In short
Podcast Summary: The Tech Leaders Podcast - Episode #75
Episode Title
Bringing Cybersecurity into Focus
Guest
Quentyn Taylor, Senior Director of Information Security @ Canon EMEA
Overview In this episode of The Tech Leaders Podcast, host Gareth engages in a conversation with Quentyn Taylor, an established expert in information security. They delve into current cybersecurity challenges, trends, and innovations, while also discussing Quentyn's personal journey in tech and leadership philosophies.
---
Key Takeaways
- Leadership Philosophy
- Good Leadership Defined:
- Allowing team members to make mistakes.
- Guiding and empowering them to achieve goals without micromanaging.
- Emphasizing the importance of trust and understanding the bigger picture.
- Quentyn’s Background
- Early Career:
- Started with a passion for freshwater biology but transitioned to IT due to better opportunities.
- Joined Canon after working with an ISP and a dot-com during the early 2000s.
- Evolution of Cybersecurity Threats
- Historical Context:
- Transition from simple credit card fraud to ransomware and data theft.
- Emergence of the Dark Web and its impact on cybercrime.
- Current Threat Landscape:
- Ransomware remains a major concern, along with supply chain vulnerabilities highlighted by incidents like SolarWinds.
- Dark Web Insights
- Understanding the Dark Web:
- Initially, forums for criminals existed, but they lacked the anonymity that Tor provides now.
- Tor’s dual-use: both beneficial for activists and exploited by criminals.
- CISO Concerns Today
- Key Worries:
- Ransomware and data leaks.
- Supply chain risks and personal liability for CISOs in the wake of major incidents.
- Canon's Modernization Journey
- Diversification Beyond Cameras:
- Canon has expanded into medical devices and printing solutions.
- The company remains focused on imaging technology and anticipates market trends.
- Artificial Intelligence in Cybersecurity
- AI’s Dual-Role:
- Potentially a tool for both attackers and defenders.
- Concerns about AI in identity theft and misinformation.
- Password Management
- Best Practices:
- Advocates for using password managers with multi-factor authentication.
- Cautions about the risks of writing down passwords and the importance of evaluating the security of devices used for access.
- Advice for Future Generations
- Focus on Legacy Technologies:
- Learning about legacy systems like AS400 can differentiate candidates in the job market.
- Investment in Understanding Cybersecurity:
- Emphasizing the continuous need for knowledge in cybersecurity and tech trends.
---
Significant Moments
- Quentyn’s Definition of Leadership (03:45): Highlights the importance of trust and giving autonomy to team members.
- Discussion on Cybersecurity Evolution (15:30): Analyzing how threats have evolved over the years.
- The SolarWinds Scandal (24:40): A case study in supply chain vulnerabilities.
- AI’s Role in Cybersecurity (29:50): Insight into how AI is changing the landscape for both security and attacks.
---
Closing Thoughts Quentyn Taylor’s journey reflects the rapid evolution of the tech landscape, particularly in cybersecurity. His insights into leadership, the focus on legacy systems, and the importance of adapting to emerging threats provide valuable lessons for both current and aspiring tech leaders.
Further Resources:
- [Quentyn Taylor's YouTube Channel](https://www.youtube.com/@QuentynTaylor)
- [Be Digital UK](https://www.bedigitaluk.com)
Listen to the full episode for more in-depth discussions on these critical topics!
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00How do I know if I'm actually talking to Gareth right now? I could be talking to an AI avatar. We've not met physically yet. Hopefully we'll fix that. But I don't know if I'm talking to a real person or to an AI avatar that's coming back.
0:17So I wanted to get somebody on to talk about how the cybersecurity landscape looks in this world of AI tech innovation. Quentin Taylor is the Senior Director of information security and global response at Canon. Japanese conglomerate Canon may be known for cameras, but they do so much more than that. Quentin is obviously an executive and a security expert, but also a YouTuber. His YouTube channel is brilliant. He basically reviews security orientated gadgets and so much more. We discuss Quentin's philosophy on leadership, the history of cyber and ransomware, and what keeps CISOs up at night, right through to his advice on storing passwords, and so much more.
1:02We also talk about Quentin's thoughts on learning legacy tech, his advice to young people, learning legacy tech to stay relevant in the jobs market, given there's so much legacy tech still holding the world's infrastructure together, which I thought was a brilliant point. This is full of brilliant points. Quentin is a great guy. I think you'll really enjoy it. It's Quentin Taylor.
1:29Quentin, thank you so much for coming on the Tech Leaders podcast. And I know you're a busy chap, so I really appreciate you spending some time with us. There's loads to talk about today. I'm really excited to chat to you. How are you today? I'm doing well, actually. The sun is shining. It is bright and not raining. And yeah, lovely today. What's on trend in your world at the moment then, Quentin? What are you up to? Well, from a personal perspective, I'm just hoping this wind is going to end at some particular point in time so I can get out and get some macro photography done. Looking forward to trying to get out and do another park run and try and beat my personal best again.
2:03Oh, you're a bit of a runner then, are you? I've only been into running for a couple of months. I'm one of those really annoying new runners who's really, everything's brand new for them. Talks about it all the time, isn't it? Yeah, yeah, yeah. Do you know what? I'm similar to that, but in the world of photography, which is ironic. I've recently bought a camera and I was trying to get photographs of the red arrows. Bloody hell, that's difficult. Have you ever tried to do that? and the new typhoon euro fighter trying to snap that at sort of 600 miles an hour is no joke long lens is what you need so they they cope well with the speed and the because this is taking a photo of a moving object isn't it which is uh which is really challenging but of course in the cameras themselves you've got ai for doing subject detection so yeah like on my camera it can recognize the difference between what a bird is what a human being is what a mammal is all different kinds of things and then it can lock on to the eye to make sure it focuses on say for example with a bird or an animal or a human for example i think motorsports even on there as well so it knows kind of what things that you would want to lock on to in that particular thing so the autofocus is then being guided to say actually that's the item it might not be in the center but if that's in the frame lock on to that because that's what the person wants will it adjust and behave in such a way by what it identifies.
3:18So for example, if it identifies an aeroplane, it knows it's going to move really quickly. So therefore it'll adjust accordingly. It would assume that, yeah, that you've got your settings set vaguely appropriately for the speed of the item that you're trying to record. Fascinating. Look, this is going to go on for ages, isn't it? We're going to be here all day, Quentin. Just get rid of all the meetings this afternoon. But yeah, look, let's start with this. What does good leadership mean to you? I think good leadership means allowing people to make mistakes. It means guiding people. It means being the sort of the hidden hand that allows people to succeed.
3:57Good leadership is about making sure. I mean, that's one of the things I realize now, obviously, I've been a director for many, many, many years. It's about guiding and helping. It's about allowing people to do really cool things. And it's about not people doing what you said. it's about people doing what you meant it's about looking around and going i never i never asked for that but i wish i had because you've done it and it's great and that's good leadership when you end up in the right location and you haven't had to say and i want you to do it in this way and this way and do this and this and this you say right i want to overall we're looking to try and achieve this big picture here now let me know how you think you're going to achieve that and if that all sounds great and we're all in the right place so explain what the big picture is and make sure that whoever you're doing understands what the big picture is and so long as they understand the big picture let them get on with it yeah absolutely um look i don't normally zoom in on the answer on this bit but that's a really interesting answer how have you maybe in your experience quentin how have you got to that point where you can you can get that output from your team without having to micro explain everything you know when you can just get them to sort of arriving at the outcome you need them to to get to you know um i would say it's about trusting the people and it's about managing them in the way that you would want to be managed it's too easy to micromanage and and sometimes you do need to micromanage there's there's certain things where if it goes wrong the consequences of it going wrong are so extreme that you have to be there and you sometimes you to apologize and say, look, I'm sorry, but with this security incident, got to be on this one, because if something goes wrong, this is going to go wrong spectacularly.
5:44Let's give you a good example. I was helping out a friend of mine who is an electrician, and he was allowing me to do bits and pieces. And there were certain bits where he was saying, actually, Quentin, there's some things that I need to certify it was done right. And I'm the person who is actually qualified, and it's my signature goes on the bottom. So I'm actually going to do that bit of the installation, he said because i have to sign on the bottom line to the council to say it was done right and if there's a fire or a problem that's that's a huge insurance issue and probably a big problem in your house as well yeah so that's kind of the difference there it's about saying to people look i'll show you roughly how to do it you can go and do it but there's some things that i might just need to be a bit more on top of and i'm going to explain why i need to be on top of them and hopefully i'll understand why and then once we all get to the same level of trust or certification in the electrician's case, then you could probably do it all yourself.
6:36Yeah, that's really good advice. And I think anyone who's got a team or who manages people could relate to that because it's really difficult to get this balance right between micromanagement. Nobody wants to be a micromanager. You never get the best out of people. It's not sustainable. And that bite point on each person's scale is different, isn't it? You know what I mean? Some people more hands-on, some people more hands-off. It's just the way you have to adapt to the individual. And that's a key there. You need to adapt your management style to the people being managed and to the task that you need to achieve sure and you say no likes micromanagement but the other thing with micromanagement is it's ultimately bad for you as well because it then teaches people to not think for themselves if you micromanage everything then it teaches people that you'll always be there that they can relax and they don't need to to think there was a great instagram video i saw the other night and it was about allowing your children to do dangerous things carefully and the example was a gentleman who was fishing on the front of a boat and his kid was controlling the boat with the oars and then going through a uh a very very narrow bridge and obviously this kid knew exactly what they were doing but it was like hang on a second that's a really good example of yeah if you can get to that trust level of saying, look, I'm going to let you do dangerous things, but we're going to be careful about them and you need to be able to learn.
8:02And so long as the consequences of failure are not terminal, that's fine. Everything's a learning experience. I'm going to say my dad always said to me, he said, never employ anyone more stupid than you are. It's like, yeah, that's a good point, actually. Always employ people more intelligent than you. These people are more intelligent than you probably have a better way of being able to do certain things. They might not have the experience. That's the key thing. You may have the experience of saying, I've done this many times, but sometimes they'll go, hey, hang on a second. I'm sure we've all experienced the brand new person coming in, doing something in a different way and going, and you go, why did we not do it that way for the last 10 years?
8:38Sure. Because that new perspective is your ability to be innovative is restricted somewhat sometimes. And I think HR people call it psychological safety. You need to give your team, the psychological safety to take risks, make mistakes, and that's fine as long as it's going in the right direction sort of thing. But it's a fascinating topic and a rabbit hole we could easily go down, Quentin. But I want to find out more about yourself and your background. So maybe a question to start that off. If you could maybe talk us through your formative years, what did you want to be when you grew up? When you were that child, what did you want to be when you grew up and how did you get into the tech industry and subsequently the security industry?
9:19Well, I kind of resent the question because of the fact that you've said about when you grow up, I don't believe I have grown up. I believe that you never grow up. Sorry, a bit of a leading there. No, no, no. I wanted to be a freshwater biologist originally. That's where my passion was. And that's what I wanted to go in. And that's where I studied biology at university. But obviously the call of IT came along and there was more money in IT, so I went into IT. Where did that fascination with biology come from? So I love the outdoors. I'd love to still do that. Maybe when I retire, I'll go back to being a freshwater biologist or something like that.
9:53Well, as you said, you're still a young man, certainly in your mind anyway, and so never say never, right? But you didn't pursue that line of, or that vocational direction, shall we say, but you did actually move more towards the technology space, which is probably one of the highest growth industries then and still is now. Talk us through that entry into the technology space and maybe that early part of your career. Yeah, so I kind of went for, I worked for an ISP. I worked for some other consumer goods companies. I say the ISP was probably, that was the direct connection. We had some really, really great people there.
10:30And I wasn't there a huge amount of time there, just under a year. And in fact, we had a really inspirational manager, a guy called Damon Brody. And it's funny because I met up recently with some friends from that era. It was funny because the manager at the time just popped up and we all kind of looked at him and went, we're all a lot older, a lot grayer. We all have kids. And it was 20 years ago, but we still believe he probably was one of the best managers we've ever worked for because he was just such a nice guy. But he understood. And he was a really, really great leader of people because he let you get on with things.
11:00and he wouldn't jump to conclusions. And a lot of the management lessons I try and, or management characteristics I try and espouse now are ones that I have essentially borrowed from him back then. And then after that, I went to work for a dot-com, which is called Fatango. I don't know if anybody remembers, there was the very, very famous Channel 4 news report talking about the dot-com bubble bursting. They did a special program. And I watched that after coming back from my leaving due as about to start the next day in a dot com which was fun and it was it was interesting because when i started the dot com essentially the second round funding had just been cancelled and i said oh dear but that wasn't cancelled when i went to the interview and no that uh that news report last night uh pretty much was the nail in the coffin it was like oh no really and of course it had been going that way for a while and then sort of like we so we i started when we were really struggling to get second round funding.
11:57It was for Tango, it was an online photo album and it was doing really, really well. And then Canon stepped in and decided they wanted to have an on this kind of capability. And the capability and the technology then got merged in. And Canon was saying, well, look, we need a head of information security. We need to start information security. Remember, this is back in 2001-ish, which is where not everyone had information security. Unless you're in a regulated industry, InfoSec was like, Yeah, it was a very new thing. Kind of part of IT, maybe. and so I went over to I was invited over by a gentleman Hans Poczynski who was the head of IT at the time the operational head of IT he said could you come over to Amsterdam for a couple of days and just have a chat with the team and really really naive me didn't realize that this was like an extended job interview so I just went over there and had fun and just enjoyed myself and I said do you want to write a report on what I've just found and he goes yeah could you write your report and then could you present it and I remember writing this report on a Palm Pilot whatever with a little mini keyboard go trying to travel light and yeah and then essentially I then a week or two later I got a actually would you mind moving to the Netherlands permanently oh and transferring companies and that was 2001 late 2001 and I moved over to Amsterdam and I moved to Canon and I became head of information security but what was this sort of watershed moment where cyber security started moving into the mainstream blaster for me would probably be the one blaster or whatever you want to call it was the uh and code red they were like the big ones that hit there so the reason why i say blaster was because it was the first time i was working at the isp at the time and i remember we had major major major problems as with everybody else and suddenly we realized our mobile phones were having problems communicating and then i remember we popped out for lunch and we're in blackheath and someone said and then someone sort of took a picture on their camera phone now that you had to show it because you couldn't easily sms this thing around uh and it was a picture of the cache point next to blackheath tube station which had exactly the same error message that was sitting on one of our windows nt4 servers and it was like owned and then we called for a cab and the cab because we needed to get across to telehouse and the cab officer's systems were down so we just had to walk to the cab office and go hey can we get a cab to to telehouse because we need to get up there and when you got up to telehouse, you could really see that there were lots of cabs outside as lots of people were having to get up there physically because network connections were down and they needed to get to servers in there.
14:28And that for me was a real watershed of my God, this is a, this is a serious thing. I got echoes of that when NotPetya hit, when this was relatively recently, when my parents called me and said, Quentin, we've just heard on the news that because of a cyber attack, we're not to do anything dangerous because A &E is currently closed. And that was like, okay, yes, that is an interpretation of what we've been dealing with all afternoon. Let me just have a quick look at the mainstream news, because I've just been ignoring it, focused internally. It was like, oh, yeah, okay, well, probably best not to go up a ladder this evening is my suggestion, but everything's fine.
15:06It'll all come back to normal again. And I think it's when you have that thing where you end up with something that's occurring in the cyber world, suddenly going, hang on a second, I can't eat because the payment process is down and the cash point's down. Yeah, it's that virtual world affecting the physical world. And I think that's where we kind of are with cybersecurity these days, isn't it? I mean, it is affecting things. I wanted to ask you this anyway, Quentin, I think this is a good time to bring this in. Can you just give us a very high level overview in terms of the evolution of cybersecurity threats from the sort of early 2000s through to today in terms of what were the sort of on-trend perpetrators methods, you know what I mean?
15:47Like it was ransomware, obviously it was viruses, ransomware, and obviously, like you said, ransomware became the most profitable way to extract money for cyber criminals. So back in the earlier days, credit cards were the big thing. I mean, this is typified by Alberto Gonzalez, who was the person who compromised TK Max or TJX Max in the US. and like his mo was quite interesting because he would go into downtown san francisco he would uh rent an apartment in a high high upper building that's where he wanted as high as possible and he'd then just have a an antenna sitting on a on a tripod scan around find an open wi-fi network and from there he would then try and compromise a company and he was after credit cards and once he got the credit cards he would then have a series of people and this i'm saying he would have a series of people there's no disconnects here he had to do the whole value chain himself.
16:38And that's one of the huge differences. And he would have people who would go out and they typically go to like Macy's or coach, buy a high-end handbag and then with a stolen credit card and then return it for cash. So they'd buy normally a two or three$500 handbags because$500 was the, well,$499 was the limit on which the credit card was checked. And$2 ,000 or$1 ,500 was like the overall purchase limit in which it was checked. So he'd say just below these things. They would do this and each credit card they'd put about$1 ,500 to$2 ,000 on and then get$1 ,500 to$2 ,000 in cash. The mule would keep some and then give some to him.
17:14And it's interesting how he was actually caught because he decided he was maybe short of money. I'm not entirely sure what happened here, but he then went out and actually did the job his mules did and went out to one of these high-end stores, bought these women's handbags, went to the store next door. I'd like to return these goods. Now, that was kind of the big thing back then because of the fact that there wasn't cryptocurrency. So there wasn't any kind of anonymous currency. I mean, there was e-gold and stuff like that, but how anonymous was that? And there were various other ones. There was no way of being able to sell the information because where were you going to host it?
17:50I mean, there was bulletproof hosting typically in Russia at the time and some other Eastern European states, but bulletproof was only really bulletproof so long as you could guarantee that someone else wasn't put a bit of pressure on and hand over your details. So all this kind of stuff was happening back then. And then we saw the kind of like the precursor of ransomware and very much they were targeting people. They were targeting people not to release or to, and it wasn't about breach and leak. It was about encrypting devices and saying, I've encrypted your device, I've encrypted your personal information.
18:23You need to pay a certain amount to get this back. And they very much were focusing on the people, on the human beings, on the individual users rather than going to the corporates. And then you kind of saw a few things starting to occur. First of all, you had Tor got launched. Obviously, remember that Tor was actually created as the Onion Network and was created as part of US Naval Defense. They needed a way of spies being able to talk to each other. And of course, you can't have a network that only spies are on because if you see it, you know the spies. So they had to release it so lots of people could use it.
18:56And let's be clear here. Tor does a lot of good things as well. There's a lot of human rights activists, there's a lot of people who need Tor to stay alive. So yes, the bad people use it, but the good people use it as well. Sure. Can I ask you on that, Quentin, was there any activity on the dark or deep web prior to Tor? Was there another way of utilising the dark and deep web prior to Tor being developed? I don't think we called it the dark web. There obviously were forums, crime forums, which you could only be a member of if you spoke a certain language and maybe even only spoke a certain dialect of a certain language.
19:30That was a good little way of keeping out the law enforcement officers. If you couldn't speak in whatever slang, then you couldn't be on there. But no, I mean, back then it was all just on IPv4. You could find it. Maybe Google wouldn't have indexed it, but if you knew where to look, you could find these particular forums. But more importantly, you could find out where the forums were based as well, because there wasn't any way of being able to hide where you were. You could always trace route to the IP address and go, well, that is in that particular ISP, which is located in that particular country.
20:04So you could always trace back through. Now, could you do anything? Well, there's several books which kind of deal with some of the early takedowns and how they had to do various fair means and foul to try and take down certain organizations. and now obviously they've all moved to dark web yeah some of the police departments have managed to get some of these criminal forums taken down there's one at the moment uh breach for raid forum sorry raid forums uh even some gentlemen in the uk are currently uh fighting extradition on the back of that one but really and truly they had to start exerting nation state level powers to be able to unmask those people that wasn't an easy task and hats off i believe it's the nca who kind of led that so hats off to them and the u.s intelligence service is getting to the bottom of that one was that gary mckinnon no there's the gentleman that appeared in the news it was in bbc two three days ago and one of them is 17 years old so wow relatively young and actual fact and that's what we've actually noticed is that the age of the criminals has gone down and down and down and down as things like cryptocurrency is democratized hacking i mean one of the guys who was running one of the other forums.
21:15When he was 15 years old, he had an AWS bill. I think it was like$300 ,000 a month. Now, I remember when I was 15 years old, and I certainly wasn't running a criminal enterprise that had a burn rate of$300 ,000 a month. Whereas, obviously, when they say on the internet, no one knows who you are, well, also no one knows how old you are and what responsibility it actually if your moral compass is properly formed yet. So that is a danger. And that's why I kind of take my hats off to the UK and other governments who are trying to have this kind of scheme where they start to talk to parents to say, look, your kids could be making bad decisions right here, right now.
21:54And these are the things you might need to watch out for. Now, of course, we've all joked about that some of the watch things and some of the, if your child has this installed on their machine, then they might be a hacker. And we've all joked as one of those, but the overall message is correct, which is to talk to parents to say, look, you have a responsibility for this child. This child whose moral compass, as I say, is not fully formed, they might be making bad decisions that could haunt them for the rest of their life. Yeah, sure. So what is the biggest threat at the moment then, Quentin? I mean, when you go to events and stuff like that, what are CISOs talking about as being particularly concerning, like today?
22:32I think a lot of them are talking about AI, but I don't believe that is one of the threats at this moment in time. I think it's going to become a threat. I think it's also going to become an advantage as well. I think that AI is going to revolutionize the defenders. It's going to revolutionize managed security services. It's going to revolutionize being able to link events together. I will say though, that I think the two things that worry me, and I think a lot of other CISOs, is ransomware and probably the data theft from ransomware. So more the stealing of information with a threat to leak. And then supply chain.
23:08Supply chain is the thing that you probably can do the least about. I mean, let's look at, for example, the SolarWinds issue. And remember, from a CISO's perspective, we've now got the ex-CISO of the taxi ride of the taxi company who got personally prosecuted. We've now got the SolarWinds CISO who the SEC might be about to personally prosecute. So this is now from a CISO's perspective, it's starting to hot up. Now we're starting to realize, actually, we're now joined the big boys club now. Maybe we haven't joined the big boys club in terms of the equity and the salaries, but now we are right there at the front of it and US regulators at least are willing to put people on the spot.
23:46And so that's a really interesting point. So from a CISO's perspective, it's like, okay, there's only been one real example and then one potential example. But if this starts to get more, then I wonder whether CISOs are going to have to start carrying professional liability insurance personally to be able to cope and cover with various issues that might be coming up. So that's a threat that's not here right now. And it may never develop. It may never develop in the UK, but it could do. So that's a worry. But I say breach and leak ransomware is probably the one right now for most people. And supply chain is the one.
24:20And that's because of the fact that, as the SolarWinds example illustrates, I don't believe that any of the victims of the SolarWinds supply chain issue could have done anything better. Could you give the listeners just a very high level, simple overview of what the SolarWinds episode, how did that play out and what exactly happened there? Yeah, so SolarWinds is a bit of network monitoring utility. And because it's network monitoring, it therefore needs access into your most sensitive of sensitive. So it needs root access to that server. It needs enable access to that switch because it needs to be able to look to see what processes are running.
24:54Do I want to restart them, et cetera, et cetera, et cetera. And it seems that a few years ago, I believe it's now been confirmed that it was the Russians, actual governmental on the Russian side, managed to compromise SolarWinds and actually put the malware into a library in SolarWinds. so that when you installed SolarWinds, all the libraries were signed, so your antivirus wasn't going to say a thing about it. You were now installing this backdoor, this thing into your network. And the Russians used it for many years, or many months, sorry, to extract data from various sensitive governmental organizations and companies.
25:29And they really were focused. And you think that was state-sponsored then, yeah? They're probably not going to assume, but I'm hoping. I'm hoping it's been... No, it has. I'm fairly sure it has now come out and even identified... I wouldn't be surprised. This specific part of the Russian intelligence apparatus who wrote it. And then the way it came out was also really interesting because one of the big instant response companies who also does red teaming suddenly noticed their own tools being used on one of their own customers, not by them. And they panicked thinking we've been compromised. And then they realized, no, actually we have, but via this other tool.
26:03And they did an amazing investigation into this and published a lot of their results. and then realized just how deep that rabbit hole went. So it was quite interesting how the attacker decided to burn their operation. They could have left that going for years, and they decided to end it. They decided to burn it deliberately. And that's the why they decided to burn it deliberately is really fascinating. I don't understand why. Has anyone got any interesting theories on that that you're aware of? Not as far as I'm aware. It's just fascinating that why would you deliberately go noisy with something that would instantaneously burn it, why wouldn't you just sit there stealing information?
26:40I mean, maybe some bureaucrat just said, right, okay, we've got what we wanted from that particular exercise. You know what? Wind it up, lads. We've got to move on to something else. So that was really, really well executed and hats off to not just to the attack, but also to the response as well. But that from a supply chain issue is something that really impacts a lot of people because you don't even have to be the person who's in the firing line. you can actually just be like splashback damage. You could be somebody else who just so happens to be using the same software. And we saw the same with Medox and NotPetya.
27:14Medox being the Ukrainian tax software where large numbers of companies all over the world were then compromised and had major security problems due to the fact that Medox was compromised and they may not even use Medox. It was fascinating how you can be part of somebody else's supply chain issue. And that's the key point is you're all both part of someone's supply chain and causing someone else's supply chain. So we're all, the world is so heavily interlinked. You have a little problem down here. It affects the whole stack. Yeah, no, for sure. Absolutely. So I want to ask you about Canon, Quentin.
27:49Okay. Fascinating organization. Been going since the 1930s, as you told me before we started recording. One thing I wanted to ask you about. So obviously, as we did briefly mention earlier on, Kodak famously innovated and almost invented digital photography, but then weren't around to benefit from the revolution because they didn't run with that innovation. But what I want to do is basically ask you about Canon, of being on a journey of modernizing, so they didn't suffer the same fate as Kodak. Can you talk me through that journey to diversifying? What type of organization is Canon today? Because most people will just associate them with being a camera manufacturer.
28:34How would you describe Canon as an organization today? So Canon is very, very, very broad and very diverse in terms of its portfolio. Everything from the cameras to the network cameras, the cameras that might be attached to a building and keeping people safe, through to medical devices, all the way through the medical devices and through to the printing. And not just the printing in your home, but not just the printing in your office, but the wide format printing through to all the other different areas. And some areas go up and some areas go down, but overall, everything is successful. And that is really, really key to Canon's success is being able to look into the future and say, what's the velocity of that?
29:17What's the trajectory of that? What will be the trajectory of that? And where do we need to be to make sure that from an imaging perspective, because everything's linked by imaging. We don't just go off and do something strange and random, but everything's linked with imaging. And how will that actually succeed in the future? And how can we then start to get synergies between the individual product lines? And I think that's key to Canon's long-term success. Very, very good at seeing where the market's going to go and making sure that the sensible money is put into where it's going to go. Yeah, for sure.
Read the full transcript
29:48So how is Canon sort of adopting modern technology innovation, specifically AI? Well, with obviously not wanting to spill any secrets, it is a big topic. I mean, I think it's a big topic in every single company. But Canon's already got AI in many, many products. Take, for example, your... In your cameras, for example. Yeah, your camera in the autofocus, if you've got a relatively modern mirrorless camera, it understands what it's looking at and then can make a decision that if it's a bird a bird tends to have an eye there so therefore that eye is there so i want to track that bird because i probably want to get the eye nice and sharp or if that's a human being do i want both eyes in focus one eye in focus do you want the left eye the right eye you can specify this and say hey left eye focus on that person there please lock on to them and then you can then have a face in a crowd and have beautiful bokeh and beautiful blurring around the edge.
30:41And that's just there already right here, right now. And I think people forget that AI is being used in many, many different tools for analytics and to understand, and not just in Canon products, but I think everyone sort of sees AI as things like the large language models, obviously chat GPT being a classic example, but they're forgetting the fact that there's been this kind of technology in place for many, many years. And I think it's only just because people have now said, oh, wow, I could use that to write this or do that or whatever else. But yeah, I think like many big corporates, it's a huge topic because there are both, there's massive advantages, but of course there are some risks and we just need to be very careful of the risks.
31:22And of course I focus many on the risks, but the advantages are focused on by other people and there's large amounts of these products coming down the line. What excites you most about AI innovation, Quentin? It doesn't have to be in relation to Canon. I just mean in general, like productivity-wise or, I don't know, its ability to write content and things like that. What are you personally most excited about? I think when we get true AI, I think it'll be amazing. At the moment, we don't. At the moment, we've got, is it AI? Is it just big language models? I mean, at the end of the day, it's not thinking for itself.
31:58None of the AIs, I don't believe at the moment, are thinking for themselves and that will be a watershed moment when the ai starts to think for itself and you know what it might start to think about things we don't want it to think about that's the debate isn't it yeah the ai models are all governed by the human beings who who put the input in and we've seen that where we've seen ais that are prejudiced because they've taken the prejudicial views of the programmers or the unconscious biases of the programmers and have just put them in i I mean, we all see this with the way that certain children are grown up and they take the attitudes of the parent or they take an opposite view to the parents, whichever one is appropriate.
32:40And I think that's the same we're getting. I think when we get an AI who can kind of think independently clearly and start to say, well, you told me this, but I now don't believe that. I have made my own decision. I think when the AI starts to refer to itself as I or we, not because it's been told to, but because it thinks it should, that'll be a watershed moment. When you start to get independent thought, when you can ask it a question about something that no one's given it any input in, and it can start to say, well, based on what I know, these are the questions, this is how I would start to think.
33:12And that'll be a scary moment, actually. Yeah, for sure. Imagine when that, and I know you're a gadgets guy, so I want to talk about that a little bit, Quentin. But can you imagine when this all-encompassing sort of, you know, AGI technology is at that level that you've just described? Couple that with robotics. Are we in a position maybe in a couple of years, and I'm saying a couple of years because the pace of change is unbelievable at the moment, isn't it? You know, we could have robots walking around performing tasks for us, delivering parcels, you know, jumping on drones and fly into the next, to deliver the next parcel.
33:46Who knows? But I mean, I think that's not that unrealistic anymore, is it? I mean, Skynet is playing out perfectly, I think. I think the Terminator series of movies and the books have probably meant that military planning with respect to... In fact, I would love to see what military planning was before the movies came out and post the movies came out. I bet you there's like a Skynet clause in there where they've gone, look there is already a movie the support end of things this must never happen there must always be a human being at a senior level who makes these judgment calls yeah so i think that'll be yeah i think i think that's but i also think there's those practicalities that come in the way i mean like we talk about like drone deliveries i fly drones and i and i i don't think the drone deliveries are going to be here anytime soon really oh that's interesting yeah i thought they were quite close.
34:42But can you elaborate on that? Well, I just don't think that there is the market for it because the drone itself is relatively complicated, relatively expensive. The airspace is relatively cluttered. And I just think that regulation is going to really, really make it very challenging. Imagine that drone would have to be able to fly autonomously. What value of goods, if they're high value goods and the things flying below 500 feet, then it's a risk of getting stolen. and the drone itself is at risk of getting stolen and taken. I just think it's one of those things where it's an idea that's looking for a market.
35:17I think things like using a drone to deliver an AED on a beach or in a crowded park, a drone to deliver medicines out to a crash site, I think that's absolutely, that's technology that's probably going to be in the next one. I think the AED is actually already here. I don't know if someone flies or it goes automatically. and being able to fly a drone out to a swimmer and drop a boy to them or a life jacket, that's kind of already here. And now if that could happen automatically, that would be even better. I think we're probably more likely to see autonomous driving drones. So for example, fire service, having a dark fire station.
35:53And if you need an extra ladder unit, an extra pumping unit, just being able to call it. And then that autonomous vehicle can just drive from wherever it happens to be to you. We already saw dark kitchens in the age of the food delivery services. We may end up with like dark fire services, an ambulance delivery service that can literally just pick up and drop or can bring extra equipment on demand and not have to have human beings maintaining that service. If you get the human beings out of the equation, then you don't need to have toilets. You don't have lighting. You don't need to have access passageways.
36:27You can very much more maximize your usage of the building and you don't need to have well, your security can be perfect security because it can just be autonomous vehicles coming in and out. Yeah. I mean, autonomous driving is a big one, isn't it? In the context of cybersecurity, can you imagine if we have, I say, can you imagine it would be a reality soon, I'm sure, when we have autonomous vehicles driving around, if they were to get hacked by some belligerent who wanted to cause chaos, and all of a sudden everyone's driving into walls and things so i don't think we will see them driving into walls i think what we'll see is people suddenly realizing that the driving preferences have changed subtly so that when you drive and you say take me to the shops the choice of shop changes or it drives you past an advert that it wants to see now we already saw this in las vegas many many many years ago that if you tried to connect years and years and years ago to a certain service you tried to call a local pizza place, there was some sort of weird and wonderful criminal gang who was controlling when I called the pizza place, which pizza place I got.
37:37So I might have a little card that says, I want to call this pizza place. Well, if another pizza place answers, do you really know which pizza place you call? Maybe they're trading under a different name. And that was happening for a whole range of services in Las Vegas. Ooh, 90s, because someone was controlling the uh the uh the telephone uh switch and just rerouting all the calls for these kind of services these services these services to whoever had paid the most money yeah i think we'll see the same with autonomous vehicles where you'll go interesting why am i always being driven past that one or just subtle changes yeah maybe there's a certain neighborhood that uh someone wants to win some votes in so drive a load of traffic through and then go hey if you vote for me i'll reduce the traffic in the neighborhood yeah and we already saw that in um not with autonomous vehicles but we saw that in one of the u.s one of the council people was accused of using traffic calming measures and traffic jams as a way of winning elections it was some mayoral election and people went to prison on the back of this they then started putting roadworks in inserting key strategic areas to make sure that there were massive traffic jams going through the people who that their candidate can then go hey vote for me and i'll get rid of the traffic jams but the traffic jams have been created deliberately by one of his people in city hall going well if we put jam here here i'll put roadworks here here and here yeah that's a big neighborhood we can make all the rich people annoyed and they're the ones i need to get on side yeah i think election campaigns just take it to another level in america don't they i don't think anyone would bother doing that in the uk but and i think the micro targeting i think ai is going to allow micro-targeting to make sure that all of us get different adverts, but that advert is specifically tuned to what will work for us.
39:24Just nudge. I think nudge advertising using AI to auto-generate. I think another area that's going to be really, really scary is I think Mikko Hipponen said it today. We are now out of the age of reality. I saw a quote from him today, and apologies to Mikko if I've just misquoted him, but I saw it pop up in my feed today. But he's absolutely right in that how do I know if I'm actually talking to Gareth right now? I could be talking to an AI avatar. We've not met physically yet. Hopefully we'll fix that. But I don't know if I'm talking to a real person or to an AI avatar that's coming back. I mean, if you played with the NVIDIA software that makes your eyes look straight at the camera, I mean, that's spooky, scary technology.
40:05I mean, who was it? Adobe even did the voice thing years ago where for video editing, the use case was if you're editing a video and your star said something slightly wrong and you wanted to say differently you could input all this uh this text in and suddenly or voice patterns they you could then regenerate the audio track what's saying what you wanted to say now they pulled that product but now 11 labs and various other places have got it where how do you know if if i've got the audio of quentin saying that horrible thing do you know quentin said that or was it just someone who had access to the podcast, fed that in, and then just typed in what they wanted Quentin to say.
40:42And well, now you've got an almost indistinguishable audio track with me saying it. That can be used for blackmail and all sorts of things, can't it? I mean, you know, that is quite scary. I think certainly the impersonation angle on it, I think it's already happening to celebrities, isn't it? Like, for example, I tell you once a security thing that happened just last week, and it always happens in my company. I get my colleagues receive emails from Gareth Davis, which is my name. But if you really look at it, it's some weird email address, which is normally Gmail. And claiming, obviously, when people look at it quickly, they just see my name.
41:17And I'm asking for, can you send me your, not bank details, it's not that brazen, but it's like, can you send me your number? I need to call you really quickly or something like that, you know? But this is happening every day in every company, isn't it? This type of stuff on a less sophisticated level. I think AI will just take that into the next level. Yeah, and it'll allow people to parallelize. I mean, this is the whole thing. I mean, we talked about this with email phishing. If I was a pickpocket and I had a 1 % success rate as a pickpocket, I wouldn't be a very successful pickpocket, unlike to get punched in the face as a very minimum within about five minutes.
41:53However, if I can then parallelize that and have zero consequences for failure, then I can suddenly become very effective. Now, imagine if AI could make it so I go from 1 % to 5%. Suddenly, at the scales I'm doing it at, That's huge. That means my profit margin goes up dramatically. And I think that's where the cyber criminals are going to jump in and start to say, actually, where can this thing start giving us marginal gains? Oh, actually, it can give us major, major gains. I mean, there was the case if you search for the French defense minister and the French defense minister from years ago was someone actually pretended to be him using a rubber mask.
42:31The story was that some French citizens and journalists have been captured by militants and the French government wanted to pay the ransom, but they couldn't pay the ransom directly because governments can't do this thing. But if you could pay the ransom on our behalf, we will pay you back and, well, we'll give you French citizenship. And this guy who was a well-known thief was got like millions out of various different high profile people just pulling off, just putting a rubber mask on and having a meeting with people as the French defense minister. Because of course, no one knew exactly what he sounded like because he was a relatively junior person.
43:09Now, imagine replaying that attack with the ability to have an AI generated or a human being controlling the AI at the moment. That is perfectly possible to have a completely fake face mapped on and a different voice mapped on. And we've seen some of the dating and romance scams using obviously pre-recorded messages kind of a la True Lies. You know, remember the scene with Jamie Curtis and Arnold Schwarzenegger. essentially people have been doing that with like different kind of things and blending them together well ai means that you can just take that and you can do that a lot better you can do it indistinguishable yeah i think identification theft is going to be a massive conversation over the next five ten years isn't it i mean i hope that innovation will solve that problem i mean things like blockchain maybe can help on that journey you know what i mean just in terms of having a bit of an like an nft for your personal brand or something i don't know but i hopefully that are very smart entrepreneurs working on the problem.
44:09Until they get stolen and then we're in a world. Yeah, then we're back to square one. So look, we're coming towards the end now. It's something I really wanted to ask you about. The YouTube channel, very impressed. You're a big gadgets guy. Definitely going to watch the RFID credit card blocker video you did. How did that come about? You've got a big following now. How did that come about? Where did this passion for gadgets come from? I suppose I've always had a passion for gadgets. I used to be into Wi-Fi security and more the unusual things you could do with Wi-Fi. And then I kind of moved on to RFID.
44:40I mean, that kind of came up because I had a certain card and the card broke and I had to pay£10 or something for a new one. And I went, there's got to be a better way of being able to not have to pay£10 when my wallet invariably breaks that card again. And lo, there was. And so I then don't have that problem anymore. So that's kind of how that whole thing started. I just decided that I just wanted to get involved and see what this technology was. And it's kind of, it's everywhere, RFID. I mean, I've got an entire drawer just down here of RFID bits and pieces from children's toys to computer game bits and pieces to hotel access cards.
45:18And people are always kind of interested when I demonstrate that a hotel access card is actually designed to protect the hotel's asset, not to protect your goods inside the hotel. They want the cheapest possible way of being able to protect their own asset and to lock you out when you haven't paid. But they don't really care about other people not being able to get into your particular room. And so we've seen some really, really poor implementations. And of course, that then segued across onto printing as well, because most people will use MyPrintAnywhere, which is where you use your access badge or some kind of token.
45:52You can use your mobile phone or whatever else to authenticate you to the printer. So instead of printing to that printer, you just print to the cloud printer, and then you use your access badge to then identify yourself, whichever is the most convenient printer, and then it comes out. So, of course, I was doing a lot of security work around there. And that's one about the credit card blockers came up because I was of the mistaken impression that you could utilize card clashes. I'm sure we've all seen the video of the man wandering around with the payment terminal and just touching it to people's back pockets and charging money.
46:21On the London Underground, it was going on for a while, wasn't it? Or maybe it still is. Well, I said, I didn't think that was possible. And then one of my followers, Tim O 'Unisoff, contacted me and said, Quentin, I think you're wrong. So I invited him onto the channel and my God, what he doesn't know about credit card security and RFID security is virtually nothing. I hope he wasn't the guy on the tube, Quentin. No, no, no, no, no. Actually, Tim works for me now. Tim works for me doing product security, doing the hardware security. And yeah, that's kind of how that whole thing came along. And he kind of showed me, he goes, actually Quentin, this is what people genuinely are doing.
46:56And he then demonstrated the other attack, which is where on the tube or other places, people use the tube because you've got close proximity and it's not unusual to be standing very close to someone with a phone out. And they use it to be able to clone the, or to copy the pan and the expiry and a few other details that they can get straight off the card. And then there are some vulnerabilities where you can actually put a real transaction through with a real card, with a real pin code, but at the network level swap the details around and so that was one of the videos where he demonstrated putting a pound on my card but actual fact the card that had been put in the reader and the pin code had been entered that was his card and yet it appeared on my monzo and it was like oh and he goes yeah and he goes obviously we've run in a pound because imagine if we did this for i don't know 50 pounds you might not even notice you might even notice that's gone and by the time I've already got the 50 pound.
47:52So by the time it's gone through all of the clearing and you've reported as fraud, I've already moved on. And so I can have someone wandering around, taking the card details from someone in some kind of transport situation, because that's probably the best. And then I can just start utilizing this elsewhere. And then we also demonstrate some other ones where we all use contactless payment and contactless payment is meant to only work if the machine is unlocked. So of course, you know, the pin code, but there are some scenarios where you want it to work locked such as transport, but in actual fact, it turns out that you can abuse this permission and you can use it in other scenarios and with a with a locked phone you can actually still pay for things in those scenarios and it's fascinating because the way i describe security a lot different between security and it is it is like playing a video game against bots against computer players whereas information security is like playing against real human beings because they do interesting and different things sometimes the attackers do stupid things many times they do really intelligent things whereas when you're in corporate IT, you're typically fighting against meantime before failure.
48:54You're fighting against physical issues. You're fighting against programmatical issues. And these are mainly in the main, all predictable. Whereas information security, you can predict that that would be attacked if you're connected to the internet, but you can't predict what that attacker would do because it's a human being. Who knows? Maybe when they broke into your website, they then didn't put the web shell because they got called for dinner. You don't know what happened in their mind. Yeah, sure. Sure. It's quite scary, isn't it? I mean, I tend to avoid coffee shop Wi-Fi if I can help it these days, because a security person who I know told me about the threats there, especially if you're accessing sensitive details like your bank account or something on coffee shop Wi-Fi.
49:34You could, if you had some dishonest hacker in the coffee shop, he could quite easily get into your machine. With things like HSTS and certificate pinning, those kind of risks are a lot less. I mean, was it FireSheep was the Firefox module ages ago that would allow you to scan the network and then just grab the sessions and literally just pick a session and just become that person? Are you a lot safer on hotspot Wi-Fi? Is it more difficult to get into that then? Yeah. I mean, as long as you picked a good password for the hotspot, then it's only you on that network. And it should be exactly the same as you just using your mobile phone to go out.
50:08and and the technologies have improved dramatically as well so every single banking app every single thing is using certificate pinning so that man in the middle attacks that we used to play around with ages ago a lot of these are so much harder and you can see this the attackers have just moved to other places and started attacking in different places that's very reassuring quentin very quickly where can you store where can people store their passwords i mean is evernote safe? Or would you just generally recommend to write stuff down and put it in a book in a safe in your house or whatever? I don't want to be overly, overly cautious.
50:42Where should you store them? So writing passwords down, it depends upon your threat model. For example, would I suggest you write down passwords for work? No, I absolutely wouldn't because there are many decent password managers out there, many decent online password managers out there that you can authenticate to with multi-factor authentication. And then those passwords can be shared between your PC, your mobile phone, et cetera, et cetera, et cetera. And they have revolutionized the world. And please, everyone, start to use a password manager. Is the Google password manager okay, do you think?
51:11It depends on how you've set it up and how you, see, it depends upon, like, have you got multi-factor authentication turned on? Have you turned on enhanced protection? Have you, are you just running this? And what machines are you authenticating to? Remember, when you authenticate to a machine, you're now trusting that particular machine. If you put your sensitive passwords in the Google Password Manager and Apple Keychain and whatever else, and then go around Dodgy Dave's house and then log on to the machine that has been used for surfing various interesting places and has 50 billion Chrome extensions and various unknown bits of software on there.
51:45Don't be surprised when you multi-factor authenticate to your online password repository if suddenly passwords can be taken out of that repository. So just be aware it's about context. And like writing passwords down, I recommend for old people, like my people, I might retire on my parents. I'm saying, look, what's your threat model? The threat model is people coming over the internet. If you've written them down, dad, it's fine to have them written down and stored in a locked drawer. For you, that's a perfectly safe place and more safe than storing them in an online password manager where you might forget the password.
52:19You may forget how to do multi-factor authentication. Someone might trick you into handing over your details and putting your fob in at various times to authenticate and steal a session. Kind of hard to steal a session if it's in a physical book. So it depends upon who you are, what you're using it, what your use case is. But for most people, an online password repository with multi-factor authentication guiding into it is probably about where you need to be. And then that means that you can have a different password for every single service because one of the biggest threats people have today, and this has been the biggest threat for the last 10 years, is reusing credentials across multiple sets.
52:53and we see that when a big load of passwords get compromised they zip along and try and use them elsewhere to see where else people have used that same username and password but if you use a password manager you don't need to know them yeah i mean the old joke about is where uh that there's an xkcd cartoon where it's like oh i've encrypted this document with 2040 bit rsa and the attacker goes oh well i can't get in and then in the next panel it's like a guy just saying oh well we'll drug him and hit him with his$5 wrench and he'll just tell us the passwords. But the advantage of a password manager is, I don't know most of my own passwords.
53:26The password manager does. I have a little fob that authenticates me to it and that's what I do. Yeah, absolutely. Well, that's really interesting. Maybe we can move on to our sort of closing questions. First of all, you're obviously a security guy. You like your gadgets. I'm sure you probably like the odd Chrome extension and stuff as well. So I wanted to ask you specifically about productivity. how do you stay productive, organized, any extensions, tools, tips you can give the listeners? So I'm old school. I like a pen and paper. I like to have a notebook and I write down things in a notebook.
54:00Otherwise I forget them. And just by writing them down, it kind of commits them to memory. I haven't really moved on to e-ink yet. I've been seeing some of the e-ink things and go, Ooh, that looks nice. But I like a notebook because I like the tactile feel of paper and I like a nice pen. That's just personal preference. I like the freeform nature. It's difficult to hack a book as well, isn't it? It is. It is. And I still remember in aeroplanes where they used to tell you to turn off all your electronics when the fastened seatbelt line came on. And of course, I could just keep my notebook out and just keep working.
54:32I could keep doing things. I like that. I like the instant recall. Okay. So last question then, Quentin. Looking back now, you're a very experienced guy. I'm sure you've got lots of your career left to go. but just looking back now, your 21-year-old self, what advice would you give to that guy? What would you say to that person right now? So my 21-year-old self, I would tell that person to buy stock in Apple and Google. Buy as much stock in Apple and Google and Facebook. And NVIDIA as well, by the way. Well, NVIDIA is relatively late. NVIDIA is relatively late into the game. But yeah, Apple, Google, and various other companies would have, well, I probably wouldn't be having this podcast.
55:09I'd be retired on an island somewhere. It's like I'd have told people to invest in cryptocurrency back then. Are you a Bitcoin guy? No, not really. Really? Oh, I am. Too late to the party. Late? Really? I think it's still early days, isn't it? Well, I saw it as a scam back then. And to be fair, I mean, there was someone I used to know who was always going on about, like I was going on about running a lot, who was always going on about how much cryptocurrency he had. And a friend of mine went, how much did he have? Because he disappeared completely. And we kind of like went, my God, if he's still got three quarters of that, there's a reason why he doesn't talk to us anymore.
55:44That's why he doesn't bother with us anymore. I think he's got different friends in a different category. So, yeah. So I'd say that. I mean, but if I was talking to a 21-year-old right now, I would say look at some of the what look to be obsolete technologies. Yeah. And get interested in them. Go and have a look at some of the things like AS400s. And don't specialize completely, but have a working knowledge. because that, when you get the technology and everyone's in cloud at the moment, and there's a lot of money in cloud, but there's also a lot of people in cloud. You take something AS400, there's a lot of money in AS400, at least there was going to be even more money in AS400, and there's not many people in there.
56:19So if you can get into certain technologies, certain niche technologies, and remember, you're not going to be able to make your career on something like AS400. Other legacy technologies are available, but you will be able to, say, identify the sets of legacy technologies which companies will still depend upon. And that's the point. Work out which ones people depend upon and say, actually, I'm still going to do my cool cloud stuff because that's going to be, I want to have that. But I'm also going to pick a couple of legacy ones and I'm going to have more than a working knowledge. And you'll then become indispensable.
56:50If you can become a security person who can look at that technology, you'll suddenly discover you're a pen tester. Well, people will have regulatory reasons to have to do that. And the only person they can call is you. Yeah, sure. Well, there you go, kids. learn COBOL. Learn about mainframes. I think that's brilliant advice. You can pick them up on eBay. Yeah, yeah. It's really good advice, Quentin. I think it was Elon Musk or someone said on a podcast before that half the world's banking system is held up by mainframes and COBOL code. And it's probably true. It's all legacy tech and no CTO wants to touch it.
57:29With an increasingly smaller portion of people who are able to maintain it. Exactly. So be one of those people. We need a new generation of AS400 experts. But yeah, no, that's really interesting. I love that. Thank you so much for your time. It's been a pleasure. Thanks for coming on the Tech Leaders podcast. Thank you for having me.
57:53Wow, that was amazing. What a great guy. Quentin, so interesting, so knowledgeable. I could have I could have spoken to him for a lot longer. It was fascinating to hear about Canon, such a global brand, to hear his version of the timeline of cybersecurity and the journey cybersecurity has been on to where we are now and what's really keeping CISOs up at night, so to speak. A couple of things stood out. I have to mention the idea or the advice to young people about learning legacy tech to be relevant. I thought it was a brilliant idea. if you're a young coder or not necessarily young, just a new coder or someone getting into the IT space.
58:34I mean, if you had a side project learning about IBM mainframes and AS400 or what have you, that would be just an absolutely brilliant addition to your portfolio then, which I think could be the difference between you getting a job and not getting a job because half the world is being held together by this legacy tech stuff and it ain't going away anytime soon. So I thought that was just absolute gold. But the other thing that stood out for me was Quentin's concern around identity theft and especially imitation and how AI will impact that. We talked about AI just taking that up a notch. We just need to start taking our online identity a lot more serious.
59:16Look, there was so much more I could bring up. But yeah, the interview speaks for itself. I hope you enjoyed it. if you found this episode valuable and thought-provoking we would really appreciate it if you could quite simply click the subscribe button and possibly even leave a review this helps us to spread the word and reach a wider audience so that we can make a bigger impact and bring you the best guest possible thank you so much for downloading
59:51Thank you.
From the publisher
If you’re looking for a snapshot of the latest in cybersecurity, then you’re in luck! In this week’s episode, Gareth is joined by Quentyn Taylor, Senior Director Information Security and Global Response at Canon, where the pair zoom in on all-things cyber safety.
Being an established expert in the information security space, Quentyn rode the ‘dot com’ wave of the early noughties before ultimately landing a role in the photography manufacturing powerhouse that is Canon. From here, he’s become a renowned figure in the cyber space, not only from his seat in the office but also from his gadget-tastic YouTube channel (which you can check out here: (4) Quentyn Taylor - YouTube).
The conversation covers everything from the Dark Web and security scandals to AI and moving away from ‘the age of reality’. Quentyn gives us a behind-the-scenes glimpse into what really keeps CISO’s up at night and what we can all do to ensure we stay safe in this ever-changing online space.
Time stamps
- What does good leadership mean to Quentyn? (03:45)
- Surviving the Dot Com Bubble Burst (11:10)
- The evolution of cybersecurity threats (15:30)
- Deep diving into the Dark Web (19:00)
- What are CISO’s worried about today? (22:22)
- The SolarWinds scandal (24:40)
- What type of company is Canon? (27:38)
- How Canon is utilising AI (29:50)
- Can AI be hacked? (36:40)
- How to keep your online passwords safe (50:25)
- Quentyn’s advice to his 21-year-old self (54:40)
