Episode 456 ·

Ransomware Readiness, Defense, & Negotiations with Adam Bregenzer, CTO of GroupSense

Today we’re talking to Adam Bregenzer, CTO of GroupSense; and we discuss what it’s like negotiating with ransomware attackers to minimize the cost, how Groupsense operates as spies to catch bad guys on the darknet, and how businesses need to change the way they think about ransomware attacks.

All of this right here, right now, on the ModernCTO Podcast! 

To learn more about GroupSense, check them out at https://www.groupsense.io

About Adam Bregenzer:

Adam has deep experience creating a wide variety of software solutions for technology vendors and service providers. From designing and building operating systems to hacking tools, Adam will be the key to expanding GroupSense’s patented cyber recon technology for the coming years.

About GroupSense:

GroupSense is a digital risk protection services company that delivers customer-specific intelligence that dramatically improves enterprise cybersecurity and fraud-management operations.

Unlike generic cyber-intelligence vendors, GroupSense uses a combination of automated and human reconnaissance to create finished intelligence that maps to each customer's specific digital business footprint and risk profile.

This enables customers to immediately use GroupSense's intelligence to reduce enterprise risk, without requiring any additional processing or management by overstretched security and fraud-prevention teams.

GroupSense is based in Arlington, Va., with a growing customer base that includes large enterprises, state and municipal governments, law enforcement agencies and more.

Transcript

(Intro Narrator at 00:00:02) Hello, my friends. Today Joel is talking to Adam Bregenzer, CTO of GroupSense, and they discuss what it's like negotiating with ransomware attackers to minimize the cost, how GroupSense operates as spies to catch bad guys on the dark net, and how businesses need to change the way they think about ransomware attacks. All of this right here, right now on The Modern CTO Podcast.

(Joel Beasley at 00:00:33) This is the Modern CTO Podcast. I was curious, alright, so I was looking at your whole background and everything, and I saw that you moved from—you were in payments for a while, and then now you're in security. Did you learn a lot about security while in payments?

(Adam Bregenzer at 00:01:00) Yeah, actually. So there's a couple of things there that, at least I find interesting. One thing is I have been fortunate to work in a large number of industries. I haven't stuck with just one industry. I had my first job at 13 as an engineer, and I started my first startup right after high school at 19. So I feel like I've been doing it forever, but I've worked in payments. I am now, weirdly, for the first time working formally in security. But I've been a part of the hacking community since the nineties. I've been at DEF CON and ShmooCon and various other conferences. I was a part of a hacking collective in Atlanta called Chaos Theory. And I always preferred to not have it be a part of my day job. At least not in the—even here as the CTO, I still have a product engineering and design focus and not on the security of the business itself, for instance. It's all about, for me, building things and producing software products, things like that.

(Adam Bregenzer at 00:02:04) And so my entry here in security in that sort of formal sense—that's what the business is focused on—is new. But I've enjoyed, as I look for different opportunities, finding a way to take what I've learned about previous industries and other things and apply it in a different way. And I actually kind of connect that with technology as well. I've always had a—I just love programming languages. I just think it's so much fun. And I've always had a process where I will pick up a new language, play with it six months or a year, and then kind of continue to add that to my repertoire. I don't get to write 40 or 50 different languages in production on a regular basis, but I have collected and learned from a lot of different languages. And once you sort of cross a threshold in that as well, you start to realize you can take something from something that seems non-applicable and apply it often in a really unique way to something different. And so while I spent several years working at actually a global tobacco manufacturing company doing a focus on light manufacturing as the business, that taught me a lot. I spent many years working in a nationwide construction company, and that still has things that I learned from finance and an organization that I can apply even in this business. So did I learn a lot about security while I was at Venmo? Not necessarily, although I was really good friends with a lot of people on our security team. But a lot of the things that I learned about payments, about processing things at that scale, about the way in which things can't fail when you're handling someone's money—these things can't fail in a way that are different than when you're liking a picture on Facebook or whatever. They both have scale problems, but that promise that you're making to the user is very different.

(Adam Bregenzer at 00:04:00) And there are things there that are really applicable to security because similarly, we do things in the security industry where we can't fail.

(Joel Beasley at 00:04:09) Yeah, it's super—I mean, it's people's data and that's people's jobs. You go into things like hospitals and then it's people's lives.

(Adam Bregenzer at 00:04:16) Yeah, exactly. Yeah, and the whole business, especially now that ransomware is at play.

(Joel Beasley at 00:04:21) So I was just curious to know, what makes a good ransomware negotiator? Do you have to have a mohawk? Is that a prerequisite?

(Adam Bregenzer at 00:04:36) Is what a prerequisite?

(Joel Beasley at 00:04:37) Having a mohawk to be—

(Adam Bregenzer at 00:04:40) Well, you know, they don't see you, so I guess I can't say it is. That would be bad ops on our end if they got to see what we looked like. You know, I think the way I would want to answer that question has nothing to do with negotiating exactly. I mean, I think there are a lot of skills that are super important in terms of being effective at negotiating. And the goal with negotiating, particularly with ransomware, is you've gotten to a situation in which the business has decided that what it needs to do is to find a way to get back online and to use money to do that, which is unfortunate. But I think—in a second I'll get to that—that's where the real answer to your question comes from. So having good negotiating skills and being able to drive that price down is something that means that you're doing your best to minimize the impact, which is that at a certain point, bad guys get cash and they get to use that cash to do more bad things. What I think is probably most valuable about how we would think about engaging with people, and therefore as ransomware negotiators, is actually the conversations at the beginning, working with them, helping them understand what's happened and what they're doing outside of talking to us to remediate it, to handle the incident response, helping them think through from our experience with working with other clients what the real impact to their business is, if it really has to and is a situation in which they need to negotiate or if there's a way out of having the negotiation to begin with. And I think that if you can find those opportunities, that's the best.

(Adam Bregenzer at 00:06:19) Not in some sense because you're saving this company money, but mostly in the sense that you're not further incentivizing this marketplace.

(Joel Beasley at 00:06:28) And so people—you work for GroupSense currently. People call GroupSense when their data is ransomed?

(Adam Bregenzer at 00:06:35) Yeah. I mean, that's one situation in which we interact with businesses. We have other things that we do, which is to also work with them to help them prevent them from getting in the situation to begin with. And we even have services focused specifically on ransomware. But absolutely—it sort of started by accident. It sort of started with the CEO, with Curtis himself, doing some ransomware negotiations and then finding out that there are a lot of people who end up in this situation, and some of them are in this situation because they're small and they don't know what to do, and some of them because they're really large and it's a real problem. And what he realized is that there are companies who are taking advantage of this situation that aren't the ransomware threat actors, but are actually theoretically legitimate businesses.

(Adam Bregenzer at 00:07:21) And so when you get hit with ransomware, you might Google and you might find a business that says, "Well, we'll help solve that problem for you. Even though everyone says you can't, we've got software. We can decrypt your files for you." And you'll reach out to them thinking, "Oh, great, I'm not paying the—I'm not contributing to this problem. I'm not paying the people who stole my money, and someone can help me solve this problem."

(Adam Bregenzer at 00:07:43) Unfortunately, the reality is that it's generally, as far as we can tell, 100% untrue. And so part of this was also Curtis having a passion in that a lot of people are actually being taken advantage of in attempting to resolve the situation, and they're paying—in some cases paying companies that are claiming to not negotiate. But what they are doing is they are negotiating, and they are paying the ransomware—the threat actors. They are getting the ability to decrypt, the keys from those people, and then they're significantly marking that price up and then charging the business an even higher fee and pretending like none of that actually happened. And that struck a very passionate chord. And as a result of that, we started thinking about, okay, most of our core business is really focused on ways in which we can keep businesses from ending up in this situation, but there's also businesses who are in this situation. In a lot of cases, they're being taken advantage of as well in other ways.

(Joel Beasley at 00:08:39) So I want you to explain to me this thing that I hadn't thought about before. So people get attacked and then their files get encrypted, right, ransomware. And then instead of paying these bad actors, they instead go search in Google for tools or solutions that could decrypt their stuff, and they end up getting screwed twice?

(Adam Bregenzer at 00:09:01) Yeah. I mean, it's possible. So, you know, with everything, I always kind of want to leave small chance, have an open mind for some sort of maybe theoretical possibility. But generally speaking, and there's quite a bit of people who've done more research than I ever would ever be able to do, the methods that are used to encrypt people's files in ransomware attacks are well-founded and are not something that someone can just write a tool for and just decrypt. You need the password, the key, whatever they're using that only they have.

(Adam Bregenzer at 00:09:34) But you can find business—well, you can Google, you know, through Google and other places, you can find companies that will claim that that's not true. But 99% sure, virtually 100% sure, that's not true. And what they're doing is—so what will happen, and this is a great way to kind of tell that this is not going well, is you'll interact with them. What we found is the compromised company will call them up, interact with them, and they'll be like, "Yeah, yeah, sure, we can decrypt your files. We don't need to work with them at all. But send us the ransomware note and a couple of files so we can test." And that's the first warning sign because they want the ransomware note because that's how they figure out how to talk to the threat actors.

(Adam Bregenzer at 00:10:15) And they want a couple of files because a common part of the negotiation process is to say, "Prove to me that you really can fix this problem. Decrypt a couple of files for me." And they'll say, "Okay," generally, and they'll ask you to submit a few generally small files that aren't super critical so they're not putting too much at risk on their side. And that's why they want those two things. Because they may then call up the ransomware group. They'll reach out to Conti or whoever it is, and they'll pretend to be you, who's the victim. And they'll walk through the whole process. They'll get the negotiation down as low as they can get it, and then they'll take that number and they'll usually double it. And then they'll come back and they'll be like, "We can totally get you your files. You know, they wanted $4 million. We'll do it for half of that—or, I mean, we can do it for $500,000 because, you know, that's a deal for you."

(Adam Bregenzer at 00:11:04) They're actually going to pay Conti $250,000, eat the other $250,000, and they're just sitting in the middle between you.

(Joel Beasley at 00:11:11) So have you ever gotten to participate in a ransomware negotiation?

(Adam Bregenzer at 00:11:16) Yeah. We don't generally do it ourselves. Curtis or me or anyone else don't generally do it anymore. We have trained a team on how to do it, but I haven't been able to participate in one specifically. I've helped out in a lot of different ways, often in technical ways with many of them.

(Adam Bregenzer at 00:11:33) Sometimes we end up in situations where we've been able to not get all of the files, but sometimes things just don't go the way they intended to as well. So in a couple of rare cases, they actually ended up—some probably accidentally—uploading access to all of the files in an attempt to prove to us that they had done what they had done. So there are also some situations in which we've been lucky and been able to use some technical solutions to kind of help work around some of the problems.

(Joel Beasley at 00:12:04) They need a better training program at their scam university thing.

(Adam Bregenzer at 00:12:08) You know, another thing that's really interesting about ransomware—and we could even talk a little bit about the whole kill chain as well—but this is an industry. This is a business. And so when you're having a negotiation, you're talking with a customer support person and a customer support department from their perspective. And they have managers, and you can ask to speak to their manager. They have whole organizations, and they also work with other legal businesses—but other organizations that will provide them with the victims at various stages of being able to be taken advantage of. And so the whole thing is actually pretty complex and, because there's so much money involved, it has sort of self-organized into a whole supply chain.

(Joel Beasley at 00:12:59) That is crazy. I'm curious, alright, so I don't have a huge security background. I got into it when I was younger, and then I found out I could make money writing code on ScriptLance, so I just sort of—it was a slight hobby for a couple years. But I'm curious, if you've got these people that are hacking as white hat hackers, right, and that's their job, and let's say they're going to an office every day, they work at a security company, they're white hat hacking because they have clients that are paying them to do pen tests and things of that nature. How does that engineer actually know that that's a client and not just somebody that they're attacking?

(Adam Bregenzer at 00:13:41) Well, on the white hat hacking side, if you're being paid by an organization to penetrate that organization, then you're going to—I mean, there are, I guess, various sizes of white hat hacking groups, but oftentimes, especially now, they're pretty large organizations. And there's going to be a lot of paperwork. You're going to have a lot of evidence. And in fact, at least from what I understand from my friends who do a lot of this, there's usually also a lot of rules. As much as in many ways they want to really understand their vulnerability and their surface and what could happen, they also will be like, "Yeah, except you can't touch this and you can't do these things over here and, you know, don't do any of that. And, you know, if you get to this point, stop and call me." And so there's—it isn't so much necessarily the way it might sound where it's like, "Cool, we just got Bank of America on the line, and they said it's good. You know, just go do whatever you can do and let me know what you find." There's a lot of process and meetings happening in between with at least some subset of that organization. So as the individual doing the hacking, you'll have a lot of rules you'll have to follow. In addition, you'll have a lot of probably clarity about what you can and can't do and how legitimate this actually is.

(Joel Beasley at 00:14:59) So these organizations that are doing this, the employees—like the customer service rep or the engineers that are actually doing the attacks—they're fully aware—

(Adam Bregenzer at 00:15:07) No, you're talking—we're still talking about white hat hacking to defend companies. Are you talking about—

(Joel Beasley at 00:15:11) Sorry, yeah. The ransomware people, they're fully aware of what they're doing. Like, they know they work at a ransomware—

(Adam Bregenzer at 00:15:17) Side? Absolutely. Yeah.

(Joel Beasley at 00:15:19) Yeah, alright.

(Adam Bregenzer at 00:15:20) Yeah. And it's complicated because a lot of the people working throughout this whole industry, if you will, in some weird corners of the internet—I've run across people and organizations who've bragged about the lives they've been able to change with this money. You're talking about people who have very little opportunity in their physical world, and through being a part of this system that is ransomware, they might be able to illegally obtain access to a few different businesses and sell that for a few hundred dollars American. And that's, you know, potentially years of revenue compared to what they would have been able to do otherwise.

(Adam Bregenzer at 00:16:04) So that side of the ethics doesn't really, in many cases, necessarily seem to be part of the decision making. That being said, they're still being taken—if you want to look at it from a business perspective—taken advantage of because the Contis and the Revils and the large groups that are coordinating the final stages of the attacks, they're not bringing in $100 or $500. They're bringing in hundreds of thousands or even millions or more of dollars from these victims. They're keeping significant amounts of it for themselves, obviously. And so the way that it trickles down, like in many other ways, is also still terrible.

(Adam Bregenzer at 00:16:42) But yeah, I don't think there's situations really where the different parts of this system—that people are not aware that what they're doing is ultimately feeding into this ransomware supply chain. And kind of what I—or to call it, to connect it with, better perhaps, with a computer security term—just to like, Lockheed Martin coined the kill chain a little over ten years ago, I guess, at this point. There is also, at least, you know, what we've been working on documenting and describing, and others as well, but is what we call the ransomware kill chain.

(Adam Bregenzer at 00:17:20) And so there is also a series of steps. Right? A series of things that happen. And in many cases, those different steps and series of things that happen can happen through different organizations or individuals that feed ultimately into the final stage, which is exfiltration of the data and then installation of ransomware software and the demand.

(Joel Beasley at 00:17:44) It's amazing as you're talking and building this mental image of the ransomware economy. You have the lower level people who are fishing for opportunities, and then they're just selling them up for the paycheck. Right? And then those people are exploiting it farther, and that's fascinating that that happens. How do you manage like—one time I got a call from a business owner friend, and they were crying because literally somebody was doing a domain switch and the person didn't forward their emails correctly. You know, that type of thing happened. DNS issues happening. And then their entire company was offline and their website wasn't working. And they thought it was the end of the world. Right? And they knew me. They had a relationship with me, and they're like, "What do I do?" So I'm imagining when these companies, you know, you get a small business, maybe $5 million a year or something, you know, little family business, they get hit, they get ransomwared. I mean, they might think it's the end of the world. How do you prepare to answer those types of calls?

(Adam Bregenzer at 00:18:45) I mean, so we've talked a lot about ransomware, and this may be another way to say a little bit about—a lot of our core business, while it has a lot to do with ransomware, is not the negotiation specifically.

(Joel Beasley at 00:18:58) I'm sorry. I'm like presenting your whole company as this amazing rent—

(Adam Bregenzer at 00:19:03) Well, what the reason why I say that, though, isn't so much that, is that we do charge a fee for our services, but we charge a fixed fee. And we don't really exactly categorize it in the perspective of making money. I mean, we do try to make sure that the people that are doing the work, their salaries are covered and things like that, but we are not aggressively pursuing this as a large revenue potential for us because of that. We struggle with the ethics. We struggle with the reality of the fact that while we do have some large enterprises reaching out to us, we also have some small businesses and maybe just, you know, small like flower shops and small, like more medium-sized businesses or hospitals. And there's a whole ethical side of this as well of not only our ability to help them, but also, you know, again, like them making these payments is a decision that they're having to make about, you know, whether it's a hospital or the family business that they've had for twenty years just being gone. Just being gone. You know?

(Adam Bregenzer at 00:20:11) And the thing about ransomware is a lot of times we talk to CISOs or other folks, and they're thinking about this as another component of security. "I gotta have my antivirus, so I gotta have my ransomware protection. I gotta have my this and buy that." And we're like, you should really think about changing your perspective about that. Because what happens when you get hit by ransomware is someone walks into the office, and they can't turn their computer on. They can't open their email. If you're a small business, your QuickBooks just is gone, isn't there. You know, as if you had no accounting data anymore. No emails. Your phones don't work.

(Adam Bregenzer at 00:20:46) To steal a little bit—it's, you know, it's not going to be hard for me to make fun of Facebook. So, you know, not too long ago, they had their incident, which I believe was largely related to routing and some DNS issues, but their employees couldn't get into the building. Right? Because they had to electronify their locks and tied it into their employee access system. Well, Facebook probably won't get hit by ransomware, but should they be? Or should a company decide to be similarly modern? No one can even get into the door.

(Adam Bregenzer at 00:21:18) And so when you think about that from the context of how you normally think about computer security and protecting yourself, you'll have your incident response plan. You'll have your disaster recovery plan. Maybe you're really good and you worked with an outside firm and you've gone through and you've done tabletop exercises and simulations. And, you know, if this happens, this is how we're going to respond. And people are trying to, you know, hack into our firewall from the outside, like the Hackers movie. So we're going to, you know, look it on the red phone and blah, blah, blah. And then you play those scenarios out and you document them, and you go to bed thinking, "I have done better than most of my competition, most of my peers. I have done all of the things."

(Adam Bregenzer at 00:21:42) And what you don't realize is—not what you're probably not thinking about is—all of those plans are written in documents that are on a server somewhere. And if you get ransomwared, that server's encrypted. Those plans are encrypted. What you, how you are going to respond, is encrypted. Your ability to communicate with your employees is gone. And so this is not the same thing as someone came in and stole some data, or someone got a copy of our user database, or somebody is trying to DDoS or shut us down, or any of the other things within computer security that we normally think about. This connects into business continuity. This is a part of how your business operates in terms of thinking about how to prepare for that.

(Adam Bregenzer at 00:22:38) And so to get back a little bit to your original question, we have a lot of empathy and feelings for the people who call us. And generally in every single situation, they are at wit's end. And it is not something that they really ever planned for. Not just because it happened to them, but even for the folks, the companies we talked to that are planning for it, we have to remind them your plans probably aren't resilient to this either.

(Joel Beasley at 00:23:05) Yeah. I was at a friend's business, and I saw—you know, showing me around the office and everything—medical type company. And I saw that they, you know, QuickBooks, and I was like, "Oh, I use, you know, I'm familiar with QuickBooks Online." And they're like, "Oh, no. It runs locally. I just have to remote in if I ever want to access it." And I was like, "Are you serious? So, like, that's the only copy?" He said, "Yeah." I was like, "Is there a backup?" He goes, "Yeah, on that machine over there." I was like, "The one that's connected to the same network?" He's like, "Yeah." I was like, "Oh." I was like, "Hey. Do you check that box on your insurance form for ransomware?" He was like, "I think so." I'm like, "Okay. Good."

(Adam Bregenzer at 00:23:46) Yeah. Yeah. And, you know, that's another thing we've seen. We have one client that had, I think, three different backup systems and they had all been compromised as a part of the ransomware attack. Two of them had been deleted and one of them was encrypted. It's tough. It's complicated. But the other side of this to not dwell on too much—

(Joel Beasley at 00:24:09) Keep them positive.

(Adam Bregenzer at 00:24:09) This side of it is a lot of what we talk to people about is—and then, you know, again, we maybe connect a little bit with like the concept of the kill chain and things like that is—

(Joel Beasley at 00:24:19) Well, what is the kill chain? I'm so sorry to interrupt you, but you've said it like three times. I don't know what it is.

(Adam Bregenzer at 00:24:23) Yeah. So the idea of the kill chain in within computer security is just—I'll try to—I mean, we can rabbit hole, but for now I'll try to gloss over a little bit and just say that it is the idea that an attack, a major incident, a major security incident is not something that happens purely just in isolation, but is a series of steps that led to that point. And those steps are the chain, you know. And that you could interrupt and prevent this major problem from happening by stopping it somewhere earlier along in that process, in that chain. And the earlier you stop it, the easier—the less damage you've suffered—and the better off you are.

(Adam Bregenzer at 00:25:04) And so that's where Lockheed Martin sort of came up with this framework, this way of thinking about when something happens to you, you don't just focus on how do I stop the thing at the very end? You should think about the entire process and try to find ways to stop things earlier in the process so that they never get to that point. And also because if done well, they often can be simpler and maybe cheaper and more effective methods of trying to prevent the ultimate real problem. And so that's why to a certain degree you end up with situations where security training and antivirus and stuff like that are all a part of computer security, because all of these are attempts to try to stop some of the earlier parts of that process.

(Adam Bregenzer at 00:25:56) Again, to without trying to dive too deeply into a full description of the ransomware kill chain, some examples of how that's relevant for ransomware are—you can kind of think about this in the context of home security, but there is a lot of—probably most people have heard about the idea of breaches and maybe we even have some sort of password manager or something like that. And at this point, there's a good chance that it alerts you. "Your data has been found in a breach. This has been exposed. You should change this password," et cetera, whatever. Well, what happens with a lot of businesses and a lot of organizations, and even just in the personal space, is people reuse things. They reuse passwords, they reuse email addresses. And in many cases, you will find that someone at your company is using their company email and the same password that they use to log in to work, to log in to a blog about motorcycles or a forum about motorcycles or maybe something about knitting or home decorating or something like that.

(Adam Bregenzer at 00:26:26) That website does not have the same level of security concerns as your accounting software, but it happens to have the same username and password as your accounting software inside of its database, potentially. And so when that website gets hacked and those passwords get leaked, then there is now an active credential that can be used against your organization at that point. And so all that comes to say, working with employees to be mindful and to not create those kinds of situations, working with businesses to give them access to that data—that breach leaked credential data—and working with them to make sure that their passwords are well maintained is sort of like locking the doors on your house. You know? It's a relatively straightforward process. It's something that doesn't solve all of the problems, but it makes you a much less likely target than the other targets around you.

(Adam Bregenzer at 00:27:17) Sort of like home security, it's—you don't need to have a house that's as secure as Bill Gates' house, but it's really good to make sure that you have a pretty decent amount of security for your neighborhood or for wherever you are. And that is a lot of what we really do focus on with our clients on a day-to-day basis is providing them with information about those kinds of entry points earlier on in that kill chain where they can close those gaps.

(Adam Bregenzer at 00:28:02) Similarly, you can find—kind of like you're talking about your friend who had QuickBooks and they could log in remotely. Well, how are they logging in remotely? Because it could be that they had left their Windows machine with their RDP server available on the public Internet on an open port, which is not good. But it's not necessarily uncommon or a thing that doesn't happen. And then even in large organizations, you end up with pockets of the business where they become frustrated with their security department or whatever, and they use their credit card and they get some things going so they can solve their problems. They can do what their boss needs them to do. But in doing that, they have created security vulnerabilities and the larger organization actually doesn't have any visibility about it.

(Adam Bregenzer at 00:28:37) And that taps into something that a lot in the marketplace is being called attack surface management or external attack surface management, which is the idea that companies don't necessarily have the ability to know everything that's going on technologically inside of their organization. And so businesses can come in and say from the outside in, "Here's everything that's connected to your organization." And maybe some of these things you didn't know about, and then can help, again, close those doors. That's sort of like the security alarm system for your house.

(Joel Beasley at 00:29:32) Yeah. So kill chain, the way I interpreted it, it's the different steps along the attack. So, like, maybe phishing as a step. Right? They get their information. Maybe like lateral movement or like gaining permissions as a step. And so there's like a series of steps that can happen, and they refer to that entire series of steps as the kill chain?

(Adam Bregenzer at 00:29:52) Yep. Yep. That's cool. I think I got it. Cool.

(Joel Beasley at 00:29:52) So I saw on your website after, you know, basically telling everybody in the world like a hundred times that you guys are a ransomware negotiation company. You do have a ransomware hotline. So I—

(Adam Bregenzer at 00:30:09) We do. We do. It's on the homepage.

(Joel Beasley at 00:30:10) So—and it is a checkbox. I looked, by the way, your website is super simple. So it made for a really easy interview prep. I just scroll down to the bottom and it's like, "I'm interested in"—it's like one of those contact forms. And it's got everything you do. So I'm just going to like rapid fire go through these things so you can help me understand what they are. What is—like, what's the context for deep web monitoring? What are you doing there?

(Adam Bregenzer at 00:30:36) So a lot of different things. So one, absolutely, one component of that is that breach credential piece that I was talking about. So we are constantly—my favorite way to talk about deep web monitoring is that we essentially are spies on the Internet. We are out there interacting with threat actors, interacting with bad people, pretending to be bad people, gaining trust within those communities, and getting further and further access and entrée into those situations where people are talking about, planning, or communicating a variety of different levels of attacks, different pieces along the kill chain, et cetera, et cetera, as well as sharing files. And so one piece of it is collecting all of those files and then looking through that and looking for our client's data and letting them know, "Hey. Here's some credentials that recently appeared that are related to you," or "Here's some documents or other information."

(Adam Bregenzer at 00:31:31) Could be financial data or other things like that. Deep web monitoring also includes us looking through the conversations for larger enterprises. We could be looking for their products, the physical things that they make, or the virtual things that they create being targeted, being actively attacked, or just being talked about. Could be the business, their executives, their physical locations. There are a wide variety of—we call them indicators of concern, or IOCs is an acronym for that—but a wide variety of different things that we're looking for for each client.

(Adam Bregenzer at 00:32:04) That kind of varies based on the size of the organization. And in many cases with big organizations, we'll actually be doing custom investigations, looking for or trying to understand more about ways in which they could be targeted or things that they want to understand about the industry that they're in, things like that. Some more along the lines of research. We have other specialized things when it comes to banks. We can help them look for their credit cards or other things that are being shared and passed and sold.

(Adam Bregenzer at 00:32:31) There's also a lot of information about individuals that's being sold and traded and swapped around. And then even just machines. There are actual marketplaces where machines that have become compromised are just being sold in bulk without a lot of human attention. So it's a lot of automation that's being applied, but they don't know. You never know. It could be the workstation of someone in a critical part of your organization, and their workstation has been compromised and is being sold often for a very cheap price. And if we can find those, we can help identify them, take them out of the marketplaces before they become escalated up the kill chain and weaponized.

(Joel Beasley at 00:33:14) That is crazy. I think I should get—I'm going to call up Keeper Security, you know, the password manager—come in and be like, you guys should come sponsor the show when Adam talks, because I can't believe, you know, I've had a password manager since I found out they existed. So at least maybe a decade or easily a decade. And to find—it's always so weird, you know, because we're so anthropomorphic as humans. We always assume people are like us. So every time I find out somebody doesn't use a password manager, I'm like, how do you survive?

(Adam Bregenzer at 00:33:47) Yeah. What are you doing?

(Joel Beasley at 00:33:51) I have like 400 logins.

(Adam Bregenzer at 00:33:54) You know, people will always surprise you. I was going to identify which human being this was, but just in case this person does ever watch this, I don't want them to come and get mad at me. But I was with someone that I know very well and doesn't think about these things with the right level of detail. And we're in a very large big box store shopping, and they wanted my help doing something. And I was like, okay, well, I need you to log in. And they go, oh, well, my password is blah blah blah blah. You're going to hate me, but I use that for everything, even my bank. And I'm like, you just told everyone at this store your password and that it has access to your financial information.

(Joel Beasley at 00:34:40) Be like, what do you use for your usernames and where do you bank? Does this certain person own AirPods and live in your house?

(Adam Bregenzer at 00:34:49) Does not live in my house. Probably, I'm sure, owns AirPods, but that does—doesn't live in this house either. But yeah, I mean, a lot of times, and what's funny is that same person might take many things about security seriously, might even take many things about their work environment security very seriously. And then with the same mind, the same mind, turn around and still use their work account to log in to, oh, it's just TikTok or, you know, whatever. It's fine, right? And that's the thing that's hard. It's those lapses. Those lapses can have really serious consequences, and they are difficult to fight.

(Joel Beasley at 00:35:38) I had a good episode like a couple weeks ago with the CISO at TikTok.

(Adam Bregenzer at 00:35:43) Yeah, he's down the field. I saw that. I just watched part of that to try to learn a little bit more about the show. Yeah, it was really interesting.

(Joel Beasley at 00:35:52) Brand protection and dark web monitoring—those sound like they kind of go hand in hand, right?

(Adam Bregenzer at 00:35:57) Yeah. So brand protection is an interesting one because obviously a lot of what we just talked about with dark web monitoring applies to protecting your brand. But for us, it goes beyond that. And I'd mentioned earlier about attack surface monitoring. We feel like your brand is a part of your attack surface too. So understanding the whole scope of your technical organization and its infrastructure, understanding the DevOps platforms that you're using, the Jenkins servers that somebody set up, the GitLab repos that somebody got, the random new startup—whatever that somebody threw on their credit card and then dumped your corporate information onto. All of those tie into the brand for a lot of reasons. One, because in many cases, your brand is literally stamped on those documents or on those files. But also the leak of that information, the exposure of it, the security incidents that can arise from any of it—in many cases, some of the largest financial impacts can come to brand damage.

(Joel Beasley at 00:37:06) I want to talk a little bit about leadership and career progression. Just kind of—I didn't have any notes for this. You just kind of made me think about it. Where you're at in your career right now, did you imagine you would get to that point? Was it a dream to get to that point? Did it kind of happen?

(Adam Bregenzer at 00:37:23) I am not one of the kinds of—you know, I've met many people, and they'll talk to them and they'll be like, I'm going to be Bob someday. I'm going to be this three-letter acronym at specifically this company in ten years or whatever. I have not felt that way. I learned a long time ago that for me, what motivates me is passion and caring about the people that I work with and the impact that whatever I'm working with has. And those are the things that I connect with. So I have, in many cases, chosen paths that have led away from making significant amounts of money towards something I found more interesting. Or I have carried the CTO title multiple times in my life, especially when I was little and starting a new startup, and I could pick whatever title I wanted, right? And I've also walked away. I've gone back to being just an engineer multiple times and loved it. I enjoyed it. I've gone away from managing people, and then I've come back to it. I don't know really in five or ten years or twenty years what I'll think and feel about what I'm doing and what I want to do. I do know now that my experience has been that even when I walk away from people leadership, I get brought back to it. And so I've come to accept in many ways—as someone who really feels more introverted or more drained by the interaction with others—I find that working with people carries a cost. And on many times, I've tried to actually avoid that in my career, but I found that I've been able to develop skills that are somewhat unique. And so I sort of accept that that's a part of what I will do now. So did I always think that I would be a CTO? Not necessarily. Do I think I'll—know I'll be a CTO next? Maybe not. No, not necessarily. But I'm really enjoying doing that where I am now. And for now at least, I probably feel like I want to continue in this path.

(Adam Bregenzer at 00:39:33) One of the things that I did not actually ever think I would do and now really like doing is—you know, I used to love writing code above everything else. And when I was especially when I was still a teenager and in high school, I just wanted you to pay me to write stuff. I didn't want to talk to people. I didn't care what you did with what I wrote. I didn't really care. I just wanted it to be beautiful. I wanted to think about how amazing the data architecture I had created was, how unique the thing that I had written was, and my scope didn't really go beyond that. But one of the things that I learned is it's not very fulfilling, really. If people aren't using what you did or you don't even know if people are using what you did, it doesn't feel really great long term. And now I care a lot more—maybe not more, but I care a lot about product. I care a lot about the business, about what's being built and how it's being used. I care about who's using it. I especially loved that at Venmo. Who knows whether I have another opportunity to work with a set of software used by so many people for so many fundamental things. But that was very, very lovely to have that experience. And so now, do I see myself ever going back to being 100% focused purely on engineering and just the technology? Definitely not. Even if I decide I just want to be an engineer for a while again, I'll still get into trouble by asking questions. Who's using this? Can I see them? Can I talk to them? Can I just get some validation that what I built was enjoyed by someone? That's where I'm at now. And because of the way—like, when I started in the nineties, product management wasn't applied to technology. It wasn't even a thing. And so now that these things have become so formalized, the best way for me to have the most impact and to leverage both product and engineering together is in a role like this. Because otherwise—which is one of the things that was interesting, like, on the Venmo side, I was in the capital E engineering bucket. And I had a product manager. I had a lovely set of product managers that I enjoyed working with, but I could have coffee with them, and I build good relationships so that I could have some influence. But here, in these kinds of roles, I actually get to have more direct influence in both spaces, and that's something I love.

(Joel Beasley at 00:41:55) Yeah. When you're saying I don't know what I'll be doing in ten years, I'm like, I know what you'll be doing in ten years. Exactly what you want to be doing.

(Adam Bregenzer at 00:42:02) Hopefully, right? Yeah. As long as I can continue to be blessed, I certainly would be. Yeah, yeah.

(Joel Beasley at 00:42:06) You seem pretty—I like your strategy, by the way. It's a very valid strategy. And focusing on, you know, what you care about and what you enjoy doing. And turning down—most people, what they do is they accept the more money and then they get really depressed and then they go back. But you seem to have figured out that, like, hey, from the beginning, I'm just going to go after the thing I love. What is executive protection?

(Adam Bregenzer at 00:42:34) So that's—I'd mentioned it briefly a little bit ago, but that is applying everything that we've talked about to the business side of things, but to an individual. So sometimes that's just going to be the C-suite of a larger organization. Sometimes—and startups are very, very, I was going to say public, but I don't mean public stock. I just mean very public-facing companies. There will be even people that are not in their C-suite that get a lot of attention, maybe a lot of negative attention. And so we're looking for—again, it's a lot of—we're collecting their personal information from them, but looking for it being exposed. But also, we're looking at social media and other places for, not just dark web, but other kinds of threats and attacks and other areas of concern for them. Yeah.

(Joel Beasley at 00:43:23) Do you have any crazy attack stories that you're allowed to share? Like, change the names or anything?

(Adam Bregenzer at 00:43:30) I was just trying to think through while I was saying that if there is something I could think of that I could anonymize enough. Yeah. The hard part is it's hard to not have any of the ones I can think of—you would know at least the company really quickly. But realistically, it fortunately is usually not as necessarily dramatic as it is for the business side. It isn't so much that we are constantly warning threats against people's homes or physical attacks of violence and things like that. There's still a lot of sad, unfortunate things, but fortunately, most of it is digital. So I can certainly say that. More, I guess, relative to the business side of things, we have, in some cases, worked with Interpol and other organizations to actually get people arrested. And we're very excited and proud of the work that we do to try to protect our elections and other parts of the United States, local and state governments, from disinformation campaigns and other kinds of things. And some of that can get really interesting and intense.

(Joel Beasley at 00:44:45) Yeah. Yeah. I was just—you just made me think of something like, you know, all these local governments reporting all this data, and they're some of the easiest entities to compromise. I wonder if anybody manipulated, like, any third-party actors, like, manipulated COVID data inside of any of these municipalities or cities or anything.

(Adam Bregenzer at 00:45:04) Yeah. It's a good question. I don't know. We—I guess we can double check. And Bryce is the person who heads up all of our analysts. But—

(Joel Beasley at 00:45:12) I don't think any city is going to raise their hand and be like, it happened to us.

(Adam Bregenzer at 00:45:16) Well, but what we would be looking for is—you know, the thing is they're still humans. And so, like, if that happened, they're going to brag about it.

(Joel Beasley at 00:45:27) I guess so.

(Adam Bregenzer at 00:45:28) Or we're going to hear about it because that's how it goes. So and if they did, there's a pretty decent chance that at some point, they went to the digital bar and told all their friends. Yeah.

(Joel Beasley at 00:45:44) What are the top two, three, one-on-one things? Maybe we got some startups out there. I know a lot of startups listening to the show. Obviously, more mature organizations have larger resources. They got CISOs. They've got teams to handle this. But for the up-and-coming company, the person that's five, ten, 15 people that are trying to make the next big product or service out there starting up, what's one, two, three things that they could do just to, you know, have some basic security in place?

(Adam Bregenzer at 00:46:14) So one, the first one, the biggest one—like we talked about—not just have a password manager, but have good, thoughtful understanding of identity inside of your organization. And those are the nouns I would want to use. Because at this point, you probably shouldn't be trying to manage your own identity, especially if you're talking about a smaller organization. And look, that can be really simple. Even though it's not a startup, that can be Google Workspace. You know, Google's approach to your identity and logging you in and authenticating you is incredibly well done. You know, they have struck such a nice balance between not annoying you and asking you for your one-time password every ten minutes or whatever else is going on, but then also being able to say, yep, still really sure that that's you. And so figuring that out and using that for as much of everything as you can is a good step. We're still relatively small. We're under 40 people. And one of the changes that we've made in the last two years was exactly that—using a centralized identity system to authenticate into everything that we can get it to authenticate us into, all of the internal tools, all of the SaaS products, whatever we're using, we want to funnel it all through that. And then that way you've got your strong two-factor, you've got—or even more, you know, you have all of these layers of protection built in. If you're writing your own software, if you're a software startup, be thinking about identity inside of the software itself. You know, we didn't get to—a whole other topic of conversation is: you're the CTO of a startup. What is the ransomware kill chain and how are you a part of it? Right?

(Adam Bregenzer at 00:47:53) We have seen many situations in which a corporation has been attacked by ransomware and then maybe they were a supplier of software for, like, the oil and gas industry. And then all of a sudden, you see a lot of reports about oil and gas businesses getting hit by ransomware, or maybe it was a company that provided healthcare software solutions. And all of a sudden a lot of doctors' offices are getting hit by ransomware. There's no explicit connection, obviously. But there are multiple avenues in that kill chain.

(Adam Bregenzer at 00:48:24) And it's possible that, you know, one of the most unfortunate things is you could be a vector of attack for your clients if you're writing your own software and you become compromised, even if not through ransomware, through other means. So thinking about not just the impact to your business, but the impact that you could have to your clients.

(Joel Beasley at 00:48:43) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague that you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn, or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.