Better cybersecurity starts with honesty and accountability | Nadya Bartol

Visit to get our entire library of TED Talks, transcripts, translations, personalized talk recommendations and more.

In this practical talk, cybersecurity expert Nadya Bartol brings this crucial topic out into the open, lifting the shame around tech mistakes and offering creative ways to celebrate and reward good cybersecurity habits at work and beyond.

The TED Talks channel features the best talks and performances from the TED Conference, where the world's leading thinkers and doers give the talk of their lives in 18 minutes (or less). Look for talks on Technology, Entertainment and Design — plus science, business, global issues, the arts and more. You're welcome to link to or embed these videos, forward them to others and share these ideas with people you know.

Become a TED Member:
Follow TED on Twitter:
Like TED on Facebook:
Subscribe to our channel:

TED's videos may be used for non-commercial purposes under a Creative Commons License, Attribution–Non Commercial–No Derivatives (or the CC BY – NC – ND 4.0 International) and in accordance with our TED Talks Usage Policy ( ). For more information on using TED for commercial purposes (e.g. employee learning, in a film or online course), please submit a Media Request at

15 Comments on Better cybersecurity starts with honesty and accountability | Nadya Bartol

  1. Well I know one infosec rule. On a firewall you first block everything. Then open only what you need be it port 80, 443, 25, 110 etc. And for years utilities have done nothing but pay lip service to information security. Part of it is the people, part the systems, and so on like an onion. And yes I’ve scanned my IOT devices And realize that it can be hacked.

    And InfoSec and Cybersecurity – it includes both networks, systems and people. One of my proudest moments was one company I worked at. My users were educated on the dangers. So one day I get a call from the controller that she got an email from the CEO to pay $30,000 but found it odd. When the email headers were examined I noted they took the company domain name and modifiied a new domain by one letter. I realized how they got the info – the company proudly put their upper leadership up on the web. Explained this was how the crime was committed. So that saved $30,000.

    • These are the default firewall settings for any cloud VPS providers. Firewall setup is a golden rule but it’s not a silver bullet.

  2. Accountability is always the issue as there’s always exceptions. “Oh, they’re just a security guard/exec/manager/temp. Who cares?” But it is never discussed that all it takes is one click to put that crack in the security of the entire company network.

    I both applaud and disagree with the comparison to Safety within the Energy industry. That is based on Compliance, a baseline for everyone to share. However, Security is rarely adequate at a Compliance level. It is the bare minimum, but actual security is everything above.

    That seems to always be the struggle is showing that baselines are the minimum effort, but truth be told, that’s probably more than many companies are doing or could be doing with their resources.

    I can’t tell you the number of interviews I had where *I* asked them (company) what they did beyond Compliance to be secure… and would get blank stares back. 🙁

  3. Until cyber security gets integrated into the programming toolkits we use, insecure code will be the norm. It’s just too complex and time consuming to get it all right inline, which means it’s audited after the fact and then it’s fixed. Maybe.

  4. Corporations have to agree to fund these multi-faceted solutions – implementation and continued maintenance. Separately, and in general, centralization and automation can help to remove many intentional (insider threat too) and unintentional negative events.

  5. At 2:15, not sure that is entirely accurate. All dates are in 2017 in US format mm/dd; 03/07 CVE-2017-5638 patch released, 03/08 US CERT contacts Equifax, 03/09 Equifax internally requests patching within 48 hours, 03/10 first evidence of exploitation discovered.

  6. What I find appalling is having cyber security “experts” and people in leadership positions with no real background in tech or tech security.

  7. Better cybersecurity starts and ends with the wall plug. This is a joke, and not a joke. Because the power grid is the largest isolated and secure network on the planet. And had Tesla’s patents not been stolen and hidden, the power grid itself would have been our communication network long before the Military created a more profitable alternative.

    If anyone was serious about creating a secure and protected network, developing protocols for information service over the powergrid itself is the answer. Both by creating a new architecture, and through physical network isolation. We could be running a fully-secure powergrid network isolated from the internet and used to share sensitive data. You know, like all the personal and financial information the news keeps telling stories about being “EXPOSED”.

    The military solution has always been network isolation. And the power grid reaches everywhere already with physical wires. The internet is not a secure network connection, no matter how much money you spend on security, how razor sharp the cutting edge you are sitting on is. Attaching to the internet is not secure. Attaching to the gridNet, would be. We’d simply have to use a fully encrypted network protocol and protect the technology behind it from being stolen. Then China wouldn’t be able to steal and repurpose every patent developed here, Russia couldn’t attack sensitive infrastructure systems, and the world would have a model for how to secure data that is affordable, and as secure as physically possible.

    And bonus, the speed and latency of this kind of network would lend itself to blockchain and lockstep technologies. Forcing the financial institutions who batch purchase investments in the spare milliseconds between transactions to steal all the real profit at the point of sale to wait in line with Joe blow and his sister Karen. You wouldn’t be able to cheat a financial system in this way with an isolated and metered lockstep protocol. Every packet would have to wait in line.

    Any more of the world’s problems you want me to immediately solve with a single easy and affordable solution?

  8. Great talk, great topic,

    but curses to the camera-person who thought that side-camera was a good idea!
    Why, TED, WHY ???

  9. Bottom line is that if given enough resources and time anyone specifically targeted can get hacked. But at least you can protect yourself against the less targeted attacks by doing the basics right.

Leave a Reply

Your email address will not be published.


*


Shares
Share This