1 00:00:00,000 --> 00:00:03,109 W. Curtis Preston: This week on the backup wrap up, we are playing 2 00:00:03,109 --> 00:00:08,269 defense, cybersecurity, defense to be specific, and we've recruited 3 00:00:08,269 --> 00:00:09,949 an amazing player for our team. 4 00:00:10,655 --> 00:00:15,844 Mike Saylor has spent decades on the Blue team side working side by side with 5 00:00:15,844 --> 00:00:20,644 hundreds of organizations as they defend themselves from an active cyber attack. 6 00:00:21,064 --> 00:00:24,875 He works hand in hand with the FBI and the Secret Service, and 7 00:00:24,875 --> 00:00:28,354 he's got a great secret service story that I know you'll enjoy. 8 00:00:28,354 --> 00:00:28,384 I. 9 00:00:28,994 --> 00:00:32,204 For our longtime listeners, this is a trimmed down rebroadcast of 10 00:00:32,204 --> 00:00:33,734 Mike's appearance from last year. 11 00:00:34,004 --> 00:00:37,304 It was one of our most popular and insightful episodes. 12 00:00:37,994 --> 00:00:42,464 He gives some amazing advice and insight for organizations looking to 13 00:00:42,464 --> 00:00:44,595 strengthen their cybersecurity posture. 14 00:00:45,074 --> 00:00:47,324 I learned a lot, and I know you will too. 15 00:00:47,894 --> 00:00:52,935 By the way, if this is your first time listening, I'm w Curtis Preston, AKA, Mr. 16 00:00:52,935 --> 00:00:57,584 Backup, and I've been passionate about backup and recovery for over 30 years, 17 00:00:58,035 --> 00:01:03,465 ever since my backup's broke, and I had to tell my boss we had no backups. 18 00:01:03,720 --> 00:01:05,744 I, I don't want that to happen to me. 19 00:01:05,750 --> 00:01:07,065 I don't want it to happen to you. 20 00:01:07,125 --> 00:01:08,384 That's why I do this. 21 00:01:08,685 --> 00:01:13,785 On this podcast, we turn unappreciated backup admins into Cyber Recovery Heroes. 22 00:01:14,054 --> 00:01:16,155 This is the backup wrap up. 23 00:01:32,065 --> 00:01:32,965 Welcome to the show. 24 00:01:33,320 --> 00:01:35,930 W. Curtis Preston: I'm your host, w Curtis Preston, a k a, Mr. 25 00:01:35,930 --> 00:01:36,470 Backup. 26 00:01:36,830 --> 00:01:40,910 And I have with me a guy who once again, has astonished me with knowledge 27 00:01:40,910 --> 00:01:43,850 that why does he know this stuff? 28 00:01:44,300 --> 00:01:46,820 He's gonna solve my office chair problem. 29 00:01:47,410 --> 00:01:49,610 Prasanna Malaiyandi how's it going? 30 00:01:49,610 --> 00:01:50,160 Prasanna, 31 00:01:50,570 --> 00:01:52,040 Prasanna Malaiyandi: I am good, Curtis. 32 00:01:52,040 --> 00:01:52,940 I'm good. 33 00:01:52,940 --> 00:01:56,180 So yeah, let's talk about you needing a new office chair. 34 00:01:57,110 --> 00:01:58,160 W. Curtis Preston: so it, it 35 00:01:58,235 --> 00:01:58,985 Prasanna Malaiyandi: show the listeners. 36 00:01:58,985 --> 00:01:59,975 Just, just squeak. 37 00:02:00,115 --> 00:02:00,950 W. Curtis Preston: Well, let's, yeah. 38 00:02:01,130 --> 00:02:06,920 So this is, so, you know, in a, in a podcast, my mic is picking 39 00:02:06,920 --> 00:02:08,750 up my squeaky office chair. 40 00:02:09,140 --> 00:02:12,650 And so either I need a new office chair or I need to lose a few pounds. 41 00:02:12,650 --> 00:02:14,120 One or the other, or maybe both. 42 00:02:14,600 --> 00:02:18,590 But uh, so you brought up what was the, it was Crandall. 43 00:02:19,385 --> 00:02:19,655 Prasanna Malaiyandi: Yep. 44 00:02:19,655 --> 00:02:20,315 Crandall Furniture. 45 00:02:21,130 --> 00:02:21,425 W. Curtis Preston: Yeah. 46 00:02:21,485 --> 00:02:24,875 Crel Furniture, which is, they're, they're apparently repurposing, 47 00:02:24,995 --> 00:02:28,325 uh, you know, all those office chairs that nobody's using anymore. 48 00:02:28,565 --> 00:02:28,865 Prasanna Malaiyandi: Yeah. 49 00:02:30,080 --> 00:02:31,490 Yeah, they buy chairs. 50 00:02:31,490 --> 00:02:33,890 They refurbish them with like new foam. 51 00:02:33,890 --> 00:02:36,290 They fix the lift mechanism. 52 00:02:36,290 --> 00:02:39,350 Sometimes they replace the arms and then they resell it at a discount. 53 00:02:40,215 --> 00:02:40,505 W. Curtis Preston: Yeah, 54 00:02:40,670 --> 00:02:43,190 Prasanna Malaiyandi: it's crazy how expensive office chairs are. 55 00:02:43,195 --> 00:02:47,300 Like some of the high-end ones are like a thousand, $1,800. 56 00:02:47,300 --> 00:02:48,620 Who wants to spend that on a chair? 57 00:02:48,620 --> 00:02:49,190 Like I get it. 58 00:02:49,190 --> 00:02:52,820 You spend a lot of time sitting in a chair just like you do, sleeping in a bed. 59 00:02:52,850 --> 00:02:57,080 But still, it's a good chunk of money to spend when you can go to like 60 00:02:57,350 --> 00:03:01,790 your local office, supply store and pick up a cheap chair for like $99. 61 00:03:02,210 --> 00:03:04,820 W. Curtis Preston: Yeah, and I don't think this was 99, but 62 00:03:04,820 --> 00:03:05,960 it wasn't much more than that. 63 00:03:06,740 --> 00:03:10,250 I don't, I don't have, if, if I had to guess, I probably got it from Costco. 64 00:03:10,760 --> 00:03:11,480 'cause I get. 65 00:03:12,050 --> 00:03:13,580 Many other things from Costco. 66 00:03:13,640 --> 00:03:14,000 Right. 67 00:03:14,600 --> 00:03:16,100 Um, but yeah, 68 00:03:16,190 --> 00:03:17,570 Prasanna Malaiyandi: I had one of those chairs. 69 00:03:17,750 --> 00:03:20,990 I had one of those chairs as well, right, where I was like, yeah, it worked well. 70 00:03:20,995 --> 00:03:24,860 And then I'll, once the pandemic hit and we were working from home, I ended up 71 00:03:24,860 --> 00:03:29,600 getting some wellness dollars from my employer and use that to get myself a 72 00:03:29,600 --> 00:03:31,400 nice standing desk and an office chair. 73 00:03:32,630 --> 00:03:37,195 W. Curtis Preston: And, uh, with that we'll turn to our guest at this moment. 74 00:03:37,495 --> 00:03:42,565 Uh, he's, uh, specialized in cybersecurity for over 20 years and is a member of 75 00:03:42,595 --> 00:03:45,915 F B I InfraGard, which is A group that I didn't even know existed. 76 00:03:45,915 --> 00:03:49,275 But it's a partnership between the F B I and the private sector for the 77 00:03:49,280 --> 00:03:51,375 protection of US critical infrastructure. 78 00:03:51,675 --> 00:03:56,475 He's now the c e O of Black Swan, a company that strives to democratize 79 00:03:56,475 --> 00:03:58,575 enterprise level security services. 80 00:03:58,785 --> 00:04:01,785 Which one of my first questions is gonna be, what does that mean? 81 00:04:02,025 --> 00:04:04,275 Welcome to the pod, Mike Sailor. 82 00:04:05,445 --> 00:04:05,745 Mike Saylor: Thank you. 83 00:04:05,745 --> 00:04:06,465 Thanks for having me 84 00:04:07,395 --> 00:04:08,325 W. Curtis Preston: so what does that mean? 85 00:04:09,145 --> 00:04:09,365 So 86 00:04:10,695 --> 00:04:11,325 Mike Saylor: Well, uh, 87 00:04:11,385 --> 00:04:13,785 W. Curtis Preston: on your website that it says you wanted to democratize 88 00:04:13,785 --> 00:04:15,375 enterprise level security services. 89 00:04:16,155 --> 00:04:16,425 Mike Saylor: Sure. 90 00:04:16,425 --> 00:04:19,065 Well, I think in, in, you know, 91 00:04:21,345 --> 00:04:26,805 simple explanation is that we're trying to provide, uh, enterprise class services. 92 00:04:26,805 --> 00:04:30,675 The, you know what, what the big boys pay for Fortune 50, fortune 100. 93 00:04:31,080 --> 00:04:35,280 And make it affordable and scalable and flexible enough for smaller organizations, 94 00:04:35,285 --> 00:04:36,780 small, medium sized businesses. 95 00:04:37,200 --> 00:04:40,500 Uh, part of our mission is to provide that enterprise class service to 96 00:04:40,500 --> 00:04:42,480 what we consider underserved markets. 97 00:04:42,810 --> 00:04:48,630 So, uh, education, uh, family offices, uh, credit unions as an example. 98 00:04:49,020 --> 00:04:52,410 Um, but also understanding that in each one of those situations you've 99 00:04:52,410 --> 00:04:55,080 got a variety of, uh, business sizes. 100 00:04:55,080 --> 00:04:57,930 So you've got a five person credit union and you've got a 101 00:04:57,930 --> 00:04:59,070 billion dollar credit union. 102 00:04:59,460 --> 00:05:04,530 Uh, and they both need, uh, help, uh, understanding and applying, um, 103 00:05:04,950 --> 00:05:07,320 cybersecurity controls and, and services. 104 00:05:07,805 --> 00:05:11,735 Prasanna Malaiyandi: So what happens today for those small customers, right? 105 00:05:11,735 --> 00:05:15,425 Or like the five person credit union, like how do they even 106 00:05:15,425 --> 00:05:17,285 approach cybersecurity today? 107 00:05:17,285 --> 00:05:19,165 Or what is their solutions look like? 108 00:05:20,370 --> 00:05:21,840 Mike Saylor: Uh, they usually don't have one. 109 00:05:21,930 --> 00:05:22,730 Um, I. 110 00:05:22,730 --> 00:05:27,000 And they even have to, uh, in, in a lot of cases, have to outsource their just normal 111 00:05:27,000 --> 00:05:29,130 help desk, you know, hardware support. 112 00:05:29,400 --> 00:05:35,190 And they're relying on that, you know, that technology expertise to, uh, assist 113 00:05:35,190 --> 00:05:37,680 them in cyber to the extent possible. 114 00:05:38,190 --> 00:05:39,780 Um, but that's changing. 115 00:05:39,840 --> 00:05:44,820 Um, and it, and it has to, uh, a lot of, uh, services and. 116 00:05:45,510 --> 00:05:48,540 Protections and controls that any organization today rely 117 00:05:48,540 --> 00:05:50,100 on, like, like insurance. 118 00:05:50,730 --> 00:05:54,660 Uh, in order to qualify for cybersecurity insurance policies, you have to 119 00:05:54,660 --> 00:05:59,670 demonstrate these, you know, kind of, uh, good cyber hygiene practices, uh, whether 120 00:05:59,670 --> 00:06:01,440 you do it internally or you outsource it. 121 00:06:01,445 --> 00:06:06,600 Uh, and so in order just to even get insurance, uh, you have to, uh, spend 122 00:06:06,600 --> 00:06:09,300 some money to check some of these boxes. 123 00:06:09,780 --> 00:06:12,870 Um, and they're just, there's, there's not a whole lot of solutions out 124 00:06:12,870 --> 00:06:14,670 there options for them to, to go with. 125 00:06:16,110 --> 00:06:16,890 W. Curtis Preston: Interesting. 126 00:06:16,980 --> 00:06:21,750 Um, and let's talk also a little bit about, uh, F B I in regard. 127 00:06:22,290 --> 00:06:25,260 'cause like I said, I, I did, I didn't even know this in, I'm, I'm 128 00:06:25,260 --> 00:06:28,470 really glad to hear that it exists, but I didn't even know it exists. 129 00:06:28,830 --> 00:06:30,700 Uh, what, what, what does that look like? 130 00:06:31,815 --> 00:06:32,205 Mike Saylor: Sure. 131 00:06:32,265 --> 00:06:35,055 Uh, well, so it started in the late nineties. 132 00:06:35,115 --> 00:06:39,465 Uh, I think the, the first chapter was, uh, um, in the mid nineties. 133 00:06:39,545 --> 00:06:47,970 Um, and the, the idea is, Uh, for every F B I field office, um, there should be 134 00:06:47,970 --> 00:06:53,730 an InfraGuard chapter, and the objective of the chapter is to tie the office into 135 00:06:53,730 --> 00:06:59,701 the community, thereby, uh, expanding its eyes and ears, uh, but also, um, 136 00:07:00,150 --> 00:07:06,120 helping elevate the, uh, intelligence and awareness of the organizations in the 137 00:07:06,120 --> 00:07:09,750 community, uh, for the things that the F B I and that community is working on. 138 00:07:10,215 --> 00:07:14,685 Uh, so some, some bi-directional, uh, intelligence sharing, which 139 00:07:14,685 --> 00:07:16,305 really didn't happen for a long time. 140 00:07:16,335 --> 00:07:19,635 It's probably only been in the last five or six years that that's, that's 141 00:07:19,640 --> 00:07:21,675 really, uh, become more valuable. 142 00:07:22,095 --> 00:07:26,235 Um, prior to that, you, you might get an infra regard notice, 143 00:07:26,235 --> 00:07:30,105 uh, a few hours or a day before something comes out on the news. 144 00:07:30,135 --> 00:07:32,445 So you really weren't ahead of it too much. 145 00:07:33,015 --> 00:07:36,555 Um, but so now there's, there's 45 chapters. 146 00:07:36,945 --> 00:07:38,895 Of InfraGard throughout the country. 147 00:07:38,985 --> 00:07:41,895 Uh, there's an InfraGard National Alliance that kind of manages 148 00:07:41,900 --> 00:07:43,665 all those independent chapters. 149 00:07:44,115 --> 00:07:47,745 Um, and the chapters are made up of people from the community, 150 00:07:47,805 --> 00:07:49,515 uh, across all sectors. 151 00:07:49,575 --> 00:07:51,975 Uh, kind of initially it was all technology people. 152 00:07:52,395 --> 00:07:57,375 Uh, so 90, 90 plus percent, uh, membership and InfraGard were people and, you know, 153 00:07:57,435 --> 00:08:00,015 CIOs and engineers and help desk people. 154 00:08:00,405 --> 00:08:06,270 Uh, but today we have nurses and doctors and farmers and, um, People 155 00:08:06,270 --> 00:08:11,070 that work in infrastructure, water dams, uh, federal government, um, 156 00:08:11,400 --> 00:08:15,120 agriculture, I mentioned, um, nuclear. 157 00:08:15,630 --> 00:08:21,210 Uh, so each critical infrastructure section sector, uh, has an infra regard 158 00:08:21,210 --> 00:08:24,360 sector chief, uh, at each chapter. 159 00:08:24,420 --> 00:08:26,260 Uh, who is responsible for going out and. 160 00:08:26,910 --> 00:08:30,930 Uh, not just recruiting others from that sector, uh, to kind of 161 00:08:30,930 --> 00:08:35,010 strengthen the, the mix and dynamics of the chapters, uh, membership. 162 00:08:35,490 --> 00:08:41,550 Um, but it's also, uh, both a feeder into the F B I, uh, for intelligence 163 00:08:41,550 --> 00:08:44,670 and threats and awareness of what's going on out in the community, uh, 164 00:08:44,670 --> 00:08:48,810 but also the FBI's ability to, to, uh, To share with them so that they 165 00:08:48,810 --> 00:08:53,160 can do their job better, uh, get ahead of threats, um, be more aware. 166 00:08:53,670 --> 00:08:58,680 Uh, so it's been a pretty, pretty effective, um, partnership over the years. 167 00:08:58,740 --> 00:09:01,710 Uh, I helped stand up the North Texas chapter in the late nineties, and 168 00:09:01,710 --> 00:09:04,740 I've, I've been sector, I'm currently a sector chief over healthcare. 169 00:09:04,770 --> 00:09:06,420 I was a sector chief over technology. 170 00:09:06,420 --> 00:09:08,280 Initially I was the president of the chapter. 171 00:09:08,820 --> 00:09:11,550 Um, and we have a, a pretty strong. 172 00:09:12,090 --> 00:09:15,660 Uh, showing, uh, in our company as far as InfraGard goes, our 173 00:09:15,660 --> 00:09:17,580 c f O was a, a past president. 174 00:09:17,580 --> 00:09:22,320 She's also the past, uh, national regional representative over I think 175 00:09:22,320 --> 00:09:23,520 three or four different states. 176 00:09:23,970 --> 00:09:26,670 Our c o o was the president of the Houston chapter. 177 00:09:26,670 --> 00:09:29,250 He was also a national regional rep for a period of time. 178 00:09:29,700 --> 00:09:32,160 Uh, and then everybody in our company pretty much is a member. 179 00:09:32,700 --> 00:09:35,820 Um, and there's similar, there's a similar, uh, organization 180 00:09:35,820 --> 00:09:36,990 for the Secret Service. 181 00:09:36,990 --> 00:09:37,650 They call it. 182 00:09:37,650 --> 00:09:41,490 They used to call it the Electronic Crimes Task Force, of which I'm also a member. 183 00:09:42,000 --> 00:09:45,570 Uh, and then both of those are kind of related to the, in Texas we have the 184 00:09:45,570 --> 00:09:49,650 North Texas Crime Commission and they have subcommittees like cyber crime. 185 00:09:49,800 --> 00:09:55,260 And then, uh, the fusion centers that police departments, uh, fun, uh, operate. 186 00:09:55,410 --> 00:10:00,600 Um, in north Texas, there's the Collin County Sheriff Fusion Center, uh, from 187 00:10:00,600 --> 00:10:02,850 which I'm also a fusion liaison officer. 188 00:10:03,210 --> 00:10:06,270 So tons of intelligence sharing, information sharing. 189 00:10:07,215 --> 00:10:11,625 Uh, both to support the community, but also naturally with what we do, uh, that 190 00:10:11,625 --> 00:10:15,195 feeds really nicely into the value that we can, uh, we can give our clients. 191 00:10:16,110 --> 00:10:16,830 Prasanna Malaiyandi: That's awesome. 192 00:10:16,830 --> 00:10:20,730 I actually, like you said, Curtis, I had never heard about this and Mike, 193 00:10:20,730 --> 00:10:24,360 thank you for going into details because that's actually a really cool program. 194 00:10:24,360 --> 00:10:27,300 Like I didn't realize that the F B I connected in like this in 195 00:10:27,630 --> 00:10:30,270 sort of a systematic way, right? 196 00:10:30,270 --> 00:10:32,100 To all these other organizations. 197 00:10:32,275 --> 00:10:32,695 Mike Saylor: Mm-hmm. 198 00:10:32,925 --> 00:10:35,655 W. Curtis Preston: Yeah, we've, we've come a long way since, um, 199 00:10:35,685 --> 00:10:40,245 the days of the cuckoo's egg, which I'm, I'm assuming you've read a 200 00:10:40,245 --> 00:10:42,405 Cuckoo's Egg or the c the cuckoo egg. 201 00:10:42,405 --> 00:10:46,155 I think, you know, because in that story from Cliff Sto back in the 202 00:10:46,155 --> 00:10:50,385 day when he contacts the F B I about a cyber attack that's happening on 203 00:10:50,385 --> 00:10:53,355 his infrastructure, They're like, well, did they steal anything? 204 00:10:53,805 --> 00:10:54,045 Right. 205 00:10:54,315 --> 00:10:57,915 They didn't, they really weren't aware of the concept of a cybersecurity attack. 206 00:10:58,215 --> 00:10:59,955 So I, I'm, I'm glad to hear that. 207 00:10:59,955 --> 00:11:02,115 You know, things have come a long way since that was the 208 00:11:02,120 --> 00:11:03,945 seventies, so, you know, whatever, 209 00:11:04,020 --> 00:11:04,920 Mike Saylor: And, and on 210 00:11:04,920 --> 00:11:05,220 the, 211 00:11:05,240 --> 00:11:06,075 W. Curtis Preston: while since then. 212 00:11:06,825 --> 00:11:08,145 Mike Saylor: Kind of along those lines. 213 00:11:08,175 --> 00:11:12,765 Uh, the other benefit of that is, uh, similar to the situation where, you know, 214 00:11:12,765 --> 00:11:15,405 there was an event, uh, we always preach. 215 00:11:15,495 --> 00:11:18,735 Uh, as far as incident response goes, you've gotta get ahead of that so that 216 00:11:18,740 --> 00:11:23,775 on game day, you know what players you can call into the, to, uh, onto the field 217 00:11:23,780 --> 00:11:25,785 and uh, you know, who's gonna show up. 218 00:11:25,785 --> 00:11:28,575 And so, um, you know, we're very adamant about. 219 00:11:29,325 --> 00:11:33,015 Establishing those relationships with law enforcement and subject matter experts 220 00:11:33,015 --> 00:11:35,925 and vendors in the community so that when something bad happens, you're not 221 00:11:35,925 --> 00:11:39,705 leaving a voicemail, you're not having to figure out the right person to talk to. 222 00:11:40,125 --> 00:11:43,815 And so in regard, and the, uh, the Secret Service organizations give you 223 00:11:43,815 --> 00:11:47,175 the opportunity to actually go to, they have chapter meetings and a lot of 224 00:11:47,175 --> 00:11:50,895 times they're at the, the FBI's field office, which is also kind of cool. 225 00:11:51,405 --> 00:11:54,585 Um, and so you get to meet people and exchange business cards and go 226 00:11:54,585 --> 00:11:57,735 to coffee and have their cell phone number instead of a mailbox number and. 227 00:11:58,290 --> 00:12:01,440 Um, and find the right person to talk to so that you can put 'em in your 228 00:12:01,440 --> 00:12:05,250 plan and you know who to call and they already know you, they've met you before. 229 00:12:05,250 --> 00:12:07,800 It's not a first date type of situation. 230 00:12:07,800 --> 00:12:11,130 So when, when, when things are going bad and the the house is 231 00:12:11,130 --> 00:12:15,240 on fire, uh, you know who to call and, um, they know who you are. 232 00:12:15,795 --> 00:12:17,985 W. Curtis Preston: Yeah, I preached the, the same thing, Mike, and, 233 00:12:17,990 --> 00:12:23,505 and, and so it's, but it sounds like InfraGard is a, is a organization 234 00:12:23,505 --> 00:12:26,835 that I can contact, go to these meetings that you were talking about. 235 00:12:26,835 --> 00:12:28,995 That, that it, that it could be that liaison. 236 00:12:29,385 --> 00:12:31,455 So that I can start to form those relationships. 237 00:12:31,485 --> 00:12:34,665 'cause you're right, it's like, uh, you know, just reaching out to, to the 238 00:12:34,665 --> 00:12:40,125 F B I blindly, um, you know, Hey, I'd like to talk to you about a potential 239 00:12:40,130 --> 00:12:42,045 future event that might happen. 240 00:12:42,375 --> 00:12:42,705 Right. 241 00:12:42,705 --> 00:12:45,195 So it sounds like Ingar can be that liaison then. 242 00:12:45,195 --> 00:12:45,255 I 243 00:12:45,840 --> 00:12:46,830 Mike Saylor: And, and you're right. 244 00:12:46,830 --> 00:12:51,960 And they do have, uh, they have, uh, speaker, um, what do they call it? 245 00:12:52,050 --> 00:12:57,030 Um, you can, you can sign up to be a speaker, uh, like as a 246 00:12:57,030 --> 00:12:58,860 resource, uh, subject matter expert. 247 00:12:59,130 --> 00:13:03,150 But then the F b I also has, uh, speakers that can come to your event. 248 00:13:03,585 --> 00:13:07,785 And so very often you can pull in that, that law enforcement, uh, perspective 249 00:13:07,785 --> 00:13:09,735 to, to your message and your content. 250 00:13:09,735 --> 00:13:12,735 And they'll bring their own slides and, you know, whatever data they 251 00:13:12,735 --> 00:13:16,545 can, they can share publicly as far as current events and statistics. 252 00:13:16,550 --> 00:13:20,865 And it's, it's usually a pretty good, uh, value add, uh, as far as content. 253 00:13:20,985 --> 00:13:22,875 And, and sometimes it's a, it's a draw. 254 00:13:23,325 --> 00:13:26,745 Uh, you know, people may not want to just come see me talk, but if it's me plus 255 00:13:26,745 --> 00:13:29,955 the supervisory special agent over cyber, then all of a sudden it's interesting. 256 00:13:30,555 --> 00:13:31,275 Uh, so. 257 00:13:32,010 --> 00:13:32,550 Um, 258 00:13:32,580 --> 00:13:32,790 yeah, 259 00:13:32,970 --> 00:13:33,480 Prasanna Malaiyandi: for you, Mike. 260 00:13:33,480 --> 00:13:33,930 Come on. 261 00:13:34,530 --> 00:13:35,550 Mike Saylor: there's a lot of value. 262 00:13:35,550 --> 00:13:37,020 There's a lot of value in membership. 263 00:13:37,080 --> 00:13:40,140 Um, each chapter has their own dues. 264 00:13:40,170 --> 00:13:44,190 Like our, I think our chapter, it's 25 or $50 a year. 265 00:13:44,640 --> 00:13:49,620 Uh, but that also pays for, um, you know, food at an event or you get 266 00:13:49,625 --> 00:13:51,570 discounts to go into some conference. 267 00:13:51,600 --> 00:13:56,490 Uh, so there's a lot of, a lot of kind of cool ecosystem, um, you belong to 268 00:13:56,490 --> 00:13:58,050 once, once you, uh, become a member. 269 00:13:58,740 --> 00:14:01,410 Prasanna Malaiyandi: I am surprised this isn't publicized more 270 00:14:03,120 --> 00:14:08,700 Mike Saylor: It's infraguard.org I N F R A G A R d.org. 271 00:14:08,940 --> 00:14:09,960 W. Curtis Preston: Yeah, I'm all over 272 00:14:10,055 --> 00:14:11,340 Mike Saylor: you can sign up online. 273 00:14:11,700 --> 00:14:16,290 The, uh, the application process is, is can be kind of long, anywhere 274 00:14:16,290 --> 00:14:19,110 from, you know, 45 to 120 days. 275 00:14:19,620 --> 00:14:23,070 Uh, they do a cursory background and then each office has to do kind 276 00:14:23,070 --> 00:14:28,140 of a vetting, uh, to determine if, uh, You know, membership is for you. 277 00:14:28,740 --> 00:14:32,640 Uh, but then, uh, you're invited to kind of a new member session 278 00:14:32,640 --> 00:14:37,080 and you get to meet people, the board, uh, other members, uh, F B I. 279 00:14:37,080 --> 00:14:40,230 And, and one of the things that I'll mention is, so for every InfraGard 280 00:14:40,235 --> 00:14:43,680 chapter there is a full-time F B I agent that is your liaison. 281 00:14:43,770 --> 00:14:46,200 And they, so they kind of manage from the F B I side. 282 00:14:46,605 --> 00:14:48,975 Everything your chapter's doing, even though your chapter has its 283 00:14:48,975 --> 00:14:52,125 own board of directors and event planning and all that stuff, there's 284 00:14:52,125 --> 00:14:54,195 always a full-time F b I person. 285 00:14:54,225 --> 00:14:58,245 Um, at your event, at your board meeting, um, kind of the liaison 286 00:14:58,245 --> 00:15:01,185 for anything you need that the, that the bureau can, can help you with. 287 00:15:01,830 --> 00:15:02,550 Prasanna Malaiyandi: That's awesome. 288 00:15:02,730 --> 00:15:02,940 Now, 289 00:15:03,750 --> 00:15:04,080 W. Curtis Preston: Go ahead. 290 00:15:05,400 --> 00:15:07,860 Prasanna Malaiyandi: just a follow up, I know you talked about sort of 291 00:15:07,860 --> 00:15:10,070 establishing those relationships, right? 292 00:15:10,070 --> 00:15:17,190 With other people who are in the chapter, do they do things like tabletop exercises 293 00:15:17,190 --> 00:15:18,720 or other things or is that kind of, I. 294 00:15:19,605 --> 00:15:21,335 Outside the scope of this group. 295 00:15:22,710 --> 00:15:25,830 Mike Saylor: So the, the InfraGard membership, well, and, and different 296 00:15:25,830 --> 00:15:29,010 chapters do different things like the Louisiana chapter is there. 297 00:15:29,805 --> 00:15:35,505 They're kind of known for, um, uh, anti, you know, maritime 298 00:15:35,565 --> 00:15:38,295 anti drone capabilities. 299 00:15:38,565 --> 00:15:41,805 So there are people at, in that chapter that are involved in how to 300 00:15:41,805 --> 00:15:46,515 protect businesses along the river, uh, from drones and drone strikes and 301 00:15:46,515 --> 00:15:48,045 surveillance and all that good stuff. 302 00:15:48,435 --> 00:15:51,285 And so they, they do exercises pretty often and they have 303 00:15:51,285 --> 00:15:52,425 some really good events. 304 00:15:52,725 --> 00:15:55,125 And they're, the Houston chapter's, good New York chapter. 305 00:15:55,125 --> 00:15:59,745 Not only do they do, um, Exercises, but they have a podcast, so 306 00:15:59,745 --> 00:16:01,335 they, they broadcast things. 307 00:16:01,335 --> 00:16:04,095 I, I wanna say it was at least weekly, maybe monthly, but I 308 00:16:04,095 --> 00:16:07,515 think it's weekly and they're very well known for their multimedia. 309 00:16:08,055 --> 00:16:10,695 Um, and so there, there are different chapters kind of 310 00:16:10,695 --> 00:16:12,255 specialize and do their own thing. 311 00:16:12,405 --> 00:16:17,670 Um, But then you're also invited to bigger events. 312 00:16:17,760 --> 00:16:22,620 Uh, so, um, I know that there's kind of a, uh, a large scale FEMA 313 00:16:22,620 --> 00:16:24,690 event, uh, every now and then. 314 00:16:24,720 --> 00:16:27,360 And so we're, you know, we're invited to participate in that. 315 00:16:27,780 --> 00:16:30,240 But as a chapter, as a community, we don't. 316 00:16:31,305 --> 00:16:34,665 The North Texas chapter has not gotten together and said, you know, we could 317 00:16:34,665 --> 00:16:38,685 probably add a lot of value if we start to collaborate and, and participate together. 318 00:16:38,775 --> 00:16:41,745 Uh, maybe this time we help, you know, this, this company or this 319 00:16:41,745 --> 00:16:45,555 set of companies, maybe this, this sector like technology or healthcare. 320 00:16:45,825 --> 00:16:48,795 And, you know, next time we focus on something else, I think it's a great idea. 321 00:16:48,795 --> 00:16:51,555 But, uh, I, I haven't seen it done, but it's definitely something 322 00:16:51,555 --> 00:16:52,285 that they're open to doing. 323 00:16:53,325 --> 00:16:54,495 W. Curtis Preston: Yeah, this is great. 324 00:16:54,545 --> 00:16:57,305 So, well let me just ask you one, one final question about this 325 00:16:57,305 --> 00:16:58,985 topic and then I wanna move on. 326 00:16:59,435 --> 00:17:05,765 Um, and that is, there is a debate when, you know, as I've been continuing to 327 00:17:05,765 --> 00:17:11,945 research incident response, having to do with ransomware, there is a debate as to. 328 00:17:12,290 --> 00:17:15,800 When or if to contact the F B I, right? 329 00:17:15,800 --> 00:17:20,060 Or just law enforcement in general, but in the us The F B I W. 330 00:17:20,060 --> 00:17:21,550 What's your opinion on that? 331 00:17:22,840 --> 00:17:28,010 Mike Saylor: Uh, my opinion is as soon as possible, however, um, You know, 332 00:17:28,010 --> 00:17:31,520 it's not always up to, to us and us by us, I mean, you know, technology, 333 00:17:31,520 --> 00:17:34,670 leadership, you know, whether you're the CISO or the c I o, unless, unless 334 00:17:34,670 --> 00:17:40,580 you're chartered to do so by executive management, uh, I always suggest that 335 00:17:40,585 --> 00:17:44,720 whoever the IT leadership is, you know, we're just, we're just putting out a fire. 336 00:17:45,290 --> 00:17:46,070 Uh, you know what? 337 00:17:46,070 --> 00:17:48,020 Whatever the incident is, we're putting out the fire. 338 00:17:48,020 --> 00:17:50,750 So from a technology perspective, our job is to recover. 339 00:17:50,765 --> 00:17:54,245 Or from a business perspective, you really need to defer that to your 340 00:17:54,245 --> 00:17:59,285 legal counsel or, or your, whoever your executive is or your insurance company. 341 00:17:59,795 --> 00:18:01,775 Uh, but your insurance company is gonna say, involve law 342 00:18:01,775 --> 00:18:03,065 enforcement as soon as possible. 343 00:18:03,365 --> 00:18:06,395 Your legal counsel, whether it's internal or, or, or outside 344 00:18:06,395 --> 00:18:08,585 counsel is gonna want to know more. 345 00:18:08,915 --> 00:18:14,120 Um, But at, at the end of the day, uh, and I, and I've, I've seen this from, 346 00:18:14,270 --> 00:18:15,740 from a lot of different perspectives. 347 00:18:15,745 --> 00:18:18,230 'cause I'm also, I also do expert testimony in court. 348 00:18:18,230 --> 00:18:21,020 So if this ended up in court, you know, one of the things 349 00:18:21,020 --> 00:18:23,060 that that benefits you from. 350 00:18:23,420 --> 00:18:26,480 Contacting law enforcement as soon as possible is, is a 351 00:18:26,480 --> 00:18:27,860 phrase called due diligence. 352 00:18:28,160 --> 00:18:32,690 So when, when we talk about, all right, so you guys screwed up, but how diligent 353 00:18:32,690 --> 00:18:34,340 were you in trying to prevent this? 354 00:18:34,340 --> 00:18:36,440 How diligent were you in responding to this? 355 00:18:36,440 --> 00:18:39,740 And how diligent were you in, in asking for help from everybody that you 356 00:18:39,740 --> 00:18:41,630 could possibly ask from for help from? 357 00:18:41,750 --> 00:18:43,810 And how open were you in? 358 00:18:44,070 --> 00:18:47,945 Um, And understanding and communicating what the problem was. 359 00:18:48,275 --> 00:18:52,985 And so if, if in any of those phases, uh, you're perceived as less than 360 00:18:52,985 --> 00:18:56,005 diligent, uh, and possibly, um, I. 361 00:18:56,375 --> 00:18:59,615 You know, hiding something or, or, or trying to cover something 362 00:18:59,615 --> 00:19:01,535 up when it gets to damages. 363 00:19:01,535 --> 00:19:04,955 If, if this lawsuit goes to damages, that's where it's gonna come back on you. 364 00:19:05,405 --> 00:19:08,525 Uh, 'cause everybody that, that goes through an incident, obviously you're 365 00:19:08,525 --> 00:19:10,265 guilty of having gone through an incident. 366 00:19:10,325 --> 00:19:13,865 You didn't do enough of something, which is almost impossible. 367 00:19:13,865 --> 00:19:17,195 But, you know, when you're in court, it's kind of black and white and you, 368 00:19:17,645 --> 00:19:20,435 at the end of the day, the fact is you had a breach, you had an incident, 369 00:19:20,435 --> 00:19:22,175 and it, it resulted in these things. 370 00:19:22,745 --> 00:19:24,755 Um, all right, so there's. 371 00:19:25,290 --> 00:19:27,050 You, you, you get a judgment for that. 372 00:19:27,440 --> 00:19:28,850 Alright, well then we go to damages. 373 00:19:28,850 --> 00:19:31,700 And some of that's black and white too, California especially, you 374 00:19:31,700 --> 00:19:35,150 know, for every record of California citizen, there's, it's defined. 375 00:19:35,690 --> 00:19:38,660 But, uh, on top of that, uh, so that's statutory. 376 00:19:38,660 --> 00:19:42,500 But then the, the judge can say, you guys were not diligent in 377 00:19:42,500 --> 00:19:44,690 protecting, responding, communicating. 378 00:19:45,050 --> 00:19:48,200 And, and because of that, I'm going to assess these additional fines. 379 00:19:48,980 --> 00:19:51,230 And so, uh, there's a lot to consider. 380 00:19:51,470 --> 00:19:54,890 And back to the tabletop exercise, that's when you need to start talking 381 00:19:54,890 --> 00:19:58,190 through, this is how this should actually go, and someone's gonna 382 00:19:58,190 --> 00:19:59,690 go, when do we call law enforcement? 383 00:19:59,690 --> 00:20:03,680 And we should look at the people in the room that would typically have 384 00:20:03,680 --> 00:20:07,640 that answer, and let's get that in writing ahead of time, uh, and put 385 00:20:07,640 --> 00:20:11,450 that in our plan as, uh, as part of, uh, how we respond to stuff. 386 00:20:12,095 --> 00:20:16,085 W. Curtis Preston: You don't want to be the, the, the, the rogue, uh, incident 387 00:20:16,090 --> 00:20:21,365 response cyber security person just randomly deciding to call the F B I. 388 00:20:21,905 --> 00:20:23,965 Uh, this needs to be decided up upfront. 389 00:20:24,710 --> 00:20:27,290 Mike Saylor: now I've been through some incidents, uh, just real quick 390 00:20:27,295 --> 00:20:34,340 where, uh, the incident was something illegal and management said, you're 391 00:20:34,340 --> 00:20:35,370 not reporting that to anybody. 392 00:20:35,540 --> 00:20:39,350 We'll handle it internally, but there are certain cases where 393 00:20:39,350 --> 00:20:41,210 you are a mandatory reporter. 394 00:20:41,600 --> 00:20:46,370 Having identified certain types of things, um, and it's kind of up to 395 00:20:46,370 --> 00:20:50,810 you on how to handle that, but I would suggest, uh, even if management 396 00:20:50,810 --> 00:20:54,230 said, don't report it, that's your, your life you're dealing with. 397 00:20:54,230 --> 00:20:56,960 If they find out you didn't report it and you knew about it, now you're going to 398 00:20:56,960 --> 00:20:58,550 jail regardless of what your boss said. 399 00:20:59,120 --> 00:21:03,770 Um, so I would suggest there's ways doing anonymous, uh, reporting and 400 00:21:03,770 --> 00:21:08,360 then just capture that activity as evidence that you did report it. 401 00:21:08,780 --> 00:21:12,620 Um, So there's, there's a, there's a lot of things to consider when you're, you're 402 00:21:12,620 --> 00:21:14,720 responsible for responding to stuff. 403 00:21:15,140 --> 00:21:19,310 Uh, and in addition to that, you may have access to things that, that require you as 404 00:21:19,310 --> 00:21:21,170 a mandatory reporter for doing something. 405 00:21:21,725 --> 00:21:23,765 Prasanna Malaiyandi: I was interesting you brought that up, Mike. 406 00:21:23,765 --> 00:21:27,335 I was just reading a, I think on Twitter or read or something like that where 407 00:21:27,605 --> 00:21:32,315 people were saying like as a programmer, right, if you're asked to do something, 408 00:21:32,315 --> 00:21:36,125 which doesn't seem right, right, and the company gets caught in the end, 409 00:21:36,130 --> 00:21:38,705 you're sort of the one responsible because you wrote the code, right? 410 00:21:38,705 --> 00:21:42,095 You did something when someone told you to do something illegal, potentially. 411 00:21:42,515 --> 00:21:42,785 Right? 412 00:21:42,785 --> 00:21:44,585 And it's still your neck on the line. 413 00:21:44,595 --> 00:21:50,115 Versus like, no one ever really gets like penalized like that for 414 00:21:50,120 --> 00:21:51,945 saying no to doing something illegal. 415 00:21:52,635 --> 00:21:52,965 Right. 416 00:21:52,965 --> 00:21:57,105 And so it applies in various cases, including responding to being 417 00:21:57,110 --> 00:21:58,455 told to do something illegal. 418 00:21:58,845 --> 00:22:01,305 Uh, the one thing I did want to ask you, Mike, just going back to the 419 00:22:01,305 --> 00:22:06,255 question Curtis asked about sort of reporting, how do you feel that 420 00:22:06,255 --> 00:22:12,405 companies have done in being transparent about cybersecurity incidences? 421 00:22:12,405 --> 00:22:12,435 I. 422 00:22:13,460 --> 00:22:16,130 Mike Saylor: Well, I think that's a double-edged sword because it could 423 00:22:16,130 --> 00:22:18,860 seem like they're not being very transparent when really they just 424 00:22:18,860 --> 00:22:20,060 don't have a clue of what's going on. 425 00:22:20,825 --> 00:22:22,475 Uh, and, and I think that's the case. 426 00:22:22,475 --> 00:22:24,575 The majority of the time we got ransomware. 427 00:22:24,605 --> 00:22:25,565 How did it happen? 428 00:22:25,685 --> 00:22:29,165 Someone clicked something, I guess, but they really don't know, or that's 429 00:22:29,165 --> 00:22:32,435 what they were told, even though that's not maybe really how it happened. 430 00:22:32,855 --> 00:22:37,295 So I think understanding and understanding comes from, you know, information. 431 00:22:37,295 --> 00:22:38,495 Well, how do we get information? 432 00:22:38,500 --> 00:22:40,205 Well, you've gotta have the right technology stack. 433 00:22:40,205 --> 00:22:43,865 You've gotta have the right visibility and people and all reporting. 434 00:22:44,765 --> 00:22:50,090 And if, if any one of those areas is lacking, Then your ability to 435 00:22:50,210 --> 00:22:53,120 really know what happened, uh, is diminished to some degree. 436 00:22:53,120 --> 00:22:56,990 So I, I think there's two, there's, there's, there's a couple of perspectives. 437 00:22:56,990 --> 00:22:58,160 I'm not just gonna say there's two. 438 00:22:58,160 --> 00:23:01,560 There's, there's the one where they just really didn't know what happened in their. 439 00:23:02,420 --> 00:23:05,360 They're sharing what they, they know in whatever way they know how. 440 00:23:05,810 --> 00:23:09,290 Uh, and a lot of those cases, it's because they tried to address it on their own. 441 00:23:09,380 --> 00:23:13,040 They didn't bring in the law enforcement or outside help or 442 00:23:13,040 --> 00:23:14,900 professional firm or, or what have you. 443 00:23:15,230 --> 00:23:16,550 They just said, we had a problem. 444 00:23:16,610 --> 00:23:20,750 We're gonna accept the, you know, the, the fact that it happened and pay 445 00:23:20,755 --> 00:23:24,440 our dues or, you know, whatever the consequences are and we'll move on. 446 00:23:25,010 --> 00:23:26,840 And, uh, so there's that perspective. 447 00:23:26,840 --> 00:23:29,270 The other one is companies that truly. 448 00:23:29,945 --> 00:23:33,095 Can't or have decided they can't take the reputational 449 00:23:33,095 --> 00:23:35,315 risk of divulging what happened. 450 00:23:35,735 --> 00:23:38,015 Uh, some of that might be privacy or contractual. 451 00:23:38,015 --> 00:23:42,155 Like you will never tell people that our network was, uh, compromised 452 00:23:42,155 --> 00:23:45,065 because that, because we rely on you for these other things. 453 00:23:45,070 --> 00:23:48,815 And so clients could be impacted by, by your incident, you know, their, 454 00:23:48,845 --> 00:23:50,315 their business or service too. 455 00:23:50,315 --> 00:23:54,725 So, uh, depending on how your business functions and how you, how complex it is 456 00:23:54,730 --> 00:23:57,245 with, with providing services or data to. 457 00:23:57,755 --> 00:23:59,645 To clients or third parties. 458 00:23:59,675 --> 00:24:03,275 Uh, you may be limited in what you can say, um, but I think what you're 459 00:24:03,275 --> 00:24:07,325 getting at is, yeah, there are definitely companies out there that will deny 460 00:24:07,325 --> 00:24:08,765 altogether that there was a comp. 461 00:24:08,765 --> 00:24:12,665 I don't, so, you know, some, some bad guys put all of our customer data on 462 00:24:12,665 --> 00:24:14,555 the, on the internet and you can see it. 463 00:24:14,915 --> 00:24:20,015 They'll, they will still deny to the nth degree that they were not compromised, 464 00:24:20,015 --> 00:24:21,425 that they did not get that data from us. 465 00:24:21,425 --> 00:24:24,245 And I was actually in a case like that with a telecom company. 466 00:24:24,755 --> 00:24:28,655 Uh, the Secret Service called us and said, Actually the F b I called 467 00:24:28,655 --> 00:24:31,595 us first and said, we're seeing your client data on the internet. 468 00:24:32,165 --> 00:24:34,985 And um, this was in the, the late nineties. 469 00:24:35,135 --> 00:24:37,745 Um, we're seeing your customer's data on the internet. 470 00:24:38,285 --> 00:24:42,275 And when we started looking into it, they were all of our internet customers. 471 00:24:42,665 --> 00:24:45,515 And so we went back to our internet provider and said, it looks like all 472 00:24:45,515 --> 00:24:50,720 this data's coming from you, and they denied it Well, Secret Service got 473 00:24:50,720 --> 00:24:52,970 involved, uh, due to jurisdiction. 474 00:24:52,970 --> 00:24:54,530 It was different states and different things. 475 00:24:54,530 --> 00:24:58,910 And so we went, we actually went to that company, uh, onsite with the 476 00:24:58,910 --> 00:25:01,640 Secret Service and said, we're here to talk about this, that, and the other. 477 00:25:01,640 --> 00:25:02,900 And well, it wasn't us. 478 00:25:03,320 --> 00:25:04,880 Uh, it, it didn't come from us. 479 00:25:05,300 --> 00:25:09,290 Well, all the data that we were seeing, and it's not just related 480 00:25:09,290 --> 00:25:11,450 to you, it's got metadata in it. 481 00:25:11,450 --> 00:25:12,410 That said it did come from you. 482 00:25:12,440 --> 00:25:12,920 No, it didn't. 483 00:25:13,310 --> 00:25:15,140 Well, we're not leaving until we talk to somebody, so they 484 00:25:15,140 --> 00:25:16,430 put us in this conference room. 485 00:25:16,925 --> 00:25:17,825 And locked us in there. 486 00:25:17,830 --> 00:25:19,715 Didn't let us out to go talk to anybody. 487 00:25:19,715 --> 00:25:21,575 And we had to, like, someone would come in and say, what do 488 00:25:21,575 --> 00:25:22,475 you want to, what do you need? 489 00:25:22,475 --> 00:25:23,075 And we would say it. 490 00:25:23,075 --> 00:25:26,495 And they would go out and, and look, uh, or, or collect that for us. 491 00:25:26,500 --> 00:25:30,845 And, uh, sometime during the day, I asked if I could plug into their, their 492 00:25:30,845 --> 00:25:34,835 wall jack and, uh, so I could have internet access to, to check email. 493 00:25:34,835 --> 00:25:35,495 And they said, sure. 494 00:25:35,885 --> 00:25:39,635 Well, I started running, running a, a network sniffer, uh, capturing network 495 00:25:39,785 --> 00:25:40,115 W. Curtis Preston: you did. 496 00:25:40,850 --> 00:25:43,250 Mike Saylor: And, and back in the day they were using, uh, I C 497 00:25:43,250 --> 00:25:45,500 Q, the, the chat, the chat app. 498 00:25:45,500 --> 00:25:48,140 And I was capturing in plain text everything they were saying. 499 00:25:48,410 --> 00:25:51,590 And it was all about, ha ha, we've got 'em locked in the conference room. 500 00:25:51,590 --> 00:25:54,110 They'll give up talking to us at some point and just go home. 501 00:25:54,110 --> 00:25:55,460 We're not gonna give 'em anything. 502 00:25:55,910 --> 00:26:00,125 Um, Tell Bob that he's safe, you know that his screw up is we're 503 00:26:00,125 --> 00:26:01,685 gonna brush it under the rug and all. 504 00:26:01,865 --> 00:26:05,105 So I remember this, this little secret service lady, uh, and 505 00:26:05,105 --> 00:26:06,215 I say she really was little. 506 00:26:06,215 --> 00:26:07,595 She was like five feet tall. 507 00:26:08,075 --> 00:26:09,785 Um, her name was Kim. 508 00:26:09,785 --> 00:26:13,595 She kicked the conference room door open and it was, it was the door that 509 00:26:13,595 --> 00:26:15,545 opened in, but she kicked it out. 510 00:26:15,545 --> 00:26:16,235 I mean, she. 511 00:26:16,790 --> 00:26:20,270 She knew how to kick a door and she kicked that door and said, I need 512 00:26:20,330 --> 00:26:23,750 the executive team in this office right in front of me in the next five 513 00:26:23,750 --> 00:26:25,010 minutes where people are going to jail. 514 00:26:25,340 --> 00:26:26,600 And she took control. 515 00:26:26,600 --> 00:26:32,570 And, and it was probably, uh, maybe later that year, we actually 516 00:26:32,570 --> 00:26:33,920 caught the hacker that did that. 517 00:26:33,920 --> 00:26:35,180 His name was Matthew Freeze. 518 00:26:35,180 --> 00:26:38,210 He, uh, we caught him in Corpus Christi with the Sheriff's Department. 519 00:26:38,750 --> 00:26:40,700 Uh, he's in, I think he's still in jail. 520 00:26:41,100 --> 00:26:41,940 W. Curtis Preston: Right, right. 521 00:26:42,450 --> 00:26:46,140 Well, that's, that's a great story with the, with, with a, with a great climax. 522 00:26:46,140 --> 00:26:49,260 I love the, the agent kicking down the door. 523 00:26:49,290 --> 00:26:52,110 Uh, yeah, that must have been something to be there. 524 00:26:52,590 --> 00:26:56,790 Um, so, so let me, let, let me do a change of tack here. 525 00:26:57,480 --> 00:27:01,320 So, you know, let's say we're a company, we have done. 526 00:27:02,265 --> 00:27:06,405 From a, so we, you know, we have, we have an incident response plan, right? 527 00:27:06,405 --> 00:27:10,305 We, we've, we've decided whether or not we're gonna contact law enforcement. 528 00:27:10,725 --> 00:27:15,555 We, um, we did all of the things that a cybersecurity company asked 529 00:27:15,555 --> 00:27:19,336 us to do in terms of prevention and, and, and all of those things. 530 00:27:20,275 --> 00:27:21,680 One thing I am. 531 00:27:23,090 --> 00:27:29,060 Interested in is obviously we, we spend a lot of our time with 532 00:27:29,120 --> 00:27:30,920 talking about ransomware, right? 533 00:27:31,580 --> 00:27:35,750 And the, and I understand that ransomware really in the end is 534 00:27:35,750 --> 00:27:40,970 just a payload of a, a much bigger cybersecurity problem, right? 535 00:27:41,585 --> 00:27:48,695 Um, what I'm seeing a lot is that I, I, I'm reading that now. 536 00:27:49,055 --> 00:27:54,605 I think it was like more than 90% of what we used to just call ransomware 537 00:27:54,605 --> 00:27:59,765 attacks are really exfiltration attacks accompanied with ransomware. 538 00:27:59,825 --> 00:28:00,275 Right. 539 00:28:00,755 --> 00:28:06,395 Um, and so I, I have a couple of, you know, sort of questions about. 540 00:28:07,420 --> 00:28:11,270 Uh, starting with, you know, given the way, the way a typical 541 00:28:11,270 --> 00:28:13,430 ransomware attack happens, right? 542 00:28:13,430 --> 00:28:16,640 You get the initial access broker, then you get somebody that's in there 543 00:28:16,760 --> 00:28:19,130 and they start probing around, right? 544 00:28:19,130 --> 00:28:22,430 They start seeing how they can, you know, how they can get around. 545 00:28:22,670 --> 00:28:26,240 And then my understanding is as soon as they can, they start exfiltrating data. 546 00:28:26,840 --> 00:28:30,050 So my question is, it is sort of two questions. 547 00:28:31,490 --> 00:28:36,230 you know, beyond the usual, you know, there are some things, you 548 00:28:36,230 --> 00:28:38,510 know, there are some things that we know we should all be doing, right? 549 00:28:38,510 --> 00:28:41,900 You know, in terms of password management and M f A and, um, you 550 00:28:41,900 --> 00:28:45,950 know, all, all of those you, you know, and, and, and, uh, patch management. 551 00:28:47,060 --> 00:28:49,910 Um, can you think of some things. 552 00:28:50,330 --> 00:28:55,520 That a company that wants to take that next step, things that, 553 00:28:55,525 --> 00:29:01,760 that, that could either stop, um, lateral movement number one. 554 00:29:02,450 --> 00:29:06,080 And then, and then just as importantly, if not, if not more 555 00:29:06,085 --> 00:29:08,210 importantly, exfiltration of data. 556 00:29:09,800 --> 00:29:11,030 That was a really long question. 557 00:29:11,030 --> 00:29:11,810 Sorry about that. 558 00:29:12,395 --> 00:29:15,335 Mike Saylor: And, and I had so many things I wanted to chime in with that. 559 00:29:15,335 --> 00:29:20,225 I've, I've lost some of them, but, uh, I'm, I'm glad you, I'm glad When you 560 00:29:20,225 --> 00:29:24,035 said typical ransomware, you didn't go down, they, they clicked on an email. 561 00:29:24,065 --> 00:29:25,745 'cause that's not typical anymore. 562 00:29:25,745 --> 00:29:27,335 That's, that's statistically the. 563 00:29:28,055 --> 00:29:31,565 Probably the higher probability of success, but in a lot of cases 564 00:29:31,565 --> 00:29:34,775 it's just that user that gets compromised, not not the whole company. 565 00:29:35,375 --> 00:29:40,715 So you're right, typically the, the enterprise, uh, scale attack 566 00:29:40,745 --> 00:29:45,515 is, uh, via some either access broker or the ransomware campaign. 567 00:29:45,575 --> 00:29:47,435 Uh, has, you know, their own. 568 00:29:48,155 --> 00:29:52,685 Uh, squad of pen testers that are finding ways into environments, but you're right. 569 00:29:52,685 --> 00:29:56,105 So typically it is access to the environment that then, you know, as 570 00:29:56,110 --> 00:29:59,255 far as the phases of attack goes, then they start, uh, the reconnaissance. 571 00:30:00,275 --> 00:30:03,515 Uh, to answer your question about, um, how do we, how do we 572 00:30:03,520 --> 00:30:05,675 address the exfiltration piece? 573 00:30:05,765 --> 00:30:10,385 Um, my favorite response is it depends, and I say that a lot in a lot of 574 00:30:10,385 --> 00:30:14,840 different scenarios and, and, Uh, and it's for good reason because it 575 00:30:14,840 --> 00:30:17,570 really depends on the organization. 576 00:30:18,170 --> 00:30:22,370 And so each company needs to go through an exercise of figuring out what's important 577 00:30:22,370 --> 00:30:28,760 to them and where is it because maybe your data's already exfiltrated, it's 578 00:30:28,760 --> 00:30:30,500 out in, you know, a cloud somewhere. 579 00:30:30,500 --> 00:30:33,620 So I'm not even have to attack your company anymore. 580 00:30:33,625 --> 00:30:36,590 I just have to go figure out where your data is and attack that company. 581 00:30:37,100 --> 00:30:40,460 Um, and, or maybe it's a partner or whoever, and there's 582 00:30:40,465 --> 00:30:41,750 tons of examples of, of. 583 00:30:42,635 --> 00:30:43,775 F bad guys. 584 00:30:43,775 --> 00:30:47,375 Figuring out where the, where the important stuff is and making best 585 00:30:47,375 --> 00:30:48,905 use of their time and resources. 586 00:30:48,955 --> 00:30:53,035 So, so it really does depend on the organization, uh, understanding 587 00:30:53,035 --> 00:30:56,425 your technology stack, your architecture, your culture. 588 00:30:57,185 --> 00:30:57,305 I. 589 00:30:57,325 --> 00:31:00,025 Uh, and then obviously where is your stuff? 590 00:31:00,085 --> 00:31:00,745 Is it data? 591 00:31:00,745 --> 00:31:02,875 Is it a system, is it a service? 592 00:31:02,995 --> 00:31:05,155 Uh, because that's what bad guys are gonna figure out when 593 00:31:05,155 --> 00:31:06,505 they're doing the reconnaissance. 594 00:31:06,505 --> 00:31:08,875 They're looking for, you know, who is this company? 595 00:31:08,875 --> 00:31:12,565 'cause in a lot of cases, they don't, they didn't specifically attack you. 596 00:31:13,015 --> 00:31:16,015 Uh, they just, they were running some tools and found a vulnerability and 597 00:31:16,015 --> 00:31:18,835 they picked at it, and now they've got access to some company's network. 598 00:31:19,195 --> 00:31:20,605 So they've gotta figure that out first. 599 00:31:20,995 --> 00:31:23,635 Once they figure out who you are, they wanna figure out what you do. 600 00:31:23,755 --> 00:31:26,035 Uh, where, where is your important stuff? 601 00:31:26,560 --> 00:31:27,880 Including your backups. 602 00:31:28,210 --> 00:31:31,930 Uh, and then to some degree, they're also looking for your financials and if they 603 00:31:31,930 --> 00:31:37,300 can find a copy of your insurance, uh, policy, all these things, well, all right. 604 00:31:37,300 --> 00:31:42,820 So depending on the company, uh, and, and your organization's particular situation, 605 00:31:43,240 --> 00:31:47,020 um, there are ways of addressing. 606 00:31:47,950 --> 00:31:52,150 Uh, the data exfiltration problem, one of those is, well, let's put our ti 607 00:31:52,180 --> 00:31:53,860 put tighter controls around our data. 608 00:31:53,865 --> 00:31:58,810 And that includes like data integrity, monitor file integrity monitoring, um, 609 00:31:59,290 --> 00:32:04,300 restricted access, network segmentation, firewall rules that throttle, you know, 610 00:32:04,300 --> 00:32:07,900 data uploads or alerts of, of doing so. 611 00:32:08,320 --> 00:32:12,640 Um, but I did wanna address one, um, one comment you made. 612 00:32:12,640 --> 00:32:14,260 How do we prevent this from happening? 613 00:32:14,260 --> 00:32:14,920 And I really think. 614 00:32:15,565 --> 00:32:19,885 People need to stop thinking about preventing it and start looking at 615 00:32:19,885 --> 00:32:23,815 ways of identifying it as soon as possible with either automated or 616 00:32:23,815 --> 00:32:26,005 human response as soon as possible. 617 00:32:26,335 --> 00:32:29,695 Uh, and then how do we collect all the information we need to make sure 618 00:32:29,700 --> 00:32:32,755 that we understand how it happened, what they did, and, and capture 619 00:32:32,755 --> 00:32:34,045 what we did to respond to that. 620 00:32:34,465 --> 00:32:38,725 And so that's very important, uh, for a lot of different reasons. 621 00:32:38,725 --> 00:32:44,875 One, if you put too much, uh, emphasis on prevention, then. 622 00:32:45,340 --> 00:32:46,570 A couple of things are gonna happen. 623 00:32:46,570 --> 00:32:51,520 One, you've, you've invested a lot of money that could be more appropriately 624 00:32:51,520 --> 00:32:54,070 used in identification and response. 625 00:32:54,550 --> 00:32:58,720 Uh, two, you're very likely going to become complacent thinking that you've 626 00:32:58,720 --> 00:33:01,810 got everything in place you need, and that's not gonna happen to us. 627 00:33:02,620 --> 00:33:05,920 And then lastly, a lot of those preventative controls don't do 628 00:33:05,920 --> 00:33:08,860 the data collection necessary to figure out how things happened. 629 00:33:09,400 --> 00:33:11,830 Um, and, and we get asked a lot. 630 00:33:11,920 --> 00:33:15,580 We had this incident and all we need to know is, is there 631 00:33:15,580 --> 00:33:17,050 evidence of data exfiltration? 632 00:33:18,640 --> 00:33:20,110 Because that's all we have to report. 633 00:33:20,115 --> 00:33:22,210 So what we had ransomware, so what we had a breach. 634 00:33:22,210 --> 00:33:24,670 If there was no data taken, then we don't have to report it. 635 00:33:25,090 --> 00:33:25,600 Okay, great. 636 00:33:25,600 --> 00:33:28,900 Well, let's look at your technology stack and, and the things that you have 637 00:33:28,905 --> 00:33:32,410 that would've collected that information and they didn't have anything or what 638 00:33:32,410 --> 00:33:33,910 they have wasn't configured well. 639 00:33:34,195 --> 00:33:38,065 And so we didn't have the information to, to determine whether or not 640 00:33:38,065 --> 00:33:40,135 data was exfiltrated to any degree. 641 00:33:40,675 --> 00:33:44,305 Uh, so we could see the, the network connections and the sessions, uh, 642 00:33:44,305 --> 00:33:48,325 but we couldn't see, uh, the data throughput or, or even what the data was. 643 00:33:48,685 --> 00:33:49,135 Prasanna Malaiyandi: so. 644 00:33:49,480 --> 00:33:53,320 In that case though, Mike, is it you have to assume worst case, that there 645 00:33:53,320 --> 00:33:58,210 was personal data or other things that was exfiltrated or is it, I don't 646 00:33:58,210 --> 00:34:02,440 know what was happened, so I'll just say I don't know or nothing happened. 647 00:34:02,815 --> 00:34:04,315 Mike Saylor: There's a couple of things there too. 648 00:34:04,705 --> 00:34:09,655 Uh, so I mean, fundamentally, all of your data should be encrypted as often as it 649 00:34:09,655 --> 00:34:11,995 as it can be, uh, at rest in transit. 650 00:34:12,085 --> 00:34:18,175 Um, so that if it is exfiltrated, you, you, you were diligent protecting your 651 00:34:18,180 --> 00:34:22,975 data so that if it was stolen, there's a small likelihood that it's even usable. 652 00:34:23,845 --> 00:34:26,305 Well, not usable within, you know, relatively, you 653 00:34:26,305 --> 00:34:27,145 know, 10 years or whatever. 654 00:34:27,310 --> 00:34:27,400 Right. 655 00:34:27,910 --> 00:34:31,480 Um, so encryption is very important from a diligence perspective. 656 00:34:31,930 --> 00:34:37,180 Well then in the absence of evidence that data was exfiltrated, um, 657 00:34:37,210 --> 00:34:40,060 and this is something you have to work with your legal counsel on. 658 00:34:40,390 --> 00:34:46,420 How do we then word our communication, uh, to employees or clients or even the state 659 00:34:46,480 --> 00:34:48,610 or regulatory agency about what happened? 660 00:34:49,000 --> 00:34:56,920 And very often it is, uh, stated similar to, uh, no evidence was found to support. 661 00:34:57,760 --> 00:34:58,150 Right. 662 00:34:58,270 --> 00:35:02,680 So it's not yes or no, it's, we didn't find anything that said it did happen. 663 00:35:03,160 --> 00:35:03,430 W. Curtis Preston: Yeah. 664 00:35:03,430 --> 00:35:05,410 We've talked about a number of those incidents. 665 00:35:05,515 --> 00:35:05,785 Prasanna Malaiyandi: Yeah. 666 00:35:06,595 --> 00:35:09,295 W. Curtis Preston: We, we have no evidence that that data was stolen. 667 00:35:09,295 --> 00:35:13,075 That because we had really bad tracking mechanisms that would 668 00:35:13,075 --> 00:35:14,605 give, that would tell us that data. 669 00:35:14,830 --> 00:35:17,230 Mike Saylor: and it, and it also depends on the threat actors. 670 00:35:17,230 --> 00:35:21,565 There are some threat actors that have a, uh, You know, a good 671 00:35:21,565 --> 00:35:23,125 reputation if you can have one. 672 00:35:23,185 --> 00:35:27,475 Uh, as a, as a threat actor that says, you know, they, they live by their code, 673 00:35:27,955 --> 00:35:32,875 and their code is, you know, if we steal your data, uh, you have, let's just say 674 00:35:32,880 --> 00:35:37,045 three days to acknowledge that you were breached and then you have, uh, and then 675 00:35:37,050 --> 00:35:38,815 we'll, we'll submit to you an offer. 676 00:35:39,355 --> 00:35:44,005 Uh, so you ransom note, and if so, first, if you, if you acknowledge that you are, 677 00:35:44,005 --> 00:35:47,695 were attacked and you contact us within three days, then we won't put your company 678 00:35:47,695 --> 00:35:51,265 on the wall of shame, which is a public indication that you were compromised. 679 00:35:51,265 --> 00:35:54,445 And, and people that know us know that we have some or all of your data. 680 00:35:55,285 --> 00:35:58,675 So we won't do that, and then we'll give you the ransom note. 681 00:35:58,735 --> 00:36:02,425 And if you pay that ransom note, or if we start these negotiations and we get, 682 00:36:02,425 --> 00:36:06,955 we go through this process and you pay us, then we promise to, to destroy all 683 00:36:06,955 --> 00:36:10,705 your data and, and keep it confidential and we'll even give you good tech 684 00:36:10,705 --> 00:36:12,535 support while you're trying to recover. 685 00:36:12,925 --> 00:36:17,575 Um, and so I've been through a variety of, of, of those types of incidents, seeing 686 00:36:17,575 --> 00:36:20,335 the, the gamut of, uh, bad actors that. 687 00:36:20,680 --> 00:36:24,310 Aren't very well organized and don't care, uh, all the way up through 688 00:36:24,310 --> 00:36:28,600 the very organized ones that, that operate like a, like a business and 689 00:36:28,600 --> 00:36:31,540 they've got good customer support or, you know, as good as it can be. 690 00:36:32,020 --> 00:36:38,560 Um, but, um, I will say that, you know, there is a trend towards 691 00:36:38,620 --> 00:36:39,940 data exfiltration with ransomware. 692 00:36:40,750 --> 00:36:46,495 Uh, there's, there's a still a large um, A large occurrence of ransomware where 693 00:36:46,495 --> 00:36:49,705 they don't care about your data, they just wanna make sure you're all locked up. 694 00:36:49,735 --> 00:36:52,285 And that's what they're gonna use for leverage to get you to pay. 695 00:36:52,735 --> 00:36:56,035 Because there's also the, the on the backside of that, even though threat 696 00:36:56,035 --> 00:37:01,105 actors are very risk averse, there's less risk from a, a consequence 697 00:37:01,105 --> 00:37:04,825 perspective, a prosecution perspective of just compromising your network 698 00:37:04,825 --> 00:37:06,145 and, and encrypting your stuff. 699 00:37:06,295 --> 00:37:07,165 Sure, I'll get in trouble. 700 00:37:07,165 --> 00:37:07,345 Sure. 701 00:37:07,345 --> 00:37:10,885 I'll get jail time and all this stuff, but if I also steal your data, 702 00:37:11,200 --> 00:37:15,190 Especially if it's regulatory data, healthcare, p i i, whatever, that's 703 00:37:15,190 --> 00:37:17,500 additional charges if I get caught. 704 00:37:17,740 --> 00:37:21,100 And so in a lot of cases, similar to the data access brokers, you 705 00:37:21,100 --> 00:37:26,170 also have, um, uh, network access brokers in addition to them. 706 00:37:26,170 --> 00:37:27,370 You also have the data brokers. 707 00:37:27,375 --> 00:37:30,130 So you've got the, and so it's this whole ecosystem. 708 00:37:30,130 --> 00:37:31,510 All right, so who do I know? 709 00:37:31,600 --> 00:37:34,180 Who, who can I pay to compromise your network? 710 00:37:34,180 --> 00:37:35,020 Alright, got that. 711 00:37:35,020 --> 00:37:35,920 I have the access. 712 00:37:36,220 --> 00:37:38,110 Who can I pay to develop the payload? 713 00:37:38,455 --> 00:37:39,145 Alright, got that. 714 00:37:39,145 --> 00:37:42,145 So payload's in there, ransomware's running, and now we've got 715 00:37:42,145 --> 00:37:45,025 their environment locked up and we've got this data set. 716 00:37:45,145 --> 00:37:47,335 I don't want the data set 'cause I don't want to get caught with it. 717 00:37:47,335 --> 00:37:50,245 So now I gotta find a data broker that will buy it from me, who knows how 718 00:37:50,245 --> 00:37:51,985 then to kinda like diamonds, right? 719 00:37:52,105 --> 00:37:54,505 I bought the rod diamonds, I gotta find a diamond cutter and then I 720 00:37:54,505 --> 00:37:55,855 gotta find a diamond distributor. 721 00:37:55,860 --> 00:37:57,985 And, you know, everybody makes their own cut. 722 00:37:58,375 --> 00:38:02,635 Um, so there isn't, there are uh, uh, there's still a large volume of, of 723 00:38:02,635 --> 00:38:06,265 attacks where this eco, this whole ecosystem comes into play and, and you're 724 00:38:06,265 --> 00:38:10,075 just, Depending on where you, where you catch the attack, you're dealing 725 00:38:10,075 --> 00:38:12,055 with different, um, threat actors. 726 00:38:12,790 --> 00:38:13,750 W. Curtis Preston: Yeah, that, that's interesting. 727 00:38:13,750 --> 00:38:14,950 I wasn't aware. 728 00:38:15,040 --> 00:38:18,520 Um, you know, it sounds like it's kind of like felony murder, right? 729 00:38:18,520 --> 00:38:22,150 Where, you know, like, um, it, it makes it worse, right? 730 00:38:22,150 --> 00:38:24,280 You killed somebody, but you killed somebody in the 731 00:38:24,280 --> 00:38:25,720 commission of another felony. 732 00:38:25,725 --> 00:38:27,070 It makes it, it makes it worse. 733 00:38:27,920 --> 00:38:30,140 Even if you didn't mean to kill them, right. 734 00:38:30,170 --> 00:38:31,040 That's my understanding. 735 00:38:31,040 --> 00:38:35,330 Like even if it, if it would otherwise be considered like accidental homicide 736 00:38:35,330 --> 00:38:38,300 or whatever, that because you, it happened in the commission of a 737 00:38:38,300 --> 00:38:40,340 felony, it makes it felony murder. 738 00:38:40,760 --> 00:38:43,700 Um, that, that is an interesting concept. 739 00:38:43,760 --> 00:38:49,520 Um, I, I, I, by the way, Mike, even though it sounds like maybe I was saying 740 00:38:49,520 --> 00:38:53,210 differently, I completely agree with you with sort of the, the assumed breach. 741 00:38:53,810 --> 00:38:54,860 Concept, right? 742 00:38:54,860 --> 00:38:59,480 That you need to spend, you need to be just as good if not better, with 743 00:38:59,480 --> 00:39:04,730 detection and response, uh, and recovery than the prevention aspect, right? 744 00:39:05,030 --> 00:39:07,760 Um, you know, having said that, there's nothing wrong with, with 745 00:39:07,760 --> 00:39:09,020 an ounce of prevention, right? 746 00:39:09,410 --> 00:39:14,240 Um, and that's why, um, I, I just, it, it bothers me. 747 00:39:14,900 --> 00:39:18,680 Like, on, on one hand we talk about some of the advanced things that you 748 00:39:18,680 --> 00:39:21,950 could do to, to help, but most people I. 749 00:39:22,535 --> 00:39:26,285 Um, you know, such as preventing, preventing lateral movement 750 00:39:26,285 --> 00:39:28,985 between systems that don't need to have lateral movement, right. 751 00:39:29,735 --> 00:39:34,775 Um, the, there's nothing wrong with that, but you're right, there's a cost and of 752 00:39:34,775 --> 00:39:38,015 doing it initially, there's a cost of maintaining that and there's a cost of. 753 00:39:38,525 --> 00:39:42,425 Of, you know, well, cybersecurity is always a pain, right? 754 00:39:42,425 --> 00:39:45,305 The be the more security you have, the harder it's to do your job. 755 00:39:45,575 --> 00:39:45,845 Right? 756 00:39:45,845 --> 00:39:48,245 Unless you're the si the sc the cybersecurity guy. 757 00:39:48,785 --> 00:39:51,185 Mike Saylor: That's why secure, that's why convenience stores are 758 00:39:51,185 --> 00:39:52,925 robbed more than security stores. 759 00:39:54,470 --> 00:39:55,700 W. Curtis Preston: I see, I see what you did there. 760 00:39:56,210 --> 00:39:59,960 Let's talk about response and recovery. 761 00:40:00,560 --> 00:40:05,930 Um, the, which is generally what we end up talking most of our time about here. 762 00:40:06,290 --> 00:40:10,970 What do you think is, you know, we talked about the things that you 763 00:40:10,970 --> 00:40:15,020 need to do in advance, establishing a communication with the F B I or other law 764 00:40:15,020 --> 00:40:20,270 enforcement, um, you know, establishing a relationship with somebody like yourself. 765 00:40:21,020 --> 00:40:25,190 Um, you know, so, so that you're not, you're not making that conversation the 766 00:40:25,190 --> 00:40:27,530 first time in the middle of an incident. 767 00:40:28,130 --> 00:40:32,780 What else do you think people need to do to be ready to respond, 768 00:40:33,320 --> 00:40:35,180 uh, in, in a cyber attack? 769 00:40:36,570 --> 00:40:40,200 Mike Saylor: Well, I think, uh, ex tabletop exercises are a great way to kind 770 00:40:40,200 --> 00:40:42,780 of ferret that out for your organization. 771 00:40:43,110 --> 00:40:46,110 Sit down with as many people in your company as you can. 772 00:40:46,170 --> 00:40:49,500 I mean, a lot of it departments are like, let's just do it with us first so we don't 773 00:40:49,500 --> 00:40:50,730 look stupid in front of everybody else. 774 00:40:50,730 --> 00:40:51,420 And that's fine. 775 00:40:51,900 --> 00:40:54,450 You know, you know, have a, have your, have your, you 776 00:40:54,450 --> 00:40:55,590 know, red, blue or red white. 777 00:40:55,985 --> 00:41:00,605 You know, scrimmage game, um, but then involve as many people as possible. 778 00:41:00,605 --> 00:41:02,585 And I've seen this be so successful. 779 00:41:03,005 --> 00:41:07,655 Um, and, and even involve your insurance broker and your outside counsel and invite 780 00:41:07,655 --> 00:41:12,905 the F b I invite the Secret Service, um, have this exercise and, and pick a topic. 781 00:41:13,505 --> 00:41:17,345 Um, and whether you do it yourself or, or, you know, look for a moderator. 782 00:41:17,405 --> 00:41:19,535 Uh, and there's a lot of good moderators out there. 783 00:41:19,535 --> 00:41:21,275 I'm, I, I do these all the time. 784 00:41:21,305 --> 00:41:22,865 I'm considered a breach coach. 785 00:41:23,315 --> 00:41:27,065 But then there's, there's even cybersecurity law firms that will, uh, 786 00:41:27,065 --> 00:41:29,015 will facilitate, uh, a good tabletop. 787 00:41:29,015 --> 00:41:30,605 And the idea is, let's pick a topic. 788 00:41:30,665 --> 00:41:34,445 Ransomware or intellectual property theft or. 789 00:41:35,045 --> 00:41:38,615 Um, our data center gets hit by a plane 'cause we're close to an airport. 790 00:41:38,855 --> 00:41:42,065 Whatever it is, pick a topic, invite as many people as you can 791 00:41:42,185 --> 00:41:43,505 and walk through the scenario. 792 00:41:43,910 --> 00:41:48,200 Um, you know, somebody clicked the link and, and you know, they came to 793 00:41:48,200 --> 00:41:52,400 work and their desktop icons are all changed and they can't use anything. 794 00:41:52,400 --> 00:41:54,710 Well, and then we got another call and then, alright, well 795 00:41:54,710 --> 00:41:56,390 let's start with who do they call? 796 00:41:56,420 --> 00:41:57,470 Who does an employee talk? 797 00:41:57,470 --> 00:41:58,460 Who is their phone number? 798 00:41:58,460 --> 00:42:00,140 Is there an what if email doesn't work? 799 00:42:00,800 --> 00:42:01,970 Uh, so who do they call? 800 00:42:01,970 --> 00:42:03,470 And then what does that person do? 801 00:42:03,500 --> 00:42:05,780 How do we, how do we assess the situation? 802 00:42:06,080 --> 00:42:08,930 And which is, you know, kind of phase one of incident response is how do we 803 00:42:08,930 --> 00:42:11,300 categorize this event into an incident? 804 00:42:11,450 --> 00:42:12,440 Is it a non-event? 805 00:42:12,680 --> 00:42:13,520 Is it critical? 806 00:42:13,850 --> 00:42:16,880 Uh, and then that then based on your plan, would indicate 807 00:42:16,880 --> 00:42:18,230 who else needs to be involved. 808 00:42:18,230 --> 00:42:23,240 Once we categorize, once we categorize the, uh, the incident, well then I. 809 00:42:24,005 --> 00:42:27,545 Having as many people there as possible is, is valuable two ways. 810 00:42:27,545 --> 00:42:29,945 One, maybe you don't know who needs to be in involved. 811 00:42:29,945 --> 00:42:33,185 And you can start asking all the attendees, uh, who are the right 812 00:42:33,185 --> 00:42:37,175 people, uh, because you know, I sent this email out five months ago and 813 00:42:37,175 --> 00:42:39,545 nobody's responded who the right person is, but we're all in the same room. 814 00:42:39,545 --> 00:42:40,175 Let's working out. 815 00:42:40,745 --> 00:42:44,075 But at the same time, uh, you're gonna get some people going. 816 00:42:44,225 --> 00:42:44,645 I. 817 00:42:45,485 --> 00:42:48,665 Would've had no idea that's what's involved with doing X, Y, 818 00:42:48,665 --> 00:42:50,165 or Z unless I was in this room. 819 00:42:50,675 --> 00:42:52,205 And I'll tell you a funny story. 820 00:42:52,205 --> 00:42:56,015 We were doing a, a tabletop for a, a company, uh, I think they're in 821 00:42:56,015 --> 00:43:03,545 healthcare and part of the scenario was, uh, threat actor used the contact us. 822 00:43:04,475 --> 00:43:07,745 Button on their website to say, that's how they said, you 823 00:43:07,745 --> 00:43:09,005 know, we have all your data. 824 00:43:09,395 --> 00:43:10,505 Call us in three days. 825 00:43:11,015 --> 00:43:13,085 Um, and here's the information to do so. 826 00:43:13,385 --> 00:43:14,585 And so that was part of the scenario. 827 00:43:14,585 --> 00:43:17,585 So I, uh, I asked, well, who's in charge of the website? 828 00:43:17,590 --> 00:43:19,655 And there were two people in the audience and they said, we are. 829 00:43:19,655 --> 00:43:21,965 And I said, well, what would you do if you got that email? 830 00:43:21,965 --> 00:43:23,375 And they said, we'd probably delete it. 831 00:43:23,375 --> 00:43:24,935 'cause we wouldn't believe it was true. 832 00:43:25,535 --> 00:43:27,815 Well, okay, well maybe you shouldn't delete it anymore. 833 00:43:27,815 --> 00:43:30,305 You should, you know, forward that to the security team 834 00:43:30,305 --> 00:43:31,475 and let them figure that out. 835 00:43:31,805 --> 00:43:32,525 And they said, good. 836 00:43:32,795 --> 00:43:34,595 Good call, uh, good policy. 837 00:43:34,595 --> 00:43:38,435 So, but there were, there were a lot of people in the audience that said, I'm 838 00:43:38,435 --> 00:43:42,785 glad I was here because I would've had no idea that all these moving parts, 839 00:43:42,785 --> 00:43:46,505 and this is this level of effort and this stuff would, is necessary for 840 00:43:46,505 --> 00:43:48,155 responding to whatever the incident was. 841 00:43:48,155 --> 00:43:52,415 Well then, well now it's a good time to ask the insurance broker who's on the call 842 00:43:52,415 --> 00:43:54,155 or in the meeting, when do we contact you? 843 00:43:54,155 --> 00:43:55,475 And they're gonna say, well, as soon as possible. 844 00:43:56,240 --> 00:44:00,050 And, and from, from an employee, uh, company perspective, I think there 845 00:44:00,050 --> 00:44:03,500 was a misconception that calling the insurance like as soon as possible 846 00:44:03,710 --> 00:44:05,360 is somehow gonna affect your premium. 847 00:44:05,360 --> 00:44:07,130 Like, we're gonna pay more because we called you. 848 00:44:07,640 --> 00:44:09,080 Um, and that's not the case. 849 00:44:09,080 --> 00:44:11,570 They want to be involved as soon as possible to help you make the right 850 00:44:11,575 --> 00:44:15,800 decisions because you may be using third parties and buying, you know, 851 00:44:15,800 --> 00:44:20,480 going through this, this expense that, uh, may not be reimbursable. 852 00:44:20,540 --> 00:44:22,520 You know, you might not be able to get paid back for that 853 00:44:22,520 --> 00:44:23,570 if, even if your claim is. 854 00:44:24,290 --> 00:44:27,590 Is accepted, but at the same time, the insurance company wants to know 855 00:44:27,590 --> 00:44:31,310 about how diligent you're being and they wanna be involved in the process. 856 00:44:31,310 --> 00:44:35,240 And that's gonna help you determine or, or hopefully help you, uh, 857 00:44:35,270 --> 00:44:37,970 towards getting your claim approved. 858 00:44:38,510 --> 00:44:42,140 Um, and then they're gonna be the ones, uh, along with your legal counsel, helping 859 00:44:42,145 --> 00:44:46,850 you make the right decisions about how to communicate, uh, situations to third 860 00:44:46,855 --> 00:44:49,670 parties and outside, you know, clients and what have you, but also internally. 861 00:44:49,675 --> 00:44:52,130 And we walked through this, just adding this real quick. 862 00:44:52,370 --> 00:44:53,660 Alright, so you've got this incident. 863 00:44:54,635 --> 00:44:58,715 And, and we did this, uh, we did a tabletop with an engineering company and 864 00:44:58,715 --> 00:45:00,155 they didn't do anything we suggested. 865 00:45:00,155 --> 00:45:02,525 And then like six weeks later, they got hit with ransomware and they 866 00:45:02,525 --> 00:45:03,665 were down for two and a half months. 867 00:45:04,055 --> 00:45:08,825 But, uh, that's the other important thing about tabletops or, or any type of 868 00:45:08,825 --> 00:45:13,145 assessment, you really need to take the remediation seriously, uh, and take action 869 00:45:13,355 --> 00:45:14,885 on those things as soon as possible. 870 00:45:15,095 --> 00:45:19,085 'cause if, if we found them, bad guys have probably found them too. 871 00:45:19,415 --> 00:45:21,815 But one of the things that we found out in a tabletop, or that 872 00:45:21,815 --> 00:45:23,555 came to mind was communication. 873 00:45:23,900 --> 00:45:25,280 Specifically internally. 874 00:45:25,580 --> 00:45:28,370 So this engineering company got hit with ransomware. 875 00:45:28,370 --> 00:45:31,670 They were down, nobody could do any work and they couldn't even email people. 876 00:45:31,730 --> 00:45:35,165 Alright, so, Do you have a system, uh, that collects 877 00:45:35,165 --> 00:45:36,965 personal emails and phone numbers? 878 00:45:37,205 --> 00:45:40,565 Do you have a system where people can call in to get status? 879 00:45:40,565 --> 00:45:41,885 Like, is it a snow day? 880 00:45:42,005 --> 00:45:43,355 Uh, are we off for the day? 881 00:45:43,595 --> 00:45:44,555 Uh, is there an incident? 882 00:45:44,855 --> 00:45:45,815 When are we gonna hear an update? 883 00:45:45,820 --> 00:45:46,535 That kind of stuff. 884 00:45:46,745 --> 00:45:50,195 But then do you also have a policy that says, in the event of an 885 00:45:50,195 --> 00:45:54,245 incident, you are prohibited from discussing this stuff on social media? 886 00:45:54,605 --> 00:45:56,075 Don't put on LinkedIn. 887 00:45:56,105 --> 00:45:57,245 Oh, we had an incident today. 888 00:45:57,245 --> 00:45:58,985 I got, I guess I got the next two months off. 889 00:45:59,600 --> 00:46:04,670 Um, that you're, you've gotta contain that and or at least, uh, uh, 890 00:46:04,700 --> 00:46:06,560 define the messaging for that stuff. 891 00:46:06,890 --> 00:46:07,580 Get ahead of it. 892 00:46:08,030 --> 00:46:12,200 Uh, go ahead and make your templates for internal and external communications. 893 00:46:12,200 --> 00:46:13,040 Like, what are we gonna say? 894 00:46:13,040 --> 00:46:18,260 Well, you should, uh, plan for that now, uh, instead of wasting time during an 895 00:46:18,290 --> 00:46:20,720 incident, you know, trying to figure it out while the house is on fire. 896 00:46:21,230 --> 00:46:26,000 Um, so having said all of that, um, you know, incident response 897 00:46:26,150 --> 00:46:28,100 exercises are very valuable. 898 00:46:28,460 --> 00:46:32,225 Um, And even though you may want to have your own little huddle to figure 899 00:46:32,225 --> 00:46:36,605 out, you know, how well are we before we invite the rest of the, the crew, 900 00:46:36,935 --> 00:46:41,225 um, you should invite as many people, internal, external, subject matter 901 00:46:41,225 --> 00:46:47,675 experts, partners, um, um, as you can, uh, to get everybody, um, playing on 902 00:46:47,705 --> 00:46:51,065 the same team, on the same field they show up for at the, at the right time. 903 00:46:51,515 --> 00:46:54,395 Um, and they have an idea of what the playbook is. 904 00:46:56,435 --> 00:46:56,765 W. Curtis Preston: Wow. 905 00:46:57,680 --> 00:47:00,410 Prasanna Malaiyandi: Wow, that's, yeah, very detailed. 906 00:47:00,410 --> 00:47:04,220 And like you mentioned, it's sort of plan ahead of time, right? 907 00:47:04,880 --> 00:47:08,690 I'm sure there are so many companies where it's like, Hey, ransomware 908 00:47:08,690 --> 00:47:09,740 hits, or We have an incident. 909 00:47:09,740 --> 00:47:13,220 It's just IT and the security org that's dealing with this, right? 910 00:47:13,225 --> 00:47:16,190 But like you mentioned, there's so many other folks involved. 911 00:47:16,195 --> 00:47:19,940 And just knowing who those people are, especially if you're a large company, you 912 00:47:19,945 --> 00:47:22,850 don't know, like one department doesn't know who the other department is even. 913 00:47:23,360 --> 00:47:23,600 Right. 914 00:47:23,600 --> 00:47:24,140 And having that. 915 00:47:25,040 --> 00:47:28,610 Mike Saylor: We had a situation where for, for four days, we were operating under 916 00:47:28,610 --> 00:47:33,650 the un, uh, assumption that they only had a, uh, $3 million cyber insurance policy. 917 00:47:34,010 --> 00:47:37,820 So we were restricting, uh, who was involved to restrict 918 00:47:37,820 --> 00:47:39,260 the expense and the overhead. 919 00:47:39,650 --> 00:47:43,400 Uh, and it wasn't until we were on a, uh, I think it was like 11 920 00:47:43,400 --> 00:47:47,030 o'clock at night on a Sunday, we were on a, an update call and we were 921 00:47:47,035 --> 00:47:48,920 talking about this $3 million policy. 922 00:47:48,920 --> 00:47:52,340 When someone walks, I could see them walk behind the person talking on the 923 00:47:52,345 --> 00:47:53,930 camera, and they go, we have 6 million. 924 00:47:55,340 --> 00:47:55,760 Like, what? 925 00:47:56,000 --> 00:47:56,540 What do you mean? 926 00:47:56,540 --> 00:47:58,520 We have two, $3 million policies? 927 00:47:58,520 --> 00:47:59,480 And nobody knew that. 928 00:47:59,660 --> 00:48:01,190 Nobody else, but this person knew that. 929 00:48:01,550 --> 00:48:02,690 And that completely changed. 930 00:48:02,690 --> 00:48:05,420 We're like, well, look, we need to start getting more resources in here. 931 00:48:05,660 --> 00:48:09,350 You know, call, call the big brand response teams and all. 932 00:48:09,470 --> 00:48:14,210 So that really changed the game because that just happened to come out in a 933 00:48:14,210 --> 00:48:18,170 meeting without, you know, everybody else being really aware of, uh, Yeah. 934 00:48:18,650 --> 00:48:21,980 And the other bad part of that situation, uh, unfortunately, was that, 935 00:48:21,980 --> 00:48:23,900 uh, they had $6 million in coverage. 936 00:48:23,900 --> 00:48:27,890 But what they didn't also know is that it was a self-funded insurance policy. 937 00:48:28,910 --> 00:48:29,130 Prasanna Malaiyandi: Uh, 938 00:48:29,510 --> 00:48:31,880 Mike Saylor: So they were paying into that over, over time and the 939 00:48:31,880 --> 00:48:35,210 insurance company said, we'll cover you, uh, if the day comes, but then 940 00:48:35,210 --> 00:48:36,800 you've gotta pay it back pretty much. 941 00:48:36,920 --> 00:48:39,920 And so, um, they didn't know that either. 942 00:48:40,850 --> 00:48:41,570 So a lot of things 943 00:48:41,570 --> 00:48:41,930 Prasanna Malaiyandi: Raid your 944 00:48:41,930 --> 00:48:42,560 policy. 945 00:48:42,770 --> 00:48:43,040 Yeah. 946 00:48:43,190 --> 00:48:44,090 W. Curtis Preston: they found that out. 947 00:48:44,700 --> 00:48:46,230 , Mike, we could talk all day. 948 00:48:46,270 --> 00:48:48,150 I, I, I love the stories by the way. 949 00:48:48,150 --> 00:48:48,420 I, 950 00:48:48,660 --> 00:48:48,780 Prasanna Malaiyandi: eh. 951 00:48:49,980 --> 00:48:52,140 W. Curtis Preston: you know, you, you know me, Prasanna, I'm, I'm a 952 00:48:52,140 --> 00:48:56,610 storyteller myself, and I, I think nothing, nothing tells the story 953 00:48:56,610 --> 00:49:00,710 like a good story, you know, nothing, nothing drills that point home, uh, 954 00:49:00,790 --> 00:49:02,640 better than a good story, for sure. 955 00:49:03,030 --> 00:49:05,880 Um, and I, I love hearing. 956 00:49:06,465 --> 00:49:10,305 From these real incidents, uh, what, you know, what, what I'm hearing? 957 00:49:10,725 --> 00:49:13,425 So I, I like, you know, the things that I picked up here. 958 00:49:13,425 --> 00:49:15,825 First off, I like the amount of time we spent on the F B 959 00:49:15,825 --> 00:49:17,985 I, uh, and for guard program. 960 00:49:18,075 --> 00:49:21,315 Uh, I definitely wanna look more into that and I think the listeners 961 00:49:21,320 --> 00:49:22,455 should look more into that. 962 00:49:22,815 --> 00:49:28,335 And I like this idea, uh, and of, of using them as a way to establish those 963 00:49:28,335 --> 00:49:31,665 communication channels before an event. 964 00:49:32,085 --> 00:49:36,615 Um, and I like the idea of, well, you know, we, we, we always promote 965 00:49:36,615 --> 00:49:42,555 the idea of, of tabletop exercises and, um, you know, in, in my 966 00:49:42,555 --> 00:49:44,235 world, you know, we call them Dr. 967 00:49:44,595 --> 00:49:48,975 Dr exercises right back before the, the cyber world was also 968 00:49:48,975 --> 00:49:50,445 attacking backup systems. 969 00:49:50,745 --> 00:49:55,125 Um, so I, you know, I think this has been a great conversation, Mike. 970 00:49:55,125 --> 00:49:56,715 So I want to thank you for coming on. 971 00:49:57,315 --> 00:49:57,795 Mike Saylor: Certainly. 972 00:49:58,800 --> 00:50:01,620 W. Curtis Preston: And, uh, Prasanna once again, as always, 973 00:50:01,620 --> 00:50:03,300 you with your, with your wisdom. 974 00:50:04,495 --> 00:50:07,975 Prasanna Malaiyandi: Yeah, anytime Curtis, and I hope you'll be ordering a chair 975 00:50:07,975 --> 00:50:10,735 or at least, or uh, browsing chair soon. 976 00:50:11,125 --> 00:50:13,135 And Mike, thank you for the info. 977 00:50:13,165 --> 00:50:13,285 I. 978 00:50:13,935 --> 00:50:14,175 Yeah. 979 00:50:14,175 --> 00:50:18,555 It's always fascinating hearing these real life stories because that's something 980 00:50:18,555 --> 00:50:20,055 that you don't hear about, right? 981 00:50:20,055 --> 00:50:23,565 What did people experience and what was it like going through? 982 00:50:23,565 --> 00:50:26,810 It's just like what you read, like reading the Cuckoo's Egg, right? 983 00:50:26,810 --> 00:50:29,540 It's like those are the types of stories that are interesting that 984 00:50:29,540 --> 00:50:33,500 you learn from, especially new people in this space, like myself, right? 985 00:50:33,500 --> 00:50:36,110 Where it's like, hey, what really goes on behind the scenes and 986 00:50:36,110 --> 00:50:37,220 what does it take to recover? 987 00:50:38,300 --> 00:50:39,290 So thank you for sharing. 988 00:50:39,655 --> 00:50:40,265 Mike Saylor: Certainly. 989 00:50:40,805 --> 00:50:40,955 Yeah. 990 00:50:40,955 --> 00:50:41,665 I've got stories all day. 991 00:50:43,925 --> 00:50:44,315 W. Curtis Preston: Sounds like 992 00:50:44,315 --> 00:50:45,365 Prasanna Malaiyandi: we'll have you back on. 993 00:50:45,365 --> 00:50:47,675 W. Curtis Preston: Yeah, you and me over beers, Mike, nobody would 994 00:50:47,675 --> 00:50:49,295 ever get the word in edgewise. 995 00:50:49,625 --> 00:50:51,485 And once again, I want to thank our listeners,