Skip to main content
Right of Boom
January 30, 2025

CyberCall – June 15th, 2020

Guests

Andrew Morgan

Video Transcript

All right, we're live. Welcome everybody. And it's another week of the cyber call. We've got six in outta seven weeks so far, um, because of Memorial Day. But other than that, great to have everybody here. Wes, welcome Gary, welcome Chris, welcome. Hello. Hello. That's gonna start catching on. Okay. Little bit about today's agenda because Chris, uh, I, I, I, it's, uh, shocking, but you're working some major IR cases. You wanna give us a tat of maybe a 32nd purview? Is anything new?

Um, are people going after more data than ever? What's, what's going on? And, and tell us a little Bit. Well, it's a case, yeah, it's a case of where we have, um, data being stolen, but the ransom. But we, we didn't need any decryption because they could restore from backups. But because there was such an, a large amount of data being stolen, there's just a tremendous amount of pressure from a forensics perspective, and there's a tremendous amount of pressure from a legal perspective.

The issue though, is because we are not decrypting, uh, most of the artifacts that we would use to determine what the attacker's access and exfiltrated are encrypted. So we have to look at other data elements. And so most of the time, and in this particular case, it's a healthcare related entity, uh, the unfortunate side is most likely they will just have to assume that all of their patient data was compromised and go that route.

So it's one of these things where you think if you got great backup, which we've been talking about a long time, which are still super important, but if these guys get ahold of a lion's share of the data, um, it, it may even be more painful than decrypting because if, at least if you decrypted, you'd have more forensics information. But it is what it is. Wow. So real quick, if you could go backwards, knew this was gonna happen. Sure. Is there one thing that they would've done differently?

Uh, not had a folder on their server called everyone. Okay. Everyone write that down? No, there, there there's another quick, there's another quick lesson to learn here. And this is more of a user experience deal. So what the attackers do is they provide some proof that they've hacked. So they've taken the data.

So in this particular case, they provided some snapshots of some directories, and they produced a couple of, of forms that had some patient information, just two patients worth of information. So we're like, where did they get that that form from? Because that form is in the EMR.

Well, after they found out what the attackers revealed, they went on an expedition and they found that they had a facility that was basically going in the EMR printing out the forms to A PDF and sticking them on the server, which is a big no-no, but no one had ever talked to the facility or knew they were doing this to even address it with them. So again, it's a, it's a training garrettson, you know, somewhat of a training issue, but it's know your stuff and know those capabilities.

And sometimes I guarantee in that EMR, there probably is some record of that stuff being printed that someone could have looked at and said, now why is this one facility printing out a bunch of these forms where no other facilities are doing that? So maybe that's a little bit better. Hindsight Thousand, give it back to data. Right. Every single time it gets back to where is the data? Who, how is accessed. Right. Exactly.

But Chris, it brings up a really good point about that, those types of rights. Because again, now that you have people that could be working from home, well, I don't know, I could just print this to my home share. Correct. In theory. In theory, yeah. There's just a number of things that can be done since it's even you got a question whether or not that's even something that should be done, is it, you know, on an exception only basis, you're exactly right. So yeah. Yeah.

A lot of lessons to be learned here. I mean, and, and you know, they actually have a great MSP, they actually had a lot of security in place. Um, and so, um, and again, they had backups, uh, but it's still way, I think this one was one where it was a, it occurred over months, so it wasn't, they just hopped in one day and jumped in and got in. And I think there was some, some preparation and some due diligence and some discovery, and then they did it. Yeah.

And it was all through a, um, it was a vulnerability of a VPN appliance. Wow. Well, let me set the stage for this week. Thanks for sharing that, Chris. Um, we have a really awesome event coming up that, again, I'll share it out with everybody. Um, we are doing a two day event, three hours a day for Cisco. Um, and most of the sessions are being done by the awesome guys and on, on the, on this show.

Um, so Chris, you and Wes are gonna be running your tabletop exercise on that event, and not in the, in the fullest sense of the two hour one that we're gonna be doing with Gary. Maybe we'll go three hours with Gary now, but to, you know, can you share about it what the key takeaways, um, will be and how for, if these folks are gonna attend, which I hope they do, how can they get the most out of it? Um, you know, being part of this session, and I will put up the link for everybody momentarily.

Good, Christopher? I mean, yeah, the overall objective, again, is for and I to help you improve your understanding and ability to execute in the face of an incident. And that incident could be something specifically related just to one of your clients, to multiple clients or obviously to you. Um, we know that MSPs are still being attacked. Uh, some of you may have got some updates from a particular RMM provider out there that, uh, told you to patch something quickly.

Uh, so that could be, uh, another use case there for being prepared for an incident. But, uh, again, it is to just be better prepared. And even if you've been to our tabletops in person or remotely, uh, this is gonna be updated content with some of the stuff that we've been seeing over the last few months. You know, who is it? You know, you want your role players, your key role players to be involved in this, if possible.

Uh, I know it's tough to take everybody away from their desk, uh, especially in these times, but it's crucial, you know, it's very crucial for those people to get a good idea of what we're talking about and kinda live inside the fire, per se, uh, to know how to fight that fire. So that's what we're gonna really be focusing on, and, and we're gonna do our best to take what we've done in the physical lo, you know, the physical type events and bring that to you virtually.

Uh, but, you know, I don't know. Wes, you want to add some? Yeah, A couple things I wanna add. So, first of all, with regards, I do just wanna give some telemetry back. So at Perch, we are seeing active, uh, scanning for the new vulnerability that ConnectWise has. I think every MSP we've talked to so far is aware and has taken precautions. So that's really good news. But we are seeing a lot of scanning. We are seeing a lot of 200 okays coming back from the scanning attempts.

So just know that that, um, threat vector is alive and well and bad guys are well aware of it. So it is a serious threat. You need to take it seriously. You need to follow connect wise's, um, recommendations here. It's a big deal. Um, but yeah, to go back to Chris, what you're talking about. So couple things super quickly. One is, if you've done the tabletop before, this is still good for you because we're going to change it a little bit as we always do.

But also, it's a great way to say, how do we do last time? And how do we, how would we, how we adjusted and changed and matured this time? Second thing is, if you've attended one of our tabletops, even like what we did at V Cyber Con and you liked it, uh, bring the rest of your team, schedule your entire team, do a lunch and learn around it. Plan around the whole event. Or if you really brave, bring some key clients onto that call as well and just have them participate and work with you.

But use our tabletop test offensively for your own purposes internally and externally in your msp. That's great advice, Wes, about bringing you a key account or to about, if that's something that you really wanted to do with them, man, what a great way to ingratiate them. Gary, what do you think of something like that?

And, and, you know, Yeah, and I'll tell you what it almost kind of leads into the more you do, this leads into the session that Wes and I are doing right around packaging and pricing, because each of these weeks we talk about more and more things you have to do.

And Wes, I was thinking about it like, if you are a, um, you know, a mid-market enterprise company, the way that you've solved this is you've gone to your board, or you've gone to the company and you've asked for more headcount, and there's one person in cybersecurity, there's more to do. Then there's two, then there's three, then there's four.

Well, if you're an MSP for all of these things, including incident response, you have to go to 30 or 40 customers and figure out what to do so that you can have the resources and staff. So I, I kind of equate it to what has to happen in an IT department is what has to happen in an MSP. And we've only had short little pieces to kind of talk around that. But we're, uh, Wes and I are gonna talk through it for an hour, uh, in our session. So Yeah, we're gonna come to that in just a little bit.

Chris, anything before, I know you got a big ca that this case is going, and I appreciate you jumping on, and I know you gotta jump off and get on some phone calls and probably negotiate with the bad guys. But, uh, anything else before we let you run? No, just on this vulnerability deal, I mean, obviously, obviously sorry about, obviously patching is key.

Uh, but the other thing is, is we gotta think about the bigger picture is how can you be better prepared, um, you know, going forward with this? Because this one, you're completely dependent upon the patch to protect you unless you've done certain things like lock your lock, your, lock it down to, um, you know, ips and, and, and I know a number of MSPs are, are looking into that, and I'm hoping or put a web application firewall in front, which is no trivial task.

So, um, anyway, but this was, um, you know, we hinted at it earlier, uh, MFA did you no good in this one, uh, because this bypassed all that and created accounts and went to town. So, and they worked really fast. And so there's even, you know, there's even people that were able to detect it, but by the time it, and they detected it quickly, but it was too late still, so the damage was done.

I think the only fortunate side of this thing, uh, and this is my opinion, is that this seemed to be more of a smaller group to do this. I think if someone like reil, which does soden or the, you know, these guys we're dealing with a lot now, net Walker, if those guys got a hold of it, it would've been a freaking World War MSP nightmare. So, um, maybe that's the only positive way of looking at this situation right now. Well, again, thank you Chris, for coming on.

Um, we are really looking forward. So everybody, I put the link, uh, the partner success, that's cisco.com, you'll see it in the chat, please share it. Um, invite peers, invite friends, uh, as Wes said, invite customers. Um, and, uh, theirs is on the 17th, I believe, at 3:00 PM So Chris, I'm gonna bring you over to the audience. I'm gonna bring up Mike Ard. And, uh, again, appreciate your time. While you're doing that, Wes, you know, Chris brought up a good point.

Just it doesn't matter what vendor you use for RMM, when, when, uh, when a vulnerability one, you're really at their mercy to make sure it's been identified and then the, the patch. Um, and it sounds like the alternatives are a little onerous, right? To protect yourself in front of that for MSPs, this is like an inherent risk today, right? Of being an MS P that you're gonna have to find some balance with. Yeah. Yeah. It is an inherent risk.

And so this is where I do think it's so important to think through a layered security approach and what we're doing, right? So we should always make the assumption, if, if we're operating under the, the, the assumption that I have a single layer, that if it fails, I'm hosed. That's really, really scary and dangerous. So you always need, always need to be thinking through, Hey, how do I truly, how do I have a layered approach to handle all these things?

If my RMM gets compromised, what can I circle and surround that? It may not be able to eliminate the threat, but what if I can delay it by a day or two days, and then if I can delay it, how can I know that something's happened so I can take action? Right? We've gotta have that defensive mindset, truly thinking through. Gary, it's an excellent point. Excellent.

Well, speaking of vulnerability management and risk assessment, we got CISO of Marco, Mike Beard, and Mike, maybe, I know you're gonna give us a purview into what you're gonna be talking about, uh, at the Cisco event coming up here. But just question, I mean, do, do you, with, you know, you guys have 35, 40,000 endpoints out there.

Do you think about, well, maybe in the case of putting these web application firewalls or, you know, buy IP address that maybe in the, um, regulated and high risk companies that you deal with to say, Hey, it's gonna be more expensive. Are you open to us putting in this additional layer? Uh, is that something that you start to consider these days? Yeah, absolutely. Um, I, I, I think anymore that's an essential component, right?

You look at any government entity, they've got mandated requirements, banking, financial, healthcare, those are all pretty common ones. But I tell you what, the risk profile extends beyond that. I, I think that's, uh, you know, listening to Chris talk on these over, over time, and then I know, you know, we've talked to him in other groups as well, manufacturing companies, and there's other lines of business, right?

I think it's having a real conversation with customers and, um, to be upfront, this is one of the things that, uh, Carl and I are gonna focus on at the tap of this event on Thursday, is proper risk identification and knowing what that risk is for your customers. And to West's point, you do have to have a layered approach. And that layer, those layers are different for different businesses, right?

If I look at coming out of covid, we're gonna have a ton of people that continue to work from home or work remotely. Data's moved out to them, they have a different risk profile than a traditional bank will still continue to have, right? Data's in different spots. People are doing different things. My solution stack needs to be able to align to those different use cases. Um, so yeah, in some cases that's additional products, that's additional things.

In other cases, it's really changing the implementation process for existing products as well. Um, yeah, and that, that, uh, I, I guess that that kind of ties into, um, to be upfront, when I look at risk treatment options, again, what am I looking at? I'm looking at how do I mitigate, or how do I avoid something, right? How do I accept it in some cases, et cetera. But it's having those conversations and knowing what the business owner's thinking, right?

All too often we've, we've been in a competitive spot where we're taking something away, typically due to a ransomware or other security type event, and the CEO gets involved in it, but, well, I never knew this was an actual risk to my business, right? And that's the, the conversations that we as MSPs have, we need to make sure that we're clear on what those risks actually are from a business owner perspective.

They don't care about all 300 different things that we're looking at in an assessment. They care about what are the top three to five risks to my business? What are you doing to protect me for those couple of things, right? If you can solve those problems and actually convince me that you can solve those problems, you nailed it.

And that's the, I think that's the thing that we want to be able to look for, is we have to be able to identify those risks correctly, and we have to be able to treat those risks. Um, and a lot of that comes back to proper vulnerability assessing and just really proper assessing a time of onboard as well as a continual improvement process throughout that. Um, you know, I look at vulnerabilities. Wes and I spoke last week at, uh, at a different event.

And, um, it was kind of a different audience, right? We had a lot of executives on that and, and really block and tackle type things. Really the fundamentals, right? We hear Belichick talk about fundamentals all the time. That's what makes a winning team kind of a deal. And, and unfortunately, all too often we see block and tackle things missed. Heck, that was one of the things I fixed in my own organization, is block and tackle has gotta be done, right?

I think that's, we like to sell products and that's good, but we can't forget the basics. I think that's the other thing. So we wanna make sure that we identify those properly as well. And I just dropped a link in the chat that goes out to us search it. It's the top 10 vulnerabilities exploited, and it was published in May. So it's quite current. Unfortunately, if you look at that list, many of the things on there are several years, if not more than five years old, right?

We're looking at the top 10 vulnerabilities, and a couple of 'em are seriously seven years old kind of a deal. And that's the, that shows the effectiveness of our patching or really the ineffectiveness. And as Chris just said, Hey, gotta patch those vulnerabilities, right?

I look at, you know, if we go into an environment we see WannaCry is still open, or Petra or some of the other things out there, and, and there's open vulnerabilities and they haven't been patched, that's the easiest takeaway from another IT organization out there. 'cause you can show that it doesn't look like they were doing their diligence, right? So we want you as MSPs to be successful in that. And that really, there, there's a process to it and I think it, it's changing the conversation.

So with that, I'll, I'll open that up. I'll, I'll, uh, Gary Westley, I'm sure you guys have some comments. I've seen, seen some reaction. Yeah. One, one thing I wanna mention, Dave said this in the chat, I don't wanna point to this, Dave, you are exactly right. And this, this is a big deal is too often we find ourselves as MSPs having conversations with whoever the administrative contact is.

Maybe it's an embedded IT person or someone that just has ownership in the org and that can cause problems. If you're not in your QBR and just your regular conversations, making sure you're talking to the business owner, the data owner, uh, that is a really important thing to do.

It doesn't have to be necessarily a weekly or even monthly cadence, but you need to have those conversations regularly and often because their thought process and perspective is totally different than who you may be working with. That's a great takeaway, Dave. I just wanted to point that out because it's a very salient point. Gary, did you have something I saw you writing down and Yeah. Yeah. Well, two things. Yeah. Uh, go to my process.

com if you want to learn how to build those relationships from A-V-C-I-O standpoint. But the point I, I wrote down when Mike was talking, listen, I deal with so many MSPs. We talk about blocking and tackling. You know, they depend on their centralized services, their person who runs the tool stack, and they're usually the least trained, the least managed, the least accountable person in a small MSP.

So it's almost like you could say they're like, create, could create more risk than they, than they solved, right? And so they're out there buying other, you know, security stack tools, but to Mike's point, they don't have the basic process in place for the current tool stack starting with their RMM, uh, that they have. And so you can't, that's your foundation. So I'm really glad, Mike, you brought that point up today. 'cause I see this in a large majority of MSPs that we deal with.

Yeah, absolutely. Person's in a closet somewhere down that has access to that stuff and they're worried about all the tickets that are on the board today and getting 'em all closed. You know, I, Gary, I'm not sure how much you can go into this. And I know, Mike, you gotta run, but it just makes me chuckle because Gary, you talking to your CPA about data and you know, and you found out some of your data and, and what layered approach he should be taking or risk losing a customer. Yeah. Yeah.

He was going to, uh, use, uh, he was gonna change Uber to use the MSP that I was part of, but he was complaining 'cause they were a thousand dollars a month more. And I'm like, a thousand dollars a month. I'm like, just charge me an extra 10 bucks all your clients. I'm like, you have my data. I'm like, this is, you either signed a proposal or I gotta find a new accounting company. Awesome. Sorry. Go, go ahead there. Um, Mike, thanks. I know you've gotta jump to another meeting.

Thank you so much. We look forward to seeing you, uh, this week as well. Again, um, I think you guys, do you guys go Thursday? If I, if I recall, Thursday, Thursday afternoon? I think we, we close it Out. Okay. Fantastic. Grab The beverage and come join. Great. Thank you Mike. I we're gonna bring up Kyle and um, we will continue here. Uh, so one second here. Okay. The safe behind him, I was saying that, uh, he keeps his data actually in that safe.

Hey, Hey Gary, while we're waiting, so I asked a question in chat if people would be interested in what A-V-C-I-O vcso is all about, how they're built, and we're getting a bunch of yeses, so, uh, might be good for us to sync up on a future cyber call and just kind of talk. But at a high level, can you give us just a little bit in, in the world of Gary Pico, what a vcso is all about or A-V-C-I-O? Yeah. And so you've kind of led to it, Wes, um, and Covid has uncovered this, right?

All these small businesses are having to make a lot of decisions. They're changing how they do work. They're downsizing, upsizing, and the MSPs that are dealing with points of contact, they're dealing with the administrator, dealing with the person who deals with the users, and they don't have a strong strategic relationship with the people that are actually controlling the budget and the strategic plan. They're struggling right now.

I had one, uh, MSP say they found out that their customer went back, uh, to their office because they saw a spike in ticket counts. I'm like, that's how you are finding this out. Like, so it's really having an ongoing process of establishing, you know, and, and again, a lot of these decisions around security really get made as a business decision first. That's what you keep talking about Wes, right? Is that you have to explain the impact on the business.

And if you don't have a process to be dealing with on a regular basis, we used to say quarterly, we don't call 'em Q Bs, we call 'em, um, you know, like the strategic sessions. But right now you gotta be doing 'em at least virtually once a month because things are changing, you know, so quickly with everything. But security's at the top of that list, Wes. Yeah. And Gary, do you feel, just curious, do you feel that maybe expanding the footprint of who those conversations are with?

Because I mean, you know, unfortunately there's gonna be a lot of people let go. It's not a hope, but maybe you were dealing with the controller as an example and that was the conversation, you know, that you would normally have. And this company decided to outsource hypothetically their accounting to a virtual CFO and now all of a sudden there's really no relationship. And this, uh, virtual accounting firm says, you know what? You really should use this MSP over here.

So here's a quick rule of thumb. You should who whatever that team is that that does other planning for them, you should be, that's who you should have access to. In other words, they have the person who runs shop, you know, the VP of ops, they have, you know, the finance person. They need to have the IT person, which should be you in these cases. Yeah. Does that make Sense? Absolutely. Absolutely. Smaller companies, you can sometimes get it done with just the owner, right?

But as the companies get larger, you need to be thinking about it as you should your strategic function. So you should have the same access to the team. Alright, it sounds like you got tornadoes about to come through there with Kyle. Alright, Gary West, talk to me a little talk. Gary, Kyle, Gary West talk you, you alluded to this, Gary, you are in Wes' session on packaging and pricing.

You know, I've known you for a incredibly amount long time, but from the beginning of true methods and, you know, packaging and pricing still to this day, this minute packs a house more than any other, uh, topic. And now, you know, we're at the point where we almost are forced to whether we, you know, are, are including these in our, you know, you know, bury these cogs or, but every, you know, week we're talking about a different layer of security.

Uh, Kyle's talked about, you know, at some point, you know, we can't do everything. We can't have zero trust across the board. But what are some of the key things that you guys are gonna be talking about and, and takeaways and how can people be prepared for this session? Uh, you know, getting ready for that.

So We'll talk about some base, but really Wes spending time with you right, over this past year has really helped expand the way that I look at it, the way that you relate it to having to go to a board, right? And how you talk to them to get budget. The only difference is in addition to the conversation with the customer, we just have to figure out right, how it fits into our unit of measure so we know what to charge, right? To do it.

And so we'll talk about both sides of it, but you know, you're as good as anybody at understanding that psychology with the customer. Yeah, I mean, you're right, Gary and I, I think every MSP wants to know how does it fit in the margins? How do I position it? How do I sell it? How, how do I make sure that someone understands? 'cause we don't have this fear. I think if we're honest with ourselves, if I go back to the, well again, that client, they're gonna say no.

And when they say no, what am I gonna do about it? And I'm gonna tuck my tail and run and I failed forever and I'm shouldering a bunch of new risks and it scares me. It keeps me up at night. How do we get through all of that and actually discuss and talk through, uh, changes that need to happen? How do we get and how do we make it work? And by the way, how can we make more money doing it too? Those things that all need to happen. So we'll talk about that in that session.

It could be really good. Or you're making a choice between making a dollar or keeping your customer secure. You don't want to have to make that choice. Yeah. Excellent. Looking forward to that one. Kyle, you have, uh, two sessions. Let's talk about the first one with Wes and the second one with Patrick fer at Cisco umbrella. But the first one with Wes, um, man, that was really well received in the v cyber con event packed house. Um, you guys talked about the cyber defense matrix.

Uh, the title def uh, it, it actually kicks off the entire event on Wednesday. Demystifying vendor cyber speak. Take us, take us through that a little bit, if you would. So obviously operate between gale winds here behind me. But with that said, uh, Wes and I get a chance every now and again to, without putting a, a rant on more or less call things like they are a spade a spade. And sometimes you gotta do that with cybersecurity speak, whether that's hype, you know, fear, uncertainty and doubt.

And sometimes just saying, here's some simple ways to solve a problem that don't have to be so darn complex that we make it so we will, we'll reintroduce cyber defense matrix. I think Wes and I got some ideas to build on that. And more or less kind of progressive as you're looking at personas, as you're selling cybersecurity, as you're trying to figure out what goes into your stack, what's a repeatable way to do it. So I'm pretty stoked. Uh, what what about you, Wes?

Hey, All I want to know is we have a lot of words in the world of cybersecurity. We've got hundreds of people on this call. Will you chat, use the chat and tell us your favorite cybersecurity buzzword. Go. I wanna see 'em come through and while they come through, uh, yeah, Kyle, you're right. We're just gonna talk about clearing those clouds. How do I see through and understand what I need, what's true, what's not? How do I sort through the buzzword? Uh, oh, you already took all of them.

AI next. Uh, but yes, please send us your favorite buzzword because I wanna see them and I wanna laugh. Uh, but that's all I wanted to say, Kyle. It's gonna be an awesome session. Probably one of my favorites that I get to do. Uh, and it's always a lot of fun. I had to take care of the low hanging fruit, right? You know, that that's the easiest ones to take care of. Ooh. Nor new normal people are definitely stealing some good ones.

Um, you know, then the next piece right of building this off of is, alright, so we talk about a, a playbook or a recipe book. That's great. We decide it for ourselves. Now how do we articulate that for an another audience, right? A non-technical audience. So a conversation with Patrick Coleford out of, uh, the Cisco umbrella team.

What we did is I spent, uh, a couple of weeks lurking on the dark web with my team, trying to find where people take these actual tools for sale and then watching how does it go for, from development to for sale to an actual marketing campaign to the point that they're compromising you and showing that full circle. And what's neat about this presentation is it's not just about what's on the dark web. It's showing you how their marketing is getting great.

It's showing you how this is being done at a level that really does resemble a professional business. And the most important piece is when you see these things for sale, the whole purpose of our conversation is gonna be to say, you know, when someone does this, this particular piece of this, whatever that is, here's how it relates to that previous piece of the stack that Wes and I talked about.

So it's kind of pulling those two topics together of one, how do you build the stack and how do you demystify some of this nonsense? And two, how do you show your clients in real world? So I'm pretty excited about that, uh, especially 'cause we've given this an update, um, that it'll be up to date at the moment of our presentation. So, um, truly breaking there. Awesome. Excellent, excellent.

Alright, Wes Okay, if I move you over, I'm gonna go find Kevin Lancaster and we'll bring you back at the end. Alright, I think I got Kevin here. So as we're bringing this up, I'm getting ready to just share a, a little link, uh, in regards to, you know, talking about hackers outpacing the marketing that some of, you know, SMBs even do, uh, with this weekend full of ransomware. I I gotta see a whole lot of it.

Unfortunately, some of it's beautiful looking, uh, you know, their own graphic designers. Yeah. Does it feel like they're evolving faster? Right? Well, they are, right? They're evolving faster than MSPs. There's definitely a tighter feedback loop. We're noticing the, the, the pace that they can pivot and just iterate faster to hone their models faster than defense, for sure. Gary. So, you know, that's, uh, that keeps me up a little bit, The infinite game, isn't it, Kyle?

It is, it is the infinite game. And you know, all of us as, as business owners are having to pivot to that as well to really try to see if we could keep on pace or even outpace them. Yeah. There's Kevin, Kevin. Hey Guys. Thank you so much for joining us. Sure. Sorry, I had technical, uh, difficulties taking my mask off. Sorry about that. Well, at least you're using a mask, you know, here in Florida. It's, it's became a, a highly contested topic.

Um, but, uh, that's a whole nother, uh, set of, uh, conversations we could have. Kevin, you are coming up with a, uh, kind of a, um, a, a, a a series if you will Mm-Hmm. And this is gonna be the first of it. Tell us a little bit about what Pasa is and, um, you know, why should we be concerned? And, and then how do we convey this all to, um, back down to our clients? Because at the, uh, end of the day, it's one of the things right?

That, you know, we're all talking about is this continued layered approach. But it doesn't, it doesn't seem to end of, of the criticality of information out there. No, it, it's never ending as you guys were talking about, right? Yeah. So, you know, this, this concept of pass, it was basically just something off the cuff, uh, uh, on the spur of the moment, I guess, uh, over the weekend.

So, so one of the things we've been focused on for a while now, right, is, is the credential based exploits are very basic common exploits, right? And so we see all the volumes of data out there. Sometimes we run into Kyle out in the dark web, shake hands, and uh, you know, and then we, we go, uh, in different directions.

But, um, you know, so there's, there's compromise, data compromise, email address and passwords and all that stuff and, and stuff that we just talk about, uh, day in and day out. But, you know, one of the things that I think people overlook is the volume of data that's out there on them, out just on the, the general surface web, right? So you could do yourself a favor and I'll, I'll post a couple of these things. I have like a couple, you know, basic slides.

I'll, I'll, I'll find a way to share with the group. But you can do yourself a favor and go out to the one of the 200, 250, uh, you know, basically data aggregator sites out there. So your, your true people searches, your spokeo's, your, um, one of the ones I was actually, uh, hanging out on this morning was, uh, family tree now.com. So everybody on the call, I, I'll, you know, maybe I'll do, uh, one or two, uh, links in here.

But go out there and just put your first name, last name, and your city and state, or just your state, find yourself and, you know, see how much data is actually out there on you. And this data that's out there, uh, is publicly available data. So it's data from, you know, your marriage records, divorce records, uh, you know, birth records, uh, all kinds of public, uh, records, uh, criminal, uh, records, traffic stops, you know, stuff that's out there that, you know, people take for granted.

How much is just out there surfaced by state and federal agencies, right? And you can get the, in various forms, the folks down in Florida probably, you know, Florida's the most interesting when it comes to, you know, just basic things like the mug mug shock databases that are, that are that circulate through, uh, Florida. But so you look out and you see, you know, first pass what, you know, data's out there publicly.

You can find your known associates, your relatives, your previous addresses, your phone numbers, previous email addresses, uh, because these guys have figured out a way to aggregate the public data. And they're also founding ways to aggregate that data and compare it against, uh, brokerage data. So data that they may get from, uh, folks that would have a, a rewards program that they want to sell their data to a data broker. 'cause it's valuable, right?

They've aggregated data on millions of, uh, individuals. They could sell it. And the data brokers go out there, run their big data algorithms, start comparing, and pretty soon you've got just about everything you need to exploit somebody. And two or three clicks, let alone what you find out on tour. And, and the actual password you have. You have relatives, child, you know, child's names, spouse information, uh, grandparents, the street you grew up on.

You could probably within maybe five minutes find, you know, 15 to the top, uh, 20 most commonly, you know, use password reset, you know, questions or answers the most commonly used password reset questions. So, so it's, it's kind of one of these things where you, we do a ton in the, the very ultra high tech side of cybersecurity, right? Stuff you guys were talking about RMMs and, and kind of the layered approach just in security in general.

But you always, we always off, I often focus just on kind of the, the basic exploits, the, the, the path of least resistance. You know, the things that are just right in front of us, day in and day out. If you just Google your name, you know, or you hop on some of these sites, you just, you'd be blown away. And so with these sites, right? You, it, it's probably, you know, five minutes to, to exploit based on the data that's out there.

So one of the things we wanna do is over the next, uh, couple of months, maybe it's a, a summertime project, is to bring in, uh, or bring attention to not just these sites, but how this data is, is, is exchanged, how it's brokered and how it can be used against somebody. And how really to start, you know, just understanding your, your attack area, right? Your, your, your surface area.

So that's, that's what we're up to here, is trying to figure out a way to get this out to the masses and just at minimum use it as a, as a education tool to start to have these, you know, these deeper, broader security conversations. Kevin, I'm gonna take this to, um, what I typically don't, uh, in, in this, and it's not about it being an infomercial. Well, can you talk about ID agent what it's doing? And then the reason I wanna bring it up is because it has to do with layering.

We're talk at the end of the day, this, this has gotta be something that MSPs can understand how to, you know, operationalize package price. So, mm-hmm. Because I don't know of another one besides your organization. Um, but can, can you walk us through that, how MSPs are using it? What are they going to find? How are they positioning it and Yeah, Right. Yeah. So, so first thing with, uh, one of our platforms called Dark Web id, right? The, the goal of that tool is to bring awareness.

So it allows an MSP to go out, search for a customer domain, search for a customer email address, and bring back the most current results or hits that we find out on tour, out on the dark. So it'll bring back their email address, uh, a partially masked, uh, password when we found it. And, and if we can attribute it back to what, uh, breach it was or, or dataset it was, uh, involved in, we'll, we'll show that.

So we grew so fast in the channel because we, we did, we broke it down to the most, you know, basic common denominator. Here's your email address and password. It's personal, you know, you see it and you're like, oh, crap. You know, wow, I use that on, you know, 5, 6, 7, 15 different things, or a derivation of that across a hundred things that I log into, right? So that's kind of the first leg of the stool. The next leg was to, and take that data and start changing behavior, as we mentioned.

So start throwing in security awareness training, start throwing in phishing testing just to see, you know, how susceptible people were to these types of exploits, right? You're showing them, you're, you're hitting them on, you know, over the head and telling 'em, don't do this, but are they continuing to do this? And do, do they continue to fall for, you know, the, the most basic vulnerabilities? And then, and you know, what's coming in through your email.

Then, uh, the, the, the next or the, or the, the most current leg of the stool is, is at minimum, you know, adding in layered, uh, defenses or, or layered, um, controls. So throwing in multifactor or adding in multifactor, using password managers, using single sign-on eliminating passwords when, when you can, right? Taking out the, the human element, uh, of password usage or re usage.

And so that's, we, we've tried to, you know, basically, you know, correlate or, or bundle these solutions together and help MSPs paint, you know, paint a very simple message in, you know, minute or less, right? Here's your data, it's out there. This is why you're exposed, why you're vulnerable. Here's, here's who's potentially targeted. This is how you change your behavior. Stop doing the, the, the silly things that you're doing.

And then here's how you start layering in, you know, you know, security controls to prevent, you know, the most common, you know, most basic exploits. And so that's, that's what we've, we've been about, uh, uh, uh, since, uh, our inception. And, and just one quick note, it's hard to believe, you know, one of the things that really brought us, or or or propelled us in this industry was this OPM data breach, uh, back in 2015. And I just had a moment where I actually forgot about this.

I can't believe it's been five years, right? Five years. And, and that was, you know, the OPM breach was a, a credential that was compromised, uh, you know, through supply chain, uh, to lead to these, you know, devastating nation state hacks. And so, you know, five years have been on, you know, on the stand, you know, trying to change people's behavior, you know, and, and five years later, you know, unfortunately it's, it's just as bad as it was five years ago.

And you talk about, you know, Mike talked about blocking and tackling, like, doesn't get much more basic right than this. You have everything you wanted if someone has your password, you know, I was with my, uh, best friend last night since I was three years old, and we were laughing about security. He's in the IT business, your partners in my MSP, and we were saying like, we could breach each other. 'cause we know the answer to every question. Mm-Hmm. You know what I mean about each other.

But what you're saying is anyone can know the answer to every question. It's all out there, right? And the answers to most of the reset questions that are out there. Um, so that's a great point, you know, on those sides. And just again, talk about like, you have all the security and then people aren't even seeing what's out there on the dark web, like the most basic, right? The most basic, uh, piece of it. So It is, you know, whatever, you know, publication, you, you, you read into, right?

One of the, the most common exploits or, or, or methods is of exploits is, is walking through the front door, right? It's, it's the compromised credential, whether it's, you know, taking, uh, you know, taking some of this public data that's out there, you know, and, and, and, you know, scripting or, or guessing the password or, you know, finding something out on tour. Or even, not even just tour.

I mean, you know, there's plenty of surface sites out there, raid forms, you know, some of these sites that, that, you know, cataloged these, you know, data breaches and, you know, wouldn't recommend is it's not an endorsement, but, um, you know, that they're out there. I mean, you can find, you know, the, the more common ones, more, you know, repurposed or recycled dumps out there, uh, you know, quite easily up on, on the surface web as well.

So, yeah, that, that's, that's the thing that's probably most frustrating five years on from OPM and what we've done, you know, uh, in supporting in that project is that, you know, it's, uh, you know, behaviors haven't changed all that much, right? Yep. It's, it's, um, well, as Gary, Gary likes to say with, with people, but he is also said it with MSPs, uh, three things, right? Gary, uh, change Doing things. Selling, selling. Yeah. Too funny. Well, Kevin, thank you so much.

What, what might be the next iteration? You, you, you were mentioning a series, um, I know I'm putting you on the spot here a little bit, if you don't have it right now, that's very cool. But, uh, I think it'd be great to continue this, because again, it does come back to the blocking and tackling and, you know, if we can help, you know, the, the folks out here, um, Yeah, I, I think we would, what what we're gonna try to do is iterate on how this data is aggregated.

You know, take for example, you know, remember a couple years ago the big dust stuff with Facebook and Cambridge Analytica, right? I think at the time they said they had data on 200 million, you know, US citizens. And I think the data that they had, uh, in some cases they had the 5,000 different attributes of a person's personality, you know, based on the, the data they're able to harvest.

And so you think about how rich, I mean, these are, you know, as, as, uh, you know, probably some folks on the, uh, on the, the call or have, you know, I mean, it, these are, that's, it's very sophisticated, you know, data, uh, analysis or data targeting. And so if you've got commercial groups like Cambridge Analytica and, and hundreds and hundreds of others that are able to, you know, mass this data and normalize it and, um, and sell it, right? I mean, that's, it's a pretty serious thing.

So we'll kind of, we'll touch on, you know, how this stuff, uh, gets, uh, pulled together and, um, normalized and, and you know, used for, for, uh, e-commerce, but then also is used for, uh, exploit as well. Really Watch the Great hack yet tonight. Take time. It's fascinating. Yeah. Oh, the great hack. Yeah. Yeah, absolutely. Absolutely. Well, cool. Well, thanks for having me guys, this week. I really Great job. Look forward to having you back, um, either next week or the following.

Um, I'm gonna move you over to the audience pullback, Wes, and we'll close start to close things out. Thanks again, Kevin. You got It guys. Thanks. Alright. All right. Um, so as we do that, you know, I want to ask, you know, uh, you know, I've got some emails this week. They're like, why are you rushing, Gary? I know that, you know, you're like, the track record isn't so good.

And I've obviously went over this time, but, um, do you guys have a few minutes just to see if anybody has questions and, you know, pop them in there. And I'm bringing Wes back up, Hear with Wes or Kyle, hearing kind of what Kevin was going through with some of that basic, uh, stuff, you know, things that he's talking about. I would love to hear their, their point of view on that, you know, when he gets down to credentials. Yeah.

So, I mean, we can go blue in our face and yeah, Andrew, answering the question about time, uh, I can definitely make a little bit of time, especially folks, this is an interactive platform. There's no reason that people can't ask this stuff here. Highly encourage people do it. Um, my job at one time at NSA was called pre-positioning, and a lot of that was using open source intelligence to be able to figure out where do they live, what do the computers look like, what's the patch level?

We more or less built a tool Friday night when we discovered that that RMM was being exploited to figure out all of our partners who hadn't patched yet doing open source intelligence, some on the technology, some on the people you could imagine. I've even seen some vendors use this information for, I got a hit from somebody, uh, it was in Reddit the other day, where a vendor actually tracked somebody down and gave 'em a call at their house.

And they were a little creeped out about it, but this is 2020 and this is how some things happen now. So, you know, to me, I understand that risk, but I think most clients have no idea how easy this is, uh, you know, out there. Can, can I just say one thing real quick, Wes, and I want to hear your take.

I mean, Kyle, you were kind enough and, and I say this truly that you found stuff on the dark web for those of you that may not have heard this before, but you found and, and and prevented an MSP from being breached, right?

And then we found out, you found out it was an insider, ironically, and the, it was crazy, the the amount of money or lack thereof and the risk this person, you know, ended up convicted and any, but did, can you share a little bit about that story real quick, because It's not Yeah, I, I mean this is, we've obviously talked about the marketplace you talked to, you know, Wes kicked the thing off, I think the right way, just making sure it's saying like, look, you know, understanding, have somebody is A-V-C-I-O that can articulate this risk to somebody.

For instance, there's not a whole lot of people that understand that there is these marketplaces. For instance, um, we had one MSP that was on the dark web. We found their data being sold. They claimed this as an MSP and how lucrative of a target wa it was it $600 to get access to that MSP. Turns out after us and another vendor collaborated, uh, we ended up getting, uh, the FBI involved.

They did catch this person, arrested them, tracked the Bitcoin that was set up in the sting, and uh, that person is being prosecuted in the state of Georgia now. Um, what's crazier is we found two more cases where MSPs are sold on the dark web that we'll be showing, uh, in that, uh, Cisco presentation we mentioned. So, Excellent. Excellent. Wes, any Any, yeah, uh, you know what I wanna say, just to pitch Kevin A.

Little bit and what's so great about what Dark Web Ideas is doing, what Kevin's company is doing is it really shows to an end user that you are a target. And I think a lot of times decision makers do struggle with, am I a target? Is somebody going after me? And I, I can just tell you, showing that information is really valuable. Being able to, um, say, Hey, to Kyle's point, you are a target. You are being attacked. Somebody is looking at you, they know who you are.

You're a value to them is just the eye-opener that they need. And so I will say that that is a very valuable thing to do. Um, you know, we're seeing that with smart, you know, a lot of the smart MSPs are that are out there, and I'm sure many of you are like this on the call, very well aware of this is a threat vector. We want to see this. We want to be able to let our clients know, Hey, this is a big deal. We're prepared against it. Like just that visibility is really important.

And that's where I think reporting comes in. That's where I think being able to convey that message back to the user of value that comes across not just in the vendors we choose, but in the technology solutions and the wraparound of a security framework. That all comes back to reporting back to the end user. So they see the value and they understand it's really important. Excellent. Lemme answer with one question here. This is really good. David said it.

One frustration is when clients refuse to use multifactor because it's inconvenient. And listen, if that's the case, you have to take it upon yourself, David, to say, the only reason a business leader, I can see why a user would say that, or a manager, but someone who's responsible for the financial future of that company, because we have not explained to them the risk profile on that.

'cause if they understood it the way that we do, they wouldn't care if they were being making their people be little inconvenient, they would position it differently. So I think that's a great example of our responsibility. If you were the IT director, Wes, and you're, and, and, uh, someone at that company that you were responsible for said, well, it's a little inconvenient. You know, you would not come off of that, right? Yeah. Look, we had to go through this at the bank that I came from.

We dealt with this in the early days and multifactor was coming out and mandating this. We started with our business clients because those are the ones that had wire and aach H capabilities. But just mandating it, making sure that we had buy-in from the bank top to bottom. This is why we're doing it. This is why it's critical, is really, really important. And Gary, you know how we got that across? We had a client that had a breach and they had a breach on their end.

They had malware on their machine. The bad guy logged in from their machine, they used the email reset password. They, uh, actually successfully did a wire, uh, and it was all on them a hundred percent, right? And so we used that both internally to say, we're this is, and we're never dealing with this again. And then also we dealt with this with our clients saying, Hey, you don't want to be like this other client. I'm not gonna tell you their name, but lemme tell you what happened.

And they're like, yeah, wow. I didn't know that could happen. Yes, it could happen. So, uh, yeah, totally agree. And and that's something we've gotta, um, make sure that we, we, we stand fast and firm on those things. And by the way, last thing I'll say with SSO and saml, it's becoming easier and easier for multifactor to be something that happens in the background.

So when you set all of that up inside of Azure ad, as long as you have vendors and partners that support that, and you need to demand it, it actually becomes easier for your clients, both for onboarding and offboarding. Uh, I'm telling you, when perch, when we have vendors that we support that, uh, we can, we can enable SSO for, I mean, it's, it's easy. You're like, I didn't even have to authenticate. It just worked. Yeah. It's, it's, it's becoming very easy. Yeah.

And from a sales technique perspective, Gary, just like your, your thoughts on this, you know, per Dave's thing, I mean, and, and Wes, you've, you've shared this too, you know, this is where David, you can, I think, uh, it's a great fall on your sword technique. Hey man, this is on me. It, it, I'm doing not doing a great job conveying the importance of this to you.

And then you can fall right into the story that Wes is talking about, you know, in, in, in your world, Hey, you know, this is what happened to a client. You know, but, you know, falling on your sword saying, you know, it's like a, a Jocko willick. It's ultimately always our responsibility as leaders. And in this case, you know, being the MSP, um, that's, that, that's my thoughts there. Um, awesome. Yeah.

Ra, just real quick, Raj ass out there is like, how long, uh, to wait for automate to get the patch right. Kyle, any thoughts on that? If you, if you have the hosted version of Automate, you are effectively patched by ConnectWise automatically. There are some other security issues that ConnectWise is working through. Patching. Patching is never a are you done? It's a constant process. Um, and some other vulnerabilities.

But the, the patch is effectively working right now, uh, with possibly some updates to come this week. Um, you're on prem. If you're on prem, Gary, that's, that's the bread and butter. Um, we discovered that of our users, about 30% of them that were off or that were on-prem, um, had either not patched or thought they patched and didn't get patched. That's a significant number. Um, that's why we were making phone calls, uh, all the way through Friday, uh, night into Saturday morning.

So, um, that's that trust but verify. We've talked about that here on the show before, or independent validation and verification, um, that reiterates that piece. So, Gary, most of the issues that we saw were people OnPrem and had patch partial batch, And you had to choose between on-prem or cloud with your RM provider. It's, it's, uh, it really is. That's, that's that gray area, right? Um, you get a lot of extra control and you can do a lot of extra optimization when it's OnPrem.

So most advanced, mature very, uh, you know, large organizations are using on-prem solutions. However, the time to patch was almost immediately when it was done managed. So there is some real benefits there. Um, yeah, I think it's, it is dangerous, but either way, but obviously you gotta pick one and go with it. I, I believe the vendor should do patching for you. So I'm gonna lead to the bias towards hosted. I also believe it shouldn't cost you extra. Yeah.

So to, to just in time's sake, there's two questions. Let me, let me cap everything out with that. And again, thanks for everybody, man. You guys have all stayed on for the most part. Really appreciate it. Um, uh, so Mark, you just came in with a good one. I'm gonna start with that. Three questions. Uh, again, I'll kick this to, uh, Kyle, maybe to you, 'cause you deal with this again. How do you verify that CW pa, the PA CW patch was installed?

Um, and I'm assuming, mark, are you saying that for the hosted version, because I On Prime hosted, there's a couple ways. I just gave a quick hint in the chat, which there is a, uh, URL called lab tech slash deployment. aspx, you put your own uur L in there, plus lab tech slash deployment where you'd usually get the unattended installer if it returns 200. ok. That's what Wes was referencing earlier in his, uh, presenta or in his, you know, pitch that he mentioned earlier.

And if it's returning you an EXE file, you have problems you need to atch. Thanks, man. You can only get this stuff here. Thank you, Kyle. Quick question here. Uh, uh, it comes from Jeff, even with SSO and saml. Isn't the endpoint, uh, the vulnerability or is it the user identity? Wes, can I throw that one to you by chance? Uh, say that, Can you see it in the question area or, uh, if you click below, it says, even with SSO and saml, isn't the endpoint the vulnerability question mark?

Or is it the user identity? I'm not sure I understand the, the word vulnerability, but I will say when it comes to SSO, identity becomes the edge, right? So the identity of your users who has access to what, um, and that enables, I mean, that's the first step on the journey to zero trust, right? Is moving to towards the identity, uh, to authenticate and using identity as the true edge.

It's not about the firewall anymore in that classic sense because where's your data, your data's in the cloud, who has access to the cloud, where the rights inside, all of that, right? So not sure I'm understanding the question, but I would say, I mean, that's the first journey and that's why I do think identity management is a critical component and, and will truly enable you to get towards zero trust, uh, in your security implementations. Kyle, you can probably add to that.

So, uh, there, there's a technical way that Jeff might be asking this question too, which is, uh, you know, Chris Laer addressed earlier, even if you had single sign on or two-factor authentication on some of these vulnerabilities. Part about layering is there could be things that don't go through two factor.

If Jeff is using the word endpoint to describe the API or the, uh, the, the website to be able to get this data back and forth, technically he could be correct that even if you had two factor or single sign on, you could still be vulnerable. But that's why there's once again, always layers all day every day.

Unfortunately, in this case, as Chris Laer mentioned earlier, some vulnerabilities when you get hit the time for detection of finding an exploit and the actual preventing and stopping ransomware, you might have moments, right? That moments could be hours, could be minutes, could be seconds. Excellent. So I know we're at the top of the hour. There are a few more questions coming through. If you want me to get those answered by our experts, just send 'em over to, uh, Andrew at Code Red msp.

I'll put it in here for everybody. Gary, did you have something? Uh, uh, Just one thing. When Kevin was on, uh, he, he didn't mention, but they're putting on an event coming up with, uh, they have Magic Johnson on it. It's, uh, oh, I love It. mvp uh, growth Fest. So go to ID agent mvp, growth Fest, um, Fest and go, go check that out. It's a really cool event and I love magic. Yeah, I submit my question.

We'll see if they, you know, maybe I can grease the wheels with Kevin and get, get a question in there. Yeah. Fantastic. Hey everybody, um, first of off audience, thank you so much. Keep, you know, if you could spread the word, tell peers, um, the community continues to grow and flourish. We've got exciting things coming down the road. Um, for real. It's not just the statement. We've got some things that, you know, Gary, Wes and I are working on, and, and Kyle will be involved as well.

So we've got a lot in the hopper. We've got coming up in August and Kyle doesn't even know this yet. We've got capture the flag again. Uh, we gotta reach out to you to, um, to you if you, you guys are interested in that. But we'll start talking more about that. Um, Gary, Kyle West. Thanks is always Kevin. Uh, if you're still out there, appreciate it guys. Have an awesome day. We'll see you next week. Thanks everyone. Take care.

Related Videos