Property operations
Cybersecurity Basics for Landlords and Property Managers
Robert Siciliano on password managers, 2FA, the AAA protocol, AI voice cloning, and why 90% of people skip the basics that make you a hard target.
My companies handle a lot of sensitive data. We store Social Security numbers, applications, credit scores, employment information: property management runs on exactly the kind of records criminals want. And I had never spent real time focused on protecting it.
So I brought on Robert Siciliano, a Boston-based security expert who has been doing security awareness training for over 30 years and working in security for 40. He's written five books on this and has done just about every major media outlet you can name. What he spends most of his energy on isn't software. It's changing hearts, to change minds, to change behaviors, so employees actually care about managing risk.
This conversation turned into one of the most practical episodes we've done for anyone who owns a business, manages properties, or has parents they'd rather not see scammed.
What "Managing Risk" Actually Means
Robert defines it simply. Every single time the phone rings, an email comes in, or you get a text: is the intention of the person on the other end legitimate? Are they trying to extract sensitive information or passwords, or get you to download or click something that infects your device?
Most people don't look at inbound communication that way at all. They look at it in terms of whether it's annoying them. That gap is where breaches happen.
The numbers behind it are staggering. On average there are between 2,500 and 3,000 data breaches in the US every single year, which at this point adds up to something like 300 billion records compromised: yours, mine, everyone's. That works out to roughly 15 to 20 billion passwords sitting in the hands of criminals.
So my first question was the backwards one: what do you do when your information is already out there?
Make the Stolen Data Useless
Robert's answer: it's about making the data useless to the thief.
If your password is in a criminal's hands, the cleanest way to neutralize it is to change it. That's step one. Step two is the one almost nobody follows: never use the same password twice.
Most people use the same passcode across multiple accounts, and Robert calls that the kiss of death. With billions of passwords on the dark web, using one password across 20 accounts means a criminal has access to 20 accounts. So it means changing the passcode on each of those 20, and never reusing one.
The next layer is two-factor authentication. Most of us use it for banking, because we have no choice. For email, eBay, Amazon and the rest, it's often optional, and that's exactly where it matters. If a hacker has your Amazon password, 2FA means they'd also need your phone in their possession to get in.
The third piece is a password manager. Robert pays about $19 a year for his and has used it for 20 years. It's the most effective way to use and manage the number of passwords you need, and it helps set up passkeys for your critical accounts.
I asked about the built-in Apple strong password feature, since our companies run a mix of Apple and PC. Robert's take: the Apple password manager is relatively new (a few years old at most) it isn't especially user-friendly, and it doesn't work on his Android or his Windows machines. It works on his Mac and iPhone, and not all that well. What you want is a true third-party password manager that's ubiquitous across hardware and operating systems, whether that's macOS, Windows, iOS or Android.
So the company-wide policy writes itself: we use a password manager, we use unique passcodes, and we turn on two-factor authentication.
Be a Harder Target Than the Next Guy
Here's the part that landed hardest for me, because it maps exactly onto how we solve crime problems at a property.
Robert estimates that about 90% of the general public (including a lot of employees) aren't doing the basics. Not changing passcodes, not using a password manager, not using 2FA. If 90% are practicing poor cyber hygiene and only 10% are secure, that 10% is the tougher target. To be in the top 10%, you don't have to do much. You just have to do it. The worst thing you can do is nothing.
That's the same principle we use in property management. To solve a crime problem at a building, all you need to do is make it marginally more inconvenient to be a criminal there than somewhere else. Over about 12 to 18 months, criminals start disappearing and go where it's easier.
Security is layers of protection. In the physical world you start with locked doors, then door and window break sensors, security cameras, and all the signage supporting the technology you've installed. Every layer makes you a less attractive target, whatever the criminal's motivation. The digital version works the same way.
I'll confess my own sin here: I hate two-factor authentication and I turn it off anywhere it's optional, because I don't want to wait for a code. Robert's framing changed my mind. Cybersecurity is only 20 or 30 years old as a discipline, and the inconveniences are no different than the ones in any other part of adult life: diet, money, relationships. It's easier and sometimes tastier to get the fast food, but it doesn't contribute to a long healthy life. As he put it, security is the best broccoli you can have.
Why Compliance Training Doesn't Work
Then we got into what goes wrong inside companies.
The first problem is that most organizations aren't doing the 101 basics at all. The second is regulatory. All companies at all levels fall under state and federal rules around compliance. If you aren't doing the basic things and there's a breach, and you can't show due diligence, you're looking at thousands of dollars per record compromised. That means a class action lawsuit, and that can bankrupt an organization.
The basics generally include phishing simulation training as a form of awareness training, plus the hardware and software side: bringing in a penetration tester (an ethical hacker) to run vulnerability software across your network and determine where you're exposed and what updates and upgrades make you compliant.
But Robert says what we see today is security fatigue caused by the compliance trap: bombarding employees with complex, impersonal rules that trigger security aversion. People don't want to engage with security to begin with, and basic compliance training makes it less attractive, not more. The result is a false sense of security from meeting regulatory requirements while actual human behavior stays unchanged and vulnerable. The employee still clicks the links and still responds to the calls and emails.
Phishing simulation is necessary, but it's only designed to fix phishing. It doesn't meet the employee where they are in their personal and professional lives, and it doesn't make them care.
Make It Personal: The Strategic Human Firewall
The fix is changing the dialogue.
Once or twice a year of compliance-based training is putting the cart before the horse. You're not talking to the employee where they are in their personal life, and you're not making security personal to them. Employees care about themselves first: what's in it for me. That's human nature. Self-care is fundamental to self-interested creatures, which is what we are.
So Robert leads with personal security, on the core belief that people protect what they love: securing their child's digital footprint, protecting their own identity, managing their own passwords, protecting their own money. Do that, and you create more secure employees at work.
He starts with a dialogue. In front of a live audience of a hundred people he asks how many use a different secure passcode across all their accounts. If 10% of the room raises a hand, that's a lot. Same question for two-factor authentication. Then he tells them there are about 20 billion passwords on the dark web, and then literally goes to the dark web and shows them the data.
The reaction he gets: "I thought this program was going to be you hitting us over the head with a hammer about protecting company data, and I couldn't care less about that. But what you're saying is this is about me and how I protect myself and my family. I've got questions. What do I do?"
That's the shift into what Robert has developed over 30 years and calls the strategic human firewall. If you're already paying attention (already reading every email, text and phone call for its motivation and seeing the nonsense behind it) you already have a degree of it. If you don't, you upgrade your cyber hygiene and digital literacy until you do.
The human firewall is about blocking deception. It's proactive governance, a mindset that turns employees and consumers from passive targets into active detection layers. It's the shift from "I trust what I see by default" to "I verify everything."
That leads to what he calls security appreciation: the move from awareness, which is knowing, to appreciation, which is caring. The gap between intellectual understanding of risk and emotional commitment to act on it is what he calls the security appreciation gap. Close it and behavior changes permanently.
And when it works, you get the kitchen table effect: a multiplier where a successful training ends with the employee teaching the concepts to their family at home, cementing the lessons for life. Try getting that out of regulatory compliance training.
From the Streets of Boston to the Dark Web
People always ask Robert whether he's former CIA, Secret Service, or law enforcement. His answer: he comes from the streets of Boston.
At 12, he and his eight-year-old brother took the train into downtown Boston and got mugged and beaten by five kids who took all their money. He went home bloody and bruised, and his father explained it to him: you were the rabbit and those boys were the wolves. Lions are true predators, gazelles are true prey. He didn't fully understand it then, but it started making sense over time.
A year later, at 13, a girl he'd met at summer camp told him her mother's boyfriend had assaulted her. He went home and asked his father what sex and rape even were: this was 45 years ago, before anyone had any of the media kids have now. Learning about that, a year after being a victim himself, had a profound effect on how he saw the world. He gravitated toward professions revolving around personal security and started teaching self-defense and karate.
The pivot to digital came in 1995. In his mid-twenties he bought an IBM PS/1 Consultant (a Windows machine with a 150-megabyte hard drive) and had to buy an additional card to connect to AOL. He could accept credit cards over that AOL connection, and within a month of connecting to the internet he got hacked and lost thousands of dollars to credit card fraud. He didn't know that was even possible.
His reaction is what made him good at this. As upset as he was, he was amazed. What they did was awful, but it was also awesome: they stole thousands of dollars over a dial-up connection. How? So his whole approach became reverse engineering the bad actor's process: how they choose victims, how they accomplish their goals. And he realized that if they could do it to him, they could do it to anybody.
Around that same time, municipalities started posting Social Security numbers online to make information accessible to constituents, and identity theft started climbing. Hackers who used to hack for fun and fame started hacking for financial gain. Robert was already in it, and he's been talking about it for 30-plus years since.
AI Made Him Worried for the First Time
For three decades, Robert ended every presentation the same way: don't worry about any of this, as long as you do something about it you'll be fine.
He's now officially worried.
AI, deepfakes and voice cloning are at this point pretty much perfect. There was a day when you could tell computer-generated imagery. Not anymore. AI has stripped away the clumsy red flags of traditional fraud.
In the past, criminals relied on what he calls blunder force phishing: mass-blasting emails riddled with scammer grammar. Today, AI allows high-precision impersonation at scale. He calls it neural puppetry: by scraping seconds of audio and a little video from your social media, criminals use voice cloning and full deepfakes to impersonate a trusted source (a spouse, a CEO, an attorney, a politician) with essentially complete accuracy.
What that does is weaponize our biological default to trust. It makes the deception 100% human.
Robert calls this the human blind spot: the psychological instinct to trust what's familiar, the cognitive gap where biological trust overrides suspicion of any kind. We're an interdependent species. We depend on each other for survival, and that requires trusting each other by default. So every time the phone rings or an email arrives, we impulsively, biologically need to believe people are generally good and don't intend to harm us. Criminals know that and weaponize it.
The part everyone should hear: when people get scammed, 100% of the time they say afterward, "How could I be so stupid?" Robert's answer is that you're not stupid at all. What you are is a loving, caring, empathetic human, and criminals take advantage of that biology. Internet fraud is a business run by organized criminals using social psychology against you.
The AAA Protocol
The practical tool Robert teaches is the AAA protocol: analyze, authenticate, act.
Analyze. Recognize manufactured urgency. Every scam call, text and email is click this link now or else: call this number or your account gets charged, respond or you'll be fined and lose your license. It revolves around manufactured urgency 100% of the time. The moment that urgency demands secrecy or immediate action, stop. Your brain is moving into emotional reaction. Take a breath and move back into analytical thinking: what's the motivation here, what's it trying to accomplish?
Authenticate. Identify the digital mask. Treat every digital communication as a potential breach and look for the technical and biological red flags of a deepfake.
Act. Once you've determined it's nonsense, act using out-of-band verification: never use the contact information built into the inbound call, email or text. Don't use that phone number, don't use that email address, don't click that link. Hang up and call the person back, go to the website you know is legitimate, or use a pre-validated number.
I get a live example about twice a year. Since moving from Seattle to Texas I keep getting the same scam text, and the first tell is an area code from the Philippines. The Department of Licensing texting me from the Philippines is a little odd. The message says I have unpaid parking fees, I need to click a link and pay, and otherwise my license will be suspended. It hits every red flag. It's easy for me because I don't own a vehicle that would be driving in Washington, but without critical thought, the first thought is "where did I park?" instead of "why would they text me a link from the Philippines, and why would a parking ticket I've never heard of suspend my license?"
The Baby Boomer Problem
I see identity theft several times a year across my communities (the 80-unit, the 45-unit senior living) because when you didn't grow up with how we get attacked today, it's easy to be duped.
Robert says that demographic is the main issue: baby boomers are the most moneyed, the least technically savvy, and the most trusting generation left, and they're targeted by multiple scams at once. That generation has amassed something like $120 trillion-plus in wealth, and it's transferring right now: the greatest transfer of wealth in human history, happening over the next 10 to 15 years to Gen X, millennials and Gen Z. That money and that demographic are the target for most of the scams we see.
Most of them, including Robert's own father, aren't using effective password management or two-factor authentication, and don't have a credit freeze protecting their identity. He deliberately stays on top of his parents' security, and he thinks those of us who are more technically savvy should be doing that for the people we love.
The Most Expensive Mistake
I always ask guests about their stupid tax. Robert, having worked with so many businesses, gave a soloreneur's answer that has nothing to do with computers.
The most expensive mistake he's made is hiring vendors, consultants and pseudo-experts to run business processes he doesn't understand. Money gets wasted because he doesn't know enough about their expertise to judge whether they're doing a good job: so he ends up spending hard-earned money on experts who are bad at what they do.
His rule: before you hire anyone for anything, have a working knowledge of that expertise. You should know enough about it that you could do it yourself, and then hire someone with a certain talent to do it better. Sales, marketing, accounting: it doesn't matter. Hire people who are excellent, but be good at it yourself first.
Key Takeaways
- Assume your data is already out there. The fix is making it useless: change passwords, never reuse one, and turn on two-factor authentication everywhere it's offered.
- Use a third-party password manager that works across Mac, Windows, iOS and Android. Robert pays about $19 a year for his.
- Roughly 90% of people don't do the basics, so doing them puts you in the hard-target 10%: the same logic as making a property inconvenient for criminals.
- Compliance training alone creates security fatigue and a false sense of safety. Make security personal to employees and it follows them home: the kitchen table effect.
- AI voice cloning and deepfakes have removed the old red flags. Criminals need only seconds of your audio and video to impersonate someone you trust.
- Run the AAA protocol: analyze for manufactured urgency, authenticate the sender, act using out-of-band verification. Never use the contact details inside the suspicious message.
- Check on your parents' password habits, 2FA and credit freeze. That generation is the most targeted, and the wealth transfer makes them more so.
- Don't hire an expert in something you know nothing about. Learn enough to evaluate the work first.
Watch the full conversation above for Robert's walkthrough of the strategic human firewall and his story of getting hacked over a dial-up AOL connection in 1995. You can find Robert on LinkedIn, where he publishes a newsletter, and at protectnowllc.com: both linked in original episode description. If you want more of what we do here, there's a free course on getting started in multifamily investing and a free community that includes a deal calculator, and mentorship details are on the site.
Read the episode transcript
0:00 Hello and welcome back to the owner meeting podcast. I'm Christian, your channel host. Today joined by Robert 0:06 Sicciliano. Is am I saying that correct? That is correct. Perfect. Robert Siciliano. Uh he is a security expert. 0:14 We're going to be talking about cyber security, how to protect your data. He'll say it better than I do, but this 0:20 is so relevant to my companies and I've never spent time really focused on this niche that we really do need to pay 0:26 attention to. So extremely excited to have you on the channel. I'm sure I'm going to have a ton of questions as will 0:31 our audience, but Robert, tell us a little bit about you. Sure. I am a uh Bostonbased 0:38 girl dad. I got a 17-year-old and a 20-year-old with 58-year-old honey. 0:44 And uh I um have been providing uh what is called security awareness training 0:50 for 30 plus years professionally, engaged in security for 40 years. And uh 0:57 I primarily spend most of my time, energy, and effort in uh changing hearts in order to change minds, to change 1:03 behaviors, to get employees to care about managing risk. Awesome. Awesome. So managing risk, 1:09 define that a little bit for us as far as your niche and your focus. Sure. It's like every single time the 1:15 phone rings, an email comes in, or you get a text message. Um, [clears throat] is that uh is the intention of that 1:23 person on the other end of that communication legit? Are they trying to extract sensitive information, 1:29 passwords, trying to get you to download or click something to infect your device? And most people don't look at 1:35 these inbound communications like that other than if it's annoying them. Uh, but they're not looking at it for 1:42 reasons of, you know, managing risk or security. Uh, which results in data 1:47 breaches. You know, we have on average between 2500 and 3,000 data breaches in the US alone every single year, 1:54 resulting in at this point probably 300 billion with the B records compromised 2:00 of you and I and all of our information. And that adds up to about uh 15 or 20 2:06 billion passwords in the hands of criminals. And so managing risk today is 2:12 what to do with all that sensitive data that's out there on the dark web and how to uh you know react and respond every 2:19 single time an inbound communication comes in that. Okay. So I'm I'm going to start this in in backwards order because I'm 2:25 very interested in this. What do you do when the information's already out there? What what options do you have? 2:31 It's your information is on the dark web which I'm sure all of our stuff has been compromised at some point. 2:36 uh what do you do after the fact? So, it's about making the data useless 2:42 to the thief, right? So, um I'll ask you uh if your password or passwords are in 2:49 the hands of a criminal, what's like the cleanest, easiest way to make that password useless to a thief? 2:55 Uh to change the password. Change the password. That's the first step. And never using the same password 3:01 twice. Mhm. That's like really the most important part of that because most people are using the same passcode across multiple 3:08 accounts and that truly is the kiss of death. Which with billions of passwords out there on the dark web, if you're 3:14 using the same password across 20 different accounts, that means they have access to 20 different accounts. So it 3:21 means changing the passcode for each and every of those 20 accounts, never using the same passcode twice. Another layer 3:28 of protection on top of changing up your passcodes, never using the same passcode twice, is engaging in two-factor 3:36 authentication. So, most of us use two-factor authentication for one account or the other. Usually for 3:42 banking, it's like fundamental. You have to, you have no choice. But for other accounts, some cases email, uh some 3:48 cases, you know, uh eBay or Amazon or whatever, you may not have to use two-factor authentication. But if the 3:55 hacker has access to your Amazon password, another way to keep them out 4:01 is to use two-factor authentication. That means they would need your mobile phone and their possession in order to 4:06 get in. So between changing up your passcodes, never using p two never using the same passcode twice and and setting 4:13 up two-factor authentication for every and all account, use a password manager 4:19 software. A password manager software generally is free to a small fee. I 4:24 think I spend like 19 bucks a year on mine and um I've had it for 20 years and it's the most effective way to use and 4:31 manage all those passwords you're going to need and also it assists in setting up pass keys for all your critical 4:37 accounts. Awesome. So in like the uh I know a lot of our companies we use a lot of Apple products though but you know we 4:44 have pl PC as well. Uh like the Apple uh smart they do now the strong password 4:51 where it automatically creates a unique password and stores it in a wallet of passwords. Is that a is that basically 4:58 the same process? Yeah. So you mentioned you know some people using Apple some people using PCs 5:04 some people use both. And while the Apple password manager that from my experience has only been around for a 5:10 few years if that is relatively new. Yeah. Which which to me that in and of 5:16 itself isn't okay. And I don't find that the Apple Password Manager is entirely user friendly. And the Apple Password 5:22 Manager doesn't work on my Android and it also doesn't work on my Windows machines. Okay? It works on my Mac and it works on my 5:28 iPhone, but not really all that well. So once you engage in a true password 5:33 manager that's ubiquitous across hardware whether it's a Mac or it's a 5:39 Dell operating systems whether it's a uh Microsoft OS or you know iOS or it's an 5:47 Android for that matter a third party password manager works across all environments which is truly what you 5:53 want perfect that that makes sense okay so that's something that everyone in every company should just institute like hey 5:59 this is this is something that We do we have a password manager. We use this password manager. We use unique pass codes and we turn on two factor 6:06 authentication. Exactly. And then what happens is as a result of that you become a tougher 6:11 target. Become a hard target. Right now I would say probably um 90% of the 6:18 general public including many employees aren't doing the basics. 6:24 They're not they're not changing up their passcodes. They're not using password managers. They're not using two-factor authentication. Mhm. 6:30 So if 90% of the population is engaged in poor cyber hygiene and only 10% is 6:36 secure, well that 10% is that tougher target. So to be in the top 10%, you 6:42 don't really have to do much, but you got to do it. The worst thing you could do is nothing. Well, and I love this. So this actually 6:49 ties very well into my niche. You know, I I do real estate. We do property management. We handle a lot of really 6:54 secure data. But when you are trying to solve any crime problem at a property, 6:59 all you need to do is make it marginally more inconvenience to be a criminal 7:04 there than someone else. And magically what happens over the course of like 12 to 18 months. Criminals start 7:09 disappearing from the property and they go somewhere where it's easier to be a criminal. I assume that's pretty much true for cyber crime. If 90% of the 7:16 internet's wide open, why would they bother trying to target the last 10%. Yeah, security is all about layers of 7:22 protection. The more layers you have in place, the more secure be you're going to be. Like in a physical environment, 7:28 you might start with, of course, you know, lock doors. And then from there, you know, various security systems that 7:33 might include uh door and window break sensors, security cameras, and all of 7:38 the signage to support all of the various technologies that you have in place. And so what you're doing there, 7:44 adding all those various layers of physical security, uh you're making that an unattractive target for that 7:51 criminal, whatever their motivation might be. That makes sense to me. And it's something as little and like it's one of 7:57 the first things I'm guilty of. I hate the two factor authentication. I turn that off on everything that's optional because I'm like, I don't want to I 8:03 don't have to get in here and wait for a code and click a button or but but you're you're right. It's the it's the 8:08 little things. It's like, okay, well, if they are if we assume everyone already has some of your information, if you 8:14 make that information more or less useless, you've solved most of the problem right there. Yeah. So, you know, cyber security 8:21 itself is only about maybe 20, 30 years old. It's a relatively new thing based on, you know, how long we've had access 8:28 to hardware and software and the internet in in its entirety. And so it's not a very common um experience for a 8:35 lot of people because they don't want to deal with it to begin with because of those inconveniences. But those inconveniences 8:41 are no different than you know um making better choices in regards to your diet, 8:48 um making better choices in regards to how you spend your money, making better choices in the relationships that you're 8:54 in and so forth. It's like it's like like these various facts of life, these choices that we have. uh look at it's so 9:01 much easier and simpler and sometimes even tastier just to get the fast food, 9:06 but that isn't necessarily going to contribute to, you know, a long healthy life. Um so you have you sometimes have 9:12 to make decisions that aren't really, you know, conducive to making you entirely happy or satisfied, but 9:18 ultimately are what's good for you. And security is frankly, you know, the best broccoli you can have. Uh it's good for 9:25 you. And so when you engage in these basic one-on-one cyber practices in increase your digital literacy um you 9:32 you do become that tougher target and you make the bad guys job that much harder. Outside of the basics, the block 9:39 in tackling the two-factor authentication and and so on, you know, unique passwords, what are the most 9:46 common traps that you see especially in the corporate environment where you'll have employees that leak sensitive data? 9:52 Super relevant to me as you know we have a lot we store social security numbers, 9:57 we have applications, credit scores, job is all the stuff happens with applications. Um we process a lot of 10:04 sensitive data in my companies. what are the most common and fixable things that you see 10:11 on the employee level in small and mid-size companies? So, the main thing is the fact that most 10:18 organizations aren't engaging in the basics. They're not engaging in the 101 stuff like we just talked about, right? That that's one thing. The other thing 10:24 is, you know, all companies at all levels are under the guise of both uh 10:31 state and federal rules and rags in regards to compliance. And if you're not doing these basic things and there's a 10:38 data breach, then you ultimately end up, you know, um in a class action lawsuit. 10:44 Okay? So, if your organization, let's say, you know, uh, is infiltrated and you can't show due diligence, um, you're 10:51 looking at, you know, thousands of dollars per record compromised, which means essentially class action lawsuit. 10:59 And, um, that can bankrupt certain organizations. And so, the basics generally include what's called fishing 11:06 simulation training, at least as a form of awareness training. And beyond that, it's all the hardware and the software 11:12 and and and bringing in what's called a penetration tester like an an ethical 11:17 hacker who runs, you know, vulnerability um software across your network to 11:23 determine, you know, where your vulnerabilities are. Uh what hardware and software updates and upgrades can 11:28 you engage in that ultimately make you compliant. And then from there, you engage in that security awareness 11:34 training, which usually is fishing simulation training. And that by itself 11:40 is necessary to essentially defend the organization from fishing and it helps with the compliance aspect of things. 11:48 However, what we see today is lots of what we call security fatigue caused by 11:55 that compliance trap. Essentially bombarding employees with these complex 12:00 impersonal rules that trigger security adversion. Like people really don't want 12:06 to engage in security to begin with. And so when you engage in basic compliance training, you're just making it more and 12:12 or less attractive, so to speak. And so that it it leads to this false sense of security felt by meeting these 12:20 various regulatory requirements while actual human behavior remains unchanged 12:25 and vulnerable. And the employee still clicks the links and responds to the phone calls and the emails, right? And 12:32 while the fishing simulation training is necessary, it's only really designed to fix the problem of fishing. And what it 12:38 fails to do is address the human, the employee, where they're at uh in both 12:44 their personal and professional lives. And it doesn't really make the employee care about security. And ultimately, 12:51 how do we how do we fix that? Well, we fix that by changing up the dialogue. And changing up the dialogue 12:58 means trying something different than you have been. So that once or twice a 13:04 year of compliance-based training essentially is putting the cart before the horse. You're not actually talking 13:11 to the employee where they're at in their personal lives. You're not making security personal to the employee. 13:18 Like the employee first and foremost cares about themselves. What's in it for me? That's human nature. That's how we 13:24 are. self-care is our is as as as is is fundamental and primary to us, you know, 13:29 selfish or self-interested creatures is what we are. And so when you engage in 13:34 personal security, the core belief that people protect what they love, like you know, securing their child's digital 13:41 footprint, protecting their own identity, managing their own passwords, protecting their own money, right? You 13:49 essentially create more secure employees at work, right? And this is really done 13:54 by engaging in a dialogue to begin with. Like I get in front of a live audience and I ask a 100 people, you know, how 13:59 many of you are using um a different secure passcode across all your 14:05 different accounts. If I get 10% of the room to raise their hand, that's a lot, 14:10 you know, so 90% aren't. And I know this, right? And I asked the same question in regards to two-factor authentication. It just shows how many 14:17 people aren't engaging in the basics. And once you start showing them, oh, and did you know there are about 20 billion 14:23 of our passwords on the dark web and then show them that, like literally go to the dark web and show them the data. 14:29 All of a sudden, they're like, whoa. Like, I didn't know that this program was going to be about this. I thought it 14:35 was going to be you hitting us over the head with a hammer about our company and and how we have to protect company data, and I could care less about that. But 14:41 what you're saying is this is about me and how I protect myself and my family. I got questions. I want to know now what 14:48 do I do? Yeah. Okay. It's so it's just putting the context in like hey where is this relevant to you and then why does this 14:54 apply to it's making it relevant through the correct communication is essentially what it is. 14:59 Plain it simple. And we do this by talking about what I have developed over the past 30 years of doing this. It's 15:06 called the strategic human firewall. Right? So, if you're already paying 15:11 attention, if you're already managing risk, if you're already like fully aware of the email and the text message and 15:17 the phone call when it comes in and what its motivation is and you see the BS behind it, then you already have a 15:24 degree of what I call the strategic human firewall. If many of us don't, 15:29 which is too many people, then you need to kind of update and upgrade your cyber hygiene and your digital literacy. And 15:36 this strategic human firewall is all about blocking deception. It's like this 15:41 proactive governance. It's a mindset that turns us employees, consumers, from 15:46 what I consider passive targets, which is most people, into active detection 15:53 layers. Like they're looking for it. You know, it's a shift from like most people they they just 15:59 fundamentally trust what they see. They want to need to trust by default, which is all of us. 16:04 Yeah. But it's the shift from I trust what I see by default to I verify everything. Like I'm really paying 16:10 attention. Like I'm looking for it. You know, I don't worry about these things. I just do something about it. And so 16:17 that leads to what we call security appreciation. And security appreciation truly is the shift from basic awareness, 16:24 which is like knowing to appreciation, which is like in your heart, which is caring. You know, it's when employees 16:31 appreciate how security protects their own lives. Like you said, we're just reframing it. And when that happens, 16:37 behavior changes permanently. I call this the security appreciation gap. It's 16:42 that chasm between an employees like intellectual understanding of risk, 16:48 which is awareness, and the emotional commitment to act on that awareness, on that knowledge, which 16:53 is truly appreciation. And that results in what we call the kitchen table effect which ultimately is like this multiplier 17:00 effect where a successful training ends with the employee teaching the concepts 17:05 to their family at home cementing those lessons for life. You know, try that with like regulatory compliance 17:12 training. It just doesn't happen. Yeah. Oh, what a cool con. H how did you 17:17 get into this space? You're super passionate about this. Uh h where did 17:23 this start for you? Where did this passion was an individual event? Is this something that has always been interesting? I'm curious on the 17:30 backstory on this because you you're very passionate about this. So I you know when I get off the 17:35 platform um speaking in front of a live audience 100% of the time somebody asks me, "So how did you get into this?" 17:40 Yeah. Like what do you what are you like for former CIA, Secret Service, law enforcement? Like like where do you come 17:46 from? Yeah. I'm like brother I I come from the streets of Boston. Like literally like 17:51 that's where I got my chops. So, at the age of 12, there's like a few different things that happened that kind of like 17:57 shaped my understanding of the human condition. At the age of 12, my my like I think I'm probably twice as old as 18:04 you, I'm guessing. Um, I'm 57 and uh when we were growing up, our parents 18:10 would open up the door at like 6 7 8:00 in the morning, let us outside. We wouldn't come back till it was dark. And 18:17 when we did, we'd be filthy, bleeding, bruised, you name it. Like the fact that 18:22 we are alive today is a small miracle. Like from what we did, what we consumed, 18:27 how fast we drove, we should all be dead, but we survived. I don't know how we did it. That said, my dad gave us a 18:35 very long leash. And uh he let us do whatever we wanted. And so I remember at the age of 12 going 18:41 into downtown Boston on the train and we get off the train, me and my little brother who was eight and um we got 18:47 mugged and beat up by five kids who took all our money, you know, and I didn't know that that was a thing. And so I go 18:54 home all beaten and bloody and bruised and my dad's like, "Whoa, like you know, today he explains to me you were the 19:01 rabbit and those boys were the wolves, right?" And he went on to explain like lions are true predators and gazels are 19:09 true prey. And I was like, whoa, okay. Yeah. All right. You know, I didn't quite fully understand what he was 19:14 talking about, but it began to make sense over time. And about a year later, I was 13 and I 19:20 met a girl at summer camp. She was like my first crush. And um you know, we liked each other and we're holding hands 19:26 on the bus one day. We get off at her bus stop and we're sitting on her front stairs. And mind you, like this is like 19:34 45 46 years ago. And she says to me, um, 19:40 all kind of solemn, you know, emotional, and she says, "My mother's boyfriend 19:46 assaulted me. I just think you should know that." And I didn't quite understand what she was talking about. 19:51 So I go home and I ask my father, "Dad, you know, what is sex? What is rape?" 19:58 Because I had no idea what she was talking about. Mind you, again, 40ome years ago, kids didn't know about that 20:04 stuff. We didn't have porn. We didn't have VCRs. We didn't have VHS. We didn't 20:10 we didn't have any of that. If if anything, you might have found a playboy in the trash on the walk to school, you 20:16 know, like that's it, you know? And so, when I learned about the birds of the bees and sexual assault and being a 20:22 victim of a multiple attack situation a year earlier, all of that had a profound effect in the way I viewed the world. 20:28 It just truly did. And so I gravitated towards professions revolving around personal security and I started teaching 20:34 self-defense and uh in karate and stuff, you know, and at the in my mid20s 1995. 20:42 Yeah. I um I got a an IBM PS1 consultant 20:47 which was the make and model of a Windows 300 machine 20:52 that had 150 megabyte hard drive and I had to buy an additional card to connect 20:58 to AOL for the internet and I had the ability to accept credit cards over my 21:04 AOL connection and uh within a month of connecting to the internet I got hacked 21:11 in 95. five and I lost thousands [laughter] of dollars in credit card fraud like back in the day. 21:17 Yeah. And I did not know that that was a thing. I didn't know that that that that was even possible. No, you may have been the first person 21:24 to ever be credit card hacked. [laughter] It was like it was a big deal to me 21:29 because I lost thousands of dollars. And for me that was like an overwhelming amount of money. But as and my business 21:36 at the time was personal security as it relates to violence prevention. Yeah. And so now this happens to me and 21:42 I'm like and like like violence prevention is also like personal security is is is theft and violence 21:49 prevention in the physical world. And so now I'm stolen from over AOL. And so 21:55 when that happened to me, as I investigated it, as upset as I was, I was just like enamored and amazed at 22:02 what they did. Like what they did was awful, but it was kind of awesome. Like what they did was awesome. like they stole 22:09 thousands of dollars over a dialup connection to AOL. Like that's awesome, 22:15 you know, how'd they do that? And so my thing has always been reverse engineering the bad actors process, how 22:22 they choose their victims, how they accomplish their goals. And so when I 22:28 started to study that, I started to see this is going to be huge because if they could do it to little old me, they could 22:34 do it to anybody. And they started to in a big way. And around that same time, 22:40 municipalities, cities, and towns started to post social security numbers on the internet because they were 22:47 posting all of their information on the internet to make it accessible to, you know, their constituents. 22:52 And so when that started to happen, identity theft started to become a real problem, like when they get your social 22:58 and open up new credit cards under your name. And I started to see identity theft rising significantly. While I'm 23:05 talking about this, it's like just blossoming all around me. And um hackers 23:11 used to hack for fun and fame. And around that time, they started to hack for financial gain. 23:18 And so I I I rolled out right along with that, was like right in it. Like my feet 23:23 were already wet and started to talk about it. And here we are like, you know, 30 something years later. And uh 23:29 I've written five books about it. And uh I've done every possible major media you can think about. Like I've done the 23:35 Howard Stern Show a couple of times, Good Morning America, Night Line, ABC 23:40 World News Tonight, Russian and Chinese Television. I mean, you name it. And because like most organizations, media, 23:47 they don't know who to call when it comes to this stuff. And I'm the guy they they they reach out to. What a what a Isn't it funny how 23:54 some of the best business models and it starts from something very very simple 24:00 and logical? So, you went from physical self-defense, which makes sense, especially with your background to like, 24:06 hey, uh, this is new and this is a threat that is, uh, it's it's interesting, 24:11 terrible, but it's it's it's sincerely interesting. And I I love the way that you've attacked this. So, so far my 24:19 takeaways are most of the defense against this is just the basics. It's 24:26 the blocking and tackling and it's the awareness more than anything. Are there any especially with the the rise of AI? 24:33 Are you seeing a material impact since AI has been a thing in the last six 24:39 months to how we attack security and how more importantly to me how criminals are 24:44 using it to obtain data? Yeah. So AI is, as you know, I mean, it 24:51 is awesome. And its capacity, what it's capable of is amazing. 24:56 And I've been saying for 30 something years, like at the end of every single one of my presentations, listen, like 25:02 don't worry about any of the things I've just talked about. As long as you do something about it, you're going to be fine. 25:08 However, I am now officially worried. And I'm worried because AI, deep fakes, 25:16 voice cloning at this point is pretty much perfect, you know, like you can't 25:22 really tell real from fake anymore, you know? I mean, there was a day when like, 25:28 you know, you could tell that it was like, you know, computergenerated imagery through like Pixar or something. 25:37 Now it's just so perfect. And so AI has truly stripped away the clumsy red flags 25:43 of traditional fraud is what it's done. You know, in the past, criminals relied on what we would call blunder force 25:50 fishing. You know, mass blasting uh emails riddled with scammer grammar, 25:55 right? Today, AI allows for high precision impersonation at scale. Truly, 26:02 uh criminals now use what we call neural puppetry to create perfect lies. And by scraping 26:09 just seconds of audio and a little bit of video from social media of you and I, uh, they're using voice cloning and 26:15 full-blown deep fakes to impersonate a trusted source like a spouse, a CEO, an 26:20 attorney, a politician w with truly 100% accuracy. And what this does is is it 26:26 weaponizes it truly weaponizes our yours and mine biological default to trust 26:35 making the deception 100% human. And so we as humans have what I call the human 26:42 blind spot. And the human blind spot truly is like the psychological instinct to trust what 26:49 is familiar to us. It is that cognitive gap where biological trust overrides 26:56 suspicion of any kind including digital suspicion and AI deep fakes and it 27:01 leaves the door wide open for all kinds of deception. Think of it as like this 27:07 biological default to trust in the psychological shortcuts or the huristics 27:12 that criminals use to bypass human logic like biological impulse that we all 27:18 possess versus intellectual understanding. It's like that internal conflict between our evolved survival 27:25 instincts and our modern knowledge or lack of knowledge of digital risks. We are what is considered an interdependent 27:32 species. We depend on each other for our survival. Man needs woman. Woman needs 27:38 man to procreate to further the species. That requires that we trust each other 27:44 by default. And so every time the phone rings, every time an email comes in, every time a text message comes in, we 27:50 impulsively want to biologically need to trust that people are generally good, that they're 27:57 not going to harm or hurt us. And so we go we go throughout the day, week, month, year, lifetime trusting by 28:04 default. And so criminals know this and they use our biology against us. They 28:11 weaponize it. And they know like if you make the story real enough, then they're 28:18 going to be able to get access to you in in your behavior, in your biology, and 28:24 make you do things that you wouldn't normally do. And 100% of the time when 28:30 people are scammed, when it's all said and done, 100% of the time they always 28:35 say, "How could I be so stupid?" And the reality of it is is you're not stupid at 28:41 all. What you are is a loving, caring, empathetic human. And what the criminals 28:49 do is they take advantage of that biology and they use it against you. And 28:54 it's not that you're stupid. It's that they just understand what makes you choose and decide what makes you, you 29:01 know, click that link because because crime at this point, fraud, internet 29:07 crime is a business and it's and it's it's it's ran by organized criminals 29:13 that use social psychology and our biology against us, which is which is is is sensible. So and 29:19 the things that you do is you go into this aware and that does solve a lot of 29:24 the problems if if you just go yes you can be an empathetic person but that is how people are going to be attacking you and AI is of course uh it it learns this 29:33 and makes this easier for them to implement and to message there's a lot that's going to be happening here 29:38 especially in the next few years as all this technology develops uh where people just need to be more aware 29:44 so the strategic human firewall that governance that mindset utilizes This is a uh technique that I speak to and it's 29:51 called the AAA protocol. So if you want to be safe, you want to be secure, you want to be aware, right? You want to go 29:57 forward um as that human firewall, engage in the AAA protocol, which is 30:04 analyze, authenticate, and then act, right? Basically, analyze 30:09 means recognize and you you've seen this before, manufactured urgency. every 30:16 phone call, every text, every email is the click this link now or else. Call this phone number or else your account's 30:22 going to be charged. You know, engage in this text message or you're going to be 30:27 fined and lose your driver's license. Whatever the BS might be, 100% of the 30:32 time it revolves around manufactured urgency. So analyze it, recognize it, 30:38 and the moment that manufactured urgency might request, you know, secrecy or 30:44 immediate action, stop. Just stop what you're doing. You know, your brain is 30:50 moving into emotional reaction. Otherwise, right? Take a breath. Move 30:55 back into analytical thinking. So once you analyze it for what it actually is, 31:00 what's the motivation of this? What's it doing to me? what's it trying to accomplish? 31:06 Then you authenticate. So analyze, authenticate, act. Authenticate means identify like the digital mask, so to 31:13 speak. You know, treat every digital communication as a potential breach, right? Look for the the technical and 31:20 biological red flags of that deep fake. Okay? 31:25 And then ultimately act. And act means generally like if you determine that, 31:31 okay, this is just total BS. not going to bother. It's not my state's registry 31:36 of motor vehicles sending me a text message because I'm going to lose my driver's license if I don't pay a fine. 31:42 It's just a known BS scam. It's not my employer telling me that I need to click 31:49 this link in order to get paid this month otherwise or this week otherwise, you know, I'm going to lose my job or 31:54 something ridiculous. It's like this is ridiculous. Yeah. and you you you act with what's what what's what's called outofband 32:01 verification which essentially is never using the contact information built into 32:06 that inbound phone call, email, text message. Don't use that phone number. Don't use that email address. Don't 32:12 click that link. Like use an outofband form of communication. like hang up and 32:18 call the person back or go to the website that you know is legit or use a pre-validated number that you know is 32:24 okay before you you know get hoodwinkedked. So a perfect example that 32:30 happens to me all the time. So I I moved from Seattle to Texas uh for weather, for business, for a whole lot of reasons 32:36 and I get the same it's about twice a year I get the same scam text. Uh that's 32:42 first first indicator the area code is from the Philippines. kind of weird. The 32:48 Department of Licensing would text you from the Philippines, but they say, "Hey, your license about to be uh you 32:54 have unpaid parking fees. Uh you need to click this link and pay them. Uh 33:00 otherwise, your license will be suspended and all." It has the urgency. Now, they think that I live in 33:05 Washington. I That one's an easy one for me because I have no vehicles that I own that would be driving in Washington 33:11 State for any reason. It's an easier one to spot, but it hits all the red flags like, "Oh, did I park somewhere that I 33:18 wasn't supposed to? I'm not aware of a parking ticket." You immediately, if you don't give it critical thought, I could 33:23 see someone being like, "Oh, I need to click this link and I need to contest this or what where where did I park is your first thought, not why would they 33:31 text me a link from the Philippines and why would I get my license suspended over a parking ticket? The first time 33:38 I'm ever hearing about it." It doesn't always need to make sense, but I see people get scammed all the time. Another quick example that I see all the time, 33:44 identity theft. I a bunch of the communities that I own, we have 80 units, 45 unit, uh, senior living. I see 33:53 the identity theft there. It's multiple times a year every year when you don't have the technological literacy. You 34:00 didn't grow up with how we get attacked today. It's easy to be duped. And like you said, it doesn't mean you're a bad 34:06 person. Just it happens. you need to be aware. The main issue with that demographic 34:11 that you speak of is that the baby boomers are the most moneyed, uh the 34:16 least technically savvy, uh they're the most trusting generation left in the planet and they're being 34:22 targeted uh by multiple multiple scams. That generation has amassed about 120 34:31 plus trillion dollars in wealth. And that wealth is currently being 34:38 transferred. It's the it's called the greatest transfer of wealth in human history. It's happening right now over 34:44 the next 10 to 15 years. That generation is transferring all of their wealth as they pass to, you know, Gen X, Gen Y, 34:54 millennials, Gen Z, whatever, you know, um that money, that demographic is the 35:00 target for a lot of the scams that we see today. And most of those most of those people like my dad aren't 35:06 engaging in, you know, effective password management or two-factor authentication. Um they don't have 35:11 what's called a credit freeze to protect their identity and so forth. Um they're a huge target. But there's so many basic 35:18 things that they can and should do that, you know, those of us who are somewhat 35:24 responsible for that generation. like I pay attention to my mom and my dad like to make sure that they're like doing 35:30 what they're supposed to do to manage and reduce risk, you know? So, I'm I'm kind of on that on purpose, you know, 35:36 because they're my loved ones and I got to make sure that they're okay, you know, and uh we collectively as a 35:43 community should be doing that for them due to the fact that we are a bit more 35:48 technically savvy than they are. Yes, I absolutely agree. as you're going 35:54 through all of you've been doing this for for for decades now. Uh I'm going to ask the stupid tax question a little 36:00 different than I usually do because you've experienced so many other people's businesses and you can summarize. You don't need to drop any 36:06 names on this. Uh but uh highest stupid tax that you have seen someone pay for 36:11 not doing the blocking and tackling and the basics in your career. What has been the most expensive mistake and uh how 36:18 can others avoid it? You know, the way that I understand or 36:23 would answer that question is like as a small business person as a as a as a 36:29 soloreneur and I've been doing what I do uh virtually for over 30 years um is 36:37 hiring uh vendors or consultants or pseudo experts to engage in business 36:44 processes that um I don't quite understand to uh 36:51 do the jobs that I know need to be done in order to build or manage the 36:56 business. Yeah. And ultimately money is wasted because I 37:03 don't know enough about what it is their expertise is in order to determine if 37:11 they're doing a good job or not. And so you end up or I end up uh spending all 37:17 this good hardearned money on experts that suck at what they do [snorts] and 37:23 because because I don't know enough about what they do to begin with. So I think with with before you hire 37:29 anyone for anything, I think you have to have a pretty good working knowledge of 37:35 what it is that that expertise is. and and you you should know enough about it 37:42 that you could do it yourself, but you hire someone that you know has a certain 37:49 talent to do it better. That's when you hire somebody. Whether that's sales or marketing or social freaking accounting, 37:57 it doesn't matter. You need to hire people that are excellent at what they do, but you need to be really good at it 38:05 to begin with. Love that. Now, if someone wants to learn more from you, uh they want to 38:10 book you as a speaker, they want to ask questions, they want to engage, what is the easiest way to find you and where 38:16 would they go? Well, certainly um I'm always providing updated content on my LinkedIn newsletter. I got tens of 38:22 thousands of followers there. So, just search me Robert Siciliano sicil 38:27 on LinkedIn or just on Google. And otherwise, uh my website is protectlc.com. 38:33 Again, protectlc.com. Oh, that's amazing. That will be linked below in the show notes or if you're 38:39 watching on YouTube on Multif Family Strategy, uh you guys can check that out in the description below. Uh as always, 38:46 interviewing owners of businesses that do the things you want to do or that directly complement your business, 38:51 [music] uh so that you can learn this while you're on the road, driving, uh wherever you're at. Like, subscribe, 38:58 listen for more, and we'll see you on the next episode.
Put these ideas to work.
Get support from Christian and the coaching team with your next multifamily deal. See how the mentorship works or start your application.
Apply Now


