Episode 419 ·

Fighting Back Against Ransomware with Dan Schiappa, CPO at Sophos

Today we’re talking to Dan Schiappa, Chief Product Officer at Sophos. We discuss the rise of the ransomware economy and how we can fight back. Findings from Sophos’ 2022 Threat Report, and why it’s important to find the right balance between threat detection and prevention in your security strategy.

All of this, right here, right now, on the Modern CTO Podcast!

To learn more about Sophos, check them out at https://www.sophos.com/

About Dan Schiappa:

Dan Schiappa is chief product officer with Sophos. In this role, Dan is responsible for the overall strategy, product management, architecture, research and development, and product quality for the network security, enduser security, and Sophos Central groups, and drives next-gen innovation into the entire portfolio.

Dan joined Sophos as general manager of the Sophos Enduser Security Group in 2013 with responsibility for the company’s portfolio of enduser security offerings, including endpoint, mobile, server protection, and encryption and data protection products. In November 2016, Dan also took responsibility for the Network Security Group, which includes the Sophos portfolio of next-gen firewall, UTM, and Wi-Fi protection.

Prior to joining Sophos, Dan served as senior vice president and general manager of the Identity and Data Protection Group at RSA, the Security Division of EMC. At RSA, Dan managed a business unit with responsibility for authentication, identity management, anti-fraud, encryption and data center operations. Previously, he held several GM positions at Microsoft Corporation, including Windows security, Microsoft Passport/Live ID, and Mobile Services. Dan was the key business leader for Microsoft’s BitLocker and Rights Management services.

Prior to Microsoft, Dan was the CEO of Vingage Corporation, a video server provider acquired by L3 Mobilevision, and was an executive at PictureVision, an online digital imaging company acquired by Kodak. Dan also held senior technical roles at Informix Software and Oracle Corporation.

About Sophos:

Sophos is a worldwide leader in next-generation cybersecurity, protecting more than 500,000 organizations and millions of consumers in more than 150 countries from today’s most advanced cyberthreats.

Powered by threat intelligence, AI and machine learning from SophosLabs and SophosAI, Sophos delivers a broad portfolio of advanced products and services to secure users, networks and endpoints against ransomware, malware, exploits, phishing and the wide range of other cyberattacks.

Sophos provides a single integrated cloud-based management console, Sophos Central – the centerpiece of an adaptive cybersecurity ecosystem that features a centralized data lake that leverages a rich set of open APIs available to customers, partners, developers, and other cybersecurity vendors.

Sophos sells its products and services through reseller partners and managed service providers (MSPs) worldwide.

Transcript

(Joel Beasley at 00:00:03) Hello, my friends. Today, we're talking to Dan, the chief product officer at Sophos, and we discuss the rise of the ransomware economy and how we can fight back, findings from Sophos' 2022 threat report, and why it's important to find the right balance between threat detection and prevention in your security strategy. All of this right here, right now, on the Modern CTO Podcast.

(Dan at 00:00:34) Here we go.

(Joel Beasley at 00:00:35) This is the Modern CTO Podcast.

(Dan at 00:00:46) Yeah, so I think it started at a pretty early age. I was introduced to kind of a super microcomputer. It's about the size of a scientific calculator. It's called the Timex Sinclair, and it was one you plug your TV into for your monitor and a little tape deck in to save your work on a cassette tape. And what was interesting is the keyboard was laid out with the basic programming keywords kind of associated with the key. So, you know, G would be the go to, and T would be then, and I would be if. And it helped you learn to program in basic pretty quickly. And, you know, the first time I wrote my own program with that, it was like a whole new world was unleashed to me.

(Dan at 00:01:27) And so I quickly overpowered that thing and graduated to a Texas Instruments TI-99/4A. And then my father worked for IBM, and so when the IBM PC came out, you know, I got one right away. And that was mind blowing, you know, to have at that time, you know, a pretty powerful PC by the standards of the day and be able to just do incredible things with it. And, you know, I'm not a terribly artistic person, but programming became a way for me to be creative and for me to do things that others couldn't do. And it just corresponded well with my high school finally offering a computer science class. And, you know, I got involved in that. That was really exciting. And then, you know, carried it on through college. And, you know, the technology just changing so rapidly, and I love it. So I'm, you know, I'm a notorious early adopter, so just always kept going on with things.

(Dan at 00:02:17) And then my first job was with an engineering consulting firm who typically built power plants. So they were more kind of an industrial mechanical engineering company, and they wanted to build an IT practice to help, you know, kind of modernize IT infrastructure for these plants outside of, you know, mainframes and the like. And the short story is I ended up being the only person on the team that actually could code well. And so I had to write all the code for everything, you know. Lots of C code, C++, you know, R:BASE. And then this kind of new thing, Oracle, was starting to get pretty popular. And so one day they dropped a, you know, a six-inch book on my desk and said, you're now the Oracle DBA. And so I had to learn Oracle. And, of course, people know Oracle. There's a whole programming language associated with Oracle that comes around it. And so I learned that and started writing tons of code in that. And I ended up working on a project where Oracle consulting came in to help the project. And it turns out I was teaching the Oracle consultants more about Oracle than they were teaching us. So Oracle hired me.

(Dan at 00:03:27) And I got an opportunity to go work on, in their emerging technologies team, who at the time was focused on interactive television. And interactive television was really the precursor to the internet. And so we built this amazing kind of proof of concept off of a product called Macromedia Director, which is kind of like a multimedia development tool. And we just blew everyone away. So now all these telcos wanted us to go build interactive television. The problem was there was really no real technology behind the demo. So we inherited basically a media pump, we called it, from another company that the Oracle CEO Larry Ellison owned called nCube. And we had to build everything else. And so we had set-top boxes with no operating systems. So we had to write operating systems. We had to write publishing platforms and billing platforms and advertising platforms. And it was—as an engineer, it was Candyland. I mean, we just had a ball. We were just blazing new territory everywhere we went.

(Dan at 00:04:31) The only thing that could stop us was the internet. So as the internet started, you know, gaining in popularity, all the telcos were like, "No. Out with interactive television. In with the internet." And so a lot of that cool innovation kind of fell by the wayside. So I ended up making the leap into the startup world and did a couple startups. First one was very successful. The second one was my own company. I founded it and got Sony to fund it. Actually three different divisions of Sony, all who hated each other, which made my life very interesting as the CEO.

(Joel Beasley at 00:05:05) How does that work?

(Dan at 00:05:12) It was tough. You know, Sony Pictures, it was Sony Electronics, and it was Sony Music. And they were very competitive with one another. Obviously, the electronics team was really focused on making sure Sony Electronics products were highlighted as part of the solution, where music and pictures didn't care. They just wanted, you know, people to publish stuff to this platform. So in essence, we built kind of YouTube before there was YouTube. But then in the genius decision of the young, foolish CEO, we pivoted off of building YouTube and just started building the technology that at the time allowed you to publish all these different videos. And we started licensing it to Disney and, you know, Discovery Network and obviously Sony and the like. So things were going pretty well until, you know, if people recall in the kind of late nineties, early two thousands, the internet, you know, dot-com bubble burst. And even though we weren't really a dot-com, it just affected everybody. And so, you know, we started to have lots of struggles. We had to make a lot of layoffs. I actually had to lay off my mother-in-law, which most people would maybe relish at. But I love my mother-in-law, so it was tough. And it was just a tough time. I would call it the most expensive MBA you could ever get because I lost a lot of personal wealth I may have made from the previous one in this. But I wouldn't have traded it for the world. I learned so much about myself. I think I learned humility from this. Up until that point, I was always a very successful technical person, engineer, developer. And this was really the first adversity I've ever had in my career. And it was pretty heavy.

(Dan at 00:06:49) When you have to tell somebody they don't have a job anymore, that's heart wrenching. And I was a pretty young kid to have to do that. And the good news was that the company ended up selling and things worked out well. And then the next stage for me is I actually joined Microsoft. And so Microsoft wanted me to lead the digital imaging group—digital media group, excuse me. And I was like, "No. No. I'm done. I'm done with digital media." And so they kind of pointed me at the cyber space. And as an engineer, I knew about cyber. I didn't have a lot of experience in it. But man, I jumped at the opportunity for two reasons.

(Joel Beasley at 00:07:25) What year was that when you're—

(Dan at 00:07:26) In 2002. Yeah. It was 2002. So cyber at the time wasn't anything like it was today. It was, you know, mostly just some antivirus companies, you know, some pretty simplistic firewalls. And it was more thought of as attacks than it is today. And so convincing anybody to use cyber, you had to convince them of the threat before they were willing to even engage with you. Now, obviously, we don't have to teach that. But, you know, I had an opportunity to work for a great company like Microsoft in a very challenging technical space like cyber and had an opportunity to work in the Windows division, you know, building all the core security for Windows. And I had great opportunity to work with people like Bill Gates on a regular basis. So Bill, you know, security was his focus area at that time. And so I spent a lot of time with him. And then my last boss at Microsoft is actually Satya Nadella. He's the current CEO. So had a chance to work with some great people, and it was a great experience.

(Dan at 00:08:23) But, you know, Microsoft wanted to kind of move you around the company and get other experiences, and I wanted just to be in cyber. So I left the company, joined another kind of legendary cybersecurity company called RSA, and kind of worked there for a while, had some good experience there. And then Sophos lured me over. And, you know, Sophos was always known as a very, very well executing kind of high-quality team. I would say that their products were known at the time for being spectacularly average. They were really good. They were not, you know, ever kind of bleeding edge, but they weren't usually behind the market either. They were just right kind of—if this was Goldilocks, they were the porridge in the middle. Right? It's not too hot. It's not too cold. And part of what happened though was the cybersecurity ecosystem was starting to move at a pretty frenetic pace. And Sophos has been around since the late eighties. And they've shown an amazing ability to stay up with the times, stay relevant no matter what the security landscape looked like. But as the security landscape was starting to expeditiously speed up, we needed a new approach and kind of a new portfolio of next-generation security products. So that was my focus.

(Dan at 00:09:28) So, you know, Sophos is a pretty big company, about over 4,000 employees globally. We're really kind of focused in two key areas, endpoint security and network security. Our company is about fifty-fifty in the billings there. And that's underpinned, you know, that pretty broad portfolio is underpinned by a couple things that we think are somewhat unique to us. We have a platform that we call Sophos Central. And what we did is we kind of built this developer platform, so internal Sophos developers can build on it. They can leverage, you know, common microservices underneath, a whole bunch of common componentry. And we've also created APIs so third parties can participate in this ecosystem. And what we did further is we've started to build analytics capabilities and kind of threat-hunting capabilities on top of this. So we created what we call the Adaptive Cybersecurity Ecosystem. This is the ability, in essence, to have a security system that, similar to kind of Darwin's theory of evolution, can adapt to risk as necessary. And so provide a lot of AI on top of that. But, you know, the human operator, the security operations center operator still has a huge role in that. But our job is really to make them as efficient as possible. There's a glut of—or I should say a lack of—experienced bodies to fill the security practitioner openings that we have in the industry. So we want to try and provide as much efficiency as we can through AI so we can leverage the folks that we have, make them better, smarter, faster. And so we put a lot of focus on that. We call it the AI-driven SOC. We don't ever think you're going to eliminate the human from the SOC, but we just want to make them, you know, more powerful. It's kind of like our version of the Six Million Dollar Man. You know, better, faster, stronger.

(Joel Beasley at 00:11:27) So on the adaptability side of things, is that adaptability automated or driven by the human? And if it's—or both? And if it's automated, what's the data that's going into it? Is it like—

(Dan at 00:11:39) It's a great question. It's a great question. So it's actually both. You know, any data science, machine learning, AI has to learn from something. And so, you know, we've built some incredible capabilities to train on real-world data, live real-world data. And so when we started our journey with AI, it always helps to have a great team. And so we have one of the best data science leaders, our chief scientist, Josh Sachs, who's literally the founder of using AI in the cybersecurity medium. And we started with one AI model, and it was to block malicious portable executables. And now we have about 38 to 40 models running live and probably twice that many in development running silently, you know, in various stages of development. And one of the things that we're focused on is learning from what the human does and then automating that. Right? So we know if a certain circumstance, a human operator does steps A through D, next time we see a similar circumstance, let's do A through D for them so they can focus on, you know, E through L. You know? And so the more and more we learn from how the human operates, the more we can automate for them. And the smarter we can get about doing that. And, you know, the last thing you want to do is automate something that you shouldn't have automated or make a decision that you shouldn't have made. It actually makes life harder for the operator, so it's really important to do that.

(Dan at 00:12:42) So part of our business is we run a what we call the Managed Threat Response service. So it's a service we operate on behalf of customers. So we have our own kind of global security operator, security practitioner set of experts that we can run our models against. So we know exactly how they operate. So it's the human informing the artificial intelligence and then the artificial intelligence informing the human. So it's a great virtuous cycle.

(Joel Beasley at 00:13:25) That's really cool. So on the topic of AI, when I was doing research for this interview, I saw there's this whole—so there's sophos.com, and there's like a whole other side of the website that's ai.sophos.com. And there's, like, a ton of content published there, by the way. Like, you guys really put out a lot of stuff.

(Dan at 00:13:45) Yeah. Well, thank you. Yeah. So we obviously, in our history, we've always had a twenty-four-seven global threat intelligence apparatus. And that continues to be a massive part of who we are and what we do. And, you know, for example, we just published our 2022 threat landscape document. We do one of these a year, and it's just kind of the collection of all the great threat intelligence they've done over the year. And, of course, it's baked into every product. You know, every decision we make, there's a threat intelligence real-time kind of component to it. And we've been always open with what we do in threat intelligence. We don't try to hide it and, you know, make it just for us because the way we look at it is, you know, cybersecurity is—there's beyond the commercial aspect of it, there's kind of a justice aspect to it. We're trying to protect society. That's what we as an industry do. And so hiding that information doesn't really help solve that. So we took the same tack with AI. And moreso, you know, we're able to attract really high-quality data scientists because they get to publish their work. We don't create black box data science models that, you know, "Oh, you can't look at it. We're not going to tell you how it's done. It's super secret." We publish everything that we do. And it's all on this ai.sophos.com. And so, you know, all these different models I talked about, that's all published there. And we encourage our scientists to publish this information out to the public. One, because we think it's the right thing to do. But two, it does showcase, you know, the quality of our data science and the team that we have. And, you know, it's something we'll continue to focus on.

(Joel Beasley at 00:15:18) With that option to publish, has that helped you guys attract some data scientists that had traditionally been operating, like, in academia?

(Dan at 00:15:26) Yeah. Absolutely. I mean, obviously, from a from an academia perspective, publishing is one of the most critical elements of what you do. And so, yeah, we're able to have a great blend of people who kind of cut their chops, you know, in academia or went through getting a doctorate. And, you know, publishing was a key part of getting their doctorate to people who've, you know, lived and bred in the commercial side of things. And so we bring, you know, both of those things together. So, but everyone loves to show their work. Right? No, I, you know, back to the interactive television days.

(Dan at 00:15:59) I remember, you know, we were working to be able to pause and fast forward and rewind, you know, video on demand. And while we take that for granted every day, back in 1992, that was black magic. Right? Oh, yeah. It was crazy.

(Dan at 00:16:15) And I remember the first time I showed that to somebody, they went, "Oh, yeah, I can do it in my VCR." I just wanted to cry. I just was like, it was so much work. And so nobody wants to work so super hard on AI and just hide it in some secret compartment that nobody can look at. They want to be able to showcase that.

(Dan at 00:16:34) And so, you know, being able to publish it on ai.sophos.com is definitely something our scientists love.

(Joel Beasley at 00:16:40) So has that always been baked into the culture at Sophos of publishing and sharing information like that?

(Dan at 00:16:47) Yeah. I think if you were to ask our CEO, one of the things he'd like us to be known for globally is to be the most open company in the industry. So open from our platform perspective, open from what we publish, open from our threat intelligence. Just open. We just want—you know, we think the industry is better if you do that, and we want to certainly be a leader by doing that.

(Joel Beasley at 00:17:09) And I'm sure that probably seeps into your AI strategy too, which, like, observability is obviously a super hot topic today and really important for the future of developing AI and keeping the world safe as more of our lives are controlled by automated things in the background.

(Dan at 00:17:28) Yeah. I mean, I think the AI as it applies to cybersecurity started on the defensive side. Right? So it was, how can we use AI models to block bad things? And then the bad guys went, "Hey, how do I get around their AI?" So they started using AI. And so now we have this kind of arms race of defensive AI versus offensive AI. And, you know, that drives, unfortunately—necessity is the mother of invention. So that drives a lot of the rapid pace at which the cybersecurity market moves now.

(Dan at 00:18:01) And not only just in AI, but in everything. So never before have we been faced with such a skilled set of adversaries and well-funded adversaries. And that's one of the things, frankly, that came out in our threat report: the commercialization of hacking continues to grow and grow and grow.

(Joel Beasley at 00:18:20) Yeah. So tell me a little bit more about that threat report. What's happening in the industry?

(Dan at 00:18:25) Yeah. So if you kind of get a short history on hacking, you know, you go back to when it probably hit the mainstream the first time for headline news back in the days when there was the Sasser and Melissa and "I Love You" virus—all these things that were really kind of what they call worms. They would get into your environment and just kind of propagate and just cause mayhem. And they were mostly attacking vulnerabilities inside Microsoft Windows. And that's one of the reasons why Microsoft brought me in to help solve that.

(Dan at 00:18:58) But that was a very kind of destructive hacking. And then the next big thing was this hacktivism. You know, this famous hacker group called Anonymous that would do hacking more to make a political statement about things. And then there was always kind of nation-state espionage and all that stuff has been going on. And it'll always go on in some form or fashion.

(Dan at 00:19:20) But when the world really changed was the concept of ransomware. So I think it first came to everybody's top of mind when WannaCry hit and really kind of exploded across the globe. And, you know, it was the first time people woke up to a screen on their computer saying, "Hey, pay me money, or I'm not gonna give you your data back." And it was a great way for the hackers to monetize their efforts. And so a whole kind of new economy was formed in the hacker community.

(Dan at 00:19:51) And what we initially saw was pretty simple ransomware attacks. And then as the defense got better, they became a little more sophisticated. And then the brilliant idea of, "Hey, instead of me doing the hacking, I'm gonna enable others to do the hacking, and I'm gonna take money from them. And so I'll let them do the dirty work. I'll give them the tools to do it." We call that ransomware as a service. And that became pretty popular.

(Dan at 00:20:13) But it was still relatively unsophisticated ransom attacks. And then the next phase we saw was much more sophisticated ransom attacks. And so instead of going after $500 a PC or $100 a PC, they're gonna go after a company's backbone of their business and ask for $5 million in ransom.

(Dan at 00:20:41) And instead of just using some what we would call spray and pray—just throw it out there and hope something sticks—but a very kind of almost nation-state-like targeting of a company, spending lots and lots of time collecting reconnaissance, understanding where the data is, where the backups are, what vulnerabilities you can exploit, and kind of stealthily moving around the system. And then at the right time, launching the attack against the data. And so that became pretty popular. Then what started to happen is companies caught on to that and said, "Well, I'm gonna start to back up my data now. So if you actually ransom me, you're out. I'm just gonna go to my backups." So the second stage of that came in, and it's called extortionware, where they actually steal the data on top of encrypting the data. And then they threaten to leak your data if you don't pay. So the backup's not gonna prevent the extortion from happening.

(Dan at 00:21:31) And what we see now in the current threat report is kind of the combination of those two things coming together. So you're taking this very sophisticated nation-state-like tactics, and you're now applying that to the ransomware-as-a-service business model. And so now malintended people with semi-technical skills can leverage these really powerful advanced nation-state-like tools that can launch massive ransomware attacks. And some of the more recent ones that we've seen came through this model. And so now you're basically productizing what used to be a little more kind of specific attacks to a broader audience.

(Dan at 00:22:12) And so it's like the worst of both worlds. It's now kind of mass campaigns, but super tactical and very customizable ransomware technology. So, you know, until the industry is able to shut that whole industry down, they're making millions and millions and millions and millions and millions of dollars. It's just gonna get worse and worse and worse. So usually, you know, if you go back in history through threat reports, every couple years the threats change pretty radically. Ransomware has been the threat now for five-plus years, and it just keeps getting worse. And the great news is the defensive capabilities of Sophos and others have made it harder for them, but they are well-funded. They're very intelligent, and they find ways to still be impactful. And they usually take advantage of the less-prepared companies as well.

(Joel Beasley at 00:23:08) So that's the really scary stuff. What's the solution to that?

(Dan at 00:23:12) So I think, you know, things like the Adaptive Cybersecurity Ecosystem—that's precisely why we built this. Part of the challenge with security historically is it looks at one very specific area. The way I use the analogy is, if you're trying to provide physical security for a building and you had one guard looking at one door and one guard looking at the other door, those doors are gonna be protected. But what if somebody starts to go through the window and you just had people at the door? There's just two things you need to have. You need to have eyeballs everywhere.

(Dan at 00:23:43) That's really important. But you also need to have ways for those security guards to communicate with one another. And so now you have a coordinated effort of eyeballs everywhere, the ability to analyze all the data that's coming in, and then share information back to those security guards. Right? So now I could say, "Hey, security guard at door number one. We see someone trying to climb in the window around the corner. Go get them." And the security guard can now go look around the corner and grab the burglar by the feet, pull him out the window. Right? Historically, security didn't work that way.

(Dan at 00:24:12) We had a firewall, and the firewall is very focused on the network. You had endpoints, very focused on the endpoint. And so now with the Adaptive Cybersecurity Ecosystem, we can use all those different visibility points, pull all that information in. We can do analytics on it and automate some responses. But those we can't automate, we can surface now to somebody who's looking at this whole ecosystem and say, "Hey, you know, here's the information you need to look at and confirm if somebody's actually trying to climb through the window. Or maybe it's a legitimate employee, and they locked their keys in their office or something." You know? And so you have to be able to do those types of analytics. And that's the best way to defend this.

(Dan at 00:24:49) You're not gonna defend it from just securing an endpoint or just looking at the network. It's really this holistic view.

(Joel Beasley at 00:24:56) So you can get the tech side of things as secure as possible and, like, impossible for a bad actor to break in without any information that they need. But eventually the weak point becomes the people, right, that could be phished or social-engineered to get them to give up their passwords or something. How can we protect against that?

(Dan at 00:25:22) Yeah. So it's an interesting question. And there's two elements to that. There's the people side where you mentioned, you know, people getting spoofed and phished for their credentials. And then there's the people side where an IT administrator opens up remote desktop protocol to the internet and doesn't know they did that. You just basically opened a door that you don't know anybody should be watching. And so there's those human elements to it. You know, on the phishing side, there's ability to train your employees. That's really, really important. I know, for example, I've done that with my own family, and now they won't open anything I send them because, you know, I'll put a link, and, "Look at this cool story." "Oh, is this a phishing email?" And they'll send it right back to me. Part of me is really proud.

(Dan at 00:26:11) But, you know, that's what you have to do. You have to train your employee base to not make those mistakes. And look, this is part of where the AI is coming into play for the attackers—they're understanding how to do these campaigns much better by using AI. And so you're always gonna—you can have an employee base of 10,000, and it only takes one to let them in the door. Right? And once they get in the door, they find vulnerabilities they can exploit, and all of a sudden, game on. So to think you're gonna keep somebody out is impossible.

(Dan at 00:26:36) So the best way to handle that situation is presume there's gonna be human error. Presume someone's gonna lose their credentials or leave an RDP port open, and then be prepared to deal with that and to deal with it as quickly as possible. And that's where this kind of security practitioner leveraging these great tools comes into play. They can see things happening, and they can stop it before it gets too bad. And so there's really two elements to security.

(Dan at 00:27:03) There's prevention, and then there's detection. And the detection is there because the prevention will never be perfect. Now what's interesting about our industry is the pendulum always swings from one to the other, and we really need to let that pendulum just hang in the middle. Because the reality is you always want to do everything you possibly can to prevent something from happening. Right?

(Dan at 00:27:24) It's the reason people put home alarm systems on their houses. And, you know, some cases they put security cameras there. And I want to stop the crook from getting in. But if the crook happens to get in, I would love to have a picture of them so we can go find them and get my stuff back. What I don't want to do is just have the picture of them, and then they're out the door with one of my kids.

(Dan at 00:27:48) Right? I want the alarm to go off when they kick the door in as well. So you have to have both. And what we do too often in the industry is go, "Oh, well, you can't, you know, you'll never be perfect, so just focus on detection." No.

(Dan at 00:28:00) You gotta do both. Because as I mentioned before, most companies don't have the number of staff they need for their security operations. And the more they're chasing things that you could have blocked, you're just taking more time away from them. So block everything you can, but know you can't be perfect and make sure they can detect it. So that's the way you deal with it. You know you're not going to stop somebody from falling for a phishing email.

(Dan at 00:28:21) You hope you're 99.9% there. But there's that 0.1% you just have to make sure you have capabilities to detect.

(Joel Beasley at 00:28:29) Yeah. That actually reminds me of recently, I've done a couple interviews with a company called Axio. Have you heard of them? They're in the security space. Yeah.

(Joel Beasley at 00:28:37) What they're doing seems really cool in terms of helping companies hit that balance where they give you the tools to view cyber risk management as a financial thing and decide how much cyber insurance to get or how much money to invest in protection in different areas and assess your weaknesses. Yeah. All you're saying there just really made me think of that. Also, their chief product officer, Rich, I think, was telling me about, for anti-phishing at their company, they've had—they challenge each other of, like, "Hey. See if you can phish me by the end of the week."

(Joel Beasley at 00:29:20) And, um, and, like, have kind of a competitive landscape there of trying to phish each other, and that seems like a really fun way to do that.

(Dan at 00:29:28) It is. We actually have a product. It's called Phish Threat, and that's what we do. We allow companies to create fake phishing campaigns and use it as a way to train their employees. So if their employees fall for it, they can train them on how they fell for it and what bad things could have happened if that was a real phishing attack.

(Dan at 00:29:46) So we sell the daylights out of it because it is an effective tool for training people. But again, you know, you're never perfect. Right? So you do have to prepare for the worst. And the other thing that we've seen too that's becoming a huge trend is because security is so—you're moving so fast and it's very sophisticated—many companies don't have their own security operation centers. They don't have security practitioners. They may have a couple security people, maybe a handful of IT people, but they don't have that deep expertise. And so we have a service we call Managed Threat Response. We do it for them.

(Dan at 00:30:18) So we manage their security threats, and we respond to the security threats for them. And that's a big part of the industry now that's growing. It's probably the fastest part of our business that's growing because it's just so overwhelming for so many companies to deal with this. And what they're finding through these kind of supply chain attacks or—everyone's at risk now. You know, in the old days, if you were a small company, it's like, "I'm just a plumbing supply company. Who would want to hack me?" Ransomware is why they want to hack you. They can make money off of you. So everyone's at risk today.

(Dan at 00:30:42) And yet, you know, that plumbing supply company may not have the budget or the sophisticated IT staff to run a security operations center, so they kind of outsource it. And that also helps. And those services like ours will help kind of establish where you are with your security threat landscape and your security risk and things you need to do as well. And then the last piece of that is the cyber insurance industry is mainstream now. You know, a few years ago it was, "Oh, you know, that's kind of a crazy idea."

(Dan at 00:31:21) Now it's mainstream. And the good news with that, just as the car insurance industry drives safety standards and pushes for this, they're doing the same thing. So they're pushing for companies to take the right steps, to do the right things to lower their insurance premiums or to get insurance at all. And that's actually driving really good behavior for the industry. And so I think that'll continue to help shape behavior as well.

(Joel Beasley at 00:31:47) Yeah. That's really—I hadn't thought about it like that, how just like the existence and mainstream of cyber insurance just improves the overall behavior because everyone's incentivized to have better cyber hygiene.

(Dan at 00:32:03) Well, look. This is an area where capitalism works. Right? The insurance companies don't want to have to pay out claims. And so they're encouraged to encourage their clients to do the right things from a security perspective. And then everybody wins. Right? When antilock brakes comes out, everybody wins, including the insurance companies, because there's less accidents. But, you know, that's kind of what we're seeing now in the industry. And that's also helping to drive the rise of security services because cyber insurance companies are going, "Hey, if you don't have the capabilities to do it yourself, then leverage something like Sophos MTR to do it for you."

(Joel Beasley at 00:32:38) Nice. So we've talked a lot about ransomware today. And I know you think a lot about the future of the industry. And I'm curious, what do you think comes after ransomware? Like, the next threat on the horizon?

(Dan at 00:32:52) Yeah. It's—to be honest with you, it's hard for me to see past it in the sense because there's so many things that have to happen before that's a viable financial path.

(Joel Beasley at 00:33:03) Right.

(Dan at 00:33:03) And a lot of it's not technology. Right? I think if there's one thing that we can learn from cyber defenses, it's you're never going to have the problem solved. It's just not possible. I remember Bill Gates used to get mad at me every time he said, "When am I going to have an impenetrable Windows?" And my answer would be "Never." And he would say, "No. Come on. There has to be a way." I said, "All right. Here's a way. Unplug the keyboard, the mouse, the network cable. You know, do all that, and you're secure. Right?" "Yeah. But I can't type on it exactly." Right? You know? And so I mean, we're going to live in that world. And when I kind of look forward, the things outside of the technologies that need to happen to stop the ransomware industry is the ability to enforce the law in countries where most of it comes from and it's not enforced. There's kind of this unwritten rule: as long as you don't attack our country and you attack others, we'll kind of turn a blind eye to it. So things like that have to change. Paying the ransom at all has to change. Right? It's the old "We don't negotiate with terrorists" because the theory is, if I pay you, you're just going to kidnap somebody else, and I'll have to keep paying you until we do that. If we keep paying the ransom, they're just going to keep doing it. And so there's so many things that have to happen outside of a technical thing. And there's some good movement now and some of the stuff that came out of the Biden administration on kind of security—cybersecurity standards that CISA's driving—some really good progress there. Some of the standards that are coming out are really good. It's still not going to be enough. And, you know, these bad guys are very driven by the monetary benefits. Many of them, the reason they have nation-state skills is many of them are nation-state actors during the day and criminals at night. And so that's going to continue to flourish. And so it's hard for me, to be honest with you, to see that slowing down anytime soon. And, you know, as a defensive company, I want to make it so darn difficult for them that even the money they're making is just not worth it anymore. That's the best I can do, but so much has to happen around the world to do that. And then, of course, you know, one thing that'll never stop is industrial espionage and nation-state spying activities. And that's going to carry on in some form or fashion. It's been carrying on since the founding of our nation. It'll go on for many, many years in the future, regardless of what technology is available to them.

(Joel Beasley at 00:35:30) Yeah. Definitely. But when you're talking about not paying the ransomware, that's such a hard thing because I mean, businesses pay it because it's a sound business decision to pay it. Right?

(Dan at 00:35:43) Well, it seems like it would be. Right? And I think, you know, one of the reasons why attackers, when they have a human element associated to them, are so successful is they create a panic and a sense of urgency. Right? So we see a lot of very simple cybercrime going on where—and some of it's not even cybercrime. It'll be someone will call, you know, somebody in an accounting department at a company, and they've done a bunch of LinkedIn research, for example, and know who the CFO is and the CEO is and their boss. And they'll say, "Hey. You know, the CFO so-and-so said you have to wire this money right away. You know, they're going to turn off our this service, which is important for this part of the business. And now here's the wire information. Oh, you know, and CFO told me to tell you to do it right now." And they're like, "Oh, or you're going to lose your job. Oh, God. I better do this. I'm going to lose my job." Right? And they just create this panic and this sense of urgency. And so when a company like Colonial Pipeline, for example, gets ransomed, man, there's a big sense of urgency there when the whole East Coast is shut down from a fuel transportation perspective. But what we've seen through some of our research is, you know, 80% of the costs associated with not paying the ransom are still incurred when you pay the ransom. So I may have paid, you know, millions and millions of dollars of ransom. I'm still going to incur 80% of the same costs that I would have incurred if I didn't pay the ransom. And so you're not really getting off free. And there's no kind of guarantee that they just won't come back again, that there's some stealthy piece in their environment that's still there that, you know—you can't look, "Oh, I paid the ransom. They're going to go away. I'm good." No, they're not. You know, they're going to keep coming back. And so all those steps you would have had to take to get them out if you didn't pay the ransom, you still have to take. And there's still systems you have to rebuild. The decryption keys didn't work or, you know, whatever. And they don't care. Right? They got their money. And so to some degree, it's not a good business decision to do it. This is where the extortion work comes in, though. Right? So each company's different. If there's things you don't want the world to know about you, then yeah, maybe you're kind of stuck paying it. But until we don't pay it, it's going to be hard for it to go away. Because again, it's going to be difficult to be perfect in the defense against it. And so until they can stop monetizing it, they'll just keep coming.

(Joel Beasley at 00:37:57) Yeah. That makes sense with that holistic view of the cost of rebuilding and also the risk that you might not rebuild correctly and they're still in there somewhere.

(Dan at 00:38:07) Yeah. It's that, you know, the panic of ending the downtime. You know, we've got to get the pipeline running. You still got to rebuild all those systems mostly. Right? And you're still going to have problems even after you pay the ransom.

(Joel Beasley at 00:38:20) Well, before we wrap up, is it cool if I ask you a couple leadership questions?

(Dan at 00:38:24) Sure. Absolutely. Love to.

(Joel Beasley at 00:38:25) Cool. So recently I had on this company called Allstream, which they provide like business communication services. And I actually got to talk to their CEO a lot about like fiber tech and low-latency communication tech. And it was a really fun episode. But another thing that he was talking about was how important it is to bring up leaders in the organization at every level and really encourage people to set a solid example for the people around them. And I'm curious, how do you bring up the next generation of leaders at your company?

(Dan at 00:38:59) Yeah. It's a great question. One of the things that I always tell people I mentor, whether it's, you know, going back to UCF and talking to engineering students or it's people inside the company, is you don't have to be in a leadership role to be a leader. And I learned this firsthand. So when I was doing the cool stuff I mentioned at Oracle, I was leading a lot of things even though I wasn't the leader of the area I was doing, just because I was, you know, thinking out of the box. I was collaborating with people. I was solving problems and doing it as a team. And, you know, that really helped my leadership—you know, my leadership skills kind of shine in that regard. So I always tell people, you don't have to be a manager or a director or VP to be a leader. So you can lead by gathering folks in the organization to solve a problem, or even just solving it yourself through initiative. Lead by example. But it's also great for a company to have a formal program to identify leaders and grow them, and grow them giving them exposure to the elements that help them grow as a leader, getting exposure to mentors that can teach them from the mistakes. And I mentioned I learned more from that failed company than anything. Hey. I tell a lot of people about what I've learned there, and hopefully they won't make the same mistakes I made. And then there's another thing that's okay to learn too. It's not everybody is a leader. And that's okay. It's great to identify the leaders, grow them, or have people self-identify and begin into these programs. But in the technical space in particular, there's a lot of people—they just love to code, or they just want to do their job, or they just—they don't want to manage people or lead it or do anything. And that's fine. And what's great is find tracks for them because they can also provide different types of leadership per se, maybe outside of what we consider leadership in the mainstream. But they just want to advance and work on cooler and cooler things and give them those opportunities. But in Sophos, for example, we have a really good program where we can identify people pretty early in their careers and make sure they have the right exposure, the right tools, the right training to grow into leaders. And I think one of the most important aspects of that is mentorship.

(Joel Beasley at 00:41:09) So I have kind of two questions. What are some of the attributes that you look for that tell you—that help you identify leaders? And then also, how is feedback built into the system to, like, let someone know, like, "Hey, we've identified you that, like, you have really solid leadership skills, and we want to help you develop those. Do you want that?" You know?

(Dan at 00:41:35) Yeah. So on the first part, everyone's got a different opinion, and I won't go through all of the character traits. There's a couple that I found to be very, very important in a leader. One is I think a leader needs to inspire people to do things that they don't necessarily think they may have been able to do. Right? So you hear about it a lot in sports. Tom Brady is a great leader because he makes every team he's on better than they would be without him. Not just because of his play, but all the players just rally and become better versions of themselves. And the same happens in any company. A good leader will inspire people to want to do something, not do something because they're told to do something. And a key character trait in that is humility. Right? And you mentioned feedback. The ability to be self-reflective and to take feedback. And that's part of being humble. It's tough as any human being to hear something negative about themselves. But the leader who really kind of takes that feedback and does—and actions on it to make themselves better, that's a great leader. And you don't have to be a leader to have that character trait. But I think a leader has to have that character trait. As I mentioned before, the reason why I learned so much about that failed company was I didn't really have a lot of humility up to that point because I never had adversity. Like, everything I did turned to gold. And, you know, you think you learn a lot from your success, but you learn more about yourself from failure. And so when you get feedback—and it's always good to hear positive feedback too. So it's great to get both. But when you hear that—like, when I hear negative feedback or "You could have done this better," it's just like I can't sleep at night until I know like I have a plan to address that feedback and get better. And when I can take that feedback from my own team and I respond to it, whether it's about how I run the organization, or how I behave personally, or how I—you know, I can make another team do something different, and it gets done, it inspires confidence in your leadership ability. And so at any point, whether you're that individual contributor showing leadership on a project or you're a CEO, the ability to be self-reflective, take feedback, and be humble about it, I think is the most important trait of a good leader.

(Joel Beasley at 00:43:40) Do you have time for a couple more questions still?

(Dan at 00:43:43) Sure. Yeah.

(Joel Beasley at 00:43:43) So you mentioned a lot about learning from failure there. What's your process of managing failure within Sophos with your employees? Like, how do you encourage the learning?

(Dan at 00:43:54) Yeah. So it's interesting. And I think each company has a different mentality for—and also different stages of companies can be a little more cavalier about what I'm about to say. So I don't want to make it so blanket uniform that it sounds naive. But in my opinion, if you don't fail, occasionally you're not pushing hard enough. Right? So failure is part of the process. Right? Any part of any scientific process is failure. And if you're not pushing, you have to fail every once in a while. And again, you've got to learn from the failure. I don't want to keep repeating the same failure over and over again. But I do want to push hard, fail, learn, adapt, push hard again. And I wrote a blog on—I'm a New York Yankees fan. So when Yogi Berra passed, I wrote a blog on taking all his famous sayings and applying them to business. And one of his famous sayings is "If there's a fork in the road, take it." And I thought that was a brilliant kind of business saying because a lot of people get to that fork in the road and just start analyzing. "Should I go that direction? Should I go that direction? I'm going to go that direction. I'm going to go here. I go that direction." And then they over-analyze things. In some degree, just pick a path. You know? Turns out it's the wrong path, come back to the fork, and then go down the other path. But just standing there at the fork wondering which path I should take—you know, in cyber, it's really important because we move too fast to do too much analysis and analysis paralysis. And so to me, it's all about driving as fast as you can, doing everything with strong quality. Obviously, in security, you have to be high quality. But be willing to make mistakes. Be willing to have some minor failures, and learn from it, and move on. I know obviously no one likes catastrophic failures. Right? You don't want to be a guy building a bridge. "Hey. Let's try this thing, and it doesn't—push harder. Build another bridge." No. You don't—I mean, that's what I'm saying. I don't want to make it naive to sound like it's applicable everywhere. But in my world, push hard. It's okay to fail. We'll learn from it. We'll move on, and just keep pushing hard. It's like, you know, get up, dust yourself off, and keep running.

(Joel Beasley at 00:45:59) Yeah, I really like that fork in the road quote because I think that's really applicable, especially to the engineer's mind. Engineers in particular are used to being able to figure out how something is gonna go down and picking the right path first.

(Dan at 00:46:16) Yeah. And what's great is with today's development tools and the world we live in, the feedback loop you get from that is pretty immediate. Right? So you'll know pretty quickly if you've made a mistake. And ideally, you can do it in an environment that's maybe not a production environment or whatever, so the impact's a little bit low.

(Dan at 00:46:32) But I'm also talking strategy. It's fine. We went down a path at Sophos where we built this—I think it's the most advanced encryption product to ever see light in the world. And it just wasn't right for the market at the time.

(Dan at 00:46:46) And so it wasn't as successful as we thought. Hey, we learned a lot. I'm not ashamed. I think the tech we built is still the best thing that the encryption world's ever seen. It just wasn't right for the market at the time.

(Dan at 00:46:57) So we learned. We kind of adjusted and took a different path. And that's fine. And, you know, for the team, the team was like, "Oh, that was a failure." No, no, it wasn't a failure. You know, I think it was Thomas Edison that said—we just learned how to not build a light bulb. We just learned that understanding the timing of the market is as important as building cool tech. And we'll learn the next time, and we won't make that same mistake.

(Joel Beasley at 00:47:18) Yep. Absolutely. So what was one of the biggest challenges that you came up against the first time you formally went from individual contributor to manager?

(Dan at 00:47:29) Yeah. I think the first challenge every new manager has is giving somebody a difficult message. Right? At our heart, we're all nice people. As I mentioned, the hardest thing to do is telling somebody they don't have a job anymore. The hardest thing to do is telling somebody they're not doing a good job. And particularly if they're—if you're friends with them. Right? In a lot of cases, you know, that new manager may have been on the team, and they're friends with people, and now they're the manager. And sometimes it's very hard for them to sit down with somebody that they like, that they've been friends with or whatever, and say, "Hey, you're not doing a good job. Here's the things I need to see you do better at, or we're going to have to make a change." It's a really, really hard message. And there's plenty of other things that are challenging to new managers as well. It's kind of starting to pull away from doing everything yourself and letting others do it—kind of that. But I think that's the hardest part.

(Dan at 00:48:17) When I see young managers, that's the part that they struggle the most with. Yeah, they'll struggle a little bit again with, you know, delegation and letting other people do stuff they used to do themselves. But they kind of eventually get there. I've seen people carry through many layers of their careers the difficult task of telling someone they're not doing well. Because it is hard. I mean, even today, I hate doing it, particularly if it's a really nice person and, you know, they're trying really hard. But it's still—that's part of your job, you know, is to do that, and it's tough.

(Joel Beasley at 00:48:49) Yeah, definitely. I mean, I've definitely run into that before where I had an employee that wasn't doing so hot and I really just couldn't bring myself to give that feedback. And I just got lucky that the situation worked itself out, and they got a better job somewhere else. I'm like, "Hey, I'm leaving." I was like, "Oh, man. Sorry to see you go."

(Dan at 00:49:16) I was saying that this hearkens back to the humility part. Right? It's the ability to take feedback. It's also to give feedback. Right? So I kind of have an unwritten rule—nobody in my organization should ever be surprised if they got fired, right, for lack of performance. Right? So they should know they've had a performance issue. You should give them feedback. You should give them all the benefit to try and improve on that feedback. And give them coaching and mentoring and whatever it takes. But if they don't improve, they should know they haven't improved. And then when you finally sit down and say, "Look, it's not working out," they should go, "Yeah, I knew this was coming." Right?

(Dan at 00:49:52) As disappointing as it may be to them, they knew it was coming. That's leadership as well. You know, people are going to have struggles in their careers. And there's some people that I worked with that really struggled. But because of the feedback, and the help, and the coaching, they became great employees. Because maybe they didn't know they were making those mistakes. So they didn't understand the impact of those mistakes. And so I think it's really important to give that feedback. And that's why it's difficult when you're a new manager. People are afraid to give it. Because the way I look at it is you're actually helping that employee. You're not hurting them. You're helping them so they know. They can't fix it if they don't know to fix it. Right? And that's the message I give my people on my team too.

(Dan at 00:50:29) It's like, if you have feedback for me, you know, I don't care if you're two weeks out of college and you look at me and go, "Oh, God. I can't tell a chief product officer they're being stupid about this." Yes, you can. Because I don't want to make a mistake anymore, and you don't want me to make a mistake. So if I don't hear it, I can't fix it. And the same goes back down to the employee as well.

(Joel Beasley at 00:50:47) Yeah. And I think that also speaks to something I've heard a lot of brilliant leaders talk about, which is trying to eliminate defensiveness in their organization and how damaging defensiveness can be.

(Dan at 00:50:59) Absolutely. That's the humility part. Right? That's being open-minded. And human nature is when somebody tells you something negative, human nature is to get defensive. That's just our nature. Right? And so you gotta kind of stop that nature from happening, or at least recognize that you're doing it and then be open-minded. I've seen several people that I've given negative feedback to, and they get very upset and very angry. And then the next day, they're like, "You know what? I thought about it. You're right. You know, I did realize." And so they just got caught up in the moment. I give them, you know, a little bit of time to kind of take it in. I don't, you know, get in a confrontation with them over it. And then they come back and go, "You know, I think you're right. I recognize that I am doing that." And that's the light bulb moment when you go, "Hey, this person's great." But if they never can admit to a mistake or a fault, then you know they're probably not the right fit because they're not going to grow as a person.

(Dan at 00:51:49) Right? We're all human. We all make mistakes. We all have faults. And until you can recognize them and work on them, you just can't grow as a person. And nobody's perfect. So I always tell my kids—we're all big sports fans—Babe Ruth struck out a lot. You know, maybe the greatest player of all time, but he failed a lot too. And, you know, you take the good with the bad, and you just gotta keep working.

(Joel Beasley at 00:52:14) Absolutely. Well, before we wrap up, is there anything that we didn't get to touch on that we wanna make sure we get out to the world today?

(Dan at 00:52:21) Yeah. I mean, I would just say I didn't have a lot of time to go through kind of all the awesomeness in our 2022 threat report. Give it a good read. It's, again, on sophos.com. Go and read it. It's really enlightening, tremendous work done by our threat intelligence team. And then I think you did a promo for ai.sophos.com. Follow that too. If you're interested in data science, you're not even a cyber person, there's just so much great knowledge that's shared through ai.sophos.com. We're very proud to share it with the industry. So I would say definitely check out those two things. And obviously, if you haven't heard of Sophos or don't know a lot about us, when you go there to read those two things, just check out Sophos. We've been around for a long time. Great security company, cutting-edge technology and wonderful people. And I think, you know, you'll find great stuff there through the AI threat intelligence or just anywhere else.

(Joel Beasley at 00:53:16) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.