My guest today, John Just, Global Educator with Know Be 4, has trained millions of learners across seventy thousand organizations worldwide.
Real cybercrime stories. AI threats. Ransomware attacks. Social engineering tactics that are working against you right now.
CHAPTERS
00:00 Know Before Platform Overview: Security Awareness Training That Actually Works
02:30 Phish Alert Button: How Employees Stop Real Attacks in Real Time
05:30 Law Firm Nearly Wires $1M to Hackers: Stopped by Training
07:00 Social Engineering Is the Top Breach Vector: Why Tech Alone Fails
09:30 Building a Security Culture: Flip the Weakest Link Myth
12:00 Psychology Behind Phishing Simulations: Why the Gotcha Approach Backfires
14:30 AI-Powered Threats: Spear Phishing Is Now Scalable and Cheap
17:00 Voice Cloning and Deepfakes: The New Face of Social Engineering
19:30 Gamifying Security: Rewards, Reporting, and Real Culture Change
21:30 Inside Man Series: Hollywood-Quality Cybersecurity Training Content
24:00 KSAT Platform and Security Culture Survey: Measure What Matters
25:30 ADA AI Orchestration Agent: Personalized Security Training at Scale
28:00 K-12 and University Cybersecurity: Protecting Schools on Shoestring Budgets
30:30 Deepfake Simulation Tool: Train Employees Using Your Own CEO's Face
33:00 How to Run Phishing Tests Without Destroying Employee Trust
35:00 KnowBefore Con, Inside Man Season 7, and What's Coming Next
Hosted by David Dean Mauro — experienced former trial lawyer, AI Security Advisor, FBI InfraGard member, VP of NetGain Technologies and Author, Moving Target Trilogy Book Series (#1 Amazon Hot New Release 2026).
I wrote Moving Target because overconfidence is the enemy. Hardcover, paperback, Kindle, and audiobook. Amazon, Barnes and Noble, and more.
I wrote the Moving Target Trilogy because overconfidence is the enemy. Hardcover, paperback, Kindle, and audiobook. Amazon, Barnes and Noble, and more.
Growth without Interruption. Get peace of mind. Stay Competitive-Get NetGain. Contact NetGain today at 844-777-6278 or reach out at DMauro@NetGainIT.com or find more at www.NETGAINIT.com
New Exclusive Offers for our Listeners!
New non-fiction Book Series is out!
- Moving Target: The Art of Online Camouflage drops April 14.
- Moving Target: The Obedient Machine drops April 21.
- Book 3 -- Ghost and the Machine -- out soon!
🔥 4 years. 400+ interviews. Available on Amazon. We are all Stevie Parker.
Remove Your Data Online Today. Consider OPTERY Risk Free. Sign up here https://get.optery.com/DMauro-CyberCrimeJunkies
Or Turn it over to the Pros at DELETE ME and get 20% Off! Remove your data with 24/7 data broker monitoring. 🔥Sign up here and Get 20% off DELETE ME
🔥Experience The Best AI Translation, Audio Reader & Voice Cloning! Try Eleven Labs Today risk free: https://try.elevenlabs.io/gla58o32c6hq
===========================================================
Learn to stop cyber crime. ~Cyber Crime Junkies
[00:00:03] Ever notice it's always the overconfident leader that thinks cybercrime doesn't apply to them who gets selected and hurt the most? Moving Target. Books 1 and 2, out now. Hardcover, paperback, Kindle, and audiobook. Amazon, Barnes & Noble, and independent bookstores. Book 3, coming soon. Be a moving target.
[00:00:42] Here's what keeps me up at night. Over 30 of every one of us will click on a phishing email. One third. That's one in three people handing organized crime the keys to our private lives and our businesses. But that's not what really bothers me. What gets me is that these people aren't dumb. They're not bad employees. Some of the worst offenders, they're managing partners at law firms.
[00:01:08] Doctors, nurses, business executives at one of the highest levels. Why? Because they're busy. They're distracted. Because the criminals targeting them have done their homework. Again, we're not talking about kids in hoodies living in their mom's basement eating Hot Pockets all day. We're talking about organized crime syndicates using AI to clone your CEO's voice in minutes.
[00:01:33] Craft a perfect email in seconds. One that is from someone familiar with zero red flags in it. They're able to scale an attack that used to take weeks of research that now takes a single lunch hour. AI has lowered the barrier of entry into cybercrime. And last time I checked, there's exponentially more criminals than there are technical experts.
[00:01:58] The good news is that we can all fight back. Every single one of us. It doesn't take much. It just takes a little bit at the right moment. The bad news, most companies are still treating security training and awareness like a 45 minute punishment module nobody wants to sit through. So what actually works? And how does one organization drop their click rate on phishing emails from 30% to 2% in just a matter of a few months?
[00:02:28] My guest today has trained millions of learners across 70,000 organizations worldwide. And he's got stories that you will not believe. One about a law firm that almost wired a million dollars to a criminal sitting silently inside their own email system. I'm joined by the legendary John Just, head of global education at KnowBefore. So stay with me. You'll want to hear how that one ends.
[00:02:57] This is Cyber Crime Junkies. And now the show. All right. Well, welcome, everybody. We have in the studio today a very special guest.
[00:03:25] Mr. John Just, Chief Learning Officer at KnowBefore, Doctorate in Instructional Technology from Nova Southeastern, former CIO from Pinellas County Schools, which is a remarkable experience, and former SVP at Healthcare Software Company in Thrive. Mr. Just, thank you so much for joining us today. Yeah, thanks for having me.
[00:03:50] You know, I always enjoy our conversations and I'm looking forward to, you know, continuing that in this format. Absolutely. So you are a busy person. You travel all over the world. I do. Heading up education for an organization like KnowBefore. If there are some people that don't know what KnowBefore is, let's give them a high level. Do you mind? Not at all. I prefer if you do it. Yeah, probably better for me. Yeah.
[00:04:18] So we are a security awareness training and email security company. We help people manage the ongoing problem of social engineering, educate them about the dangers. We have a simulated phishing platform that helps you practice the common attack of social engineering and several of those attacks these days. We actually also have recently launched inbound and outbound protection for email so that you have all the layers of defense.
[00:04:46] And we also use AI agents as part of that. So the cyber criminals are using those. So we're using them to help expand our capacity and your capacity to defend against these attacks. So my charge is I lead a global team that helps create our phenomenal training content that is used by millions and millions of learners across the globe.
[00:05:10] We serve around 70,000 organizations from household names to small organizations, from banks to not-for-profit organizations that are doing amazing mission-driven work. And we're very mission-driven here at KnowBefore. We are driven. Our CEO, Brian Palma, is former Secret Service, worked in cybersecurity a long time, and he is very focused on the mission at hand, which is protecting as many people as possible.
[00:05:38] And so, yeah, that's a bit about what we do. Well, and, you know, I will say that you don't do it half-baked. I mean, you have over a thousand interactive modules, videos, games, posters, newsletters. You have KnowBefore available in 35 different languages with KSAT. We can talk about what that is, but reducing organizations' fish-prone percentage from 30% down to 5%.
[00:06:08] Yes. And then less than a year. The bottom line is this, like, you have the largest security awareness or risk awareness platform on the planet. It's remarkable. I've been involved. I've been using it as either an administrator or a user or helping businesses with it for 10-plus years, and it just keeps getting better and better. It is really remarkable, and what's outstanding is it's very affordable.
[00:06:37] For a small organization, for a small business, you can really lower your risk by using this platform and have empirical evidence that your culture is getting more security-minded. What I love about it is in the beginning, when you roll it out, like, close to half of everybody is still falling for these things. Yeah.
[00:07:01] It goes down significantly, and then over time, it gets down to a much lower, you know, a 2%, 3% of the organization. Now, it's still too high because it's 2% to 3%, but humans are humans, and you're really never going to get that down below. Yeah. Right? Yeah. But then I love you guys have the ability to focus on those super clickers. Yes.
[00:07:25] Because the super clickers, against common, like, urban myth, they're not bad employees. They're not dumb. They're not gullible. Sometimes, like, at law firms, I've seen them be the managing partners. They're busy, right? And they literally are just— Distracted, on their phone. Exactly. It's harder to see where that URL is going. Right. Yeah, for sure, and I would say a lot of our organizations, as you mentioned, we've had organizations that have been with us for 10-plus years,
[00:07:53] and if we continue to evolve and we're committed to continuous improvement and striving for excellence, and as we've seen the industry grow, the number one way, and this has been verified by many different sources and case studies, that you actually find out about these attacks is through people reporting them. Right. So this whole concept of, okay, well, they're my weakest link, you need to change the culture to be like,
[00:08:21] you're all a part of this, and that's what our training strives to do. So lowering click percentage, important. I don't want to disregard that. That is very important. But another thing is we offer a free tool called the Fish Alert Button. Right. And I was just about to get into that because that changes the dynamic of the culture completely, right? You can protect your organization, your colleagues from an attack because you got the training, you identify these attacks,
[00:08:48] and then you were able to alert your IT team. So it sort of flips that dynamic on its head. You'll never get to zero on the clickers. But if you can get your reporting percentage to a high enough level, several years ago there was a landmark study, a case study done by the UK government, the GQ, their headquarters there. And they said that really they did a case study on an attack that was remediated.
[00:09:16] And the whole reason that they found out about the attack was because people used the Fish Alert Button to alert the IT team. They were able to pull it out of people's inboxes and go find the people who had fallen for it and remediate them before any further damage occurred. So absolutely. And that is that's so important. So on the one hand, first of all, what we're talking about is protection against social engineering.
[00:09:42] Of all of the data breaches out there, you can have all the technology in the world. You can have all the best firewalls, etc. All important. I'm not minimizing that. But it matters less when humans fall for trust issues, convincing issues, senses of urgency. Right. And especially in light of AI, these things look better and sound better than ever before. Oh, yeah.
[00:10:10] And so that is the largest vector that breaches occur is social engineering. So this platform and the organization is mission driven to reduce the risk for organizations, just giving everybody a high level of. Yeah, for sure. Those that aren't in this field. Right. Then you really have two main approaches, several layers, but two main approaches. One is the monthly customized test phishing where it goes out periodically and it's testing.
[00:10:39] And should you click on it, it would not be a data breach. It'll say, hey, this would have been a data breach. You've been assigned training. And then you have a library of this incredible training to really get people to learn from that. But in addition to that, what I love about it, you have that fish alert button. It sits in. For example, if you have Outlook, it sits right there.
[00:11:02] So 24-7 from the phone, from anywhere while people are working and they see something that is suspicious. It turns every employee into a beacon. Into something that is like, let me see, this looks odd or I wasn't expecting this or this is an odd sense of urgency. They alert and it gets triaged. We're able to set it up, I know, at our organization. It goes right to our SOC.
[00:11:28] So our team will go in, remove it, block that, and then be able to investigate it right away, which is remarkable. I mean, we've had great success stories with a lot of organizations where that has led to breaches getting stopped before they actually could arrive and go further. It's really remarkable. Yeah, my favorite story of all time is a law firm. You mentioned the law firms. And there's many of these stories and I love them.
[00:11:58] Again, coming back to Be Driven by the Mission, where people share their stories, where there was a conversation ongoing for a settlement. The settlement was roughly around a million dollars. And, you know, we always say assume breach, right? And so the perpetrator, the hacker was actually in the system already, was in the email monitoring the conversation, waiting for the best opportunity. And so they, you know, they started acting odd.
[00:12:27] They put urgency into the thing. And so the lawyer said, I'm just taking that training like 30 days ago. I'm going to pick up the phone because this is, this is just, you know, there's a few red flags here that I remember from the training. So she picks up the phone to verify. Lo and behold, on the other hand of the line, the other attorney, he had been locked out and said, I haven't been able to get in my email all day. They, someone, someone had changed my password.
[00:12:57] I was on the phone with IT. I've been trying to get into my email. So obviously changed IT, enabled MFA. So they couldn't get into the account, even, even with a password change, lock the people out. So save that organization from transferring a million dollars to not the rightful person who was due that, right, right. The settlement, but actually to a perpetrator.
[00:13:20] So, and, you know, that's one of many stories that we've heard, not just at an organization, but personal, you know, where, where they were, you know, were alerted to a romance scam or something because of our training. And so that really energizes me because, you know, we don't do this just, just to make a profit. We do it for, for the mission and, and it saved a lot of people. And it happens way more frequently than people think.
[00:13:45] Like, that's, that's the challenge is that there's a stigma with getting breached, with getting tricked, getting scammed, whether it's at the organization or the personal level. And, and we all know people who have done it in our friends and family group that have, have shared that experience with us. But you have a tendency to go, well, that won't be me. And I, I, you know, that won't be our organization. And so we have to fight against that stigma. Right. Cybercrime happens.
[00:14:15] Elsewhere. Right. Yeah. The more, and you come from an education background. And so I wanted to ask you, what about that background leads you to understand human behavior? Right. And that sometimes the cybersecurity industry might even get wrong or general business might, might get wrong. And I think some of the stigma about humans are the weakest link or that this won't happen to us. Yeah. Or if we buy a product, then it's not going to happen.
[00:14:45] And it's the tactics. It seems to me that they use for social engineering are the ones they've been using for thousands of years. Stay with us. We'll be right back. Ever notice it's always the overconfident leader that thinks cybercrime doesn't apply to them who gets selected and hurt the most? Moving Target.
[00:15:13] Books one and two, out now. Hardcover, paperback, Kindle, and audiobook. Amazon, Barnes & Noble, and independent bookstores. Book three, coming soon. Be a moving target. Yeah, yeah. So it's embedded in psychology. So when I talk about, you know, we need to use AI agents. I said that earlier.
[00:15:41] They're using psychological tricks to and playing on psychology. So we have to be able to do that as well. Exactly. And so there's great theory base that goes back a long time. So first of all, I'll talk about simulated phishing. Because I think sometimes it can be controversial. And it's been more and more accepted, but you still see pushback from people. Every once in a while, you'll see an article that says it doesn't work.
[00:16:08] And, of course, you read the article and then read the research paper and the research paper saying you can do it right and you can do it wrong, which is totally true. It's not that it doesn't work. It's a tool. You know, simulated phishing, much like a hammer, you can drive a nail in or you can hit yourself in the thumb. And so we have to think of it like a tool. So, you know, in education, we're always trying to simulate the environment as much as possible.
[00:16:33] And so when I first made the transition from building healthcare education, we're building these complex simulators to show people what this could be like. To go to cybersecurity, where we have this simulated phishing coming in, it's as close as you could get to the real thing, which is really powerful from an educational perspective. But I don't think oftentimes we see people look at it as an educational opportunity. They look at it as a gotcha exercise.
[00:17:01] And I think framing it as practice, it's drilling, it's getting you used to when I see something weird, I'm going to hit that phish alert button and then I'm going to get feedback back. The feedback loop is important. I'm either going to get a congratulations or I'm going to get something that is, you know, hey, this is actually fine. And we've used phish ER in the background and we looked at it, it actually came from HR and you're good to click it.
[00:17:27] That feedback loop in psychology research, really, really important to take advantage of, but to position correctly and communicate correctly that, hey, you know, we do a fire drill every once in a while. We do these practice things. This is essentially, you know, that safety practice for cyber hygiene. And then when you fall for one of these, you point it out, you can get education.
[00:17:51] When I first joined eight years ago, the most common thing was like, OK, now you've got to take a 30 or 45 minute module. Oh, and it's almost it's almost punitive. It's punitive. It's almost punitive. But now it's not like that. No, no, no. Now I might play a game. I might play a game. That's what our recommendations would be because. Almost makes you want to click. I'm just kidding. Yeah. Yeah. Because I like them. Yeah. And then we tell you the why. Why? Why was this happening? Why are you getting this simulation?
[00:18:21] And for adults, there's a theory called andragogy about adult education. And we like to know the why behind things. We don't just like to know, hey, we need to do it. And I think we have a bias as cybersecurity professionals and education professionals in cybersecurity. You should know the why. Don't assume people know the why. Don't assume your leaders know the why. You have to be educating about the why as well. Yeah, absolutely.
[00:18:45] I wanted to ask you about, you know, how because things have changed because of AI. And I know that, you know, you guys have developed a suite of AI defense agents. Yes. Brilliant. We can talk about that in just a second. But to me, you know, I've spoken with Perry Carpenter at your organization. Brilliant. Great. And deep fakes. And he had a really interesting point.
[00:19:13] And I'm curious if you see it from the educational arm there, too. And that is like when Perry's talking about deep fakes, he's saying we're asking the wrong questions. He says we we it doesn't matter if we fit. We spend so much time. Is it real? Is it fake? Ask ourselves. What is it asking us to do? Yeah. What's the right. Right.
[00:19:37] And if it's asking us to do something against our interest, release information, wire transfer something, whatever it is, then verify with the human. Right. And from from the overall education perspective, my my question to you is it seems like because of AI. The emails today. Oh, yes. Today can be perfect. Like, yeah, they can be real.
[00:20:05] But if they're asking like like there's virtually no way of determining some of the red flags in some cases, depending on the attackers use of AI. And so if that's the case, rather than fall for it, whenever you're asked to do something. Right. Verify the human, not the email. Like, are you? Yeah. Are you kind of seeing that as well? We are.
[00:20:30] And so a lot of customers and another story I'll tell about a customer, you know, wrote in and said, hey, again, because of the training and because I we've been educating people that AI is making these threats. The level of the threats, the sophistication of the threats. It's so much easier to make. So spear phishing. Right. Which is a very targeted attack used to happen to high level profile people because it wasn't scalable. Right. Right. Now you can.
[00:20:59] It was very rarely done. Exactly. Because you had to research and find all the vulnerabilities. And understand all of their vendors, you know, really do that. Now it's minutes before you can find that. Yeah. A polymorphic attack. So I can change the attack slightly and make it a little bit more customized. And that makes people, you know, fall for it more frequently. Yeah. If they're not if they're not educated in on guard.
[00:21:27] And so we had a customer that received a voice message in WhatsApp and it was a voice cloud message. And, you know, she went and called and verified and, you know, pointed out that, like, if I wasn't aware that these things were even out there. Right. The sense is I don't want to embarrass them. I don't want to pick up the phone. Right. You know, it's fine. And if we encourage that in our security culture encourages verification. That's the point.
[00:21:56] That is really the point. That's the best point. And that's what I love about your heading of the education, because when there's a culture, meaning any small business, when you promote people for seeing something and saying something. Yes. When you reward that at my at my last employer and oftentimes here where where we are, there's rewards. There's like bonus reward points and things.
[00:22:20] If you catch fishing the most that month, you'll get like a gift card and things like that. Like what a great idea. Right. Yeah. Gamifying it as opposed to that. Gamifying it. Computative side where it's like you did something. Now it's now that way. Yeah. Right. Years ago, it was like 30 minute thing. I don't want to do it. But what happened is, is then people, if they thought something was weird, they would not tell anybody because they didn't want to get involved. No. Right. And so, yeah, it's kind of cool. Yeah.
[00:22:51] Setting up that culture that I love that idea. I love that concept. How do we get more people involved? Personally, I work here. And when I catch a real fishing attack and I get that back in my Slack message from our coaching tips that says, you actually caught a real. I still go pump my fist up. I'm like, I'm educating people around here about this. I'm bragging about it at the office. Exactly. I'm like, I got three last month. How did you do? You know what I mean? And that's the sort of thing that we needed. That's cultural.
[00:23:48] It's kind of fun. Yeah. You come back to, I just mentioned Perry Carpenter. Yeah. We had Kevin Mitnick here who was doing our hacking demos and the rest in peace. He was, the spirit of Kevin Mitnick lives on with us because we have a number of people here at Know Before taking up that mantle and continue to do hacking demos. Those tend to be really popular, by the way, because it shows you why they're doing it. What can happen gives you behind the scenes look. So some of our most popular.
[00:24:17] And then our Inside Man series is like a Netflix Hollywood high production. You know, again, behind the scenes. Let's see what hackers, let's see what cybersecurity is like. Gets people engaged. I'm really excited about our latest production by the same team called Chameleon, though. And Chameleon sort of learns about all the things that we learned with, hey, people don't want to watch a big movie and an arc. But they want that high production value. They want it to be snappy. So it's in seconds.
[00:24:47] It's smaller. Yes, very smaller. And could be standalone or could be, you know, but it brings personality. It brings character. There's character development in it. So interestingly, the Inside Man has been super popular, watched by millions and millions of people. We've won so many awards in cybersecurity, education in general, and even in media, competing with the National Geographic and the Apple Studios and the Netflix Studios of the world. We've won awards for this. Again, we've learned a lot from that.
[00:25:15] As you mentioned, we're constantly evolving it. Chameleon has that same potential, right? It's already exceeding organically the usage that we had for the latest seasons of the Inside Man. So Inside Man continues to live on. We're actually doing demos with the Inside Man characters. So they're coming in and actually doing hacking demos. We're teaching them, the actors, how to do these little hacks. And they're doing hacking demos like Kevin used to do. So super excited about the universe. How do people access these?
[00:25:46] You probably should mention that. Is that by being a subscriber to Know Before You Have Access to the Mod Store? Correct. The Mod Store is the module store from which you can access all this amazing training content. And games. You mentioned games. There's games for season one and season two of the Inside Man. Yeah, it's as good as Netflix, man. Like it is as good. Like there's so much stuff to do. It's like entertaining. Yeah. And we're always adding.
[00:26:15] So it's about fresh content because the threat landscape is changing. AI is advancing the threats. We need to tweak how we present them, what we're seeing in the threat landscape and provide that. So we're releasing 30 to 50 new modules per month and retiring some of those older ones. So you're talking about an evergreen subscription. You don't buy a static set of something. You actually buy an evergreen subscription like Netflix to this latest content.
[00:26:43] So yeah, KSAT you mentioned earlier, the Know Before Security Awareness Training Platform allows you access to all of these through the module store, through the Mod Store, all of these terrific learning modules, whether they be videos or games or our assessments, which are super powerful. So we talked about security culture. You can take the security culture survey. I had a customer in Europe who used to pay an outside consulting firm 150,000 euros a year.
[00:27:10] He said, I canceled that because now I just give my security culture. I've gotten more data from this. I can benchmark against my industry, against my local, for my size. I can actually see where is my security culture moving? Where are my weak points? Where do I need to address? In a 10-minute survey that I send out as a scientific instrument, as opposed to bringing someone in to do a bunch of interviews, interrupt workflows,
[00:27:38] and then come back with sort of nebulous things I maybe could do. And more like a snapshot in time or something just generic. This is actually interactive, evergreen, constantly evolving. Yep, for sure. Tell us about it. It is, yeah. It just came out of the tech preview. And inside our Know Before community, people were able to opt into this.
[00:28:06] And so we did extensive testing with it. So what we've been asked for years and years is we'd like something that we can provide differentiated instruction to people. We'd like something for, okay, there are people who are doing, hey, my finance organization takes this. My sales organization takes this. My legal team takes this. But let's get down even further to an individualized level. That, hey, I may, like we've talked about games.
[00:28:35] Some people on your podcast may go, and I don't really like to learn from games. Okay, well, I might get a game. That person might get more of a straightforward, you know, video. So there's some learner preference that goes in there. And we use all the profiling behind the scenes. So we have these millions of learners and data points that can feed that. And so this orchestrates what I can get as far as learning interventions and allows that to be more powerful. So it's a game changer. It's been huge.
[00:29:04] It's something that's been in development for some time. It obviously takes a lot to get those algorithms trained and the LLM tuned to exactly what it needs to be in terms of providing you with those individualized instructional moments that are going to make the most sense for you. Maybe you're a more advanced learner, right? And you're bored with, hey, what are the basics of phishing? I want to know what happens behind the scenes. Maybe I'm a developer. Maybe I'm in IT. I want to know what, you know, SQL injection looks like.
[00:29:34] I want to know what some of these more advanced attacks are looking like from an AI perspective. And so it's able to differentiate, we say, in education, right? It's able to provide something, right? Yes, exactly. Provide something different to based on your needs, your profile, your history. That way be much more powerful and targeted. Yeah. I came from the K-12 space. Came from law and then I was in law and then I was in the K-12 space.
[00:30:04] And I'm just telling you, if you could survive in the K-12 space, it is enterprise environment, you know, nonprofit budgeting. And in no other industry does everybody leave all at once. And then you get disconnected and then all of a sudden everybody comes back at once. Yeah, yeah. I mean, I miss my K-12 days. I get to work with a lot of our K-12 organizations, but there's things I don't miss. And like you said, minuscule budget.
[00:30:31] We had, you know, over 150 sites, over 120,000 students, 15,000 employees, largest employer in Pinellas County. And to serve and on a two-string budget. But, you know, again, talk about people who are very mission driven and focused on making a difference. So, you know, I get to work with a lot of our large and even smaller K-12 organizations. And I love that.
[00:30:55] And our university systems because they do an outstanding job of doing, you know, rubbing two sticks together and making fire. Like really taking that budget and making it go really far. And we're partnered with them all the way. You mentioned low-cost solutions. We have specials for those folks because we understand the budget limitations and we want to be on their side. And we recently launched student edition not too long ago. That is pennies on the dollar for students to license content.
[00:31:25] We're creating student-specific content. I have a colleague, Ben Sin, who's a former middle school teacher turned instructor in college out in University of Colorado. And now he is heading up that effort for us and some outstanding content for them. And by the way, if they license that for pennies on the dollar, we also give them the email protection for inbound and outbound dimensions. That's great. For free included with it. So, you know, the other thing you know, 120,000 students, I have 120,000 points of entry.
[00:31:55] A certain percent of them are little hackers themselves trying to get into stuff and cause. They're not afraid of anything. They're just beating up the keyboards, man. Yeah, exactly. And so, you know, definitely a focus for us here at KnowBefore. Amazing. So before I let you go, let's, you know, AI has dramatically changed everything. Yes.
[00:32:18] I think in the beginning everybody was kind of waiting to see what would happen, but it has definitely hit its stride now. Everything from data leaks that are happening to AI scanning of vulnerabilities, finding those vulnerabilities, getting in to really improving attackers' social engineering abilities. Yes. Like AI deepfakes. It used to take part of the reason why AI deepfakes were really parlor games in the beginning. Yeah.
[00:32:46] It was really only able to be done on Tom Cruise or President Obama or somebody like that back in the day because you needed hours and hours of these samples to generate that. Yeah. All of that has changed. Now, just with a few seconds, you can clone voices. Yes. A minute or two, you can clone video. And it's pretty good. It's getting better every single week.
[00:33:13] I mean, just in the last couple months, it's gotten almost where it's undetectable by the human eye, which really leads to the issue of stop trying to figure out if it's real or not. Look at what it's asking you to do and then go verify. Right? Yeah. Now, you know before there's something exciting about this. You allow now through a subscription, you are able to generate your own deepfake of your own CEO. Tell us about that. Yeah.
[00:33:42] And Hank, my CEO, better watch out because I want to get in there. I'm going to talk to our team. I want to get in there and play with that. Yeah. Yeah. Yeah. It's a great educational tool. So, by the way, you know, there are other tools that you could download tools to like create a deepfake. But what I love about our tool is it gives you scripts to choose from. And they're all educational scripts that are vetted by our folks. And so you upload a little bit of video. You let that cook for a little bit.
[00:34:11] And then what it spits out is an actual deepfake that is, you know, hey, I'm going to ask you to do something. And then in the same message, I'm going to say, this is a deepfake. Here's the things you should have been looking for. Here's the points that... Most of you guys are telling them right at the end. Exactly. So you're not letting them go and wire transfer things and go into the store for gift cards or doing anything like that.
[00:34:36] No, no, we'll ask them to do some things and we'll lead them down that road a little bit in the same message, but then turn it very quickly to the educational message. That's that. And so I feel like that's powerful because there's other things out there. But again, if you talk about what know before brings, we bring this trusted. We've been doing this. We do this for some of the biggest and smallest organizations on the planet. We've learned a few things about how to educate people. And so we bring...
[00:35:05] How not to make it, you know... How not to shoot yourself in the foot and send it out and then end up having problems or that... Well, I've seen this fishing. Yes. I know people from like the legal community who their quarterly bonuses were coming and the test fish said like from the managing partner... Yes. ...your quarterly bonuses here. And they're like, ha ha, this is a test fish. And you're like, okay, that's not cool. No, no.
[00:35:34] Like that's not a way of building the culture. That's just going to tick off employees. Exactly. Coming right back to the whole thing at the beginning that we talked about, which is it's all about culture and working in a way... It's not about getting gotchas. It's not about having fun ourselves. It's making it fun for the users, making it interesting and engaging on a cultural level. Exactly. Ultimately reducing risk. Ultimately reducing risk and people... Yeah.
[00:35:59] And if they're invested and they feel like they're part of the team and we're working for them and they're working with us, then for sure. That's absolutely phenomenal. Yeah. And you guys really did the deepfake approach correctly. Like you get the authorization to do it and it's really phenomenal. Yeah, we're very proud and a lot of really great feedback about it thus far from people saying, number one, it's easy. So again, I could go out and do this and people have been paying...
[00:36:29] Larger organizations have been paying very specific people to do it. Lots of money to create a specific deepfake for them. Now you just... It comes with the ADA platform. You're able to go in there, upload something, really quickly turn it around. You don't have to give it a lot of thought. Just pick which scenario works best within your organization and you're off to the races. That is fantastic. Mr. Jess, what do you have on the horizon? What do you have coming up? I mean, it's been wild because you were all over the world.
[00:36:59] I'm like, when will he be in the States? Can I just get him for an hour? Yeah, so we will be in the States for a little while because we have Cabo4Con coming up in May. Which is an exciting event. It's a great opportunity. And by the way, season seven world premiere will be at Cabo4Con this year. So I'm super excited about that. We all get together, red carpet event. I was just going to say, it's like a big red carpet event. It's really exciting. If you guys are in the... Is it Clearwater? Orlando. We'll be in Orlando. Orlando.
[00:37:29] In Orlando. If you're there, check out the CaboCon. Cabo4Con, yeah. It is phenomenal. It is really, really cool. And then we'll be doing other premieres around the world. London is in June. So I'll be back on the road again and with our team. It's a good time to be in London, actually. It is a great time. And not to be in Florida. Right. Yeah, that's exactly right. You planned that trip correctly. Yeah.
[00:37:55] And then we'll be recording New Year demos for next year with Perry and Roger Grimes and some of our other amazing experts, as well as cast of the Inside Man. And then we'll be releasing a new season of Chameleon later this year as well, which I'm also super excited about. So amazing things on the horizon. That's so fantastic. That's great. Well, hey, thank you so much.
[00:38:18] I hope the listeners and viewers really got to understand just understanding what it takes to build a security-minded culture because it's so important to reducing risk. I don't believe humans are the weakest link, but they are the most targeted and they're targeted in ways that tap into our human nature.
[00:38:41] I mean, we're still, you know, we still react the way we reacted millions of years ago to there's a woolly mammoth in our village and we have to run, right? Like, it's that trigger that causes a lot of this despite all the advances in technology. And so being able to really address that and having a mission like that, you know, Noble 4 is fantastic. Well, thank you. And thanks for having me. It was really a pleasure. And look forward to future conversations for sure.
[00:39:18] Hey, everyone. David Mauro, creator and host of Cybercrime Junkies and author of the new nonfiction Moving Target book series. If you're a leader in an organization curious how to roll out AI safely or if you have questions on your incident response plan, how to run tabletop exercises or looking for 24-7 eyes on glass to protect you and keep you growing without interruption,
[00:39:44] and I invite you to sit down with me and my team at NetGain Technologies. We've been around since 1984 before cybersecurity even existed. A simple conversation, absolutely no pressure and no salesy fluff, and you will walk away with a great roadmap no matter what. So if improving your IT, bolstering your security or rolling out AI interests you, contact me directly today at dmorrow at netgainit.com.
[00:40:13] That's d-m-a-u-r-o at netgainit.com. Find out more on our website at netgainit.com. That's netgainit.

