Select Page
Episode 57
The Phish Whisperer: A New Approach to Cybersecurity
Tired of feeling "gotcha'd"? Craig Taylor is changing cybersecurity training from a punishment to a positive, gamified experience. His mission is to empower employees, not shame them, making everyone a stronger link against cyber threats.
Guest

Craig Taylor

Follow on LinkedIn
About the Guest

Craig Taylor is a 30-year cybersecurity veteran and Certified Information Systems Security Professional (CISSP) since 2001. He is the co-founder and CEO of CyberHoot, a cybersecurity training platform built to teach cyber literacy through positive reinforcement, gamification, and automation, particularly for SMBs to Enterprises, and MSPs or MSSPs, and their clients. Throughout his career, Craig has led cybersecurity programs across diverse sectors, including web hosting (CSC), financial services (J.P. Morgan Chase), and manufacturing (Vistaprint). He also leads a growing virtual CISO practice that has delivered strategic security guidance and compliance programs to more than 50 companies across multiple industries. Beyond the boardroom, Craig is a Toastmaster, a committed Rotarian in Portsmouth, NH, and a passionate fundraiser for cancer research. He has raised over $150,000 for Dana-Farber through 11 years of riding in the Pan-Mass Challenge.

Summary

The Phish Whisperer: A New Approach to Cybersecurity

Craig Taylor, co-founder and CEO of CyberHoot, is on a mission to change how the world approaches cybersecurity, particularly the pervasive threat of phishing attacks. He argues that the traditional method of punishing employees for failing fake email tests is ineffective and actively harms company culture. Instead, he advocates for a positive, psychology-based approach, inspired by his own academic background and a core belief that people learn best through positive reinforcement, not fear and shame.

The Flaws of Traditional Cybersecurity Training

Traditional “attack phish” methods, where companies send fake phishing emails to employees and then scold those who click, are fundamentally flawed. According to a study of 20,000 participants from the University of Chicago and San Diego, this method showed a mere 1.7% improvement in outcomes, and in some cases, actually made users more likely to click on malicious links. This is because when employees fail, they are often sent a remedial video, but as Craig points out, “you don’t want to train someone when they’re in a mood.” The average person watches only 10 seconds of these videos, leading to widespread disengagement.

The Power of Positive Reinforcement

Taylor’s company, CyberHoot, offers a different path based on the principles of operant conditioning. Similar to how a dog is trained with treats rather than a shock collar, CyberHoot rewards good behavior. Their “HootFish” approach sends a training email that is clearly marked as a non-trick, inviting employees to an interactive assignment. The goal is to teach users the “puzzle pieces of phishing”—like sender, subject line, and urgency—in a structured, engaging way. By walking employees through what to look for, the program builds muscle memory and teaches them to respond to emails rather than react to them.

Gamification: Making Cyber-Safety Fun

A key component of the CyberHoot method is gamification. Employees earn points, receive certificates, and can see their personal avatar grow in ferocity as they complete assignments. This positive feedback loop fosters a sense of accomplishment and encourages active participation. This approach not only improves security but also enhances company culture by promoting psychological safety and trust. Instead of making employees feel “stupid” for falling for a sophisticated scam, it empowers them with the knowledge and skills they need to protect themselves and their company.

A Proactive Approach to Profit

Ultimately, an ounce of prevention is worth a pound of cure. Breaches, which are often underreported due to stigma, are costing businesses billions of dollars annually. By taking a proactive, positive approach to cybersecurity training, companies can improve their overall resilience, boost employee morale, and protect their bottom line. CyberHoot offers a free individual training platform to help everyone get into “cyber shape” and encourages companies to try a free trial to see how a positive, engaging approach can transform their security culture.

Additional Resources:

Matt & Crista Vance (Hosts): Welcome everyone and thanks for joining us on today’s episode. We’re tackling a topic that lives at the intersection of HR headaches and security nightmares. We’re talking about cyber security, but instead of more fear-mongering, we have a veteran fish whisperer, and we want to hear the background there from New Hampshire. So, let’s give a warm welcome to Craig Taylor (Guest), the co-founder and CEO of Cyber Hoot. Thanks for joining us, Craig.

 


Craig Taylor (Guest): Thank you, Matt. That is a very fun uh introduction. I appreciate that. Crista, nice to see you as well.

 

Matt & Crista Vance (Hosts): So, Fish Whisperer, is that spelled F I H or P H I SH?

 

Craig Taylor (Guest): Yes. BHS.

 

Matt & Crista Vance (Hosts): I thought so.

 

Craig Taylor (Guest): Yeah. For fishing. That’s right.

 
Craig Taylor (Guest): That’s right.

 

Matt & Crista Vance (Hosts): Perfect. Yeah. And we have some more fishing metaphors coming later. So Oh, get ready. So, a little bit about Craig. Craig Taylor (Guest) is a 30-year cyber security veteran and certified information system security professional since 2001. He is the co-founder and CEO of Cyber Hoot, a cyber security training platform built to teach cyber literacy through positive reinforcement, gamification, and automation, particularly for MSMBs to enterprises and MSPs or MSSPs and their clients. Throughout his career, Craig has led cyber security programs across diverse sectors including web hosting, financial services like JP Morgan Morgan Chase and manufacturing like Vistarrint. He also leads a growing virtual CISO practice that has delivered strategic security guidance and compliance programs to more than 50 companies across multiple industries. Beyond the boardroom, Craig is a toastmaster, a committed pro, how do you say Rotarian? Rotarian.

 

Craig Taylor (Guest): Yes, perfect.

 

Matt & Crista Vance (Hosts): Rotarian.

 

Craig Taylor (Guest): Rotarian Portsmouth, right?

 

Matt & Crista Vance (Hosts): Rotarian. And you’re gonna have to tell us about that, too. In Portsmouth. Portsmouth.
 
 
Matt & Crista Vance (Hosts): Portsmouth. Is it Portsmouth? New Hampshire. Portsmouth. I knew that it had a unique pronunciation. The New Hampshire way of saying it, right? And a passionate fundraiser for cancer research. He has raised over 150,000 for Dana Farber through the 11 years of riding in the pan mass challenge. Kate, you have a whole lot. Yeah, we got to hear more about that.

 

Craig Taylor (Guest): Yeah, it was actually just last weekend uh less than five days ago. I ran my son and I rode 192 miles over two days from one end of Massachusetts to the other. All in the spirit of fundraising for cancer and it’s um the world’s largest sports related fundraiser and it’s just passed a 1 billion mark in terms of the numeric amount of money raised since 1980. They’ve been doing it

 

Matt & Crista Vance (Hosts): Whoa.

 

Craig Taylor (Guest): 45 years now. Uh I started on ride number 35 11 years ago and it was torrential downpours. People had hypothermia. It was cold and miserable that year and I kept doing it for the last 11. Yeah.
 
 
Matt & Crista Vance (Hosts): Well, that sounds dangerous, too. And tell us about your nickname.

 

Craig Taylor (Guest): Well, so the biggest problem I see in cyber security today is fishing attacks. Uh in St. Paul, Minnesota last week, they called in the National Guard and the FBI because their entire city was down from a ransomware and probably a fishing attack that led to it.

 

Matt & Crista Vance (Hosts): Whoa.

 

Craig Taylor (Guest): When we look at cyber crime as a uh as a revenue source of funds, it last year was the third largest in the world economy. So there was the US GDP at many trillion, then China, then cyber crime. It’s so under reportported that people don’t recognize just how bad it is out there and how many businesses are being attacked every day and losing tens of thousands, hundreds of thousands, even millions of dollars.

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): I’m sure in St. Paul they’re going to lose, you know, in the 20 to$30 million range of down systems and lost services and upset population. So, it’s an enormous problem. And it’s an enormous problem because hackers are beating us.
 

 
Craig Taylor (Guest): It’s working because what we’re doing to teach people how to fish is completely wrong in general across the industry. It focuses on not exclusively but primarily on punishing bad behaviors.

 

Matt & Crista Vance (Hosts): What is this?

 

Craig Taylor (Guest): And 30 years ago, I studied operating conditioning and psychology up in Canada. I went to the University of Ontario. I studied psychology and I learned about how behaviors are changeable.

 

Matt & Crista Vance (Hosts): Fore

 

Craig Taylor (Guest): They are not changeable by punishment. No different than you know the crimes you commit lead to incarceration leads to what? Change behaviors. Do you think recidivism doesn’t happen? No. What happens is if you want someone not to recidivize or go and create more crimes, you have to teach them better skill sets. You need to teach them positive behaviors. Teach them a job that provides a livable wage.

 

Matt & Crista Vance (Hosts): speech.

 

Craig Taylor (Guest): And then they begin to become model citizens because no one wants to go to jail, but they don’t have the ability to not do that because they have not learned any of the good behaviors that society expects.
 

 
Craig Taylor (Guest): Fishing is the same way. And so 10 years ago, I founded Cyber Hoop. Five years in we said this fake email fish testing that where we got you doesn’t work and we’re trying to emulate what doesn’t work and psychology says it doesn’t work and a multi-disciplinary approach says it doesn’t work. What can we do differently? Let’s reward good behaviors. Operant conditioning says if you want to train a dog, train them with treats and they will with an intermittent reward schedule and you can train them to do just about anything. And if you train them with a short collar, the dog’s going to shut down, disengage, get angry, maybe even nip at you. And if you know, if there’s a squirrel across the street, they’re still going to go after that squirrel. They don’t care about the shock. So all of this came together and it’s my mission in this world to whisper into all of the CEOs and CFOs of the world and the cyber security people, there’s a better way. Listen, you don’t have to punish employees all the time or primarily punish them.
 

 
Craig Taylor (Guest): You can do it once a year, but what you really want to do is teach them and educate them on how fishing works.

 

Matt & Crista Vance (Hosts): Watch this.

 

Craig Taylor (Guest): Feeding like there’s that classic saying, feed a person a fish today, they’re not hungry today, but teach them how to fish, they’re not hungry for a lifetime. And that’s what we are with what I’m whispering about my fish whispering is to get on these podcasts and get to talk to people wonderful people like you Christa and Matt and explain that cyber security is an emerging

 

Matt & Crista Vance (Hosts): This is

 

Craig Taylor (Guest): field of study. They’ve got this wrong and they’ve been wrong before. They used to say nine character passwords, complex uppercase and lowercase , and change them every 90 days until they realized that the human mind can’t remember more than three or four of those things. So everybody cheats and when everybody cheats it’s predictable and when it’s predictable or reused hackers win. So they changed the advice because they learned this doesn’t work. They need to learn as a society as a whole as a as a cyber security culture as a an industry.
 

 
Craig Taylor (Guest): We got to pull on our big boy pants and learn hey multid-disciplinary approach. You should look at psychology and what would work better to teach people and to change behaviors, reward the good ones, make it fun, get engagement levels up.

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): Because when you look at programs all over the world, engagement is in the tank. And what does that mean? People aren’t prepared. So what does that mean? They click on things they shouldn’t. And the answer is not to make it, oh, you’re fired if you click on two or three of our tests. The answer is here’s what you should be looking for. And when we make it fun for you, you’re going to engage more. And you can learn this if you just give it a little try. And we’ll make it fun enough or enough incentives or rewards to get you to engage to see that you can learn it to then learn it. And then you’re prepared.

 

Matt & Crista Vance (Hosts): Yeah. Yeah, honestly what comes to mind with this is thinking about the element of psychological safety in a company culture where the threat of cyber security attacks is real and it’s there and so companies have a necessity to be prepared and to have a plan both preventative and a response plan.
 

 
Matt & Crista Vance (Hosts): But that can have a very negative byproduct of damaging company culture, damaging the employee experience, making people feel on edge, increasing anxiety and all of those things are bad for retention, for productivity, for morale. But if we to your point, if we can focus on the good then we can take this critical business critical function of preventing cyber security tax and having it go from a negative to hopefully something that can be a lot more positive.

 

Craig Taylor (Guest): You said it. Anybody listening to this, that was Matt speaking, not me, because that’s exactly my message. And uh you know, I whisper it enough times that I hope it gets out there. But Matt, well said because you’re absolutely right. And by the way, this is not that I didn’t invent the knowledge here. BF Skinner in 1937 trained a dog with positive reinforcement. rang a bell, fed him, and every time he rang the bell, the dog salivated. Then people said, “Oh, that’s interesting. There seems to be a correlation here.
 
 
Craig Taylor (Guest): Let’s do some other things. Let’s try and before it was probably illegal to do this. Let’s try a control group to shock the dog and uh treat the dog and then try to teach them skills.” and they realize, “Oh my god, the dog really really wants to do these behaviors when we give them a random treat.” And then the dog gets a little aggressive and angry and disengages and crawls back to his cage when we shock it too much. Huh? Maybe this applies to parenting. Maybe this applies to, you know, classrooms. Yes, it does. You want to reward your students in a classroom just enough to get them to try and read The Great Gatsby or you know that book and then they develop an internal desire to do it because once you expose

 

Matt & Crista Vance (Hosts): Yeah.

Craig Taylor (Guest): people to these amazing mental storytelling and and and educational exercises they get an intrinsic that’s like a source inside me I want to learn.

 

Matt & Crista Vance (Hosts): That’s awesome.

 

Craig Taylor (Guest): When you’re just punishing things, it’s an extrinsic or outside me control variable.
 

 
Craig Taylor (Guest): Like, don’t touch the fence, it’s electrified. Okay, I won’t touch the fence. Don’t eat the cookie. All sorts of things. So, yes, 100% agree.

 

Matt & Crista Vance (Hosts): Yeah, I can speak as someone who has fallen for a couple fishing scams. I am saying that on this podcast, but there like I can think back to those times and it still makes me sick to my stomach, you know? There’s just nothing worse than feeling like you were taken advantage of and that you fell for it, right? You were too dumb or something to not see it. But they are so good.

 

Craig Taylor (Guest): But you weren’t too dumb, Christa. The fact is is no one is dumb that falls for these because um if you if you had to be asked to do um I don’t know let’s say u Matt if you had to bake a birthday cake

 

Matt & Crista Vance (Hosts): They’re so sophisticated.

 

Craig Taylor (Guest): I’m going to do stereotype question are you a good cook do you do a lot of cooking right but if you if you if Christa said bake a cake for your one of your children’s birthdays and you didn’t

 
Matt & Crista Vance (Hosts): Um, only a few specific things, but not kinks, that’s for sure.

 

Craig Taylor (Guest): do it very well right your first time your first trial, would you think, gosh, I’m stupid. I don’t know how to bake a cake or I just never learned. No one taught me, right?

 

Matt & Crista Vance (Hosts): Yeah. Yeah.

 

Craig Taylor (Guest): So, Kristen, were you taught in school how fishing works?

 

Matt & Crista Vance (Hosts): Yeah. Definitely not.

 

Craig Taylor (Guest): Were you taught about password hygiene and how emails can sneak into your inbox and if you click by accident, you could be opening the world to that person on the other side?

 

Matt & Crista Vance (Hosts): Definitely not.

 

Craig Taylor (Guest): And by the way, did you know that every hacker in the world can reach you through your email address? No one teaches us these skills in classrooms. So, how can you feel stupid for making a mistake on something that you were never exposed to, you were never taught?

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): That’s our mission at Cyberhood is to We’re free for individuals. So, before this episode, we talked about this.
 
 
Craig Taylor (Guest): You should register for personal use a free account for yourself, Christa, so that you can learn this fishing because now people are listening to this, oh, she already clicked twice. I’m going to target her some more. You might be inviting more stuff. So you need to get good at it. And that’s what’s happening all over the world.

 

Matt & Crista Vance (Hosts): Yeah, 100%. You just put a target on your back, Krista. I am totally signing up for the free count. And I will say thankfully nothing bad resulted, at least that I’m aware of. Nothing bad resulted from them. Like I didn’t get far enough or something. But even so, without even those con consequences, I feel violated.

 

Craig Taylor (Guest): Mhm. You feel violated.

 

Matt & Crista Vance (Hosts): I feel I just feel sick about it, you know. And so to me, if I’m in a company that’s testing me that way and then slapping me on the hand every time I mess up, that would just not be a safe work environment for me.
 

 
Matt & Crista Vance (Hosts): So yeah.

 

Craig Taylor (Guest): Right? It happens every day all over the world. And the justification, which isn’t entirely wrong, is that hey, if you make a mistake, all of our jobs could be gone, right?

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): But you have to ask yourself, what is the ultimate goal? It’s to put more resilience in every person. And the only way to do that is if they engage. And you cannot force engagement. This is not Clockwork Orange where they get the toothpicks out and they say, “Watch this video and if you close your eyes, the toothpicks will sharp like poke through your eyelids.”

 

Matt & Crista Vance (Hosts): Watch this.

 

Craig Taylor (Guest): No, that’s not how we work in this country or any of the civilized world. So you need to make it fun and entertaining and enjoyable and gifted so people actually want to participate and stop punishing the bad behaviors. Go to the good.

 

Matt & Crista Vance (Hosts): Yeah, I love how you said the end goal because you know we talk about on the culture profit that investing in your employees is actually profitable and in the cyber security world the end goal is to prevent these things from happening.
 
 
Matt & Crista Vance (Hosts): So, I mean, if it really was more effective to have lower engagement and have people receiving these tests and failing them, then they probably would, you know, have some bottom line, I guess, justifications for continuing that.

 

Craig Taylor (Guest): Sure.

 

Matt & Crista Vance (Hosts): But the truth is it’s not as effective. So, it’s not good for the bottom line. So, maybe we can dive into that positive reinforcement and what the cyber hoot method is?

 

Craig Taylor (Guest): So, first off, engagement. When you send a fake email fishing test to your employees, that’s the traditional what I call attack fish, you only get metrics on half the employees. Typically, it’s about 50%, because you can only measure those employees if they open the email in their inbox. If they just do a preview, it doesn’t trigger and you don’t know that they saw it or didn’t see it. If they open it, there’s a hidden beacon that says, “Hey, John Doe, open the email.” And now we’re watching to see if they click click. Oh, John Doe failed.
 
  
Craig Taylor (Guest): Let him know he failed the fishing test. And then, you know, send him remedial class and 45minute video, which there’s a black hat study or a black hat briefing this week going on right now. The University of Chicago in San Diego studied 20,000 participants in that methodology. And they found a 1.7% difference on the outcomes for all the fake email fish testing they did in manipulating it. And in some cases they found it got worse in a large proportion of the users.

 

Matt & Crista Vance (Hosts): Wow.

 

Craig Taylor (Guest): They clicked on more things. And there’s some very technical reasons why that is. Uh which I wouldn’t we wouldn’t want to bore your readers with but it is there are some major flaws in traditional fake email attack fishing. The second thing that they said is that when people failed, they were sent this video. Go watch this video to learn how not to make the same mistake. But psychology says you don’t want to train someone when they’re in a mood, right? Like having just failed something where you said, “Aha, you failed the fish test. Don’t
 
 
Craig Taylor (Guest): worry, it’s okay. You can watch the average person watch that training video after their failure for 10 seconds and then they went away.

 

Matt & Crista Vance (Hosts): The brain doesn’t work, right? It doesn’t work. It’s shut down. Oh, wow. Wow.

 

Craig Taylor (Guest): They stopped. They gave up. They didn’t watch anymore.” So

 

Matt & Crista Vance (Hosts): Is it still crashing?

 

Craig Taylor (Guest): there’s disengagement like as far as the eye can see. So what do you have to do is something we’ve come up with is our hootfish approach where we send you an email. Christa, it’s time for your fishing training. This is not a trick. This is an interactive assignment where we want to teach you what to look for through a rubric or a set of rules to follow when you’re looking at an email. and you go visit the Cyber Hoot website and it asks you, okay, here’s an email from Netflix, let’s say, is the sender safe or not? And we have a wizard that walks you through the seven components.
 
 
Craig Taylor (Guest): Think of them as puzzle pieces of fishing. The sender, the subject, the greeting, spelling, punctuation, and grammar, urgency, and emotionality as how does this email construct links and attachments. Now, as you go through, the wizard says, “Is this safe or suspicious for the sender and it’s Netflix.com?” What we’ve done is we’ve taken what is traditionally a domain name like account resets are us and it’s supposed to be Netflix and you look at it, you go, “Well, clearly that’s not Netflix, right?” What we’ve done is we’ve done what hackers do in our examples. These are simulations. So, we dropped the I in Netflix.com. It says neflx.com. And people often look at it, they go, “Well, I know that’s not an account reset, so it has to be Netflix, so it’s safe.” And then they fail the first time and we specifically tell them in the followup that is immediate, right? As soon as you fail that test the first time, we say, “Well, you made a few mistakes. Here’s your results.” We
 
  
Craig Taylor (Guest): drop the I in Netflix because that’s what hackers do. They typo squat the domain name, which is just a fancy word for changing one letter to make you think it’s Microsoft or Amazon or Netflix, but it isn’t. And now you’re in real trouble because you’ve clicked on something you shouldn’t. So, we got them to retake it immediately. And then they’re more careful and they’re more aware of that type of squatting that happens. And so, they learn when the sender is in, you have to make sure you know what the domain name is. We had some feedback the other day that the S in Docusine was a capital S because two years ago Docusine’s officially registered TM trademarked name was D capital D O CU capital SIG GN. But their marketing team said no no no we’re just going to call it docking like a real word and take the s to lowercase. Well we didn’t remember that. We didn’t know. So, someone got a new fishing test and it said a document with a capital S and they were like that’s not safe because they’ve changed their name and they wouldn’t send that.
 
 
Craig Taylor (Guest): And so, in our feedback loop at the end of the exam, we asked you did you like it? Did you hate it? And they said, “No, I didn’t like it because it’s wrong.” Right? And then we asked, “Well, why is it wrong? Here’s a little feedback.” They said, “Well, the name changed and you might not know this.” So that same day when we got the feedback, we went into our database, we did a little update, we zapped it out to everywhere and now no one else has to worry about that, right? That’s what we do.

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): So it’s kind of like a real- time feedback loop for us. So that’s kind of cool. But we walk you through those puzzle pieces and you have to read if you know, you just have to pick safe, unsafe, safe, unsafe, safe, safe, safe, safe, unsafe. Submit. 10 seconds later, you’re done. You pass 100%. You get a certificate of completion. You get continuing education credits.
 
 
Craig Taylor (Guest): You get an avatar that grows with ferocity and defensive lookingness.

 

Matt & Crista Vance (Hosts): Does it Yes.

 

Craig Taylor (Guest): And it’s up a couple of levels as you complete assignments for gamification. We know that people care because they email support. How come my colleague is ahead of me? We both did the same number of tests. Well, good sir, you were late finishing your test. And just like in school, if you submit your paper late, you get less. you get deducted 10%. And your score was 80% which passed the grade, their score was 100%. That’s why you, you know, you get more points when you’re perfect scoring and you’re on time. So all of that is a feedback loop to get people to engage on time and get it right the first time, which is muscle memory.

 

Matt & Crista Vance (Hosts): Thank you.

 

Craig Taylor (Guest): No different than going to the gym and working out three times a week. So you get into shape, physical shape, or you get into cyber shape, right? And the gamification is what increases that engagement because all it takes is engagement.
 

 
Craig Taylor (Guest): We’re not teaching rocket science. We’re not flying a man or a woman to the moon now. We’re just teaching you common sense with a tiny bit of knowledge. Typos squatted domain names are oneletter differences. And urgency and emotionality is a key trick that hackers use because it gets you to react. If you’re driving down the road one day, right, and someone cuts you off, Matt or Christa, your first reaction without thinking might be to open the window, right, and throw, you know, I won’t go there. But if you think about it, oh my gosh, look at they’re going right to the hospital and there’s a pregnant woman in the front seat. Oh, wow. Let them go. You know, like context is everything.

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): So if you give yourself time to respond to an email instead of reacting to it, you’re not going to click those links. So that’s what we teach you.

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): We teach you all these different things so that when you finish this hoofish exercise, you’ve got a perfectly crystal clear picture of what fishing is.
 
  
Craig Taylor (Guest): All the puzzle pieces are put together. You go, that’s fishing. My god, why didn’t anybody ever teach me this?

 

Matt & Crista Vance (Hosts): Let’s see.

 

Craig Taylor (Guest): Because now I can feed myself for a lifetime.

 

Matt & Crista Vance (Hosts): Yeah. And the psychology behind that uh you know em emotional and urgency is that’s not the logical side of your brain. It hijacks the logical side of your brain. And so it is easy to fall for.

 

Craig Taylor (Guest): There you go.

 

Matt & Crista Vance (Hosts): And I was telling you when we talked a while ago about the gamification aspect that I love that you guys do that. Matt is like a big gamification. I definitely love that.

 

Craig Taylor (Guest): I bet you’re a family that plays games at night, right? Do you have game night? Family game night.

 

Matt & Crista Vance (Hosts): Yeah, we do.

 

Craig Taylor (Guest): And we did too. I did too growing up. And you know what? I love to this day to play crib with my son.
 

 
Craig Taylor (Guest): And we played, you know, card all kinds of card games. My parents, my mom, she’s so excited to go play bridge at 80 years old. And games are how the world works. It motivates people to stay active and to think and to use the big brain in their head.

 

Matt & Crista Vance (Hosts): Yeah. Yeah. 100%. And it definitely fits in well with this use case. And I think, you know, this is something that’s really important. And uh to everybody that’s listening today, definitely go back and evaluate how you’re approaching cyber security because it does affect all businesses, all industries. It’s just something that we all need to pay attention to. But as we wrap up here, Craig, any last advice you’d give to HR leaders and company leaders to just kind of get started?

 

Craig Taylor (Guest): Yeah, because this is the culture’s profit, right? It’s the culture of your company and profit as the goal, right?

 

Matt & Crista Vance (Hosts): Nope.

 

Craig Taylor (Guest): You want to be a successful business and you want profit.
 

 
Craig Taylor (Guest): Well, what eats away at profit are breaches, right? or uh employees that are disengaged because you’ve been mean to them quite frankly. Right?

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): So if you can win in five different arenas of a business, the culture is better, the morale is better, the users are better educated, the risk of and the resilience of those users is much higher, the risk of a breach is lower. you avoid just one breach and you know maybe you have cyber insurance to save you but there’s still a deductible of 10-20 $30,000 sometimes and that’s out of your profit. So if you want to be profitable as a business especially today where the truth of the matter is if you’re talking about 101 12 trillion dollars of profit loss across all the businesses of the world.

 

Matt & Crista Vance (Hosts): Happy

 

Craig Taylor (Guest): It’s happening to everyone but not unlike mental illness where no one wants to talk about it because of a stigma which is not fair. It is an illness not a choice and that illness is not fair to be castigated for.
 
  
Matt & Crista Vance (Hosts): birthday.

 

Craig Taylor (Guest): We don’t talk about mental illness enough either and we don’t talk about the breaches that happen because we don’t want to let our customers know. We don’t want to embarrass our companies but it’s costing us a fortune.

 

Matt & Crista Vance (Hosts): No. Good accent.

 

Craig Taylor (Guest): So like Ben Franklin said 200 years ago, my message to you is this. And he was talking about fire prevention. Okay, he said an ounce of prevention on fires is worth a pound of cure. I don’t know how he spoke, but that’s a pound, right? And the same is true for cyber security.

 

Matt & Crista Vance (Hosts): Let’s

 

Craig Taylor (Guest): The time is when you’re in the driver’s seat today to decide, I’m going to deal with this on my terms right now. Budget for it. Put it out there. It’s not expensive. cup of coffee a person a month in your business from Cyberhood’s perspective and you control all of the variables. You’re in control. You have peace of mind. Sleep at night happy that I’m doing what I can.

 
Craig Taylor (Guest): Now, is it a guarantee? Absolutely not. But there’s a lot of businesses doing nothing and so you’re ahead of the game if you take a proactive approach to it. That’s what my message would be. So, there’s a 20% off coupon for anybody that’s listening to this that wants to take that step and try a free 30-day trial in their company. Take a pilot group. Let them tell you if they like it or not. We measure thumbs up or down after every assignment. We get about 80 to 90% on videos and 70 to 80% on fishing today. That’s unheard of from a fishing simulation perspective.

 

Matt & Crista Vance (Hosts): Yeah. No.

 

Craig Taylor (Guest): No one likes fake email attack fish, right? And so just mention the Culture Profit podcast. You get 20% off for your first year. And to book a demo, email sales@cyberhoot.com or just visit cyberhoot.com. We have a really cool new white paper that’s up there now that you can download that explains this study that I’m trying to remember if I mentioned it to you about Chicago and San Diego studying 20,000 people and they found almost no improvement and some people did worse.
 

 
Craig Taylor (Guest): We did mention that.

 

Matt & Crista Vance (Hosts): Yeah. Yeah.

 

Craig Taylor (Guest): Um we wrote a white paper that compared that those statistics to what we see regularly which is anecdotally actually right before this I was on a phone call with three universities and three different professors who are building a

 

Matt & Crista Vance (Hosts): It’s crazy.

 

Craig Taylor (Guest): study an empirical research study of what we do in hotfish to prove empirically that we have better affect. How do people feel doing these exercises? And we have a better effect and what the size of that effect will be. We can’t guarantee that the results will be what we think they are, but we want that empirical research to back up the anecdotal evidence that we see every day. People feel better doing these things and they perform better.

 

Matt & Crista Vance (Hosts): That’s cool.

 

Craig Taylor (Guest): So, that’s what I was doing just before you guys spoke to me. And uh I’m so excited to be talking to you too. You’re a lovely couple and uh thank you for having me today. I really appreciate that.
 
 
Matt & Crista Vance (Hosts): of course. And I’ll add one more thing. So, we post our episodes to LinkedIn and you know, a lot of people are looking for jobs and I feel like that’s definitely an issue right now. And I’m guessing that when you get your certificate of completion, you can post that to your LinkedIn. Yeah.

 

Craig Taylor (Guest): You could and it’s each certificate comes with 15 minutes of continuing education credits, but it says exactly what you did. I did a hootfish or I did a video on ishing attacks. I say ishing because there’s fishing, there’s quishing. Who hasn’t listened to this or yourselves gotten that your tolls haven’t been paid? You better visit this website and pay your tolls or else it’s going to double.

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): That’s smishing. There’s vishing over the phone. And we’re not talking about deep fakes. We’re just talking to people calling and trying to solicit information out of you. And how about the QR code? When you go to the big city and you pay for parking, like I’m in New Hampshire and I go to Boston.
 
  
Craig Taylor (Guest): There’s QR codes to pay for parking. But if there’s a sticker slapped on that, like you can see a Vista Print sticker or something printed somewhere else. Guess who you’re paying? not the parking attendant and you’re gonna get a ticket when you come back from the Bruins hockey game or the symphony or whatever or the restaurant. So, be aware of those issues. So, we do videos and we do all of that stuff and that’s all free for individuals. If you hear this and you want to sign up for free, Kristen, you said you would visit cyberhoot.comindividuals with an s and it’s a free registration.

 

Matt & Crista Vance (Hosts): Yeah.

 

Craig Taylor (Guest): Our hope is that we can train all these individuals, but if they like it, maybe they’ll bring it to their company, to their organization, whatever that is.

 

Matt & Crista Vance (Hosts): Yeah. Yeah. Yeah. And then you have the gamification aspect and everything. But I can think as an employer, you know, seeing something like that on someone’s LinkedIn would just show me that they’ve taken the initiative to be a good asset for any company. And so I definitely check this out, you guys.

 

Craig Taylor (Guest): Absolutely.

 

Matt & Crista Vance (Hosts): This is super important and I didn’t even know something like this existed and I’m I’m I’m all about it now. So, thank you Craig for your time today and everybody leave us a review and check us out next time. Yep. Thank you Craig. We’ll see you everybody.

 

Craig Taylor (Guest): My pleasure.

Meet the Hosts

Matt R. Vance

Host, The Culture Profit

Co-Founder & CEO, Mobrium

Crista Vance

Host, The Culture Profit

Co-Founder & COO, Mobrium

Podcast Available On
+1
+1

Get notified of new episodes!

Subscribe on LinkedIn