Skip to main content
Right of Boom
January 30, 2025

CyberCall – June 1st, 2020

Guests

Andrew Morgan

Video Transcript

All right. Welcome Gary. You wanna give a ha ha. Nice, nice. That was good. That was real good. Welcome everyone. Great to have you all back with us. I hope you had a, uh, healthy, uh, memorial day and, uh, I hope things are going well in everyone's world. Can everybody hear me okay? I know we can hear each other. We did some practicing beforehand, but I'll just take a look in chat. Can you just, uh, let, let me know? Uh, hey Michael, can you guys hear us okay? Yeah. Okay, great.

Chris, thank you for letting us know. Um, alright. Let's talk about the lineup and let's get right on into it. Um, so today I am really exci. I'm always really excited, but I'm especially, uh, grateful to have, uh, Carl with us today. Carl Bickmore, the CEO Snap Tech. It, um, he's doing a phenomenal job.

Um, he and I, uh, have been, you know, work, I wouldn't say working together, but, uh, in, in groups together for the past three years and watching man, his maturity and command of the cybersecurity framework and using risk-based approaches to sales, um, uh, I think you're really gonna enjoy it. And so we're gonna follow that up with a kind of a combination after he goes over how what he does with Gary, who, you know, this is a very process driven approach around standards.

So I thought, what a better person to kind of ask some questions about it than, uh, than you Gary. Uh, we'll move on and bring on, um, uh, Wes who's gonna talk about using analogies to establish a common language with people that you know, again, if, if, if we're talking, you know, something so arbitrarily different than, you know, the c-suite or the business owner, we can't get on a common language with them, it's gonna be really difficult to, to, to talk about.

So Wes is gonna be doing some analogies. Um, we're gonna have Kyle, um, go through why vulnerability management is more than patching. Um, I've got a link out to his, um, LinkedIn, which kind of stirred up some stuff around this. So I think, uh, it'll be great to have, have a discussion around that. We'll round things out with Ken Tripp, um, from networks doing the data security trifecta, uh, what's new in data privacy laws coming to a theater near you, a pretty, uh, amazing.

And then, uh, Amit's got some really interesting stuff happening in the world of fishing. Um, so with that, not Andrew, we better get moving, man. I know, I know. I, I overstack the deck, Gary, so I'm, every week I tell you less is more. And then every week there's more, there is more, um, there more is more I guess in this case. But, so I just threw a quick reading here, Gary. I'm not gonna spend time on mine. Let me just share with you why I thought this was applicable.

I was, I'm reading a book called Life Is Sport and in it they give a John Wooden quote. And I thought you would find this, uh, you, you probably know the quote Gary, but it talks about that failure isn't fatal, but failure to, failure to change just might be.

And the article talks about how this particular, um, group was prepared actually, um, for Covid, not because of Covid, but because it was an, it's an enterprise read, but it has a lot of applicability to SMB because they had done active shooter situations where they had to literally get all their staff in remote, um, all their equipment remote, uh, connectivity remote, et cetera. And he talks about a tabletop exercise that they went through.

And I mentioned that because this is something that, you know, we are gonna be doing, Gary, uh, with, you know, we're gonna invite everybody here. We're gonna invite your members and everybody, uh, out there. But he, he concludes, and I'll conclude it with this, that he said, you know, it's never too late.

But, and what he meant by that is, you know, look, if you're an organization and you haven't started doing preparation for these types of things to go get budget, to be able to now all of a sudden get your people in a remote scenario with the right equipment, right? Connectivity, just like that, man. Um, and so I thought it was a great message for MSPs, Gary, that I hope it's not too late, but man, they better get going. And so what are your thoughts on that, Gary?

And Yeah, Yeah, I'll expand it more just in work from home, just in general. Right now we're in a business as MSPs where every one of our customers is changing their business plan. So if we're not changing ours, look, one, there's a couple things. MSPs in general, and I don't want to offend anyone 'cause I've owned a couple, they're not that great at. One of them is change Selling stuff and doing things right.

So they're the three things we gotta help people with and that we all have to get better at. And right now, the one that's at the forefront, you mentioned it, is change. And, you know, on this call, you know, we're basing it around how people have to change their conversations around security. There a lot of things, right? We've talked about, right, how they secure themselves and their customers. And so, uh, but in this case, not changing is increasing our risk.

And you've heard that in the calls, right? In recent weeks. So, uh, and that'll be a great lead in to Carl. It's, it's, it's How He literally talk. Yeah, yeah, yeah. Absolutely. And he talks about literally, he's like a risk, you know, if, if, if enterprises aren't taking a risk-based approach, like light bulb, like be, be better. Start having those types of conversations with your board or things aren't gonna happen and get into a common language.

So with that, Carl, I think it's a perfect segue if, uh, you could kind of take us off on, on your approach to how you talk to customers and prospects. Yeah, you bet. Well, I mean, first just a quick little shout out. You know, Gary May not know it, but it was a few years ago when he did a roadshow through Phoenix when I was just thinking about being an MSP. And I might have heard him talk about and said, I think that's something I should do with my little IT business. So mad props. Gary.

It's good to hear you buddy. Awesome. Great to see you. Yeah, yeah. Um, so yeah, you know, the thing about it is, is, uh, you know, during this like pandemic thing, uh, and or a major downturn, I think Gary had it spot on that customers are looking to make strategy changes. And so, you know, when things are going really well, we have a lot of good messaging we can have, and a lot of us MSPs are in the mode of selling when things are going well.

A lot of us haven't changed our messaging to how to sell when things are going poorly for our customer or retracting because that's just as but big of an opportunity for us, but we have to change how we approach it, right? And so when he speaks about how we're not good at change, I think that's like the number one thing to recognize is how are you pitching or how are you explaining your services and how it helps them because you need to now help them become more efficient and do more with less.

And it can be great at that, right? Um, the reality of it is though any business owner should be concerned with risk, they should be concerned with making more profits, and they should be concerned with, um, making sure they're operating efficiently, which is really, I guess, part of the profit as well. And so, um, I find out there, you know, our primary market segment of customers is the 25 to 100 seat environment. Um, and we do spend some time in the 100 to 500.

We've had some great success there. They eat it up even more there. But what I find is in that 25 to 100 segment, and I think this is true, the smaller segment is that the business owners typically don't formally manage risk. They don't know about it.

And so if you're following something like the challenger sales model where you're trying to teach them something they didn't know, a lot of times you have a lot of opportunity to teach them how to better manage risk or how to better qualify their risk. And it is a great area of risk for any business where they can have one event cause major even game stopping risk if the wrong IT event happens in their environment.

Now, be really careful though, because what we're selling is not fear, uncertainty, and doubt. In fact, I think that's about the worst way to sell because you're just freaking people out. There's no long-term relationship in it. What you need to do is teach people how to responsibly categorize risk likelihood and what the impact of it is.

And so what we do in our engagement process is we begin the initial conversation by just getting the customer to realize that maybe they don't know something about their it or there's some questions that are unanswered. And our first step is to do a risk assessment from that risk assessment, which by the way, we charge for by, by our, our standard hourly rates in whatever market we're in, because we have offices in the San Francisco, Phoenix, and Atlanta area.

Whatever market we're in, we charge our standard hourly rates for it. And a small risk assessment for us is usually around 20 hours. Um, that's for a, you know, a 30 seat office that has lots of questions to be answered, right? Um, a larger company, we would have more involved in a risk assessment, there'd be more complexity or more things to assess. And when we're assessing, we're doing things like running scans of their environments.

We're determining assets, we're looking at firewall configurations, we're looking at their backup, we're looking at their software use. We're looking at lots of security settings. We run a ransomware simulation. We, uh, port check their firewall. We'll, like, we'll do, you know, external scans, we'll do some internal scans, and we look through the configuration of their permissions, their groups, their active directory, their to user accounts, their password management, their Office 365.

We, we take a look through all that stuff and produce a report that essentially gives them a list of their asset information and then gives them their top 10 risks. And we're categorized 'em by likelihood and impact. And then we give them further reports that help them understand a roadmap. And that's a kind of a key point to this whole thing, is getting it to a roadmap.

Because if you just say, and here's the three times you ever spent on it budget to all buy right now, you'll, you're not gonna get that one closed either because it's overwhelming. And so a really key thing to this is putting this in the context of a plan, prioritizing and putting in order. And so that's just a quick highlight of how we engage it's risk assessment, and then we provide roadmap doing all those various details. Thanks, Frank. So I definitely dig what you're putting down, brother.

I think this is one of those things that I'll probably, uh, call an audible a little bit on my presentation based on some of the stuff you said. I think you perfectly highlighted some of the, you know, you just gotta understand that there is risk before you can start articulating what it is, let alone moving forward. I thought you had some pretty actionable results too, on how you get it in there. So, uh, huge kudos to you for, uh, pushing me to, to move a little bit of my presentation.

All right. Sounds good. Yeah. And you know, Carl, what I would add is, um, if I look at how I've built, you know, my two MSPs and how I've helped, you know, a couple thousand other people, the only thing I would add is the process you just described isn't a sales process. You're using it right, in a very smart way to open up new accounts.

But the idea of having standards and comparing your customer to those standards, making recommendations based on risk or productivity, putting those onto a strategic roadmap, that's pretty much the ongoing process of what people buy from MSPs. Now, MSPs get confused 'cause they spend all their time doing tickets, alerts, and billing stuff. So they think that's the business.

But hopefully Covid is getting more people to see when every single one of your customers is redoing their business business plan when every one of your customers risk profile has changed at eight weeks. And they are requiring that from you. That that's really what it's been. Andrew, you've watched me do this, Andrew, right? For 15 years, and he's pretty much describing the business model, right? Yeah.

And so, um, it's great from a pre-sale standpoint, but it's even more important forever when they're your customer on a monthly, on a monthly basis. Yeah. Gary, you're so right. It's, it's so funny. I'm famous for calling it the non-sales method, which is just let's go manage your IT and help you understand what you don't know and make good choices, right?

But the, um, the thing about that, Gary, is that, uh, um, a lot of MSPs don't understand that once you've signed up a customer for this, this is the ongoing sell as well, and to existing customers, long-term customers that you aren't doing these kind of things for, this is an opportunity to enhance your services and update what you're doing to be more appropriate for now, right? Which, which, no, I didn't say the word upsell because that's not my goal, but it's what happens.

But the point is, is all I'm trying to do is deliver current IT and teach them how to manage risk. Awesome. Really, really great job. Carl. I'm gonna add one last thing, and I, I don't want to, I know we gotta keep moving, but, um, you know what's interesting, Carl, is that very similar process to what, how I've run my MSPs. The only difference is because, you know, my background's in sales, you know, coming into it, and I try to be efficient with that.

We normally do all that assessment after they're a customer, showing them how we do the assessment. We can create risk in showing them how we do it compared to their current vendor and get 'em to sign the deals, you know, because, you know, we were going out on 4, 5, 6, you know, appointments a week, so we didn't have the technical resources to do all of what you're talking about. We just didn't have the resources.

So I found a workaround to it and sold the same thing, but I sold it pre right, and delivered it post agreement rather than pre, but it's just the concept's exactly the same, right? Concept's exactly the same. Does that make sense, Andrew? It does. It does. And I, one of the thing you said that, uh, about tickets, time and billing is don't confuse, I'm gonna butcher the quote, Gary, but don't confuse with activity, with success. Yeah.

Um, so, hey, Carl, first off, really great Job, succinctly explaining Yeah. The Relationship and the conversations we need to be having with, with SMBs. Man, really great job. Yeah. Carl, We, uh, since we opened this up and went a little bit long, uh, do you want me to give you about three minutes back and just cruise through this piece? I was gonna say, I thought it, it lend itself, you literally called the perfect audible.

Wes is out there, but I, I think it lends itself well, right into your piece, Kyle. So Carl, hang with us. You know, we, we did talk about cybersecurity framework. I just want everybody to know that there, they're just, that's your backdrop, if you will, of irrefutable truth, that if people, you know, like, you know, what are you basing me on again, we don't have enough time to really delve into that. Oh, you threw it in there, Kyle.

The, uh, the, uh, yeah, I'm, I'm throwing a handful of these things in here just to make sure people have time to get the resources today. Perfect. So I'll let you take off for a few minutes here, then Kyle, and then when you're done, I'll, Carl, I'll move you over and I'll pull Wesson up. Gotcha. So I'll be, uh, plenty brief for everybody on here, obviously great to see everybody for another cyber call. Huge thanks for, uh, attending after the holiday Monday.

Um, with that said, I just shared in the chat one of the links, and it was one of those in LinkedIn, sometimes you post and you don't really realize that you might open a can of worms. It's, it's very rarely do I get a LinkedIn post where I, I get so many emails, they start trickling into our own company's, uh, support queue asking What did Kyle mean by this?

But the can that I opened was, I said, look, when it comes to vulnerability management, configuration management, all of these things, there's a lot of attack surface, and there's a lot of things that we as MSPs aren't thinking of. And I called out the, the number one thing that I usually see is good configuration management, uh, for the sake of being very quick and to the point today, one of my ones that I said was, look, security baselines.

And just as Carl kind of mentioned as I'm going out, my notes here, the first thing he talked about was change. And ironically, here I am talking about change management. I'm telling you, it's one of those things that whether you're inheriting a new client or you've just had somebody that's been on board for 10, 15 years, you probably haven't had the time to invest in your own change management. So I wanted to give some very explicit feedback on how and what you can do.

So the first thing someone said to me was, and ironically Carl hit this one as well, when things are going well, everybody knows what to do. But when things aren't going well, you'll look back in hindsight and say, oh, gosh, what could I have done better? Or how could I have taken this to the next level?

And so I wanted to share this very first, um, resource in regards to, on modern Windows operating systems, if you've never hardened a modern Windows os, we're talking about Windows 10 server 2016. This is very explicit. This isn't the high level business acumen that I tried to give you on this, uh, cyber call. But the difference is, is this is very actionable. So it starts with how in the world does Microsoft recommend you look at these security baselines?

So if you're doing something like Carl, for instance, assessing risk or just trying to get somebody to understand what that risk is, whether it's active directory, configurations, user accounts, permissions, you name it. Microsoft has all kinds of really useful things here. One of 'em is called the Secure, uh, security Compliance Toolkit. Once again, it's in the chat.

Um, and just in case this whole thing is a very, very foreign view, um, Microsoft has even made a video on how to do some of these initial, like, uh, security compliance things and use their tool. So, um, my high level thing that I'll leave the whole team with is, look, when it comes to assessing risk or anything in business, it's never a one size fits all solution. The same thing is true in group policies. It's way more than just patching.

And the thing I'll mention to you is everything that I just shared here needs to be tweaked and tested and refitted to each client in each unique environment. So just like your business, I can't give you a business plan. And I wanted to make sure today that as we're talking about minimizing risk or even discovering risk or how to articulate it, here's a tried, tested framework from Microsoft that I wanted to share with everyone. Perfect. Thanks so much, Kyle.

Carl, I'm gonna move you over to the, um, audience. Thank you again, something Going on. One real quick thing. I know we're gonna run behind, but I'm interested something Carl said, and now I'm, I'm listening to Kyle, I want everybody to hear all of this takes time, right? This is all things talk about hardening, talk about 20 to 30 hours just for an initial assessment. Now, those things had to be checked ongoing. So look at your offering to your customer. Are you charging enough?

Is the time built in? Do you have roles and process? Is somebody responsible for the things you're hearing about, which is not, you know, it's not tickets, it's not just upgrades. This is a whole separate, okay?

That's why you keep, he hearing me hit this thing and it was, Well, I mean, Gary, and, and what a better way to sell right now too, in the sense of if someone says they should, if someone should be at 4,500 bucks a month and they're only spending 3000, you can literally say to them, I can tell you right now, you're not secure. Yeah, Carl would tear him apart. He can, he I can already tell you that he would weaponize low price. Yeah. He would weaponize a competitor low Price.

He's been doing that for years. Been doing that for years. I mean, the reality of it is, is, is, um, uh, you know, you, you gotta really learn. Uh, the problem is a lot of us technicians, like you said, three things we're not good at to change. Another one was, we're not good at selling. And I tell you, that's been a big growth area, and I still have a long way to go.

But one thing I've learned is to not be afraid because I'm twice the cost of the other joker, because that Joker is doing them a huge disservice. He should be Free, Is helping them understand why. Awesome. Awesome. Carl, thank you. I'm gonna bring up Pez dispenser, hold on, and let's go. I'm gonna fire it up now. Let's go. Bring on Wes. Come on Wes. He's giving out Bitcoin.

I think he said, well, Wes is typically negotiating with the bad guys, giving out Bitcoin, but, uh, uh, we got him coming up here. So Let's see. Wes is coming on up. Here he is. Hey. Oh, he's definitely giving out Bitcoin there. He's, yeah. Look, If Carl's gonna be on the call, I gotta show myself up too. How are you bud? I'm awesome. How are you guys? Good to have you on. Good to have, good to be on. So Wes, you have done some really cool things with analogies.

Um, the analogy I, that isn't an analogy I like the best is to get budget. Um, just have a breach. Um, but, uh, what do you got for us today? Yeah, you know, so I, I posted this, uh, in LinkedIn. It doesn't look much different With that. On or off. You look pretty good There. How's that? That better now, now people will respect me. That's what it's all about, except for this one. Okay.

So, uh, I posted this in LinkedIn last week and I got some good traction out of it, and Andrew wanted me to share a little bit more, right? So I've, you know, I've spent my career, uh, as a CISO and as a CIO learning how to speak to boards. And I've discovered like communicating it concepts is really, really difficult. I don't think it normally, like, it comes natural to people. And so I wanted to share one of my favorite analogies, but I wanted to do that just to kick things in motion.

And then I'm actually really curious to hear what analogies do you guys use on a daily basis? That makes sense. Because when we share and talk in analogies, it's such a unifying language. It's a really powerful way to make sure people have different backgrounds and, and levels of expertise, all feel like they're understanding what you're talking about. And, and you, you, you never end up like talking down to them, right?

When you share an analogies, it's just like Reddit, uh, you know, explained to me like I'm five every single time someone answers like that. It's in an analogy. So lemme give you my favorite one. And I've used this multiple times with it decision makers and non-decision makers that are executive and board level. And it works. So here it's going to the dentist and I know what you're thinking, right? Like, uh, personally, I hate going to the dentist. Like I loathe it.

It is the worst thing that could ever happen to me. I don't enjoy going, I don't want to go. It's like, if I could avoid that at all costs, I will. But what's worse than going to the dentist at least twice a year for a hygiene checkup is a root canal. So pick your poison. Which would you rather have? Would you rather have often hygiene cleanings or would you rather have a root canal? And for me, every single time, I'll pick the hygiene, right?

And I love this analogy because when you start sharing this, when you're talking about, and this, this analogy works in multiple different ways, but it really highlights when we're talking about security and hygiene and doing the, the necessary things that must happen and why. Someone's like, why are we doing this again? Why am I supporting this? Why am I paying for this? What am I getting out of this? I don't see anything directly evidenced from it. It's hygiene.

And using that story gets them to say, okay, I understand that. That makes total sense. You're talking about hygiene the normal things we've gotta do. So something worse doesn't happen like a root canal. I love it. So it's just one analogy that I, I use often and I'd love to start a conversation and I'd love to hear from you guys what your go-to analogies are. Because the more we share those together and we all learn from each other, the better we're all gonna be. That's great.

Wes, You just explained no third option. Go for that, Gary. Talk about it. So, Awesome. Wes, no third option is like a sales technique that we teach. And I'll use Carl's example. You know, he goes in, he does its risk assessment and the client says, yeah, but you want to charge me $4,500 a month and I'm paying 3,500. And you say the client, well, let me ask you, what if you only had two choices?

Choice one is you can keep paying 3,500 and you're gonna continue to live with this risk, which makes sense. 'cause you, you have it now, or you could pay $4,500 a month and you, you would feel like you greatly reduced that. If that was your only two choices, then what would you do? And so in other words, you presented in a way that there's no, that there's no third option root canal checkup. Right? Excellent. Excellent. Well, I, I don't think the next person, Kyle.

Okay, if I move you over one. Sounds Good. I'll be In chat Tha Sounds good. Uh, speaking of, um, you know, fun checkups, we'll bring on Mr. Uh, mc, uh, Ken Tripp. Uh, I don't see him as, uh, root canal. I see him more as the, uh, checkup side. And, you know, uh, uh, speaking of things, coming to a theater near us, boy, uh, data, data privacy. Wes, I'm glad to have you on for this.

Uh, man, the, um, amount of legislation coming our way, and I've got some links that Ken has shared is just mind boggling. California obviously be, you know, being the GDPR of the US if you will, first. Um, but Ken, welcome. Hey, Andrew, thank you. Yeah, thanks for it and a great conversation. Be happy to be a part of this right now. So, uh, Well first, where are the minions?

You know what, uh, yeah, did a little cabin cleanup, so still working from home, obviously, but, uh, the girl got back into a room this weekend and got to play around, so I feel a little bit lonely, but yeah, I'd like the, I'd tell the twins, I'd like the minions back next time. All right. You got it. Will do it. Alright, well, I'm gonna put some, uh, links in Ken the chat, uh, just real quick if we could highlight 'em. One is, it's, it's a landing page at networks.

It's not a sales pitch 'cause we're not selling, but what it does do is it goes through DS a r and Ken, I'll let you explain that today. And the other links are out to external third party sites about really where the legislation is in privacy laws. And it's pretty staggering what's coming our way. So, yeah, I, let me let you take it.

Yeah, definitely it's already here, but it's expanding and like you're saying, it's coming to a state near you very quickly, uh, when you're looking at consumer privacy laws in terms of their data, right? So, um, obviously, uh, we're seeing things like C-C-P-A-G-P-R causes, but, uh, it's coming down to the local level and it, and it's, uh, it, when we get to it, really a, a great opportunity, uh, for MSPs to, uh, take a part in what they're labeling as a DS A R, right?

And, uh, basically that's a data subject access request, and we'll get to that. But in, in all honesty, um, like Gary was talking about earlier about change, right? And security no longer is just preventative. Your antivirus, your firewalls. Um, and what's going to happen is we have to evolve and change. And literally, uh, coming down to the MSP, uh, to their SMBs, 20 years of enterprise security is being thrown at them all at once in the last 12 to 24 months.

And you are being asked as an MSP to achieve it. Sometimes they don't want to pay for it. Uh, and again, that comes back to that education, right? Um, because it, it's not cheap to do, it's not easy to do. Uh, there's a variety of technologies that can help. Uh, but just expanding the workforce, uh, might not be the thing as well.

So when we're looking at the trifecta, and, and Chris talks about this all the time, Chris Laer from solid security, uh, one of them obviously you all know, is a breach. And when you get breached, what does Chris always say? Here's, here's what's gonna come. Uh, I need to know, is the client regulated? What type of data was stolen? Is it being held ransom? Maybe it was even exfiltrated, maybe they had just grabbed it, right? Those crown jewels that are worth something.

And then how do you respond to it, right? So it's not only preventative anymore, but you've gotta have some kind of response. You gotta notify those consumers, uh, that their personal information was stolen. And the fact is, MSPs, uh, and w you see it all the time, are huge targets because instead of going after a sole company, you are getting 30 companies for infiltrating one instance because of multi-tenancy.

So obviously a lots around a breach, not only preventing it, but unfortunately it happens and there's nothing we can do to stop it. Um, the bad guys are really good, but we just gotta try and be better and be able to respond to it. So when you are looking at compliance, again, that's CCPA, that's GDPR, but it's filtering into PCI. So, and what we're looking at there is really just the least privilege model.

And unless you go scan that data and exactly know where it is, how do you know if you're following the least privilege model? We had, uh, one of our MSP partners get, not a funny story, but it's natural story, uh, decided to take our data discovery and classification tool for a spin. Went in the next day, they had pointed it to their public share, and he goes, uhoh. I was like, Hey, what's going on, Brian?

And he goes, uh, well, that's my social security number sitting there on my public share, right? So, uh, kind of one of those eye-opening things. Um, you think you know where it is, but you don't, and it needs to be continuous, right? It's almost, I hate to use this analogy, but if you go get tested for the virus right now, and you're okay today, well, what happens tomorrow, you might not be okay, right? So data is constantly changing. It's constantly being modified.

But now what's scary for us is it's not only these compliance regulations that you're getting audited for the process, they're putting this power into the consumer now, right? So the consumer has the right to go to a company and say, Hey, where is my data? Are you securing it? Or two, do not sell it. Or three, have that right to be forgotten. And it's more than just crawling the data.

There's a process to this and garner's coming out and saying that every DS a R access request is costing up to about four, uh, $1,400 and usually about two weeks to fulfill it, right? And that process goes from requesting the capture and then logging it, identifying and verifying the verification of that person requesting it. And then you gotta do the planning. What are you gonna do with it? Is it gonna be deleted? You just have to tell where it is. Or on a do not sell list.

Then you gotta go through all the data you've collected and find everything that they have on Andrew Morgan, right? And then the response validation before you send it. You gotta go through a legal process to make sure you got the right stuff and then finally to the end client. So the big thing is, are your clients gonna be asking you to do that? And if so, what an opportunity, uh, for you? It sounds expensive. It does. It's really expensive. No, Gary, you nailed it.

It it, and, and the consumer has the right. So let's just kind of just role play this real quick. 'cause I know we're at the top of the bottom of the hour. We have Amit closing us out, but Wes, I'm gonna kind of point at you where, let's say you have the banker hat back on. You're the ccio o of a bank. You're in California, the privacy laws you've done, you know, Gary's come to you for a mortgage now. Yeah, yeah. You know, and now he says, Hey, Wes, what information does your bank have on me?

You gotta tell me. And oh, by the way, I want it in essence redacted, and I want proof. It's gonna be redacted. And oh, by the way, that burden's on you. Now, the MSP you, as you as the banker, or saying the MSP, how am I gonna manage all of this requests of data? Yep. It, it's an enormous task.

And I've discovered the older the organization, the more legacy their processes equals both of those together in the, uh, in the, in the equation equals an enormous amount of work that must be done in privacy, uh, practice and, and updating, modifying. That's why all of these privacy laws are coming about is a, we've demonstrated that unfortunately they're necessary and we've gotta put power back into the consumer.

But b um, I have also seen this is a huge monumental challenge for larger organizations. I'll give you two super quick examples and maybe 10 seconds each.

So one of my good friends is the CISO of Valvoline, and he would allow me to share this, uh, going through GDPR for them was about a year of nonstop work for him and a dedicated team of about three to five absolute nonstop monumental work for perch, uh, a month or two or three because we're younger, smaller, we understand where our data lies and the processes behind them, and it's incredibly modern. Um, so that's difficult, right?

And the second one I would share, and I can't get too deep into this, maybe this is one over beers, and we meet in person one day, but the bank I came from, we ran into some regulatory issues and the federal regulators were calling back a whole bunch of data for us that they mandated for us to give them. And we have to comply with that because of what they were asking. We ended up having to assign an FTE for about six months just assigned to that project to get the data out.

And so my, my CFO is sitting here screaming, saying, why is this so difficult? Why is this so challenging? Well, the answer is because we've never really wanted to update and change some of the processes we've had. Now, we're paying the price for it. So yeah, privacy is, uh, is extremely important, and it best to take it now and hit the bull, uh, by the horns now, uh, then, then pay for it later. Yeah. And when you say expensive, you're right.

There's just so much data out there, it's dispersed over multiple repositories and it really requires expertise and then access, right? So now all of a sudden that request comes in, you have to take your IT team off what these should be doing to do this, right? So, um, it presents a huge problem. And, and with the consumer, it's, as a consumer, I'm glad that we have that right.

You know, it's, it's almost like college athletics where, uh, those players were, uh, getting extorted for people making money off of their likeness, right? If you look at USC, for example, never had a a name on the back of their jersey, but in that heyday they were selling number five Reggie Bush jerseys and Matt liner, and they weren't making any money off of it, right? So these companies are grabbing our data and selling it and making masses amounts of money.

And we have that right again, um, we still may want it, uh, but at least we wanna know that it's secured or at least have that right to be deleted. So, great Stuff.

Uh, you and Andrew came on to a true methods webinar recently, and we were talking about, you know, how some of the security now, and you talk about data, it goes into like your design of how you design yourself and your customers, and sometimes you're gonna make decisions prioritizing security over short-term profits, or maybe even efficiencies, right? Absolutely. And it's interesting to see, I mean, a lot of these different states, regions are pulling from CCPA.

Some of 'em are a little tighter, some of'em, a little bit stronger, uh, but I think Andrew shared those links with you. Again, not affiliated with Trio at all, but they provide great information. You can drill down by state, uh, to see what's happening, what's coming, and what those regulations look like that you need to be prepared for. Thanks, Ken. Um, I'm gonna move you back over to the audience, gonna round out with Amit. Really appreciate you coming on with us. You bet.

Thanks for having me. Take care, guys. Wes, you started a whole analogy. Fire going off now they're Flowing through. Yeah, they're Awesome ones too. Hey, And our potter, I just saw what you put in. You avoid car analogies and sports analogies. That's awesome. Use the analogies that work for you. That's the way to do it, for sure. All right, we're gonna, we're gonna, um, I, uh, and this is on me guys. Sorry for going a little long.

Um, Amit has been seeing something exponentially, uh, increase that's on the phishing side. That is, um, pretty, pretty, pretty frightening what it does. Um, I'm gonna put the links out there, uh, so that you can follow along. There's gonna be, um, a link on the PowerPoint and there's gonna be a link on what Amit's talking about. Um, just in case, you know, um, you wanna take a look at that. Go, uh, Amit, go ahead.

Why don't you kind of frame out what is, what, what's n you know, you know, we hear about in attachments, like, you know, devil's advocate. What's so big about it? There's been attachment stuff all along that's been fishing. What's, what's different this time? Yeah, so we, we used to two things. We used to attachment that carry malware, and we used to phishing that carry links. So what's happening is that malware, you, we know, let's say we know how to deal with it.

We have, uh, antiviruses and we know how to deal with malware, but we're not used to attachment that. Once you click them, then you download the kind of weaponized HTML attachments, right? That, uh, create local phishing pages or redirect to preloaded phishing pages. So what ha what's, and these HTML files campaign encrypted phishing links, right? And, um, we redirect to phishing pages.

So what's happening is that you don't have the experience of like, uh, you know, when you click, uh, attachment with malware, you know that you download X Excel file with virus, but when you click attachment, it's like nothing happens because there is no malware and they tend to, uh, steal your credentials. So you as a, the experience of the victim, like nothing happens there.

So what, okay, so, um, what's the different, it's, it's obvious, uh, four or five things that are happening, uh, uh, or why does this attachment phishing link are not detected? Usually, first thing, as I said, they contain no malware whatsoever, no links encrypted. The file is downloaded, um, uh, to your local browser. It means that, and that, therefore it means that no blacklist is detecting that whatsoever. Right?

And these are attacks are going through like that through, uh, all the, all the relevant security actors, uh, Google, Microsoft, and all the others. Uh, if you want to, uh, you want to share the screen, uh, Andrew, the presentation? We can't, we can't, the links are there, so they'll be able to take a look at, okay. Yeah. So if you wanna, so just guide you for, yeah. So I, I'll just guide you. If you click the links for the presentation, I'll just guide you for the interesting stuff.

So, um, you see, this is our platform, but once you see there's a, there's a attachment there, right? So once you click it, then you receive actually a picture, right? An html, a picture of office 3, 6 5, a voice email express. And once you click it, then you actually move and you have, uh, you receive like A-A-U-R-L-A link. And when you click it, you actually see that it's still live, by the way, until now. And it's days that are after because no one will detect that.

And, uh, you actually don't experience any real experience of phishing, which is the immediate link that you carry on, and obviously not the attachment of malware. So you feel free to click it and to deliver your credentials like, like, uh, like, uh, in a very easy way. But if you go on with that, you can see examples of A PDF containing generic phishing link, which is not rare whatsoever, but it's rare that it's detected.

Um, so you all, you all might experience an experience of downloading A PDF, but that contains a phishing. Um, and, um, the last one, by the way, is a very rare example, uh, to see, but it's not very, in our case, an HT ML attachment will local, uh, as I said, local use, uh, in attachment phishing website.

So once you click it as the, uh, experience of the victim, uh, you can see that, uh, you see the about, uh, blank means that it's local and you see that actually receive an opportunity, uh, to go to secure document area. Then you log in with your email address password, and then you deliver, uh, all of your credentials. You obviously do that, uh, uh, in a much easier way because you feel very secure. Um, and these one are not detected, uh, whatsoever.

Um, what we offer is two, three tips, by the way, and that's also written in your, uh, in this attachment that, uh, uh, Andrew, uh, Andrew put in. First of all, um, the most important one is obviously if you want to keep on working with your, without any, uh, distractions, uh, is use email security that knows how to analyze these files. Okay? Uh, I know it's rare, but you should do that.

If not, at least ask, be aware of that kind of HT ml, uh, uh, in attachments and ask the company's it to configure the email security gateway to alert or to block HML attachments to all of the employees and or to, uh, train your employees just to know about a new kind of phishing attack that exists, by the way, for few months now.

But because it hasn't been detected, and no one is really aware of that, um, need to know that these days in dark web, it's one of the most, uh, wanted the phishing kits that is using, uh, uh, in attachment phishing. So most of these phishing kits are used, you're getting lots of them, and no one knows about that. So now you know about it. Uh, obviously we use this, uh, uh, this kind of, uh, visual sandbox, what we call it to detect these ones.

Um, but, um, that's the main thing you to do and you can do in order to protect, protect yourself. That's great. Amed, thank you for, uh, for, for coming on. Wes, any, you know, from a practical side, anything you'd like to comment before we Wrap? For for Yeah, please. Yeah. I'll just close this on this. So Ahmed's exactly right. What you'll always see in the world of malware is a constantly evolving and changing landscape, right?

So if, uh, if Kyle were on here, he could speak to this probably better, definitely better than I could, right? But I remember the days of like HTA attachments being sent through, and I know some organizations that got absolutely plastered because of HTA attachments before that, uh, it was word macros, right? And so we as defenders are constantly understanding what bad guys are doing and they're understanding what we're doing and they're pivoting and changing, right?

And so another example of this, and by the way, this is what I'm gonna talk about at IT nation, at the virtual conference coming up, is two factors, awesome. But we're already starting to see, uh, phishing and malware based, well not malware, but phishing based attacks that completely bypass two factor. And how is that happening? Why does it work? Uh, shocker uses OAuth, uh, and it allows you to kind of give them keys to the kingdom.

And, and I think what all of this comes back to is constantly preaching a, a cybersecurity regimen that is up to date for all things security awareness. And if you don't have a security awareness platform that is up to date in training your users on the evolutions and changes, you're gonna already be a step or two behind and you're gonna get hit by something. It's a matter of time, right? So, um, absolutely agreed Are offering, uh, you know, cyber training as an option still. Yeah.

You have it with or without. Yeah, you could have it with or without viruses. Yeah. Right, right. That's, that allows breaches or the one that doesn't Well, Program is much more cost effective. Just, just high chance you're gonna get breached. Yeah, no, that's, that's right. And, and, you know, the, and just like they're evolving technology are evolving, like the visualization stuff that you, that you guys do at Cyber Phish. So we appreciate you guys, uh, protecting all. Thank you guys.

Thank, I'm gonna bring Kyle up. We'll close on out. Thanks. Am Kyle's the best at chat? He's really, he's The chat. Oh my god. He's incredible. All right, we'll close it out here. Gary, I told you we shouldn't have had the extra people on Gary. Not too bad Andrew. I always like to bring more. I don't know what. Alright, Kyle, do you have anything to say? You like, I think we about Amit's stuff because, um, I, I thought it was really interesting the way they're bypassing now.

What Wes hit the nail on the head, it's constant evolution. He called out HTAs to macros, um, move to shortcuts and emails, and now you're seeing one webpage that spawns another webpage. So just that part of that constant iteration in any type of security platform, it's never done. It's what's good enough for today and what pivots to tomorrow. So I have nothing to add other than I did put a neighborhood watch alert out, uh, there was a rather shady character in there.

Uh, so just everybody keep in mind like that, that person is somewhere lurking the streets of Florida. Probably like a hashtag Florida man Neighborhood watch where, you know, aren't they? Oh, it's in our chat there. Uh, how many Take down on that trust? Just that guy looks completely legit to me. Yeah, exactly.

So yeah, no, nothing there to add, Jens, other than I, I know we're a little bit above time, but hopefully, uh, this was worthwhile for everybody to get the additional perspective, uh, you know, for the cyber call with the analyst notes to begin your week. Yeah. Well, thank you Kyle. So I guess you're saying that like bad guys are much more adaptable and readily able to change compared to MSPs that are a little slower to change.

So we need to start catching up with their, uh, cha with our change management process, right? So There is, there's a, there's literally a measurement from the offensive side of hacking is how quick can you iterate? And you should understand that that is directly opposed to how quick can you adapt as well. So they're opposing forces and if you don't keep up, they're, they're gonna do it. Obviously, change management being one of them. Wes, any, any closing thoughts from you my friend?

None from me. Thank you everyone for attending and really appreciate the comments. Uh, in fact, uh, maybe just this, Andrew, it would be great if you summarize some of those, uh, analogies that people were sharing and maybe we could share that out to the whole group as community fed analogies. Yeah. And the research roundup. So, uh, thanks everybody. We had a great turnout today. Gary, as always. Thank you Kyle. We great job today, Andrew. Appreciate everything. See you guys next Monday.

Cheers.

Related Videos