The Cyber Business Podcast
Guest Introduction: Nico Stein [https://www.linkedin.com/in/nico-stein-34041711/] is the SVP of IT and Operations at Signal Financial Federal Credit Union [https://www.signalfinancialfcu.org/], a community-based, member-owned credit union headquartered in Maryland with branches across the DC and Virginia region. With more than 12 years at Signal Financial, he oversees everything from laptops to cybersecurity to the financial core, and has built a reputation in the credit union community for open knowledge sharing at a time when most financial institutions treat peer conversations as competitive risk. An Object First ACE and Cisco Champion, Nico brings a practitioner's skepticism and a community-first mindset to the challenges of defending a regulated financial institution on a budget that does not scale with the threat. Here's a Glimpse of What You'll Learn * Why Nico shifted Signal Financial's entire security posture from hoping ransomware would not happen to assuming it will and building around recovery speed * How he made the case to a non-technical board using a single Washington Post headline framing that unlocked the budget he needed * Why backups being the first target of every ransomware attack changes how you have to think about immutable storage strategy * How AI-powered voice printing and stress detection in the call center is Signal Financial's frontline defense against voice phishing attacks targeting elderly members * Why agentic AI and MCP servers are Nico's personal security nightmare and what he believes most organizations are not yet ready for * Why the credit union peer network gives small and mid-sized financial institutions an intelligence advantage that banks structurally cannot replicate * Why AI should be evaluated by the problem it solves rather than the token count someone purchased In This Episode Nico opens with a framing that cuts through a lot of the performative confidence that shows up in security conversations: he told his board directly that he cannot stop ransomware, and if he had figured out how to do that, he would be on an island drinking margaritas because he had found the holy grail. What he could do was shift Signal Financial's entire security posture from hope to assumption, build around recovery speed, and make the case for immutable storage by asking leadership to picture the alternative on the front page of the Washington Post. That framing worked. The immutable storage solution has been in place for more than a year, the RTOs and RPOs are being met, and Nico talks about it with the kind of quiet confidence that comes from having actually built something rather than having sold someone on a strategy. He also offers a considered acknowledgment that backups are now the first target of every ransomware attack, giving credit to the organizations who thought they had it handled and missed one thing. It is a more generous framing than most and more useful for the organizations listening. The financial services threat section of this episode is where things get specific in a way that is rare on this podcast. Nico's members include elderly individuals who are being targeted with AI-generated voice cloning attacks where the caller sounds exactly like their grandson. That is not a network perimeter problem. It is a social engineering problem that lives at the intersection of AI capability and human vulnerability, and it is happening in Signal Financial's call center right now. His response is equally specific: voice printing systems that verify caller identity and detect stress indicators that may suggest someone is being coerced or lying when withdrawing large sums. He is direct that this is a vendor-dependent solution and that the vendors are starting to build the right tools. He is equally direct that the threat is outpacing awareness among members who have no reason to know that a call from their grandchild might not be their grandchild. The back half of this episode is where Nico pulls back from the operational and gets into the questions that the security conversation usually avoids. Agentic AI and MCP servers are his stated personal nightmare from a security perspective, not because he cannot block them but because utilizing them securely in a way that keeps data where it belongs is a problem nobody has fully solved yet. His AI evaluation framework is the same one that has shown up across the best episodes in this season: start with the problem, ask whether AI actually solves it, and resist the pressure to spend tokens because someone bought a million of them and wants to see adoption numbers. What makes Nico's version land differently is the context he brings it from: a regulated financial institution with limited resources, a peer network that functions as a genuine intelligence advantage over banks, and 12 years of scar tissue that makes him appropriately skeptical of anything arriving in a vendor PowerPoint with AI in the title. The Cyber Business Podcast Brought to you by Cyberlynx [https://cyberlynx.com/]
224 episodes
Comments
0Be the first to comment
Sign up now and become a member of the The Cyber Business Podcast community!