In This Episode

In this episode, Stacey Cameron, Founder and CEO at CyCam Strategies, joins me for Voices of the Vigilant Season 2, Episode 11!

You can learn more about the conversation and the guest below.

 

Tune into the audio version of this episode by clicking the player below:

 

Tune into the video version of this episode by clicking the YouTube player below:

VIDEO: Voices of the Vigilant S2 Ep11

The Art of Redirecting Force with Stacey Cameron , Founder and CEO at CyCam Strategies.

About the Guest

Stacey Cameron, Founder & CEO of CyCam Strategies, an executive cybersecurity and risk advisory firm. More than 20 years as a CISO, strategic advisor, fractional security executive, and trusted partner across SaaS, healthcare, finance, education, retail, energy, critical infrastructure, defense, and government. Judge for the Cybersecurity Woman of the World Awards and a 2026 CapitalCISO ORBIE Award finalist.

Full Episode Transcript

Jess Vachon: 00:33

Hey, welcome back to Voices of the Vigilant, the show where we sit down with the people defending our digital world and pull back the curtain on how they actually think. My guest today followed her father into technology, earned her stripes on the front lines of federal cybersecurity, and now advises organizations as a founder, a fractional security executive, and a CISO. She is the founder and CEO of CyCam Strategies, an executive cybersecurity and risk advisory firm, and currently serves as a CISO in the anti-ransomware world. Along the way, Direct Defense, the Department of Homeland Security, a computer science degree from UMBC, and a Meyerhoff Scholar, a judge's seat at the Cybersecurity Women of the World Awards, and a 2026 Capitol CISO Orby finalist nod. And no exaggeration, a black belt who once threw grown men across a mat while six months pregnant. Saying she's an overachiever doesn't begin to describe her. Stacy, welcome to the voices of the vigilant.

 

Stacey Cameron: 01:36

Yes, thanks for having me. I'm so excited to be here with you today and really get into a fun, fun conversation.

 

Jess Vachon: 01:44

Great. I know we talked a little bit about before we got started, and I know this is only Tuesday. Thank you for reminding me prior to us going live that this was Tuesday, not Monday. How has your week looked so far?

 

Stacey Cameron: 01:56

My week is it's not too bad, actually. So usually, it's good and I'm saying this, and I'm in the middle of working with a client for an audit. So that tells you how my typical weeks are. So I'm really excited just about you know helping my client through this particular audit and some things that are coming on, new potential things coming new to the horizon, meeting with a some other strategic folks in the field that are considering startups. So we're doing some advisory there. So it's a lot of fun that's coming up. I'm really enjoying this side of this side, the advisory side of the cybersecurity world.

 

Jess Vachon: 02:31

Nice. I like to start these conversations getting in the “Wayback Machine”, finding about you know what shaped you, what led you into this field. So let's start with your father's footsteps. So you followed your father's footsteps into computing. What did he do? And did watching him, what did watching him teach you about the field before you even chose it for yourself?

 

Stacey Cameron: 02:53

I'll even go all the way back to you. I would I was probably maybe 11 or 12. And I went to work with him, and it was just the cool gadgets. So cool gadgets I loved. And we had like this really big office, and my sister said all he does is talk all day. And that's what she saw, but I saw this wonderful world of gadgets, and then later on started working with some folks he was working with that were doing music and teaching with math and science, and it was the startup tech company that was building this, and those things started interest with of interest to me. And I started reviewing some. I love math, so I started reviewing their product before they would release it, and it started because I found an error in the logic. So I was that kid. I was like, this should be greater than or equal to because you're missing an infinite set of numbers. I was that was just the type of kid I was, but even just sort of watching that grow, and he even did it from a community standpoint on the church side as well. So I helped him through that. And I just started programming in high school and getting more exposure and really understanding more about various things from a computer science perspective, and grew from that into really understanding that people aspect. And that's where I started going into more of IT of helping people and communicating with the business side and the scientists to make sure they could deliver the types of projects and products that they wanted. And from there, it just started becoming very natural as far as understanding. I got into regulations and cybersecurity, all that came in. I'm going really quickly, right? So I progressed in that through the when I started supporting an AD as a contractor. That's really when I really got into doing what we call it information insurance at that time. But it was the security standards and the security guides and controls that we had to focus on. So really going through that and starting to understand it and love it. And I started seeing it was giving people a headache. And they're like, oh my gosh, this is more security. Oh my gosh, this is more compliance. And I was wondering, like, what's the problem? Isn't this fun? But what I was seeing was people just looked, they didn't understand why they were required. So when the laws and regulations started requiring certain security standards and guidelines and processes to be put in place, there was a lot of there was no explanation, or people didn't have time to get an explanation. And that's kind of when I really start growing from a consulting standpoint of understanding the underlining why this is needed. And sometimes certain things they were right. It just made no sense. And kind of really trying to explain it and translate it from a standard perspective and kind of just make people feel a little easier when they're trying to work towards their compliance goals and security goals, and really putting in perspective on hey, you could ignore this, but this is the risk that you're putting your organization at. And I wasn't the one I wasn't gonna beat you over the head and tell you have to do X, Y, and Z. I'm like, absolutely, you can say no. And this is exactly what will happen. And then the stuttering starts. So it's like, all right, well, here's the here's an alternative method that you could try. And you know, don't buy it off more than you can true, phase it in. So it was just, I have a general love for helping people, and I do that from a cybersecurity perspective as well as a compliance and regulatory perspective. And I just look at it as helping people understand to achieve their end goals. And I love it, and I've been fortunate to be in a lot of different industries and a lot of different spaces to be able to do this. Nice. I think that's a short version.

 

Jess Vachon: 06:30

Yeah, that's great. That's great. So, I want to talk a little bit about your time at UBMC and the Meyerhoff Scholar. I had to look it up because I had never heard of it before, but I think it would be great if you could share more about the program at UMBC and the Scholars Program and what you took away from your time at UMBC that you incorporate into the work you do today.

 

Stacey Cameron: 06:53

Oh, absolutely. So I big fan of UMBC and even a bigger fan of the Meyerhoff Scholars Program. So the Meyerhoff Scholars Program originally started with there was a need between the it started for black males. That's how the program we originally started. There were black males in Baltimore, and there was this need of these are brilliant men without, and some of them didn't have the resources to go to that higher education. So the original founders, Dr. Friedman Rabowski, Robert and Jane Meyerhoff, they came together and said, what would happen if you enabled these folks with not just financial resources, but that mentorship, that guidance, which is different than a lot of scholarship programs. Some scholarship programs, they take off the financial burden, which is wonderful, but you're kind of on your own from there. The Meyerhoff program was indeed, we called it when I went, we called it a summer boot camp. So you had six weeks leading up to your freshman start, and you would come together, you would take classes, you would do etiquette lessons, you would visit different businesses. We did visits to NSA, to NASA, and just a lot of other different areas that were partners with the program so we could really see what that next level of research sciences look like. So a lot of that was promoting terminal degrees, even though I didn't go and do my eventually I didn't do my PhD, but it does promote those terminal degrees in the STEM field. But it's taking these really bright students that are already accelerating and giving them more than just money as a program, but showing them how to work together, showing them how to understand that diversity matters. Even the program grew to be more diverse. So it started with black males and then it opened to male, males and females, and it opened to everyone of all ethnicity, races, origins, everything. And the program has is it's been going since 1988, and it's still growing strong. There's still a lot of support. I still work with the students that are coming into the program. I still do interviews with some of the high school students. It's just a it's really pushing that research in STEM. And I mean, and some people, it's a lot because you're like, I'm in college, I'm finally leaving my parents' house, I can kind of do my own thing. But wait a minute, I gotta go meet with my Meyerhoff counselor because I'm not doing the best that I can in one of my classes. But it gives you those resources, those study groups, those people, those older folks who have gone through the program. I'm still I still get you know, folks reaching out to me for like, hey, you know, this scholar just finished XYZ. They want your perspective. Or I have friends that are graduates from the programs that are medical professionals or biomedical professionals are like, hey, I got this group. I want they're about to present. Hey, let's run some, let's do a dry run with you so you can give some feedback from an industry perspective. So it bridges in all those different connections from across the field. And even those that didn't stay in the STEM field, we are still like family, and you have judges and lawyers and entrepreneurs and all different types of areas, but it's really when I tell you it's a diverse group of people and talking to some of these students that are coming in, the things that they're going through and what they want to achieve. I've had students who are high school students saying, you know, they're going to school, they're taking the most advanced classes, they're doing dual enrollment with college courses, and they still have to go provide for their family, right? So they're they have a job where they're contributing to the household income, or they're taking care of their younger siblings so their parents can work, or other things where there's all different types of individuals, like some of them, a lot of them, of course, everyone went through COVID, right? Through the pandemic, on then you had to transition on how to learn. Some of these students will give you stories that puts you in tears, and they're like, but this is the reason why, you know, I want to cure cancer. This is the reason why, you know, I want to do more research for the underrepresented in the field. They're looking at different, all different types of things from a medical perspective, from an engineering perspective. And it's these minds, and they're there, they're us, they're the next level of us. They're we're I'm older, I'm getting older. Yes, you're getting older, you're beautiful, but you're getting older. We have these folks that are coming in afterwards. And even from a when you're looking at industry and a cybersecurity and tech perspective, and you're wondering where that next level of talent is coming in, where you see when there's a drop, maybe in enrollment in science and engineering courses, how do we keep them interested? How do we start this? And to me, it starts in education, it starts in elementary, just getting that interest and being that exposure that you may not have, reaching out to all different types of populations. Even growing up in my county and surrounding counties and what have you, I could see that certain areas were they were more privileged with the type of resources they had in an education system. I would see how does a class survive for half a school year without a permanent teacher? And you're, you know, you're doing things that you could essentially print out on the internet and do it yourself. What where's that motivation? Those types of things. So I'll so Meyerhoff particularly building that next level of talent and all they do in it in the program teaches you to pay it for it. Too much is given, much is expected. And that's what continues to happen, and it's growing, it's growing, it's growing. There's probably about I think 2,700 or so Meyerhoff scholars that have gone through this program, and it's I'm still able to volunteer and work with the program, so I enjoy it. So, and it's at UMVC.

 

Jess Vachon: 12:55

So, one, yes, I am getting older. And I do I admire what you said, and I think it's a truth is that though there's some of us that are in the field that were pre-internet or age of internet coming about, we've seen the iterations, we've learned in a different way about technology than people today have. And we had we there were certain things we didn't have that could have helped us through our college experiences. You were lucky enough to find this program, and it sounds amazing. It sounds like something that needs to be at every college because we take our graduates from high school and we throw them in the college and say, Here, you're gonna spend a hundred thousand dollars a year for your education, you gotta figure it out, and you're gonna owe us half a million dollars when you're done, and good luck. There's no structure, they don't know fully how to adult yet, they're still maturing. They may or may not have good learning skills in hand from their high school experience. They're all coming to college at different levels of capability. They have struggles, as you've noted. You know, I don't have numbers in front of me, but I bet if we were to go and pull people going into college, half to three-quarters come from very diverse, very challenging backgrounds. And they know college has been put out in front of them as this is how you're gonna be successful in life. If we're gonna put them there, we need to give them some supports. And not just at the front end, not just going into the programs, but I think all along the way. Regular check-ins and you know, helping them think about the next steps. And I applaud you for continuing to give back to the program because those who've been through programs, those who have experience can help the newer generations avoid some of the pitfalls they went through, some of the frustrations, make those connections for them that help build their success. And that's what keeps someone that has that passion, you know, right out the gate. It keeps them engaged and energized and hopeful. And that hope carries so many people through their lives, right? The hope that I can reach my dreams, I can do more, I can provide for my family, I can change the culture that I live in. That those are huge pieces of motivation that I think we need to encourage.

 

Stacey Cameron: 15:25

And absolutely now and the scientists in me, right? So I love the data points. My sister and I are 18 months apart. So she's she was a year ahead of me in school. She received a scholarship to another university in Maryland, to University of Maryland College Park. So she received a scholarship to that school, I received UNBC the following year. Mine was the Meyerhoff School Scholar, her was just financial aid. And we had totally different experiences, right? So when I had struggles with my courses, I had an attire, I went in with a cohort of 47. There were 47 of us total. So I went into college after living, breathing, walking with, eating with 47 other students for six weeks. So I already had sort of that same-minded, focused group of scholars with me. And what I tell people all the time, when you're doing with those, especially academic scholarship recipients, you're used to being at the top of your class, right? So it's the top of your class, and you've been at the top of the class for typically several years. And when you get to higher education and you're in those groups with other scholars, they've all been at the top of the class. But now it's on a countrywide or international basis. So you're used to not having to ask for help. And now you're in a position like, oh my, I actually need to ask for help. But where do I go? Everyone used to come to me. So those types of things and those resources being available to me where I had a different experience and dealing with certain things versus my sister who struggled on that end a little more. And I even teased her. And my graduation was, I think, an hour before hers. So I was like, it still counts. But those types of things, but we definitely have, and my mother was there all the way watch watching, watching us. She was very involved. Very, very still involved, no moms. But she always has that comparison of watching her two girls with the two different programs. So that's another reason why I'm definitely an advocate for it.

 

Jess Vachon: 17:47

Awesome. All right. Now I want to pivot to your early career because we've talked about this before, and I was I am fascinated by your perspective of working within the government. And I, as I mentioned before we went live, I think it's important for other people in 2026 to understand what it's like to work within the government and give to your country in a different way, not necessarily in the military, but bringing your skills to government service. So early in your career, you were an information system security officer at the Department of Homeland Security, correct? Yes. And you specifically supported ICE and Homeland Security investigations. Talk about your time there, talk about what you learned and you know, your view of government service, because I think it's very insightful and very unique.

 

Stacey Cameron: 18:40

So, I started as a contractor, contracted with ICE for about eight months before I applied to a federal position. So, there's a as a contractor, you know, you're coming in, you're getting all the work, you're working hard and you're in and out, but you really just focus on the task at hand. When I became a federal employee, then it opened up, well, you know, I'm not confined to the scope of our contractual agreements. Now it's to the mission, right? So even going in as a civilian worker for ISO ICE has a lot of law enforcement. And so, you have law enforcement employees, and you have federal civilian employees. So, coming in as a federal civilian worker with ICE, I had a little some expectations because I also did contract work for the Navy, but the Navy runs a different program than your federal civilian agencies. And so, coming into one that didn't have the same level of structure at structure, but it wasn't military structure, it was an adaption from that. Because when you're working in certain areas, especially from being a security officer and you have to work with different business system owners and different folks, you have to make sure to be effective, you have to really understand how do they operate, how do they understand things to be, and how can you make it plain for them so they can essentially meet the, and these were requirements that were pushed down from Congress, right? So, a lot of what I did was based on federal information security laws and dealing with the different systems. So, I supported classified systems as well as mostly unclassified systems, but some classified systems. But working in the government, you see a lot of different things. One, I definitely I swore an oath, and that oath still stays with you even after you leave government service. And I meant it. I wanted to, and I was excited to be an employee to really serve my country, right? So, I never served in the military, I've always been a civilian, but being able to support our law enforcement and ICE does a lot of different things that a lot of that I wasn't even aware of until I worked there, right? So, there's anti-money laundering that they're working on, gang units that they're working on, narcotics and all those types of different things. One of the biggest initiatives that they do that really was pulled the pulled on my heartstrings was fighting human trafficking and child exploitation. So as a federal employee, I went beyond the security aspect of it. I was able to go and take my experience from understanding the systems and applications and tools that we have to spend some time with our child exploitation unit and really saying, hey, we have these tools that maybe help, you know, gather evidence that we can give to the respective officers that they can add to their package. Because when you're looking at it from a law enforcement standpoint, you have that investigation, and but you know, you got to go to court and things have to stick. If they don't stick, then all that work that you've done before to pull these the bad guys off the street is kind of for null. So, you want to make sure that they can do these things quickly and from a support. Perspective so that was beyond just the security aspect of it but really getting out there and understanding all sides of equation so yes in the news we see a whole lot of different faces there is the good the bad the ugly there is that everywhere and that when and working inside I got to see I got to see it all there were some that I got to see that were disappointing but then there were a lot more that were really out there trying to make a difference and things that were being getting clouded from all the other areas that were happening. So, I don't take anything I don't want to belittle anything that's serious from that standpoint of anyone being mistreated or what have you but there is a lot of other focused areas when folks are able to stay on the mission to help the country overall and I'm strengthening the actual citizens there. So yes I was excited to be part of that most of my time was working with systems and systems owners and making sure data was protected and safe and designed well and working with different vendors and contractors and what have you so it was a lot of great technologies I really got to expand working within mobile applications and the underlining technology and working with even different sectors within law enforcement to say okay what do you need to do X, Y, and Z and explaining on this is why you shouldn't do that because it presents a security risk. But because you have this need, let us find a way so you can get done what you need to get done without slowing you down. And that part and then translating that to the business side right so the business side they may not understand what our law enforcement is doing every day because you know they're focused okay this is coming down from Congress. These are our policies this is what we have to do but really to help them understand hey this may be a matter of life or death this may be a matter critical for you know building cases or what have you so let's make sure that we're able to focus on these aspects to get these officers what they need to be safe.

 

Jess Vachon: 24:02

So, a lot of different aspects of it so are anything questions in particular that you wanted to ask about it but I want to highlight something I think you touched upon and you kind of framed it in you know we have these regulations and these ways of operating but let me see how I can advise you a different way to approach this. And I want to highlight that because I think a lot of us who haven't worked in government service think it's so rigid and so slow and some people have been there so long that change doesn't happen and things don't get done quickly you kind of touched slightly upon it but maybe go a little more in depth about the people behind the scenes their commitment their drive and when they're met with red tape obstacles within their own operations how do you work around those especially when it's something as important as security and supporting security initiatives and child trafficking and gang related activities and stuff like that. Those are all critically time dependent can you go a little more in depth?

 

Stacey Cameron: 25:08

Absolutely so and you know I understand when people say government can be slow I still stand by that but it's because there's a lot of processes and there's a lot of essentially red tape but they're in place for a reason right so there are certain things that you want to make sure are in place for instance that you're not purchasing products from folks that are intending to borrow in the US and those types of things which is why some of that exists but you have to really understand when you have critical missions that we need to understand okay we need to move this along and being able to be that voice I only understood that because I worked directly in support of law enforcement officers. I saw what they were doing. I went to their command centers I went to their different locations and was right there with some of them when they were running operations. So I see the I saw it firsthand and a lot of what happens when folks are on the business side on government they're not really seeing the urgency of what happens for certain tasks. And I think they that needs to be better communicated and I'm always big on fine-tuning processes what is the fast track there's always and there's always some way that you that people will fast track and I'll tell you law enforcement's going to get things done one way or another and if we want to make sure that we have everything we need to provide them with the services that are there because some things are an immediate need where you can't go through the same red tape but you don't want to bypass critical checkpoints and that is that communication of really understanding and having somebody to go to bat on you like I would go into various directors offices I went in with our privacy officer our lawyer she and I had conversations all the time but it's like hey let's say we got to explain this because we want to make sure from a legal standpoint we're good to go but I want to explain this especially if someone's not as technical as the request that's coming in and we want to make sure that we cover all bases. But that was just one of the things that I did I would go to bat for the teens that I work with and explain this is why this is an urgency. I mean sometimes you had the to drop a hammer or two but I mean that's just the nature of business. And but yeah so sometimes it can be like I've even said things like oh my gosh this is taking forever I mean there's definitely a difference from the private sector to the government and that's why I'm seeing a lot that's changing in certain areas of the government that I'm looking at where they're bringing more sort of private trying to bring more private sector in to understand a difference like hey this is how this usually streamlines and so not sure how all that's going to work out but we're here to see but I understand because I've said the same thing before and I'm working in different tools and you know they're all excited hey we've got this and I'm like man that's about four years old we're on to something else now but you just made it through all the it made it through procurement so woohoo but that's I mean that was government for you. So you take the good of the bad with it and you just make it work. So I was like okay well this is what we're working with let's make it work. So but making sure like some of the aspects of it that have the RD so the research and development aspects of government is really great because then you have those cutting edge technologies that they're out here testing and then being able to implement. So I was also fortunate to work with some of the teams over there's a lot of collaboration especially within Homeland Security because there are so many different components that make up Homeland Security. And so I was fortunate as a federal employee to be able to collaborate with others and seeing some things that were cutting edge on technology so cutting edge in the government like yes these things do exist. And then just how to you know how do we make them available for those that need and just it's a lot of that communication some folks that know you do something for years and years and you just keep doing it but you have to understand the way the world goes the way technology goes there's always going to be a better way you know the next year how can you how can we improve so some of those types of things of being able to work with the different let the leaders know right so and they'll tell you their strong points of like you know this group is they're just not they're a tech savvy I was like say less we got you we can help you we can make it foolproof we can help you out on that aspect so I mean even just I'll give you one example of joint collaboration. It was really funny to be in a group with a lot of different government law enforcement organizations. So I think we had like some folks from alcohol, tobacco and firearms Department of Homeland Security I think I don't know if the FBI was in the room but a lot of different other folks and we were with a vendor and you've got like Coast Guard I need things that can float and you've got you know CVP I need things a customs border control I need things that can get you know shot at and you know it is you know I need something that can fall off a truck so it's really it was really fun understanding that aspect of and that translates even into the private sector no one standard will fit for everyone right so everyone has their different type of customization with ever with their tools and shoes and even mapping it back to regulatory standards right so you have a regulatory requirement but it may be done differently depending on where you are so but yeah so yes government yes it can be slow it is going faster maybe but it definitely does have that aspect but there are some areas that are on cutting edge and are moving quickly so it's a mixed bag but yeah it's still the US government thank you I love that we just pulled back the curtain on government service the good the bad and the ugly but the honesty was there.

 

Jess Vachon: 31:11

And I intentionally wanted you to talk about this because I think we owe those in government service a thank you a big thank you a kudos for the work they do behind the scenes because it's not always glamorous it's often hard and it's often unseen and then we hear politicians come out and rail against the government and government employees well you know what that's a large segment of employment in the US it moves a nation it's and it's important to our overall security and well-being so thank you so much for you know highlighting and championing the people behind the scenes and I think that's a good segue too so you talked about practicality and CyCam's whole reason for being is making cybersecurity practical tell us about a little bit about CyCam and I hope I'm seeing CyCam right so CyCam Strategies I started this one so I previously started a company and then branched out and created CyCam from that which kept a lot of the same mission but one of the needs that I was seeing is kind of what we touched on earlier was that strategic advantage that I've been able to focus on of working across so many different industries from a consulting perspective and even being a former federal employee.

 

Stacey Cameron: 32:39

So I've worked and helped folks in healthcare in the financial institutions gaming and entertainment education federal government department of the defense or now department of war whichever acronym you want to go with but from that standpoint I was able to see certain things that were effective certain things that were ineffective but it made it easier for me to kind of identify and working with others and being able to say okay finding others like hey you understand this you've seen this way we can use our knowledge and our skill set to help these organizations that are trying to tap into a particular space right so if they're trying to sell to the federal government with a lot of organizations I work with they want they were breaking into the federal government but no one in the organization had previously worked with the government so there were a lot of unknowns right so there's what you assume but then there's what is actuality so those types of things of just being able from a strategic initiative and then I've advised a lot of CISOs and CIOs and from those aspects of okay so let's look at it from an enterprise level let's look at risk let's look at how you're building your cybersecurity programs I've worked with I have some fun examples of helping different companies trying to make sure we let's keep this up one of the companies I worked with they had an assessment and their assessment was like hey you got to have this 24 by seven sock right you got to have it and one of the things that we're coming in so I'm coming in to help you get things ready help you build your programs you have your assessment reports you have ones that are coming up you're trying to meet your needs trying to making sure that this is required to you know make tap into this multi-million dollar project you know it's a requirement you got to have a sock tour or what have you so those types of things but really trying to understand and these folks are just getting help so they're getting reports and the reports you got to decipher some of these reports that are telling them you need X Y and Z. I'm like well this company sells SOC services so everything they said you needed is things that they can provide which is great you have a resource but let's look at the feasibility like do you have an emergency brick problem let's just say that's an example I don't think you do. And so those types of things of like yes this is needed but you don't have to build out this multi-million dollar one this will be sufficient for you and those things of really helping people understand and put it into perspective is able what I'm able to do under CyCam. So whether people are you know talking about mergers and acquisitions those types of things of like hey let's look ahead let's look at these companies let's look at the type of risk that I'm going to take on or if you have startups that are coming and they're at a certain point and the starter's like okay you know we've gotten in we've gotten our customer base going we've been going for a solid two three years now we need to be a little bit more strategic from our cybersecurity perspective so let's bring CyCam in to come in and help with that situation. So it's one of the things that I always say honesty integrity accountability right we always get the my husband always tells me you just always right I was like well mostly but it's not just from that it's just the level of detail and research that you're that you attack a problem with and to identify those solutions. So when you put that much level of effort in that accountability is strong right so I'm gonna stand we're gonna stand by this decision stand by these solutions you have to be able to back it up right so why did you make this decision a lot of different you can make several different decisions why did you choose them with the information that was presented at that time this is the best decision and I will stand by that and we're and I'm okay with that and those types of things to me are needed. I've always wondered when people get really squirrely even if you're wrong right so if like oh yeah that was my decision I thought that was the best thing at the time but it didn't work out the way I thought it was going to work out but how do we recover right so I had an intern one time and I said you were the best intern that I've ever had and he said what do you mean I broke a lot of things I said I know but you fixed it and you fixed it on your own doing your own research doing your own due diligence and you only engaged me when you absolutely needed to I said that is the type of work ethic that is the type of character that is the type of things that you can't buy that's just who you are and those types of things I said and that's what matters there are we are going to make mistakes they're going to happen we're in a day and an age and Jess you remember this years ago it was all about preventive from a cyber security standpoint right if you got breached and somebody did something wrong it was always their fault it's like using the CISO right so the CISO's fault right you should have been doing this better you should have been doing this better but now we're in the point where some breaches have happened with so many high profile companies and organizations that we're everyone's starting to understand it's I mean assume breach right this is what we're doing and from that aspect of it how do you deal with it's not just preventative but it's resiliency how do you recover those types of errors so we're not just looking from that aspect we're doing preventative detection recovery those types of situations because they're going to come in that planning that preparation that we need to be aware of so those a lot of those areas is where CyCam helps organizations from an enterprise strategic standpoint yeah a great example with the intern and allowing you know mistakes to happen because that's how growth happens and then also touching upon soon breach right it's impossible it is impossible for any CISO any security professional to go in an organization say you will not be breached technology is moving much too fast.

 

Jess Vachon: 38:57

AI has completely changed the landscape for us so it's understanding that everyone is sharing in the responsibility of protecting the organization which I think to your point you know things have changed over the last 10 to 15 years. It's no longer just the CISOs responsible if you use your risk register effectively it's the line of business owners it's the CEO ,CFO, everybody has a stake skin in the game right, and they need to understand that we have to educate those that come in I'll say and this was a lesson learned on me learned for me.

 

Stacey Cameron: 39:32

So, we had a new C level exec come in and they have an area that they're responsible as you know when we're dealing with incidents and we were doing our annual tabletop and she was asking great questions but some of the questions she was asking should have, she should have already been answered. And I took that on me because I didn't run her through that training scenario before when she first onboarded and that was one of the takeaways like making sure as we're bringing these new folks in that responsible yes be aware of what we have be now other people were able to answer certain questions but from that perspective is like oh let me make sometimes you know the sea levels get so busy that we're like oh we don't you know don't want them bog down their calendar but for certain areas they absolutely yes get on the calendar arrange that making sure that they're trained you know I say we give you a few days a few weeks to figure out your organization but by day 30 we're getting on your calendar to make sure that you understand what your responsibilities are from a cybersecurity perspective. So yeah so that was one of the things that one of the takeaways and like yeah we absolutely need to make sure that when we have new folks coming into these positions that we don't just wait for our annual training that they're trained within time of them coming to the organizations because you know things may happen before then and it'll be great to find to be able to find some new areas of improvement instead of things that are already documented. So those types of things just for us to be vigilant with and aware of right yeah absolutely I tease this at the top you made the case that the threats have fundamentally shifted attackers aren't breaking in anymore they're blending in do you want to paint the picture for us about that and what you mean by blending in oh yes so all right so this is a lot of fun so we have a lot of different technologies on your as you're talking about that things are growing so there's it's not just tools you have AI you have deep fakes you've got all types of impersonations and as they're starting to blend in they're doing things a lot more they're tactical. So before you get a fishing phone call and someone's trying to study with something you know it's an accent that you don't recognize and they're not saying things the right way and you're like okay this could be fake but now you're people are like okay if we're gonna target these people we're gonna target folks that are in their own country. That way they you know they recognize the accent and then they start automatically feeling safe. These and tools and enhancements have gotten so well that things valid contacts valid phone calls or what have you are really starting to come into question if they are asking for anything sensitive. I think I was with my dad two weeks ago and he took a call on speaker phone and I was like don't give them any information you call them back directly I was like he's like yeah I always do that I'm gonna check this I said I know I said that sounds like it could be real it could be fake but they're blending in from a standpoint of sometimes they're in your environment for an extended period of time so they're understanding how you operate how you communicate so now if somebody wants to impersonate me I'm like oh Stacy's always you know loling her or what have you at the end of her email. So now they've gotten a bit more crafty from that aspect they're using all different types of tools that are going undetected by some of your standard tools they're blending in with processes that are seen to be standard operational processes. So your tools that are designed to detect those aren't going to detect these types of things that's happened a lot from I spent a lot of time with ransomware so a lot of time dealing with that's how a lot of ransomware groups operate right so we're going to use your remote max as tools that you're already using and we're going to exploit that we're gonna exploit your vulnerable drivers so I haven't installed anything that's malicious. I'm just exploiting what's already there. And then once I you know get hooked into your environment you look at these cases and people are saying oh yeah we realized we had intruders in our environment for three months or six months or sometimes even it goes back even longer than that. So now they're in your resilient systems they're in your backups that you go to you know if you have to restore now you have to what is that true genuine restore point that I should start with. So those that level Of complexity, that level of advancement is really coming in. And we always talk about, you know, we always like to beat up on our end users, right? It's always the people. It doesn't matter what you put in place, people will undo you every time. So, you know, so it's like, oh, we put Monty Factor in place, but now we just keep sending them pings, pings, pings, and they get tired of, and they just say eventually one time they're gonna say yes instead of no. And now I'm in, right? So those types of things. So even from that perspective, we've got to make sure how do we educate our end users, how do we make it easy for them? But they don't, that's not their job to be the experts. We have cybersecurity professional professionals. That's our job. Our job is to stay on top of that. Our job is to do our best to keep up and to reach out to those. I mean, we don't touch to know everything, but we know we need to know where to go get the information. But you know, your standard user, we don't have to have them to be CI SSP level, cybersecurity or what have you. They should be able to sit down and do their job, and we should be able to help others put certain things in place to be able to tackle what's happening. And again, I will say it a million times resilience, resilience, resilience. Because if somebody wants something bad enough, it doesn't matter what you do. They're if they want it bad enough, they have the resources. You have nation state back attack. So they want it, they're gonna go get it. So, you know, let's prepare. So yeah.

 

Jess Vachon: 45:28

Yeah, you know, and when we say it's always the people, I think the perspective is that's individuals clicking on stuff, but it's the people that are in charge of the organization as well because they're making the decisions on budget and security, they're making those trade-off decisions. So, yes, it's people, but not just in people clicking emails, it's people making decisions throughout the organization. And it's a valid and important point you make that it's our we're the experts, so we're supposed to help the people not make those mistakes. And if they do make a mistake, that we've put defense in depth that catches those mistakes before they cause damage.

 

Stacey Cameron: 46:10

And you brought something up. You mentioned the budget, so it's like now the technology from that advancement has outpaced most budgets. You can't just like, well, you know, this happened. Let's get this tool, let's get this tool. The cost of some of these tools, the cost of doing the research to really understand your organization, how your organization operates, and what you really need. It's it is growing. So you at some point something's gotta give. It's just an you don't have unlimited funds. So you gotta, that's why it's like resilience. You gotta prioritize. We and don't we still don't go away from the basics. We still making sure that we have our perimeter protections, we have our access controls, those types of things are still needed, our backups, right? We just advance our tactics as technology go grows, but we can't get all the fun tools. I wish I could, that'd be fun.

 

Jess Vachon: 47:02

Yeah, and it's not just getting all the tools, it's the speed to solutioning. It's the procurement cycle now, yeah. Is it is make or break for security as well. Because if you need something, the threat is here now, you need a solution in place, a three to six to nine month procurement cycle and or budget oversight on that, yeah, not helpful. It's not helpful. Not helpful at all. The threat actors just keep moving, and that six months, that nine months, now they've moved three or four or ten steps ahead of where they were. So important message, I think, to get out to everyone is each of the pieces of the puzzle, or each of the parts that help you build the program, procurement, finance, leadership, all have to be moving in sync and all have to be executing in it in a timely manner. You know, what when it's when I'm asked for a three-year plan from anyone that I work with, I'm like, yeah, I can give you a three-year plan, but in 18 months, probably less than 18 months, it's gonna be invalid. So, you know, I'll give you six to nine, six to nine months. I'm pretty sure what we need in place. 12 months, yeah, I'm probably still good there, but after that, it's guesswork because I don't know what the next thing, the next threat is gonna be that and when it's gonna come. I know it's gonna come because I've been in this technology field for 30 years. I've seen the cycles, but it's gone from once every five years to once every two years to every other week. Now we get alerts from CISA or wherever that there's a new exploit. And yeah, it's I don't want to say it's the speed of light, but things are changing pretty darn fast these days.

 

Stacey Cameron: 48:47

Oh, yeah, absolutely. So it's really understanding your threat landscape or your customer's threat landscape and their security response here and explain it to them. I'm like, this is where you are, this is my recommendations, or you know, what are your thoughts here? Where's your business going? I'm starting to see certain things now where you know you've gotten these two and three year deals, and now you're stuck with things that you aren't that are ineffective. And you're like, oh, I'm gonna wait my other year, or I'm bringing legal in to see what we can do. Like, we need to get out of this because you know, we've got things tied up our budget that's at this point not needed. So those, yeah.

 

Jess Vachon: 49:28

So, such a great point. I have stopped doing three-year agreements, I do one-year agreements now because I have to be able to pivot and I don't want to be locked into a solution that is no longer serving the need. Are there some that continue to serve the need? Sure, a vulnerability assessment and management platform. There's not a lot of change that's gonna happen there necessarily, but you know, if you're looking at endpoint protection, well, a lot of things are changing around endpoint protection, right? Cloud, cloud security, a lot of things are changing there as well. So important to look at those aspects along the way. Now, I want to touch on one thing because I think it's really important. I mentioned this at the beginning too. You hold a black belt in Aikido. Did I say that? Aikido?

 

Stacey Cameron: 50:10

Aikido.

 

Jess Vachon: 50:11

Aikido. And you mentioned throwing grown men around while six months pregnant.

 

Stacey Cameron: 50:15

Loved every bit of it.

 

Jess Vachon: 50:16

Yeah. One, why did you choose that particular martial art? And two, what did it teach you that you actually use in your daily life in terms of defending an organization?

 

Stacey Cameron: 50:28

I love that. There's actually a security tool called Aikido too, right? So I started doing when I was in college, and there was a one of the guys that went to my church was he had a school in Brooklyn and it moved down from New York. So he was an Aikido instructor. And so we had conversations. I just walked up to him. It, you know, it's something out of karate kid, right? It's like, can you? I was like, I'm interested in learning martial arts. Can you teach me? And he Mr. Meowg me and said, Well, I will not call you my student yet. You have to prove yourself, right? So, you know, so because I mean he's he studied under folks, like he's a living student, his instructor didn't speak English, so he was one of those hardcore. And then he's from Brooklyn. So I said you got a little Brooklyn flair to your Aikido. So I went early in the morning on Saturday. I just started on Saturdays going to his house at 6 a.m. I drove 45 minutes from school on Saturdays and 6 a.m. And once I showed my dedication, then he said, now I can call you my student. So 20 plus years later, I've been training with that group, and I have my black belt and been able to do, you know, a little bit of cross-training, some sword work as well. I have a katana. So I was able to do that. But a lot of that discipline, you know, we used to do things, and he would tell me this is a 20-year technique, and you know, I'm like in year two. And I'm like, okay. So when I hit year 20, I was like, yes. But one of the things is that is, and then I was able to train with a lot of different folks from different areas. So I've trained with former military, law enforcement, semi-pro boxers. So those types of things of really understanding and you know, protecting yourself, right? So that was one of the things I've never, yeah, I've never been in a fight. I've never had to be in a fight. And so a lot of things that we learn with that, you learn that de-escalation. So when you're doing Aikido, you're watching the movement, you use your opponent's energy. So even how I translate that within work, I'm paying attention. I'm seeing, you know, what motivates you. I, you know, when you're working, we work with a lot of different folks. I'm not gonna, you know, like pick on the men, but maybe a little bit. I've more men have had larger egos that I've for my experiences. I will talk with my experiences. And I didn't have that problem. I just, I'm like, I don't care who gets credit. My thing is this is what we need to get done. And if you need to get all the credit, then I can you can if that gets us done, then that's fine with me. But it helped me be strategic and even just working with people and working out solutions because that kind of it's the same thing with that redirection of your opponent's energy. And I literally took videos when I was pregnant to my OB and I said, these are the things that I do, showing her the video, these are the things that I do in class. Can I continue to do that? And she said, Yes, but don't fall. That meant they can't throw me. So sometimes it works out well, sometimes it works out well, so yeah, that went for a little bit to they realized it was just unfair. And you're like, okay, you're now a bystander. But it was really great of understanding that discipline to being able to see different problems from different vantage points, right? So I've worked with senior, I always call them like some dangerous folks, right? So I worked with senior martial artists and then those that are just beginning. So I got used to adapting to different techniques and different scenarios and going from teaching to practicing more and learning. So that all happens within my professional world, right? So some aspects a lot of times, especially when I'm hired as a consultant, I'm always teaching, right? So when you're hiring your consultants, they're not always, I don't go in there saying, I'm gonna be here forever, you know, like I'm with the company. I go in, like I'm going to help you until you have, you know, you're on your legs where you're able to move into that next level, or come in and help you periodically on a project-by-project basis. So those types of things. But being able to see, all right, let me show you how you can be successful. I consider it successful. If somebody comes back and they no longer need me, I think I've done a wonderful job because I've been able to train you to be able to take this on for yourself. And it's funny because you know that's how we get our work. We go in and we but if I get you to the point where you no longer need me and I'm moving on to help other clients, then to me that is what I consider success. So, yes. And I got to do Aikido. I had one payment card industry assessment. At the end of the assessment, one of the guys at the company, his daughter was practicing Aikido. So at the end of the meeting, I was like, hey, let's do some techniques. So fun times.

 

Jess Vachon: 55:33

Stacy Cameron, this has been an amazing, amazing session. We could go on and on and on for hours. We have had long conversations outside of this. I hope to have you back because I think you have so much wisdom and so much energy that we just want to share with the cybersecurity community. Where can people find you and where can they learn more about CyCam Strategies?

 

Stacey Cameron: 55:54

Okay, so you can go to cycam.io, and you can learn about CyCam Strategies there. And you can find me the best way is probably on LinkedIn, Stacey Cameron on LinkedIn. Or if you want to, I'll even give my email if you want to email me at CyCam, it's scameron@cycam.io. So I love to hear what you're doing. And if we're going, if you want to collaborate, if you want to work on something that's great or just have questions. I definitely love our field and I love the youth that are coming out of it and that are looking at and tackling different problems. I'm working with a couple of folks on that right now. So, let's go.

 

Jess Vachon: 56:30

Awesome. If this conversation moves something for you, do us a favor, follow Voices of the Vigilant wherever you listen, leave a rating and a review. It genuinely helps us reach the next defender and share this with someone who needs to hear it. Thanks as always to our sponsor, Onyxia Cyber, for making this show possible. Onyxia unites your security stack to automate program management and reporting, pinpoint asset coverage gaps, and continuously govern your security posture. You can visit Onyxia.io to learn more. Until next time, stay curious, stay kind, and stay vigilant. Bye.

 

 

 

 

Want to get notified when new episodes are released?

Click the button below to subscribe:

 
Next
Next

Voices of the Vigilant S2 EP10 | Ask a Different Question