Episode 760 ·

How to talk Cybersecurity with your C-Suite in 2024 with Chris McKie & Matthé Smit from Datto

Today we’re talking to Chris McKie & Matthé Smit from Datto. We discuss how to have the cybersecurity conversation with c-suite executives, the ransomware threats that aren’t going anywhere anytime soon, and why the smallest stupid oversights often lead to the biggest breaches.

All of this right here, right now, on the Modern CTO Podcast! 

To learn more about Datto, visit their website here.

Have feedback about the show? Let us know here.

Produced by ProSeries Media.

For booking inquiries, email [email protected]

About Matthé Smit

As General Manager for Datto RMM, Matthé is responsible for driving the RMM product roadmap and managing the product management team. He plays a critical role in making Datto RMM the most efficient and scalable remote management platform in the world.

Over the last 20 years, Matthé has exclusively worked in the managed services market working for leading software vendors. Having worked with countless MSPs across the world, Matthé has a deep understanding of the space and a strong focus on finding simple solutions to complex technical problems. Matthé is located in Amsterdam, Netherlands.

About Chris McKie

Having more than 15 years of cybersecurity experience, McKie leads the security solutions product marketing team at Datto and Kaseya. Prior to joining Datto, he managed global market strategy and product marketing for FireEye’s network security product portfolio. Additional experience includes having worked at Cisco, Fortinet, MetricStream, and WatchGuard. McKie has authored numerous articles regarding compliance, cybersecurity frameworks, email security, ransomware and lateral threat detection. He holds a JD in law.

About Datto

As a leading global provider of security and cloud-based software solutions purpose-built for MSPs, Datto, a Kaseya company, believes there is no limit to what SMBs can achieve with the right technology. Datto’s proven Unified Continuity, Networking, and Business Management solutions drive cyber resilience, efficiency, and growth for MSPs. Delivered via an integrated platform, Datto’s solutions help its global ecosystem of MSP partners serve over one million businesses around the world. From proactive dynamic detection and prevention to fast, flexible recovery from cyber incidents, Datto’s solutions defend against costly downtime and data loss in servers, virtual machines, cloud applications, or anywhere data resides.

Transcript

(Intro Narrator at 00:00:00) Today, we're talking to Chris and Matej from Datto about how to navigate a cybersecurity conversation with the C-suite and more. You're listening to Joel Beasley, Modern CTO.

(Joel Beasley at 00:00:16) Where are you guys calling in from?

(Matej at 00:00:18) Amsterdam.

(Joel Beasley at 00:00:19) Cool. It's a little late over there, right?

(Matej at 00:00:21) It is, nine in the evening.

(Joel Beasley at 00:00:23) Okay.

(Matej at 00:00:23) It's not too bad.

(Joel Beasley at 00:00:24) Alright. And then Chris, where are you at?

(Chris McKee at 00:00:26) I'm in San Jose.

(Joel Beasley at 00:00:27) So it's almost lunchtime for you then?

(Chris McKee at 00:00:29) Yeah, it is. It is actually lunchtime.

(Joel Beasley at 00:00:32) Alright. Well, we'll do this awesome conversation, then we'll get you off to bed and you to some lunch. Does that sound good? Alright. And so I was just hoping to, at the beginning here, just get a quick understanding of what we want out of the conversation today.

(Chris McKee at 00:00:51) What it ultimately comes down to is, I think, the acceptance of cybersecurity as just part of business operations. And one of the things I was thinking about earlier today is the role the CISO has in talking to the C-suite. But this could apply to anybody talking to executive management about cybersecurity. And there's a few things that stand out, but a lot of it is really reducing the conversation to terms that make sense—having it presented more as a risk discussion and business interruptions or operations. Those are the things to me that we as an industry need to do a better job of demystifying, you know, all that goes into cybersecurity.

(Joel Beasley at 00:01:37) So let's say I don't get to spend a lot of time in cybersecurity. I just get to touch on it here and there for some interviews. And I've heard that before, right? Like, this move to conversation of risk. Is there still companies out there that are like, we're gonna hire a CISO so that we don't get a breach, and if we do get a breach, we're firing the CISO?

(Chris McKee at 00:02:01) Well, it is definitely part of the job, right, is to prevent that. But nothing's 100%. So it is a challenge. I think of it as more of three functions. There's the day-to-day CISO role or anybody in cybersecurity for that matter, which is just dealing with the daily, how do I stop what's attacking me, right? How do I deal with a DDoS attack? How do I deal with phishing? These types of things. Then there are what I call the KT events, right? These are the big breaches, and this is where you're talking about in terms of getting fired for, right? These are the big ones that really, and in some cases, may sink your business, right? Or at least set it back by months. Those are the things that we think about, like, what do you need to do to avoid those? But the other part that doesn't, I think, come into the conversation enough is how does security play a role in things like digital transformation? I'm updating my operations. I'm changing the way we do things. I want to be more efficient, more effective. Security is usually an afterthought, right? As we change apps and we're doing more things, how does security play a role in that? And I think that's a part that needs to be more visible, certainly with the board, but also the C-suite is security needs to have a voice at the table in those kind of business decision discussions.

(Joel Beasley at 00:03:23) Are you seeing that a lot right now or no?

(Chris McKee at 00:03:25) I think for companies who are proactive, yes. I still think though for the majority, and when I say majority, 80% of the market, security is an afterthought.

(Matej at 00:03:35) Well, it's not just an afterthought. It's just, it's seen as a big, big cost, right? And the people trying to get security in place, they're generally going back to the C-suite board and asking for more money. And it's like, well, we gave you a bunch of money last year. Why do you need more money? Right? And that's the difficulty, right? Like the people doing the work, understanding security, they're generally not in the board, right? And they have a hard time explaining what they need. And when you have any business, the attack surface is only increasing, right? And the attackers only get better. And the solutions, well, they're generally getting more expensive, and you're never done, right? So these conversations, they're pretty hard to navigate because generally someone in C-suite board, they think money, expenses. So how do you have that conversation? It's a fascinating topic and it has meaningful consequences, right? If you get the budget or not. It's, yeah, we think about that quite a bit. And it's a reality in any company—not just small, medium businesses, enterprises, IT services providers, everywhere. Not until you can translate security to a business benefit, right? Like, if you can frame it in a way that makes real sense to invest there. And part of that, and Chris mentioned, it's about dealing with risks, right? Like then it starts to make sense. It's not necessarily return on investment, but it's talking about risks and the fact that you're never 100% secure. That makes something like that an interesting conversation. Doesn't necessarily make it easy to get money for a piece of technology that most people have no clue what it really, really does, right? Like advanced, I don't know, EDR or next generation security technologies. It's very hard to explain that to someone, and they're like, well, we bought antivirus a couple of years ago. Why do you need this? Right? It's, yeah.

(Joel Beasley at 00:05:45) Chris, can you tell me about what company you're at and what's your primary objective?

(Chris McKee at 00:05:50) Sure. So it's Chris McKee. I'm VP of Product Marketing for Security and Networking Solutions at Datto. So Datto being now acquired by Kaseya, I'm part of the whole Kaseya suite of products, including security and networking as well. But yeah, so Matej is absolutely right. And one of the things that I think gets lost, just to reiterate a point he was making there, is security is dynamic and you're always buying new things. And part of that is because the bad guys, adversaries, are just as dynamic and just as innovative and just as determined to come up with new ways of getting your data. So we do see this constant battle and it seems like it does never end. And in some ways, it won't just because for many of them, ransomware makes a lot of money. It is a business operation. So when you take that into consideration, security has to be viewed as something that's going to constantly evolve, just as you would evolve your business processes.

(Matej at 00:06:50) Yeah. I'll jump in there quickly, also to introduce myself. So I'm Matej. I work at the same company, I'm Matej Smit. And I am responsible for the IT management products. So, it's called RMM in our world, remote management and monitoring. So I've done this for a long time, but we manage millions and millions of endpoints. And the funny thing in our world is that we talk to a lot of system administrators and people managing systems, but the worlds of IT management and security, they've blurred or are blurring, right? Like it's one and the same nowadays. Where it used to be a completely different department, but you can't get to a proper secure state if the ops people are not involved. It starts with deploying things in the right way, in the right configuration, and understanding what you have, and making sure you can upgrade, update quickly, etc. If you don't do that, well, you can have the best security team in the world, but it doesn't really help. So, but that's my role. I run a large software team or a couple of teams there. And we talk to many, many companies in the world about how to get to a better secure state. A lot of our customers are also IT services providers. So many MSPs that manage the small, medium businesses around the world. And we, with the enormous amount of data that we gather with all these endpoints and all the solutions that we have, I think we have a pretty good understanding of the behaviors of the attackers nowadays as well. So yeah, that's us.

(Matej at 00:08:31) And one of the things that we see a lot as well is security is just not about a single tool. It's not about buying multiple tools. It's about, well, first of all, people always say it's the technology, process and people, but it's actually more of an integrated approach, we think. Because there's always something more, right? There's always something more you can buy. But if you end up as a company with a whole bunch of different islands and technologies that don't work together, you're not really better off. You have, you end up with all these different silos with information, with alerts that are being ignored, and just people not working together. So our approach there is, I'd say, different in the sense that our mission is to give you one platform that does it all, right? From endpoint management to security to compliance. It's all deeply integrated. There's no copy-pasting of information or searching something in one application and then in the other. It's like connected workflows. And that's how we think we can help the companies to become more secure, to just be more efficient, not just with operational processes, but also with spending, right? So cost. But the big driver behind our business growth and that of many of our customers is the security conversation. Because that's what's keeping everybody up at night.

(Joel Beasley at 00:09:58) So what's the most difficult thing since you're the technology provider, companies come to you? Obviously, you get a wide range of customers. You've got the people who really are gonna embed this in their culture, and this is gonna be a big thing. You got the people who kind of are or whatnot. How do you actually help them do that more than just giving them a software? Do you actually do consulting with them? How does that work?

(Chris McKee at 00:10:23) Well, in addition to the tools, we do provide a great degree of additional resources there. But I think what you're hitting at is even more important. It's a concept that doesn't get enough attention, which is this idea of security maturity, right? So every business to some degree is on a different curve or security maturity curve. And depending on where they are on that curve is an indication as to how far along they are in terms of their maturity. We still deal with a lot of companies, and Matej referenced this earlier, that are still at the very low levels of their security maturity. So things like antivirus, right? So believe it or not, in this day and age, there are still a lot of smaller businesses in particular who questioned the need. Why do I need this? You know, why would a hacker come after me? What would I have that a hacker would want? And even larger sized organizations run at the same challenge. And the reality is those are the ideal targets for a hacker because in many situations, those smaller and mid-sized organizations are the low hanging fruit. They don't have the high degree of skill sets there. They don't have a security culture within their organization. And they're certainly not investing in the latest and greatest of tools to prevent these types of attacks. So, in many situations, we see these challenges with small and mid-sized organizations where they're on that low end of that security maturity curve. To contrast that at the high end, you'll have organizations that will want to either have their own SOC, security operation center, or they'll outsource a SOC to another third party to do much more proactive things—threat hunting, incident response, forensics, things that would indicate they're already taken a—and you hear this term a lot—zero trust. A zero trust mindset approach that, hey, I may have already been breached, and I just don't know it. So I'm gonna take the resources and the tools to proactively ensure my data is safe, my users are protected, and my systems are gonna maintain their continuity.

(Matej at 00:12:25) I wanted to tie it back to something we were talking about earlier, right? Sort of like, hey, how do we address this with our management, the C-suite, etc.? And Chris mentioned maturity and one of the things that we've seen that helps quite a bit is actually thinking and talking about frameworks, right? It just makes it more approachable or from a theoretical level. And it could be something simple like just talking about NIST, right? Pretty much everybody knows that. But sort of saying, hey, these are the areas that you need to address as a business. You need to have something to detect. You need to have something to respond. You need to have something to recover, right? And this is where we are. And this is what we have done. And these are our gaps, right? We have a pretty, I don't know, pretty good backup and recovery, disaster recovery solution in place. But we don't have this. And then it suddenly becomes an, I'd say, more interesting conversation. Especially, I always like these conversations to show either gaps or simple boxes, right? Like there are certain tricks that we even internally use, right? Where you have some kind of a scorecard with green areas. Like these are the things that we do well. And then some orange and some red. And every time you do something like that, the conversation will always be about the red box, right? Like, why don't we have that? So tying it back to like, hey, what is a good strategy for getting better at security? Well, if you know what you want, make sure you highlight that in some kind of a report. And it could be framework based, could be tool based, anything.

(Joel Beasley at 00:14:12) And do you guys do this as part of the sales process where you can do a scorecard and see where you sit?

(Matej at 00:14:19) Yep. Yeah, we definitely do that, but we also have, especially this is for the service providers and some enterprises as well, we build, we have tools that help you tell the story, right? So we don't just look at your organization, but we enable the IT professionals to just have that conversation. And perhaps not just once, but also how do you show progress, right? How can you now, the next quarter in, show that you've improved? So we have tools either to report on that or to show compliance. And of course, those things talk to the other products that we have. They talk to the EDR, the MDR, the IT management technologies. So you don't have to make up the data or populate it manually.

(Joel Beasley at 00:15:04) So that's one way you could have that conversation with the board or with your C-suite is you could build that scorecard essentially and say, hey, here's the standard. Here's the minimum stuff companies need to be doing. And here's where we're at. And we need money to cross the chasm. Is that what you're doing?

(Matej at 00:15:23) Well, it works two ways. Yeah. Absolutely. Ultimately, that's the end result. You can also highlight areas where you have something but it's just very outdated, right? But ultimately it's about getting that mindset of almost like continuous service, continuous improvement, right? Like this is where we are, these are the gaps. We know we're not gonna be—like, there's no such thing as perfect security and 100% secure. But let's at least make sure that we're better in the next period when we talk again. And some kind of consistent way of reporting up and talking up is gonna help you with that. Because that's, I think, the bottom line. There's no single ask, right? And that's sometimes where we see companies fail. Like you come in and say, we need this, I don't know, we need to upgrade to the highest tier of Microsoft 365. It's gonna cost us a lot of money, it gives us advanced security tools, and then we're done. Well, not really. You're gonna need something else. That's the point. You want to have this ongoing conversation about risks. Either frameworks based and or some kind of a reporting that you do.

(Chris McKee at 00:16:35) I'd like to add to that. So without a doubt, having that framework discussion, it doesn't matter what framework you use. And in fact, you know, there's no single one framework that's better than the other. There's probably close to two dozen popular ones out there today. NIST, ISO, COBIT, kind of what you're doing.

(Chris McKie at 00:16:51) CMMC, if you're in the government space. CIS is a great one if you're just starting out. But having those conversations with a framework as, no pun intended here, the framework of security to say, how do we have these discussions? How do we do the gap analysis? Where do we stand on these different initiatives?

(Chris McKie at 00:17:08) That's hugely important and probably should be reviewed at least once a year. The other part I was going to add to this, though, is also the discussion around, from a financial standpoint, cyber insurance. Right? So even in the last year, we have seen cyber insurance rates increase 50% to 100% depending on where you are. This now takes security into that kind of CFO discussion.

(Chris McKie at 00:17:32) Now let's talk about security in terms of risk, risk reduction, and what are the things we need to do to ensure, a, our cyber insurance will cover it in case an incident should occur. And then b, what do we need to do to make sure that we're ahead of that curve? So using your cyber insurance as a wedge, so to speak, as a way to have that CFO discussion, C-suite discussion, helps open up discussions about products like EDR. Do you have EDR in place? Are you doing security awareness training?

(Chris McKie at 00:18:01) Right? Nowadays, we're seeing more and more carriers, the underwriters for insurance, mandate you must have certain things and we want to see proof of compliance. So just because you have the insurance there, you still could get denied if you have a claim because you may not have been doing security awareness training, for example. So it's important to look at it through a different lens depending on who you're talking to and how you present security in that lens.

(Joel Beasley at 00:18:26) Yes. Yes. I remember seven or eight years ago, I was getting a business insurance policy and there was like a checkbox for cyber security, like a $2,000,000 checkbox. Now it's gone from being this tiny little checkbox to this massive application and proof, like all of these requirements for you to meet because they got hosed. I did some interviews about three years ago with the people that the insurance companies call to negotiate with the bad actors, and that was their business.

(Joel Beasley at 00:18:57) Their client was the insurance company. They would validate that the company actually got attacked and then they would negotiate the ransom. Right? And so it was happening at such a large scale. The insurance companies now have really tightened up. Right?

(Matthé at 00:19:11) That's a fascinating job as well. So they're effectively talking to the bad guys all the time or just negotiating on both ends.

(Joel Beasley at 00:19:20) He says it's like a corporation. He goes they have customer service that you can negotiate with them. Yeah. It's like, it's this whole, he's like, you'd be surprised at how well they operate.

(Matthé at 00:19:29) Well, I mean, 100%. Like, and we see that a lot, right? Like, so even though we protect a lot of people, we see a lot of ransomware attacks. Either we save people with our, we have ransomware detection technology, so we know at the moment when it gets executed and we can prevent it. But we also do, we have huge data centers with a lot of disaster recovery going on, right?

(Matthé at 00:19:57) So we have people that virtualize in the clouds and we kind of save their bacon like that. But ransomware attacks, like of course we read it in the news all the time, but we see it in our data all the time as well. It's real. But it's such a profitable business. It's, and you're absolutely right.

(Matthé at 00:20:15) They're mature software companies in many ways. They have great customer service, like great release management, a great sales channel. Because the people that build the technology are not the people that run the attacks, right? But that's I think one of the lessons for us. That's not going away, right? Ever since we invented crypto, we have found a way of paying people anonymously.

(Matthé at 00:20:46) And it's become very, very profitable. And as long as it remains that, like they will always find a new way to get in. And that's the difficulty. Our attack surface to protect is immense. It's all the different layers.

(Matthé at 00:21:01) And they only need one way to get in. Right? And that can even be someone from the inside, like it can, either malicious or by accident. Doesn't always have to be a zero day, right?

(Matthé at 00:21:15) Like most attacks that we see are just stupid, right? It's either unpatched software where a patch was available for months and months. It's someone clicking on a link and it was not even a well crafted, tailored email. It was just something stupid, right? And then that's how most companies get breached right now.

(Matthé at 00:21:38) And yeah, that's definitely not slowing down. Actually, now with AI technologies and all the other things that we're seeing, it's only going to get more difficult. And there's this saying, right, like attacks only get better, they never get worse. Well, that's definitely happening.

(Joel Beasley at 00:21:56) Chris, how long until the point where we're talking to AI for all of our security needs? Like I just unleash this AI inside my org. It has root access to everything, and it keeps everything secure for me, and I just talk to it and tell it who can...

(Chris McKie at 00:22:09) That's a great question. So let's talk about AI a little bit. We're in the early stages of the game, admittedly. Right? And there's a few things that we're seeing already both on the defensive and offensive side of this.

(Chris McKie at 00:22:25) So as an attacker, AI is great in that you can leverage it. We'll use a couple examples. Phishing. Right? I think we've all seen the poorly written, the misspelled bad grammar.

(Chris McKie at 00:22:42) Obviously, this is not, you know, Bank of America sending me a note. It is coming from somewhere else where English is probably their second language, maybe a third. Those days are going to disappear real quick because AI, and the bad guys know this. They can now take existing emails from, and again, I'll use a bank example, run it through an AI engine and now spit out something that really looks legit.

(Chris McKie at 00:23:05) So those classic phishing emails that we've all received over time are going to be harder and harder to spot. And on top of that, they're going to use behavior analytics to see where you go, things you do. Right? Track your kind of web footprints, if you will. And they will have even a better sense of what phishing emails are going to be effective in trapping you to click on a link.

(Chris McKie at 00:23:28) Because at the end of the day, and as Matthé pointed out, and I call it human error, not any sign of intelligence. People make mistakes. And a good, well crafted phishing email, you're going to click on something. I don't care how solid you are. It happens.

(Chris McKie at 00:23:46) So AI definitely is going to benefit the bad guys in that sense. It's also going to benefit them in code development. So a lot of older legacy security products are signature based. So when a new variant comes out, if a new signature isn't created soon or and updated, it may bypass your existing tools. As a hacker, AI is great in that sense because now I can take existing malware and I can do derivatives of that all day long.

(Chris McKie at 00:24:17) I can create new strains, new variants and sooner or later, something's going to bypass your toolset. So from, and as Matthé pointed out, it is a machine. It is an industry. They run it like any other business. So they will do innovations, product updates, malware updates, if you will, to bypass whatever tools you have.

(Chris McKie at 00:24:38) Count on that. On the flip side, people are thinking, oh, AI is going to protect all of our systems that we're going to learn how to better defend. And we will. Those things are definitely in place today and they've been for some time and those will continue to improve. But where I worry is the introduction of AI in new code development.

(Chris McKie at 00:24:58) So I'm sure you're aware a lot of people are talking about AI is going to revolutionize new software development. The problem is AI is only as good as the engine in the training it's had, right? And Matthé, correct me if I'm wrong, but the issue here can be, you may start developing code based on something you think is 100% solid and stable and secure and it may not be right. So you may inadvertently open up kind of a Pandora's box of new development, new code that may not be as sound as it could be or should be, which means you've got to spend more cycles in testing and making sure everything is protected. So AI is going to cut both ways.

(Chris McKie at 00:25:36) I like to say, I think we're in the early stages of the game. This is probably what maybe the first quarter if I did a football analogy. We've got a ways to go just to get to halftime.

(Joel Beasley at 00:25:45) Are you seeing the chat interfaces start to emerge inside of security tools?

(Chris McKie at 00:25:50) They definitely are taking a greater role there. Yeah. So and you'll see more of that. And then, and I think that's again, there are a lot of benefits that AI can bring to the table. I just, and maybe it's just me, I'm a little more concerned with it. I want to take a more pragmatic approach to say it's not yet a silver bullet. And it looks like...

(Joel Beasley at 00:26:08) Well, it's definitely not 100%.

(Chris McKie at 00:26:11) Yeah.

(Joel Beasley at 00:26:11) But it's only 100% when it's already been, when it's done and operating. So I'm like, I see it coming on the horizon. I'm like, oh, there it is. You know?

(Chris McKie at 00:26:20) It's just going to make things interesting for the next, you know, ten years.

(Matthé at 00:26:23) We do see like a couple of things. When you, I mean, I think Chris mentioned like EDR and like detection technologies. Right? Like what you see there is there's just too much information for humans to process efficiently. Right? That's where AI, other like more advanced technologies, they will help out, stay on top of the noise, right? So that's one. And when you asked about chat, chatbots, etc., you do see a bit more generative AI technologies, at least on the response side of things. So either you get a message saying, 'Hey, this and this happens.' You have ransomware.

(Matthé at 00:27:05) And it, like coming up with the next steps, like either like what do you need to check? What do you need to do? That can be fed through either a bot or like something that is going to help you decide the next steps, but also the communication after that. Right? So if you're dealing with users or customers, like you need to craft messages, you need to tell them something about, like hey, you need to do this. This is generally the kind of stuff that the security conscious technician is not good at or doesn't really want to do, and that's where AI can save a ton of time.

(Matthé at 00:27:41) So it's not even, we're not, you don't have to think about the advanced work. It's taking the mundane work out of that job, so they can spend more time thinking about the more advanced work. Right? Security analysis, etc.

(Joel Beasley at 00:27:55) Are they building AIs that, like you take all, you have all these clients, right, that you do this monitoring and stuff for. You could watch all the different clients and as throughout the year or whatnot, as they get attacked and attacks happen and they resolve and take all that data and train it on this AI that's like, hey, here's the historical knowledge of like 10,000 attacks and then talk to it. Like, is that something people are doing?

(Matthé at 00:28:23) Well, as a vendor, right, we have enormous datasets and we are using that to get better. Right? We find these patterns either with AI or other analysis to find attack patterns and make our software better all the time. So yeah, there's definitely, definitely that. One of the other things that we are doing, and I wanted to get back to the chatbots a bit, it's not necessarily using very, very large datasets across customers, but it's especially on the help desk side, right?

(Matthé at 00:28:53) We have very popular help desk applications. One called Autotask, very popular in the space with service providers. That sits on thousands and thousands of tickets that people worked on. A lot of the customer information, a lot of the details about all the assets. We're working on implementing bots there that will actually help you like respond to a ticket but also say, hey, this ticket, it looks like it's about this.

(Matthé at 00:29:20) I don't know. It could be something simple, like it's about this user needs more access. Well, like the AI can get that from a ticket pretty easily. But then also recommend the next step, like hey, you probably want to execute this task in this other application, and shall I do it for you? Like that's the, going back to what we're trying to do with this integrated platform.

(Matthé at 00:29:45) Like we're bringing all these applications together and with one of our new technologies that we've been working on, the Cooper Bots, that's what we call them, we're using AI, applying it in a way that just, it saves a ton of time in every single workflow, especially like on the support and the operations side. You don't need necessarily big data, but it will get better over time for each customer as well, because their data set grows. One of the key things that we're always very nervous about, like is just like what you put into these public models, right? Like that's not allowed for us.

(Matthé at 00:30:22) Internally that's not, like I think many companies should be very careful with using all these public models, right? But also like these models that learn from information across different customers. I would be very worried if our data gets used and applied to a lot of customers. I mean, you can look at system events and you can do it pretty, like if you can anonymize it and no real corporate data gets leaked, that's fine. But my God, like on that, there's a lot of sensitive information in either even a help desk or a security, like a SOC.

(Matthé at 00:31:04) You just want to keep to yourself.

(Joel Beasley at 00:31:07) What's the most interesting application of AI that you've seen in the cybersecurity space?

(Chris McKie at 00:31:12) Well, I'll jump in and I'm going to add actually to this point. So, for example, we have an email security tool called Graphus and Graphus uses AI almost in the way you've described it, where it's looking at a volume of data and making decisions based on that and it works very well. So I think you're going to see AI used in more and more tools like Graphus, especially in email because it, well, one, it's the number one threat vector. But two, there's just so much volume of data that can be tapped into there. But I think the point that really needs to be stressed here is where you're going to see AI really make a difference, the space in between.

(Chris McKie at 00:31:49) So for example, one of the key metrics in any sort of breaches, from time of breach to time of detection, time to remediation. Right? These are key points in time that anything you can do to compress that, the better for you. It minimizes the damage, the blast zone. It minimizes, you know, ransomware affecting hundreds of systems versus two.

(Chris McKie at 00:32:10) So I think this is where you're going to really see AI take off immediately is the space between when a breach occurs and the reaction response time, the remediation process, the forensics, all of that. AI can play a major role because as Matthé pointed out, these are typically very human heavy, intensive responsibilities where AI can immediately connect different disparate systems together, trigger the tickets, trigger the results, trigger the automation response. And then now it's just a person, you know, at a console doing click, click, click, there you go, versus spending what could be hours, could be days in some cases of trying to deduce what breach occurred, where did it occur, what systems are affected, you know, what's that damage. The longer that takes, the greater the risk and the exposure. So anything that shortens that, and AI definitely plays a role in this, that's going to be huge.

(Joel Beasley at 00:33:10) What's the coolest breach that you've ever seen? And you can abstract it to talk ambiguously about it if you want.

(Chris McKie at 00:33:16) I'm sorry. To say the coolest breach I've ever seen?

(Joel Beasley at 00:33:18) Yeah. Like what's that when you saw it, you're like, wow. That's actually pretty cool.

(Chris McKie at 00:33:22) So there's a few. One that stands out, I think, is really interesting because it shows you how vulnerable any company can be. And I'll try to anonymize this. It was a company in Europe and a fairly large size organization. And like many organizations, they had a video camera, write a video camera system and they left it open on the internet.

(Chris McKie at 00:33:50) So anybody, if you're pinging their network, you would have sooner or later discovered this open webcam basically. Right? They started noticing odd things happening at different hours of the day for their time. It would have been, you know, 10 a.m. I'll use China as an example, 10 a.m. China time. And they're in a different time zone. So they're seeing unusual traffic hitting their network at times that aren't local to their network traffic. Right?

(Chris McKie at 00:34:08) So already there's an anomaly here. Long story short, what ended up happening is they were breached and the breacher used this open webcam that no one ever bothered and it's the classic, right? No one ever changed the admin credentials from admin and password. Right? So once they got their hooks into that webcam, then they were able to move laterally throughout the network, find other systems that they could exploit.

(Chris McKie at 00:34:21) And as Matthé pointed out earlier, it's not a zero day that's gonna bring you down. It's gonna be something really simple like you didn't run a vulnerability scan and you didn't patch, you know, a server somewhere. They'll find it. Trust me. They will find whatever it is. If it's not patched, they'll take advantage of it. Jump on that, open up another command and control. Right? And it just propagates. And so once now they've got two command and controls running, then they're just gonna keep looking around. They're gonna drop in things like Mimikatz or other tools like that that are basically looking for network traffic that has credentials, username, password.

(Chris McKie at 00:34:49) They're going to do recon on every system in your network. They're going to know who's on the network and what's on the network. At that point, now they're just looking for admin credentials. Right? And this happened. And so they were in there for many, many days. We're talking over a month before they finally got to a point where they got to a machine that they wanted to compromise. They dropped in their dropper. Ransomware hit. They were able to isolate it luckily and prevent it from spreading beyond that.

(Chris McKie at 00:35:06) But you can see how just one little thing like an open webcam on the Internet and a few unpatched systems could wreak havoc through any organization. And that is kind of a classic. It happens all the time.

(Joel Beasley at 00:36:09) Wow. Matthé, you got one?

(Matthé Smit at 00:36:10) Not like that. That's a great story. Yeah. No. I mean, I see a lot of those attacks that happen through not updated software. Right?

(Matthé Smit at 00:36:21) So, very common in my world that I've seen a ton of is compromised Exchange servers or Citrix servers or VPN, and that's always the way in. Right? And I've seen quite a few of them. I'm always surprised about the time people take then. Right?

(Matthé Smit at 00:36:39) I can imagine, you're in, you're okay, let's get in and get out. Right? Like a bank robbery. But that never happens. It's the gut—almost it takes to stay in a network for weeks. And yeah, I mean, they can do whatever they want.

(Matthé Smit at 00:36:55) People are just not paying attention. You kind of know that after you had all these Exchange vulnerabilities, like the proxy logon vulnerabilities, if you have a network that still has that one after months of a patch being available, you kind of know that you can do whatever you want in that network anyway. Because they're not security first. So it's hard for me to find a favorite one. I always find it kind of, I really feel for the customer, for the company that has that.

(Matthé Smit at 00:37:24) It's so difficult to do security well right now. And it's so easy to be in it on the bad side at the moment. That's, you can use any publicly available web scanner to search for open ports or for specific versions. It's like, people should almost try it themselves and see how easy it is because the reality is that that teaches you, almost like push—tells you the hard facts about your job. You need to be on top of everything.

(Matthé Smit at 00:37:56) And that's an enormous task. And yeah, I really feel for the people that have that job. It's immensely stressful. And we started off with talking about the stuff that gets the CISO fired. And the reality is, you can do everything right and still get fired for a terrible breach.

(Matthé Smit at 00:38:17) Let me say then, a good reason to get fired is if you just don't handle the breach well. Like the communication, the response. If you do it all well, you should definitely keep your job. But any mid-sized company will have hundreds or thousands of assets. And you need to be on top of everything.

(Joel Beasley at 00:38:37) What does good communication around cybersecurity incidents look like within a company?

(Matthé Smit at 00:38:43) Yeah, you have two sides of that. Of course, it depends on what happened internally and externally. If you have customers, and it's very common that you, I mean, websites get breached all the time. The key thing is to be very, very, very clear and transparent. And that applies both internally and externally.

(Matthé Smit at 00:39:08) Communicate early, communicate often. Our CEO always tells us, there's nobody gets fired for over communicating. And that's really the case here as well. So even though you know little, communicate it. Right?

(Matthé Smit at 00:39:22) So we know you've been breached, you don't know how, how long, etc. Communicate what you see. In the space, you see a lot of companies do is sort of take months and say, well, we've been breached a couple of months ago. Yeah, you'd never want to do business with that company again. Like, they don't have a good security posture there.

(Chris McKie at 00:39:44) Let me add to that. Part of that also comes down to running tabletop exercises. Right? Having an incident response plan in place, plans actually portal. These things are critical.

(Chris McKie at 00:39:57) And I can't stress enough to go through those emulations if you will. What if you get hit with ransomware? Yeah, because there are different variants of ransomware where you could say, well maybe 10 Ks, I'll pay it and hopefully get my data back. 100 K, maybe I won't. Right?

(Chris McKie at 00:40:13) But having done tabletop exercises in advance where you're bringing in the stakeholders, you know who to contact at 3 a.m. You know who your local FBI contact is. You know who in legal is gonna respond. You know who in maybe Corp Comms, PR is gonna respond. Right?

(Chris McKie at 00:40:30) These are all different disparate groups in many situations that oftentimes get pulled in at the last minute. And at that time, people make mistakes because they're scared, they're nervous, they're rushed. Much of this can be avoided by doing tabletop exercises in advance so that you already know what that game plan is. You already know what the playbooks are. You already know what you're gonna do because sooner or later, it's probably gonna happen.

(Joel Beasley at 00:40:56) Does the FBI care? Why would I call the FBI if I got—

(Chris McKie at 00:40:59) Oh, absolutely. Yeah. Yeah. Yeah. Depending on the type of breach.

(Chris McKie at 00:41:02) Business email compromise, we're seeing a huge growth in that area alone. And that's really fraud at the end of the day. Business email compromise is I've tricked you into earning your trust to send me money. So it may not necessarily even be a breach per se, but I have figured out either social engineering, doing my research, doing, setting up relationships with you or others to basically trick you into sending me money. Common examples and they're simple ones as simple as I send in, I find out who your employees are.

(Chris McKie at 00:41:39) I emulate one of them and say, hey. And I send a note to HR. I've changed my bank account. Can you redirect my, you know, direct deposit payroll to here's my new bank account. If there are no systems in place to check that and to verify, it's very easy for someone in HR just to go, oh, okay.

(Chris McKie at 00:41:57) You know, John Smith is now at, you know, this bank. And the next payroll, John Smith is like, where's my check? And you know, the money's gone. That's a real simple example. Obviously, this can get much more complex where it is, you know, attorneys.

(Chris McKie at 00:42:13) Hey. You guys are behind on your payment. You need to do this. You need to wire it now if you're gonna retain our services. Right?

(Chris McKie at 00:42:18) It can go a number of ways to CFOs, others involved. FBI absolutely takes interest in these things. They will do what they can to actually pursue and address it. So by all means, you should know who your local FBI—they have cybersecurity task forces set up just for these things.

(Joel Beasley at 00:42:38) Oh, interesting. Alright. So just to just to touch a little bit back to the end of the conversation and to answer the question directly, how can leaders prepare and handle any feedback or pushback from stakeholders regarding cybersecurity policies and incidents?

(Chris McKie at 00:42:55) Well, I think they need to prepare it as if they're having a business discussion versus an IT or technology discussion. Right? Frame security from a risk perspective. What does this mean to your organization? And earlier, it was said, you know, security oftentimes is seen as a cost center.

(Chris McKie at 00:43:13) And I would argue it's just the opposite. It allows you to do things more efficiently and effectively if you're taking a security awareness approach to it. So for example, a new area in the security world is, it's called SASE, Secure Access Service Edge. And it's a solution really geared for remote and hybrid workers. So you've got people on the road or they're working from home, wherever it may be.

(Chris McKie at 00:43:38) Typically, the way you would address that is as a VPN. Right? So I would set up a VPN, but as you've probably been on the road and use VPNs. The user experience may not be ideal. Right?

(Chris McKie at 00:43:50) There's latency because you're back hauling all your traffic back to the corporate network. The other problem is VPNs. Well, there's a lot of issues with VPNs. They're highly targeted by bad guys. SASE, which is this new area.

(Chris McKie at 00:44:04) So we have a product called Secure Edge that addresses that use case where instead of using a VPN, I can basically wrap you. I can take the edge, my corporate edge and protect you as if you're behind the corporate firewall now. So I can add the same policies, the same control mechanisms, web content filtering, next gen firewalling capabilities, all wherever you are. So regardless of your location, I can protect you remote worker, hybrid worker, the same way as if you were in the office. VPNs can't do that.

(Chris McKie at 00:44:35) Right? These are the new things on the horizon that it's important to have a discussion to, you know, the C-suite in terms of I can enable a more flexible workforce and they're gonna be more secure.

(Joel Beasley at 00:44:50) How do you guys do your calls to action? Because there's definitely people right now who are listening. They're gonna be at various stages inside of the security maturity model and all of that. But what's typically when you're talking to a broad audience of technology leaders, what's the next action that you want them to take?

(Matthé Smit at 00:45:07) Well, you have to start somewhere. If people pick our technology, that's great. I think, ultimately, people have a gap somewhere. Right? Either it's they don't have good endpoint management, or endpoint security, or user awareness training, or backup. Right?

(Matthé Smit at 00:45:24) But you have to, you have a gap somewhere, and we offer solutions for those gaps. But one of the things that we'd like people to think about is also, think about security in this case, or even IT management, IT in general, holistically. Because I think our approach is completely different, because it all works together. Right? I think we are the only one with such a broad platform used everywhere in the world. So, yeah, I would definitely—the call to action, it is pretty simple, but we have roughly 40 products that are immensely popular in the enterprise and MSP space.

(Matthé Smit at 00:46:06) Definitely check them out if you have a problem. Go to our website, datto.com, kaseya.com. Yeah, find the one for the problem you need.

(Chris McKie at 00:46:15) Yeah. And I'll add to that. Right? I mean, gap analysis definitely is part of that. But also people tend to forget about just basic things like refresh cycles.

(Chris McKie at 00:46:24) Right? Firewalls get old over time. Endpoint security gets old over time. You know? So when those refresh cycles come up or you've got other initiatives coming into play, maybe you wanna build out a SOC.

(Chris McKie at 00:46:34) Maybe you already have a SOC and wanna augment it. I think one of the challenges we have is people don't really know how much Datto and Kaseya have in terms of security solutions and capabilities there. So to Matthé's point, go to our websites, check it out. But when you're going through that product refresh cycle, even things like networking gear, access points. Right?

(Chris McKie at 00:46:53) These tend to change over time. Wi-Fi, you know, six is now the current standard. Wi-Fi seven starting to come out. People are looking at switches, things of that nature to say, okay, maybe it's time I look at, you know, an alternative. I would definitely say, you know, put us on that list of whether it's networking, security, other tools, we have a ton. It is almost kind of scary how much Kaseya and Datto have in the broad portfolio of things, but it's worth checking out. And I would definitely recommend if you're at that point of again, cyber insurance review, let's look at, you know, what are we doing for security awareness training?

(Chris McKie at 00:47:26) What are we doing for EDR? We have a lot of great tools for those.

(Joel Beasley at 00:47:30) Yeah, I loved I loved you saying earlier about using the cybersecurity policies compliance as a way to have that conversation. It's, because you're already paying for it. Right? And it's only gonna get covered if you meet these requirements. And so you at least have to make sure you're meeting these requirements so that if you do get an issue that they're gonna pay for.

(Joel Beasley at 00:47:49) I think that's a really good starting point for people who are who are just trying to get up to speed. This is great, guys. I think we did it. We made a podcast. How do you feel?

(Chris McKie at 00:47:58) Oh, it's great.

(Joel Beasley at 00:48:00) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.