CyberWiseCon Europe 2025

Robert Carson: Guerrilla Warfare for the Blue Team

42:51 · 20 May 2025 – 23 May 2025 · YouTube

About this talk

In this talk, Robert Carson discusses the concept of guerrilla warfare and its application to cybersecurity, particularly for blue teams. He draws parallels between historical military tactics and modern security challenges organizations face. The speaker explains different generations of warfare, ranging from traditional hand-to-hand combat to decentralized guerrilla tactics, and illustrates how these principles can guide cybersecurity strategies. He emphasizes the need for a strong cause to rally support for security initiatives and the importance of effective communication within organizations. Carson advocates for engaging employees through tailored messaging that resonates with their specific roles and challenges, ultimately fostering a collaborative approach to cybersecurity.

Full transcript

[Music] ladies and Gentlemen please welcome our next speaker Robert Carson presenting the topic gorilla Warfare for the blue team am I good yeah all right yall hear me all right uh super excited to do this uh thank you guys for having me here um this is my first time doing this talk with a non us audience so uh as a quick disclaimer I'm going to show pictures

of GFI Saddam Shay AA ma tongue whoever it is I'm not endorsing any of these people we're just talking about facts things that we can learn from Insurgent tactics things like that okay want to be clear I don't want to get cancelled today because it's probably coming um my background so uh before I got into cyber security I was a Marine Corps infantry officer I live with

the Iraqi Army for a year on one of my tours um where I got to see a lot of uh really cool things and see how the Iraqi Army was able to operate without a lot of Technology right A lot of people in process they would come in we would go to these different Villages they would dress somebody up in a ski mask they' point out where

the where the bad guys were where the cache was by lunch we were usually having a lamb Feast it was wonderful very far less kinetic than you might might imagine um and then a corporate background so been on your side uh in America we call it the blue team those are the good guys right red team are all the cool guy hackers that you know get to

speak at Defcon I'll never get to speak there because I'm not that cool but uh you know they're the guys that you know no one ever gets an email you guys don't get emails saying hey thanks for not getting ransomware today right but you're the ones who prevent it that's the blue team right um yeah and uh I uh I I run Seer sex I've got 10

employees we do the Arts and Crafts of cyber but I'm not here to sell you what I do so who cares and um yeah as we're going through please feel free to ask questions you can raise your hand assuming I can see you um and uh away we go first another disclaimer this talk is not about overthrowing your boss changes in leadership May produce undesired results yeah

all right so let's talk about purpose and motivation we're going to talk about tools and techniques how do we execute some current events all right so what is Warfare all right how many people do I have in here that are prior military at all got one okay cool so there's you'll hear multi-generations of warfare so when you think of first gen Warfare and second gen Warfare first

gen Warfare is basically people online shooting at each other with bows and arrows with muskets up to muskets right second gen Warfare you're still online but now we've got rifles so that's like your World War I type scenario that's your second gen Warfare you'll hear gen 3 Warfare gen 3 Warfare is Big maneuver elements that's World War II that's the the Germans coming through that's the um

uh the big left hook that the US Army took during the first Gulf War that's your gener that's your third general warfare and then fourth gen is decentralized that's your gorilla Warfare those your gorilla tactics that's things that uh you know happen in current events today all right and then fifth gen Warfare still debatable what that exactly is but a lot of it people are looking at

as more as piracy uh your ransomware your letters of Mark where people are operating uh independently uh but sanctioned by countries things like that less ideologically driven more uh financially driven whereas your fourth gen are generally more ideologically driven and how does that apply to the corporate world right well if you think about your third gen Warfare right there's a front and a back there's good guys

are over here bad guys are over here that's maybe what your your environment looked like preco where everyone went to the office they did their work and they left right or you VPN in you hit your network and you were in the good guys Zone postco the perimeter is dead long live the new perimeter right right so that's that's kind of how it applies when you want

to think about is like what your old school world was versus what your new school all right so one of the things that you need to know if you're going to launch a gorilla campaign is you need to have the right mindset so this is a term uh coined by General KAC called a three black war three block war and basically and it's very true in Three

City Blocks you can be handing out candy doing a medical intervention helping people out Second City Block you're doing patrols and the third City Block you're in kinetic attack and if you want a copy of this I'll just send you just let you know you don't have to take a picture everyone it's cool um you can see right here copy distribute and close without permission because it's

not a typo that's intentional um but uh back to the three block war so how does that apply to your day-to-day basis running cyber security at your companies well in the morning maybe you're doing some training helping people learn how to change their passwords for the first time holding their hands it's going to be okay we're going to do this right putting on MFA in the middle

of the day maybe you've got a change management meeting maybe your governance meeting something like that that's your patrols and then because nobody attacks at 9:00 a.m. on a Tuesday after you've had your first cup of coffee it's the end of the day that's when the Cyber attack happens and that's when you can tell people to shut up in color right but the way you operate in

your mentality is different during the those different phases and that's very important as a cyber security professional and as a gorilla Warf fighter is to be able to engage with people the right way right so in the morning you know you're super friendly maybe in the evening you can you know when you're in kinetic action it's a little more direct right all right the other thing you

need to know about is hybrid Warfare right so luckily I don't have to explain some of this to this audience but uh it's just like the Russian during uh 2014 they started using uh you know text messages things like that the little green men were coming over things like that pushing that information out that's the same as you putting up posters in your conference rooms I used

to put them in the bathrooms i' put the security newsletter in the bathroom stall because while you're sitting there I have your attention and you can read about cyber security that's right um but the point is using different tactics right different tools techniques whatever it takes we're seeing drone Warfare right that's coming up now there's always an information campaign things like that so what does that mean

for the corporate world right so it's fishing fishing attacks maybe inviting your Executives to a cyber security conference you know maybe it's connect wicon maybe you can get them all the way out to Vegas go out to Defcon they can uh really get scared it'll be fun um but it's also trip wires honey pots honey honey uh honey Nets things like that using those uh uh what

is it called the uh the yellow canaries like things like that that can be that can be considered Warfare all right so the other part if you're gonna launch a gorilla campaign that's what we're trying to do today you got to have a good cause all right that's one of the most important things because if you're walking around trying to push out cyber security to people they

don't care like my company we help companies put in cyber secur programs some of our customers are cyber security companies Nobody Does this stuff for fun okay maybe you do but the rest of us we don't wake up in the morning going man I can't wait to put multiactor on that sounds awesome like that's not what happens right so you've got to think about your messaging and

what you're talking about what's that cause that resonates so you know these are different types of causes right what are you fighting for um you know making sure that you've got something that people care about right so is it about their paychecks is it about business it's about Market opportunities is it things like that downtime something that they might actually care about as opposed to running around

going the hackers are coming the hackers are coming nobody cares it is what it is right um you know and you if you want to look at historical examples so if you look at uh there's a thing called the Sunni Awakening it was in 2007 I think in Iraq and essentially we had a group of disenfranchised sunis that were uh we're in power during Saddam now they're

no longer in power we started cooperating with them in an alanar Province we started making their own local patrols they because we had a cause that resonated both sides wanted to go back to they wanted to run their businesses they wanted to farm their dirt they wanted safety they didn't want the bad guys there so we started working together we had a cause that resonates that created

that that that group and we were able to be very successful and bring the attacks down in Alan bar Province uh but we found and we found that cause generated support super important all right uh the other thing too is you need to have a cause that generates support internally and externally that's why your customers your verticals that you're going into that might matter more than anything

else because you want to be able to get support not only from inside the company but your investors your customers what do they care about using them as advocates for your cause and if you guys have questions along the way feel free to shoot them out um I get excited all so I love this quote um so this is a qu there's I'm GNA give you guys

a quote by Chay Gava um and again I'm not endorsing Chay in any way shape or form but his quote is the peasant must be helped technically economically morally and culturally the gorilla fighter must be sort of a guiding Angel who is falling into the Zone helping the poor always and bothering the rich as little as possible in the first phases of War so what Chay is

saying and how that applies to us is don't be an ass right so when someone gets infected with their laptop or they let their kids do their homework on it and now it's got Roblox and all sorts of fun things I'm sure no one's ever come across that hand him an ET sketch you guys know what an exra sketch is in Lithuania okay I just want to

make sure like that's their new tablet they'll be secure for a minute it'll be fine like have fun with it but screaming at them isn't going to help right so you want to be there to help them you don't want to yell at people when they screw up because they're going to screw up but the minute you start screwing up yelling at them they're going to stop

talking to you they're going to stop giving you Intel what's going on you're going to be seen as a problem not as someone that's positive that's there to help them right so you want to think about that mentality when you're working with your analyst because like and you got to remember all day long this might be what we think about but I can guarantee you it's not

what they think about so and this and these tactics like this is no joke this is stuff that like this is from CH a like these are gorilla he wrote a book on gorilla Warfare ma Tong wrote One tranier wrote One French dude these are all tactics that come from historical examples so treat others you want to be treated right um so describing what your Rules of

Engagement are going to be how are you going to handle it um you know one of the fun things I like to do is I like to block Myspace you know why that's how you figure out who the weirdo is because you want to see complains yeah exactly that's that guy that's like an elf level five or something in Dungeons and Dragons or something just saying it's

possible all right so what tools and techniques so let's talk about the historical example here so luckily with this group you might actually know who these people are uh American audience is a little on the right Eran anyone know who the guy on the left is or this guy son mbar right so he was the former president of Egypt for prime minister I'm not really sure at

this point but one guy used excellent communication this guy and he shut down a coup using FaceTime he did it happened right he created a cause that resonated he created what you could argue would be look look like modern day tianan Square he had tanks and he had he had his supporters out on a bridge over the boss first in estanbul created that imagery that the Turks

didn't want to go with so that he winded up staying in power Samar lost control of his power he was helped by a bunch of activist groups Anonymous things like that they were shown they they gave the locals how to get their message out which created that cause that resonated right so he couldn't just shut down the uh the protests that were going on on on in

Tuck square right he now he's no longer in power so that's why communication is a big piece of your security program and that's one of the things I think you know you go to these conferences and it's super tech tech tech and it's all awesome but you got to be able to talk to humans you go to know what they want right we got to be able

to think about that I'm G pause for a second are there any questions in the chat thing no not yet all right cool really right so let's talk about what matters to them right treat them as civilians or prospective members of your local militia I gave a talk yesterday on changing paradigms and talking about using business information security officers same thing use finding those people those allies

in those different departments who can be part of your security program who can help you give you Intel what's going on with the different types of business what's going on in the business what do they care about what's what what struggles they're having so you can be a part of the solution you know it's like single sign on it's good for security it also makes people's lives

a lot easier sometimes right things like that figuring out how to uh get your Intel sources and talking to people in a way that resonates with them what do they right and here you go here's a list of what matters to them so sales they care about use a transaction they want to make money so hey you know I had a problem I had a had half

the half the sales team hadn't done their security training but I was doing all these calls all these questionnaires you guys don't get any of those in in Lithuania no no questionnaires from your customers security addendums nobody yeah yeah okay I just want to make sure I wasn't the only one we got all these questionnaires right uh I told this head of sales I was like I

can't do any more of these because I'd be lying because your team isn't doing their security training and I was like maybe 3:30 on a Thursday by 7:00 a.m. on Friday the entire sales team had done training because they cared right because I talked about What mattered to them Dev not slowing done Employments we don't want to talk to Dev about their MacBooks that'll just piss them

off they're more paranoid than we are you want to talk about how to do a th pushes a day and be compliant you want to be be able to make them faster right sometimes you have to have that discussion that devops is not of the Flies and you can do whatever you want that's actually not devops but you yeah yeah yeah you know the difference though like

that's that's I don't know if that's actually you know every once in while I'm come across a company I'm like that's not devops that's just you're doing whatever you want uh employees keep the customers happy like paychecks general counsel they like defendable positions right so what matters to them it's important so successful gorilla is going to have a plan right so you need to have that plan

resonates economic growth right we talked about this Co careful big dumb American uh cause that resonates uses intelligence we talked about all this understand the long game use your resources strategically you don't have unlimited budget what's up you raise hand no uh understand strategically right that's important piece you don't have unlimited budget you can't do all the things so what can you be good at what matters

you can do a lot of free security with the tools you already have if you're an 0365 shop you're a Gmail shop whatever there's a lot of stuff that's already built in sometimes it's just upgrading a license it's not the end of the world you don't need to go buy all the things what we got here we used to build blue teams based on Military structure and

pattern do you think it's still valid I do uh but I think you need to look at it uh it depends on how you I guess for whoever is asking that question were you building like platoon or your own little fom or were you building decentralized advisory units would be the question I'd ask because the way I look at it now is opposed to trying to build

a big command structure I'm decentralizing my stuff so I have advisers that go you have Specialists and I I embed them either I I cut them from my team and put them with Dev or I put them with certain departments so that they're able to support and be part of that unit and be far more effective lost the is the clicker it's impressive all right what you

want to think about for your ecosystem right here's your business here's what we do you got your regulatory body so here's all the different risks that come around right nation state actors you have uh those of you who live around here you have some neighbors to the east that maybe you're not friends on Facebook with you know it is what it is um but knowing what's going

on right and understanding like what is your ecosystem what's the target what are they actually after and then build your thread Intel I don't know if this resonates with Six Degrees of Kevin Bacon but um figure out who's brought stuff in so one of the things that I always tell people to do is at any organization there's two organization charts there's the official one that HR draws

it's really pretty and that's nice and then there's the real one because there's what happens with most organizations is like like for myself I went to uh went from one company to the next guess what I brought in other people from the previous company I'd work with right and they may may not be underneath me they may be sitting over in a different department but they're my

boy I already see them on bar we have barbecues on the weekends things like that you need to know who's connected to who and why because that can be your influencers those are the people that can influence something you can drop say something at lunch inadvertently that can wind up getting back to the person you're trying to influence so you need to have those two or charts

in mind you need to understand there are two or charts have no illusion is that it's all perfect and just and respect um and one of the things you want to think about is and the reason why two or charts is important is it's way easier if you have a known identity and a known risk or a known identity and an unknown risk right you don't know

exactly what the risk is but you know that that you know who that you've identified them as opposed to unknown identities and unknown risks you can't protect against that you can't do anything with it right so when you're building your Intel trying to get that who's who's actually after me I don't may not know the risk but I want to know identify the risk actors who are

my threat actors who are coming after me and this is one thing that yeah if you want to take a picture of this if you don't want the whole slideshow I would take a picture of this uh this is as stupid as this is any metrics you're building if you're trying to quantify your security program trying to build Intel and validate the efficacy of how things are

working you should be able to write something like this that says this is how we're going to collect the data this is what we're going to do with the data when something goes wrong who's going to collect it what how often we're going to evaluate it all of those things if you can't Define that for a metric why are you collecting it it doesn't produce action otherwise

if the if the metric just looks cool it's like uh people all the time I see them track number of vulnerabilities who gives the crap what I care about are the number of vulnerabil ities that are new that weren't remediated that are highs and criticals within 30 days that's a metric that tells me if my Security Programs working or not I don't really care how many vulnerabilities

I have we're always going to have new vulnerabilities I care about how old they are the Aging right for something that might produce action so I highly recommend stealing that from please and then there's lots of threat feeds people will sell you all sorts of stuff I know this is Twitter now it's X whatever but this is a tweet deck I think you can still do it

it's free right you get that now have I been poned account guess what you've already got you've already started your Intel feeds you can buy a bunch of stuff out there and there's some great Intel providers I'm sure maybe even here but what are you going to do with it is it curated is it valid for what do right and I used to do this I this

is great because like uh everyone think things are getting dos half the time they're really not and also you can use this for locations right so if you have offices in certain places where you have employees things like that know what's going on in those different environments I used to do that all the time when we an international company so I was able to validate like hey

they're going to be protest near that office stuff like that actually here we go all right embed people right decentralized Workforce you social security program I talked about this in the last talk but people process technology right where are your people put them in the right spots or build your influencing campaign you know we all got influencers now you can be a cyber security influencer be the

new hotness right maybe you'll get invited to something cool probably not but you um the other thing too is like when you're rolling out a program you know just as in any gorilla fight the support the support of the population is conditional on your ability to execute so if you try to roll out an entire program all at once you're going to have a bad day because

if you're not there there to move quickly on third party risk assessments or security training or updates whatever it is that they need whatever you're out they're going to start going around you so you want to make sure that you you're the sport is of your knowing that there's that sport is conditional will help you understand that that you can't screw up you've got to be tight

you got to make sure that your your part whatever your role is is very efficient effective all right problem with the threat Intel in Lithuania is that we are not hiring them companies see no value in CTI teams hash sad CTI is diff in the US I like it um well you don't need to necessarily hire thread Intel that's the thing is like you can get feeds

what kind of Intel do you actually need what are you going to do with it are you building dossier or are you building are you just doing what kind of Intel do you actually need are you a uh I got a customer that's a uh what do they do non for-profit so they have they they fundraise all over the US for uh to prevent suicide they have

a lot of social media so what do we care about I care about their social media so that's where I build the thread Intel and that's what we recommend if they're looking at certain products or things like that or how to do it cheaply what to look for what the risks are right because they've had it happen where someone left and they uh wound up with qanon

taking over their uh their feed which those you don't know what qon is don't worry about it you're better off um any suggestions on effective threat intelligence INF strategic or there you go I think I just kind of covered that of like what does the company do so what the Intel feeds do you need you need to figure that out because every one of these dark web

things the dark web scanners blah blah blah like it sounds freaking great half the time it it's not going to do anything for you right you can get Intel feeds from your Sims things like that there's different threat actors but are they targeting you or is it just purely random acts of hacking you know I remember back in the day I get all these bash attacks I

was like but I don't run Linux outside so why am I doing this um it's a good question what else we got how is the transition from the military to it any challenges uh was pretty actually wasn't that bad so I was a Marine Corp infantry officer didn't know anything about cyber security or it I knew how to buy I knew how to her nerds I could

buy pizza and Red Bull and let them solve the problems that was my key to success I paid for a lot of lunches with Engineers so they could teach me things because I I've had so many things explain to me with salt shakers and ketchup bottles and whatever was on the table that that's how I learned right because it's really just different weapon systems for me it's

just I need to know how to employ them how are they used correctly what makes the most sense those are the questions I asked so that was how I transitioned um the only challenge I had was uh figuring out what to wear to work every day that was probably my biggest transition cuz you know you're in the military you just have your uniform it's easy um and

there's one more what is the challenging situation you encounter with H they hold on to their precious I would say that's the biggest challenge I see with blue teams is they sit there and it's like this is my precious I have to hold on to it I have to insert myself into every single process and be a part of everything stop you need to distribute that accountability

to the different business departments make them responsible you're not the risk owner so stop worrying about risks that aren't yours to be responsible for your job is to advise to help make sure they understand things but at the end of the day if they don't care you don't care like you have to learn to let some stuff go right because you're going to wind up bald looking

like me I say this from a guy who's screwed this up and done it the wrong way okay like have no illusions that I got this right the first time unfortunately I got it wrong that's where I've learned that's a great question though anything else going on right now if not keep going all right so information IO right so zalinsky how many people have seen that green

t-shirt just about every single conference call it might be a blue t-shirt every once in a while right his messaging is on key on point over and over repetitive I need f16s I need f16s I need weapons I need this I need this I need this he is always on message doesn't deviate he has a great IO campaign okay um that's very important your messaging needs to

be consistent what are you here for you're here to enable the business you're not here to make people's life suck nobody wakes up in the morning going hey how can I screw up your day right people think that it looks like you do but I can tell you there's no security person in the world that's been like man I want to talk to devops today I'm gonna

turn on some AV malware and just see what happens you know see I I you know I won't get into your personal life but uh um I can tell you for the most part people don't because they're busy right they aren't they are but there are people out there that's true but for the most part you know and you as a security person need to guard against

that because you're absolutely right like that's how you feel right and like if you're a security person you need to recognize that's how that's how people may perceive you right so again back to that messaging campaign how do they look at you what is their perception of you are you a a Force for good or a force for bad are you trying to help people or not

right because like I remember I had an in I had a this Irishman came in he's like by he's all pissed off and I'm like you're right I turned this on this morning just so you come talk to me how you doing bud like and he's you know he de-escalated really quickly because he realized like no I had no interest in talking to him I don't know

what happened let's figure it out right but you gotta but you have to guard against though to that that mentality of like if you feel that way that's how there are people in your organization that might have that perception of you so understand how are they viewing you all right again about IO you know remember if you're doing counterinsurgency and this is the difference between Insurgency and

counterinsurgency insurgence can lie counter Insurgency you have to inform you uh you're not there to fool people um but remember you're not the only one with the ca right think about uh when Snowden breached the NSA right at first it was a guy from Booze Allen Hamilton very quickly it was a government contractor that's how the io messaging was right think about every time Boeing has an

issue or Airbus the the other airlin the other air airplane manufacturers don't go out there and go oh Boeing's bad like they might get a little pissed recently but for the most part they aren't they aren't because you know why they they don't want to create a mentality of air travel is unsafe right so they mess they kind of stay silent they aren't they aren't trying to

tell you that the that Airline is unsafe and their Airline their airplanes are safe that would be stupid that's why want think about the message and what you hear what you don't hear and what do you have an information campaign from when you have to do instent response that's one thing I think that people do very poorly is that when you roll out your response plan you're

doing your training right here's what we're going to do we're going to turn this on we're going to log this do you have marketing as part of those tabletop exercises sales customer success whatever you call them those people need to be part of those exercises and I would make those exercises all about them I would keep all the nerd stuff in a separate conference because they don't

want to hear it they don't care about bits and bites their eyes are going to glaze over okay but you want to have your cuz like who's going not me I'm not allowed to talk to the public I can talk to you that's about it right not all of us are qualified for that so what is your messaging campaign going to be if you get ransomware what

are you going to tell people right let's say you're a public entity I got a customer that's a major port they're like oh that would be awful what do we do right like those are the things you need to think about what's your IO campaign when you do have instant response how am I doing on time here 15 all right cool so this I add the slide

just the other day because I met uh some dudes from Falco um but you know as you're looking at resources what do you have open source I used to be I would say not anti-open Source but I would discourage it with most of my customers that has changed over the recent years there's things like the Linux Foundation op SS scorecard those are ways where if you're going

to use open source things to save yourself money because you don't have the money but you might have the engineering Talent those are ways to do it and validate those projects are valid there's a community behind it and you'll be able to keep up to date because the biggest risk when you use open source is you got no one to blame you got no support right so

those are ways you want to mitigate the risk using your resources uh appropriately right because you don't have unlimited budget maybe you can use open source for some things and besides you're not paying for stuff need all right execution where do we operate first anyone here old enough to know what the office is you the TV show show up over here okay I had the other day

people had never even seen the office and I felt very old um I was sad uh what's that yeah see I'm glad glad you know it's like I'm like I'm not that old um but uh need a mutual cause right so maybe you work with the people that uh support certain things maybe you leave Dev out of it depending on how that your deployment cycle looks like

with your software product let's say if you're treating you could treat it as commercial off the-shelf software if it was different releases Ops takes it tests it just like they would any piece of software and you could leave Dev out of it at first or you put Dev in it which is where you know if they're a devops operation and you start with them maybe you would

keep sales out of it because who cares do sales have access to the data keeping your program based on what actually matters so I go back to military classifications you've got for official use only you've got secret you've got top secret guess what There are rules for handling those types of data that's how your security program should be written too what matters why right that way it

makes sense you're not putting in man traps for things that don't matter right you're you're you're basing the level of pain is commensurate with the risk and it's something people can actually understand all right now we're executing our gorillo fight you can do drawn out execution that's what Ma tongue did uh the problem with that is you can have loss of will missed opportunities right you might

get a call from Brian Krebs you don't know who Brian Krebs is he's like the Diane Sawyer like the the investigative reporter of infos SEC if you get a call from that person you don't you should just hang up update your resume and walk out be honest you're it's not going to be a good day I would assume um but the other part they drawn out is

it doesn't matter how far you uh how slow you go it's just as long as you get to the end right so I like me medium pace but you can do drawn out execution there's the shortcut method this is what Isis did they went all or nothing right this works right before an audit right after a breach that's when you can probably you can break things and

it's okay all right um but the problem with that is like you've got to be in a spot where like it's okay to break things and shut people off because you're rolling out security tools very quickly enforcing things and it might overcorrect and you got to be prepared for for that so that's your shortcut method that's why I say the medium pace is a good good way

to do it um I always look at if I'm deploying a program I start with six months to certification because there's only so much time so much change in organization can absorb but you also need to keep it moving if you try to if you want it to take two years it'll take two years but it doesn't have to right good good you guys don't even know

that commercial um but movement right now you've got support you've got your ins program you've got your cause that resonates we're moving through that execution phase right now it's time to change your tactics and techniques in Iraq they used to they would uh they would have roadside bombs right and they were using garage door openers so we put metal like axe almost like six foot ax in

front of our Humvees that would literally uh heat up and it would it would it would shut off it it would detonate the uh IEDs it would blow up into the engine compartment saving the the Marines lives what did they do well they started using radio frequencies what did we do we started jamming all the radio frequencies even our own it was great but the point is

changing tactics techniques and procedures so what worked won't always work if you've used posters you put posters up or you do a certain type of security training maybe it's time to change it up right if it's the the no before blah blah blah okay let's change it up let's do something different right rotate that stuff continue to to evolve what you're doing how you're reaching people things

like that there's no reason why you have to write all your policies and procedures or your procedures especially you can make a YouTube video for a work instruction press Zoom press record now your work instruction's done right here's your little internal video YouTube video library make it easy cessation okay once you accomplish your mission make peace disenfranchising new problems all right real quick anyone know who are

you should all be embarrassed do but do you know who these people are this should really embarrass you I will pay for someone's steak dinner I'll give you 50 EUR right now if anyone can give me six out of five or six out of seven because math is hard five wait wait which what did you say which one youing about this guy this one who did you

say CH Vera all right what about this one it's not a proper military presentation without a dead Prussian [ __ ] yeah there we go now sunza sunzu this is a Brazilian guy that's Fabius he's like the OG of Gill of warfare he was blocking Hannibal as they was coming through the Alps and this gentleman right here WR another book great book on Gill of warfare uh a french

guy named tranier I do not endorse his tactics but uh dude's a tough dude um yeah all right I'm I do it on time I all right five minutes we're going to do some questions here I'm skipping current events the only thing I'd like to push I should actually that's website is long it's Blu team Warrior podcast.com if you would like to be on my podcast it's

10 minutes I'd love to hear stories of view of things that worked I don't need to hear stuff that didn't work got plenty of that stuff I want to hear a story of something that actually happened so it's blue team Warrior podcast.com not Blu team Warrior although I don't know maybe it is uh you'll see it on LinkedIn I'd love to have you sign up hit me

up love to hear your story okay it's a chance for you it's 10 minutes all you gotta do is tell me who you are tell me a cool story and anyone you want to thank chance for you to get an infomercial for us to get that messaging out out there our own IO campaign that The Blue Team doesn't suck the blue team is helping people we need

to get that messaging out there that's why I started it so I'd love to have you on it because as I said no one says thank you the servers worked all week sales didn't lose a deal they didn't have a blue screen we need to get credit that all right uh and these are my references any questions how [ __ ] is the I love this pretty [ __ ] so

what I would tell you because that's is unfor this is what I do for a damn living uh put it in early the smaller you are the easier and cheaper it is this is how it is this is how people join the organization the bigger you get the harder it is the more expensive it is the more painful it is um but security and compliance here's where

people screw up is they try to they write either they download stuff off the internet and they write these aspirational policies aspirational being like this is what I'd like us to be like but you're not so write down what you actually do draw a treasure map no one knows how to read you know I was a dumb I'm a marine right like I got out my crayons

and I'm like here's the little map and here's how I get to yes give them a map words are hard right those are some tricks on putting in a program any other questions here how many your passwords are currently what is Hib oh uh mine personally not that many few I've rotated them but I get those alerts absolutely that's the thing is like the high phone will

show up but you can get high phone Google has it Microsoft has it they'll have them any other questions all right well thank you all for your time