Episode 537 ·
Getting Your Data Back In A Ransomware Attack with Eric Wilkens, Director of Cybersecurity at Arvig
Today we’re talking to Eric Wilkens, Director of Cybersecurity at Arvig; and we discuss how the cybersecurity landscape has changed in the last twenty years; whether companies should pay for their data back in a ransomware attack; and why it’s critical for every team member to be responsible for cybersecurity.
All of this right here, right now, on the Modern CTO Podcast!

About Eric Wilkens:
20+ years of Information Technology experience. Seven years in the banking industry working in Information Security and Systems Administration. Ten years teaching in higher education in topics including Information Security, Networking, Systems Administration, and Political Science. Over five years working for an ISP focusing on system architecture and Cybersecurity.
About Arvig:
Great service is all about providing you with the ultimate experience, and that’s something you will always receive with Arvig. Our employee-owners are passionate about taking the time to understand your business's current and future goals to ensure we provide the right telecommunications solution.
Arvig is a Minnesota employee-owned Telecommunications Company that has been providing homes and businesses with high-speed cutting-edge products and services since 1950.
Business solutions for fiber construction, internet, business IT, WiFi, TV, local/long distance phone, business phone systems, security, and more: arvigbusiness.com
Arvig Answering Solutions: arviganswering.com (formerly Time Communications)
Internet, Managed WiFi, TV, phone and security for your home: arvig.com
Arvig's Multiwav internet service: multiwav.arvig.com (available for townhomes, condos, apartment buildings in the Twin Cities, St Cloud and Rochester)
Transcript
(Intro Narrator at 00:00:03) Hello, my friends. Today, we're talking to Eric, Director of Cybersecurity at Arvig, and we discuss how the cybersecurity landscape has changed in the last twenty years, whether companies should pay for their data back in a ransomware attack, and why it's critical for every team member to be responsible.
(Joel Beasley at 00:00:42) How did you first get into technology and find your way to where you're at now?
(Eric at 00:00:47) No. That's a great question. So my journey has been a winding road to get where I am today. My interest in computers really started back in the mid-1980s. That gives you any idea of how long I've been in this sphere.
(Eric at 00:01:00) Back then, my high school actually purchased a couple of Tandy TRS-80s. We can go back that far in our history lessons. And I had a friend who had a Texas Instruments '99. Right? You'd hook it up to your TV, and you'd have the cassette tape.
(Eric at 00:01:14) So I dabbled a little bit in basic programming back then, kind of that whole rural North Dakota vibe and feel. After high school, I joined the Air Force, and continued my interest in computers all through that. Then in 1998, I took my first full-time position in IT, and during that stint, I worked both system administration and the early days of information security, and that was in the banking industry. I did that for a number of years. From there, I moved into a college faculty position, and then I taught computer network security for ten years, and then I moved back into private industry where I am currently.
(Eric at 00:01:55) You know, during that time and even to today, I continue to further my education, either through academics, self-interest studying, industry certifications, formalized training from other training organizations. And another big part of this is also that I believe in giving back to the industry through various cybersecurity committees that I serve on, working groups, and other nonprofit organizations. And so that's kind of where we started and where we are today, and that covers a lot of time in a very few seconds.
(Joel Beasley at 00:02:27) Yeah. I'm curious, what was the cybersecurity threat landscape like?
(Eric at 00:02:33) Well, so when I started in 1998, they were just coming off of mainframe for a lot of things. So email and client-server architecture was still fairly new at that point, and this puts us back into the Novell networking days, as you know, with IPX and SPX protocols, and really a different landscape than we live in today. You know, shortly after we got into there, you saw federal regulations really starting to come in. So you saw things like the GLBA or Gramm-Leach-Bliley Act come in, and then not too far after that, you saw Enron and their collapse fall out, so then you saw Sarbanes-Oxley come in. So you saw a whole new set of regulations.
(Eric at 00:03:14) So being in that banking industry in the late 1990s and into the early 2000s, you really saw the regulation pieces come into it. Not only did you have your regular regulatory bodies that did audits, but now you saw the federal government really coming in with all of these other requirements that you had to follow.
(Joel Beasley at 00:03:32) That's crazy. I mean, and now you got to follow all the regulatory compliance requirements from the entire world.
(Eric at 00:03:39) Right. Yeah, especially if you're international and you start getting into GDPR and all of these other things. And Australia has their own, and I think even within the US, it depends where you do business, because California has different laws than does the state of Minnesota. So really, you have to be up on those regulations across wherever your business takes place.
(Joel Beasley at 00:04:03) Yeah. Absolutely. Well, how did you find your current role at Arvig? How did you meet the team there and join as Director of Cybersecurity?
(Eric at 00:04:12) So that's an interesting story. That actually involves the gym.
(Joel Beasley at 00:04:16) Nice.
(Eric at 00:04:18) So I actually met an individual who was a director at Arvig one day. We both shared an interest, both Air Force people. And we got to talking one day, and we were talking about different things. He's like, Hey, I might know something. Well, you know, that conversation kind of, we had that, and then a couple months later, things had transpired. And having taught for a number of years, I picked up the phone, and I called a former student, and I said, Hey, got a question for you.
(Eric at 00:04:47) If I was looking at leaving and maybe sliding over, who would I talk to? And so we had that very first interview the next day over a cup of coffee. And then from there, you know, things just went very quickly. I came actually back into Arvig as a system engineer. So I was responsible for data center engineering.
(Eric at 00:05:06) So anything that utilized data was in my sphere for helping design it. During that time, we were able to greenfield the new data center, but I always maintained a portion of the cybersecurity responsibilities for the company. And as the company continued to grow and its threat landscape continued to develop, we actually created a cybersecurity department at Arvig, and then I slid over to take care of that. And that's where I entered into my current role as Director of Cybersecurity.
(Joel Beasley at 00:05:35) Awesome. And can you give me the overview of what Arvig does?
(Eric at 00:05:39) Yeah. So Arvig is one of the largest independent telecommunications and broadband providers in the nation. We actually started as a small rural telephone company in 1950. Today, we're still family-owned, but we've grown our network to serve more than 155 communities across a 9,000-square-mile service area. We have a presence in more than half the counties in Minnesota.
(Eric at 00:06:04) While we're primarily Minnesota-based, we also have out-of-state connections through our data center partnerships, not only in Greater Minnesota, but also into North Dakota, Nebraska, Illinois, and Iowa. And first and foremost, Arvig is a broadband provider, and we offer all the traditional telco services including internet, television, phone service. But people may not realize that we go far beyond that. We also offer a broad range of technology solutions from managed Wi-Fi, managed voice services, including voice over IP phone system, hosted PBX systems, streaming television, managed IT, security systems, computer repairs. So at Arvig, we've really taken an out-of-the-box approach with our customers. Instead of saying, here's what we have, hopefully it works for you, we really like to say, tell me what you need and we'll find a solution that works for you.
(Joel Beasley at 00:07:01) Nice. That's super cool. So as a broadband provider, I'm sure reliability has got to be huge. How do you guys ensure maximum uptime for what you do?
(Eric at 00:07:13) Well, that comes down to people and products. Right? We have some of the best people, I think, working for us. We've got brilliant minds that design our networks, maintain our networks. You know, we run a twenty-four-seven network operation center. We are able to quickly identify not only outages and resolve those quickly, but also potential things. Right? So we can be on the front side of this knowing, hey, we need to do maintenance here before this becomes an issue. Along with that is where you start to get into that cybersecurity aspect of it too, where we're looking at where are the current threats? What do we need to make sure that we're patching accordingly, right?
(Eric at 00:07:49) Has Cisco issued any new vulnerabilities? If they have, what's our exposure to it and keeping those things really going up to speed and doing those types of things? You know, just to touch a little bit more on that NOC idea. So our NOC, as I mentioned, is a twenty-four-seven operation, but they monitor our entire network every day of the week. During extreme weather events in particular, we focus on nodes that are critical to providing internet services for those customers. They're monitored for operational issues, adequate power being supplied, you know, that the communication levels are correct.
(Eric at 00:08:27) And then, you know, in the case that there is an outage, we push notifications out to the relevant customers, and we ensure that our help desk has that information upfront. So if the customer hasn't received a notification and they call us, we're able to give them information upfront saying, Yes, thank you very much. We are experiencing an issue in your area. Here's our estimated time of repair, and this is what's going on. We also, with that, monitor regional power companies, and so we know when they're having outages in particular areas, so that we can quickly rule out that, you know, oh, this is a power outage in a local area, so we have to wait until that comes back on. We also have some of our equipment that is able to notify us that they've lost power prior to shutting down. So if they go on to UPS or battery backup, they'll send us notification saying, hey, we've lost power, and so we can start to get on to that right away to ensure that generators have kicked in or other means as necessary would be there. That NOC also dispatches technicians for repair of nodes that don't come back online after a power outage, or if sometimes things break, or you know, breakers go off in power. Sometimes you'd have to go manually reset the breaker even though the power came back on.
(Eric at 00:09:43) You know, sometimes equipment gets damaged, car accidents, snowplows up here in Minnesota, right? We've seen snowplows take out pedestals. We've seen car accidents roll right over them. You know, there's nothing we can do, but we get people out on those right away to ensure minimal disruption to our network and our customers.
(Joel Beasley at 00:10:03) From a security perspective, is it challenging to be able to interface and share data with those utility providers, the electric companies? How do you create transparency in sharing that data in a safe and reliable way?
(Eric at 00:10:17) So we don't have a lot of direct correlation with the power providers as far as the threat landscape because they kind of run their own threat landscape piece. But overall, in the industry, there is something that's called an ISAC. Information Sharing and Analysis Center is what that stands for. So the power companies have their own ISACs where they get threat intelligence in, and they're monitoring that. So they're looking for threats to their information technology or IT networks and their operational technology or OT networks.
(Eric at 00:10:49) And we do the same. You know, we belong to an ISAC, so we're getting daily feeds about threats that are coming out and things that affect our networks just as well. But then, you know, you talk about, there is a correlation between the power companies per se, or any other public provider, and broadband companies such as Arvig, and that we need to make sure that our networks are secure, because we could be transmitting their data as they're communicating back and forth across their IT networks, and they're not only customers, but their employees and their dispatch. So by us taking a proactive stance on cybersecurity, it not only helps us, but it also benefits our customers. In this case, as you mentioned, could be those power providers.
(Joel Beasley at 00:11:34) So I'm curious, as a telecom company, the threats that are out there, what are the bad actors going after when they target a telecom company?
(Eric at 00:11:46) Well, that's an interesting question because I think you need to frame that into the type of attackers that are coming after companies, right? Because there's different types of attackers. So you could have, if we go with, you know, the biggest threat right now, obviously, mostly in the news, is ransomware, right? That's one we're hearing about almost on a weekly basis, and they're simply out for money. Right? That's all they care about, right?
(Eric at 00:12:09) So in today's ransomware environment, they're going to find a way into your network. They're going to try and exfiltrate some of your data, right? They want that data, and then they're going to hold that data kind of ransom. So first they're going to say, Hey, we have your data. You should pay us, and we won't leak it to the dark web, and by the way, here's a snippet of what we have. You say, No, I don't think so. I'm not paying. Well, then they may encrypt all of your data, right? So their whole objective is to get you to pay, and if you say, No, I'm not going to pay, then you know perhaps they release that data.
(Eric at 00:12:44) Now, what data is that they grab all depends on what they're able to compromise. So that's one type of an attacker. Another one could be somebody out for personal information to sell that. So they could be going after your customer records, you know. So they may want names, addresses, billing information, payment information, or any of those other things.
(Eric at 00:13:04) So personal data is a big thing. And then there's people out there that just like to do disruptive things. You know, quite often we see, and our NOC is able to handle a lot of this, gamers. You know, they get deeply involved in these games against each other, and they'll go on the dark web to order up a denial-of-service attack against their opponent, to knock them offline so they can win. You know, so that's a different type of an attack. It doesn't directly affect us, but it affects our customers and indirectly, then, affects all the other customers because of that bandwidth that's being utilized.
(Eric at 00:13:36) Well, those are a couple of different scenarios with different attackers and kind of what they're after.
(Joel Beasley at 00:13:41) Awesome. Yeah. Thanks for that context. I know, hot topic in ransomware, to pay or not to pay. Where do you land? Do you think people should ever pay it?
(Eric at 00:13:51) I think that's a slippery slope. And again, you know, each company has to make that decision on their own. There are guidelines, right, that there are federal laws against paying certain companies, because they're on lists from the FBI and the government. The FBI will probably always tell you never pay, because it only encourages it. Your insurance company will say, Well, maybe we pay.
(Eric at 00:14:16) Your company may say, Maybe we pay, maybe we don't. That's a 100% business decision, and I think in today's modern ransomware, you know, where they're doing this triple extortion piece, it really kind of, I think, depends on the company. What did they get? How sure are you of what they got? And can you recover from backup?
(Eric at 00:14:34) But, ultimately, that's a business decision.
(Joel Beasley at 00:14:37) Is triple extortion the three things you just listed?
(Eric at 00:14:40) Yes, sir.
(Joel Beasley at 00:14:40) Okay. Cool. Cool. I hadn't heard that term before. So what does your day-to-day look like running cybersecurity at Arvig?
(Eric at 00:14:50) So, you know, each day has some similarities to it. Right? You know, we're going out. We're looking at the logs, looking at the data. You know, we get daily reports of some transactions that occurred overnight, so we're looking to see, you know, what happened. Anything we need to go back and take a look at? We're also looking at alerts as they come in from different monitoring systems that may indicate a threat, investigating those to find out, you know, is this an actual event, or is this a nope, it's, yeah, it triggered something, but it's not of great concern. You know, sometimes, depending if you haven't tuned your systems quite right, as soon as your system updates, Adobe pushes an update for Adobe Reader, or Windows pushes an update. Sometimes, you know, systems will trigger that and go, Oh, this file changed. You're like, Yeah, it's okay. I know. This was expected behavior.
(Eric at 00:15:37) We also do a lot with projects, right? So anytime that there's a project going on, you want to have cybersecurity involved in that to ensure that things are being done to maintain the confidentiality, the integrity, and the availability of those systems and the data. We also do quite a bit with enabling other parts of our business, right?
(Eric at 00:16:04) So, you know, as a broadband company, we're selling products to other people, and there is a big push recently into what is called third-party risk management or vendor risk management, depends on the company on the terms they use. So if we're selling a product, you know, like broadband access to a regulated company, you know, we're going to probably get this questionnaire and have to fill all that out where they're asking about our security practices, and how are we protecting our network, and how would we be protecting their data. So, you know, every day is a little bit different, but those are some of the core things that we see.
(Joel Beasley at 00:16:41) Cool. And I know at top executive level, a lot of the time, people in your position need to spend time talking with the C-suite about how to justify cybersecurity expenses. And a common thread I've heard is positioning cybersecurity as enabling the company rather than shooting stuff down. And you actually mentioned the word enabling business practices there. How do you go about that with your team?
(Eric at 00:17:09) So it really comes down to exactly what you said, right? So you have to show value to this as part of the culture and the business enabler, as I previously mentioned. Many times, cybersecurity is seen as a cost center or something that they have to do because of requirements or regulations. But by shifting the thinking, it can be seen as creating greater customer trust, creating business opportunities, and protecting vital assets of the company, including data in good standing.
(Eric at 00:17:38) We also need to take the time to make sure the employees and leaders are aware the important role that they play in protecting the company and provide them with training and awareness that they need to protect themselves and the company. Right? So the saying that it all comes from the top down is absolutely true. If that C-suite and those leaders that layer directly under them aren't buying into it and don't believe in it, it gets to be really hard. So from a cybersecurity standpoint, then it's important that when we have wins, right, when we have done our part for a massive contract, and they needed the third party risk management assessment done, and we do that, and they go, yes, you're good to go.
(Eric at 00:18:21) Congratulations. Here's your contract. That's us supporting that business win. When we're coming out and doing things that are promoting the company and in podcasts like this or articles, we're showing that, hey, we take security seriously, and that maintains a posture out there where people go, oh, you know, they really do care about this. I'm willing to do business with a customer that knows that, takes concerns about security, and takes it seriously.
(Eric at 00:18:49) The other piece, too, is I don't believe in running and screaming, the world's on fire, we got to fix this, we got to do this, right? It's just not the way that I operate. You know, fear, doubt, and uncertainty, or fear, uncertainty, and doubt—FUD—is not a good way to operate, right? So another way that you easily interact with that C-suite is you provide actual realistic data. The CFO wants to understand how much is this going to cost, what's our benefit.
(Eric at 00:19:17) So we can say, well, by having these policies and procedures and having this program enabled, we are able to help lower our insurance rate by X. That's tangible savings, right? That's something they can see and understand. You know, contracts won, reputation maintained. You know, many companies get phishing attacks, you know.
(Eric at 00:19:38) So as a telco, we see quite a few attacks coming out towards our customer base because they're trying to snag customers' usernames and passwords. Luckily for us, we have some programs in place that help us identify a lot of those, and we have a lot of customers that are willing to say, hey, is this really you? And send it in, and we're able to assess that really quickly and get those sites taken down. So that's another aspect where we're protecting the customers where they may not even realize that, but it's protecting the company and the brand, and that really goes far because if somebody gets compromised and they're going to blame, well, I got an email from Arvig, and no, it really wasn't from us.
(Joel Beasley at 00:20:17) For sensing those phishing attacks as they're going out, how do you pick up on them if not from someone actually sending it into you and saying and asking, is this you? You mentioned you have tools for monitoring it.
(Eric at 00:20:32) Yeah. So we have a subscription with a company that deals with brand impersonation, both on the website and on the social media side that we coordinate with that helps us with that. So that's been a big change recently that we've made. So we added that into our whole programs along with our third party risk management and our other programs that we have to help move us along in the space.
(Joel Beasley at 00:20:57) Nice. That's cool. Well, I got a question I really like asking cybersecurity people, and we can skip it if you want because I know it can be a sensitive issue. But have you been through a particularly rough attack in your career, and are you comfortable sharing what it was like dealing with that and how you got through it?
(Eric at 00:21:20) Well, my career spans many, many years, right? I mean, I've been in this for twenty-four years now. So across the sphere of twenty-four years, right? I won't put any company under the bus. Yep. I've seen a lot of things, right? You know, I've seen where hosting Microsoft Exchange on-site and having to do a restore because something was deleted, like an account was gone, and you go to put that back in, and all of a sudden, it overrides the current production with an old copy, and you take the entire email system for a company offline for three days.
(Joel Beasley at 00:21:55) That's tough.
(Eric at 00:21:56) That's a really big deal in today's environment, right? You know, at that time, it was still a big deal. You know, that's why I think you've seen a lot of companies kind of send that mail part off to the cloud. Yeah.
(Eric at 00:22:07) You know, so you see a lot of people utilizing mail services from Google or Microsoft or Yahoo or somebody like that for a lot of those things. You know, I've seen and worked through a few incidences of ransomware in my career. Those always get you, right? And that's one of the things that scares me the most about ransomware is because I've seen it progress over the years, right, from, you know, very simple, oh, great. Yeah, we got it. Okay. It got a server. Just rebuilt the server to now we're at this triple threat extortion. You know, we've seen people get terminated and, you know, try to delete things off the network right before they walk out the door or, you know, on their computer, you know, wipe it clean so that you can't get anything off of it for data files they may have.
(Eric at 00:22:52) So it's ran a gamut in twenty-plus years.
(Joel Beasley at 00:22:55) I remember about two years ago on the podcast, we had a guy come on who's a ransomware consultant. He shared a story of a time when, you know, a company was under attack, and they decided they needed to pay it. But the attacker requested that he had to be paid in Bitcoin. And so this was before it was as easy as it is now to just get a large amount of Bitcoin. So they didn't know what to do, and they just asked their employees, hey.
(Joel Beasley at 00:23:23) Does anybody know where we can get some Bitcoin? And someone spoke up and said, I know where we can get some, but you can't hold it against me. And the company said, sure. And a drug dealer came into the office and helped him out of that tough situation, and they paid him for his services. That one has stuck with me from, yeah, the past couple years just hearing that on the podcast.
(Joel Beasley at 00:23:49) That was
(Eric at 00:23:49) Stick with me now too because that's an interesting story. I've never heard that one before. So it's definitely that thing has become much more the norm, right, as we look at it. But, yeah, ransomware is still, I think, one of the scariest things out there for right now, just because it can be so devastating. You know? So I know of a company that had a ransomware attack. You know? They were able to clean up their systems. It only affected their IT network.
(Eric at 00:24:16) It didn't affect their operational network, right? So in a telco kind of thing, our transport network for that broadband and our side stuff would be our OT, our operational side, and then IT would be everything internal type scenario. So it only affected their IT side, and they ended up paying, right?
(Eric at 00:24:34) And so they went through their broker and did all of the negotiations. And, you know, if this ever happens, you certainly need to involve your insurance carrier because they'll help you out with the correct people for all of this. But they ended up paying, and they got 70% of their data back. So then they had to hire a developer to try and write and decrypt the other part, and so they ended up getting about 90% of it back. Well, I was talking to a friend of mine—we all three share a mutual friend—and he was saying that they are still finding issues with this, mostly in spreadsheets that have macros and things.
(Eric at 00:25:08) Like, they were able to get the data back, but it broke all of the underlying financial formulas and spreadsheets and all that other. So there's still, even after you recover from a ransomware, you're going to feel the effects of that for quite a long time. And if you think about it in an accounting world, you know, if you're doing your books annually for year-end closeout, you haven't touched those files in a year. You didn't know they were broke.
(Joel Beasley at 00:25:30) Right.
(Eric at 00:25:31) And now you gotta try and go, what was in this, or how did this work again?
(Joel Beasley at 00:25:35) Yeah. That is tough. And I know another really scary thing about it is you can pay them, and they give your data back and say that they left, but they might still have left something in there that lets them come back.
(Eric at 00:25:48) Right. How do you know that they truly aren't gonna hit you again, right? Or you go into some database of people that paid and, you know, oh, well, they paid. Let's hit them again.
(Joel Beasley at 00:25:57) Yeah. Exactly.
(Eric at 00:25:58) You know, although, you know, as you start to look at the statistics, it's really they like to go after those small and medium-sized businesses because they don't have big staffs. They don't have good data backups to be able to restore from, so they're way more likely just to pay. And a lot of those small companies that get hit, they just simply go out of business. So it really can be a devastating thing, you know, for a lot of companies.
(Joel Beasley at 00:26:19) Do you guys do any training scenarios, like war room type kind of thing?
(Eric at 00:26:25) Yeah. So we call them tabletop exercises. So as part of our program, we tabletop exercise quite a bit with different teams and over different scenarios, you know, so we've held tabletop exercises with our executives and given them a scenario and, you know, well, we're gonna do this, and then we'll throw a curveball in and say, well, that's unavailable, or can't because this happened. And really just, you know, the purpose behind those tabletops is to get people to think about things, think it through. How would we react if this happened?
(Eric at 00:26:57) But what if this part happened? You know, where's our threshold? Who do we—at what point do we do X, or what point do we do Y? And so that really helps then not only bring them into it, so that in the event of an actual crisis or incident, they know their roles and responsibilities, but how they would react. We've done other ones where we've done simulations and not told people, where we've intentionally broken something and see how they react.
(Eric at 00:27:26) You know, what's the first thing that they're going to do? What's the second thing they're gonna do? You know, did they grab the playbook? Did they notify the right people? Did they move down this path?
(Eric at 00:27:35) And so we will let that run, and then kind of come back and do a learning session and refine. Maybe we need to tweak a process somewhere. So, yeah, those war room or tabletop exercises really become important into making sure that everybody involved knows what their responsibilities are, and your processes are good to go.
(Joel Beasley at 00:27:54) Awesome. I love the idea of those simulations where you don't tell them and just see what happens. That reminds me of the concept of chaos engineering. We've had a couple of people on the show talk about that, you know, just running through the server room, pulling out wires, and seeing if it still works.
(Eric at 00:28:11) Yeah. You know, part of that, though, you gotta be a little bit careful on that one, right? Yeah. Because, you know, you don't wanna take the wrong stuff down.
(Joel Beasley at 00:28:17) Yeah.
(Eric at 00:28:18) You know, so in those kind of things, you know, we'll do somewhat of a simulated failure.
(Joel Beasley at 00:28:22) Right. Right.
(Eric at 00:28:23) But we won't actually take it down, but we'll say, okay, this system's unavailable. Can you bring it up in this data center over here? So we'll run those while not truly disrupting the business.
(Joel Beasley at 00:28:31) Yeah. That seems like a better call for telecom. Yeah.
(Eric at 00:28:36) Can you recover this? Boom. And you pull the main, you know, pull the main router out and the whole company and all your customers go dark. It's probably not a good—I mean, it'd be a test, but not one I really wanna test.
(Joel Beasley at 00:28:45) Right. Well, I wanna wrap up not talking about FUD, as you call it. It was fear, uncertainty, and destruction. Doubt. Oh, doubt.
(Joel Beasley at 00:28:55) That's it. But a lot of people like talking about what's the new threat that's come to light. What are attackers using now? What's the big new scary boogeyman? But I'm curious.
(Joel Beasley at 00:29:07) What are some new tools for defenders that you're really excited about to be using today?
(Eric at 00:29:13) Oh, I think one of the biggest things we've seen has been for EDRs or XDRs, right? EDRs, endpoint detection and response, and then XDRs just extended detection and response, right? So if you think about your traditional antivirus, right? It would see something—it would have to look up against a signature and say, oh, this is a good file, that's a bad file.
(Eric at 00:29:37) Today's malware detection type, if you will, in the EDR and XDR world really looks at behaviors, right? So it doesn't—I mean, it looks at the file and goes, okay, it's a file. Oh, wait, it's trying to encrypt something? Stop that, right? So it looks at the heuristics.
(Eric at 00:29:52) It looks at the behavior more than a signature-based. So it doesn't matter if the attacker, you know, goes in and changes, you know, one character, so it has a different, you know, hash value that the old antivirus was looking for. It cares about what the actions are. That's been a huge leap forward in the last few years. I'm also really, you know, excited within the focus that's happening now on supply chain risk management.
(Eric at 00:30:19) We don't have to go very far back to think about what happened with SolarWinds when that got compromised and their source code got pushed out. There was kind of the telltale signs of that with the Ukrainian one that Russia did against it, kind of their equivalent of QuickBooks, if you will, right? They pushed out an update, and it caused all of those things. So those things are out there that are happening. I think that the increase in knowledge, the amount of companies that are actually taking cybersecurity seriously has been great.
(Eric at 00:30:49) Providing people with training and with awareness just overall has been—it's done leaps and bounds for preventing phishing attacks and those other things, right? People looking at emails and going, I don't know. Can somebody look at this? So those are a couple of things, I think, you know, recently that have really come out and been a big deal, especially for us, right? It's for us, the big changes for us has really been awareness and training, right?
(Eric at 00:31:19) So one of the things that I'm very proud of is we've been able to infuse cybersecurity within our culture, and that's no small feat, right? I mean, company cultures are company cultures and they're culture because it's ingrained, but we now have people at every level willing to reach out and willing to say something if they see something, like, hey, I don't know, or, hey, I saw this weird thing, or my computer did this. That's vital. That's how you're gonna catch stuff early.
(Joel Beasley at 00:31:49) That's awesome. Yeah. That is huge, having everybody—everybody needs to be involved with cybersecurity all the time. That's just how to be safe now. But before we wrap up, is there any extra shout out you wanna make or point you wanna get across for people to be safe?
(Eric at 00:32:07) I'm gonna kinda give you two things. One is for everybody that's listening, and that is if you're not using MFA or multi-factor authentication, you really should be. And that's not only at your company, that's for you as an individual, right? If you look at Facebook, it will allow you to do MFA. Instagram will let you do MFA.
(Eric at 00:32:26) LinkedIn, all of them offer the multi-factor authentication. We really need to be utilizing that. And as a person, check with your bank, right? Do they allow you to get alerts every time that your debit card is used or something like that? These are—identity theft is huge, and this is a quick way to help stop that from the individual side.
(Eric at 00:32:46) You know, from an Arvig perspective, we're always looking for great qualified people. You can check out arvigcareers.com and see all of our openings and what we have going on. And, you know, we pride ourselves in being an employee-led and driven team. We share one common purpose, and that is that we enhance lives by creating solutions that connect people to their world.
(Joel Beasley at 00:33:10) Boom. Mic drop. That's it. I'm out.
(Joel Beasley at 00:33:15) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email: [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.