SecurityMetrics Podcast | 21
How to Get Cybersecurity Buy-In: A Message from SecurityMetrics CEO Brad Caldwell
“The single biggest contributor to data breaches is a lack of testing. You have to be testing, you have to be reviewing, you have to have pentests.”
After experiencing a data breach as a small business owner 20 years ago, SecurityMetrics CEO Brad Caldwell (CISSP, CISA, QSA, PFI) set out to provide affordable data breach prevention and remediation to businesses of all sizes. Since then, SecurityMetrics has tested over a million systems and provided cybersecurity services and audits for tens of thousands of businesses.
In a special episode of the podcast, Brad Caldwell sits down with Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to discuss how security complexity has evolved and what he’s learned from over 20 years in the cybersecurity and PCI compliance industry data breach investigations, and tips to keep a cool head in the wake of a data breach.
Listen in to learn:
- Common mental roadblocks people face in making security a priority
- The number one problem with incident response plans
- Tips to keep a cool head when experiencing a data breach
Resources:
Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide
Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide
[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.
How to Get Cybersecurity Buy-In Transcript
Hello, and welcome back to the Security Metrics podcast. I'm Jen Stone. I'm a principal security analyst here at Security Metrics. Very excited for this, last episode of season one.
If you're listening to us on the podcast or if you're YouTube, wherever you are, if you haven't left us a review yet, please do that. I'm really hoping that they're gonna let me do this for another season. So if you say something nice, they probably will. Let's, let's see how that goes. But today, I have with me, so excited, CEO and founder, and I don't even know what to call you, Brad Caldwell, started up Security Metrics. You wanna tell us a little bit about you and a little bit about Security Metrics?
Sure. I I I, had a business. I was a small business owner, and, we had a website. And we were selling a product that was a Linux based product, and we were charging educational price. And in the early days of Linux, there were a lot of purists, and they thought, how could you dare charge for a Linux product? They all should be free. And so they came in and they hacked our website.
Oh.
And so I thought, oh my gosh. You know? How does this work? So I went and talked to our developers, and they said, I have no idea how they got in. Mhmm. And so I checked around, and IBM wanted eighty thousand dollars to do a one time assessment.
Mhmm.
But I couldn't afford eighty thousand dollars Mhmm. In our in my small business, so I just got hacked again.
Oh, no.
And that's when I thought, oh, you know what? Small businesses have so much to deal with. They shouldn't have to deal with this too. And so we I started Security Metrics, and we have very affordable, pricing on our products.
So you can do your scans and, hopefully, within a hundred or two hundred dollars, you can do a scan every quarter, make sure your site is secure. And that was the whole genesis is trying to help small businesses not be attacked. And especially in this day day and age where your data is maybe ransomwared and it's gonna be posted and you could be you could be ruined as a business. Right.
It's more and more important for businesses. So I'm excited that we're in the in the space where we're able to help hundreds of thousands of businesses.
Oh, that's awesome. So, I mean, awful that you had to learn it the hard way. Yeah. But if you if you were to go back and talk to yourself at that time, what would you what do you wish you had known about security that you just didn't know then?
Well, I think the biggest thing was I'd always historically gone back to my developers. They were always the smart guys. Mhmm. So I'd go to the smart guys and I'd say, how did they do this?
And this was the first time I went to my developers and they said, we have no idea. Yeah. I mean, we just we don't know how they did it. And I said, well, that doesn't help.
I mean, how do we fix this? And there was no fix. And so we went and we patched the server and we reinstalled the server and we did all those things, but then the vulnerability was still there.
There wasn't a vulnerability scanner in those days. Right? This is in the nineties. Right. And so I didn't have any blueprint. There was nothing for me to test, and we got hacked again. I was I was fortunate in that we kept all of our card data off of that web server, and so they weren't getting in anything except they were just, taking down the server.
They were, you know, doing a lot. Hacktivism because they didn't like how you were going about your business.
Was. We were charging an educational price, and they thought that was a bad idea.
So they came in and and wreaked havoc on our side, but it didn't feel good.
Yeah. I mean, you literally I mean, I literally went through the five stages of grief. Right? You talk about that, but, I mean, it was real.
I was like, something's not really doing this Yeah. To me. And then I realized they were. And I didn't know where in the world they were.
I didn't know anything about it. But it felt really bad, and so we were able to, you know, get the site eventually secure, and and we didn't have that problem.
But it was just a real wake up call that people are actually they're they're bored Yeah.
And they have time Yeah. To be a hacktivist and to come in and do damage to your system.
Rough. You weren't just a drive by malware. It was actually you were targeted.
Yeah. No. They came into the site and they deleted files and took the site.
That's rough. Yeah. And it's it's funny how you said, back in the nineties.
You and I, you know, have been working since at least the nineties.
I think we're about the same age.
But Let's not talk about that.
For anyone who is actually listening and not on YouTube, I carry it better.
Okay. No. You do. Okay. No. You look much better.
Yeah. Yeah. But, thinking about, you know, the current threat landscape compared to back in the nineties, how do you how do you think things have changed?
Well, the sophistication of the systems are so much they're so much more complex. Security is so much harder today. You know, in those older days, your configuration was much less of a problem.
Mhmm.
And so there was a lot less to to check back then. Now you have to check so much, and there's so many different places you can be holding your data. There's CDNs. There's all of these things. I mean, it's just so complicated that I think it's just kind of running away.
Mhmm.
And we we all wanna know instant data all the time, which means all of these systems are coming and connecting into our websites Right. Into our systems that we never even thought of in the past. So the complexity has really gone up, and I think security is is getting harder and harder over time, not easier. So it is interesting to see that change in that dynamic.
Initially, when I started, I thought, well, eventually, computers will self heal. Right? They'll self secure, and we found the opposite is true. It's actually getting harder, not not not easier.
Right. Well, biscuit systems are more complex.
And, there's a lot more of them, a lot more applications, a lot more, surface area.
And there's a lot more people out there poke trying to poke holes in it.
Yeah. No. It's true.
So so finding those vulnerabilities where, and it's I I believe it's only going to get worse. So so I think you're talking about automation of not just security controls, but also, like, you were talking about vulnerability scans and things that Yes. So knowing about your system.
So Right.
But, before we get to to kinda that topic, let's, let's first talk about breaches. We actually have a forensics, group, or forensic. Sorry. Forensics is the thing that the study or whatever and forensic group. But I got yelled at for saying that wrong.
So Not yelled at. Oh. Just reminded.
I what I mean is nobody would yell at me.
No. No. No.
I mean, usually Especially those guys.
Like, if I started it I'm just saying.
Yeah. Yeah. Okay.
I wouldn't start anything. Yeah. But let's talk about breaches. So you've you as part of this, having a forensic group and and being part of that, you've actually helped investigate data breaches.
Yes. In fact, I, I did the first nine forensic cases that we did as a company.
And so, Dave Ellis, who's been here for a long time He has.
And he's been on this show too.
Yeah. No.
And and he's great.
He is great. And he, so I I went out with Dave, and we, you know, we trained together and and, got him going. And then he's added people to the to the staff, and it's it's worked out really good. And because he's a he was a policeman Mhmm. He speaks the right language.
Right.
So when he talks to the government officials, they kind of know that he's a policeman and he's one of them. And I never got that luxury yet. They always kinda looked at me like, whatever.
He's got the vibe. He does. You don't have that vibe.
I know. I don't.
No. I know.
Yeah. So he does he does a much better job than I did, but, but it's fun it's fun to kind of see that and see how forensics has evolved and to see how it does shift. You know, when we originally had, when before EMV, before the chips were out, everything was retail based pretty much. Right.
We had some ecommerce, but not not that much. Now the lion share shifted as we went to EMV. So we we knew it was coming. We could look at the graphs from in in Europe when that happened, and and it's pretty much followed suit.
The same things have happened.
Oh, interesting. So you have the advantage of of having conducted investigations. And at the same time, now you're you're an executive. So you can kind of bridge that gap. As an executive, what advice would you give other executives on on dealing with a breach?
Well, I think I think the first thing that happens typically in a breach is emotion. So five stages of grief again. Right? And so once you've gone through that a couple times, you kinda see that.
I think you just have to realize this, you know, the sky is not falling and, that if you get a good group in, they're gonna help you. They're gonna represent you well. They're gonna help you fix the problems right away and get you to a place where you're going to be in a good state, you know, for for quite some time. And so that's really what we're trying to get people to understand.
So I think I think getting rid of the emotion and then being methodical, you know, there's the reality is there's a lot of legwork that needs to be done in advance, like notifications.
Right.
And so you can't really wait. Mhmm. And then find out that you need to notify because the time frames can be fairly short in some of these states because it's state by state. It's not it's not a federal mandate.
Sure.
So I think that's the thing is you've gotta do some leg work up front. And if you're prepared, you're gonna be in good shape. If you're not prepared, I think it's gonna be a little bit of a whirlwind Right. Because, there's some legal issues that get serious pretty quickly depending on the the type of breach you had.
So what what I'm getting from you is that plan for a breach even if you believe you are not gonna have a breach because your security is a plan for a breach breach, and what are you going to do if it happens?
Yeah. I mean, we we just have to assume that there's gonna be a vulnerability somewhere Mhmm. That's gonna bite you. And so being prepared, having a plan, I think one of the biggest problems with with people and their plans is they don't have anyone who's responsible ultimately to determine that a breach has happened, and the process starts.
Sure.
So if you don't have someone designated to do that and you don't have the criteria, then you may not state that a breach happened. You may not kick into your plan. But you you really need to have a plan, and if you don't, you're just gonna be it's gonna be ugly. Right.
And once you have the plan, you have to make sure that it goes through, and then you need to test the plan. I think that's the biggest thing. Everyone finds all of the problems when they test it. So Right. If you test we have, our auditing auditing staff will go out, and they've done that, for lots of organizations where we go out and just sit down. They go through a mock breach, and then we give them a write up and say these are the things that we witnessed that you may have been able to do better.
And that's where that's where I think everyone gets so much faster and better Mhmm.
And it becomes less emotional because you've done it a few times.
Right.
And, and then you just it's just a business process that you go through like any other business process. Right. And, and you can get through it.
Because if you're trying to figure something out that's new, like how do we respond to a breach while, emotions are elevated Yeah. Because of the breach Yeah. Then that's the worst decision making. That is the worst creative thought process.
And and have we crossed all of our t's and dotted our i's? I don't know. My hair's on fire. So Yeah.
What do you see, though, as the single biggest high level contributor to a data breach? What causes them?
I I think it's almost always lack of testing.
You know, in the software world, it doesn't work unless you've tested it. You can't assume it works. You have to assume it doesn't work.
And and I think that's what happens.
It's it's always a problem where somebody wasn't thorough enough. They didn't there was a human error.
You know, we didn't test that one server. Right? We didn't really think it was in scope. We didn't think it really mattered.
It was just this kind of a server. It doesn't matter. But it's still on our network. It's still trusted.
Mhmm.
It still had an open port through the firewall. You know what I mean? Those are the things that if you really sit and look at it, so I think that's the I think that's the biggest thing is, it's just hard to always be perfect, and all of you know, all the IT group is always gonna be perfect. Mhmm. And, I think that's the mistake that everyone makes is they just think, well, it won't happen. We've got really good guys.
Right.
You have to be testing. You have to be reviewing. You have to have pen tests. A pen test is really just somebody coming in, looking over your shoulder, and and testing it objectively. Mhmm. And they're they almost always find issues.
Right.
And and so, again, you get businesses that don't wanna spend the money. They think it they're it's not gonna happen to them. The odds are so low, but the the reality is the odds are high.
So those are the types of things I think that people need to be aware of.
I really like the the the thought that the testing is what what really gets us there. Because you can sit and have a, you know, a thought exercise all you want. But but the more intensively that test happens, the more the realities come up. And also, one of the things that I see a lot is that people think it's the IT group.
It's the developers that that make the Right. The the security or it is the the, sysadmins that make sure security is there. Or it's or they might even have a security group or they might have a compliance group. Like, somebody will will take care of this.
And so especially for some of the assessments that I do, which are against certain standards or things, and they'll just hand it to to them to deal with. But the business side doesn't get involved. And so I I think a lot of that testing that you're talking about, are the right people in the room for a response?
Well, there's only so far that, the operations team can go Yeah.
Before they go, this is the decision we can't make. This is beyond us.
Right.
We can't communicate to the outside. We can't when do we bring in our lawyers? We don't know. Like Right.
And so understanding that it's not just IT, but it's also the business side Yes.
I think that that helped that comes out in testing.
Yeah. And and it it really does, and it's really important an important point. We have a security council because everyone to your point, it's like it's the developer's responsibility. It's the IT responsibility.
We have, a security council, and we have smart people in the room like the forensics group even though they're not necessarily the group that we're as concerned about, but we also have the pen test group. We have all of these different groups coming together. Right. And then we all go through it and talk about it together, and it's all of our responsibility. And the council makes the decisions.
And and I think that's a real big deal because once you start to understand that these other groups can get you know, marketing can can push the wrong things out. Once you get all of the company together to understand it, they really understand the threat more, and then they're they're more they're they're less susceptible to fall for those those things. And we, you know, we I I mean, I had an example that I just I giggle about every once in a while, but one day I was walking by the receptionist. I'm not gonna tell you who.
And, she was answering these questions.
Brad Caldwell, CEO, Blake Stevens. And she was and I'm like so I just sat and listened.
And at and at the end, she had gone through company officers and given them their their name and their titles and all of this stuff. And I finally said, so, who is that? She goes, well, I get these all the time. And I and I go What?
What do you mean you get these all the time? And I never tested it. I never asked her that question. I never thought that that was a problem.
And that's the kind of things that pop up. How how do how could I even assume that that was gonna be something that was happening? People were calling and getting social engineering data. Uh-huh.
And she had no idea. She thought it was her responsibility to provide the data because somebody asked, and she wanted to provide good customer service.
Right.
So I had to have a conversation, and then then we could go through. But, you know, you won't make that mistake again. And that's how it is with these, you know, going and testing. You'll you'll test and you'll all of a sudden find something, and then no one will make that mistake again.
Right.
And that's that's it's such there's so many points of entry. There's so many vectors that it's really hard to wrap your arms around all of them.
Right.
But you really have to try hard and you have to be diligent or it's not it's never gonna happen and you're gonna get you're gonna be in trouble.
Right. And and it, all it takes is one.
So, you know, it got cold here this week here in Utah. Like, really cold all of a sudden. And our chickens are fine just in case anybody was worried about them. We have the it's they're warm and they're snug.
And we had you know, they're they've got the water. It's not frozen or any of that because we had taken care of that for them. Right. The rabbit cage, not so much.
And all of a sudden, we have two more rabbits. So now I have three rabbits. Right? And this cold snap pits.
And I'm like, we can't leave them out there. They are not prepared for this weather, and we didn't give them the right so we have rabbits in our living room.
Yeah. I'm that kind of house.
And Do rabbits smell? Yes.
Okay. Yes.
I just thought I'd find out about that.
They do. They're not as bad as chickens. But really I mean, the only thing worse than chickens is maybe ducks.
I'm glad you don't have chickens in your living room.
No. That would be bad. Yeah.
That would be bad.
But I do. I have three three rabbits in my living room, which wouldn't be bad. But I also have a husky German shepherd mix that my daughter has in my living room. Oh. And so she sits outside of their cages and stares at them and waits. And every once in a while, she will lick her chops. And I thought, this is just like cybersecurity.
Yeah. Right? I can do everything right sixteen days in a row. And on that seventeenth day, if I forget to latch this latch, that dog is going to eat those rabbits.
Yeah.
Right? And that's Yes.
And that has been your farm bit for the minute. Yeah. But that's like data breaches. Right?
Yeah.
You could do everything right for months. You can do everything right for years.
And then you have one little weakness in your systems No.
You're right.
And suddenly have dead rabbits in your living room.
Yeah.
And I think this idea that it's not going to happen to them maybe is because they've had sixteen days of of Yeah. Security. Yeah. And and and people get complacent.
But, there's a lot to lose with a data breach. Right? There's there's a lot to lose. So Yeah.
Why do you think with with the potential so there's laws that can be broken. There is standards. There's fines and fees. There's different impacts.
But also, the financial impacts to your business from losing specific types of information. Anyway, I'm preaching to the choir. You they're they're real world impacts to a business, and yet I still see there are c levels who are not engaged in the concept of security for their companies.
Why But they think that's not gonna happen to them.
They just they're convinced. It's like it's like, you know, I I remember the early days when DOS was out, and viruses started to came out. And everyone said it's not gonna happen to them, and then nobody bought antivirus. And then as soon as it happened to you Mhmm.
Guess what? That's when you said, oh, it can happen to me, and you went and you spent the money. And you get the same mentality. It's it's the exact same thing.
Oh, I've got these super complicated systems, and I've got all of these servers everywhere.
And, but I'm gonna be secure. I'm sure I'm gonna be secure. I'm sure my configuration's a hundred percent and that there's never gonna be any problem, and there's never gonna be a patch that has a problem. And and it's just you know, as soon as it happens, they they they they hit themselves on the head and go, why could I how could I have thought that? Right?
Right.
But it's because it doesn't happen. And I remember going through that as well where I didn't buy antivirus because it was it cost money, and I was younger, and I didn't felt like I have the money. Right.
And as soon as it happened, I went and bought and put on my laptop because I didn't want that to happen again.
And, you know, that that concept of it's about the money. Right? As as a sea levels, they have to make decisions. Yeah.
Where am I going to put this budget? It's not an unlimited amount of money. Yeah. Right?
So how how do you help other c levels around you or people who talk to you? How do you help them justify the expense of security?
Well, I I think, you know, the best thing to do because I did the first nine forensics cases Yeah. I experienced that. You know, I experienced the guy going, why did my acquirer not tell me about this? Yeah. And and I had to say, I don't know. You have to ask them. But I knew the answer.
You know, it's it's when you go through that and when we see it. Mhmm. And, you know, I I I remember a year ago, we had a lady, a small business in Salt Lake, and she, you know, came through some friends of ours. And, you know, I sat on the phone while she cried.
Yeah.
She never got her data back. The FBI told her not to pay the ransom, which I understand. Yeah.
We verified that the hacker could decrypt it.
Mhmm.
But she didn't wanna do that. And so all of her data, all of her accounting data since she started the business was lost. Mhmm. I mean, we actually see those happen Yeah. Over and over again. So for us, it's it's really obvious that you should be doing have.
You should be doing this thing.
Somebody who's never seen it, it's just like I was. I when I I found that same trap. Yeah. I don't wanna I don't wanna justify the expense. I'm I'm not I'm not gonna do that. Yeah. And it's it's really not a a wise strategy, but I understand why it happens.
Yeah. Okay. So, I I'm one of your auditors. I don't know if you knew that.
I did know that. I did know that.
Of course, you knew that. And so I I do a lot of work, as a cybersecurity analyst with customers. Like you said, the the people who have either dealt with a breach or who are are need to to meet PCI DSS or HIPAA or, you know, one of these various things. And one of the things that that I see a lot when I go in to try and and evaluate what's going on and give them a good report and so give them something that they can, you know, take and and use.
I see them hand off. I see leadership hand off the responsibility for cybersecurity to people in other departments. And I think that there might be a balance there. I think that there might be a Mhmm.
Hey, let's designate this. But but a lot of times, it's almost a disengagement from it. How can I I don't know? How can I help them be more engaged?
Well, and that's that's tough. Right? Because, again, you get you get the filter of it's not gonna happen to me, and, this is just a nuisance. I mean, we we tend to see that a lot. You know that as you go through the audits. Mhmm.
Can't you just not make us do that Yeah. Secure thing?
Nope. Can't not do that.
But but, I mean, that's the that's the kind of thing you get. They you know, they're busy doing other things, and so this doesn't seem to be the priority. And and the reality is is we're getting to a point where security needs to be a priority.
Right.
And, we're getting people coming to our website, that are bounty hunters Mhmm.
And helping us to understand that they think there's a problem and and and there isn't. Mhmm. You know? But, that I mean, what are you gonna do as a business when that starts to happen to you, and it's gonna happen to all businesses?
And so, you know, the the days that security could be a a third priority Mhmm.
Are are quickly gone.
Right.
And, as we get more sophisticated, you really need to be on top of it, or you're gonna have to go through the process. And anyone who's going gone through the process of notifying in all the states, hitting all the deadlines, all the timelines, getting the fines and penalties because they're because they're real, and we we deal with that.
And and to have the business impacted in negative ways, having customers do lawsuits, you know, it's just it's just not worth it. So, you know, we can say it and they, you know you know what it is. When you go say it, they go, well, that you're just you're just pitching me.
Right.
You're selling me.
Yeah. Don't sell me. We don't why are you using fear tactics?
Yeah.
It's like, well, because We're all trying to.
Because we see it. Yeah. It's real. And I don't want to have the lady crying on the phone with ransomware. Yeah.
And and so, you know, people just need to understand that it's a reality, that it is happening. You can roll the dice if you want. But the reality is antivirus kinda caught up with all of us, and we all ended up buying antivirus. Right. And I think that's how security is. It's gonna catch up to all of us. Right.
And so they they really need to just understand that instead of waiting until I get hacked, I should make it a first priority now and not have to go through the hassle and the pain and and the suffering that you go through, the five stages of grief.
Sometimes I talk to, like especially, like, the IT teams or security teams, and I'll say, hey. You know that you need this.
What's the what is the blocker there for you? And, one of the common answers that I get is, you know what? They're just old, and they don't get technology.
And then I meet the the c level, and they're, like, in their fifties.
I'm like They called someone in their fifties old.
Dude, fifties is not old. Just because you're look.
Yeah.
Hey. So I am a what is it? Gen Xer where where you you adapt to technology like a millennial, but you're mad about it like a boomer. Right?
So That describes it. Yeah. Totally describes it. And so, it's like, how do we I think it's not an age thing.
But, you know, for people who are nontechnical and haven't grown up with the technologies, part of it is, do I know these just because I've lived it? No. But can you learn it even if you are what we call nontechnical? And I think that's such a dumb word.
Someone who is really, really smart at running a business can be really, really smart at running IT. You know, we're we're all a white belt at something and we all take time to learn something. We can learn it. Mhmm.
But maybe it's about if you're a c level and you don't have the time or don't wanna commit the time to understanding the technology. Maybe there's other ways that you can make good decisions based on leaning on, I don't know, good people that you hire.
Well, yeah. I I mean, you you can. There's no question that you can. I I think for the people that aren't in technology, they don't understand they don't understand the granularity.
Mhmm.
So I'll I'll give you an example. We have a security council. We get everyone together, and we meet regularly, and we all talk about new products coming out. We have rules.
If it's if it's a backup, you can reinstall it without getting the security council. But anything else has to go through the security council. We have to look at the architecture. We have to see how it's done.
I mean, we have everyone in agreement. We are all a bunch of security people.
Mhmm.
So it's as easy as it gets for anyone to us. Right. But it's hard for us.
Yeah. It is hard.
And so you get somebody who's nontechnical. And what does that mean? It means they just have no understanding.
Mhmm.
They really shouldn't be making the decisions for their company on security because for us who are technical and who are in the space Mhmm. Even knowing everything, having free access to scans, we can scan ourselves as much as we want, right, every day, and we do. Yeah.
Still, security is is hard.
Yeah. Yeah.
It's it's it's a process. It's it has to be a priority because if it's not a priority, you just won't do it.
Yeah. Yeah.
And and I think that's what they don't that's the part they're missing is that even if I have everything dialed in the right way and I'm and everything's lined up for me to be secure, it's really, really hard. Is it possible that somebody in development pushed a new feature, you know Mhmm. In in all of our code that was new Yeah. Even though it didn't go through the security account.
I mean, that's that's the problem you get to. It gets really tough in the implementation stage to really dive into everything perfectly. Yeah. And and I think I think that's what they don't understand.
So they just look at it and are kinda blowing it off.
Mhmm. We have antivirus. What else do we need?
Yeah. Yeah. And, you know, I I I actually talked to a guy in February before the COVID hit.
Mhmm.
And, there was a there was a meeting with a bunch of us, and I just it was just potluck. And I was sitting across the table from this guy, and he had so I asked him what he's doing, and he he scaled Everest.
Wow.
And I said, cool. You scaled Everest. So I started asking him all the questions. How much air did he breathe? One point five liters up and point five liters down.
And, you know, and he said, coming down, you only use point five liters.
And he said, most of people die on their descents because they're using so little oxygen Oh, really?
So little air. And he goes, so my my friend and I decided we were going to ask ourselves, simple, math problems.
Oh, okay.
Because we're gonna stay sharp. Right? So he goes, we're gonna do that. And so he he did. They said so we'd ask questions like, what's seventy plus thirty?
And he goes, I remember distinctly thinking it doesn't matter Because my mind, instead of saying I can't tell you that Uh-huh.
It said it doesn't matter.
Oh, that's interesting.
Behavior that we need to understand because that's really what's happening to these people. Yeah. I'm not a security person. Uh-huh. It doesn't matter.
Right. Because they don't have the context to make those decisions.
Therefore, the brain goes And if you can think about it that way, that it's a human behavior thing Sure.
They're gonna naturally say, well, I don't know anything about it. I I can't deal with it, so I'm just it just doesn't matter. And the reality is it does matter. Mhmm. And it's typically a matter of time before they find that out. And that's the sad part is that we have to come in and and and and fix that at the end.
And more information is is important.
I I really like working with a lot of the people who have to to meet HIPAA compliance because there's they don't have a checklist of things they have to do. And therefore, they have to say, alright, where are we now? And what can we do to improve our security stance? I find that a very creative and compelling problem to help people with.
So, last year, I had a group that I said, look, guys. You're to the point now where you need, a SIM. You need an event management. You need you need to be able to see what's going on in your systems so that you can recognize potentially, potential indicators of compromise and then react to them.
And it was it was not an easy sell because this was such a new concept to them. And, just last week, I had a a phone call with one of them, and and I said, so how how's that going? He's like, we are catching things. We're seeing things going.
And I I just said, that's that's amazing because it's it's again, it's like if you have insight and knowledge into things that are going on, you know what how to react to them. Yeah. But if you have no insight into the security and the activity in your in your systems, then you can't make those good decisions.
Yeah. So you don't know where to start. Right?
Yeah.
And that's that's one of the most satisfying things about our SOC product is we actually are stopping people from, you know, hackers coming in from other countries trying to get into their financial server. We can see it in real time.
Right.
We can contact them, let them know, and they can shut it down, and there's no there's no incident.
You know, that that site so some people might not know that we have a a managed SOC here, but we had, Heff and, Forrest on one of the podcasts to talk to us about it. But, maybe just just for the people who didn't see that episode, maybe talk a little bit about the SOC product and and what that is about.
So what we have is a product you know, historically, big enterprises could afford a SOC. Mhmm. Right? And so they they had that benefit, but small businesses could never do that.
Right.
And so one of the things that bugged me as a smaller business. Right? Sure. And and our business was a lot smaller at the beginning, but, is that the enterprise people had this luxury, but none of the small businesses did. So what we've done is we've created a product where for a a small monthly fee per location, we will monitor all the traffic coming in and out. Now we're not monitoring the actual data Right.
Because that there's privacy because there's privacy and it's But we're we're we're understanding all the packet, metadata so that we know where it's coming from and going to.
Mhmm. And from that analysis, we can start to see as soon as there's a shift, as soon as there's a problem. And then we can also say from our threat feeds, is that a known bad site?
Right.
Oh, that's a known bad site, and all of a sudden traffic went. Okay. Alarm. And we and we contact.
And and I just for the people who who are unfamiliar with what SOC means, it's a secure security operations center.
It's SOC. So yeah. Very cool.
Yeah. So it's good to have those kind of products, right, that actually help people and stop stop the incidents from occurring. That's that's what we're all about.
Right. So that kinda brings me to my my next question, which is, insight into cybersecurity stance. So, in addition to a SOC, what other ways can, and specifically because we wanna talk about security metrics today. What other types of things can people use to to improve their cybersecurity stance that the if they can't hire their own have their own internal staff? What else is up there?
Well, that's that's a real problem. And you keep reading articles that are saying that the shortage of cybersecurity people is millions. Yeah. Right?
It's not it's not like, you know, a hundred thousand. It's millions. And so they can't really go hire someone. They can't afford it because those people are really expensive right now.
So smaller businesses just can't do that. And so the thing to do is to hire and outsource a lot of that.
Right.
So if I can, if I can look at my, vulnerabilities on my on my public facing servers, if I can do pen tests annually, if I can use a SOC system where I can monitor traffic.
You know, the thing that's interesting is that, that product has found people that have been hacked for over a year. Their data is being actively stolen on a daily basis.
And I didn't know about it.
No idea. Yeah. Because if I can most people rely a hundred percent on antivirus. Mhmm. But that's really what we're about is trying to add layers.
Yes.
If I can add layers, and if one layer fails, the other layer will pick it up. So relying a hundred percent on antivirus, you know, I I get the antivirus. You should do that. But then what are your other layers? And that's why having a product like this sock, they this this this person had a, had an antivirus that was functioning installed, but the people had circumvented it.
Right.
And so they were completely naked, and they got they they got hacked. And it was and it was deep. I mean, we we had to go in and help kinda figure that out with them. And so it's it's really fascinating.
If you can think about it like you would a bank and all the layers Mhmm.
We offer cyber products that pretty much coincide with that, and and we can help you add layers to your systems so that and it'll cost you a little bit more, but you get that feeling of security.
And, and then the other thing is training, and we offer training. That's really important, just like my receptionist story.
Yeah.
Sure. I I had no idea. And so those are the things that are are important. And if they can add those layers, get the training, do all of these things, their security posture is much better. And there's hope.
So do you think training is the way to, make data security part of a company culture? Or do you think training is a is just a part of that?
Well, I I think it I think you can do some fun things with it.
We you know, we've we've done some really creative things, and had really good success. So, I know the audit team, your your team, and this was years ago. They went and created a site, that was one letter off of of a site, and, they spidered all of the the website of of the company we were working for.
Mhmm.
And then they, created a username and password basically into this site. You just had to log in to the site, and so they sent this email to all of the public emails they could find on this company, and we had, like, a ninety five percent click through.
Yeah.
I mean, it was just incredible because it looked like their site.
Yeah. And when you glance up at the top, it looked like their site. So they had it extremely high. And, you know, we were told we were we were cheating.
Right?
Fishing's not cheating. Fishing is real.
Yeah. But I mean so what do you do as a culture? Because, you know, you really quickly can get to this point. If you're not misspelling everything, the grammar isn't bad, and the site doesn't look terrible. Mhmm.
People will click. Yeah. And so it needs to be part of your culture. You can have fun with it.
Mhmm.
You know, when you go to places like Defcon, they have the wall of shame and they have, you know, you know, so, I mean, those are the types of things that are fun.
And you can you can do those. We we do those here. We'll, our IT staff will send off every quarter some fake, phishing emails. And it's and it's fun to get them and to recognize them. And then they come back and they give you a report, and they tell you if you passed or failed.
Yeah.
I get all excited about them, so I go in and look at them. And so I I they they always mock me. But, but it is really fun. And I think that that's where the culture gets can get really fun when you get into the training because training can be fun.
It doesn't have to just be sitting there and staring at a screen Yeah. But seeing the acronyms for an hour. Yeah. It really can be something that's practical.
The the people that I talk to at different companies that we serve, the ones who really get excited about the training and foiling those phishing campaigns are are your your frontline like your receptionist. Right? Like, people who people who are not in IT, people who are learning about security maybe a little bit for the first time. And they get excited about it because it it helps them, like, feel like they have skills that they can translate, not just their their jobs, but then they're they're home and they get a phishing, email or a phishing text.
My son got a text. He was sure was from Amazon telling him to to change his passport, but it was from my account. I'm like, why would you get that for my account? Right?
And so he's like, but you gotta check it. I'm like, this is a this is a fishing camp. Do not click through.
Yeah.
So, it it's one of those things where, we are in our just our day to day on a regular basis, we are hit by, people who want our information. You know? And and I'm starting to see sales campaigns that mimic phishing campaigns.
And, like, your well, well, I mean, the one we all know about, your warranty on your car is we've been trying to reach you. Yeah. Really? Because I don't have one.
Yeah. And you you know and and so people who pay bills because they think this invoice is real. Right? So the more you kind of start questioning, is this real or is this person just trying to get something from me?
Yeah. So it it helps people. And and what I see is the people who get this training at work turn around, use it at home, and are so excited to tell me about these these stories of where they helped their grandma or they Yeah. They themselves foiled something in their lives, and I just love those.
Yeah. No. It is it is fun to help people and to help them understand that there are people who have nothing better to do than to try to scam you Yeah. All day.
All day.
And that's their job. So it is it is it's a little disappointing, you know, at some level that people are doing that, but it also is gratifying to be able to help people and make sure they're they're not caught in a bad way. Yeah. Or they're not big repercussions because of, you know, something that they they found on their computer in a phishing email.
Alright. Great. Well, before we wrap up, what's, what's your favorite part about, leading security metrics?
It's getting to work with all of these great people like you.
Like me.
And Hunter.
Hunter's awesome, isn't he?
Yes. It is.
Hunter is our producer, and we just love him.
Yes. So, no. That's I think that's the fun part is that we have a good team, and and and you know that. And, we have people that have been here a long time Yeah.
Which is also great. And in the security industry where there's millions of jobs shortage Yeah. Right? Yeah.
It's kind of fun to be at a company that there's there's a lot of people. We have pretty high retention rate. Yes.
And, For for good re you know, every time I speak and I speak at a lot of conferences now.
I used to get to travel for them. I'm supposed to be in Saigon next week. But so sad I'm not. Anyway but every time I would go to one of these on-site things and speak, I would get two, three, four, five job offers at one thing. And my answer's like Yeah. No. Because, there's a level of trust and autonomy and and drive here and and enjoyment of being part of a a security company.
So whatever you're doing, keep doing that because it makes me happy.
And Wellness and I'm glad that you're here, Jen, because you're fun. And you're Canadian Yeah. Which is also very cool.
Right. Oh my gosh.
You just shouted me about the Canadian thing.
Oh, sorry.
No. Actually so, yeah, you and I shared some childhood, areas. Like, we Yeah.
Our little towns in Southern Alberta Yeah.
Were very, very close to each other. We have both milked cows and ridden horses and gotten gotten dirty doing dirty farm things.
Yeah.
All of those fun things Yeah.
That we thought were really fun when we were when we were younger.
You know, I remember mucking out of a barn once because it was a beautiful day and it needed to be done. I'm like, Yeah. I'll do this. And I look back and go, Wow.
Yeah. I need to recapture that. Yeah. Because those bunnies really do smell.
No.
I I know that you I actually knew somebody that had bunnies in their living room. So that's why I asked you because every time I walk in their house, I go, oh my goodness. Those bunnies smell.
They're not gonna be there forever. But they have to be there at least until the first week of November, and we have a little time. So Halloween is a big deal for all the people in my house. There's work involved at local, you know, haunted houses and things that that the crew goes and works on. But, we'll we'll get them outdoors before too long. But for now, we get to enjoy that earthy, earthy smell.
Yeah. Yeah. Yeah. I'm I'm glad you're the one smelling that.
I appreciate you coming and talking to us. And and everyone, thank you for enjoying us at this, this this last episode of the season one podcast. I've really enjoyed talking to all of the people that have been willing to come and and speak with me and and hopefully looking forward to if I'm lucky, get to do it next year.
Talking to more people and getting some great if you have ideas on people that you'd like to hear from, don't hesitate to reach out. We'd love to hear from you. Take care.
Thank you, Evan.
Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the right. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.
