Meet Our Guest

Kate Oliver

Information Security Officer at Skipton Building Society

Kate Oliver has spent more than 20 years at Skipton Building Society, joining as a mortgage underwriter support before moving through business analysis and into information security around nine years ago. Her route into the profession was not a technical one, and she credits that as a strength rather than a gap. Today she leads a team whose remit spans third party risk, penetration testing, policies and technology risk, with security awareness training across the whole society as her particular focus.

ONE-PAGER

The Human Firewall Explained with Skipton Building Society

Best Practices & Lessons Learned

Most organisations know that people sit at the centre of their security risk. Far fewer have worked out how to turn that into a genuine advantage.

This one-page summary distils Kate Oliver’s experience of building a security awareness programme inside a heavily regulated financial services organisation into four practical lessons any team can act on.

Download One-Pager

Episode Transcript

Adam Myers:

Hello and welcome to our podcast, Tales from the CyberLab. My name’s Adam Myers and I’m sales director here at CyberLab and I’ll be your host for today. Joining me is Kate Oliver from Skipton Building Society. Welcome Kate.

Kate Oliver:

Thank you. Hi, everyone.

Adam Myers:

So we’re going to be discussing today the human firewall, and Kate is here to talk us through all the stuff that you’re doing at Skipton. But before that, can you just tell us a little bit about your role and what you do on a day-to-day basis?

Kate Oliver:

Sure. I’m an Information Security Specialist and my team has quite a varied role. We cross over the whole spectrum of security related work that needs to be done for the Building Society. So we cover third party risk, pen testing, policies, tech risk. And my baby is the security awareness training that is offered to everyone across the whole building society. And it plays a really key part of what the team delivers. So there’s an expectation that we do that every, well, every day really, but every year certainly people have to sign up to certain training. And then we also carry out ad hoc stuff that happens all through the year. And it’s really interesting stuff because it doesn’t just affect people at work.

Adam Myers:

Yeah. Amazing. And you’ve worked at Skipton, let me get this right. You’ve top trumped me here. So I’ve worked at Chess and CyberLab now for what, close to 16, but you are, I think –

Kate Oliver:

20 years.

Adam Myers:

Whoa. There we go. Look at that.

Kate Oliver:

Skipton stole my youth. I started off as a mortgage underwriter support. So my route into information security wasn’t through tech at all. I saw a job advertised about nine years ago in information security and I though, “That sounds interesting.” And that’s how I got involved. And then it was the people aspect that really appealed to me. So I kind of found my niche.

Adam Myers:

Amazing. And we’ve worked together as a sort of Skipton and CyberLab for close to 10 years now, which is a big celebration milestone for us. And we work very closely and I think 20 years, that is very impressive. So yeah, congratulations. So the first topic, so Kate, we hear that people are the weakest link in cyber security. Is that fair or is there a better way for us to think about this?

Kate Oliver:

I think it’s really unfair because we’re all human. People who are trained and talk about this stuff every day are still susceptible to risk. And the best analogy I ever heard was from Becky Holmes who wrote Keanu Reeves is not in love with you. And she said, “People who are victims of scams like this, we have a tendency to victim blame. So if anyone falls for a cyber security scam, we use that terminology, you fell for it.” But we don’t say you fell for a burglary. So why are we differentiating? It’s a crime and it’s something that happens to a human. It’s not their fault. These fraudsters and scammers and hackers are really good at what they do. So to blame the human is really unfair.

Adam Myers:

And I think that comes from the culture within the business of how you position that, isn’t it? So there’s ways that you can position that if somebody does fall for an attack or whatnot. How do you do that? Because that’s a key part of getting this right. The people were then willing to maybe share if they’ve made a mistake as opposed to hide it because that’s a big thing that happens within organisations if the culture’s wrong.

Kate Oliver:

Yeah, 100%. And it’s something we’ve worked really hard on focusing on the positive. And the positive is, wow, this many percent of people reported a phishing attack, a phishing test, whatever that might be. We work really hard to not talk about blaming and failures and falling for something. We focus on, okay, you clicked on something, let’s use it as an opportunity to learn. And people who report things, we celebrate that. So we have a winner’s Wednesday, for example, where we look at the leaderboard and we dish out some random prizes to people. And so it creates a culture of it’s a bit of fun, it’s important stuff, but we put a lighthearted spin on it and introduce a bit of gamification as well, which the people who get involved in that and the competition it creates is incredible. But we work really hard to not blame people. We want our doors to be open. We want people to come to security. We want people to ask our advice. And it always warms my heart when someone comes and says, “I want to do this thing. Can you help me?” Because it means that they’ve though about security first, which is a huge improvement in how things were when I first got involved in information security, I think.

Adam Myers:

And when we were talking in the build us this, you said that the goal isn’t zero mistakes. That always kind of stuck and resonated with me and it’s catching mistakes before they become incidents. Is that how you see things?

Kate Oliver:

Definitely, because we are human and I could get an email tomorrow that I click on because it was something that resonated with me at that moment in time. Nobody is perfect. Scammers are really good at what they do. They are relentless. They do this as a full-time job and they create scams which are convincing. So people who become a victim have something going on in their lives and we’re never going to get away from that. So zero mistakes is really never going to happen in anything. So we have to have the doors open and help people to spot. Actually, I think something wasn’t quite right there, so I need to ask for some help rather than stick my head in the sand. So incident reporting is really important.

Adam Myers:

And I think we’re going to mention AI, obviously throughout this, it wouldn’t be a podcast on cyber security without that. But the branding now of how they can launch these phishing simulation campaigns and then they can target you, they just look so real. And it’s like on brand, the colour looks right, it’s using your logos. They can do it with such speed now so the volume’s out there. So again, it’s inevitable at some point you’re going to fall for this because it’s gone up a notch hasn’t it in terms of the attackers and the tools they have.

Kate Oliver:

Do you remember the old email that came out and it said, “I’m a prince of some far flung country and I want to share my $10 million with you.” Everybody thought that was a bit suspect, but now you get an email and it looks like it’s from your manager talking about a file that you shared and who hasn’t done that in a working week. So we have to have some uncomfortable conversations where people say, “When you’re doing testing, that’s a bit close to the mark, but the reality is that’s what criminals, fraudsters do. They will launch attacks based on what’s topical, on something affecting the company. So we can’t shy away from those tests. We have to make sure that what we’re. We’re training our people to be resilient, so we have to make sure that it’s realistic as well.

Adam Myers:

Yeah. And the tools that you use, are you measuring it sort of here’s the benchmark where we’re at the start of this simulation and then it’s working towards improving those scores. Is that how you’re working? Is it seeing gains and improvements that people are not following them as much so that you can measure it?

Kate Oliver:

Yeah. We do measure the click rate. That’s a traditional metric that most people will want to see, but I like to focus on the reporting rate. And certainly over the last year we’ve seen huge improvements in the number of people who’ve reported things that they think are suspicious. So there are lots of different metrics that you can provide, but you hope that you’ll see an improvement and overall that the risk to the company will reduce.

Adam Myers:

So I guess this podcast today, it’s the viewpoint of a customer and what you are doing and how other customers who are listening to this can learn from such a huge organisation such as Skipton. So again, really good insight there, Kate. Moving into our next topic, what does effective security training look like in practise beyond this annual tick box course, which I think a lot of people get a little bit of fatigue with in today’s world where it’s just the same thing over and over. What does that look like now?

Kate Oliver:

Again, we’ve worked hard in trying to reduce our annual online learning. We have to do it. We can’t get away from that. We have to have some measure of being able to prove to our regulators. We’re a really regulated industry. We have to prove that we are training our people. But one thing I was really passionate about is making sure that that wasn’t just death by PowerPoint and the traditional online learning that someone can just click through and answer a quiz at the end and job done for a year, don’t have to think about it for a year. So we’ve moved to more bite-size learning modules, little videos, quizzes, games. We put out articles to the whole society every week and it’d be something that’s in the news. It doesn’t necessarily have to be work related. It is something that’s topical that’s affected people in their home lives. And I think once you hook people into that, you teach them how to behave more securely at home. They’re going to behave more securely at work. We make things easy for them by giving them a phish alert button. They can report stuff really easily. But the training, we’re the Netflix generation, aren’t we, people haven’t got that attention span to sit through a 30-minute PowerPoint slide presentation that you read it and then you forget what that was next week when the actual situation comes up. So we try and do stuff more frequently, more topically, and hopefully more interestingly.

Adam Myers:

Yeah. So we’ve done things like the live hack, haven’t we? Which we did. We did that in the Bailey, the big screen that I talk about all the time that I presented on what is probably the largest TV screen I’ve ever been in. I don’t know.

Kate Oliver:

It’s like a football stadium isn’t it!

Adam Myers:

It is, yeah. So anyway, that was a career highlight I’d say so far in terms of presenting other than this podcast. So there’s lots of things that you are doing there that just a little bit different like the live hack we did. Do you see value in stuff like that?

Kate Oliver:

Absolutely. We try and bring it to life because you can tell someone something till you’re blue in the face, but if you show them it, it has a completely different effect. So the live hack that we did showed someone what would happen if somebody was trying to take over your machine and that really hit home because you hear about these things and people hear about them in the news. These attacks happen all the time, but until you can actually think, oh, I see how it actually works, it’s hard to grab someone’s attention with that. So we do these sort of events all the time and working with partners like you is really useful because you bring such expertise and an outside voice because it’s all very well me. I do the trading all the time and if it’s coming from me all the time, then it can get a bit stale. So we bring in outside voices who are experts in their fields and people love that. So we’ve used our partners really quite a lot over the last year. We’ve got relationships with the police, the Yorkshire and Humber Regional Organised Crime Unit are great at presenting stuff for us. And when you tell colleagues that there’s someone coming from a different organisation, that creates a bit of excitement. So we work on these events a lot to make sure that we are bringing a whole spectrum of subjects to people.

Adam Myers:

And also, I guess you’re always trying to appeal to different personas within the business as well, aren’t you? So there’s people that maybe are techies potentially, so they find maybe some of the normal training a little bit, probably getting a little bit bored, let’s say. They work in every day. So it’s trying to stimulate those people to how that might help them, I guess. Like career development and a little bit more maybe we go down the techie rabbit hole a touch more and we’ve worked hard to do that as well.

Kate Oliver:

Exactly. Everyone’s got a different learning style. Everyone’s got their different favourite subjects, so we have to appeal to the masses. So we bring in a broad range of ways to do that. So it might be someone loves a PowerPoint, so we’ll give them a PowerPoint, but someone who needs a two-minute video, we’ll give them that as well. So you have to cater for everybody and it’s really hard to keep people’s attention, so you just have to keep things fresh. So we’re always trying new things and it’s always evolving. I’m not saying we’ve got it right, but you just have to keep trying. And it’s exciting because you can use all sorts of different media and people to bring the subjects to life.

Adam Myers:

Yeah. So we’ve done some of the deep fake stuff, which works well, hasn’t it? So how we even use it in our business in terms of a deep fake video of a member of your team, it was very real. We obviously can pull the sounds so it sounds like a person. Has stuff like that helped you?

Kate Oliver:

Very much because when you see, I’m thinking of Martin Lewis, he’s always talking about things like that that happened to him. And when people see that, it makes them realise that actually I couldn’t tell the difference between that video of Martin Lewis and the real Martin Lewis. And when you do it for someone at work, it’s even more powerful because you can look at somebody on a video and say, oh, I can tell that that’s not quite real. But if it’s presented as a phone call and it’s a deep fake of your finance director, how can we all know for sure that we’d be able to tell the difference? So just bringing these things to people’s attention I think is really important because we talk about this stuff all the time, but normal people don’t. So it’s important to tell them what’s out there and what could potentially happen.

Adam Myers:

Listening to this episode, one thing becomes really clear. Security awareness training for your people is paramount for good security posture. And that’s why here at CyberLab using our hack risk platform, we have created security awareness training to help mitigate security risks. And if you feel like that’s a first step you might already be doing with other vendors and suppliers, maybe check out some of our tabletop exercises in terms of how to stress test the board and ensure that the C-suite is working as best as they can as well. And with that, back to the episode. So into our next topic. So how is Skipton’s information security team structured to support this kind of people focus work?

Kate Oliver:

So we have various teams within our security department as a whole, and that includes tech risk and resilience. So it’s really important that we have this whole holistic view of the building society, the risks that are potentially important to the building society. And we therefore have teams which look at change that goes on across the business, working to make security a first thought when someone is running a project. That’s been a real big change in the way the team is structured over the last couple of years. There are now specialists who work with the teams who are delivering change. They have also introduced security champions, which has been a huge improvement because those people are sitting doing the day jobs and they are really technical people at the moment. We’ll expand it to people who aren’t in the technical roles, but at the minute it’s really worked well because they are in the technical teams. My team is information security, so we look at the GRC side of things. So we’re looking at policies and training and third party risk. So we are looking at the BAU side of things almost alongside the project side. And then we have an operational security team as well, so they’re monitoring the threats and the alerts that come in. And then the operational resilience team are looking at how our business would deal with an incident and also how our third parties would deal with incidents as well. So it kind of brings everything together that could possibly be security related under one team and therefore collaboration is really key and it cuts out all the middlemen and the conversations that could take ages over email we’re all sitting together.

Adam Myers:

Because it is quite a team, isn’t it? When you obviously go into the office, you see the size of security at Skipton is a huge part of the people that you have there, isn’t it? When you see the floor of people, it’s a big organisation and how you link that all together is difficult, isn’t it? But you’ve got so many teams, it just feels like the regulations are heavily regulated. There’s just so many things you have to moving cogs with securities to keep that right, isn’t it?

Kate Oliver:

That’s it. And to keep people at the heart of that is also a challenge. So again, that’s improved in the time since I’ve joined the team. We didn’t really know that we had, if we had a problem, but now human risk is the buzzword. The human firewall is the buzzword. We want to make sure that people are aware of their responsibilities when it comes to security and are capable of reporting something. They know what to do if they find something. So our team has really been at the forefront of being able to share those messages. And the key thing that we’ve had is we’ve had support from the executive. So if you haven’t got support from the top, then it’s a losing battle because you’re pushing upwards all the time. But if the support is coming from the top, then it makes everybody’s job much easier. And it really is seen as an important part of security, which is huge and has turned around how my job has worked over the last few years.

Adam Myers:

Yeah, because we work very closely with a lot of IT teams and security teams to take the message to the board and present the risk and try and mitigate risk. And then it goes into our budget conversations and how we’re trying to prevent that. So that often is the challenge for a lot of maybe our listeners and IT professionals, how do we take this message to the board? And I think what we’ve done with you guys is a perfect example of how you work very closely with the board and senior stakeholders to share and talk around the challenges and what you see on a day-to-day basis.

Kate Oliver:

And when the board are engaged and ask for training and ask for information, you know that you’ve won the battle because they’re really involved and interested and keen to solve the issues that we might have. And some of them look at it from a personal perspective of actually I’m very visible. How can I protect myself? How can I make sure that I’m doing the right thing? To those who are working closely with their teams across the organisation and say, actually, can you give us a bit of extra support here? And that’s brilliant. When it’s coming from the top, it just makes the job so much easier. And when you came in and you did some training for our board, that went down so well because we talked about current topics, other organisations who’d had attacks and how it affected them. And it just meant that it brought it to life to these people who are, they are very visible, they’re very senior. And if there was going to be an attack at Skipton, these people could very likely be targeted. So when they ask for training and we’re able to do that and bring an external partner in to deliver that, it’s really key in what we do and was really well received as

Adam Myers:

Well. Yeah, good. So if any of our listeners are interested in that board engagement, those assessments where we can review and mitigate risk with the board, reach out is a service that we do offer. But I think lots of engagement buy-in opens up conversation very quickly and it just helps people like yourself within the organisation just get that conversation going, I guess, doesn’t it?

Kate Oliver:

Yeah. And it is all about the conversation. And that’s what I really strive to make sure that there are conversations happening all the time, whether it’s just a little article that I put out on our internal intranet to say, “Hey, there’s been a scam that’s affected a hotel booking website.” Or if there’s an Easter egg scam that’s going around, I’ll share that with people and the board see that as well and they appreciate it and they then raise conversations with their teams, which is great.

Adam Myers:

Yeah. And bringing to life those stories, isn’t it a little bit like we see in the news a lot. I think there’s lots of articles that are shared now. There’s lots of books that are written now. Netflix has got different sort of things going on. So it’s almost become a different narrative now where we can share that information, it’s quick to access and then get that out to the teams. And that seems like what you do quite well.

Kate Oliver:

It’s become normal, which is scary, but also quite helpful in what we do because if people don’t hear about it, they won’t engage with it. But when you see things on Netflix like the Tinder Swindler and programmes like that, people watch it, talk about it at their desks and that’s great. And then we reference it in training that we do. And if people then have something to talk about rather than it being a distant subject that has no impact on them at all, it brings it to life and it makes it real. And it’s very rare that I do a training session where there isn’t somebody in there who says, “Oh, that’s happened to me or that’s happened to someone in my family.” So that’s what I mean, it’s become normal, which it’s horrible, but it’s the way the world is. So we have to make people aware of that and make them resilient. Whenever I do training, I always think, would my mother-in-law understand this because she’s the person who’s going to pick up the phone and ask me a question and be scared of something. So we don’t want to scare people, but we want to introduce that healthy level of suspicion.

Adam Myers:

Yeah. And keeping it simple. It’s what we try and do, but we’re in a very complex industry and it’s easy to create buzzwords or shortened three letters acronyms that we just think no one understands what it means, but we play along and we nod. But it is about simplifying the culture, isn’t it, of cybersecurity and making it a language that people understand. And I feel like that’s starting to change. Again, it goes back to the culture within a business. Do you try and do that to keep it simple? Is that something you do? I

Kate Oliver:

Do that by default because I’m not a technical person. So there are lots of technical people in my teams, and if they ever have something that they want to talk about, I’ll ask them to run it by me because if I understand it, then they’re going to be able to get their message across to another team that’s not technical. Like I said, that was my route into the role. I am a people person rather than a technology person. So I’m not playing the game when I say I don’t know what that means. I actually don’t. So it’s been a great learning curve and I’ve obviously picked up some technical skills along the way, but I would always be that translator. And whenever I prepare some training, I always think about will the teams who are answering the phones, will they understand this? Will the HR teams understand this? Rather than the technical teams, we will do technical training, but that’s very specific. But the general foundations of what we have to do has to be available for everybody.

Adam Myers:

Yeah. And there is a role. I think I try and do this. It’s like translate the message a little bit. And there is a role and that’s people skills, that’s soft skills. So people looking at, I don’t know, careers in cyber, there is ways into that where you don’t always have to be a techie, for example. We have a good understanding of it, but the skill working very much for you, you are a people person, you’re that easy to get on with, they’re chatty, I love it. But that is a skill and an art in itself, isn’t it, of how you translate the message into a business? And that’s a soft skill is a key asset, I think, when you’re trying to get the message out

Kate Oliver:

There. Definitely. In previous roles in Skipton, I was a business analyst and taking requirements and translating them into something that a developer could build something from was key. So that was a really good foundation for me and the skills that I had to be able to say, I need somebody to understand this technical concept and how it could affect them in their life. I like to say I’m a bridge over troubled water because sometimes that’s what we’ve got to do. We have to take something that might be uncomfortable, it might be scary, but we have to bring that to people and put it in a way that’s accessible.

Adam Myers:

I feel like we need to just plug the song in there at this moment in time. So Olly, who works in our marketing team, I don’t know, it feels like that’s a natural segue and transition there. So moving into topic number four, are attackers getting better at fooling people and does that change how training needs to evolve?

Kate Oliver:

Definitely. We mentioned AI before. AI has lowered the bar for scammers. It has meant that someone can construct a phishing email in seconds and it hasn’t got any spelling mistakes in it and it looks good and it looks convincing. So we can’t get away from the fact that AI has affected everybody. It has affected the technical aspects of cybersecurity as well because vulnerabilities are being exploited more quickly than ever before. So it means that we just have to be constantly on the ball. We’ve got to be ahead of the game. We’ve got to keep up our learning. That’s really key that we don’t know it all. What we know today is different tomorrow. So we have to make sure that we’re constantly evolving what we do and our teams have got to evolve and the messages that we share have got to evolve as well.

Adam Myers:

Yeah. Good. Nice. Topic number six. So for an organisation that knows people are the biggest exposure, where should they start in building this culture that we’ve talked about?

Kate Oliver:

I think it’s to start at the top. You have to have the board, the executive buying in because if they don’t, your message is, you’re like a voice in the wilderness. It has to be an agreement that everybody understands the importance of this and that it’s everybody’s responsibility and that time and resources dedicated to this because that’s a huge challenge as well. I know lots of other organisations who we speak to who people are doing this sort of off the side of their desk. It’s seen as a job that needs to be done because we have to tick a box, but it’s not always given the gravitas that it needs. And when we say that people are the first line of defence, we really mean that. We can have all the technical controls in the world, but if people don’t know what their responsibility is, then it becomes a really losing battle,

Adam Myers:

Really. Yeah. It’s an interesting take. You’re right. And I think as regulation becomes stricter, we’re going to find that for businesses to operate and work together in the future as AI takes full steam and technology evolves. We’re in this transition, I think, where compliance and regulation are going to drive a lot of this, where this will become more that you need to have this in place. Things like cyber essentials, it’s a starting point, but it’s going to become where you need to have that to trade and have a business and operate. I guess that’s where we’re heading it.

Kate Oliver:

And I think every certification is a good thing, but if your culture’s not right, then the certifications become pointless. You have to have people who understand the risk and who understand why they’re important in the role to make those certifications be worth the paper that they’re written on. It’s got to start at a fundamental level in the organisation that everybody has a role to play and everybody sees the importance of security. So it’s not just a, we’ll add it on at the end or, oh no, security has stopped this project going ahead. We don’t want to be seen as the blockers.

Adam Myers:

So our last episode was secure by design and starting with security at the heart. You talk about projects. Again, just reframing how maybe you undertake a project. And at the core, if you can start with security and work from there, you know that what you’re putting in place from the start is secure.

Kate Oliver:

Yeah, exactly. And we want people to come to us before they introduce a change or buy a product or change a process. We want them to have that conversation and we want to be the trusted partners, not the red tape guys at the end who’ve stopped me doing something. And I think that’s something that’s changed certainly at Skipton over the last few years that we are now seen as more accessible, the doors open, we produce things more clearly like the policies and standards are easier for people to understand so they know what they’ve got to do as part of their job because everything has been clarified and laid out for them and we’re there to support in the background. We’re not there to say yes or no. We’re there to highlight risks and to make sure that people know what their obligations are. So that’s been an interesting journey that’s taken time, but started because the leadership realised that this was that important.

Adam Myers:

Yeah. And I’m just going to ask you a quick question. We’ve obviously worked together as organisations for what, close to 10 years. What is it like working with CyberLab as a customer?

Kate Oliver:

Honestly, you have offered us so much support. It’s been great. And you’ve offered things that I wouldn’t necessarily have thought about. So obviously all the work that’s taken place over the last 10 years has been great, but our relationship has only really been over the last year or so where we’ve talked about certainly a lot of security training options and you’ve offered us solutions to problems I didn’t even know that we had. So it’s been really, really eye-opening and you’ve been really easy to work with and you’ve offered some really creative solutions that have gone down really well among the organisations. So yeah, thank you. Long may it continue.

Adam Myers:

Yeah, it makes me very proud to hear that. And thank you very much for coming on as a guest today. And I ask this question to every single person on the podcast. If there’s one top tip that you can say for our listeners on what they should take from this episode, what would it be, your final statement of what you think they should take from this?

Kate Oliver:

I think the thing that I say to everybody in every training session, every piece of content that I put out is that security is everybody’s job. Everybody has to believe that. Otherwise, all the training in the world doesn’t matter. If someone thinks it doesn’t apply to them, it doesn’t matter. So security is everyone’s job, but the battle is less because we have people who understand that this impacts them in their home lives. So like I said before, if you can get the hook into people of making them see that security isn’t just a work thing, not just about my email or it’s not just about logging into a system, it’s about everything in your life, then it’s much easier to get people to behave in the right way. So security is everyone’s responsibility. I think that’s my tagline.

Adam Myers:

There is. Yeah, that’s it. We’ll plug that in. I love it. So thank you so much, Kate, for joining us. You have been an excellent guest and I’m sure our audience would’ve enjoyed today’s episode. And that concludes this episode of Tales from the Cyber Lab. Join us next time for a brand new episode. Until then, stay secure.