330
00:34:11,680 --> 00:34:19,520
kind of be like really doing a lot of research in this aspect so is it a way we can actually stop the

331
00:34:19,520 --> 00:34:30,080
attack from happening by kind of like reducing the information footprint of every single person

332
00:34:30,080 --> 00:34:37,760
that is within a company or is it just like I'm just to a process of trying to

333
00:34:37,760 --> 00:34:45,200
which I've learned a lot in this area and I also do a lot of, as also focus on open source

334
00:34:45,200 --> 00:34:50,480
intelligence and my job open source intelligence technique and social engineering and I know

335
00:34:50,480 --> 00:34:57,520
the places I go to get this information and why is this not becoming more of a priority because

336
00:34:57,520 --> 00:35:07,520
as as we go and we continue to see attacks I feel like it's going to come more and more and more

337
00:35:07,520 --> 00:35:16,000
from personal data and I believe it was verizon that one of the statistics say like 60% of bridges

338
00:35:16,000 --> 00:35:24,160
now happen because personal data and this is only going to grow at this point. Yep, I absolutely

339
00:35:24,160 --> 00:35:29,840
echo that. I think it's, you know, we talk a lot about AI but if we can't figure it out now

340
00:35:30,800 --> 00:35:38,800
with AI and in more advanced technologies we're in a big big challenge there. You know, I yet ask

341
00:35:38,800 --> 00:35:46,480
a lot about AI, should I allow chat GPT and all these things and I'm like, well, I mean it depends,

342
00:35:46,480 --> 00:35:55,520
it depends on the strategy but if you can't get it right in like in an on-prem environment

343
00:35:55,520 --> 00:36:02,320
it's going to be harder to get things more secure in the clouds so I know I want to be mindful of our

344
00:36:02,320 --> 00:36:08,560
time and I thank you so so much for being here. I love everything about you and I appreciate your time

345
00:36:08,560 --> 00:36:14,960
and I just feel like you keep shining girl, keep shining, keep meeting, keep sharing and I thank you

346
00:36:14,960 --> 00:36:22,640
so much for being on the podcast today and thanks for being here. No, thank you, thank you so much for

347
00:36:22,640 --> 00:36:27,600
having me and giving me this platform and opportunity to talk to you. You are very soon. Thank you.

348
00:36:27,600 --> 00:36:30,080
Thanks, have a good day.

349
00:36:30,080 --> 00:36:30,880
Good to see you too.

350
00:36:30,880 --> 00:36:39,280
You've been listening to the Executive Connect podcast. If you have questions or ideas on how to

351
00:36:39,280 --> 00:36:45,680
bring leadership to your next level, email us at ExecutiveConnectPodcast@gmail.com.

352
00:36:45,680 --> 00:36:51,520
And don't forget to subscribe so you can catch every new episode. Until next time.

353
00:36:51,520 --> 00:36:54,100
(upbeat music)

354
00:36:54,100 --> 00:36:56,680
(upbeat music)

