1 00:00:00,049 --> 00:00:03,649 You found the backup wrap up, your go-to podcast for all things 2 00:00:03,649 --> 00:00:05,989 backup recovery and cyber recovery. 3 00:00:06,559 --> 00:00:11,599 This week we look at network segmentation and how it can prevent ransomware from 4 00:00:11,599 --> 00:00:13,250 tearing through your organization. 5 00:00:13,879 --> 00:00:19,039 My co-host persona and I, uh, talked to Dr. Mike Saylor, my co-author on 6 00:00:19,039 --> 00:00:21,139 learning ransomware response and recovery. 7 00:00:21,679 --> 00:00:23,989 Uh, and we talk about, first off, we. 8 00:00:24,349 --> 00:00:28,549 Talk about what it actually is, uh, what VLANs are, how they figure 9 00:00:28,549 --> 00:00:33,019 into this, uh, the need to talk principle and also micro-segmentation. 10 00:00:33,469 --> 00:00:37,429 We started with the, the UCFS ransomware attack as a good case study. 11 00:00:37,759 --> 00:00:42,139 They did get hit, but they weren't destroyed basically because they got this. 12 00:00:42,754 --> 00:00:43,294 Right. 13 00:00:43,804 --> 00:00:48,454 Uh, we talk about how to, to do this without destroying everything. 14 00:00:49,024 --> 00:00:50,584 Um, not that I've ever done that. 15 00:00:51,574 --> 00:00:53,944 Anyway, just a quick note about me. 16 00:00:54,004 --> 00:00:59,614 I'm w Curtis Preston, AKA Mr. Backup, and I've been obsessing over backup recovery 17 00:00:59,614 --> 00:01:02,764 and now cyber recovery for over 30 years. 18 00:01:03,124 --> 00:01:04,714 If that's your bag, then I'm your guy. 19 00:01:05,224 --> 00:01:08,434 You're not gonna find anyone that cares about it more than me. 20 00:01:08,945 --> 00:01:13,354 Ever since 1993 when I had to tell my boss there were no backups of that 21 00:01:13,354 --> 00:01:15,214 production database that we lost. 22 00:01:15,845 --> 00:01:18,574 Now I've written five books, a blog and a podcast. 23 00:01:18,964 --> 00:01:22,744 Here we turn unappreciated admins into Cyber Recovery Heroes. 24 00:01:23,044 --> 00:01:25,234 This is the backup wrap up. 25 00:01:40,791 --> 00:01:42,091 Welcome to the backup wrap up. 26 00:01:42,091 --> 00:01:47,731 I'm your host, w Curtis Preston, AKA, Mr. Backup, and I have a guy who continues to 27 00:01:48,211 --> 00:01:51,091 surprise me at the stuff he knows about. 28 00:01:51,091 --> 00:01:54,481 I don't remember what it was, persona, but just like the other day we were 29 00:01:54,481 --> 00:01:58,891 talking and you were like, do you, do you, you started talking about 30 00:01:58,891 --> 00:02:02,281 something else where you're like, are you surprised that I know this? 31 00:02:02,611 --> 00:02:04,651 And then, it was something yet again. 32 00:02:05,146 --> 00:02:08,956 I'm like, of course you are aware of the, I don't know what it was, 33 00:02:08,956 --> 00:02:11,296 but something persona, Molly Yondi. 34 00:02:11,296 --> 00:02:11,686 How's it going? 35 00:02:11,686 --> 00:02:12,106 Persona, 36 00:02:12,840 --> 00:02:13,560 I am good. 37 00:02:13,560 --> 00:02:16,740 Curtis, you know what it might have been, was it our discussions around POE? 38 00:02:18,116 --> 00:02:19,136 probably was about P oe. 39 00:02:19,406 --> 00:02:19,796 Yeah. 40 00:02:19,896 --> 00:02:20,136 yeah. 41 00:02:20,136 --> 00:02:24,396 The, exactly the power over ethernet for those uninformed, I've been, 42 00:02:24,726 --> 00:02:29,126 I've been living POE quite a bit, lately because I've been, re, re. 43 00:02:30,371 --> 00:02:33,701 Basically reinstalling, you know, replacing all of the 44 00:02:33,701 --> 00:02:35,201 cameras in a, in a, yeah. 45 00:02:35,201 --> 00:02:36,041 Updating, thank you. 46 00:02:36,041 --> 00:02:40,001 Updating a, a p OE based security camera system for a preschool. 47 00:02:40,991 --> 00:02:42,341 And it's been, it's been a journey. 48 00:02:42,611 --> 00:02:46,811 and, lots of, lots of time on ladders and, you know, good times. 49 00:02:46,871 --> 00:02:49,681 I have yet to, you know, fall or anything. 50 00:02:49,741 --> 00:02:51,721 I have drawn blood at least once. 51 00:02:52,291 --> 00:02:53,281 But anyway, so. 52 00:02:54,556 --> 00:02:55,336 It is expected. 53 00:02:55,546 --> 00:02:56,146 but anyway. 54 00:02:56,566 --> 00:03:01,096 And then we have our Intrepid cybersecurity 55 00:03:01,096 --> 00:03:03,196 professional, Dr. Mike Saylor. 56 00:03:03,196 --> 00:03:03,976 How's it going, Mike? 57 00:03:06,207 --> 00:03:07,437 Well guys, thanks for having me. 58 00:03:07,936 --> 00:03:11,736 Yeah, I am, you know, no one at home knows how much effort we went 59 00:03:11,736 --> 00:03:14,076 into today to get you to sound 60 00:03:16,866 --> 00:03:18,961 we were having, we were having so much difficulty. 61 00:03:21,317 --> 00:03:22,637 microphone, troubleshooting. 62 00:03:22,746 --> 00:03:25,436 Yeah, that was, something I, yeah, 63 00:03:25,765 --> 00:03:26,425 But, but wait. 64 00:03:26,425 --> 00:03:27,985 Curtis, before you go on, I think 65 00:03:28,046 --> 00:03:28,556 yeah. 66 00:03:28,855 --> 00:03:32,245 You should probably sort of give a bit of background about Dr. Mike 67 00:03:32,756 --> 00:03:34,076 Yes, yes, 68 00:03:34,255 --> 00:03:37,195 I know we have, we've been having him on a bunch recently on the 69 00:03:37,256 --> 00:03:37,946 yes. 70 00:03:38,515 --> 00:03:40,165 I think it might be worthwhile. 71 00:03:40,616 --> 00:03:46,306 Yeah, so Mike is the, co-author on this book here, learning 72 00:03:46,336 --> 00:03:50,776 Ransomware Response and Recovery that was published just last month. 73 00:03:51,016 --> 00:03:55,426 Although he and I are still, it's, it's so new that he and I are still waiting 74 00:03:55,426 --> 00:04:00,986 for our own little copies and, it's gonna be like a competition, like a, like a, 75 00:04:00,991 --> 00:04:06,566 we need a. We need a, a pool to see who gets their, who gets their copies first. 76 00:04:06,596 --> 00:04:11,486 Mike, of course was the, he did the cyber part of this book, and I did 77 00:04:11,486 --> 00:04:13,916 the backup and Dr part of this book. 78 00:04:14,276 --> 00:04:19,056 And, honestly, I think it was a, it was an incredible, I was about to say marriage. 79 00:04:19,086 --> 00:04:20,616 let's not do that partnership. 80 00:04:20,676 --> 00:04:21,876 Incredible partnership. 81 00:04:22,086 --> 00:04:24,401 And that, Mike, I don't know if I told you, but the, but the, the. 82 00:04:24,896 --> 00:04:28,196 Our editor said that she had actually never seen a team that worked as 83 00:04:28,196 --> 00:04:30,476 well together as you and I did. 84 00:04:30,546 --> 00:04:35,256 because I mean, you, it was such a clear delineation of expertise. 85 00:04:35,596 --> 00:04:37,456 and you clearly know your stuff. 86 00:04:37,456 --> 00:04:38,806 I clearly know my stuff. 87 00:04:39,136 --> 00:04:44,056 And, this is one of those books where you really need stuff on both sides, right? 88 00:04:44,536 --> 00:04:45,706 And, many of our, 89 00:04:45,830 --> 00:04:45,990 like 90 00:04:46,186 --> 00:04:46,696 what's that? 91 00:04:47,451 --> 00:04:49,431 And it doesn't feel like two separate books. 92 00:04:49,431 --> 00:04:49,821 Right. 93 00:04:49,871 --> 00:04:52,721 we, we worked really hard to keep the voice consistent. 94 00:04:52,781 --> 00:04:57,961 and, you know, that was, you know, Mike is clearly way smarter than I am, so I just 95 00:04:57,961 --> 00:04:59,671 have to use lots of big words when I talk. 96 00:05:00,271 --> 00:05:04,421 So, but yeah, so that's, that's, why Mike has been visiting us so much 97 00:05:04,421 --> 00:05:07,751 on the podcast and will continue to do so for the foreseeable future. 98 00:05:08,621 --> 00:05:14,291 Today we're, gonna talk about another cyber related topic. 99 00:05:14,291 --> 00:05:16,241 And Mike, why don't you start us off with a story. 100 00:05:17,241 --> 00:05:20,801 there's, there's so many good stories, but one of the stories we'll talk about is, a 101 00:05:20,801 --> 00:05:22,881 healthcare, healthcare related, because. 102 00:05:23,556 --> 00:05:27,096 they are one of the high, highest, targeted industries, 103 00:05:27,176 --> 00:05:28,316 for a number of reasons. 104 00:05:28,656 --> 00:05:33,036 one, it's easy to leverage them if you can bring the hospital down and, you want to. 105 00:05:34,016 --> 00:05:37,496 You wanna get paid in return for restoring hospital operations. 106 00:05:37,496 --> 00:05:38,696 That's, that's good leverage. 107 00:05:39,866 --> 00:05:45,566 patient data is pretty valuable, both from a identity theft perspective, 108 00:05:45,566 --> 00:05:49,166 but then believe it or not, big pharma and some of these other less than 109 00:05:49,166 --> 00:05:53,786 reputable companies are willing to pay for patient like oncology reports 110 00:05:53,786 --> 00:05:57,416 and like, what could we sell this person, or what data could we use to. 111 00:05:57,441 --> 00:05:57,561 I. 112 00:05:58,496 --> 00:06:00,806 Promote our new drugs or, or procedures. 113 00:06:00,806 --> 00:06:02,006 So there's a lot of reasons for that. 114 00:06:02,006 --> 00:06:07,616 But nonetheless, university of, California, San Francisco, u 115 00:06:07,666 --> 00:06:09,884 U-C-S-F-U-C-S-F. 116 00:06:11,167 --> 00:06:13,837 you know, in an industry full of acronyms, sometimes I get 'em wrong. 117 00:06:14,257 --> 00:06:18,437 so University of California, San Francisco, got hit with ransomware. 118 00:06:18,887 --> 00:06:19,547 When was this? 119 00:06:19,692 --> 00:06:20,652 how it happened, but. 120 00:06:21,657 --> 00:06:22,167 when, 121 00:06:22,307 --> 00:06:22,667 Yeah. 122 00:06:23,437 --> 00:06:25,417 it's probably like five, five years ago, 123 00:06:25,617 --> 00:06:25,857 Yeah. 124 00:06:26,047 --> 00:06:26,527 maybe. 125 00:06:27,847 --> 00:06:29,917 which is, which is another, another. 126 00:06:30,922 --> 00:06:34,132 of the, of discussion is, you know, the, even, even though it's been 127 00:06:34,132 --> 00:06:37,702 five years, the, the way bad guys compromised them and, and how that 128 00:06:37,702 --> 00:06:39,652 whole thing went is still current. 129 00:06:39,702 --> 00:06:43,992 it's still stuff that happens today and yet, you know, tomorrow, you 130 00:06:43,992 --> 00:06:46,752 know, it's nothing, nothing that we've done in the last five years 131 00:06:46,752 --> 00:06:48,552 have has helped mitigate this. 132 00:06:50,427 --> 00:06:54,017 And in this particular case, it was, what we believe or they believe 133 00:06:54,017 --> 00:06:56,157 to be, compromised credentials. 134 00:06:56,207 --> 00:06:57,527 so it wasn't a phishing attack. 135 00:06:57,527 --> 00:07:01,277 It wasn't, you know, bad guys, you know, truly kicking down the door. 136 00:07:01,697 --> 00:07:05,927 it was, it was likely remote access or VPN credentials that were, 137 00:07:05,927 --> 00:07:07,697 were harvested some other way. 138 00:07:08,507 --> 00:07:11,597 whether they were easily guessed or, you know, former employee didn't 139 00:07:11,597 --> 00:07:12,977 get turned off, that kind of thing. 140 00:07:13,667 --> 00:07:18,257 so ransomware group got access, deployed their ransomware, and, you 141 00:07:18,257 --> 00:07:20,087 know, people started having a bad day. 142 00:07:23,057 --> 00:07:26,277 The good part of that though is, I think the topic of today, 143 00:07:26,277 --> 00:07:28,257 which is network segmentation. 144 00:07:28,677 --> 00:07:32,247 this environment was very well segmented for. 145 00:07:33,697 --> 00:07:34,657 Any number of reasons. 146 00:07:34,657 --> 00:07:37,637 One of them could just be compliance, hipaa, HIPAA compliance 147 00:07:37,637 --> 00:07:40,067 and healthcare, strongly advises. 148 00:07:40,067 --> 00:07:43,697 If not, in some cases, when with regard to confidential or sensitive 149 00:07:43,697 --> 00:07:49,267 information like healthcare records, requires, segmentation, this group. 150 00:07:50,467 --> 00:07:54,427 Did very well at segmenting their core IT environment from their, 151 00:07:54,817 --> 00:07:57,607 healthcare operating environment, from their lab environment. 152 00:07:57,997 --> 00:08:01,357 And so when, when one part of that network got infected, it 153 00:08:01,357 --> 00:08:04,027 was contained that segment. 154 00:08:04,430 --> 00:08:04,910 Mike, 155 00:08:05,010 --> 00:08:07,470 and that's one of the reasons why this DISEN environment 156 00:08:07,470 --> 00:08:08,550 didn't completely shut down. 157 00:08:08,923 --> 00:08:12,853 and Mike, for some of our listeners who may not be as familiar with the 158 00:08:12,853 --> 00:08:17,053 network side of things, could you provide a bit more context around 159 00:08:17,053 --> 00:08:18,733 like, what is network segmentation? 160 00:08:18,733 --> 00:08:21,968 Why is it important, that sort of thing as we walk through this. 161 00:08:24,300 --> 00:08:24,660 Sure. 162 00:08:24,760 --> 00:08:27,280 and there there's a, there's a number of analogies we can use in the, 163 00:08:27,280 --> 00:08:30,340 in the book we talk about kind of comparing it to a warehouse where 164 00:08:30,340 --> 00:08:33,400 you'd have different sections of the warehouse, even if it's just two. 165 00:08:33,400 --> 00:08:36,775 You've got the office air condition section, and then The warehouse 166 00:08:36,775 --> 00:08:38,275 on air conditioned section. 167 00:08:38,665 --> 00:08:41,185 in my case, when I worked at a warehouse, at least the bathroom 168 00:08:41,185 --> 00:08:42,505 was in, was air conditioned. 169 00:08:42,505 --> 00:08:44,095 So that's where I went to take my naps. 170 00:08:44,515 --> 00:08:50,315 But, in, in company environments, if you can, if you, and, and it's not just for 171 00:08:50,315 --> 00:08:54,605 security, it's also for management and maintenance and, and bandwidth control. 172 00:08:54,605 --> 00:08:58,625 I mean, there's a lot of benefits to network segmentation, backups, And 173 00:08:58,625 --> 00:09:00,095 there's different ways to approach it. 174 00:09:00,095 --> 00:09:01,655 So there's strategy behind this too. 175 00:09:01,655 --> 00:09:06,605 It's not just, you know, marketing has its own segment, or the first 176 00:09:06,605 --> 00:09:11,315 floor is a different segment than the second floor, or your, your 177 00:09:11,315 --> 00:09:15,515 production network is a different segment than your voiceover IP network. 178 00:09:16,505 --> 00:09:18,515 idea is how do we. 179 00:09:19,235 --> 00:09:23,855 Organize our environment from an operations and management perspective. 180 00:09:24,095 --> 00:09:30,095 So now we, we can truly measure and manage network traffic, 181 00:09:30,405 --> 00:09:32,605 anomalies, troubleshooting. 182 00:09:33,475 --> 00:09:37,960 from a. perspective whenever we create these segments. 183 00:09:37,960 --> 00:09:43,780 We can also apply access control rules depending on the hardware you have, the 184 00:09:43,780 --> 00:09:46,420 network hardware, so routers and switches. 185 00:09:46,900 --> 00:09:48,590 we can, we can control who can. 186 00:09:49,420 --> 00:09:51,220 Who can access that segment. 187 00:09:52,150 --> 00:09:56,110 so marketing or, or, you know, maybe, maybe we put a HR and 188 00:09:56,110 --> 00:09:57,490 legal in their own segment. 189 00:09:57,490 --> 00:09:59,710 So in payroll, you know, maybe accounting. 190 00:10:00,040 --> 00:10:03,730 So the rest of the company, you know, that doesn't need to worry themselves 191 00:10:03,730 --> 00:10:10,600 about paying the bills and, HR records and, you know, legal holds on, on data. 192 00:10:11,000 --> 00:10:13,040 all that stuff is, is truly protected. 193 00:10:13,040 --> 00:10:17,510 Or depending on your business, whatever your, your prize drill, your, your. 194 00:10:18,335 --> 00:10:23,585 Whatever your prized jewels are, you know, your data, your, logs, your fi, 195 00:10:23,615 --> 00:10:24,935 whatever it is, intellectual property. 196 00:10:25,700 --> 00:10:31,020 Put that in a secure segment or container, you can think of it that 197 00:10:31,020 --> 00:10:36,690 way too, and restrict who has access to it and what can happen, at, at 198 00:10:36,690 --> 00:10:38,040 a lot of different levels, right? 199 00:10:38,040 --> 00:10:42,750 It's not just, it's not just the user, it's also the type of network traffic, 200 00:10:42,750 --> 00:10:47,550 the services, the, the protocols, the, you can even limit bandwidth. 201 00:10:47,890 --> 00:10:51,430 there's a lot you can do, when, when you look at that 202 00:10:51,430 --> 00:10:53,550 type of, network architecture. 203 00:10:54,025 --> 00:10:54,745 Strategy. 204 00:10:55,865 --> 00:10:56,500 They think that 205 00:10:56,668 --> 00:11:00,868 probably easily, easily associate with sort of wifi 206 00:11:00,868 --> 00:11:02,368 networks, having like the guest 207 00:11:02,430 --> 00:11:02,650 the 208 00:11:02,968 --> 00:11:03,778 that you hand out to 209 00:11:03,875 --> 00:11:04,985 hand out to every client, 210 00:11:05,008 --> 00:11:05,198 they get. 211 00:11:05,428 --> 00:11:05,698 No 212 00:11:05,795 --> 00:11:06,785 get no access to. 213 00:11:06,868 --> 00:11:10,708 other than the internet versus like people who might be logging into 214 00:11:10,708 --> 00:11:14,428 like the corporate network or their home network where they have access 215 00:11:14,428 --> 00:11:17,428 to devices and they're streaming things and other things like that. 216 00:11:19,035 --> 00:11:19,890 And guess what? 217 00:11:19,890 --> 00:11:22,980 For those of you that're like, I will absolutely never do network segmentation. 218 00:11:22,980 --> 00:11:27,525 If you have a. Wireless network at home, and you've, you've separated, you know, 219 00:11:27,555 --> 00:11:30,885 you know when, when, when your neighbor's kids come over and they can't, they 220 00:11:30,885 --> 00:11:33,505 can't access your, your, your secret lab. 221 00:11:33,505 --> 00:11:35,005 You've only given them internet access. 222 00:11:35,005 --> 00:11:36,295 You've done segmentation. 223 00:11:37,068 --> 00:11:37,638 That's what I 224 00:11:37,740 --> 00:11:38,340 Interesting. 225 00:11:38,478 --> 00:11:41,208 it does cause issues sometimes and 226 00:11:41,460 --> 00:11:42,270 Yeah. 227 00:11:42,348 --> 00:11:44,868 we'll talk later about firewall and how do you connect these 228 00:11:44,868 --> 00:11:46,248 segments and all the rest of that. 229 00:11:46,248 --> 00:11:49,398 But yes, it does lead to some issues. 230 00:11:50,025 --> 00:11:52,815 Yeah, we have, we have tenants here at the house, like we have, 231 00:11:52,845 --> 00:11:56,265 we are renting rooms out and I created a guest network for them. 232 00:11:56,685 --> 00:12:00,195 And then of course they wanted to print and I was like, dang it, 233 00:12:01,335 --> 00:12:02,565 printer's on the wrong segment. 234 00:12:03,075 --> 00:12:07,215 which meant that either I have to give them access or I have to, I have to go on 235 00:12:07,215 --> 00:12:10,425 the guest network to print whichever, you know, one, one or the other is gonna work. 236 00:12:10,985 --> 00:12:11,585 so. 237 00:12:11,640 --> 00:12:15,300 And, and by the way, luckily this recording was segmented because I 238 00:12:15,300 --> 00:12:18,390 just got a call from my daughter and I was able to take that without, 239 00:12:18,490 --> 00:12:19,930 destroying the rest of the recording. 240 00:12:21,160 --> 00:12:24,400 You know, if you, you know, your, your adult daughter calls, you know, you 241 00:12:24,400 --> 00:12:25,810 got, you gotta take the call, right? 242 00:12:25,810 --> 00:12:27,160 That doesn't happen all the time. 243 00:12:28,020 --> 00:12:30,500 so let's talk about, hang on one second. 244 00:12:30,830 --> 00:12:31,130 Yeah. 245 00:12:31,160 --> 00:12:31,460 Okay. 246 00:12:32,390 --> 00:12:37,430 So am am I right in assuming Mike, that the key. 247 00:12:38,555 --> 00:12:42,305 tool in network segmentation are VLANs. 248 00:12:43,305 --> 00:12:48,975 The, the key tool is network, a network devices that would support segmentation. 249 00:12:49,114 --> 00:12:49,534 All right. 250 00:12:49,534 --> 00:12:50,044 Yeah, 251 00:12:50,115 --> 00:12:53,355 old school way is still just as effective. 252 00:12:53,715 --> 00:12:55,125 It's just not as easy. 253 00:12:55,125 --> 00:12:58,785 It's not a, you know, it's not an interface that I can log into and 254 00:12:58,785 --> 00:13:00,645 just drag and drop and click buttons. 255 00:13:00,645 --> 00:13:00,795 I've 256 00:13:00,874 --> 00:13:01,234 right. 257 00:13:01,335 --> 00:13:03,210 line, right? 258 00:13:03,310 --> 00:13:03,530 So 259 00:13:04,384 --> 00:13:06,304 So let, well, so let's, let's go back. 260 00:13:06,574 --> 00:13:07,924 Let's go back to that old school way. 261 00:13:07,924 --> 00:13:08,734 The old school way. 262 00:13:08,734 --> 00:13:11,044 It was literally, you gotta switch for this, you gotta switch for this, 263 00:13:11,044 --> 00:13:12,214 and never the twain shall each. 264 00:13:12,214 --> 00:13:13,174 Is that what you're saying? 265 00:13:13,744 --> 00:13:14,554 And that, and that. 266 00:13:14,554 --> 00:13:16,094 Now we have, VLANs. 267 00:13:16,094 --> 00:13:17,294 What, what is a vlan? 268 00:13:19,390 --> 00:13:22,090 Well, a VLAN is a capability of a switch. 269 00:13:22,420 --> 00:13:26,080 So newer, newer switches, and I say new, but the, you know, the 270 00:13:26,200 --> 00:13:29,860 VAN capable switches have been around for 10 or more years. 271 00:13:30,044 --> 00:13:32,589 New to those of us with with gray in our beards. 272 00:13:35,440 --> 00:13:39,625 So the, the older switches still could do segmentation, but you would have to. 273 00:13:40,375 --> 00:13:44,245 You know, you, you'd plug a console cable into the back of the switch and 274 00:13:44,245 --> 00:13:48,055 you, you would bring up a, a command prompt and you would have to physically 275 00:13:48,055 --> 00:13:52,915 type and know what to type the commands and the, the configuration of, of 276 00:13:52,915 --> 00:13:54,655 the segments that you want to create. 277 00:13:54,655 --> 00:13:57,655 And, you know, heaven forbid, now we've gotta add security with 278 00:13:57,655 --> 00:13:59,035 access control and other things. 279 00:13:59,035 --> 00:14:01,855 That's more typing and more things you have to know and, and. 280 00:14:02,225 --> 00:14:04,625 You know, it, it prone to mistakes. 281 00:14:05,025 --> 00:14:08,355 and from a backup perspective, also something you would want to back up. 282 00:14:08,355 --> 00:14:13,035 So if that switch died and you need to put a new switch in, you've got a a, a backup 283 00:14:13,035 --> 00:14:15,225 of, of that config for all those segments. 284 00:14:15,315 --> 00:14:19,185 'cause if you don't, then your network is broken and everybody's upset. 285 00:14:20,025 --> 00:14:25,855 the newer switches, newer even, you know, being around 10, 15 years, it 286 00:14:26,035 --> 00:14:29,035 you, you still log into the switch, but you can do it over the, the network. 287 00:14:29,035 --> 00:14:30,385 You don't have to have a console cable. 288 00:14:30,385 --> 00:14:35,245 You just, you hit the IP address, you get a nice user interface like a webpage, and 289 00:14:35,245 --> 00:14:38,845 there are tabs and buttons and to fill in. 290 00:14:38,995 --> 00:14:43,975 And as you interact with this interface, it's writing all that code in the backend. 291 00:14:44,755 --> 00:14:49,705 To create these VLANs, and now it's, now it's a, it's a graphic, you know, 292 00:14:49,705 --> 00:14:51,895 dashboard that shows you all your VLANs. 293 00:14:51,895 --> 00:14:56,485 You can name them, you can apply restrictions, you can do reporting. 294 00:14:56,925 --> 00:15:00,550 I mean, it's, it's, it's pretty, it's pretty easy to use. 295 00:15:01,723 --> 00:15:06,218 And so with VLANs, right, you're basically creating those segments that you have. 296 00:15:06,328 --> 00:15:07,648 Talked about earlier, right Mike? 297 00:15:07,648 --> 00:15:13,438 So you might have a say a VLAN N ID of 10, which is your production network. 298 00:15:13,438 --> 00:15:18,548 Maybe a VLAN ID of 20, which is your guest network, maybe a VLAN n 299 00:15:18,548 --> 00:15:21,508 ID of 40, which is your HR network. 300 00:15:21,868 --> 00:15:28,138 And in most cases, once you configure it, VLANs should not cross 301 00:15:28,138 --> 00:15:32,818 unless you give access for them to communicate with each other. 302 00:15:33,263 --> 00:15:36,203 Now, I know there are some systems out there where once you create a 303 00:15:36,203 --> 00:15:40,793 vlan, it allows traffic by default, which isn't always the best approach. 304 00:15:41,663 --> 00:15:41,963 Right? 305 00:15:41,963 --> 00:15:45,113 It's, I know Curtis, we've talked a lot about sort of, okay, shut everything 306 00:15:45,113 --> 00:15:49,823 down and then sort of add things back, and so I think from a VLAN perspective, 307 00:15:49,823 --> 00:15:53,363 yeah, you want those isolated except for the things which should be 308 00:15:53,363 --> 00:15:54,683 allowed to talk across each other. 309 00:15:57,170 --> 00:15:57,860 You're right. 310 00:15:57,920 --> 00:16:01,900 And, I think, I think the, the majority of devices that, that support 311 00:16:01,900 --> 00:16:04,820 VLANs do, Unrestricted by default. 312 00:16:04,820 --> 00:16:08,330 So it it's gonna start with, everybody can talk to this segment. 313 00:16:08,840 --> 00:16:11,960 And so, and, and I don't think we've, you know, VAN stands 314 00:16:11,960 --> 00:16:13,970 for Virtual Local Area Network. 315 00:16:14,810 --> 00:16:18,950 and so when we talk about segmentation, you know, within this, this 316 00:16:19,970 --> 00:16:25,580 company network, got the local area network, the land, and when you 317 00:16:25,580 --> 00:16:31,580 create a segment by itself, it's not necessarily a different land. 318 00:16:32,615 --> 00:16:35,945 When you restrict it, it becomes kind of a lan. 319 00:16:36,995 --> 00:16:39,545 so because you've gotta have access to it, just like you would the 320 00:16:39,545 --> 00:16:43,085 normal, the normal company network. 321 00:16:43,565 --> 00:16:48,155 Well, very similarly when we talk about VLANs, because it's virtual, 322 00:16:48,185 --> 00:16:49,775 I'm not adding new hardware. 323 00:16:49,955 --> 00:16:50,555 I'm just adding. 324 00:16:51,425 --> 00:16:54,515 Or taking advantage of the capability of this new switch, 325 00:16:54,905 --> 00:16:59,555 this new router, this new gear that allows me to virtually configure. 326 00:16:59,945 --> 00:17:03,635 And the way that works is, you know, if, if you can think of a network device 327 00:17:03,635 --> 00:17:08,225 and it's got all the, the, the plugs, the jacks where you can, you know, plug 328 00:17:08,225 --> 00:17:12,965 in a network cable, you know, whether it's, you know, eight or 16 or 32. 329 00:17:14,585 --> 00:17:17,945 When you, when you go into the VLAN console, it shows you a picture of the 330 00:17:17,945 --> 00:17:22,145 front of this device or the back where all these jacks are, and you just, you click 331 00:17:22,145 --> 00:17:24,845 on the ones that you want in this vlan. 332 00:17:24,845 --> 00:17:26,915 So it's both physical and virtual. 333 00:17:27,125 --> 00:17:31,715 Virtual from the perspective that it's applying logic to the traffic within the 334 00:17:31,715 --> 00:17:35,915 device, and then physical on the front end where, know, if I, if I want something 335 00:17:35,915 --> 00:17:40,205 on VLAN N one, I just need to plug it into whichever JAKs on the front of 336 00:17:40,205 --> 00:17:43,355 this device I've assigned to VLAN N one. 337 00:17:43,493 --> 00:17:46,793 Yeah, and there are also the capabilities, I know you were talking about the 338 00:17:46,793 --> 00:17:52,163 ports, Mike, where you can have actually multiple VLANs assigned to a single port. 339 00:17:52,163 --> 00:17:56,603 So you could imagine the case where you have a wifi access point, which is. 340 00:17:57,953 --> 00:18:00,293 broadcasting your guest network, your production 341 00:18:00,293 --> 00:18:02,513 network, your HR network, right? 342 00:18:02,513 --> 00:18:06,533 You could basically have all three VLANs come in on one physical 343 00:18:06,533 --> 00:18:10,223 port, but it, that port would support all three of those VLANs. 344 00:18:10,223 --> 00:18:14,213 So it's not always sort of a one-to-one physical to VLAN mapping, but you could 345 00:18:14,213 --> 00:18:15,983 have multiple sharing, a same, port. 346 00:18:18,304 --> 00:18:18,484 Yeah. 347 00:18:18,484 --> 00:18:21,864 And I, I, I was trying to think of, of a scenario where that was, you 348 00:18:21,864 --> 00:18:25,734 remember you were trying to talk about the, the, the, the wireless one there, 349 00:18:26,244 --> 00:18:29,424 but I was trying to think of a, of a different scenario where I would want 350 00:18:29,994 --> 00:18:35,274 an individual port, you know, which is gonna talk to another device, right. 351 00:18:35,794 --> 00:18:37,534 to be on more than one vlan. 352 00:18:37,534 --> 00:18:40,114 Can you think of a, of another scenario besides wireless? 353 00:18:42,543 --> 00:18:47,093 Well, you can think of the case where you're doing an uplink from one port 354 00:18:47,093 --> 00:18:51,353 to another, or sorry, sorry, from one switch to another, or from one 355 00:18:51,353 --> 00:18:52,793 switch to like an aggregate switch. 356 00:18:52,793 --> 00:18:57,263 So you need to be able to transfer all of those VLANs from that need to be. 357 00:18:57,738 --> 00:18:59,568 Transmitted from one switch to the other. 358 00:18:59,568 --> 00:19:02,958 And so you would have multiple VLANs on a single port. 359 00:19:03,574 --> 00:19:05,584 Yeah, that actually that's a, yeah. 360 00:19:06,904 --> 00:19:08,884 Yeah, that's a really good, that's a really good analogy. 361 00:19:08,884 --> 00:19:09,214 Thanks. 362 00:19:09,214 --> 00:19:13,774 That because of, because of vlan, and again, for those that not familiar 363 00:19:13,774 --> 00:19:17,194 with the VA VLAN isn't, like you said, it's not limited to a port, but 364 00:19:17,194 --> 00:19:18,934 it's also not limited to a switch. 365 00:19:19,264 --> 00:19:19,534 Right? 366 00:19:19,534 --> 00:19:23,344 So a VLAN could be across switches, so then you've gotta have inter 367 00:19:23,824 --> 00:19:27,764 intercommunication, but then you've gotta allow that communication to go. 368 00:19:27,764 --> 00:19:28,184 So, yeah. 369 00:19:28,214 --> 00:19:31,034 So that's, and then you might, like you said, you might 370 00:19:31,034 --> 00:19:32,354 trunk multiple ports together. 371 00:19:33,094 --> 00:19:36,904 When you're doing, inter switch communication, the, so what's, let's 372 00:19:36,904 --> 00:19:40,924 talk about, so that I, so I still go back to my original statement, that 373 00:19:40,984 --> 00:19:47,314 VLANs or the principle manner in which we're gonna implement this, but. 374 00:19:47,443 --> 00:19:48,673 It's like virtualization. 375 00:19:49,064 --> 00:19:49,334 Yeah. 376 00:19:49,334 --> 00:19:49,484 Yeah. 377 00:19:49,484 --> 00:19:49,874 I get it. 378 00:19:49,874 --> 00:19:50,264 I get it. 379 00:19:50,264 --> 00:19:55,284 I just, you know, anyway, so let's talk about, the need to talk principle. 380 00:19:55,284 --> 00:19:56,544 You wanna talk about that, Mike? 381 00:19:56,634 --> 00:19:59,244 what do, what do we mean when we talk about the, the need to talk? 382 00:20:00,244 --> 00:20:03,934 So, yeah, the need to talk principle is, is similar to at least privilege. 383 00:20:04,384 --> 00:20:07,784 is just a, it's a good security, strategy. 384 00:20:09,104 --> 00:20:13,034 The need to talk or the, the need to access, however, however you may have 385 00:20:13,034 --> 00:20:17,594 heard it, or, or you can think of it, is the whether or not it's appropriate 386 00:20:17,594 --> 00:20:19,454 for an end user device like a laptop. 387 00:20:20,119 --> 00:20:23,839 to be able to connect directly to a, a production server. 388 00:20:24,799 --> 00:20:29,479 and there's a variety of, of reasons to determine whether that's appropriate. 389 00:20:29,759 --> 00:20:32,039 but it's also an exercise you have to go through, which a 390 00:20:32,039 --> 00:20:34,139 lot of organizations don't. 391 00:20:35,009 --> 00:20:39,169 so identifying your critical assets, determining and based on the, that. 392 00:20:39,489 --> 00:20:43,749 That criticality, you can classify them confidential, public, et 393 00:20:43,749 --> 00:20:47,989 cetera, and then determine what's appropriate from an access perspective. 394 00:20:49,249 --> 00:20:52,189 In this case though, we, we were talking, we opened the, the segment 395 00:20:52,189 --> 00:20:55,189 with a, an example of ransomware. 396 00:20:55,429 --> 00:20:57,769 Imagine a, a user's computer. 397 00:20:58,819 --> 00:21:03,619 Got ransomware and they had a, a network, you know, there was a, a map drive. 398 00:21:03,979 --> 00:21:06,289 you know, when whenever they turn their computer on, they look at, 399 00:21:06,349 --> 00:21:09,859 you know, my, you know, the file explorer or my computer, and there's 400 00:21:09,859 --> 00:21:11,569 your S drive or your U drive. 401 00:21:11,569 --> 00:21:16,549 And that is an automatic, you know, scripted to a production server 402 00:21:16,549 --> 00:21:18,439 based on this user's credentials. 403 00:21:18,439 --> 00:21:20,329 Well, that ransomware now has. 404 00:21:20,639 --> 00:21:25,569 Those users credentials and would also, by association, have access 405 00:21:25,569 --> 00:21:29,019 to everything that this does, this device and that user is mapped 406 00:21:29,019 --> 00:21:30,849 to like those production servers. 407 00:21:31,659 --> 00:21:40,689 And so even though it's difficult and it's, it's a, it's a burden like security 408 00:21:40,689 --> 00:21:46,109 is automatically scripting access to production systems is, is frowned upon 409 00:21:47,282 --> 00:21:47,672 It's 410 00:21:47,789 --> 00:21:49,079 Say that again Automatically. 411 00:21:51,025 --> 00:21:54,465 Script automatically scripted, authentication to production 412 00:21:54,889 --> 00:21:55,429 Oh, okay. 413 00:21:55,429 --> 00:21:56,449 I understand what you're saying. 414 00:21:56,449 --> 00:21:56,839 Gotcha. 415 00:21:57,049 --> 00:21:57,409 Right. 416 00:21:57,709 --> 00:22:02,629 So, and, and I, I, I can see that because if, if we think about it, would you 417 00:22:02,629 --> 00:22:08,899 agree that end user, end user devices are probably the ones at most risk 418 00:22:08,899 --> 00:22:10,579 of being infected with ransomware? 419 00:22:10,879 --> 00:22:11,239 Right. 420 00:22:11,479 --> 00:22:11,714 Would, is that? 421 00:22:12,844 --> 00:22:13,474 Seem like a fair. 422 00:22:13,504 --> 00:22:13,714 Yeah. 423 00:22:13,744 --> 00:22:14,014 Okay. 424 00:22:14,044 --> 00:22:16,624 Yeah, because they're the ones, like they're taking their laptop and they're 425 00:22:16,624 --> 00:22:18,994 going to Starbucks and whatever. 426 00:22:19,054 --> 00:22:19,474 Right. 427 00:22:19,504 --> 00:22:21,604 And so they're, they're getting infected in that scenario. 428 00:22:21,604 --> 00:22:26,464 And so this is why you have this concept of not allowing them to 429 00:22:26,464 --> 00:22:29,704 directly communicate with servers unless there is a reason to do so. 430 00:22:31,980 --> 00:22:37,350 Yeah, server servers are not proactively or, or, you know, mindlessly clicking on 431 00:22:37,350 --> 00:22:39,120 links and opening emails with attachments. 432 00:22:39,484 --> 00:22:40,444 Yeah, exactly. 433 00:22:40,740 --> 00:22:43,920 I mean, we, we start deploying AI agents to do, to do more. 434 00:22:43,920 --> 00:22:46,590 You know, that may, that may, there may be a phase we go through. 435 00:22:47,340 --> 00:22:48,810 but currently, yeah, it's, it's 436 00:22:49,144 --> 00:22:52,549 Where ser, where servers get bored and they start browsing the web. 437 00:22:53,673 --> 00:22:56,913 So, so I was just, as you guys were talking through this, I was thinking 438 00:22:56,913 --> 00:23:01,353 about the episode, I think a couple weeks ago maybe we had, where we were talking 439 00:23:01,353 --> 00:23:04,503 about sort of users having admin access 440 00:23:05,259 --> 00:23:05,679 Mm-hmm. 441 00:23:05,913 --> 00:23:07,083 on their systems, right? 442 00:23:07,083 --> 00:23:08,613 And it's very similar in this case, right? 443 00:23:08,613 --> 00:23:11,433 It's like, hey, it's easier to just be like, yeah, users get 444 00:23:11,433 --> 00:23:13,353 access to production, whatever. 445 00:23:13,353 --> 00:23:14,178 I don't need to worry about. 446 00:23:15,063 --> 00:23:17,913 authorizing access every single time someone needs it. 447 00:23:18,393 --> 00:23:21,693 Maybe my IT shop is a little lazier, doesn't want to deal with 448 00:23:21,693 --> 00:23:26,163 these issues, or the end users want certain, privileges, I guess. 449 00:23:26,343 --> 00:23:31,108 And so it's sort of a bad design to say, Hey, all the users can run as. 450 00:23:32,028 --> 00:23:34,878 route or admin on their personal laptops. 451 00:23:35,118 --> 00:23:38,358 I think in the same way here, it's sort of like, okay, if you let them 452 00:23:38,358 --> 00:23:44,358 run with full access to production, that may be a risky maneuver. 453 00:23:45,774 --> 00:23:46,204 Same thing. 454 00:23:46,204 --> 00:23:46,924 It's less work. 455 00:23:46,924 --> 00:23:50,374 Just like you're saying, Mike, it's less, it's more work to do what we're saying. 456 00:23:50,374 --> 00:23:54,154 It's more work to segment, it's more work to say servers can't talk to 457 00:23:54,154 --> 00:23:59,074 laptops unless there is a particular use reason for them to do so, and they 458 00:23:59,074 --> 00:24:03,134 can't talk to, you know, mobile phones and, you know, all of that kind of stuff. 459 00:24:03,624 --> 00:24:05,274 but yeah, go ahead. 460 00:24:06,024 --> 00:24:11,124 Well, I just, well, but it's a good idea to do so, just like everything that we 461 00:24:11,124 --> 00:24:16,644 talk about, literally, there's nothing that we say in any of this, any part 462 00:24:16,644 --> 00:24:18,624 of this book where it's like, you know. 463 00:24:18,984 --> 00:24:23,004 Here's the thing that you could do that has no effort and great 464 00:24:23,124 --> 00:24:25,404 level of reward right there. 465 00:24:25,404 --> 00:24:28,824 There's just, there's everything we say. 466 00:24:28,824 --> 00:24:31,164 It's like, you should probably do this. 467 00:24:31,314 --> 00:24:33,954 There is a great amount of reward, right? 468 00:24:34,034 --> 00:24:35,864 a great reduction in risk. 469 00:24:36,014 --> 00:24:39,044 Imagine, you know, just like, again, another previous episode, 470 00:24:39,044 --> 00:24:40,394 not that long ago we talked about. 471 00:24:40,904 --> 00:24:44,774 If you don't have business with China and Russia and other similar 472 00:24:44,774 --> 00:24:50,084 countries, then just don't let servers in anyone in, in Russia or 473 00:24:50,084 --> 00:24:51,974 China communicate with your servers. 474 00:24:51,974 --> 00:24:53,384 Just turn it off and boom. 475 00:24:54,044 --> 00:24:55,334 Takes a little bit of effort. 476 00:24:55,484 --> 00:24:59,564 Huge amount of reward in terms of making sure you're not gonna get stuff from that. 477 00:24:59,564 --> 00:25:03,734 Of course, what those guys are gonna do, just hop on A-A-A-V-P-N 478 00:25:03,734 --> 00:25:05,204 and pretend like they're in the us. 479 00:25:05,204 --> 00:25:05,714 But you know, 480 00:25:06,188 --> 00:25:06,478 Yeah, 481 00:25:06,644 --> 00:25:09,044 we're, we're, we're trying to stop the stupid bad guys, not the. 482 00:25:09,268 --> 00:25:09,488 So, 483 00:25:09,494 --> 00:25:10,219 Not the smart ones. 484 00:25:10,393 --> 00:25:14,143 about the effort, right, Curtis, and we understand that managing, managing 485 00:25:14,143 --> 00:25:17,443 these environments, especially as new applications are spun up, right? 486 00:25:17,443 --> 00:25:18,973 New systems are brought on board. 487 00:25:19,093 --> 00:25:20,053 It's complicated, right? 488 00:25:20,053 --> 00:25:24,583 You have a network admin who's probably very overwhelmed or an IT generalist, and 489 00:25:24,583 --> 00:25:28,993 yes, the tools may be easier to configure it and versus what they used to be, 490 00:25:29,263 --> 00:25:30,943 but it's still work, it's still effort. 491 00:25:30,943 --> 00:25:32,833 You still need to monitor all the rest of that. 492 00:25:32,983 --> 00:25:33,728 And so. 493 00:25:34,578 --> 00:25:38,088 are managing these rules in order to allow those access. 494 00:25:38,088 --> 00:25:41,238 And Mike, in some of these environments, and I know you're just gonna say 495 00:25:41,238 --> 00:25:47,208 it depends, like how many firewall rules do you see sometimes in these? 496 00:25:47,208 --> 00:25:49,728 Like is it like tens to hundreds? 497 00:25:49,728 --> 00:25:50,778 Is it thousands? 498 00:25:50,778 --> 00:25:54,438 I'm sure it varies significantly, but like these are rules that someone 499 00:25:54,438 --> 00:25:56,238 created, someone has to manage right? 500 00:25:58,690 --> 00:25:59,140 You're right. 501 00:26:00,295 --> 00:26:04,155 I have seen quite a, quite a variety, if not the whole spectrum of like. 502 00:26:05,205 --> 00:26:09,645 Just default rules and because we don't know, and then just 503 00:26:09,645 --> 00:26:13,665 overly crazy cumbersome rules that actually cause problems. 504 00:26:14,245 --> 00:26:17,155 and then somewhere in between, you know, there there's also layers. 505 00:26:17,155 --> 00:26:20,905 So you've got your perimeter firewall and you've got, you know, internal firewalls. 506 00:26:20,905 --> 00:26:24,390 You've got firewalls for specific applications or servers or segments. 507 00:26:25,585 --> 00:26:28,315 there's a variety of strategy and architecture thought you 508 00:26:28,315 --> 00:26:30,775 can put to deployment of. 509 00:26:31,930 --> 00:26:35,800 Things at multiple layers, firewalls, one layer, segmentation's, another layer. 510 00:26:36,280 --> 00:26:38,740 yeah, there's, there's, I've seen, I've seen a lot. 511 00:26:38,920 --> 00:26:39,340 I've seen it. 512 00:26:39,400 --> 00:26:39,940 I've seen it. 513 00:26:40,030 --> 00:26:40,840 Good and the bad. 514 00:26:40,840 --> 00:26:46,000 And, and not to say one's better than the other, it depends on the, 515 00:26:46,660 --> 00:26:49,420 environment and, and the organization and, 516 00:26:49,470 --> 00:26:50,670 There's probably a point. 517 00:26:51,660 --> 00:26:51,960 Go ahead. 518 00:26:51,960 --> 00:26:51,980 Go ahead. 519 00:26:51,980 --> 00:26:52,440 Finish Mike. 520 00:26:52,810 --> 00:26:55,360 And the people and skills that, that you need to manage it. 521 00:26:56,055 --> 00:26:59,445 There's probably a point of decreasing marginal returns where like, you know, 522 00:26:59,685 --> 00:27:05,025 with, you know, with 50 rules, you get, you get this much, but with 400 523 00:27:05,025 --> 00:27:07,065 rules, you get this, this much more. 524 00:27:07,275 --> 00:27:11,265 The, the one that I saw, the, an environment that I was at where 525 00:27:11,270 --> 00:27:17,110 they had all of their applications stored very sensitive information. 526 00:27:17,775 --> 00:27:18,195 Right. 527 00:27:18,555 --> 00:27:23,955 And they had ano and they were, they were publicly faced, publicly 528 00:27:23,955 --> 00:27:27,345 facing applications, like to the public via the internet. 529 00:27:27,975 --> 00:27:32,655 And what they did a really good job of is segment, you know, basically vertical 530 00:27:32,655 --> 00:27:35,175 segmentation within their environment. 531 00:27:35,175 --> 00:27:40,185 So if you were interfacing with this app, you got access, you and 532 00:27:40,380 --> 00:27:43,335 the, the application that you were talking to and everything that 533 00:27:43,335 --> 00:27:45,105 that application needed to talk to. 534 00:27:45,670 --> 00:27:48,100 Was all available to that application. 535 00:27:48,250 --> 00:27:50,890 But if you were right next door and a server literally in the 536 00:27:50,890 --> 00:27:56,080 next rack, and you were talking to that application, that server 537 00:27:56,080 --> 00:27:58,240 couldn't talk to this server, right? 538 00:27:58,240 --> 00:28:00,310 So that I, I really like that now. 539 00:28:00,310 --> 00:28:02,020 It didn't end up creating. 540 00:28:02,515 --> 00:28:06,175 An incredible pain in the butt when I, the crazy backup guy 541 00:28:06,415 --> 00:28:07,855 wanted to talk to all the servers. 542 00:28:07,855 --> 00:28:10,735 That was considered like really verboten at the time. 543 00:28:11,105 --> 00:28:14,105 and, it led to a lot of fun, which, I've told a story about. 544 00:28:14,255 --> 00:28:14,615 Go ahead. 545 00:28:14,643 --> 00:28:15,333 I thought that was a 546 00:28:15,545 --> 00:28:17,135 Yeah, it's the, it's the same story. 547 00:28:17,135 --> 00:28:18,065 It's the same story. 548 00:28:18,065 --> 00:28:22,565 The one that results in me losing my, you know what, and 549 00:28:22,738 --> 00:28:23,318 At late 550 00:28:23,435 --> 00:28:25,415 out obscenities late at night. 551 00:28:25,415 --> 00:28:25,775 Yeah. 552 00:28:25,835 --> 00:28:26,165 Yeah. 553 00:28:26,165 --> 00:28:26,585 Mm-hmm. 554 00:28:26,678 --> 00:28:29,968 and Mike, I want you brought up a very interesting point, in your last 555 00:28:29,968 --> 00:28:32,488 comment, which was the skills of people. 556 00:28:32,518 --> 00:28:32,848 Right. 557 00:28:32,848 --> 00:28:36,658 And I think what ends up happening is a lot of what we talked about has. 558 00:28:37,378 --> 00:28:41,158 So far been mainly about like on-premises networking infrastructure 559 00:28:41,428 --> 00:28:42,238 to the most part, right? 560 00:28:42,238 --> 00:28:45,418 When we talk about physical switches, everything else, once you start throwing 561 00:28:45,418 --> 00:28:50,968 in cloud and the various ways that they protect their networks, the perimeter, 562 00:28:50,968 --> 00:28:56,788 their virtual data centers, whatever you wanna call a vbcs and AWS's case, right? 563 00:28:57,148 --> 00:28:59,578 All of that now adds a layer of complexity, and 564 00:28:59,578 --> 00:29:00,778 now when you try to overlay. 565 00:29:02,068 --> 00:29:05,758 settings, those rules would say something that also runs on premises 566 00:29:05,878 --> 00:29:07,648 and communicates back and forth. 567 00:29:07,648 --> 00:29:10,798 Now it gets very, very complicated, very quickly. 568 00:29:13,455 --> 00:29:14,325 It does. 569 00:29:14,385 --> 00:29:18,645 I'll, I'll, I will add part of this conversation that virtualization has 570 00:29:18,645 --> 00:29:22,065 so many benefits and security is one of those, if something's compromised, you 571 00:29:22,065 --> 00:29:26,715 just blow it away and, you know, go back to the most recent snapshot if you're, if 572 00:29:26,715 --> 00:29:28,605 you've got a good strategy around that. 573 00:29:29,005 --> 00:29:33,565 but for sure, whenever you're, you're talking cloud, you know, someone else's 574 00:29:33,565 --> 00:29:38,375 data center, whether it's co-located or truly outsourced, You're relying on all 575 00:29:38,375 --> 00:29:42,425 the controls and capabilities and and skills of the people supporting that. 576 00:29:42,770 --> 00:29:46,100 That, that you don't have control over it, aside from your, your 577 00:29:46,100 --> 00:29:50,330 contract, and then all of the communications between you and them. 578 00:29:50,330 --> 00:29:51,410 So how are you syncing? 579 00:29:51,410 --> 00:29:53,300 How are you sending and receiving? 580 00:29:53,640 --> 00:29:58,500 how do we, how do we ensure that access is appropriate and how 581 00:29:58,500 --> 00:30:00,060 are we monitoring all of that? 582 00:30:00,430 --> 00:30:01,455 and so one of the things I was. 583 00:30:02,070 --> 00:30:06,270 Touch on just from our last, you know, just the last thread, was 584 00:30:06,450 --> 00:30:10,500 the more complexity you add to your environment, more overhead it's gonna 585 00:30:10,500 --> 00:30:14,350 take to make sure, well one, how do we troubleshoot what's going on? 586 00:30:14,350 --> 00:30:15,370 What is anomalous? 587 00:30:15,370 --> 00:30:18,070 How do we go through these different layers to figure out what happened? 588 00:30:18,430 --> 00:30:21,700 And then back to the skills, you've gotta have the right people. 589 00:30:22,120 --> 00:30:23,230 and, and sometimes those. 590 00:30:23,555 --> 00:30:25,835 Those people will tell you, you need all this stuff. 591 00:30:25,835 --> 00:30:27,605 It needs to be this complicated thing. 592 00:30:28,035 --> 00:30:30,135 which maybe that's because of where they came 593 00:30:30,483 --> 00:30:31,533 Shiny new toys. 594 00:30:31,575 --> 00:30:33,645 it in that other environment, right. 595 00:30:33,915 --> 00:30:39,205 Or, sometimes the, you know, selling you this overly complex thing is, is their 596 00:30:39,205 --> 00:30:42,535 way of, sometimes overselling themselves. 597 00:30:42,925 --> 00:30:45,295 So a word of caution there too. 598 00:30:45,365 --> 00:30:48,035 the more, the more layers and things you put in place does not 599 00:30:48,035 --> 00:30:51,875 necessarily mean that you're, you're more protected or that your 600 00:30:51,875 --> 00:30:53,795 operations are gonna be more reliable. 601 00:30:54,155 --> 00:30:57,035 in, in the majority of cases that I've been involved with, 602 00:30:57,035 --> 00:30:58,295 it's actually been the opposite. 603 00:30:58,595 --> 00:31:02,105 The more complicated something is, the, the more difficult it is to 604 00:31:02,105 --> 00:31:04,295 respond and truly analyze things. 605 00:31:04,625 --> 00:31:08,530 It's also more difficult to manage it and keep it, keep it, keep it up and running. 606 00:31:09,495 --> 00:31:12,645 Glad you brought that up because the next topic that I wanted to talk under 607 00:31:12,645 --> 00:31:16,215 this, and it's related to the thing that persona just mentioned, which is the 608 00:31:16,215 --> 00:31:18,825 concept of microsegmentation, right? 609 00:31:18,825 --> 00:31:23,385 Where we're not just limiting things to VLANs and things like that, but 610 00:31:23,385 --> 00:31:26,955 we're also saying, this application can only talk to this application, or 611 00:31:26,955 --> 00:31:30,915 this applica, this piece of storage can only talk not just to this server, 612 00:31:31,165 --> 00:31:32,995 but especially in a world of the cloud. 613 00:31:33,275 --> 00:31:37,410 the where I, for example, have seen this when, you know. 614 00:31:37,890 --> 00:31:42,540 Persona and I worked, used to work at a cloud backup company and they, they 615 00:31:42,540 --> 00:31:47,910 used S3 as their target and they had, they had S3 configured so that only 616 00:31:47,910 --> 00:31:53,310 their application could write to that S3 write and read to that S3 bucket, 617 00:31:53,310 --> 00:31:57,000 so that even if you somehow had managed to break through all of the levels 618 00:31:57,000 --> 00:32:02,160 of security, get to get to S3, it wasn't, it you, you wouldn't be able to 619 00:32:02,160 --> 00:32:03,780 actually, read or write because they had. 620 00:32:04,015 --> 00:32:07,195 Pre preview already configured it so that it could only talk 621 00:32:07,195 --> 00:32:08,455 to the appropriate application. 622 00:32:08,845 --> 00:32:14,665 So I, I like the idea of microsegmentation, but Mike, I, this 623 00:32:14,665 --> 00:32:21,715 idea, you know, what you're saying is, is so true, is we can configure 624 00:32:21,715 --> 00:32:22,855 it just like everything else. 625 00:32:22,885 --> 00:32:25,195 We can configure this till the cows come home. 626 00:32:25,795 --> 00:32:30,835 And we can configure it so that it's so good that A, nobody can understand it. 627 00:32:31,285 --> 00:32:36,145 And b, we can't troubleshoot it when things, you know, when we get a, 628 00:32:36,445 --> 00:32:41,605 when we get a trip, you know, that nobody understands why we, why we 629 00:32:41,605 --> 00:32:43,225 got it and why we keep getting it. 630 00:32:43,355 --> 00:32:45,125 the more complicated we make it. 631 00:32:45,305 --> 00:32:49,625 You, you know, even though we, we talk about this stuff a lot, right? 632 00:32:49,895 --> 00:32:52,235 We're, we're, we're always recommending you need to look into 633 00:32:52,235 --> 00:32:53,435 this, you need to look into that. 634 00:32:54,545 --> 00:32:57,515 But we still have to argue for simplicity, right? 635 00:32:57,545 --> 00:33:00,155 Simplicity or complexity. 636 00:33:00,815 --> 00:33:03,065 Equals risk, right? 637 00:33:03,125 --> 00:33:07,415 Doing nothing equals risk, but doing way too much equals risk. 638 00:33:07,475 --> 00:33:13,415 You, you have to find a balance between doing things that you can understand. 639 00:33:13,505 --> 00:33:17,765 And I do think, by the way, just that, you know, we haven't, it has been 30 640 00:33:17,765 --> 00:33:19,535 seconds since we've said the word ai. 641 00:33:19,925 --> 00:33:23,315 I, I do think this is an area where AI can help, where you can say, 642 00:33:23,315 --> 00:33:26,765 you know, potentially you can say, here are the goals that I want 643 00:33:26,765 --> 00:33:29,375 to have for this organization. 644 00:33:29,435 --> 00:33:35,315 And that potentially AI could make a much more complicated security, 645 00:33:35,315 --> 00:33:40,415 you know, security forward network and application segmentation that 646 00:33:40,445 --> 00:33:42,785 wouldn't be possible otherwise. 647 00:33:42,785 --> 00:33:46,145 And I'm really curious to know your thoughts on what I just said. 648 00:33:46,385 --> 00:33:47,855 The, the, that last part. 649 00:33:50,065 --> 00:33:51,140 I, I agree with it. 650 00:33:51,265 --> 00:33:53,720 I, I agree that AI should be a good. 651 00:33:55,235 --> 00:34:00,075 Resource, for organizations to assess not only what, what they, 652 00:34:01,065 --> 00:34:03,615 what they're thinking about doing, but also what they currently have. 653 00:34:04,455 --> 00:34:07,395 and don't forget, and I've said it a couple times, 654 00:34:08,205 --> 00:34:10,035 forget to include your people. 655 00:34:10,575 --> 00:34:13,575 Whether those are internal people or your contractors, don't, don't 656 00:34:13,575 --> 00:34:16,665 forget to include them in this analysis because that's critical, 657 00:34:17,025 --> 00:34:18,975 especially if it's something complex. 658 00:34:19,365 --> 00:34:24,585 One of the biggest risks to environments that have these complex, you know, 659 00:34:24,585 --> 00:34:28,755 segmentations and layers, it, it's usually one or two people that built 660 00:34:28,755 --> 00:34:31,455 that with almost no documentation. 661 00:34:32,045 --> 00:34:32,125 Hmm. 662 00:34:32,235 --> 00:34:35,525 and so if you lose those people, you, you're. 663 00:34:38,210 --> 00:34:41,780 You're in a, I don't wanna say world of hurt, but, that's, that's a lot of 664 00:34:41,780 --> 00:34:43,940 risk to bear for someone new to come in. 665 00:34:43,940 --> 00:34:49,250 And I've seen this a lot, unfortunately, or coincidentally, the last couple 666 00:34:49,250 --> 00:34:52,570 of environments where I've seen a new person come in, into an 667 00:34:52,570 --> 00:34:54,160 environment that's overly complex. 668 00:34:54,160 --> 00:34:58,360 It was usually, pretty close to an incident, ransomware or something else, 669 00:34:58,360 --> 00:35:01,660 and they're trying to figure stuff out, out while the house is on fire. 670 00:35:03,610 --> 00:35:08,050 And they're figuring it out, but they also don't have time to document any of it. 671 00:35:08,050 --> 00:35:09,280 So it's still not documented. 672 00:35:09,280 --> 00:35:09,550 But, 673 00:35:10,030 --> 00:35:10,320 Yeah. 674 00:35:10,401 --> 00:35:14,001 a lot of environments where all these great things are in place. 675 00:35:15,081 --> 00:35:19,701 more than you need, and that person, you know, walks off the job or isn't available 676 00:35:19,701 --> 00:35:23,061 anymore and there's people have no idea. 677 00:35:23,331 --> 00:35:28,281 One other thing I'm gonna a add real quick about microsegmentation and, and 678 00:35:28,281 --> 00:35:32,261 you touched on it briefly, Curtis, you know, this application can only talk to 679 00:35:32,291 --> 00:35:34,841 that backend database or that bucket. 680 00:35:35,831 --> 00:35:40,001 of times that authentication is hard coded somewhere. 681 00:35:41,636 --> 00:35:45,416 You know, it's, it's, it's saved credentials or cashed credentials, or it's 682 00:35:45,416 --> 00:35:48,656 in a script or, it's a service account. 683 00:35:49,466 --> 00:35:53,246 again, years later, know, we're doing some other kind of audit or 684 00:35:53,246 --> 00:35:56,036 assessment and we find these things and we're like, what's this for? 685 00:35:56,036 --> 00:35:56,756 And nobody knows. 686 00:35:56,756 --> 00:35:59,966 So we turn it off and things break, or we delete that account 687 00:35:59,966 --> 00:36:02,216 or, you know, we update the code. 688 00:36:03,296 --> 00:36:04,466 It's not documented. 689 00:36:04,526 --> 00:36:07,346 It's hard coded, it's bad practice. 690 00:36:07,526 --> 00:36:09,806 And in a lot of cases it's, it's really not necessary. 691 00:36:09,806 --> 00:36:14,606 There's other ways to do this than, than some of these one-to-one 692 00:36:14,606 --> 00:36:16,056 authentication, approaches. 693 00:36:16,849 --> 00:36:22,099 you say though, Mike, that that example you just gave where you're using 694 00:36:22,399 --> 00:36:25,219 some sort of credential or service account or whatever else, so talk to 695 00:36:25,219 --> 00:36:28,369 another between two services that. 696 00:36:30,224 --> 00:36:37,844 Network microsegmentation is an additional layer, like it's not an either or, right? 697 00:36:37,844 --> 00:36:43,004 It's just an additional benefit to the authentication such that if someone 698 00:36:43,004 --> 00:36:48,314 stole those credentials and say, try to access that server from a different 699 00:36:48,314 --> 00:36:53,474 machine or something else, that the microsegmentation can help at least 700 00:36:53,474 --> 00:36:58,139 isolate and protect that endpoint rather than leave it completely wide open. 701 00:37:00,201 --> 00:37:00,491 Sure. 702 00:37:00,671 --> 00:37:04,276 and, you know, I, I got, I got pretty granular with, with credentials, 703 00:37:04,276 --> 00:37:06,811 but a step up from that is just, you know, the trust relationship. 704 00:37:07,156 --> 00:37:09,496 Is it one way trust, is it bilateral trust? 705 00:37:09,496 --> 00:37:10,816 I mean, that's been around forever. 706 00:37:11,806 --> 00:37:13,036 and those are appropriate. 707 00:37:13,346 --> 00:37:15,146 'cause that's just, that's a setting, you know? 708 00:37:15,146 --> 00:37:15,446 Right. 709 00:37:15,476 --> 00:37:17,406 So it that, that's not credentials. 710 00:37:17,406 --> 00:37:21,286 That's a, that's, you know, tokens or, Berros ticket or whatever. 711 00:37:21,726 --> 00:37:22,626 that's a setting. 712 00:37:22,656 --> 00:37:24,126 And, and those are appropriate. 713 00:37:24,126 --> 00:37:26,766 And those, those are, you know, very prevalent and. 714 00:37:27,011 --> 00:37:31,431 And, you know, good best practice if you can put the time into making sure it's 715 00:37:31,431 --> 00:37:33,741 set up right and main and documenting it. 716 00:37:34,881 --> 00:37:35,751 but no, you're right. 717 00:37:35,961 --> 00:37:41,631 I think, if, if you can start with network segmentation in general, put your 718 00:37:41,631 --> 00:37:43,851 production environment its own segment. 719 00:37:45,056 --> 00:37:49,016 Determine how to restrict or what's appropriate for other devices and 720 00:37:49,016 --> 00:37:51,406 users, to access that segment. 721 00:37:51,676 --> 00:37:54,646 And the, the behavior, like what does the network traffic look like? 722 00:37:54,646 --> 00:37:56,086 What do the trusts look like? 723 00:37:56,516 --> 00:38:00,596 in a lot of cases, you know, the majority of cases, that approach is gonna satisfy. 724 00:38:01,511 --> 00:38:05,711 Your objectives, your security objectives, your resilience, your backups, your, 725 00:38:05,741 --> 00:38:07,511 you know, protection from ransomware. 726 00:38:07,941 --> 00:38:10,531 that's gonna do the majority of the, of the heavy lifting. 727 00:38:10,861 --> 00:38:17,291 If you, if you really have sensitive systems, you know, maybe you're 728 00:38:17,291 --> 00:38:22,641 A-A-A-C-P, a firm and you, you've got all this tax data, you can do more, you 729 00:38:22,641 --> 00:38:25,666 can, I, I don't know that, you know. 730 00:38:27,321 --> 00:38:30,381 The, the very technical approach to microsegmentation that we've been 731 00:38:30,381 --> 00:38:34,521 talking about is necessary, but there's other security approaches, you know, 732 00:38:34,521 --> 00:38:38,741 with, dongles or tokens, you know, the UB keys and some other things, 733 00:38:41,081 --> 00:38:44,921 that could probably be more user friendly and manageable than 734 00:38:45,011 --> 00:38:48,701 the very technical approach to microsegmentation that, that would 735 00:38:48,701 --> 00:38:51,251 take some skill and, and some strategy. 736 00:38:51,529 --> 00:38:51,799 And it's 737 00:38:51,990 --> 00:38:55,890 I. Yeah, I, I think I like this idea. 738 00:38:55,890 --> 00:38:59,640 Again, you know, we're in sort of the action items part of, of the, of the 739 00:38:59,760 --> 00:39:04,980 recording here, and I like this idea first just sort of segmenting production from 740 00:39:05,040 --> 00:39:08,580 test dev and from end user devices, right? 741 00:39:08,580 --> 00:39:13,970 If we could create those three segments and then, I'd say the next step past 742 00:39:13,970 --> 00:39:19,340 that is when you look at your production environment, most applications are multi. 743 00:39:19,885 --> 00:39:23,155 They're, they're, you know, you start with like a web server in the front end. 744 00:39:23,155 --> 00:39:25,645 Then you have a database server, an application server behind that, 745 00:39:25,645 --> 00:39:26,995 and whatev whatever you've got. 746 00:39:26,995 --> 00:39:31,495 You might, you might have a whole number of things behind, but you could 747 00:39:31,495 --> 00:39:37,675 say, well, I, my, my devices only need to be able to talk to the web server. 748 00:39:37,885 --> 00:39:40,285 They don't need to be able to talk to all these other service. 749 00:39:40,350 --> 00:39:42,300 This server needs to be able to talk to those servers. 750 00:39:42,540 --> 00:39:46,020 So you can start with, with sort of a basic thing like that. 751 00:39:46,050 --> 00:39:49,410 Like you said, I like the idea of separating the, the dev and test. 752 00:39:49,410 --> 00:39:52,860 There's no reason that the dev and test need to talk to production. 753 00:39:53,230 --> 00:39:55,210 well, there's one reason I can think of, but again, that's a, 754 00:39:55,330 --> 00:39:57,100 it's a, it's an occasional reason. 755 00:39:58,120 --> 00:40:02,330 and I like the idea of restricting the end user devices, in their own 756 00:40:02,330 --> 00:40:05,690 little, you know, land ghetto, right? 757 00:40:05,690 --> 00:40:08,360 So that they're not allowed to, you know, talk to things. 758 00:40:08,360 --> 00:40:10,550 Again, anytime you do this, you just have to. 759 00:40:10,730 --> 00:40:12,140 you know, we've said this before. 760 00:40:12,260 --> 00:40:15,800 You need a, you need a, it, it's an on high thing. 761 00:40:15,800 --> 00:40:20,450 You need support from the people above you, because once you start doing 762 00:40:20,450 --> 00:40:23,720 this, you're gonna step on some toes. 763 00:40:24,140 --> 00:40:28,340 You're gonna, you're gonna hurt some apps and you're gonna, and, and so what you 764 00:40:28,340 --> 00:40:32,930 do, you is the thing of like, we turn on the new feature and then we wait. 765 00:40:33,430 --> 00:40:33,730 Right. 766 00:40:33,730 --> 00:40:36,970 We wait for, we wait for people to call the, to call the thing. 767 00:40:37,180 --> 00:40:37,450 Okay. 768 00:40:37,450 --> 00:40:39,340 It's been 15 minutes and nobody's called. 769 00:40:39,340 --> 00:40:39,700 Right? 770 00:40:40,030 --> 00:40:42,520 again, I, I'll give you a story from, from back in the day. 771 00:40:42,520 --> 00:40:45,140 There was this server, it was called Snazzy. 772 00:40:45,140 --> 00:40:46,160 I still remember the day. 773 00:40:46,190 --> 00:40:50,870 It was a little HP UX box, this little, little tiny thing. 774 00:40:51,410 --> 00:40:55,820 And, I had been told a lot of times backups would break on this 775 00:40:55,820 --> 00:40:59,300 box, and I, I didn't know why I, I was a brand new Unix guy. 776 00:40:59,390 --> 00:40:59,780 Right. 777 00:41:00,410 --> 00:41:03,880 And I was told, that when that happens, you just reboot the server. 778 00:41:04,585 --> 00:41:05,005 Right. 779 00:41:05,605 --> 00:41:09,985 And so one day this was happening, and so I rebooted the server and then all 780 00:41:09,985 --> 00:41:11,845 of a sudden, whoop, whoop, whoop, whoop. 781 00:41:11,845 --> 00:41:14,215 You know, people are literally running into the server room. 782 00:41:14,215 --> 00:41:15,565 They're like, what's going on with snazzy? 783 00:41:15,565 --> 00:41:17,245 I'm like, it's, it's rebooting. 784 00:41:17,275 --> 00:41:19,735 They're like, that's our communication. 785 00:41:20,215 --> 00:41:23,455 That's, that, that is the server through which we communicate to the 786 00:41:23,455 --> 00:41:27,325 mainframe in Dallas, you know, the, the mainframe that has all our money 787 00:41:27,415 --> 00:41:28,855 and we're a credit card company. 788 00:41:29,080 --> 00:41:29,410 Yeah. 789 00:41:29,860 --> 00:41:34,810 So you, you know, you, you're gonna break things, but you need to be prepared. 790 00:41:35,140 --> 00:41:38,620 The, the management needs to prepare and they need to support you. 791 00:41:38,890 --> 00:41:42,510 We're gonna do this, we're doing this for a reason, and we're doing this, you know, 792 00:41:42,510 --> 00:41:46,060 in a way that, we're trying, we're trying not to step on as many toes as we can. 793 00:41:46,060 --> 00:41:48,690 But, anyway, I'll step down on my soapbox. 794 00:41:49,154 --> 00:41:51,074 like you said, you do it in a phased approach, right? 795 00:41:51,305 --> 00:41:51,725 Mm-hmm. 796 00:41:51,854 --> 00:41:53,204 those four groups, right? 797 00:41:53,594 --> 00:41:56,714 Production, right test and dev end users. 798 00:41:57,074 --> 00:42:01,424 And then you could honestly just leave everything open on your 799 00:42:01,424 --> 00:42:04,304 production and then over time, just start locking it down, 800 00:42:04,770 --> 00:42:05,130 Yeah. 801 00:42:05,130 --> 00:42:06,840 And you monitor right? 802 00:42:07,170 --> 00:42:08,700 Leave it open and monitor. 803 00:42:08,790 --> 00:42:09,150 Right? 804 00:42:09,200 --> 00:42:11,330 Mike, can you talk about, about that a little bit? 805 00:42:11,330 --> 00:42:15,500 How do we monitor I vlan traffic. 806 00:42:15,650 --> 00:42:16,400 How do we figure that out? 807 00:42:17,400 --> 00:42:18,930 Well, there's an interface for that. 808 00:42:19,175 --> 00:42:19,535 Yeah. 809 00:42:19,950 --> 00:42:22,650 and then there's, there's, there's an, there's a variety of tools, 810 00:42:22,650 --> 00:42:27,800 both free, like Spiceworks or SolarWinds From a network operations 811 00:42:27,800 --> 00:42:33,060 perspective, you know, you can, you can monitor a, a number of attributes 812 00:42:33,060 --> 00:42:34,800 of your network across those VLANs. 813 00:42:34,830 --> 00:42:36,630 'cause it's, it's essentially. 814 00:42:37,515 --> 00:42:42,525 at traffic and whether you have that inside a, a segment or enterprise wide 815 00:42:42,675 --> 00:42:44,955 firewall all the way out to the perimeter. 816 00:42:46,515 --> 00:42:48,975 but that's really just network attributes. 817 00:42:49,035 --> 00:42:54,195 so bandwidth, thresholds on packets, users, machines, health. 818 00:42:55,420 --> 00:42:58,740 Someone trying to print, across different, segments. 819 00:42:58,800 --> 00:43:01,830 you can see all those protocols, all that good stuff from a 820 00:43:01,830 --> 00:43:03,480 cybersecurity perspective. 821 00:43:03,480 --> 00:43:08,290 Very similarly, you would put a a, a collector in each, within 822 00:43:08,290 --> 00:43:10,360 each segment that doesn't have. 823 00:43:10,955 --> 00:43:11,555 Trust. 824 00:43:11,560 --> 00:43:15,635 So any, any truly segmented, part of your network, it would have to 825 00:43:15,635 --> 00:43:18,635 have its own We call 'em sensors. 826 00:43:18,965 --> 00:43:23,225 And then you would push all the cis log and agent data to that collector. 827 00:43:23,525 --> 00:43:27,725 That collector would then meet up with other collectors and consolidate 828 00:43:27,725 --> 00:43:31,565 before it goes out through the firewall to a, a cloud data lake. 829 00:43:32,015 --> 00:43:32,495 And that's where 830 00:43:32,565 --> 00:43:32,805 That, 831 00:43:32,825 --> 00:43:33,905 run all this analysis 832 00:43:34,035 --> 00:43:35,805 that be a collector of collectors? 833 00:43:37,345 --> 00:43:39,655 It would be a collect a collector collection. 834 00:43:39,835 --> 00:43:39,925 A 835 00:43:40,200 --> 00:43:41,130 Electric collection. 836 00:43:41,485 --> 00:43:41,875 Yes. 837 00:43:42,750 --> 00:43:43,290 All right. 838 00:43:44,040 --> 00:43:46,380 Well, hey, I think that, I think this been good recording. 839 00:43:46,440 --> 00:43:50,580 we got, you know, we get in the weeds on, on how to do this and obviously 840 00:43:50,580 --> 00:43:54,360 the implementation is gonna vary from, environment to environment right. 841 00:43:54,390 --> 00:43:56,520 And how you actually do the dragging and dropping. 842 00:43:57,070 --> 00:44:00,190 but and I think Mike is recommending that everybody just go back to 843 00:44:00,190 --> 00:44:02,620 old school lands, not VLANs, just. 844 00:44:03,445 --> 00:44:05,305 Sports on a switch? 845 00:44:05,765 --> 00:44:09,425 no ai, no v anything. 846 00:44:09,595 --> 00:44:10,075 just, 847 00:44:10,075 --> 00:44:11,275 not recommending that. 848 00:44:13,409 --> 00:44:14,489 back in the day. 849 00:44:14,830 --> 00:44:18,820 I'll tell you, I'll tell you, I'll tell you the new, the new generation of hack. 850 00:44:18,820 --> 00:44:21,760 You know, the older guys are, are, you know, they've, they've, they've 851 00:44:21,760 --> 00:44:24,340 finally filled their nest egg and they're on a beach somewhere. 852 00:44:25,120 --> 00:44:27,370 or they moved outta, they finally moved outta mom's house. 853 00:44:27,370 --> 00:44:31,690 But, You know, a lot of the newer guys don't know how to hack some of the legacy 854 00:44:31,690 --> 00:44:37,910 stuff, you know, back, you know, old IBM, you know, big blue hardware, Novell, 855 00:44:37,970 --> 00:44:41,010 they, they have no idea how to hack a Novell, even though there's, there's 856 00:44:41,010 --> 00:44:42,480 good stuff out there for how to do it. 857 00:44:42,920 --> 00:44:47,630 so I'm not, I'm not, I'm not saying, you know, simple network, flat network 858 00:44:47,630 --> 00:44:52,610 is bad as long as it's appropriate for your environment, and your risk profile. 859 00:44:52,610 --> 00:44:53,240 But yeah. 860 00:44:53,420 --> 00:44:56,550 any number of things, you know, segmentation, load balancers, 861 00:44:56,580 --> 00:45:00,750 firewalls at the application network, even operating system level. 862 00:45:01,530 --> 00:45:03,450 there's a ton of resources out there. 863 00:45:03,450 --> 00:45:05,130 You just have to do the, an analysis. 864 00:45:05,250 --> 00:45:07,920 You have to know yourself and what you're trying to do, what your objectives 865 00:45:07,920 --> 00:45:11,340 are, and where everything is that inventory, and then figure out the 866 00:45:11,340 --> 00:45:13,320 best approach to protecting it all. 867 00:45:14,834 --> 00:45:16,484 Well, persona, thanks again. 868 00:45:16,614 --> 00:45:19,254 you got to, got to show off your VLAN expertise there. 869 00:45:19,663 --> 00:45:22,183 That this is what I've been doing at home the last couple years. 870 00:45:22,183 --> 00:45:22,393 Curtis 871 00:45:25,033 --> 00:45:26,713 gotta try things out for once. 872 00:45:27,324 --> 00:45:30,874 All right, and once again, thanks again, Mike for, for being on the pod. 873 00:45:32,325 --> 00:45:32,835 You are welcome. 874 00:45:33,439 --> 00:45:33,919 All right. 875 00:45:33,949 --> 00:45:37,159 And thanks to our listeners, you know, you are why we do this. 876 00:45:37,159 --> 00:45:38,299 I hope you're enjoying this. 877 00:45:38,299 --> 00:45:41,299 you know, give us a comment, give us a shout out, recommend the pod to 878 00:45:41,299 --> 00:45:44,509 other people, and, tell 'em to buy the dang book while they're at it. 879 00:45:44,959 --> 00:45:45,619 There you go. 880 00:45:45,739 --> 00:45:49,579 The Learning Ransomware Response and Recovery by w Curtis 881 00:45:49,579 --> 00:45:51,559 Preston and Dr. Mike Saylor. 882 00:45:52,069 --> 00:45:53,299 That is a wrap.