Rebooting Business, Episode 30
A conversation about the man who has spent twenty years learning to think like a criminal, the phishing email that will eventually find you, and why the hundred dollars in your account is worth a month of somebody else’s life.
Assume It Is Bad: Cybersecurity with Daniel Ford
There is a particular kind of loneliness in the security profession, and Daniel Ford named it about halfway through our conversation without ever calling it by name. He has spent more than twenty years training himself to think the way a bad person thinks, running the world through a mind tuned permanently to malice, and he wanted me to understand that this is not a natural condition. Most people are good. Most people therefore assume good, because assuming otherwise is exhausting and a little bit poisonous, and so most people click the link.
Assume it is bad. It may not be, but just assume it.
That is the whole sermon in five words, and everything else we discussed for an hour was commentary on it. What follows is that commentary, sorted and set down, with the parts that have aged flagged plainly at the end, because a security article that quietly passes off six-year-old guidance as current would be its own small act of fraud.
The Ballplayer Who Became a Doctor of Cyber
He came to the work sideways, which is how most of the good ones come to it. His father was an accountant, so he tried accounting and computer programming and discovered he loathed both. He stayed out of school for a while, tinkered with machines, took a job maintaining computers for a woman in Annapolis, and then enrolled at the Computer Learning Center, one of those late-nineties trade schools that promised the future and eventually went bankrupt. He came out with certifications in Windows NT 4.0 and Novell, which were the load-bearing walls of the server world at the time and are now archaeology.
Then he simply stopped saying no to things. He worked at XM Radio. September 11th happened, and he went to Homeland Security, and after that he bounced through a series of government agencies. He went back to school while working full time and earned an undergraduate degree in computer science, then a master’s in computer forensics at George Washington, then a master’s in information assurance at Capitol Technology University, which was among the first schools certified by the National Security Agency in this discipline, and then a doctorate in cybersecurity. He finished an MBA at the University of Michigan the spring before we spoke. Somewhere in the middle of all of that he helped build an Android handset called Blackphone, and then he crossed over into financial services, where he now runs security for a credit union with billions of dollars in assets.
The engine underneath all of it, he told me, is baseball. His father taught him that you are only as good as the next game you play, which means that yesterday’s win buys you nothing and yesterday’s loss costs you nothing, and that if you give a hundred percent a hundred percent of the time you will beat more talented people, because the talented ones know they are talented and will take a play off. He reads Kipling on the subject of triumph and disaster being two impostors wearing the same face, and he told me plainly that you only truly fail when you decide to stop spending time and resources on the thing. Everything else is a setback with a bad haircut.
The Mentor’s Arithmetic
Daniel is a technology mentor, and he insists on being mentored in turn, speaking with his own mentors weekly. His argument for teaching is unsentimental and self-interested in the best way. He believes that when you teach a thing, you retain far more of it than you retain by merely learning it, so he keeps interns and young talent around him not out of charity but because grooming them sharpens him.
The harder half of mentorship, though, is translation. Technologists, he says, use the wrong words constantly. We walk into a room and say technical debt, and the business owner hears the word debt and thinks about the cost of capital, wondering whether the cost of equity exceeds the cost of debt, and concludes we are not making sense. So the mentor’s real job is to learn the language on the other side of the table, to speak in capital expenditure and operating expenditure, to ask what the business objectives actually are, and only then to show how technology might serve them. Technology, in his framing, is not a strategy at all. It is a tool, and never more than a tool.
Which is why his answer to nearly every clean, binary security question is the same, and it is not forty-two.
I used to think the answer was forty-two. After the MBA, I learned the real answer is: it depends.
Five Eyes, and the Allies of Convenience
I asked him how the United States compares with the rest of the industrialized world, and his answer split the map into tiers.
The first tier is the Five Eyes, meaning the United States alongside Canada, the United Kingdom, Australia, and New Zealand, and within that circle he considers everyone roughly aligned. The regulations carry different names and sit under different ministries, but they gesture at the same things and they aim at the same posture.
Below that tier sit what he calls, in his own phrase and not the government’s, the allies of convenience, and he places countries like Israel and China there. An ally in one theater is not necessarily an ally in the economic one, and he pointed to the long history of intellectual property theft as evidence, recalling the years when the National Counterintelligence Executive reported to Congress on which nations were bleeding American inventions out through the walls. What matters for a business owner is the part that comes next. In much of the world it is not a crime to attack a company that sits outside your borders, which means the attacker faces no jail and the defender faces no recourse, and the whole asymmetry of cybercrime rests on that single unglamorous fact of jurisdiction.
He also volunteered the point that offensive capability does not require a large country, only an organized one. A small nation with a disciplined program can do a great deal of harm, and the only real difference that size buys you is volume, because a denial of service attack mounted by a million trained people is simply a bigger wave than the same attack mounted by fifty.
The Election Question, Answered Carefully
I asked him whether the voting machines are as fragile as they look, and he refused the word safe, because safe is a relative term and he prefers to speak in probabilities. What he would say is that compromising the physical machines would take a state-sponsored level of effort, since the machines are not generally connected to the internet, and that the defense is therefore physical rather than digital. Every state should know every physical component inside every device, should run diagnostics at intervals to detect whether hardware has changed, should physically inspect the machines before they go out, and should apply tamper-evident seals. Hardware that has changed is hardware that has been compromised, and there is no gentler way to read the result.
I told him about volunteering at a polling place years ago, where nobody checked my background, nobody watched me, and I could have carried an armful of machines behind a building and gone unnoticed for an hour. He did not flinch at the story, and he said the way we vote is archaic, and that other countries have proven technology can do this better.
Then he gave me the sentence that reframes the entire argument.
We were not hacked in 2016. We were socially engineered.
The data came out, the campaigns ran, and a very large number of people were tricked into giving away more than they should have. He is unsentimental about the moral geometry of it, noting that the United States has done the same thing to other countries for a very long time, and that the only surprise was our surprise at finding the capability finally turned around and pointed at us.
The Outrage Engine
The machinery that made that possible is not mysterious, and it is not even hidden. Smartphone adoption climbed, social platforms matured, and the whole population became continuously connected. Then the studies arrived and said what every platform now builds its revenue upon, which is that a negative post outperforms a positive one, reliably and by a wide margin. If you say something inflammatory, whether from the far left or the far right, you will be rewarded with more likes and more shares and more furious replies than any measured sentence could ever earn.
By 2016 we were riding the steep part of that curve, and Daniel does not believe we have crested it. Every media organization now understands the mechanism perfectly well, which means the incentive runs permanently toward the extremes.
I told him about an editor I had when I was a young journalist, a woman with no sense of humor whatsoever, who told me she wanted either a water-skiing squirrel or a car wrapped around a tree on the front page, and nothing whatsoever in between. If it bleeds it leads, and if it does not bleed it had better be adorable. I remember thinking even then that this was not a reflection of reality, and I have watched the internet industrialize that same editorial instinct and sell it back to us as a personalized feed. This is the terrain I keep circling in my fiction as well, in the study of echo chambers and in the question of whether social media is a psyop, because the dystopian writer and the security officer are looking at precisely the same machine from opposite sides of the glass.
Daniel’s counsel, learned in intelligence analysis, is to read several sources and then work out what none of them are saying, because the story lives in that silence. He is candid that this grows harder every year, since the technology for fabricating a convincing image or video is accelerating faster than our collective ability to detect the fabrication.
Phishing Is Still the Front Door
When I asked him where the small business is actually vulnerable, he did not hesitate, and he did not reach for anything exotic. It is phishing. It works on the smallest company and the largest one with roughly equal cruelty, and it works because it is aimed at the one component that cannot be patched.
He offered a merciless example. In the summer of 2020, a few weeks before we recorded, the SANS Institute was itself compromised. This is an organization whose entire business is teaching people how not to be compromised, an organization to which Daniel sends his own staff for training, and a single employee clicked a single link and tens of thousands of records walked out the door. If the teachers can be taken, the students should stop feeling clever.
His practical advice for a small business is refreshingly cheap. Configure your mail so that every message originating outside your organization is tagged as external in the body, which both Microsoft and Google make trivial, and then change the color of that tag every ninety days, because the eye stops seeing a warning it has grown accustomed to. Hover the mouse over any link before you touch it, and read the address the browser reveals, and on a phone press and hold until the true destination surfaces. When the message claims to be from your bank or your card issuer, do not click anything at all, but open a browser, go to the institution directly, log in, and see whether the message exists inside your account. If it does not exist there, it never existed.
He was honest about the tension this creates with my own trade. He would love to abolish HTML email, since a plain-text world would be far safer, and he knows perfectly well that no marketer will ever surrender the brand to get there. Security and usability are always negotiating, and neither ever wins outright.
Think of an old fashioned. The alcohol is the security and the sweet is the business, and every bartender pours a different ratio. Too much security and nobody will use the thing. Too little and you are out of business, because you are constantly compromised.
You Are Going to Be Breached
He says this the way a fire marshal says a building will eventually burn, which is to say without drama and without apology. It is not a question of whether but of when, and his working estimate at the time of our conversation was that a small business should expect a breach on something like a six-year cycle. So plan for it exactly as you plan for fire. Carry cyber insurance. Have the uncomfortable conversation with your partners before the incident rather than during it, because during it nobody is thinking clearly and everybody is looking for someone to blame.
The businesses that survive a breach are the ones that treated it as an inevitability rather than an insult, which is the same principle that governs so much of what actually kills small companies. The failure is rarely the event. The failure is the absence of a plan for the event.
Transfer the Risk, Because You Cannot Carry It
Here is where Daniel becomes genuinely useful to the person running a five-person shop, because his advice is not to become a security expert. His advice is to stop pretending you can be one.
Push the risk onto organizations that are built to hold it. Run your storefront on a certified e-commerce platform that carries payment card industry certification, so that the certification is theirs to maintain and not yours to fake. Take payments through something like Square rather than building the plumbing yourself. Live inside web-based applications from vetted, reputable vendors, because when you choose a hosted platform you are not merely buying software, you are buying somebody else’s security team, and that team is larger and better paid than any team you could assemble. Host the website with a major provider rather than in a closet, which also makes a denial of service attack largely somebody else’s problem, since taking down the giants is a far bigger event than taking down you.
He is fond of Chromebooks for exactly this reason, being cheap and simple and hardened by design, and he notes that the old belief in Mac invulnerability was never really about superior engineering but about market share, since the attacker goes where the victims are. The same shelter, for now, covers the Chromebook. And if you have servers of your own exposed to the internet, patch them, and stop postponing the update until tomorrow, because the Equifax catastrophe was in the end nothing more sophisticated than a patch nobody applied.
His most human suggestion was also his cheapest. Go to the local university, find the students in the cybersecurity program, and pay them properly for part-time work. They will be trained on current technology, they will take longer than a seasoned professional, and they will do good work while you feed talent back into your own community. Occasionally you will find someone you never want to let go, which is a rather better hiring pipeline than most of the ones businesses actually use.
Nobody Wants What I Have
This is the sentence every consultant hears, and I hear it constantly. I have nothing worth stealing. I am too small to be interesting. Daniel dismantles it in two moves.
The first move is arithmetic. Do you have two hundred dollars in your account? To someone living in another part of the world, two hundred dollars is a month of groceries for a family, and if the attacker only needs to find four accounts holding fifty dollars each, then he has eaten for a month and you have funded him. You are not being valued against your own cost of living. You are being valued against his.
The second move is patience, and it is the one that unsettled me. Records stolen from academia command a higher price than almost any other category, because the attacker is not stealing from a student who owns nothing. He is building a pipeline. He takes your personally identifiable information while you are twenty and worth nothing, and then he waits, quietly, for a decade, until you have become someone with something, and only then does he arrive. It is the long con, played across a working life, and the victim never sees the connection between the theft and the harvest.
The Tools He Actually Uses
When I asked what a business owner can reach for without a budget, he named a short list and he uses all of them himself.
VirusTotal is the first, and it exists to answer the question you have every time an attachment lands, which is whether the thing you are about to open is carrying something. You upload the file and it runs the sample against dozens of antivirus engines at once, and it belongs to Google now.
Have I Been Pwned is the second, and it tells you whether an email address of yours has surfaced in a known breach. He recommends feeding every address you own into it, personal and corporate alike, and paying for the alerting if the corporate exposure warrants it. I ran my own while we spoke and found one, and I changed that password immediately, which is roughly the reaction the tool is designed to provoke.
For the browser, he leans on tracker blocking rather than on grand gestures against surveillance, because his worry is not so much the government as the cookie. He is blunt that platforms read across every open tab and sell what they gather, and that in this arrangement you are not the customer at all, you are the product. He names Ghostery as a blocker he trusts, and Privacy Badger from the Electronic Frontier Foundation, and both of them plug into the browsers most of us already run.
Privacy, VPNs, and the Onion
I confessed to him that what I want from privacy is not conspiracy but ordinary liberty. I want to read what I want to read without wondering whether my carrier approves. I want to watch a British television programme I would happily pay for and cannot legally buy. He understands the impulse entirely and he thinks the geographic fences are unfair business practice rather than security policy, and he asked the obvious question, which is why a company that already knows he is paying for a virtual private network could not simply monetize that fact instead of blocking him for it.
His own privacy posture is a study in accepted risk. He runs a smart speaker in his house because he likes what it does for him, and he has simply attached it to a burner identity rather than to his real one, which raises the cost of tying the device back to the man. He knows things still leak. He has decided the benefit outweighs the leak, and he is honest that most people would not know how to build even that much separation.
On the tools themselves he is measured. A virtual private network and the Tor network both work, and both are increasingly blocked, and the blocking is an arms race that the blockers tend to win for a season at a time. Tor exits through identifiable nodes, and those exit nodes get catalogued and blacklisted, so the entrance you found last month is the wall you walk into next month. He compared it to the old satellite television piracy, where the pirates got a few good weeks and then the provider changed the codes and everyone went back to the drawing board. What he would do himself is stand up a modest remote server in the region he wants to appear to be in and route through it, which works beautifully and which is entirely impractical for a person who only wanted to watch a television show.
Stop Sending Official Communication by Email
His closing advice was the most actionable thing in the hour, and it inverts a habit almost every company has.
The phishing problem persists because legitimate email looks like fraudulent email and fraudulent email looks legitimate, and no amount of shaming employees who click will change that, because the fakes are good. He refuses to shame the people who fail his own phishing tests for exactly this reason, and he celebrates instead the people who report a suspicious message.
So take the target away. Move official corporate communication out of email entirely and into your internal channels, whether that means a team chat platform, an intranet, or a simple mobile application with push notifications, and then tell every employee plainly that the company does not issue official communication by email, ever. Once that is true, the fraudulent message arrives already convicted, because the channel itself is the tell.
And then he closed the loop back to my side of the table, which I did not expect from a security officer. Build that internal channel the way your marketing team builds the public one, using the same content management instincts and the same care for the reader, because employees who are communicated with well begin communicating well in turn, and the customer feels the difference at the far end of the chain. Security, in his hands, stopped being a wall and became a communications discipline.
What Has Changed Since This Conversation, and What Was Wrong When We Recorded
This episode was recorded in the summer of 2020, and honesty demands a reckoning with the parts that have not survived the interval, along with one claim that was already incorrect when it was spoken.
The patent point is the significant one. Daniel described the United States as a first-to-prove country, in contrast with a world that awards inventions to whoever files first, and he invited anyone to correct him if he was wrong. He was wrong. The Leahy-Smith America Invents Act moved the United States to a first-inventor-to-file system effective in March of 2013, more than seven years before we spoke, which brought American practice into line with most of the world. The broader argument he was building, concerning the asymmetry of intellectual property enforcement and the way jurisdiction shelters attackers, still stands. The specific legal claim underneath it does not.
The SANS breach he described was real, though his figures were approximate. The institute disclosed in August of 2020 that a single phishing message led to a malicious mail add-in and a forwarding rule, that roughly five hundred emails were forwarded to an external address, and that approximately twenty-eight thousand records of personally identifiable information were exposed. He said twenty-four thousand from memory, and the true number was somewhat higher, which does nothing to soften the lesson.
The product names have moved. G Suite, which he praised repeatedly, is now Google Workspace, and Office 365 is now Microsoft 365, though the underlying advice about external-sender tagging and moving official communication into chat applies to both under their current names.
His figures on knowledge retention, the ninety percent from teaching against the sixty percent from learning, come from a model often called the learning pyramid, which has been criticized for years as lacking solid empirical support. The instinct beneath it, that teaching a subject forces a deeper mastery of it than passively receiving it, is defensible and widely felt. The precise percentages should not be quoted as research.
His estimate that a small business should expect a breach roughly once every six years was offered as a working figure rather than a citation, and it should be read that way. Treat it as a planning heuristic and not as a statistic.
Finally, the man himself has moved. He is now the Chief Information Security and Risk Officer at Jovia Financial Credit Union rather than its Chief Information Officer, and he founded a venture called Echelon Orchid. The personal site listed in the original version of this post no longer resolves, which is itself a quiet lesson about the half-life of anything published on the internet.
About Daniel Ford
Daniel Ford is a cybersecurity consultant, educator, and technology mentor who holds a doctorate in cybersecurity from Capitol Technology University and an MBA from the University of Michigan. He has worked at the Department of Homeland Security and across a range of government agencies, contributed to the Blackphone secure handset, and now serves as Chief Information Security and Risk Officer at Jovia Financial Credit Union. He can be found on LinkedIn and on social media as NostraDanielus.
Listen to the Episode
The full conversation is available to watch on YouTube and on BitChute, and to listen on Apple Podcasts and Spotify.
Related Posts:
- Zoombombed is the companion piece to this one, since it examines what happened when the whole working world moved into video calls without locking the door behind it.
- Whereby for Video Conferencing looks at the tooling that carried conversations like this one, and at what a business should ask of any platform before trusting it.
- Why Business Owners Should Avoid WordPress Admin Access is the same transfer-the-risk argument applied to the one login most owners insist on keeping.
- Is WordPress Bad? weighs the platform honestly, including the maintenance burden that turns an unpatched site into an open window.
- Gravity Forms for Contact Forms, E-Commerce, and More covers the plumbing that touches your customers’ data, which is exactly the plumbing worth hardening.
- How Free Websites Are Bad for Business counts the cost of a platform that owes you nothing, security included.
- Eight Reasons DIY Template Builders Are Bad for Business explains why the cheapest build is so often the most expensive one to defend.
- Website Design Standards sets out what a business site owes its visitors, beginning with not endangering them.
- Ethics in Web Design asks what we owe the people on the other side of the screen, which is the same question security asks in a different accent.
- What Pages Should a Business Website Have? starts with the architecture, because you cannot secure what you have not deliberately built.
- Does My Business Need a Website? answers the prior question that too many owners skip on their way to worrying about the wrong things.
- WordPress vs. Joomla vs. Drupal compares the platforms, and the comparison is partly a comparison of their patch histories.
- CRM Uses considers the system that holds every customer record you own, which is precisely the trove an attacker wants.
- CRMs with Samuel Cook of Sanity Desk is another Rebooting Business conversation about the software that sits closest to your customers.
- Small Business Failure reports what actually sinks companies, and an unplanned catastrophe is rarely the whole story.
- Five Roadblocks You Need to Avoid in Your Business catalogues the obstacles owners build for themselves, denial chief among them.
- Digital Marketing and the Stages of Denial maps the psychology behind the phrase nobody wants what I have.
- The Cart Before the Horse insists that strategy precedes tooling, which is Daniel’s argument about technology being only ever a tool.
- Tactics Over Tools Every Time makes the same case from the marketing side of the table.
- Eight Ways Digital Marketing Can Reboot Businesses in a Post-COVID Economy is the sibling episode to this one, recorded in the same anxious season.
- Understanding ROI in Digital Marketing teaches the vocabulary of capital and operating expenditure that Daniel says technologists must learn to speak.
- Digital Marketing Budgets 101 puts numbers to the same conversation, security spending included.
- Digital Marketing: Understanding Cost, Value, and Price separates the three words that businesses use interchangeably and should not.
- Are You an Ideal Client for Digital Marketing? asks whether a business is ready to be helped, which applies just as sharply to security.
- Eight Types of Digital Marketing Clients You Do Not Want to Be Like includes the client who waits until tomorrow to install the patch.
- Hiring a Digital Marketer covers how to bring in outside expertise without being taken, whatever the discipline.
- Working with Freelancers is worth reading before you hand anyone the keys to your systems.
- The Real Benefits of Working With a Business Coach speaks to the mentorship Daniel insists on receiving as well as giving.
- Entrepreneurial Balance with Savannah Blake approaches the same tumultuous season from the direction of the mind rather than the machine.
- Nonprofit Digital Marketing with Mickey Desai speaks to the organizations that most often believe they hold nothing worth stealing.
- Church Marketing covers another category of mission-driven organization sitting on more donor data than it realizes.
- I Hate Social Media, and Here Is How I Use It Properly Anyway is my own uneasy truce with the platforms Daniel describes reading across your open tabs.
- Facebook Pages Are Not Websites explains why building your business inside somebody else’s walled garden is a security decision as much as a marketing one.
- Echo Chambers examines the information loops that made social engineering a national-scale weapon.
- Is Social Media a Psyop? asks the dystopian version of the question Daniel answers as an intelligence analyst.
- How Narrative Storytelling Crowns and Crushes Political Campaigns follows the same outrage engine into the machinery of elections.
- Be Seeing You: The Prisoner, Genre Alchemy, and the Village We Now Call Home is the surveillance nightmare that got there sixty years early.
- The Technology of 2096: Progress, Control, or Both? carries these questions forward into the world of my trilogy, where the answer has already been decided.
- Near-Future Dystopia: A Guide to Political Science Fiction is the genre built entirely out of the trends Daniel describes.
- When Dystopian Fiction Feels Like Reality sits with the discomfort of an interview like this one.
Sources Cited:
- Rebooting Business, Episode 30, on YouTube.
- Rebooting Business, Episode 30, on BitChute.
- Rebooting Business, Episode 30, on Apple Podcasts.
- Rebooting Business, Episode 30, on Spotify.
- Daniel Ford on LinkedIn.
- Jovia Financial Credit Union.
- CyberScoop on the SANS Institute phishing breach, August 2020.
- Computer Weekly on the SANS Institute data breach.
- United States Patent and Trademark Office, First Inventor to File resources.
- Federal Register, implementing the first-inventor-to-file provisions of the America Invents Act.
- VirusTotal.
- Have I Been Pwned.
- Ghostery.
- Privacy Badger, from the Electronic Frontier Foundation.
Quotations from Daniel Ford are drawn from the episode transcript and lightly tightened for readability without any alteration of meaning. This conversation was recorded in the summer of 2020, and the section on what has changed should be read before acting on any specific technical recommendation within it.

