Episode 212 ·

Tyler Ward - VP of Security at IGI

Today we are talking to Tyler Ward, the VP of Security at IGI. And we discuss the security issues from billions of devices coming online, 3 critical measures CTOs can take to make their organization more secure, and the craziest ending to a ransomware situation that you’ve ever heard.

All of this, right here, right now, on the Modern CTO Podcast!

About Tyler:

Tyler Ward is the Vice President of Security with 15 years of experience in IT and Cybersecurity. He is an Air Force veteran in cyber operations, and a dynamic presenter in the Cyber Intelligence Community. He is currently the leader of IGI’s cybersecurity services practice, specializing in vCISO, compliance, Incident Response, MDR, Pen Testing, and more.

About IGI:

IGI is a channel-friendly company that specializes in cybersecurity services. We are the creators of the new Nodeware vulnerability management solution, recognized as a 2017 Vendor on the Vanguard by the ChannelPro Network.

Transcript

(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to Tyler Ward, the VP of Security at IGI, and we discuss the security issues from billions of devices coming online, three critical measures CTOs can take to make their organization more secure, and the craziest ending to a ransomware situation that you've ever heard. All of this right here, right now on the Modern CTO podcast. Here we go. This is the Modern CTO podcast.

(Joel Beasley at 00:00:50) We're here. Hey, did you move down to Tampa yet?

(Tyler Ward at 00:00:55) No, not yet. We booked our Airbnb on Barefoot Beach last night, so nice. Yep, so we're gonna be headed down at the end of August, and that's it. And then we're gonna be house hunting, so stoked.

(Joel Beasley at 00:01:07) Amazing. I know I'm in Colorado.

(Tyler Ward at 00:01:12) Are you really? No kidding.

(Joel Beasley at 00:01:13) Yeah, I'm in this cabin, and I don't know if you can see outside, but—

(Tyler Ward at 00:01:17) Oh yeah. Yeah, that's awesome, man.

(Joel Beasley at 00:01:20) It was tough, you know, because doing so much travel for work last year and then not going anywhere for seven or eight months, I was like, what's a socially distanced place I can go? You know? And this actually ended up working nicely because it's a very, very small town, two and a half hours outside of Denver, just up in the mountains.

(Tyler Ward at 00:01:43) That's awesome. How do you feel? Feel good?

(Joel Beasley at 00:01:46) I feel good. I had that little bit of headache feel that you get sometimes when you go from being at sea level to thousands of feet above sea level.

(Tyler Ward at 00:01:57) Yeah, after a couple days it kind of goes away, but that's real. Good thing you didn't get sick or anything. You feel good?

(Joel Beasley at 00:02:02) I feel good. Yeah, usually it's just a headache and then drink a lot of water, and then in 24 hours it's like you're activated or you feel better.

(Tyler Ward at 00:02:10) It's so peaceful there, man. Half of my team is in Colorado. We've got 35 people in Colorado, and it's just amazing there. It's so peaceful. So peaceful.

(Joel Beasley at 00:02:20) Yeah, I went on a run this morning and I was like, I'm in a pretty remote area and I'm running up this mountain, David Goggins-ing myself and my eyes, you know. And then all of a sudden this thought got into my head that there was a mountain lion behind me.

(Tyler Ward at 00:02:36) I was just like, hey, look, it's real. It's real out there. I went for a run this morning, but I'm in New York, so not like that. But yeah, there's some crazy animals out there.

(Joel Beasley at 00:02:45) Yeah, and I was like, if I had a pocket knife, that wouldn't do anything to a mountain lion.

(Tyler Ward at 00:02:49) No. No, you gotta have at least some bear spray on you and maybe even a pistol.

(Joel Beasley at 00:02:58) Pocket knife as a toothpick after he ate me.

(Tyler Ward at 00:03:02) Those animals are no joke, man. They're no joke. That's awesome though. That looks so peaceful out there. Did you bring the family with you or just you?

(Joel Beasley at 00:03:10) No, that's why it's peaceful.

(Tyler Ward at 00:03:13) I was gonna say, I'm like, that's gotta be a trip, man. How long are you staying out there for?

(Joel Beasley at 00:03:18) A week. So one of the starters of this was we come out here a lot. We try to come out here every year. This year though, when the COVID thing happened, my wife started refinishing cabinets, and that business is growing for her. Now she's making more money doing that than she was before. So she's really happy that she's got all this work, and she's like, oh no, you know, you just go and that's fine, because I travel a lot by myself. So it was pretty exciting, and then I was like, oh, I'm so excited that I get all these awesome podcasts. I was looking at all the different people I get to talk to, and I was super excited to talk with you, especially since our last conversation. There's been new news on TikTok.

(Tyler Ward at 00:04:01) There's been a lot of new news on TikTok. Yeah, did you see it last night? Microsoft potential acquisition of TikTok?

(Joel Beasley at 00:04:07) Yeah, what's going on from a security perspective with TikTok?

(Tyler Ward at 00:04:12) You know, it's one of those things where TikTok is a company owned by—they're a Chinese company. And for a very long time now, the Chinese government has had the ability to snoop into any Chinese company that they want to. So when we look at it from a security and privacy perspective, it's like, you know, they have access. The Chinese government has access to everything on TikTok. They have to. They're mandated to give the government access to all of their data. So when you start to compile how much data that really is and what it really means as far as facial recognition, as far as body language, and being able to pick people out in an airport and identify them from an online persona by the way that they move—I mean, it is creepy. Not only that, the Chinese government, if they do have access to an application, there's nothing to really stop them from, let's say, turning on your microphone or turning on the camera while you're not using it. So there's a whole bunch of security and privacy implications behind TikTok. Microsoft acquisition, that's a whole other animal. They're gonna need to tread really, really carefully because of how many heavy Microsoft contracts they have with the federal government and the intelligence community. So that's gonna be a doozy.

(Joel Beasley at 00:05:27) Yeah, that's interesting. If Microsoft took it away from the Chinese company, then it would be—you know, the first question I have is, from a technology perspective, would they clone the code base or would they just operate the TikTok users and have a separated code base or database for US or UK users? Or, you know, how would they actually create that segmentation so that the data doesn't get routed back to them?

(Tyler Ward at 00:05:56) Well, logistically, it's really interesting because TikTok's been a flagship for government involvement into applications and something that we've not really seen too much of before, where the government is actually stepping in to say stop using it. And it's been really interesting to see, under the current administration, what that's actually looking like on the privacy side. And they've actually mandated a lot of agencies to not use these applications, TikTok being one of them, for federal employees. Right? You're not supposed to use it because they can snoop in on your conversations. And if you're a covert CIA agent, right, and your kid's using TikTok in the house, that could have some pretty wild security implications for you that could go a little bit further than anticipated. So it's crazy. It's crazy. I honestly, if I could make a prediction, I think that if they purchase TikTok, it's going to change almost completely overnight—the logistics of it, the location of the data, how they use the data. And Microsoft is very careful nowadays. Some would definitely disagree with that. I understand Microsoft services are very chatty and sell a lot of data. But Microsoft is a US company, and they do have to abide by those privacy regulations. So they will get dinged for it. Chinese companies, not so much though. Not so much.

(Joel Beasley at 00:07:15) Yeah, I also saw that Apple removed 20-something thousand apps from the Chinese App Store. Did you catch that?

(Tyler Ward at 00:07:23) Yeah, that's a lot. It's a lot. And Android is even worse. I mean, Android is the wild west, right? I'm a big fan of Android because, you know, I'm a hacker, so I really like playing around with the freedom of Android. But yeah, Apple has really taken a bold initiative to kind of stop or at least try to curb this. It's been going on for so long, and a lot of these applications are made in China, and they're very well-crafted applications. And what people have to understand is that the applications that are coming out of China, it's not like the Chinese government is in there and they're meddling all the time and they're creating these secretive applications to go and just spy on us. We're naive if we're thinking that. What is happening is that the companies within China are doing this for legitimate purposes to grow a business or whatever the case may be, and then at some point the Chinese government steps in, right? And that's the point where TikTok—right, and I'm just speculating, I'm saying I don't know too much about the business side of TikTok—but what I imagine has happened is that TikTok grew from a very small organization to this large global phenomenon that all of these kids are using, and then now the Chinese government has a vested interest in the amount of data that they're pulling in. So, you know, there's a lot of preconceived notions that these Chinese app dev companies are just doing it to spy on people. Don't get me wrong, some may be, right? And it's not only China. It's a lot of other countries as well. But they may not be doing it for those purposes from the starting point. So that's been a little bit of a misnomer out there that China's the big bad entity that's creating all these apps just to spy on us. Maybe in some cases, but the majority of them are legitimate companies that at some point the Chinese government will knock on the door and say, "We need access to your servers right now," and there's nothing that these companies can do about it. So that's the danger in it.

(Joel Beasley at 00:09:13) Yeah, and they don't even have to provide reasoning. They just say—and that's the interesting thing about the way China works, is you don't have to provide any reasoning. You just say, "Give us access to your data now." You're not saying, "Give us access to your data now so we can go through the database and particularly find these US people that we wanna spy on." They're just saying, "Give us your data." And then the company TikTok, with all good and meaningful, nice intentions, they just have to do it.

(Tyler Ward at 00:09:39) Right, right. It's very—that's interesting. Yeah, it's really interesting the difference. I mean, here we need subpoenas. We do, right? And I know that there's loopholes between these things, but there's a legal process. It's very formal. It's quite vocal at times as well about needing a subpoena. And if we remember the FBI cases with Apple where they were asking for—and I think it was the Florida shooter in which they were trying to unlock his Apple iPhone after he committed these crimes—and it was extremely vocal. Even in a case that's limited to one device, it was public knowledge. So that disclosure factor is much different than, you know, the potential of a Chinese entity being spied on by their own government for purposes of collecting data on other people, whether it be internal citizens, whether it be citizens of Hong Kong or the United States. You know, what their motivations are is really unknown at times. So it's an interesting quandary that we have.

(Joel Beasley at 00:10:37) Yeah, it's a good point too, because the culture here is that the companies are able to push back. You can push back publicly, be vocal. And then in that country, push back against the government is just not tolerated. There's—it just doesn't happen.

(Tyler Ward at 00:10:53) It's not.

(Joel Beasley at 00:10:53) Now have any security researchers gone in, ripped apart the code base, reverse engineered it, and checked in to see if they're doing anything interesting or weird with the data?

(Tyler Ward at 00:11:07) Yeah, I believe so, to a certain extent. And I mean, where that really stops is at the application layer. So they can't necessarily see what the servers on the backend are doing with that or what the people in the data centers are doing with this data. But they can see the application. And if I can recall, the application—somebody did set up a Wireshark packet capture to look at the traffic streams to see what was going on. And apparently it was sending data. It was definitely sending data while the application was turned off, I believe, in turning on the microphone and activating the camera. And they did witness some of these things. And if I remember correctly, there was also a clipboard where they were peeling information off your clipboard. So if you're using an Apple iOS device and you were selecting copy on a picture or some text, I guess it was sending that information back. And I think that's what started this whole thing, you know, what really kicked off this privacy target on TikTok itself. And one of the big things is there's so many children on this app, right? And I think that's really the big thing that has really infuriated a lot of people, is the lack of privacy of children, right? And that's a whole other can of worms, what these kids are into on cell phones now and smartphones. They're just into so many different applications, and there are privacy implications to these things when these children—and we had the luxury, right? We had the luxury of what was out there. Myspace, right? We had Napster. We were in this age where the internet was just kind of being created and it was very cobbled together. And I'm really thankful for that, for having a flip phone and having a beeper. When I tell my kid about a beeper, she looks at me like I'm crazy sometimes. But I'm really grateful for having that because now, you know, you have these kids who are born after 2010, and their entire life may be recorded. And their digital personas are recorded, and you could pick them out in an airport from a camera pointing at them just based on their body language and, you know, how they speak. So it's very interesting to see how much privacy has gone away in the 21st century with the advent of just all these different technologies. So when you compile them all, that's where things start to get very, very risky, right? And that's the slippery slope that, you know, privacy advocates like myself are always enforcing—it's a slippery slope. It's just because you're collecting—you know, there was this Russian face recognition app, if you remember. It was "Make Me Older" or something like that. And it was this huge wave that hit social media, and within a couple days they had amassed just hundreds of millions of facial photos of people. And it was found out that this was, I guess, a Russian organization that was collecting that data, and nobody knew what they were really doing with it. So you have to think about that, right? What are they using that facial recognition data for? And it's these waves of popularity that take over social media that are the culprits, and they're the gasoline on the fire on all of this. So we have to be really careful, very skeptical.

(Joel Beasley at 00:14:08) So you had to explain a beeper to your kids?

(Tyler Ward at 00:14:13) I did. I did. And the only thing that they were able to understand is that you could put cool messages in there with numbers. So I had to flip some of the numbers around to show them how some of those messages may look. But the concept of it is just so very foreign to them.

(Joel Beasley at 00:14:28) But it's such an improvement upon carrier pigeons, right? That used to be a reliable form of communication. Okay, so I thought of you about two weeks ago because I have dogs. I have two dogs, and they bark when the garage door goes up. And one morning we go out there and the garage door won't open. There's a giant spring, and the spring broke.

(Tyler Ward at 00:14:53) Yeah.

(Joel Beasley at 00:14:54) And so the repair guy came, said you need some new springs, and I asked him, I said, "Hey, is there a way to get this to be quieter?" He said, "Yeah, these types of motors are really loud. We've got these nice electric quiet motors we can put in there." And I said, "Okay, great."

(Joel Beasley at 00:15:08) And wasn't expensive, so I had them installed and it came with a WiFi. Right? You could connect to your WiFi so you could open and close or share codes or whatever. And I was like, okay, cool. And then I went to go download the app. My wife downloaded it and then I went to go download it and had a bunch of one-star reviews and I started reading their one-star reviews.

(Joel Beasley at 00:15:26) I was like, that's odd, you know. And these people were saying that they were sniffing the traffic or monitoring the traffic with third-party apps.

(Tyler Ward at 00:15:34) Yeah.

(Joel Beasley at 00:15:34) And the app for the garage door was sending out 14 gigs a day. And I'm like, whoa. So I just didn't—

(Tyler Ward at 00:15:43) That's a lot.

(Joel Beasley at 00:15:43) I didn't dig. I didn't download it. I have my wife uninstall it because we don't need the app. Right?

(Tyler Ward at 00:15:49) We don't—

(Joel Beasley at 00:15:49) We don't need it. It's too much. But the point was, or the thing that I thought about was, how many of these IoT devices are either being hacked because they're built poorly? I doubt the manufacturer of that overhead garage door system is incentivized to ruin their brand like that. Right?

(Joel Beasley at 00:16:10) Clearly, it's probably some security hack where they left something open or use some technology and someone scanned it and then they're somehow hijacking it. But that brings into this question: all of these little IoT devices, they're basically all these little mini computers that you're installing on your network, inside your trusted network.

(Tyler Ward at 00:16:27) They—

(Joel Beasley at 00:16:28) are. What do you think? How do you think about that? How do you talk about that with people? What's your main talking points on security and IoT?

(Tyler Ward at 00:16:37) Well, you know, it has become such a problem in cybersecurity. There was a light at the end of the tunnel at one point in my career. And if I can revert back, I wanted to share a story about how I came into this field, which is a kind of an interesting thing. And it segues into where we are today and why you hear so much of the "there's no light at the end of the tunnel," why all the security professionals now are saying, you know, we're always behind the curve. We're always counter punching to a punch.

(Tyler Ward at 00:17:05) But real quick story. So when I was 17, my parents, they owned an asphalt chemical company. And I was doing work for them all summer just trying to save up enough money to buy my first car. I was 17, I was a senior in high school. And I finally saved up about $5,000 at the end of the summer. And I went on eBay and I bought a Toyota Celica. Only the eBay page, when I clicked on it, it redirected me unknowingly to a spoofed eBay website. So this was back in 2004 time frame, 2005 time frame.

(Tyler Ward at 00:17:39) So I ended up sending about $5,000 to Romania, and I never saw my money back. Called the FBI and they brought me to school on this new thing that was happening on eBay. EBay was new. It was really new back then. And I was just so impressed by it. And it really took me for a ride in my career to get really immersed in technology and specifically security, which took me through, you know, the military and then the intelligence community. And now I'm back to the commercial sector, kind of where I started out. But as I went through my career, before we had IoT labeled as IoT, IoT has always been there. Everything's a thing. Right?

(Tyler Ward at 00:18:16) So everything with an IP address has always been IoT, whether it be a computer or a desktop or a laptop, smartphone. Now we've taken upon ourselves to connect just about everything. Right? Your garage door opener, our baby cameras, our home thermostats, our nest monitors, home security systems, anything, everything is now being connected, and it's very frightening. The reason why it's frightening is because, you know, my team, one of our primary jobs is to hack organizations. That's what we get paid to do: to hack into companies, to respond to data breaches, and to inform security teams and organizations how to secure themselves. We see the bad most of the time. We're either cleaning up or hacking in, and we're exposing and finding flaws to relate to these companies. The more devices that we have connected to the internet, it's just simple math, we don't have enough security professionals to ever secure those amount of devices. By the year 2020, we're expected to have over 10 billion IoT devices.

(Tyler Ward at 00:19:22) 10 billion. Okay? So that's more people in the world than are in the world right now. By 2025, it just starts to grow exponentially—20 billion by 2025, and this is what these statistics are saying. So it's a problem that only is compounded by how many devices are now being connected.

(Tyler Ward at 00:19:42) And these manufacturers, they don't really—it's not that they don't really care about security. It's just that it's not their first priority. Their first priority is when they hire a development team to get those applications out quickly, to not really worry about all the secure software development lifecycle stuff and do code reviews and checks and static and dynamic analysis of code and have somebody try to break in. It's just to get this app out there just because they're on a tight deadline. They've got a budget for development.

(Tyler Ward at 00:20:09) And what happens is when they reach that budget for development, they offshore it or they find a group of developers that are very cheap. And we all know what happens when you find cheap developers. You get cheap code, you get bad code, and you get code that's hacked into very easily by, if you're lucky, my team. If you're unlucky, it's our counterparts out there. So it's just growing exponentially and everything's becoming connected, which is, you know, garage door opener. Right? Could it be hacked? Absolutely. Is it already? We don't know.

(Tyler Ward at 00:20:38) Right? It very well could be. And it could be—

(Joel Beasley at 00:20:40) Might be the lead for you guys. Hand that over to your sales team. Screenshot the reviews on that app.

(Tyler Ward at 00:20:45) It could be. I mean, and there's just there's so many. Right? And even in our, you know, our penetration testing, we find lots of IoT devices, and we're always beating them up because the manufacturers very rarely secure them. And we've got some pretty cool stories around those as well.

(Joel Beasley at 00:21:02) Around securing the IoT devices?

(Tyler Ward at 00:21:05) Yes. And well, around hacking into them. So—

(Joel Beasley at 00:21:07) Okay. What's one of the crazier ones?

(Tyler Ward at 00:21:11) So we work with a lot of manufacturers. And manufacturers are traditionally very—you know, they're notorious for having lots of IoT devices. They have, you know, conveyor belt systems that relay products. They have systems that do everything that are connected to the internet. Sometimes they're exposed to the internet. Gas pumps, right, are exposed to the internet as well. There's a site out there, and I'm probably not doing myself any favors by telling people this because I'm sure you have some people that are maybe a little bit curious watching this podcast, but there's a service called Shodan. Have you ever heard of it, Shodan? No. Okay.

(Tyler Ward at 00:21:41) So Shodan is basically—they call it the bad guys' search engine. But what it is is it's the search engine for the internet of things. So shodan.io, you can find an interactive map with every IoT device that is reachable all over the world. So you can go onto this interactive map, you can pull it up, and you can see every single device that's connected. And that, as soon as that site was created, we saw so many hacks.

(Tyler Ward at 00:22:08) I mean, it was out of control. It was out of control. We were actually calling businesses, especially local businesses, and letting them know, hey, in our research, we found that your organization has 65 devices that are exposed to the internet unsecured. We're telling you now so you don't get hit.

(Tyler Ward at 00:22:23) And sometimes we would get a response, sometimes we wouldn't get a response, but that's the sites where everything is really exposed from. And what they do is they have these—Shodan has these scanners that continuously scan large blocks of IP addresses across the internet. And as soon as they pick up a known port or a protocol for a device, it's usually correlated back to some kind of a device. Right? Whether it be a gas pump or a wind turbine.

(Tyler Ward at 00:22:49) Right? Wind turbines are out there. I mean, you're talking everything. Critical infrastructure is on this site to where you can actually click on a camera and go and look inside of a power plant right now. I mean, thousands of them. Hundreds of thousands of open camera systems. It's very disheartening to see, and that's the battle that we're fighting right now is not really against the hackers. It's not. It's just against these businesses that are doing things unknowingly, exposing themselves. We're trying to bring them to school on, please just don't do that.

(Tyler Ward at 00:23:25) It saves you from being that low-hanging fruit to where they pluck off the tree.

(Joel Beasley at 00:23:29) Which brings me into an interesting topic I didn't have planned to talk about today, but I've been thinking a little bit about risk, appetite for risk. And the thing that sparked this is my conversations between—so my brother's a doctor and my stepmom's a doctor. And so, you know, we have a thread going essentially like this conversation between the three of us, and I'm, you know, bouncing the whole mask coronavirus thing off of them because their opinions, you know, have changed throughout the whole past six months as most people's have. And what I've learned from watching—I'm a huge fan of observing. So what I've learned from watching, you know, my wife play social justice warrior with arguing with people about the mask and all of these types of stuff is that people have different appetite for risk.

(Joel Beasley at 00:24:24) And so I can see how frustrating it could be to say, hey, look, your technology, you're completely open, you're 100% vulnerable. And some people just be like, okay. Next.

(Tyler Ward at 00:24:34) Yeah. Like, next. Yep. Yes. Yes.

(Tyler Ward at 00:24:38) You know, COVID's been an interesting, you know, risk management tool for a lot of people, and it's true. COVID is crisis management. Right? And it's down to its bones, business contingency and continuity. So all those things, they flow and they intertwine with that. The risk tolerance is definitely something that we've seen in organizations. They have different perspectives on it, like you said. One thing that's really opened up organizations to understanding their cyber risk a little bit as more of a deeper subject and something with a lot more gravity is ransomware. Look, ransomware, I've sat with CEOs of organizations on multiple occasions, one of which he was in tears because he had to let go of the majority of his employees, and his business was going to fold under, and it did. Right?

(Tyler Ward at 00:25:27) So we're talking about something that's not just code ruptured or, you know, some of your systems are knocked down for a little while from a denial-of-service attack. You're talking about your family and friends that may work for a business that you've built with your bare hands or a business that your father and mother have passed down to you. You're talking about a business that is now shut down. You're having to let people go, lay them off, fire people because of cyber attacks. So the gravity of the situation has become a lot more drastic, and people, I think, now are awake to the fact that it is not just—it's not just some far-off concept in the Matrix that, oh, systems got hacked, IT will fix it. No. It could mean that you're out of millions of dollars because you've got to reimburse cyber attackers or you've got to pay off cyber criminals. You've got to pay your lawyers. You've got to pay regulatory fines if you're in a regulated organization.

(Tyler Ward at 00:26:23) You've got to pay for the downtime, of which one of the businesses that we work with, they had a ransomware attack, and they were losing $250,000 a day. Right? That's not a lot to some organizations, but to this particular business, it was quite a bit. So the gravity of these situations now, these cyber attackers—I don't call them hackers because we're in the hacker community, and hackers aren't bad guys. Hire a hacker. That's the one thing you should take away from this. Hire a hacker. But these cyber attackers, they're throwing haymakers at these companies now. They're going for the throat, and they're going there quickly. And the scariest part about this is that the cyber attackers that used to cause a lot of damage in the past, a lot of damage, they were extremely sophisticated. They knew how to code. Right? We were all brought up in that generation to understand how to write our own tools and how to use command lines and things like that that were a little bit more obscure, that weren't as—they weren't publicly available to everybody. Now there's a tool for everything that's freely available on an operating system that's already built for you to attack enterprise organizations. So now you have kids, kids who don't know how to code, who are able to hack into Fortune 500 businesses.

(Tyler Ward at 00:27:36) Right? Twitter, I can't wait to see the story that comes out of that. That was a social engineering attack. So most likely, it didn't even involve a whole lot of systems. It didn't involve a whole lot of code, maybe not even any.

(Tyler Ward at 00:27:48) It likely just involved a group of talented social engineers who are young. I know one of the kids was 17 and conveniently down in the location to where—

(Joel Beasley at 00:27:59) I know. To be.

(Tyler Ward at 00:28:00) Right? So—

(Joel Beasley at 00:28:01) You gotta be scared now. All the Tampa kids are scared because you got Tyler coming down.

(Tyler Ward at 00:28:05) Oh, boy. Oh, boy. You know what's interesting is that I imagine that, you know, some of them will be at Black Hat conferences and, you know, some of the different shows that are out there later on in their lives. And I hope they find their path. Right? Because that life of crime leads to one place usually.

(Joel Beasley at 00:28:20) I have opinions on age. Yeah. And specifically because I was a 16 and 17-year-old individual. And I'll tell you, you know, I'd say around then, I had taken the path to business technology because that just is—my parents' real estate company, I'd go there after school and solve their problems, and that was more interesting to me, you know, than testing security of legal systems.

(Joel Beasley at 00:28:48) But there was a couple years where I got really into it. There was a site way back in the day. I don't know if it still exists, but it's called Hack This Site. And it was—I found this basic book on security and white-hat hacking at Best Buy when I was 10 or 11, and I got interested in it and started doing tutorials and understanding things. And there's a curiosity thing. But I guess my opinion or the things that I wanted to think about is: when the kids are that young, definitely have to give them some flexibility to make mistakes and be stupid because at the end of the day, it's just a computer with an internet connection to them. They don't—they're not, you know, 30 and understanding the gravity of what they're actually doing. They're just like, dude, it'd be so cool to post as Elon Musk. And, like, should they go to jail for 10 years for that? Probably not, you know?

(Joel Beasley at 00:29:42) Right.

(Tyler Ward at 00:29:43) Right. Right. I agree. I agree. And it depends on the type of attack. Right? Fifteen years ago, you know, if a kid did that, they would get a lot more leeway because there weren't so many laws and regulations. But I mean, as an industry, everybody has really been sickened by how much this has happened. So it depends on the type of attack. Right? If they're stealing money, then it is what it is they're doing.

(Tyler Ward at 00:30:06)
If it's essentially that it's looked at as the same thing as going to rob a bank or robbing a group of people, of which this case was. There's a lot of attacks that are called hacktivists, and they are doing it for a purpose. Right? They're doing it because of something that they believe in, and then sometimes it's just because of curiosity. Now the number one way, and I've talked to a lot of people that are on the other side of the fence, which we know who they are, some of them.

(Tyler Ward at 00:30:33)
And I've talked to people who have gone from that side of the fence over to this side, and they all have one thing in common. How do they get into it? Guess what? Online gaming. Number one, hands down.

(Tyler Ward at 00:30:45)
Yeah. If you're on online gaming, there is a very good chance that you have been asked to come to some kind of a forum outside of the game, and that's where it starts. Whether or not it's like Fortnite or anything of the sort, that's where it starts, and that's where that creativity turns from online gaming to I know this group of people that I'm gaming with to now we've turned this into a game to go and hack these organizations and these sites, and they become very talented at it. They become very talented at it. So we want that talent. We want that talent. That kind of raw talent to think like a criminal is what separates the really, really good in this field from the okay. Right? But those kids who grew up in that sort of lifestyle, or just even somebody who understands that lifestyle or can understand how a criminal thinks, they're highly valuable in this field. And I've got colleagues who have been on that side, and now they're leading organizations over here making a ton of money doing it.

(Tyler Ward at 00:31:46)
So now there's positives over here. So come on over when you're done.

(Joel Beasley at 00:31:50)
And I, yeah, right. And I don't know how to articulate this exactly, but I feel like a 17-year-old robbing a bank is worse than a 17-year-old hacking some site and stealing money. Like, there's just something about the in-person adrenaline, having the gun, like, all of this other stuff that is just, and again, I don't have the words for it, but it's just different.

(Tyler Ward at 00:32:18)
It's very different. Yeah.

(Joel Beasley at 00:32:20)
So I'm curious. You've got an amazing background, NSA and now VP of security at IGI. I was talking with Christopher Greg, who's over at Gillware, and they work a lot with insurance companies that will do cybersecurity insurance, and then when they get hacked, the people will do a ransomware attack, and then they will call up Gillware, and then Gillware will somehow determine if it's a legitimate hack and if they should pay out. They're on the insurance company side. They're somewhere in that business model.

(Joel Beasley at 00:32:51)
But from that conversation, he was talking with me and he said that there are these farms of people that are hacking, and they're like businesses, and they go to work and they're in buildings, in public, and mostly in other countries. And with your experience, NSA and all of that, are there a lot of those out there? Or is that true, or is it an overstatement? Or...

(Tyler Ward at 00:33:15)
No. It's not an overstatement. I'm, yeah. Just a lot of countries that are out there, they don't have the laws to govern these businesses in the same way that we do. The overtness of them may be of question sometimes. I agree that there are centers that are out there that are dedicated to this. You get phone calls from them. Right? Those are some of the same groups that are actually doing some of these ransomware attacks in some cases. The calls that you get of, I've gotten one a couple years ago, which was particularly funny, of which I ran with for a little while, and it was we've kidnapped your cousin. Right? And they knew my cousin's name, and they had all this information on them and, you know. But those are the groups, and you can hear people talking in the background of those places. So you have to figure if they're doing that, of course, you know, if they can pick up another set of skills and go and rob some companies online, then, yeah, absolutely. It's rare that they're caught and brought to justice. That's, I think, the one thing that we've all kind of looked at and scoffed at is how difficult it really is. If they're based in the United States, then it's probably a lot easier to prosecute them. But in a lot of cases, I was reading an article and there was the top dog hacker out of Russia who's done all these bank hits and all this kind of stuff.

(Tyler Ward at 00:34:34)
And they showed him standing there with a bunch of police officers in Russia, and he was standing outside of his Lamborghini, I think it was. And they were just talking, and they were like, we're, and he's the most wanted by the FBI right now. So sometimes it's just comical of how much money these organizations are making. I mean, I've been on the side of responding to ransomware. That's been a highlight of my career, you know, highlight reel, right, is responding to ransomware. And it is a lot of money that they've got to shell out to these companies. The insurance part is interesting. I've been in situations where the insurance company has not paid out because they've come in and they've found either negligence on the part of the business, or they found out that, look, that little application that you're filling out when you go to get cyber insurance, you better know what you're putting on there. I'm just saying. Because when you get hacked as an organization, or if you have a ransomware attack, they will ask you all sorts of questions about how this transpired, about how they got in.

(Tyler Ward at 00:35:36)
And if they find that on that initial application that there's just a glaring discrepancy from how you said you are protecting your network to how they got in, and you may have lied, or maybe something had changed, they can deny your claim. They absolutely can. And we see that a lot with cyber insurance. It's either that route, or it's the fact that one of my customers is a $500 million business, and they've got a million-dollar insurance policy for cyber. It's like, you know, what is that going to cover? You know, it's not covering anything for you. That's a drop in the bucket for you guys. So adequate insurance is definitely important. It's not the end-all-be-all, and you've got to be really careful about what you're saying on those applications as well. So...

(Joel Beasley at 00:36:16)
Have you guys got, do you guys have that business model at all where you work with the insurance companies?

(Tyler Ward at 00:36:22)
A little bit. I try to keep my team out of that just because of conflict of interest stuff. We do have preferred insurance companies that we work with. We actually work with a ransomware broker as well, which is fairly odd. So what this company does is they basically interface with the ransomware threat actors. Why my organization would respond and try to recover a company from whatever has happened, this company's job is to talk with the ransomware threat actors and negotiate pricing between them and the business. Here's the problem. All right? Is that when an organization is hacked or they have a ransomware attack, the ransomware threat actors are asking for a million dollars in Bitcoin. This company doesn't have a million dollars in Bitcoin. And to get a million dollars into Bitcoin, wow, you're talking a week. You know, you're talking a significant amount of time to float that much money over. So what these ransomware brokerage companies are doing is they understand that time is money. So if a business is out for a week, that million dollars doesn't mean anything because they've lost $15 million in that week. But if that broker can get in there on day one, pay that ransom, and then get their business back up and running, then they have a nice business model. It's so weird.

(Joel Beasley at 00:37:35)
Oh, it's an amazing business model. That's insane. That's such a...

(Tyler Ward at 00:37:40)
It's nuts. It's nuts. And those are the new businesses. Funny story actually about that. So it was about four years ago. I was with another organization leading a team, and one of my consultants, he was responding to a local ransomware attack and they had trouble finding a Bitcoin account. So the CEO of the company who was hacked asked his employees, do you know anybody who has a lot of money in Bitcoin? We need somebody to come in, and we'll pay them in cash and give them a little bit on top to give us their Bitcoin. So they had this guy come in, and it was one of the friends of one of the employees, and he's sitting there in the IT room with my consultant. And my consultant is having small talk with him. He goes, so what do you do? The guy turns to him and he goes, I sell drugs. I'm not kidding you. And so I'm getting this text message as he walks in there, and he's like, this is the weirdest conversation I've ever had in my entire life. He goes, there's a drug dealer here who has a large Bitcoin wallet and he's helping us out. I'm like, that's the level of complexity that this, it's just, it's still the wild west. It's comical sometimes. So that was funny.

(Joel Beasley at 00:38:42)
I love how, I love how as humans, our social networks operate, and we can come together around causes, which is, you know, like...

(Tyler Ward at 00:38:49)
It's true.

(Joel Beasley at 00:38:50)
Yeah. I want us to come together as a world or a country towards one specific goal. I don't know. I've said it two or three times now, and as I hear myself saying it, I want it more and more. Like, I want to feel that feeling that we had as unity, like, launching the first space shuttle to anything. Maybe it's AI or security or whatever it may be. But, all right. So I had a couple specific questions for you that I just kind of jotted down while you were talking earlier. All right. So the first one goes back to our question about, let's use the Twitter hack as the example. And so what I want to get, the result I want is I want to know at what moment does the illegal thing happen. And so, like, let's just say I'm social engineering and I make a Twitter domain that's similar to Twitter, but it's not. And I make a login page. I'm just going to capture that. And I send a password reset email to someone, then they get, you spoofed a little similar to how you got redirected from eBay. And then they enter in their password, and then I log in as them, and then I post as Elon Musk, you know, and then it's a financial thing. Like, is the first illegal thing the financial posting as something like...

(Tyler Ward at 00:40:08)
No.

(Joel Beasley at 00:40:08)
What is the illegal thing?

(Tyler Ward at 00:40:10)
It's way back. It was when you first started. Right? Having that motive and then putting an action to that motive is essentially where the crime happens. Right? So even if you didn't steal anything financially, you didn't steal any money, and you just captured somebody's credentials. Let's say you sent a phishing email to somebody and they gave you their credentials back, you've committed a crime.

(Joel Beasley at 00:40:31)
But, so, okay. Because I disagreed with your first part when you said motive and action creates the crime, because you would have to break a law to create the crime.

(Tyler Ward at 00:40:39)
Exactly.

(Joel Beasley at 00:40:41)
So the law that, so they're breaking a law when they send the phishing email.

(Tyler Ward at 00:40:46)
They're breaking a law when they send the phishing email under the CAN-SPAM Act. It's called the CAN-SPAM Act, and that was originally intended to curb pornography and spam way back in the day. So they're essentially breaking that by sending an email to a recipient that doesn't want that email. And not only that, they've taken a step beyond because they're trying to capture non-public information from that employee. They're trying to capture personal information from that employee. And once that personal information is transferred, I have something that I shouldn't have that is a secret of that employee, and it's actually company property. So if it's a company system, like, in the case of Twitter, right? So in the case of Twitter, me having credentials for an employee can be considered property of Twitter because it's resident on their systems. It was given to that employee from the company, and I've stolen it. So that's where a crime happens.

(Joel Beasley at 00:41:45)
Oh, so interesting. Yeah. Which then brings up the question, if I got your credentials from another database or another system you're using passwords, is it property?

(Tyler Ward at 00:41:57)
So no. That's public information at that point. So information that's been disclosed in a public data breach is already public information, and you have committed no crime by stumbling upon that on Pastebin, right, whatever the case may be, or Troy Hunt, right? So you've committed no crime stumbling upon that information. But if you use that information, you're essentially back in that position where you're now using something that was publicly available to now try to break into a company or break into a system. And breaking into somebody's email account is breaking into a system that you shouldn't be in, that is property of that company, or property of Microsoft, or property of Twitter, whatever the case might be.

(Joel Beasley at 00:42:40)
So with the security, or the password managers, like there's LastPass and 1Password and all of these types of things. They're actually integrating and sending me notifications when a password that I use was publicly disclosed. And so that's something, you know, I only saw for the first time last year for whatever reason, and so I was actually a little bit surprised by it. But what's happening? So, like, companies are having a data breach and then they're publicly exposing the passwords, or hackers are collecting them and selling them in lists, and people get copies of the list being sold, like, what's happening? Both of those things?

(Tyler Ward at 00:43:19)
Yeah. Yeah. It's both of them. So usually when you get those notifications is because, you know, if you're using LastPass, they've contracted with a company that does dark web scanning. So dark web, surface web, doing all that kind of scanning and looking for password dumps. Once they stumble across the password that has been compromised, they let you know. So it could be on a nefarious website. It could be publicly available on a good guy's website, right? Have I Been Pwned dot com is a website where you can actually go on haveibeenpwned.com, pwned.com. And you can type in your email address, and it will tell you if you've had an account compromise. And I think there's also a password checker on there as well. So they're scraping from different locations just letting you know, hey, something bad happened. That's great. You know, dark web scanning, surface web scanning to find out that information is really, it's valuable insight, but it's sometimes a little too late. So that's the only problem. It's usually what happens is when you get these large lists, right? If a service is compromised and I'm an attacker and I have this huge treasure trove full of information, I'm going to sell it. I'm going to sell that to the highest bidder that I can find. And that highest bidder is then going to take that and they're going to break it into very, very, very fine chunks. And there's essentially two types of threat actors, well, there's a lot of types of threat actors, but the ones that are more common are the ones that hold those credentials and they just sell them out. They farm them out. They get people to purchase them, and they're really kind of hands-off on that crime aspect of it. They buy them in huge bulk quantities, and then they put it out there in little chunks. Right? I've compromised company A, or I have company A's credentials for all of their employees. They put it out there. They'll get a bidder. And they can do that 500 times and just keep on breaking up this big list.

(Tyler Ward at 00:45:10) By the time that whole list gets out there and it's actually public, it's like, you know, really late. Unless the company, unless the company who is hacked into recognizes that it happened and then they tell everybody your account was compromised, then it's public.

(Joel Beasley at 00:45:25) Okay. So we have a lot of, you know, engineers, directors, technology, CTOs, VPs, all those types of people listening. What are like the top three 101 type things that they could be doing to help protect themselves or their organization?

(Tyler Ward at 00:45:46) So, you know, that's a great question and that's traditionally one that's a little bit more difficult to answer for organizations that are managing themselves. And, you know, I always recommend, now we're in kind of a status to where going out and procuring a second set of eyes is pretty easy to do. Going and finding a firm to tell you where you need to shore things up is a pretty easy action to take. The number one thing is make a plan and base it on best practices and base it on industry standards. And for the CTOs and the CIOs and the CSOs out there, you know what I'm talking about.

(Tyler Ward at 00:46:22) The 20 critical controls from the Center for Internet Security, NIST, HIPAA if you're a health regulated entity, PCI for somebody who swipes credit cards. Find a trusted framework and assess yourself against that framework and be honest. Be brutally honest in your assessment of yourself to find where your discrepancies, where your gaps, and then make a plan on mitigation. Hold people accountable is number two. If not number one, I would actually put that back up to number one is hold yourself accountable, take ownership, and hold other people accountable. Go Jocko Willink on your cybersecurity.

(Tyler Ward at 00:47:01) Right? Accountability is king. And if there's nobody accountable, guess what? Nothing gets done. And there's nobody whose feet are to the fire when that something doesn't get done or when an organization is compromised.

(Tyler Ward at 00:47:12) CISOs get fired a lot. And you know what? I understand. I get it. They get fired when their organizations get hacked into.

(Tyler Ward at 00:47:19) But sometimes, you know, in being that leader, hold people accountable. Give them ownership of something and tell them specifically, this is your job. You are meant to secure this and hold them to it. Number three, I would say is measure the effectiveness of your security program. That's the one thing to where I see it a ton.

(Tyler Ward at 00:47:39) Right? And being a virtual CISO to organizations is a lack of metrics. It really boils down to that. It's usually the case to where, oh, you know, we set out a security plan three years ago and we're still working on it. We're chipping away.

(Tyler Ward at 00:47:53) And it's like, okay. Where are your metrics? You know, where are your quarterly reports? Have you formulated a quarterly risk report to show what you've done and what you still have to do, or are you just kind of flying by the seat of your pants? So, you know, accountability, have a game plan, and make sure it's based on best practices, not what you think is a good idea.

(Tyler Ward at 00:48:12) Right? That's never a good thing. If I walk into our organization and I say, Tyler Ward's top 10 for security, and, you know, they're gonna look at me like, what are you talking about? You know?

(Tyler Ward at 00:48:22) I hope they would. Base it on a structured set, a structured criteria in security that's proven. Right? The CIS 20 critical controls, I'm a huge fan of those.

(Tyler Ward at 00:48:31) And the reason is because it was a set of security standards that was originally created by the Department of Homeland Security and the NSA when they said to each other, let's write a list to get rid of 80% of the cyberattacks that we're seeing. And that list has just grown from there, and it really has remained that, you know, that list to knock out 80% of those cyberattacks that's out there, and it's very effective. Now it's managed by a commercial party. So those would be my three.

(Joel Beasley at 00:49:00) Now let's say I go look up that list or like NIST or something like that, and I just have a lot of questions. Are you like, is your company, they do that as a service? Like could people reach out and meet with your team and ask them some questions because they're like, oh, I listen to this guy talk. He's pretty awesome. We've got something in place, but it'd be good to have, you know, Tyler's team look at it. Are you open to that? Like is that something you do?

(Tyler Ward at 00:49:29) Yeah. Absolutely. Yeah. We're consultants first and foremost. And it's not purely on the ethical hacking side or the incident response side. Those are things that we do. We do them very well. We've got some really talented people, but we're consultants. So it's just a very mixed of consultations that we provide either long term or short term projects. So to answer your question, yes. Always. You know, you can definitely reach out to us and ask for help. I always encourage people to do that. And, you know, one of the big things in security is we've all gotta do it, is put ego aside. Put it away.

(Tyler Ward at 00:50:02) Right? We don't know everything. Inside of these organizations, if you're running an IT team, you're running an operation, you say, you know what? I implicitly just trust my team. Got a problem. I'm telling you, you've got to audit your team, and your team should be on board with the fact that they want to be audited as well. Not from an auditor who's coming in wearing a black tie and a suit, but somebody who's coming in or doing that yourself to audit yourself or audit your best practices to look on Shodan and see if you're exposed to the Internet. Right? To do these things, act like an attacker. Because at the end of the day, you know, we've been with so many organizations that have said to us, we thought we were good. We spent so much money on security, so much. We spent $5 million last year on this new tool, and they found out that an attacker, 17 years old was able to hack into Twitter. Do you have any idea how much money Twitter probably spends on security? I have no idea, but it's gotta be a lot.

(Joel Beasley at 00:50:56) It's probably definitely over 10 million. Definitely. Probably, I don't think 100 million is a horrible guess.

(Tyler Ward at 00:51:07) I don't think so either. I think that's actually probably pretty accurate if you consider, you know, DevSecOps and all that kind of stuff that they do as well. All of that money and you've got a group of kids that got it. Right? That's where we're at in security. And it's because we're relying on the money when sometimes it's just a very, very simple equation of removing yourself as the low hanging fruit. And the people aspect of it, that's tough. Right? We all joke about it. And, you know, the hacker community, they say you can spend all of your money on systems.

(Tyler Ward at 00:51:39) And if you don't have your employees as cybersecurity sentinels for your organization who are very savvy on social engineering, then guess what? If they're a marked target, somebody's getting in. And it's true. Just happened with Twitter, happens with big banks, happens all the time. Happens with the federal government. Right?

(Joel Beasley at 00:51:56) Yes. Look, signal versus noise. Right?

(Tyler Ward at 00:52:00) Yeah.

(Joel Beasley at 00:52:01) Like, it's if somebody, I was giving a talk and it was an older crowd and so this gentleman came up to me after the talk and the talk was about what I learned from speaking to all of these great leaders in technology. And he came up to me after the talk and he goes, I'm retired and I have a lot of money. He goes, I'm scared that people are going to get my money. He's like, what do you do? And he's like, people can just go in. I was like, because I had said something along the lines of if you're a target and people want it bad enough, they're gonna get it. But you've got this protection of there's so many devices online and so the business models have shifted for like people just randomly scanning IP blocks, finding open stuff that's easy to get and can run automated attacks, and then find out there's useful stuff and lock it up. So I was just, you know, talking with him about technology, and I guess the takeaway from that was I just said, do you have two factor authentication? Like, ask your bank for two factor authentication. I was like, the one thing I could give the poor guy who was like scared for his money.

(Joel Beasley at 00:53:03) I was like, do you, do you just get a text before you log in? Do you have two factor? Like, no. I was like, well call the 1-800 number on the back of your card and ask them to help you set up two factor authentication. That's like the one thing you could do today because, you know, I was walking out of a talk. Like, I'm trying to go get some lunch. Yeah. It's like I'm hungry. Yeah.

(Tyler Ward at 00:53:21) Two FA. That's like the default. And, you know, I find it really beneficial to, I always equate cybersecurity and cyberattacks to covert and overt operations for the government. And I forget the name of the book, but I actually, oh, I've got a book called Spycraft, and I recommend it to anybody who's out there who wants to read a really cool book. It's called Spycraft, and it's all sorts of early tech gadgets from the CIA.

(Tyler Ward at 00:53:46) And that's, you know, real CIA. It's got pictures, so I'm a big picture guy, and it's got all sorts of really cool stuff in it. But the CIA, right, they say, and every time they're in covert operations is don't be a target. Stop being a flamingo out there. Right?

(Tyler Ward at 00:54:03) You're like the peacock in the middle of a crowd, and this is social media. Right? And I know we're on a podcast right now. We're obviously, we're on social media. But when you're on social media, a big point that I always give to my clients is don't be a target. Right? When those quizzes come up that ask you what your mother's maiden name is and your favorite color and your favorite type of food, guess what? Those are your security questions for a lot of your banking websites as well. So be careful. The things you post, right, the pictures that you post on social media, they can be geotagged.

(Tyler Ward at 00:54:35) So an attacker can go on to your Facebook, copy a picture, pop it into an online program, and they can find out and pinpoint your exact location when you took that picture. So if you're on vacation, the Internet has become a treasure trove of data of which they can find out who you are, and they are likely just stumbling across you at times. That's the thing. Stop letting them stumble across you because you're so out there.

(Tyler Ward at 00:54:59) Another thing is, you know, I usually tell people who ask me that question is, well, how do I secure myself? Go freeze your credit. Freeze your credit. Keep it frozen. And if you're not using your credit, if you're worried about identity theft, keep your credit frozen until you're ready to buy a house, buy a car, and then do a temporary lift on the freeze and then freeze it again. That at least provides you another setup.

(Joel Beasley at 00:55:17) You can freeze credit?

(Tyler Ward at 00:55:18) Oh, yeah. Absolutely. Keep your credit frozen all year long. It costs nothing. We can thank Equifax for their snafu because now it's free across all three credit bureaus. But if you call TransUnion, Experian, and Equifax, or if you go online, just Google freeze my credit. Just hit all of the three credit bureaus, freeze your credit. And that way, when you're going to open up a new line of credit, you'll either call or go online, enter your passcode, lift the freeze temporarily, set it for like a day, and then lock it back down. That provides you a lot of protection. Another thing that is becoming a little bit more prevalent is you talked about MFA.

(Tyler Ward at 00:55:54) MFA on bank accounts is great. Use MFA on all of your accounts, but call your, tell your cell phone provider and tell them you want to prevent SIM swapping. Okay? Because now, guess what? The identity of all of us is the iPhone, and it is your Android, it is your Samsung Galaxy. And if somebody can call and socially engineer Twitter, they can call and socially engineer Verizon, and they can let them know, hey, I am Joe Schmo, and I want to swap my SIM over to my brand new device. Here's my manufacturer code. And guess what? That immediately swaps all the data from your system over to the attacker cell phone. And they've got all your MFA tokens, and they've got your Face ID. They've got all of it. So they don't need it anymore. They don't need your phone.

(Joel Beasley at 00:56:38) That's crazy. So you can call them and you can basically, this freeze my credit and prevent SIM swapping. These are things that just put, they're basically a multifactor ways to, you know, get these things done. I'm not saying it very clearly, but you get, you know, the text message stuff when you, and that's like what the API supports, like usually upon login. But there's these other things that happen in the real world that are different than logging in, and you can freeze your credit and you can call and then you get like some password if you wanna actually swap your SIM later in the future or something.

(Tyler Ward at 00:57:14) Yeah. They'll have you set up, you know, a pretty complex password. I know some providers use like a 15 digit code. Pretty long. Right? So you've gotta keep that copy down somewhere. But it at least provides another layer. Right? And it's all about creating these layers, whether it be personal protection or whether it be organizational protection. It's creating these layers and what a lot of organizations have not yet realized is that your personal Gmail account and the route into your personal life is a soft target into that Fortune 5 or Fortune 10 business.

(Tyler Ward at 00:57:47) And that's what they're going after. They're not knocking on the front door usually. They're going after the executives of organizations because they're soft targets. They do so much to secure their infrastructure. They forget about themselves, and they're out there on social media giving it all away and giving somebody an avenue into not only their life, but their organization as well. So those two things are kind of hand in hand now.

(Joel Beasley at 00:58:11) Earlier, you were talking about, you know, this concept of, you didn't say it exactly like this, but trust but verify as far as like auditing your team and all of that. And so I was curious, you know, we have a culture that favors measurement over at our company, like where we track stuff like week over week or month over month and things like that. But how do you, how would you advise a leader on approaching their team about security and like, let's say they approach them and then they get like a response to go, we got this, we've got these things, like, how do you, would you go back to like that list of the 20 things and ask them, you know, hey. Check what you're doing against these 20 things. Like, how do you have that conversation?

(Joel Beasley at 00:58:57) How do you, I'm getting to it. I promise you. I'm getting to the question. I'm getting to the, it's getting better as we go. It's not scripted. How do you have the first conversation about security with your team?

(Tyler Ward at 00:59:12) So, you know, five years ago, hard conversation to have. And even still today, you know, when my team is hired in to take over a security program and we've got to, you know, we're still working with IT. It's always a different dynamic. You're essentially stepping on somebody's sandcastle when you walk in, so you gotta be a little bit careful. Luckily, in the last few years, it's become an easier conversation because of ransomware. That's the only good thing that ransomware has ever brought to the table, is the fact that I can call a CEO and say cybersecurity, and they equate it to financial damage. That's it. That's the best thing that's happened because of that. So what I would do is to sit your team down and let them know is, hey. If this castle falls, so do we.

(Tyler Ward at 00:59:57) And guess who has to clean it up? We do. And guess who looks bad to the board? We do. And we may lose our jobs. So, you know, it's not fear tactic because it's just being realistic. I mean, we've seen organizations that have been compromised and the CISO, when we get there, says to his whole team, you're all fired. You're gone. Whole team out. And they hire my team for the interim or they hire another team and or they start to replace people.

(Tyler Ward at 01:00:23) So this is real. Now, as a leader in the organization, I would either, if you have the time, which most of us don't, is audit yourselves. Because if you have your team audit their own work, obviously you're gonna get maybe mixed results back with that, right? You've got, you know, maybe a 22-year-old kid who's a sysadmin.

(Tyler Ward at 01:00:40) He may not, or she may not, you know, audit their work in the same way as you would. So either do it, you have to do it from a third party perspective, a neutral third party, whether that be somebody inside of your organization or you as the CSO or the CTO, whatever the case may be, or you call in a third party assessment company to do that. Make the parameters clear. And as I walk into an organization to do a security assessment, I always tell the employees, "Just look, this is not a slap on the hand to you at all. This is not to knock your work by any means. This is a learning experience, and that's what I'm here to do."

(Tyler Ward at 01:01:15) I'm here to teach you how to secure yourselves so that I don't have to come back on my Saturday night and clean up when you get hit. And they're like, "Okay, that sounds good." But you do have to be careful. You've gotta give them the right message. And at the end of the day, it's about getting better, and we can't honor our new work. And also, I find that one particularly nice tactic to use that, you know, I have CTOs use is let their team know, like, "I don't wanna beeline you from what you're doing. I need you to do these tasks for system development work or code reviews, and I need this third party to do this security thing because we don't have the time to do it. And I don't want to flood your work schedule."

(Tyler Ward at 01:01:53) I don't wanna have you working on a Saturday morning. I want you to have a nice family time, and I don't want you to have to worry about this. And then we'll review the results together, and then we'll fix some stuff. So, you know, there's a whole bunch of ways to pitch it. And then the totalitarian way is, "We're doing it because I want to, because I know that if we don't, then we could be vulnerable in a number of different spots, and I'm not willing to take that risk as a leader."

(Joel Beasley at 01:02:16) Yeah. And the different ways depend on the different company cultures.

(Tyler Ward at 01:02:19) Sure, they do.

(Joel Beasley at 01:02:20) You know, you get a company that military background where a lot of people working there used to be military. Yeah. That works very well.

(Tyler Ward at 01:02:28) Very well.

(Joel Beasley at 01:02:29) Everyone's bought into that concept. And honestly, you know, I grew up with my dad being in the Air Force. I know you were in the Air Force too, but waking up, making your bed, like, you know, the little disciplines here and there. So important. Like, I'm really, I hated them as a kid, but as an adult, I'm like, "Oh, I wish I would have dove deeper into that." Like, I did it, but I could see all the benefits. Now I was curious, which came first for you, Air Force or NSA?

(Tyler Ward at 01:02:58) So I was at the Air Force first. So I was doing cyber ops and IT operations with them for about four years, and it was really cool. It was awesome. Just got to spend just shy of a year in Afghanistan at the foot of the Hindu Kush Mountains. So with my brothers and sisters from the Army and the Marines, and really interesting experience.

(Tyler Ward at 01:03:18) My wife remembers those, you know, shoddy Skype calls where there's, you know, the air sirens going off because you're getting mortars. So great. And then I spent, let's see, about eight months in a little tiny African country called Djibouti, which is just about 10 clicks away from Somalia. So very hot. Very hot, but very nice people.

(Tyler Ward at 01:03:39) So I did that for a while, and then I stepped out and I went to the intelligence community up in the DC, Virginia area, bounced between a couple of the Army intelligence bases up there, a little bit at the Pentagon, and then I went down to Augusta, Georgia at the Cyber Center of Excellence. And loved it.

(Joel Beasley at 01:03:55) That just opened up, right?

(Tyler Ward at 01:03:56) They just opened up. Yeah. Yeah. And it's crazy to look at it because you have two things down there. You have the Masters, and then you have this huge cybersecurity community in the middle of rural Georgia.

(Tyler Ward at 01:04:09) So it's really cool to see. And I enjoyed it, and we're headed back down south here pretty soon. So...

(Joel Beasley at 01:04:15) There's like a, I might get this wrong, but there's like a James Brown statue downtown in Augusta, Georgia. Is that right?

(Tyler Ward at 01:04:21) There is. The James Brown statue. Yep. And then there's some kind of a pole statue from some kind of a flood, I believe. I don't know. I never really experienced the whole, you know, tourist point of it down there. I was just working a lot. So, but it was nice. It was a nice go. And yeah.

(Tyler Ward at 01:04:38) So I'm back in the commercial sector now. I really enjoy it. The intelligence community, I work with a lot of different agencies. I was a contractor in there, so it was nice to be able to bounce around between these different agencies and see the unique things that they were doing. But the commercial sector, I had this burning desire, right? They needed help. They do need help. We need help. The commercial sector is not as tight as the military.

(Tyler Ward at 01:05:01) It's not as buttoned down as the government. And we just need good minds out here that are responsible and hold themselves accountable to secure these organizations because there's a real lack of that. And it's not just from a security perspective. And that's what I tell a lot of people who are coming through or up and coming in their career field is, you know, they say, "How do I get into cybersecurity?" Do IT really well.

(Tyler Ward at 01:05:25) That's how you get into it, is go through your IT and be a steward of cybersecurity of whatever technical job that you may be working. And that's how you get into cybersecurity. So it's a route for many.

(Joel Beasley at 01:05:37) That's true because even as like a Ruby engineer, you can get into some security, you know. There's security pretty much everywhere. So that's, I like that. So people wanna learn more. What's your website?

(Tyler Ward at 01:05:51) Website is igius.com or nodeware.com. So nodeware.com and IGI is the services arm of the organization. So it's my team and then some other teams as well. And Nodeware is our development team that makes a vulnerability scanning tool. So if you wanna...

(Joel Beasley at 01:06:12) Oh, pretty cool.

(Tyler Ward at 01:06:12) Check that out. Yeah. It's a really cool tool. It's kind of a byproduct of all the bad stuff that we've seen out there and giving tips to the dev team about, "It would be really cool to have a tool like this, and there's nothing that exists out there like that today." And we've used all of these, so it morphed into, you know, what this beautiful product is.

(Tyler Ward at 01:06:28) So it's a really cool organization to have, you know, really both of those services and software dev minds across the team. So...

(Joel Beasley at 01:06:36) I love it. Dude, Tyler, we did it, man. We made a podcast.

(Tyler Ward at 01:06:41) Wow. Finally. And I'm so sorry about my mic situation, but I've got a pro mic now and I've got the headphones, so I'm ready to go whenever and it's seems to be flawlessly working. So thank you.

(Joel Beasley at 01:06:52) Yeah. Yeah. And it sounds amazing, and your team will love it too as you do your conference calls. You'll sound like a pro now.

(Tyler Ward at 01:06:58) Nice. Nice. Hey. This was fun, man.

(Joel Beasley at 01:07:01) Yeah. It's cool, right?

(Tyler Ward at 01:07:02) Yeah. It's a nice chat, and you're an easy guy to talk to. So that's always great.

(Joel Beasley at 01:07:08) Right back at you.

(Tyler Ward at 01:07:09) Thanks. Hey. Have fun in Colorado. Enjoy that weather, man. Watch out for elk and cougars.

(Joel Beasley at 01:07:16) Alright. See you, buddy.

(Tyler Ward at 01:07:18) Alright. See you.

(Joel Beasley at 01:07:18) Thanks. Bye. Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected].

(Joel Beasley at 01:07:40) Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.