Episode 287 ·
Jon Murchison - CEO at Blackpoint
Today we are talking to Jon Murchison, the Founder at Blackpoint. And we discuss their nation-state grade cyber security ecosystem, the art of the go to market plan, and a checklist for CTOs thinking about cyber security.
All of this, right here, right now, on the Modern CTO Podcast!
Check them out now at Blackpointcyber.com!

About Jon:
Jonathan Murchison, the founder and CEO of Blackpoint, started his career in Network Engineering and IT operations, but quickly made the switch to the quiet world of the intelligence community. He has since spent over twelve years planning, conducting, and executing high-priority national security missions.
As a former NSA computer operations expert and IT professional, he is bringing a unique perspective to the mission of developing cyber defense software effective at detecting and detaining purposeful cyber intrusions and insider threats. Murchison holds multiple patents in methods of network analysis, defense, pattern analytics, and mobile platforms.
About Blackpoint:
Blackpoint Cyber is a technology-focused cyber security company headquartered in Maryland, USA. The company was established by former US Department of Defense and Intelligence cyber security and technology experts. Leveraging its real-world cyber experience and knowledge of malicious cyber behavior and tradecraft, Blackpoint provides cyber security products and services to help organizations protect their infrastructure and operations. The company’s proprietary security operations and incident response platform, SNAP-Defense, is available as a product or as a 24x7 Managed Detection and Response (MDR) service. Blackpoint’s mission is to provide effective, affordable real-time threat detection and response to organizations of all sizes around the world.
Transcript
(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to John, the founder at Blackpoint, and we discuss their nation-state grade cybersecurity ecosystem, the art of the go-to-market plan, and a very special checklist for CTOs thinking about cybersecurity. All of this right here, right now on the Modern CTO Podcast. Here we go.
(Joel Beasley at 00:00:25) This is the Modern CTO Podcast.
(John at 00:00:36) Hello, hello. Hey, hey. How's it going?
(Joel Beasley at 00:00:39) Fantastic. Look at that background.
(John at 00:00:41) I know.
(Joel Beasley at 00:00:41) It's very secure.
(John at 00:00:43) It's really a green screen. It's our SOC, though, a picture of it at least.
(Joel Beasley at 00:00:49) Oh, that's neat. So that's a picture of the inside of your SOC?
(John at 00:00:53) Yeah, yeah, absolutely.
(Joel Beasley at 00:00:55) People are like, can you tell me what SOC is? Because it's not the one you wear on your feet.
(John at 00:00:59) No, security operations center, right? It's our threat ops center. It's where our analysts sit when we're doing our 24/7 detection response type stuff.
(Joel Beasley at 00:01:11) Yeah. I was geeking out so hard when I was reading your bio and your profile and what your company does. It's literally like the secret agent slash secure—it's a dream of what you would want to do as someone in technology. It just sounds so cool. Can you tell me a little bit about it?
(John at 00:01:30) Yeah, yeah. Kind of our background, where we came from, and what we do now. So, you know, my primary background—I was a network engineer, right, originally. And then I ended up going to the National Security Agency and spending 12 years and really kind of flipped over more to the CNO side and did that for a long time, kind of, I guess, more as the bad guy for the right team. And in about 2014, I had a little bit of an injury that prevented me from working. And so I ended up kind of spinning out what is Blackpoint's offering today. And, you know, we flipped to doing only defense, and we're really a software company, but people consume our product as a managed service.
(John at 00:02:13) So, you know, it sounds sexy on the outside, but it's kind of like what pilots describe. You know, flying a plane is kind of boring until it's not sort of thing. So, you know, what we really do is we use all of our software and instrument folks' networks and computers, and we monitor them. And if we see any form of breach or tradecraft or lateral movement, we take action to stop it out of our SOC. So that's called managed detection response.
(Joel Beasley at 00:02:38) Why are you uniquely qualified to be doing this? I want you to say stuff about like the NSA and stuff.
(John at 00:02:45) Yeah. Well, I won't say too much there. But what I would say is, you know, there's a difference between doing like a test penetration operation. There's a lot of similarities. You know, I think ultimately when you've had to bring all sorts of technologies and humans and things together to go conduct an operation somewhere, there's a lot of details. Like I tell everyone in security, details matter. They really, really matter because that's the land the bad guys are living in and taking advantage of. So I think, you know, for us having sat on both sides of the fence, I think it really gives us a much greater appreciation for additional observables in a breach, right? You know, I think one of my takes is I think a lot of people get overly focused on catching malware, like the malicious toolset. The thing is, though, there's so much when you land in a network for the first time as the bad guy, you don't know where you are. You don't know what permissions you're running with. So it's little things like, how do I find other subnets? How do I find maybe this person I'm going after? We definitely prey on them during that phase of the bad guys' operation. So we're looking for guys trying to figure out where they are, laterally spread, which is really the common—almost every breach you'll see. So it's probably all of that coming together, which can help lead you to malware maybe that hasn't been detected before or, you know, servers on the internet, command and control infrastructure the bad guys use. Most of it's brand new in the hacks we see. So I think it's kind of bringing the whole operation together.
(Joel Beasley at 00:04:18) When you first learned to hack, I guess, was it like a class you took, or was it part of your job? How did you get into it, the actual hacking?
(John at 00:04:29) That's a good question. There's probably a ton of hackers way better than I ever was. You know, the reality is I was an athlete at University of Maryland and, you know, my brother—I'm the youngest of four—he was in Silicon Valley. He's a VP over at CrowdStrike for a bit. And, you know, back in the late '90s, he handed me a few Cisco books and said, "Hey, knucklehead, you know, start reading this stuff. It'll be good for you." So I did. So it was really all self-taught. So I started with networking, you know, got into kind of Windows domains, more IT stuff. And I think IT is some of the best fundamentals you can have because it allows you to understand networking and subnetting and how to move around. And then I got an interest in security, and then when I went to NSA, the rest was history. And it was very little formal training, almost all on the job and just learning. You know, that's the thing. There's so much on YouTube today that you can learn to do a ton just by curiosity.
(Joel Beasley at 00:05:29) Yeah. When I was—they didn't—we didn't have YouTube when I was a kid. Now I sound like an old man.
(John at 00:05:34) I know. Same.
(Joel Beasley at 00:05:35) I was at like Books-A-Million or Barnes & Noble and I was choosing between, I think it was like an MCSA book set collection or this book, I think it was called like Hack This Site or something. It was some hacking-related book where they gave you like introductions and they had a test site and you could go run these things. And I had already been programming, so I was already pretty familiar with tools and things and how to use the computer. So I went with the more exciting one. And then I didn't get into security. Basically, I just played around with it for a little bit trying to get into my other computers and things like that and having fun with my siblings. And then I just ended up making money doing legitimate stuff. And I said, well, you can make a ton of money doing legitimate stuff. No reason for me to be messing around over here.
(John at 00:06:24) Right.
(Joel Beasley at 00:06:24) Little did I know it would become this giant industry.
(John at 00:06:27) Oh, I know. Who would have known? I mean, it's—I guess it's a good thing, bad. It's good for us that there's, you know, companies to protect and bad guys out there. But the other side is that, you know, I wish companies weren't dealing with this stuff. It's terrible. Puts a lot of them out of business. But, yeah, it sure exploded.
(Joel Beasley at 00:06:45) It's in line with your passion now, what you're doing. So that's how you have like an awesome life. How did you pick the name Blackpoint?
(John at 00:06:53) Boy, that was—you're one of the only people I've ever asked me that, actually. So it was 2007. I had left NSA. They had asked me to come back, and I said no a couple times. And I don't know what I was thinking. I decided to ask them, you know, would you hire me if I started my own business? And so there's really been two Blackpoints. Like, one dot O, which is really all government services focused, and then that ended in 2014, and I sold that. And then the commercial one. And, you know, I was really just talking to my brother on the phone and trying to think like Black Ops, you know, some nod to what I, you know, kind of the past or the history. And and then I was kind of really into hunting at the time with my dog, like bird hunting. And so I was, of course, like, oh, on point. You know, dog's on point or whatever, but there's about a thousand of those. So I just smashed the two together. So it really means nothing. But that's how we got Blackpoint.
(Joel Beasley at 00:07:48) That's a good story. I like it.
(John at 00:07:50) Yeah, yeah.
(Joel Beasley at 00:07:50) What type of dog do you hunt with?
(John at 00:07:53) He's a Vizsla.
(Joel Beasley at 00:07:56) I've never heard of that.
(John at 00:07:57) They kind of look like a Weimaraner or German Shorthaired Pointer. You know, really skinny, you know, kind of dog that can run all day.
(Joel Beasley at 00:08:04) Yeah. I've been looking at the Border Collies recently.
(John at 00:08:07) Oh, yeah. Those are like the smartest ones, aren't they?
(Joel Beasley at 00:08:10) That's what they say. I just Googled smart. I was like, I want a smart dog.
(John at 00:08:14) Yeah.
(Joel Beasley at 00:08:15) I've had a couple dogs in my life and not so much. And so what's a smart one? And then I found Border Collies. But I want to know about your specific security company. What's the big thing that you see constantly over and over and over, like why your customers are coming to you?
(John at 00:08:33) The big thing I see over and over, I'll say on the tech side, is someone gets in one way or another. The most popular ways that we've seen lately are firewall vulnerabilities, unpatched firewalls. Those are hitting companies, smashing companies left and right right now because there's really very little malware involved. So they kind of come in, they VPN in, they hit you. Phishing. You know, you see something like SolarWinds, which is a little more rare, nation-state supply chain attack. They get in somehow, and like the common thing is rapid spreading, stealing privileged accounts, and using all the, you know, what people call living off the land techniques, the same techniques IT professionals use to push software, monitor machines. They do all that to get it. And so, really, what's happened is it's 2021. The volume of attacks have gone up so much, and companies are so reliant on their IT infrastructures that they just cannot afford to run a 24/7 operation. And you can't leave it up to automated software anymore. And actually, a lot of the anti-malware products have gotten much, much better. But that whole gray area where the bad guys are, you know, RDPing around or VPNing and spreading, like, it just doesn't trip those tools. And so what you really need is kind of a set of technology and people, and we're able to do it at a price point that gives a small company or medium enterprise real 24/7 operation, but with a hammer where we can respond to stop it really quickly. And I think that's what's brought most people, you know, kind of to the table for us. So it's just kind of a cost-benefit sort of thing. You know?
(Joel Beasley at 00:10:16) Yeah. It's easier to just hire Blackpoint rather than building it out all internally. That's how all of it—like Slack. Like, we don't build our own Slacks. We don't build our own Zooms. They build it for us, and we just pay them.
(John at 00:10:27) Pretty much. Pretty much. So you can focus on your main job, which is running whatever type of business you run so you don't have to become professionals in the game we're in.
(Joel Beasley at 00:10:35) Tell me about the SolarWinds attack. That was a recent one. It's pretty popular in the media.
(John at 00:10:40) Yeah. That was very sophisticated, you know, kind of in an odd way have to respect the skills that were behind that. You know, so that was really a supply chain attack, you know, supposedly from a nation-state, which I would believe, that really essentially—let me back up a little bit. So one of our verticals is managed IT service providers, MSPs. So we protect them, and then they resell our product to their end customer. They use tools called remote monitoring and management. So tools to, you know, push updates, to do help desk, you know, screen share type stuff, and patch computers. Well, if you think about those tools, they're like a legitimate glorified backdoor. So hackers love that stuff. Well, SolarWinds, they make that product, Datto Central, and that was not, to my knowledge, breached. But they make another product that does application and network monitoring, performance monitoring. And so what this threat actor group did is essentially broke into that company, found their kind of their software engineering servers and were able to get into the build process and essentially hook the updater, kind of like they did in the NotPetya worm attack several years ago with that M.E. Dock company. And they were able to—you know, when that agent phoned home to get a software update, they got a special update. And that update gave them remote access into the networks. I don't know, you know, that platform collects a lot of router configs, and I don't know if they were able to get that, which would make it even easier. But, essentially, it gave them—they were able to, boom, get right on the endpoint there. And then from there, they did the normal stuff, the lateral spreading stuff that we catch. And so that was a really sophisticated operation, and there was more to the story where they were going after kind of Microsoft 365 environments as well. There's something that, you know, they really kind of opened my eyes to this vector, which is taken advantage of what's called enterprise applications in 365, which is—I tell you, this has got to be going on like crazy right now. Essentially, you know, kind of the maybe layman's terms version of this is, you know how you can log in maybe with your Amazon account to pay for something on another site or Facebook? Well, let's say you're using like a CRM, like HubSpot, and you want to integrate that with your 365. You can log in to the HubSpot application with your 365 creds, and it gives your permissions to that end application, even if you have two-factor on. And so now that's going to open the door for all these rogue third-party applications that you're going to be able to start social engineering people to get in. So they played in that game a bit too. And I think that's going to become a big hot problem in 2021. There's already been some companies that have come out and said they were popped that way.
(Joel Beasley at 00:13:39) Yeah. My bank doesn't allow that. So if you do 2FA, it just voids all of your current like hooks or app like API keys sharing.
(John at 00:13:49) Oh. Interesting.
(Joel Beasley at 00:13:50) Yeah. At least, you know, my bank does. And because I found that out by accident because I had two-factor on and I needed to go do an integration, you know. And I went to go do it and entered my stuff and then it popped me back a notice that said, you have to turn off two-step authentication in order to use this service. And then I further found out that all the previous integrations were expired automatically.
(John at 00:14:14) Oh, wow.
(Joel Beasley at 00:14:15) There's a lot of reasons—there's a lot of things you can do that need your bank, third-party connected, right? So, yeah. From like QuickBooks to any sort of third-party cost monitoring software, all those types of things.
(John at 00:14:30) Yeah, yeah. A buddy of mine up the street here in Colorado, he unfortunately, you know, this is a year and change ago, he had an issue where, you know, it's typical stuff. He didn't have multifactor authentication on. So it's kind of a neat story just so folks understand how this kind of financial wire fraud stuff goes. They found his creds online, dark web, whatever, some other breach. He's the same ones, you know, across multiple accounts. They log in to his business account because they had his creds and he was using the same ones. They then read his email and found he uses T-Mobile. We'll go try that. And so they log in to T-Mobile, same creds. And then what they really rapidly did there is they went and made a rule on his email to forward, you know, anything coming into his inbox to another folder so he didn't see it. Then they forwarded his phone to their burner phone. Then they called his bank up, and then they said, "Hey, I can't log in." They said, "No problem. We're going to send you a two-factor cred to your phone via SMS." This is why you don't use SMS or phone calls for this. They got the cred, and then they were able to log in.
(John at 00:15:43) And they said, "Okay, I want to do a wire transfer," and sent another two-factor code, which came to the burner phone. And they then made a wire transfer to a bank in New York. They had a Bitcoin company as a direct customer, and that way it didn't go through international borders.
(John at 00:15:58) If you lost 200 Gs, it was gone. Never got it back. But that's literally just because you don't have app-based multifactor authentication. That's how fast it went. And that'll happen in about a four and a half, five-hour period. He was on a plane online, just wasn't getting emails.
(John at 00:16:15) Just thought, "Weird day. Didn't get emails," but that's what really happened.
(Joel Beasley at 00:16:19) How do you protect yourself against that? Is there insurance you buy? Like, what do you do? There has to be something in the marketplace.
(John at 00:16:24) You know, I don't—we sell cyber insurance. We have a cyber insurance agency at Blackpoint called Blackpoint Risk, but I don't know about that type of thing. What would have prevented that is having two-factor on the Microsoft Authenticator and then two-factor on his phone account. You know, that would have been—
(Joel Beasley at 00:16:45) As simple as prevented it?
(John at 00:16:47) Totally. Yeah. Yeah. Totally. It's unfortunate.
(Joel Beasley at 00:16:51) Oh, because of the original login is what happened. They were able to get the codes. Yeah. Yeah.
(Joel Beasley at 00:16:57) That's the thing.
(John at 00:16:58) That's why you don't want to use SMS or phone call for your second factor, because people do the game where they call your phone company and say, "Hey, I got a new phone or a new SIM card. I want to swap it." Boom. You're done there.
(John at 00:17:09) Or they log just right into your account with AT&T or T-Mobile and set up a phone forwarding rule, which you can do from those websites, just to forward all your calls to another number.
(Joel Beasley at 00:17:21) You know? So your base—what you do, what you tell people, like, let's say you're at the grocery store and someone's like, "Oh, hey, security expert. What's the two things I should do?" It's what?
(John at 00:17:33) It's multifactor authentication. Any application that's web-enabled—I mean, it's not negotiable anymore, I don't think.
(Joel Beasley at 00:17:42) It's like, what's more annoying? 2FA or losing $200,000?
(John at 00:17:49) Yeah. I think 200 Gs is worse.
(John at 00:17:53) Yeah. Yeah. Yeah. No. It's unfortunate. So you've got a lot of, you know, the scams where people get in, they break in, this normal hacking—didn't encrypt you or whatever—and then you have the scams which are really just a clever con man game where you're just trying to trick people into wiring you money or you're breaking in and wiring their own money out.
(Joel Beasley at 00:18:14) What's the most common for businesses? So they get through the firewall, they get in there, they bounce around, they live off the LAN, they gain super admin access. What's the most common end result? What are they trying to do?
(Joel Beasley at 00:18:26) How do they process?
(John at 00:18:27) Ransomware. So what they're really going to do—yeah. So, you know, that really started with most of the groups who just encrypt all the computers, call you up and say, "Hey, pay up or you're never getting your data back."
(John at 00:18:40) And so folks started saying, "All right. Well, I'm really going to double down on backups." So the bad guys then evolved and really started targeting the backup infrastructure as well, of course. And really what shifted in 2020 is the more sophisticated groups said, "We need more leverage on these folks to pay, so we're going to steal the data first." So we're going to steal a whole bunch of your sensitive data.
(John at 00:19:04) So if you're a, you know, manufacturer, maybe they're stealing designs, whatever. And then they encrypt you. And then they'll reach out to you and send you screenshots of the data, give you a deadline, and say, "If you don't pay up, we're going to release all your private customer data or HIPAA or whatever on the Internet, and you're not going to get your keys back." And so they really jacked it up. So that's why the insurers really took it on the chin, I think, in 2020 with cyber insurance policies, because—and then what they'll say is, "Show me your policy. Tell me how much coverage you have," and then they'll ask for that.
(Joel Beasley at 00:19:40) There's a new one I got recently, like, about a week ago, and I'm going to try to share it in the most respectful way possible. So I got this email and it was from me because they spoofed my email. I'm like, not hard at all. And it said, "Hey, I have full access to your email. I tapped into your webcam and recorded you watching a certain type of adult-type video doing a certain thing."
(Joel Beasley at 00:20:06) And I'm going to—and I also have your contact address book, and I'm going to send the video to all of your contacts unless you send Bitcoin to this address or whatever it was. And it was like, I guess, it was between one and $3,000. I was like, "Well, given that I don't do that, like, I know you don't." And this is clearly—but it was such an interesting one because for decades, I've gotten all the other scam emails that are just so obvious, but this one was like a whole other level.
(Joel Beasley at 00:20:42) I took a screenshot of it and sent it to my producer and my associate producer and said, "Hey, are you guys getting spammed?" to see if it was domain-wide. Like, is this happening on our whole domain? Because I need to know if my employees are all getting their own version of this. But it was interesting because of the way they wrote the message. It was very—it was very convincing and it was very direct, and it would be something you wouldn't want to share with anybody.
(John at 00:21:08) Yeah.
(Joel Beasley at 00:21:08) Even if you were innocent, you would not want to share this with somebody. But I'm never shy of difficult conversations and I need to protect my team and make sure this isn't spreading. So I did, but I was curious—so many people must be seeing this and doing it out of fear.
(John at 00:21:27) Oh, one of my family members got that over a year ago, and they freaked out. "Oh my gosh. I don't know what it could be. I haven't done this, but what do they have?" I'm like, "No. They're just lying. They're tricking you." So, but yeah, it was a really well-written email, the one I saw. That was, you know, it's spooky. I mean, that's the best thing. If you want to scam someone or trick someone, you need to generate an emotional response out of them.
(Joel Beasley at 00:21:51) Yeah.
(John at 00:21:51) That's when people start making bad decisions. Right? And, yeah. So con artists are good at that.
(Joel Beasley at 00:21:59) I guess you're right. Those are all the popular ones. I'm stuck in another country. I can't get a hold of—always a really emotional reason.
(John at 00:22:07) Yeah. No. It's the best way to do it. It's the best way, I think, to, you know, unfortunately, manipulate a human. So—
(Joel Beasley at 00:22:15) So you're out there cleaning up the world, right, stopping these guys, superhero style.
(John at 00:22:21) We're trying. Yeah.
(Joel Beasley at 00:22:22) Yeah. Tell me about some of the things that you've caught.
(John at 00:22:25) Yeah. So, let's see what would be a good one. We had one over the summer that was a municipality, actually. We onboarded this customer. You know?
(John at 00:22:38) And like a lot of municipalities, you see maybe not enough investment in IT modernization, so they're running a lot of end-of-life, like, Windows 2000 or 2003 servers still. So we roll out, and they were already breached, but there was no real indications yet because they were sitting on these servers that we can't even run on. They're so old. And then what we find is our most active times for response are about 6 PM East Coast Friday night to about 6, 7 AM Saturday morning.
(John at 00:23:13) Right? I think that's on purpose. I think some of the groups wait for, you know, everyone to go home and get drunk on Friday and go do their thing. And so what we experienced there was an absolute mass lateral spread all at once. So we see this server, which we don't have one of our agents on, and they hit the 911 server, the criminal justice information server, the fire dispatch, all the security cameras, badge, everything.
(John at 00:23:42) This was going to be a Baltimore-like ransomware event. And, you know, so we stepped in. We started responding. And I think we had four people working on this one all at once because, you know, when someone gets in a network and there's no antivirus alerts, which is actually really common—we went three months, we had a 2,000% increase in our breaches right before the election that we had to respond to. There wasn't one anti-malware alert in any of them, you know, from any of the products that were installed. And so, you know, we're killing proxies. We're isolating machines. And, you know, you probably had a 20 to 60 minute window before this place is mass ransomware. And so we stopped wave one, but, you know, there's so many holes in this network that they had free access to come in from the Internet, and, you know, we had limited control on that piece.
(John at 00:24:31) Long story short, it was cool. The second time we watched them, it probably took—we knocked them out, and I'm sure they were probably confused as to what was going on. And we had about an hour time frame, and then wave two came. When wave two came, we watched them disabling two antivirus products because they thought that's what was catching it. And long story short, this went on six times.
(John at 00:24:56) So that was one. We had another cool one. Well, I guess, cool. This is—
(Joel Beasley at 00:25:02) It's not quite cool. Yeah.
(John at 00:25:04) For me, it was kind of cool. So we had one where we rolled into a network. And, again, they were also owned by two groups. One was a nation-state, and one was a criminal group that was getting ready to ransomware them. They got in through bad firewall hygiene. Right? So we get in, and we see the ransomware group's making a lot of noise trying to get ready to pop this whole company, and they're probably 4,000 employees or so. So we knocked them out, and then we found a really quietly persisted one. And that turned out to be a pretty prominent nation-state. So we, you know, we kind of kicked them out and got their toolset and whatnot and reversed it.
(John at 00:25:48) And so another one that—one last third one I think you might find kind of neat is, you know, nation-states when they go after, they have a lot of agenda. It might be to destroy something, you know, just to make a mess of a network or when we hear about intellectual property theft. This particular—a lot of times nation-states will—let's say you were targeting, would be a good example, as in this case, a space program. Right?
(John at 00:26:15) You might not target the main kind of big contractor, the big notable name. There's probably seven downstream supply chain companies that make a little part here, a little part there. So—and this is like small business at this point. Right? So we had one customer, small business, they made a really specialty part that flew, you know, that went to space, and another country wanted it.
(John at 00:26:42) We watched them come in. There was a true kind of next-gen AVE, DR running. No alerts there. We watched them. They do the normal stuff. They exploit the firewall. They tried to figure out who the domain admins are, but then they immediately went and tried to hit a CNC machine.
(Joel Beasley at 00:26:59) Oh, the cutting machines.
(John at 00:27:02) Yeah. Cutting machine, like a water cutting machine. Why? That's a brilliant place to go get production part. So you know if you get that diagram, you can take that billet of aluminum or whatever it is in your own CAD machine, load it, and cut it perfect.
(John at 00:27:18) So we stopped them before we got it, but they're totally after that raw file that would allow them to get a perfectly—you know? So that's how you don't have to do any R&D at that point. It's already a production-ready part. It's not something United States does, but that's absolutely something other countries do. So we're glad to stop them before they got anything, but that is—that's something where a lot of these kind of smaller mom-and-pops that make something special don't realize they're really on the radar for some, you know, pretty powerful groups.
(Joel Beasley at 00:27:48) I want you to—we're talking a lot about the attack and this side of things. I want you to walk me through the offensive team. Like, what is it like? Tell me a story. Like, what is it like? I'm—you mentioned these waves. Am I sitting there with a team of five people around me and I'm commanding them and we're going after the CNC part? Like, how is that playing out at the nation-state or at the attack facility?
(John at 00:28:13) Oh, well, I could probably give you more of the defensive one. I probably won't go into too much on the kind of—
(Joel Beasley at 00:28:21) No blueprint.
(John at 00:28:23) But yeah. Yeah. The reality is, like everything in life, things that look really spooky from the outside are a lot simpler and it might be one or two people doing something. You know what I mean? So, you know, I'll say on the defensive side, most of the time, it's pretty low-drama. It's like, "Oh, we see this piece of tradecraft, see this going on." It gets escalated by tier one, and it's about a 30-second decision to click a couple buttons and stop it, notify it, and ring the customer's phone off the hook, and maybe give them a couple other things we want them to do. In the case of when we roll into larger customers that are really owned, it can turn into an all-hands-on-deck with multiple people working on kicking the bad guys out of servers on one side and workstations on the other. And you kind of—and that one is really more kind of intense and has a lot of folks, but that's a kind of rare event. You know, most of the times, when we roll out, the company is not owned, but we see a lot of holes, what we call IT hygiene problems, kind of like underlying conditions if it was the human.
(John at 00:29:31) And those are cases we're able to kind of give them a couple of pointers to tighten their game up really fast, and that really reduces the attack surface. So it makes response a lot more calm. But, you know, you look at—I can only surmise that SolarWinds breach and everything that went on was a pretty large team of folks. And when—and I apologize for my child in the back.
(Joel Beasley at 00:29:52) You have a banshee too? I've got two.
(John at 00:29:53) I have them. Yeah. He's upstairs. Yep. There's a time when a lot of resource could be thrown towards making, you know, a technical capability and working with humans. You know, there's a lot that goes into, you know, big operations. And so—and that I think that's one of, again, one of the reasons companies come to us is, you know, Main Street America companies or even a medium enterprise of 4,000, 8,000 folks, they're not—they're not equipped. They don't have the people that know this game, and they don't want to spend money on a 24/7 operation themselves. Yet they might have, you know, a very well-resourced large team of people who wake up every day and their job is to break into them and make a mess or, you know, hire people to go work for them. So it's—and I think that's where this game's moving, where you're going to see more specialization and outsourcing.
(Joel Beasley at 00:30:48) Do you have any favorite movies that, I guess, dramatize the offensive in a pretty interesting way or a way that you enjoy?
(John at 00:30:56) No. I can't watch them.
(Joel Beasley at 00:31:00) You can't watch them?
(John at 00:31:01) Let me ask you. Have you ever seen a movie where stuff comes on the screen and it doesn't make—and it makes noise, like, every single time? I mean, it drives me nuts. Like, the computer's printing stuff out really slowly. Like, that's old movies. I can never watch these spy movies. You know what movie I thought was actually pretty good is Red Sparrow, more on the kind of human side. I thought that was a pretty good movie and, you know, kind of a nice nod to a certain human tradecraft, not on the tech side. Some of the movies—what was that TV show? Was it Mr. Robot? I don't remember.
(Joel Beasley at 00:31:40) Yeah. I know. Mr. Robot.
(John at 00:31:43) They used to use at least real commands in there. It wasn't just garbage stuff on the screen. I remember there was one of the Matrix movies used Nmap in there, and all the computer guys went crazy. They're all excited to actually use a real product or tool.
(Joel Beasley at 00:32:00) I know. Nothing's worse than when they're using stock footage or nonsense on the screen, because for me, without even trying, my brain can just see the image quickly and process exactly what's happening because I've stared at that screen for a decade plus, right?
(John at 00:32:14) Yeah.
(Joel Beasley at 00:32:15) And I think one of the first times I noticed it was the Facebook movie. He was running curl commands, but it was better than just nothing, just whatever they would put in before. Or the worst is when it's code from another application that you see running and you can read it, but the director or the editors had no idea. They're like, "That looks like code. Let's put it in." It's a cat picture image algorithm.
(John at 00:32:38) Oh, yeah. Totally. Totally. I think they're trying harder now to put at least a little bit of, you know, some realism into it. But I haven't—I can't say I've seen a great one, to be honest. It'd probably be a really boring movie if you did it all for real, because the reality is you fail about 85, 90% of the time, I think, when you're trying to do this stuff. You know, there's so much failure, and then finally, you found one little hole and you keep worming your way through. But yeah, no, I'm not sure I've seen a great movie, but I did think Red Sparrow was pretty well done.
(Joel Beasley at 00:33:11) You've used the word "tradecraft" a couple times. Can you give me a better definition of that?
(John at 00:33:17) Yeah. I think some people would call that behavior. It's really your tools and tactics and techniques and procedures that you use to, let's say, figure out where you are in an environment. So here's an example. Let's say I sent you or anyone a spear phishing email. You clicked on it and now I have something running on your computer. I have to figure, are you at home? What type of firewall do you have? What's your default gateway? Is this like a SOHO home thing? Is this a Cisco device? Or did I land in a really large enterprise network? And how many hops am I to, let's say, Google? What's filtering some of my maybe ICMP or ping type traffic going out? Because all this is—these are little techniques you use to try and orient yourself in the virtual environment.
And that's why I said, when you break—and this is not a hard and fast thing, I'm sure people take exception with this—but I think when you take the best guys for making malware, backdoors are really awesome software engineers. They find exploits or they're good reversers or all that. I think the best people to use the tools the software engineers make are guys with a strong IT background because they understand networking, segmentation, you know, how different authentication systems are working. I think that's like the dynamic duo—those two groups moving together. Now some people can do it all, but I really, really think we tend to hire more in our threat operations center, more folks with the strong IT background, because so much of the—when I use the term "tradecraft," other people use the term "behavior," it's the same thing. So much of that is actually mounting C dollar sign admin share. IT guys know what that is in two seconds, or a net command to interrogate a domain controller. IT guys know that just instinctively off the bat if they were domain guys. So I think there are some backgrounds that lend yourself to one skill set or the other.
(Joel Beasley at 00:35:29) Yeah. I'm definitely on the software side. It was when I realized the software is only as good as the people who wrote it. And then, so here are the holes that I wouldn't—or that I didn't think about earlier in my career, that I found out about later in my career, or I found out after watching more experienced engineers operate. And I'm not super strong on the networking side, but—
(John at 00:35:51) Right.
(Joel Beasley at 00:35:52) To your duo pair back, I'm actually 33 today. So back when I was around—
(John at 00:35:58) Happy birthday.
(Joel Beasley at 00:35:59) Thank you. Like, 10 to 13, when the first Xbox online things came out, right? So it's 20 plus years ago, which sounds ridiculous. So one of the people found out that if you used a firewall to—because they would load the game off of someone's disc. Like, 10 people join the room and they're going to pick one Xbox console to load the game off of, way back in the day. And so they found out that if you had a firewall system running and you identified the other IP addresses trying to connect, because it's testing all the ones to figure out which one to go to, and you mark them as medium threat, it would confuse it and it would make you host. You could essentially game the system. I'm trying to remember 20 years ago. You could game—yeah, you could game this. You would install this software on your computer and it was just a standard over-the-counter defense software, and you could select these IPs as they were coming over your network and treat them a certain way with a certain rule set, and it would then block them. It was really complicated. So I wrote a little piece of software that just extracted that feature because it was this massive suite of tools, and I just looked up how it was working. I didn't really need to know about the network or how it worked on a really detailed level. I just figured out how this one specific feature worked and mimicked it into its own container so that I could give it to my friends and things like that, so they wouldn't have to download a whole suite and crack the suite, because, you know, that's what you do when you're 10. Of course, you don't have money to pay for it.
And then we just basically extracted this hack out. And then, of course, Xbox solved what was happening because you would modify the disc. You would modify the files on that disc so that you could have whatever weapon you wanted. You could have a rapid fire thing that shot rockets, and you would be the only one that had it. You could make everybody spawn in one location. Basically, it was fun and boring. It was like something you do over the summer as a kid, right?
(John at 00:37:53) Yep. Awesome.
(Joel Beasley at 00:37:54) Yeah. And so it was a network guy found the exploit and knew how it worked, shared it with me. I was a software guy. I helped extract that out. And ultimately, it was for the sake of winning the video game.
(John at 00:38:07) Yep. I really think there's something to that kind of merging of skill sets. And then the last person you'd want to add to the team is a guy that's a great human manipulator that can help design content to lure people and socially engineer them. When you bring those skill sets together, there's a lot you can do. And, you know, it's one of the things in our product, actually—we're one of the only companies that does live network mapping. We build whole dynamic maps of the network because I always felt like, man, the SOC guys, and I've been on both sides of this, they're always focused on kind of malware, command and control, bad DNS, but the network and IT guys really know what should be happening where, which part's the segment for the IT and privileged users, where's the C-suite, where's your server line segment. So we do all that together because we're monitoring thousands of networks and we need to be able to make sense of it really fast. Like, what subnet did they land in? Where are they trying to spread to? And it allows our response to be a lot more efficient. But yeah, you're spot on. To me, programming seems so incredibly hard. I think you guys are the bigger brained ones.
(Joel Beasley at 00:39:15) I disagree. I think we all see it like that. Wherever we have a decade plus of experience, we see it as very simplistic, and then something else that we can barely scratch the surface over, like, those people are so brilliant and I'm just—
(John at 00:39:27) Yeah. Yeah.
(Joel Beasley at 00:39:29) Yeah. I was talking with Vinu. He's over at Presidio and they do this digital transformation. So they're a digital transformation company. They move companies to the cloud, a variety of ways. Really, really great company. But I was looking for questions for the show and one of the ones that came up was, what's the security that you need to think about when you're moving in that digital transformation process? Do you come across that? Do companies come to you and say, "Hey, we're going to be moving our environments. We want you to wrap your security around us and watch us in this move"?
(John at 00:40:04) Not as much during the move, I would say. Most times when people are coming to us, it's because they know they don't have any eyes on their infrastructure and they need our software and our folks to do it. There is a lot to be said, though, during that transformation time, because that's a time where, as you know, a lot of people have to get it working first and secure it kind of as fast as they can after. It's hard. It's a pain in the butt getting everything up and running and working. So, you know, it is a good use case. We find a lot of folks in—we counsel them on this. We're monitoring literally every privileged transaction going between devices, right? And that can be really helpful because so many times you'll find there's a dozen service accounts that aren't associated with one user, and they're littering creds and tokens everywhere. And that's exactly what the bad guys go after. And when you're kind of making that transition, there's a lot of that activity going on. So the places where you can maybe steal credentials increases a bit when you're doing that kind of move.
I'll tell you the other areas we've seen that are terrifyingly kind of loud and sloppy are DevOps environments—
(Joel Beasley at 00:41:18) Mm-hmm.
(John at 00:41:18)—you know, where you're doing all your automation orchestration. I guess on one hand for the bad guys, it's confusing to figure out what the hell is going on. But on the other hand, there's a ton of observable stuff. The amount of passwords we see in clear text from scripts and even commercial software it's using, it's unbelievable. We had to create a whole new class of alert just for this because we see it so often. And the reality is, if we see it, if anyone gets on there—bad guy—they're going to see it too, and it makes their life a lot easier.
(Joel Beasley at 00:41:49) So they're storing them in config files versus as environment variables?
(John at 00:41:53) Yeah. They're in config files or, you know, you can turn on command line ordering in all the modern Windows, and so you'll see in the command line arguments, the clear text password is sitting there with, like, a dash P and then the password, all the time.
(Joel Beasley at 00:42:09) Absolutely. Look in the history of your commands and pull the password.
(John at 00:42:12) All the time. And you'd be shocked how many companies that make legitimate software are doing these little tricks here and there to remotely get data or operating system information or patch levels off another computer. It's pretty shocking. It's pretty shocking. So that's why it's kind of better if you're going to design some agent thing to make sure it runs as system and it gets its commands securely, as opposed to it authenticating out to another machine to interrogate it and bring its data back. We see that all the time, unfortunately.
(Joel Beasley at 00:42:47) What do you recommend to CTOs? As far as a two- or three-step checklist? And I'll give you some context. Let's say they're between maybe 100 and 500 people, right? So, like, that range. So you've got a CTO, maybe they've gotten some growth, they know how to manage people, they're growing. They know they should maybe get a CISO or something. Do they have a two- or three-part checklist for what they should be doing?
(John at 00:43:13) For tightening up their game? I think so. I think first off, it starts with external vulnerability scanning, right? Your outside interface to the internet. That's low hanging fruit. So many people don't upgrade network devices or firewalls regularly enough. And there's some really bad—that SonicWall one just came out. There's some really bad ones on the Pulse Secure VPNs in 2019 that got exploited like crazy. We have a—we found a list in the dark of 50,000 companies that the hackers had of vulnerable firewalls. Scan that, make sure you don't have RDP open to the internet, make sure your firewall's up to the latest patch level. Because what happens if you mess that part up, there's a gazillion bots scanning looking for this, and then a bad guy will take over and connect right in. Most people integrate their VPN with Windows Active Directory. So some of these things allowed you to get clear text creds for anyone connected, which means in COVID, everyone—a lot of people moved to work from home, including the admins. That means they're walking in as domain admin. That's when, you know, we've stopped a ton of these, but they're also high stress because the time to it going bad is really short. So that's one: your boundary.
The second thing I think they need to really focus on is an audit of all privileged accounts. And make sure that your admins have a non-privileged day-to-day account, and they only use a—they put in their privileged separate account only when they need to do something privileged. So really bring that down. We find way too many companies have over-permissioning of privileges, and they have bad group policies that are giving users local admin on all the computers. So it's as good as domain admin, really, at that point.
And then the last one is the basic one, which is for all your kind of internet-facing web applications, get MFA on them, get MFA on your VPN. You do those three things, your attack surface comes down massively.
There's probably one fourth thing at that size where a lot of folks at that size use an MSP, some sort of outsourced IT, either partially to augment or fully—make sure they have multi-factor authentication on their remote monitoring and management tool. Because what happens is the hackers are going after MSPs like crazy. Because if they can hit them in that tool, they can encrypt 40, 50, 100 companies all at once. I mean, you heard about the 22 towns in Texas a couple years ago that got ransomware all at once. That's how it happens. So that's the other kind of secret factor that can really burn you. And it requires one question, and, "Hey, vendor, just make sure you're doing this." And it really, really brings down your attack surface.
(Joel Beasley at 00:46:04) Nice. Thank you for that. We'll make a little checklist of that and put it into an email and send it out, get the awareness out there for people. One thing I definitely wanted to touch on was you race cars and self-driving cars and you're into security. What is going on in the self-driving security world?
(John at 00:46:24) Oh, that's a good question. I don't think I know the answer to that. First off, I like racing cars. I'm not amazing at it, but it's so much fun, and you get to go real fast. And racing wheel to wheel is really fun. So the whole kind of automated car thing doesn't really excite me. That being said, from a security standpoint in cars, one of the things that makes me a little bit nervous—so there's the sensors, right? I think weather is probably going to cause a lot of those self-driving car LIDAR systems and everything more issues, but I'm not an engineer on that side. It's the firmware updates that come over the air. You know, like Tesla, for example, they can update their cars and unlock performance or optimize whatever. And the question I always have in my mind is, okay, how is that code written? How is it secure?
(John at 00:47:15) How is it authenticated? And how is it deployed? And over what networks? And how could you get to that as a bad guy? I think cars, and this is probably going to touch all cars whether they're internal combustion or not, is you start being able to remotely upgrade your car, no different than a firmware update in a computer.
(John at 00:47:36) I mean, firmware attacks are brutal because you can just break things totally. There's a lot of network devices, routers, switches out there that don't even cryptographically authenticate their firmware, which opens the door for just turning them into a total brick. So I think that would be one area that I would assume the car companies are putting a ton of focus into. But that's what would make me nervous, someone taking over that type of infrastructure just because of how damaging it could be.
(Joel Beasley at 00:48:08) Yeah. You could broadcast. I'm curious about their internal security. I always like to go to the gun to the head analogy, right? Because that's my favorite one, because it's like, okay, all the security in the world and someone walks up, if you put the gun to the right person's side, you're going to get what you want.
(Joel Beasley at 00:48:22) And there's got to be one central point where they broadcast out updates over the air to all of these vehicles, and how is this going to happen? Not just Tesla. Let's talk about any place you're going to have that congestion of you have a bunch of multi-thousand-pound vehicles that are autonomously driving that you can take control over.
(John at 00:48:44) Yeah. Yeah. You know, I don't know enough about that technology, I think, to comment.
(Joel Beasley at 00:48:50) Come on, John. You're supposed to be an expert.
(John at 00:48:53) I know. The it always seems to me like an autonomous lane would be really nice where the car, maybe the lane has some sort of RF something to tell the car to stay in the lane, to reduce all the calculations it has to make as far as avoiding other traffic. It seems to me, you know, and I'm sure they'll get there at some point, but the whole idea of this complex world and all these known unknowns that have to be thrown at this algorithm, like, they're going to mess up, I would think. So I always thought an autonomous lane would be kind of clever.
(John at 00:49:31) Keep those vehicles there, and I think it'll be a lot simpler on the types of decisions they have to make. You can put trucks in that lane, and, heck, they'll probably manage their spacing a lot better than humans would. But, you know, I don't know. It'd be so cool if you had someone from that world on your podcast just to kind of go into that technology. I would definitely listen to that.
(John at 00:49:52) It's fascinating to me.
(Joel Beasley at 00:49:54) All right, Adam. Make a note. Adam and Jake are listening. We have to go get an autonomous, self-driving car security expert, and then we'll send you a link and see if we can geek out about it. What type of cars do you race?
(John at 00:50:08) So I race a form of Miata. Like, you know, everyone seems to race. It's the most popular. It's called Chump Spec Miata, SSM. My main home's in Maryland, and I'm out in Colorado for half the year because my kids are ski racers.
(John at 00:50:25) So they're kind of like the original Miata that's all caged and kind of spec. So we all race with the same horsepower and suspension and tires. And then, you know, it's on a road course, and there's anywhere from thirty-five to fifty cars at the event.
(Joel Beasley at 00:50:42) Good commute.
(John at 00:50:42) It's a blast. It's great. And there's some tech guys. The ZeroFOX guys race back there, and they're good. And it's a ton of fun.
(John at 00:50:53) There's a lot of crashes, though. That's the only thing that kind of stinks because you have to foot the bill for your car. So I got wrecked twice over Labor Day and another day. So my car is getting fixed right now.
(Joel Beasley at 00:51:06) Was that a previous wreck? You were discussing way at the beginning that you had some injury that changed the course of your progression. Was that car related?
(John at 00:51:17) No. That was me being an idiot. I was, I was skiing down a dirt bike trail in Maryland because I have a bad back from sports. And instead of sledding with my kids, years and years, this is 2014, I didn't buckle my boots really. I had, like, one buckle, and snow was heavy.
(John at 00:51:37) I went to stop and my ski stuck, and I blew up both my knees. Like ACL and MCL, a lot of meniscus, all that stuff. So that's where I was kind of stuck.
(Joel Beasley at 00:51:46) You know.
(John at 00:51:46) I was in a wheelchair and I couldn't work for a while. So that was kind of the, you know, in hindsight, I'm not sure I would have ever left the Intelligence Community if that didn't happen and start the commercial version of Blackpoint. So, you know,
(Joel Beasley at 00:52:01) maybe that was a
(John at 00:52:02) blessing in disguise. I don't know.
(Joel Beasley at 00:52:04) I 100% believe that. So when I was around twelve, younger, I got hit by a car. I was in a wheelchair for a year, broke my right leg in a bunch of places, and really tore up my left leg. And my sister-in-law asked me to talk to her two boys who are seven to ten about playing safely in the street and to tell them my story. And she's like, "Can you go talk to them and tell them how bad it was and everything like that?"
(Joel Beasley at 00:52:33) And I started to think about what I would say to them. And the problem is I go around and do national speaking tours, and I use that as, like, I took all the energy from that horrible event and spun it into power. And it's, like, one of the greatest events in my entire life. I'm like, I can't go over there and tell them how bad it was and how it ruined my life.
(Joel Beasley at 00:52:53) Because it made me who I am today, and I absolutely love that part of my history. It taught me so much. It made, yeah, there's
(John at 00:53:01) there's a lot of truth to that. I mean, there's a lot of good things that can come out of adversity. A lot of good things. It's a great hardening process too. You know?
(John at 00:53:10) So, yeah, I mean, especially for COVID. I mean, it's terrible, but I mean, just terrible and tragic. You know, just for my own business, we were so stuck in this brick-and-mortar, hiring everyone at our office mindset, and then we went so virtual after. We have employees in Canada, Latin America, Central America, you know, Middle East, Europe, all over the place. We're able to find, and the commute has cut down. Like, so I think everyone's kind of working a bit more. Like, our productivity went up, and it's worked great.
(John at 00:53:45) And I don't think I would have thought that way until I was forced to think that way. So I'm totally agreeing with you. Now I wish I didn't blow up my knees, but the flip side is it got put back together pretty well, and, you know, just dumped almost two feet here in Colorado. So I snuck out with my kid this morning for an hour.
(John at 00:54:05) This year sounds good.
(Joel Beasley at 00:54:07) So that sort of the difficulty of that moment helped prepare you for the difficulty that is I'm a founder. A lot of people, "Oh, you're a tech guy, podcast." It's like, well, I'm an entrepreneur and this is my current project. But I'm curious, you know, that helped. Those difficult moments help harden you and help prepare you. What are you learning now as a leader?
(John at 00:54:31) I will say, man, I've made a ton of mistakes with this company. You know? But now we're kind of kicking butt, and it's going awesome. I would say the biggest thing I didn't understand in starting a business, we knew how to make tech. We knew how to catch hackers.
(John at 00:54:48) The art of the go-to-market plan, picking your customer, how you, you know, we made a product at the time that was so far ahead of its time, and everyone's stuck in the SIEM mentality and gobbling up terabytes of logs, and they still are, frankly, trying to make sense of it. We built this thing that was like a SOAR platform out of the box, you know, Security Orchestration, Automation, and Response. And the thing is, you know, when you go upmarket and sell large enterprise, what I find is they look at what Gartner recommends, and they look at what their customers use. And a lot of them don't necessarily understand, like, why they're buying. Like, I tell everyone, if you want to be good at security, details matter.
(John at 00:55:27) They really matter, and you better roll around those details and understand them. And so, you know, for me, picking when we picked MDR, Managed Detection Response, which became kind of the hot new security area. When we settled on that, when we were kind of settled on a channel-based go-to-market, we realized sales is really about building a machine. You know, you have to have a value proposition that resonates. It's got to fit in a product category they understand. You have to have some folks who are focused on bringing new channel partners on.
(John at 00:56:00) And then one of the things we did recently is we reorged our sales team so that every time we bring on a new partner, they immediately get a Customer Success rep that trains them how to sell, gives them all their sales materials, gives them sales tools. It's like a white-glove onboarding because we want to make our channel partners better because it helps us. And it was figuring out that entire machine. I mean, we floundered a few years ago just trying to understand that it wasn't ever a tech issue. It's like the best product only wins 50% of the time.
(John at 00:56:29) Like, I didn't know that. I didn't know how much more, and I didn't appreciate it, and, boy, do I know. And I think we got it figured. And how much we can automate and instrument every piece of our sales process so that we know, you know, where our best leads come from, why are people buying, when they go to competition, who it is. It's all automated now in Power BI dashboards. We have it all kind of dialed.
(John at 00:56:51) That stuff was really, I think, what I slept on big time in the early days. So I would do it totally opposite. I would start on go-to-market and realize we can engineer our way into the right product if I start a company over again.
(Joel Beasley at 00:57:05) The ratios of how many unique contacts need to be made versus response rates and all, building a sales org is something I literally, so I was so great with technology. I could build you anything, run teams of teams, but it wasn't until the past, you know, thirty-six months that I learned how to build a sales team and the difficult, you literally described it perfectly. You're building a machine. People will ask me, they'll say, I was working so many hours, right, doing this and completely ignoring my family until this past October. I started really investing and spending time in them because we figured out sales.
(Joel Beasley at 00:57:41) Like, figuring that out relieves all the pressure. Right? And going through that process, I said, you know, if I were going into the garage and I were building a physical printer that could print money, people would be like, let's do it. I'll come over and help. You know, every night, you know.
(Joel Beasley at 00:57:58) But that's what I was doing. It just, I was building a money printing machine. It just wasn't a physical machine that was illegally printing money. It was a business. And that's what I just kept doing, layer after layer after layer.
(Joel Beasley at 00:58:08) And it just took a long, it just takes a long time to figure it out.
(John at 00:58:12) It does. It does. And, you know, the power of the data and getting quality data going into kind of your sales process, and that's another, we've spent so much time making sure in that whole BANT phase, we're figuring out, you know, how many endpoints, what's the total addressable market, you know, what other products you're using. And then that all goes in where we can say, well, we're going to do this integration next because we know most of our market is using this piece of software. Right?
(John at 00:58:41) It makes sense. And then everything from BDRs, you know, the dialing and conversion rates. Like, I know exactly how many contacts now and how many calls a BDR can do in a day and what that's going to convert into. And then it's all kind of taking that funnel of all your lead sources and your scoring of your leads where that will convert into a real sales lead in the sales pipeline. But I wish I knew that when I started this.
(John at 00:59:07) I would have saved a lot of time, money, and heartache and frustration.
(Joel Beasley at 00:59:12) But now you have that skill forever, and it translates. So if you want to do another business, if you want to do another thing, like, as life goes on, you know, it's, it's like a monkey see, monkey do learner. Like, if I can see something happen correctly once, I can mimic it and I'm fine. And now that I've seen sales operate and have had to build that, I mean, I'm just so grateful. It's a weird transition because now what, now the thing I'm learning, and tell me if this resonates with you, I'm learning patience because I watch my cash flow.
(Joel Beasley at 00:59:42) I know it takes me three months to ramp a salesperson. I bring one on, I watch them ramp, I hire two more, I watch them ramp, I hire another one. And so it's just the patience of, like, going through that cycle and watching the revenue grow.
(John at 00:59:55) Yeah. It's kind of nice too to when you instrument it right, you can see what's working and what's not. Right? You know? Are we missing something in the messaging upfront that's, you know, are we not getting enough kind of what we call NCA, or New Customer Acquisition type leads coming in?
(John at 01:00:10) It's a whole new world. I'm pretty fascinated with it now that I understand. It's kind of, like, engineered, if that makes sense. Like, a lot, it got a lot easier to conceptualize for me. So, yeah.
(John at 01:00:21) Boy, if I, that would be all my advice there when starting a company is do, that's boring and, you know, mentally challenging, and, you know, you don't want to think through it. It's way more fun to think about your creative strategy, you know, for marketing or, you know, building the widget. But the other, if you don't have this other thing dialed, you know, your odds of success are low.
(Joel Beasley at 01:00:47) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.