Cybercrime Magazine Podcast · Cybercrime Magazine

Culture Shapes Security. Building Empowerment. Deneen DeFiore, United Airlines.

March 30, 2026·11 min·1 clip
Why does United Airlines' CISO believe cybersecurity is a journey with no destination?
1. Cybercrime Magazine interviews United Airlines CISO Deneen DeFiore and OutThink CEO Flavius Plessou at RSA 2026 in San Francisco about building positive security culture in enterprise organizations. 2. Flavius Plessou is CEO and founder of OutThink, described as an AI-powered human risk management platform; Deneen DeFiore is CISO at United Airlines with responsibility for security across pilots, flight attendants, engineers, developers, and corporate staff. 3. The episode's core thesis is that culture amplifies security controls — deficiencies get worse, strong controls get stronger — making culture the hidden strategic lever in security outcomes. 4. Plessou identifies two emerging attributes of effective security culture: engagement (making security personally relevant) and psychological safety (creating an environment where people can admit mistakes without punishment). 5. DeFiore argues that people respond to what happens to them daily, not to policies — and that bridging cybersecurity to employees' existing safety mindset is the key to behavioral change at scale. 6. DeFiore notes that her workforce includes pilots, flight attendants, engineers, and developers who each experience risk very differently; the goal is not to make everyone a security expert but to build 'resilient digital workers' appropriate to each role. 7. Plessou explains that generic security awareness training kills engagement because employees immediately dismiss content that doesn't apply to their work context. 8. He calculates that a 20,000-person enterprise, accounting for variations in attitudes, behaviors, roles, work factors, and organizational policies, would require over 100,000 variants of the same security message to achieve genuine personalization — a volume impossible to produce manually. 9. Plessou argues this personalization gap can only be solved with AI-driven technology that adapts security communications to the individual, making training land rather than get clicked through. 10. On CISO leadership practices, Plessou shares advice from a customer CISO named Darren: never say 'no' to the business; instead say 'here's a better way' that delivers the outcome without blocking innovation or slowing operations. 11. A second example from Plessou: a CISO in the natural resources sector who presents exclusively positive security news in board meetings — never bad news — and builds stronger executive relationships as a result. 12. Plessou frames this positive-framing approach as a deliberate counter to the standard CISO practice of leading with risk dashboards, red indicators, and severe vulnerabilities. 13. DeFiore's success metric for security culture: when employees proactively raise their hand to flag a process that seems insecure, without a CISO pointing it out — 'democratizing security across operations.' 14. Plessou builds on this with the 'network of human senses' concept: hundreds of thousands of empowered United Airlines employees, when trusted and given a clear 'why,' form a distributed threat-detection network that spots anomalies before technical controls can. 15. Both guests express optimism about AI-influenced threats, arguing that people are 'incredibly good at adapting' when the rationale is clear and they feel trusted. 16. DeFiore notes that AI-era threats include highly realistic scenarios, so resilience and response processes matter more than achieving perfect phishing-test scores. 17. The conversation is a three-way panel hosted by Amanda Glassner of Cybercrime Magazine, with questions alternating between the two guests. 18. The tone is collaborative and optimistic, with both guests reinforcing each other's points and drawing on real-world examples from their organizations and consulting work. 19. CISOs, security awareness professionals, and HR leaders trying to improve employee security behavior in large enterprises would find this episode most relevant. 20. Listeners seeking technical security controls, incident response frameworks, or vendor-specific product guidance would find this episode too focused on culture and leadership to meet their needs.
Listen to the show on