I'm Mary Ann Kolbasek McGee, Executive Editor at Information Security Media Group. Today I'm speaking with Dr. Chris Pearson, founder and CEO of Black Cloak, a digital executive protection company that provides threat modeling and deep fake protection to C-suites and Boards. We're going to be discussing digital executive protection and lessons that are emerging from the fatal shooting this week of United Healthcare CEO Brian Thompson.
So Chris, in the wake of the murder of Brian Thompson, there's been a flood of social media and similar public posts directing a heavy volume of harsh criticism and even rage towards the company and its coverage practices, but also towards the health insurance industry in general. What do you make of this sudden flood of hostile comments that are surfacing and are these potential red flags for executives at similarly controversial companies to take action and what sorts of action? Yeah, I mean, at first just starting at the top, I mean, look, this is an incredibly, incredibly sad state of affairs. Brian Thompson, his wife, his family, his friends and the company colleagues that he had just amazingly said.
So we massively, we've sent her condolences. When you think about the level of kind of hatred and vitriol and fervor that is out there, I mean, you know, it does pop up its head in rear, it's ugly head, so to speak, in healthcare, in biomed, in pharmaceuticals, a little bit more because their services that everyone goes ahead and uses in some form of fashion. But the level of hatred there, vitriol, just really, really pungent stuff out there that we've seen in the past five and even 10 years, it's just really risen to unacceptable levels. There's complaining, there's frustration, there's venting, but I mean, I know for sure from our clients that are, you know, Fortune 1000, Fortune 500, even down to Fortune 10 clients, these executives and board members, they're getting death threats, they're getting emails being sent and they're getting text message sent to their phone, they're being docked, right?
Their personal information is being put out there, and their families are being targeted too. So this level of hatred is out there, it's just risen out of control. And I think with some industries, there's much greater trigger factors there, right? And when it's about you or your body or your health or loved ones health, you know, that really seems to trigger people, you know, in addition, I mean, it's a holiday time area and it's like, you know, Thanksgiving travel and the holiday travel coming up and New Year's travel, it's like, you know, people get frustrated at airlines or hotel and that whole experience is something always goes wrong.
Those seem to be trigger points as well. But like you said, we're seeing a lot more in this health care firms that will buy a med space. So Chris, some health care companies have already taken down from their websites, their executive leadership pages in the wake of this murder. Do you think taking down executive leadership pages is actually an effective way to protect these people and their companies?
Why and what else should they be doing at this point? And really, there are kind of two different aspects to this. There's the physical side and there's the digital side. There's a convergence between the two and there is causal implications between the two.
So in terms of your about us or leadership page for anyone, this is the number one, OSIN, token source intelligence tool that everyone, nation, state, cyber criminals, as well as aggrieved parties or per persons that have, you know, perhaps have a, you know, axe brine. First place that people go, they look at those executive pages, they look at the bios, they look at, you know, hey, Jennifer is married to Larry and has, you know, kids look and lay and a dog named Fluffy and they're always at the equestrian complex and they, you know, donate to X, Y and Z charity. There's a lot of information that is contained within those pages that's meant to humanize the executives meant to inform the consumers about the strength of the executive team. But there's a lot of information there that quite honestly is extraneous and does not need to be there.
I don't think taking those pages down is going to hide who those leaders are for a really, really persistent adversary. So someone who wants to know they're going to go to the SEC filings, they're going to go to old pages, they're going to go to old capture pages on like kind of way back machine and stuff. They're going to find different things there. They're going to find the annual reports on the companies and see the executives there.
But I do think right now taking a look at how you can mitigate and reduce and really shrink that tax surface down is a prudent step given what we have seen. And so I think a lot of those are going to continue with that practice in healthcare and outside as well in terms of what do we really need to post here. But that is a great jumping off point for anyone. Once again, an adversary that's on the cybersecurity side or somebody that might transition into verbal attacks, physical attacks and other kinds of directed attacks to executives and board members and C-suite people.
They're just the face of the company. And as they are the face of the company, individuals that are their clients will assume that they know everything that is going on are in charge of everything that's going on accountable for everything that's going on. And they're really, really taking the message to the top. So now Chris, do you think this hostile climate that we're seeing in the wake of the United Healthcare murder is raising the cyber threat level for healthcare insurance companies and similar organizations?
The healthcare sector has already been a big target. You think this is going to perhaps spur DDoS attacks or other sort of similar incidents directed at the healthcare industry based on what's going on right now? Absolutely. I think it's going to actually increase attacks on those key leadership team members.
It could be 10 people at a company. It could be hundreds of people at companies. We Black, we've seen this happen. There was just two years ago, we saw in Q3 and Q4 of 2022, a massive rise in doxing and swatting attacks on board members, swatting attacks specifically on board members in biomed pharmaceutical and healthcare, the nights before board meetings.
So totally disrupting board meetings because police are surrounding the homes of board members with their families. Of course, swatting being an attack by which somebody pretends to call from on the inside the house could be a robotic voice and a person saying, hey, my young husband has killed my kids. I'm hiding in a closet. Please send the police.
You know, these things have disrupted those board members lives, those executives lives, and the boards there. We've seen that for the past two years. We've also seen doxing and protests whereby when people have raised drug prices, when people have raised healthcare prices, that people have actually been sent in an organized fashion to protest the kids homes, schools, those executives and families homes and schools. And so we've seen that being taken to the people directly.
And we have to understand why. And the why is that those people that are executives and board members, their lives are inextricably intertwined, their personal life and their work life. There is no difference. They're always on.
They're never offline. They're always on. And as a result, whether they're at Saturday at Habitat for Humanity with their, you know, acne health insurance, carers, t-shirt on, the whole team is there, they're still on the clock. They're still working.
And that's where it gets really, really tough from a risk perspective. These folks face risks like no other and so do their families. And that's really why we see people lashing out both cyber-wise in terms of, hey, let's target them for fishing, let's target them for a submission. Let's target them during ransomware attacks.
We had that famous right with drugos when their internal systems were targeted. They, the threat actor went ahead and targeted. It's public, right? Targeted the executive teams, personal lives, their husband's wives, kids, spouse, all the rest.
They targeted them. And so we're going to see more of that and more coordinated attacks here, both on that physical realm as well as the cyber realm. So speaking of physical and physical security, how does that fit in with digital executive protection? For instance, you know, if a company sees troubling posts on social media directed at their policies or their executives or there has been, you know, sort of hate email or doxing or any of these things going on, what should companies do?
Should they share this with law enforcement because they are afraid that maybe this will escalate from, you know, just, you know, kind of threats to actual physical security threats? Should they be taking certain actions like, you know, assigning security details or bodyguards, their executives? What's your advice? And how does this all kind of fit together?
Yeah, what's really interesting is that, look, once again, board members, executives, C-suite, they face unique risks, personal life and company life. And they're both intertwined. Inside the four walls of the company from a cyber security company, the CISO has things under control. It's that personal life where they don't.
They can't apply those same protective controls, defensive controls in their personal life for them and their families, which can really shrink the attack service, right? So removing data broker information, knowing what's out there on the deep web dark web, even able to put in place, anti-boxing, anti-swadding types of procedures and technologies, being able to advise people on what they should do in their personal life. So they decrease the risk of nothing's going to erase it, but decrease the risk of personal attack as well as their attack is going to be key. The second part of that is on the physical side, right?
Internal teams, the chief security officer or really the heads of executive protection, the directors of executive protection on the inside of companies, they're charged with protecting that executive, pretty much just that executive in their work environment. And when they go to different conferences, events, major travel, investor meetings, board meetings, from time to time, they also will protect the home with cameras, different measures, their alarms, a whole bunch of other tactics. Really, at the end of the day, it's the mirroring of the fact of, there is no 12 hours a day that the executive and their family need to be protected. They need to be protected 24 hours a day, not because of their name, but because of the comma, comma, CEO, comma, COO, comma, CTO.
It's the position that they have, the role that they play, which is why they need that protection in different varying degrees. Really, you know, honestly, the first place to start is an executive threat assessment. Get an executive threat assessment done on those 10, 20, 100 different executives, differing levels there to be able to understand what you think the risks are might be and then put in place the proper mitigated controls. You're never ever going to move this down to a zero.
Never. That's not what it's about. It's about controlling the risk and powering folks and protecting the other 12 hours of the day because bad stuff does happen there physically, does happen there from a threat perspective and does happen there from a digital perspective as well. And part of that to your point, Marianne, is making sure you have the right relationships with law enforcement to be able to raise up those levels or those threats that reach a critical or high level, however the company's classifying it or the external providers are classifying it, so you can bring in the right resources.
So Chris, you mentioned one number of steps that companies can take, assessing your threat level, et cetera. Are there any new digital executive protection lessons you see potentially emerging from this incident to this tragedy at United Healthcare based on this sort of public reaction we've seen so far and the unusual circumstances of how this person was targeted in such a sort of bold way in the middle of Manhattan, an executive going to his company's investor meetings. What's your advice right now from the digital executive protection perspective based on some of the things that are emerging from this tragedy? I think there are a few things.
Number one, really that executive threat assessment can help understand the full picture of what information is out there, what's available and what needs to be going to get this first. Second, let's just go to a really, really poignant part. There are going to be at every single company, whether you're a public or private, there are going to be at least four board meetings a year. Obviously if you're a publicly traded company, if you're a fortune 1,000 company, those are going to be more public, more known as well as an investor meeting done annually at least.
The fact of the matter is that teams should be, whether it's cyber security or the physical protection side in terms of the CISO, merged with a CISO. They should be working together immediately to right now make sure that for any of those meetings, any of those events, plus special conferences. Hey, X, Y, and Z, you know, Bob Johnson is going to be the keynote speaker at Acmeconference.com and whatever in San Francisco, making sure that the right level of physical protection, executive protection is there for all of those attending board members, executives and C-suite is in place. It's going to be critical.
That's just a really, really basic, immediate first step, as well as making sure that the digital breadcrumbs that executives leave behind in terms of their profiles, where they're at, the different travel, always want to broadcast right things internally to the company of where the executive team is going, where the CEO is going, what things are happening, and to some extent externally, right, really does help inform what the business is doing. We're going to want to really, really work in conjunction with marketing, with PR, with investor relations, have the CISO and CSO, work collaboratively with them to kind of mitigate and really minimize those different breadcrumbs that are left. And then finally, with different executive devices, right, their personal devices are on them at all times. There are different steps that can be taken to also lessen their digital footprint and their digital breadcrumbs.
But I would say this, now is a new day in terms of the risk level that we've now seen. The inherent risk of physical attacks on executives has risen at a massively high level. This is a well-planned, well-coordinated attack. Never seen anything like this within US.
There's one kidnapping, maybe 20 years ago inside the US Open Executive. Now, what we need to do is reach rigor how we think about the controls we apply to this, so that the residual risk is within an acceptable appetite. And this is going to take a lot of folks working together, inside experts, outside experts, and it's just a conversation that we're going to need to start having in a very respectful manner, probably next week. And finally, Chris, one more question.
We're all assuming that this person that killed Brian Thompson was perhaps maybe disgruntled or somehow linked to somebody that was disgruntled over their insurance. That's what it looks like at this point. But how about digital protection for executives from insiders, disgruntled insiders? Are there any advice for that?
Not that somebody that you work with is necessarily going to try to assassinate you, but there are threats that insiders that are unhappy pose, and any advice along that point? Absolutely, absolutely. This is something that actually gets dealt with quite commonly, especially on the inside of the company. There's a lot of information that's available to inside colleagues on the executives where they're going to be from a physical perspective.
So, you know, that always needs to be looked at. This is really a great time for managers to receive training from HR professionals on how to spot signs and symptoms of frustration, of fear of anxiety, of different people expressing themselves in different manners, making sure that they have ways to elicit and identify when this might be happening, when a colleague is in some type of an emotional distress and may take action, in some way of reporting that and working on that with the physical security team, cyber security team, as well as HR and other professionals. You know, sometimes bad things happen. Sometimes they're miscommunications.
What I want to do is be able to spot those different triggers, be able to work on different types of tactics to actually quash out those flames, and then find a way to actually make sure we're communicating it, reporting it, and making sure that people are able to get the right help and right assistance, and sometimes these are just misunderstandings. But that's going to need to be something that's looked at. The one, it's an interesting question, but one place that does a really great job of this is actually airlines and airline training. So for those flight attendants, they're trained on how to go ahead and use some better language in recent years to go and really remove the risk of different things exploding out of proportion.
And that is going to be a critical skill that I think needs to be taught to managers and people within. And I know it's taught in other industries as well. And I think there's some good models that we can look to to find out how we can go ahead and kind of tamp down that forever. So people express themselves, but really, really tamp that forever down.
Well, thank you so much, Chris. I've been speaking to Chris Pearson. I'm Mary Ann Cobasak McGee of Information Security Media Group. Thanks for joining us.