Episode 465 ·

Improving Your Risk Profile with Paul Ashe, Founder & President of Securance Consulting

Today we’re talking to Paul Ashe, Founder and President of Securance Consulting; and we discuss why it’s important to invest in training your end users on security to guard against phishing attacks, and why it can be problematic to have a company’s technology function report directly to the finance function. 

All of this right here, right now, on the ModernCTO Podcast! 

Learn more about Securance Consulting at https://www.securanceconsulting.com

About Paul Ashe:

Paul Ashe, President and founder of Securance Consulting, is a cybersecurity professional with over 20 years’ experience helping organizations align their security postures with their cyber risk appetites. Paul began his career as a Southeast Area Security Expert for Ernst & Young, then started Securance to realize his goal of delivering personalized, cost-effective services to businesses of all sizes.

Through his work at Securance, Paul has educated hundreds of clients about effective cybersecurity and IT risk management. As both president of the firm and a practicing cybersecurity professional, Paul provides independent assessments and advisory services to help public and private sector organizations secure their networks and systems, mitigate known risks, and thwart evolving cyber attacks. He champions the importance of enterprise cybersecurity through innovative services, such as advanced persistent threat simulation testing, Cybersecurity as a Service, and ransomware readiness assessments.

Paul is a graduate of the University of South Florida and received his Master of Science in Information Systems Management and Accounting in 1998.

About Securance Consulting:

For over two decades, Securance has delivered IT audit and cybersecurity services to help organizations combat cyber threats, build effective risk management programs, and meet compliance requirements. We tailor each assessment and our approach to the client, ensuring the long-term value and sustainable benefits of every project. To learn more, visit securanceconsulting.com or follow us on LinkedIn.

Transcript

(Intro Narrator at 00:00:03) Hello, my friends. Today, Joel is talking to Paul, founder and president of Securance Consulting, and they discuss why it's important to invest in training your end users to guard against phishing attacks and why it can be problematic to have a company's technology function report directly to the finance function. All of this right here, right now on the Modern CTO Podcast.

(Joel Beasley at 00:00:32) Here we go. This is the Modern CTO Podcast. Are you the founder of your company?

(Paul at 00:00:45) I am the founder of Securance—March 4th, 2002.

(Joel Beasley at 00:00:50) Oh, the day you started staring into the abyss and eating glass, as Elon Musk says.

(Paul at 00:00:56) That's right. That's right. Working twenty hours a day.

(Joel Beasley at 00:01:00) So where is it at today? Is it at the point where it's rocking and rolling? Is it scaling? Where are you today with your business?

(Paul at 00:01:08) I think we are at a really good place today. I mean, I've got a really good team of consultants, team of administrative and back office staff, and it's pretty much just running itself. Obviously, the guidance and leadership is always going to be there, but we're always just looking for new revenue avenues, new opportunities to grow. Recently, we were admitted into the federal 8(a) program, which is a great program for small businesses. So yeah, I'm still nose to the grind, right? I'm not satisfied with yesterday and looking forward to what tomorrow brings.

(Joel Beasley at 00:01:47) And so you're primarily security consulting?

(Paul at 00:01:50) We are 100%. I like to refer to us as IT risk management, which kind of covers more than just cybersecurity or security. There's other things associated with IT risk management, but certainly in today's market, the thing that you hear most commonly is cybersecurity, right? Cybersecurity risk and ransomware. And so we have deep expertise in that space. But we work for internal audit departments, we work for IT departments. Those are our main two customers.

(Joel Beasley at 00:02:25) Oh, nice. And so the way I got connected with you is I was asking the team, I was like, "Hey, do we know anybody that has security experience, that has really cool, maybe attack stories that they're willing to share?" And David said, "Yeah, I know a guy," and he connected us. And so I was curious—I know we can edit stuff or we can use placeholder names, but I was hoping that you could share some of the attack stories that you've been a part of, like responding to threats.

(Paul at 00:02:53) Yeah, yeah, absolutely, certainly. So I obviously have to withhold names, and if I slip, that's, I guess, the purpose of an edit. But I can share two stories. A few years back, we were engaged by a very large—I think they're Fortune 1000 company—to attack their organization just as a bad actor would. And so we performed the activity, and our approach is to communicate with our clients. And so we got into their environment through the Internet. And at the time, we were asking, "Hey, how far can we go?" We were at the point where we were on their HR directories, and we had access to everyone's salary compensation. And so immediately, the CFO gets on the call and says, "You guys need to stop immediately. You've proven your worth. You've been extremely successful, but we don't want you looking at sensitive information." And certainly, attacking the HR directory or attacking where HR stores all their files—there's a lot of confidential information there. And so we didn't exfiltrate, we didn't take any data out, but we certainly showed them screen prints that, hey, who is this person? This is their comp. And so it was interesting because at the time, they were frustrated with us for getting that far, but also happy that we got that far and not a bad actor, right? And so I guess, from our perspective, it was also rewarding because as an ethical attack organization, right, your challenge is to break through whatever security barriers are in place. And so our team was happy that we did that. Unfortunately, that client scaled back our engagement because of our success. Right? And so, yeah, it's just one of the types of things that happens.

(Paul at 00:04:36) Another interesting story that we had was—one of the older ways to breach an organization is through breaching their physical security, right? It's not just coming in through the Internet, but if I can get in through an open door or if I can tailgate into an area where I'm not supposed to be, that is also a form of a breach. And certainly, if you can get into an area that's a restricted area and then connect to the network. And so we've had a lot of success. In fact, we were working at an electric utility, and they had some locations that were supposed to be restricted areas, and we got through those restricted areas, got into a very, very sensitive area and connected our toolbox to their network. They didn't even see us connected to it, and so we started performing our activities. And basically, we could have shut down a big portion of that utility, just literally stopped electricity from flowing. We didn't go that far, obviously, because we're an ethical group. But certainly, that set up various levels of alarms throughout the organization. And again, I think one of the reasons I started this company was because what I really enjoy is when a client engages us, we perform an activity, and then they actually take our advice on how to secure themselves.

(Joel Beasley at 00:06:21) You have clients that you do the activity, you give them the advice, and they don't take it?

(Paul at 00:06:28) Yeah. So, yeah, it's interesting, Joel. You mentioned that because, yes, we have—we try to identify those clients upfront and not work with them. But sometimes it's very, very challenging because you have a client engage you, and they seem, during the contractual phase, that, yes, they want to get this done, and they're gung-ho and eager to do it. And then when you actually start doing the work, they're like, "Hey, by the way, we see this as just a check-the-box item. Some state agency or some federal agency requires us to do this, so we're just doing it. And we're not really interested in what your findings are or what you can do. Just be able to say that we did it." And so from my perspective, that's not a client that we want to work for because, you know, security is security and it's a great field. I love it. I'm not going to become a billionaire anytime soon doing this. And so the sense of satisfaction that I personally get is when we do the work and a client calls and says, "Hey, by the way, that was great advice, and we've changed this and we've changed that, and we feel better, and we feel more protected."

(Joel Beasley at 00:07:36) What would you do if you did become a billionaire doing this?

(Paul at 00:07:41) That's another great question. What would I do if I did become a billionaire? I really enjoy what I do. I really enjoy what I do. You know, so when you're an entrepreneur, you have a vision, right, and you try and execute that vision. And my initial vision was just working with clients. And then, of course, as the company has grown, I've hired all these people. And so there's a part of what I do that I just don't like, and that's the people side, the administrative staff. So if I ever became a billionaire, I would try and set myself up in a situation where all I had to do was interact with clients. And resources and marketing and sales, all of that stuff would take care of itself, and I could just—you know, before this discussion I'm having with you, I was on a call with a client in California, and it just fully engaged me. I mean, I was just fully engaged and entrenched in it, and I love that. And people that know me and my peers and staff, they say, "Man, you are a totally different person when you're talking to a client about something security than when you're talking to me about hiring a staff," right? And it's just because that's the part of it. That's the part of being an entrepreneur that I don't like. So if I ever became a billionaire, I would just try and separate those two. I would still do what I do because I absolutely love it.

(Paul at 00:09:04) Interesting thing is that I'm originally from Key West, right? So I'm born and raised in Key West, Florida. How many times have you heard that or met anyone born and raised in Key West, Florida?

(Joel Beasley at 00:09:16) Well, I mean, my wife and I were born and raised in Sarasota.

(Paul at 00:09:19) Sarasota, by the way, is just an hour south of where I'm at. Right? But Key West is the endpoint of the country.

(Joel Beasley at 00:09:28) Yeah. And it's super touristy. So Sarasota is touristy because of the beaches, so people are always surprised when you're native. But Key West is like Sarasota on steroids for tourism.

(Paul at 00:09:37) Right, exactly. But Key West wasn't always like that. I'm not going to give away my age. I'm really old right now. But when I was growing up, man, Key West was nothing like it is today. Anyway, so I'm originally from Key West, Florida. Long story short is I like to be on the water. I like to fish. I like to just be out on beaches, right? I love that beach life. I don't really get to live it that much because I'm traveling about—before the pandemic, thirty, forty weeks a year I would travel to clients. Pandemic happened and then clients were like, "Well, you can do this work remotely, can't you?" It's like, "Yeah, I was telling you that before, but you always wanted me to come on-site." But now it's starting to get back to where clients want you on-site again. And that's fine. I mean, I'm just used to it. I tell people all the time, you get up in the morning, have your coffee, jump in your car, and go to work. I get up, have my coffee, jump on a plane to go to work. Anyway, I think where I was going with that is that I'm a Key West—I'm a conch. And so I would also try to do my job from a beach somewhere or from a boat. That would be nice.

(Joel Beasley at 00:10:46) A fun fact. I don't think I've—in five years, I don't think I've brought this up on the show, but my grandfather is a world champion boat racer. He won the world championship of boat racing in 1988 with Don Johnson as his pilot.

(Paul at 00:11:01) Get out of here. Yeah. So here's another interesting thing about that—I think you're talking the super boats, the power boats.

(Joel Beasley at 00:11:11) Yeah.

(Paul at 00:11:12) On that circuit, they came to Key West, and annually, I would go and watch them race.

(Joel Beasley at 00:11:16) Oh, yeah, yeah. That's where—so he came here from Greece and started playing professional soccer. So America wanted to build a team, I think, in Miami or—I can't remember the exact place, but it was down there. And so they went to different countries and recruited different players for football, soccer, right? And so he's a goalie, and then he had an injury. And then in the off season, he had been just working at the docks to just make some extra cash. And then when he had an injury, he just started hanging around the docks more and more and more and then just started racing and then had a career for like twenty, thirty years in boat racing.

(Paul at 00:11:48) Oh, nice. What was the name of the boat that he was on?

(Joel Beasley at 00:11:50) I don't know. But if you want to look him up, his name is Gus Anastasi. And then there's a three-person crew that he was on that was driving because one does steering, throttle, and navigation, right? So it was him, Don Johnson, and someone else.

(Paul at 00:12:06) Okay, okay. Yeah, I bet you I probably saw him race because I left Key West in 1992, '93. But prior to that, I mean, from '70 all the way to '92, I was there. And we went to the races religiously.

(Joel Beasley at 00:12:20) Yeah. No. And I was curious. One of the things that I'm thinking of as we're talking is when we're talking about you being a billionaire and what you would do. Do you think it's possible—and I know it's hard because I'm an entrepreneur as well—but you think it's possible that you could hire a president or something at your company to do the things you don't like to do?

(Paul at 00:12:40) So I have already transitioned into that phase. Jillian, who was on just before, she's our VP. And she's been with the firm eight, nine years, and she is starting to take on a lot of those tasks that have to get done. They're critical to the success of the firm, but they're just not my favorite things to do. So she was just promoted, I think, last year. And I think in another year, eighteen months, she'll fully be able to just take on all of those things, and then that'll relieve some of my time to doing more client engagement.

(Joel Beasley at 00:13:14) I'm curious to sort of get back to the security conversations. We have a lot of people, like technology leaders that listen to this show, everywhere from startup, growth, scale-up. What are some of the basic hygiene 101 security things that these technology leaders should be thinking about?

(Paul at 00:13:34) Yeah. I think that's a great question. I think most people would think a firewall or some basic stuff like that. I would disagree. I think that probably the first thing that I would certainly share with someone that's a technology leader and looking to have some level of security is to train your end users relative to their role in securing the environment and securing the data. Subscribe to some type of end user training so that end users are aware when they're being phished, whether it's a phone phish or SMS message or social media message or an email message. I mean, the truth of the matter is phishing is one of the highest methods and vectors that bad actors infiltrate organizations. And so I think that's probably a number one—real close to number one, number two—things that starting out, you should do is invest in some type of training program.

(Paul at 00:14:35) I think also, you probably want to invest in something greater than traditional antivirus software, right? So years ago, antivirus was just antivirus. It was signature-based antivirus. You install it on a workstation, on an endpoint, and you had some level of protection. Now that just doesn't do it. That just doesn't do it. So you really need to invest in some endpoint protection solution. The most common are EDRs, endpoint detection and response solutions, that you have to put on every workstation, on every server, and it helps to isolate and contain. I think those are probably the top two things. And I know—I participate in several forums and discussions, and you're going to get some differences between security experts as well. You have to have a great firewall and intrusion protection and SIEM. I think for someone just starting up, some basic 101 type security things—yeah, give your end users training. Train your end users because everyone is responsible for security of the environment, not just IT. And too often, it's looked at as just an IT thing.

(Paul at 00:15:52) While I'm thinking about it, I also think that—I'm in the process of writing an editorial about this—is that when I left, during my career tenure with Ernst & Young and certainly for years after, from real startup organizations or organizations that are maybe looking to scale up but not yet hit their running speed, they have the IT department report to finance. And I think that that's a big, big mistake. And the reason it is a mistake, in my opinion, is because—and I say this with all due respect to CFOs and CPAs; I am a CPA myself. In fact, when I went to college—

Paul Ashe at 00:16:35: I went to college to be an accountant, and then I quickly realized I also wanted to do computer science. So I dual majored in accounting and computer science, but I am a CPA. And so with all due respect to that industry and that discipline, an accountant very rarely understands the value of technology relative to products and services that they can't see and touch. So if I am in IT and I'm reporting to a CFO and I say, "Hey, I need to go purchase this EDR solution," or "I need to go purchase this third-party managed security service," well, the CFO is going to look at it and say, "Well, yeah, but that costs X, and I don't see a software application, or I don't see how that's helping my end user be more productive today." And so oftentimes, they will slash that out of the budget. It is because security-type items—security technology, security defense measures—cost a lot of money but don't have an immediate tangible value to someone that doesn't understand IT and what that technology is actually doing. It's kind of like—I've just worked on deploying a security operations center for a very large municipality, and it's hundreds of thousands of dollars.

Paul Ashe at 00:17:51: And one of the executives there looked at it and was like, "Man, we're spending all this money a year on this one technology, and I don't really see what it's doing." And I'm like, "But you don't see what it's doing, but you haven't been a victim of a ransomware attack, have you?" "No, we haven't." "And all of my neighboring municipalities have. Well, that's what it's doing." Right? You can't see it. You can't touch it. You can't feel it. But trust me when I tell you, it's protecting you. And so I think, you know, speaking editorially, a lot of organizations—maybe you can't afford to hire a CIO, you can't afford to hire a chief information security officer because the price of those keeps going up and up and up. But I just think it's also misaligned to have your leader in IT—maybe you have an IT director, right, not a CIO or CSO, but maybe you have your director report to the CFO. I think that's just a misalignment. And I think it's well worth the investment, even if you just have to go out to market and get a virtual CIO or a virtual CSO, someone that's going to give you twenty hours a month but can provide strategic information, strategic guidance, and can articulate to the CFO or to the comptroller or to the chief accounting officer the value of the services that you don't necessarily see on your workstation. Right? You go to your workstation. You don't click an app and see security. But it's behind the scenes. It's working behind the scenes, and it's doing a great job. I sometimes go off on these tangents because I just love this topic. So you have to reel me back in when I'm saying too much about something.

Joel Beasley at 00:19:29: No, this is a talk show, man.

Paul Ashe at 00:19:31: Oh, okay.

Joel Beasley at 00:19:32: We hang out. We talk.

Paul Ashe at 00:19:33: I could talk forever about this because I mean, I live, sleep, dream, eat this stuff.

Joel Beasley at 00:19:38: I was surprised to hear you say that you're still seeing companies have IT report up to CFOs because I thought that was an old thing that had stopped happening.

Paul Ashe at 00:19:49: Yeah. You know, you would think that. I mean, it's certainly—I'm certainly seeing it a lot less than I was, let's say, five, ten, certainly ten years ago, but I still see it in pockets. Right? I still see it in pockets. And generally, it's the smaller organizations that don't—you know, there are some organizations that just see IT as just, "Hey, we need PCs. We need someone to give us PCs and manage PCs." Right? Those types of organizations that aren't looking strategically at what technology is doing. Right? And then, of course, you know, the next misalignment in terms of reporting structure is the chief information security officer reporting up to the CIO. You think about that. That is inherently conflicting. Right? The CIO is charged with operations, strategic guidance, getting the technology to support the business strategy. The chief information security officer is charged with protecting the environment. Sometimes those things butt heads. Right?

Joel Beasley at 00:20:52: Yeah.

Paul Ashe at 00:20:53: So the CISO needs to know that he or she can freely speak about the risk that they see and not have to worry that the CIO is going to suppress that risk because it conflicts with an initiative that the CIO's office has.

Joel Beasley at 00:21:06: They just need to find a different company. That's a bad culture.

Paul Ashe at 00:21:10: I couldn't agree with you more. I couldn't agree with you more. I would agree with that.

Joel Beasley at 00:21:15: Yeah. Yeah. So I'm curious, when you're talking about how to explain it to the CFO, a lot of what you're describing sounds like how I would explain an insurance policy. Right? Like, you don't necessarily see it. It's there. It's protecting you. And then my other question is, how has insurance, like cyber insurance, changed over the past couple years? Because I remember five, six years ago, I could check a box and get a million dollars, and I didn't have to do anything. And now they send you a questionnaire that's 800 questions long to get a $50,000 policy.

Paul Ashe at 00:21:54: All right. So two good questions. One—so you said that what I was explaining in terms of the spend for protection is kind of like an insurance policy, and it is, with the exception that, you know, from, let's say, a CFO's perspective, right, CFO has to have insurance because maybe their customers are requiring that they have insurance, whereas there's no one really requiring that you invest in these defense mechanisms to protect the environment. So that's one major, major difference. The other question that you brought up is a really hot, interesting concept and topic right now, because cyber insurance—you're exactly correct—used to be check a box, you get a million-dollar policy or whatever the limit you need. Now, because there have been so many successful ransomware attacks—I'll share with you a project we're just coming out of. We led a war room where a big organization was attacked, and we spun up a war room to build out their recovery, eradication, containment, recovery. And so the directive that we received from the CIO was, "Hey, this is critically important to us. We need to recover as timely as possible. Our purse strings are completely open. Whatever the spend is, we have X amount of million in cyber coverage to reimburse us." So we just went with that directive, and we got them back up in a week. Most of their systems, we got recovered in a week without paying ransom. We didn't pay ransom. We initiated negotiations with the actor, but we ended up not paying. We then had to deal with the application to get reimbursed, and the cyber insurance came back and said, "By the way, we're only going to reimburse one-third of what you're requesting because we see these other activities and these other costs as preventative measures as opposed to getting you back to the place where you were at before you were attacked." Now the interesting thing about that is like, wow, when you think about it, it's like, you're still my insurance provider. Why would you only want me to get back to a place where I was successfully attacked just so the attack can happen again? Well, insurance is in there to take premiums and reduce claims, and so that's their posture. So now what we see is two things happening in the cyber insurance space. One, it's very difficult now to get cyber security insurance. As you mentioned, the checklist is phenomenal, and not only is it long—you have to—they're asking you things about how are you protecting your endpoints, what is your end-user security training, what percentage of the users are passing that training, do you have a SOC in place. You know, all of these questions, and they have a direct impact on if you get the insurance levels you want or not. And then the other thing we're seeing is that a lot of insurance providers are fighting claims, and they're putting in these high levels of deductibles where they're not going to reimburse. You know, if they think that—back to—so it—this is how it just comes full circle back to my discussion about the purse strings at the CFO side being held because IT is wanting these security things that they may not need. Well, now insurance is saying, "Yeah, but if you don't have those things, not only maybe we won't insure you, but we're going to reduce your reimbursement from a claim." So now that insurance base is just crazy in terms of competitiveness and what it takes for an organization to get it. Not only that, I can tell you probably within this year, 50% of our clients have said, "Listen, when we get attacked—because it's a matter of when, not if—when we get attacked, the first call we're going to make is now to our insurance." Now, as a cybersecurity professional and expert, I'm fighting that. I'm telling these clients, "Look, I get it. I understand why you want to have your insurance as part of your eradicate, contain, recover. But what I'm telling you from experience is that might not be the first call you want to make because their response and their agent's response is to minimize the claim and not fully protect you as you should be protected." It's just an interesting space right now.

Joel Beasley at 00:26:18: Yeah. So it's better just to have good systems upfront and do the best you can there rather than relying on the insurance?

Paul Ashe at 00:26:29: Yeah. I think it's best to build multiple layers of defense, architect the zero-trust network, and really rely on your own internal experts. Make sure you have immutable backups. Like, do all of these rudimentary things that sometimes, quite frankly, just get missed, or—I don't know. I mean, we're all human beings, right? So we can have a whole list of things that we want to do and we know are necessary. Some of them just get missed. That's just part of being a human being. Continually check on your environment. Continually check. You know, Securance as an organization, we do assessments all the time, but we typically would say to a company, don't just rely on Securance. Go out and get another set of eyes. Right? And have them look at it and bounce off of them what we do and bounce off of us what they do. And that's really the best preparation that we recommend to our clients. It says, got to do everything you can to prepare. And even then, there's no guarantees.

Joel Beasley at 00:27:28: So as we start to wrap up, I'm curious, what sort of advice would you want to leave with all of these technology leaders in regards to security? Is it get a CSO? Is it, you know, budget for this type of thing? Like, what advice do you find yourself giving most commonly?

Paul Ashe at 00:27:48: Yep. You know, the most common advice—you know, I'm going to say—is really in three areas. One is define a strategy. Right? Define a strategy. And there's ample places you can go online to define a strategy that's applicable to your industry, applicable to your business industry, and also applicable to your organization size. Define a strategy, get end-user security training, and then patch your systems. Patch your systems, and not just the common Microsoft patch. Patch all of your systems—application systems, operating systems, network device iOS, firmware. Patch them and keep it up to date. Keep it up to date. You know, what I still see in the market is companies and organizations protecting their perimeter. "I got a firewall in place. I got IDS, and I have some security on my web apps. No one can get in, but I don't care what inside looks like." And that's just the wrong approach because I can get into any organization by phishing a user or by tailgating a user or by social media tricking a user. And so, years ago, it was just, "Oh, the perimeter," and now that has still stuck. And now what we're telling our clients is you need to look at your internal network just as you do your perimeter, just as you do your perimeter. When I say get a strategy, you don't necessarily need to have a CISO for a strategy, but you have to have some method to accumulate strategic information relative to protection, IT security protection. And so maybe you get a virtual CISO, or maybe you have someone in the organization that is interested in security that can get some training and kind of bring security into the environment. But you can't just haphazardly do it, and you certainly can't take the approach that, you know, "It'll just happen," because it never just happens. It has to be strategic. It has to be focused.

Joel Beasley at 00:29:48: Yeah. As you're talking about that lateral movement, you know, it's not like people just put a lock on their front door of their office, and then all the internal doors are unlocked. They have locks on all the doors.

Paul Ashe at 00:30:01: Very great—very, very good analogy, Joel. But I see that so often. I mean, you know, we're doing a few hundred assessments a year. 80% of them don't care about the internal network. So I would like the industry to shift from—listen, let's keep that perimeter protected, but now let's shift some of that focus to the internal network.

Joel Beasley at 00:30:25: Is that an assessment that's on your website that people can take?

Paul Ashe at 00:30:30: We do have a what we refer to as a hard network assessment on our website, securanceconsulting.com/hardnetworkassessment, and it'll give you a snapshot of what your security posture is, not only on your perimeter, but for your entire environment. Now, you know, it's a snapshot. It's—I think it's probably 20 or so questions, and it sets up a maturity against the NIST framework of security and control. So it's a really best practice framework, and we don't expect every organization to have all of those things in place, but it gives you a snapshot of what key items are missing because we then also prioritize. We also prioritize and say, "Okay, these are the top things that you need that you don't have. These are the moderate-level things. And for an organization that is highly mature in their cybersecurity posture, here are some things that you can do to add to it."

Joel Beasley at 00:31:20: Nice. Nice. Have you ever had to negotiate with ransomware people?

Paul Ashe at 00:31:24: We have. We have. You know, again, I will restrict on behalf of who we did that, but we have had that. You know, in a lot of cases, they're looking for some type of, you know, Bitcoin or cryptocurrency. We have not yet had to be involved in making an exchange.

Joel Beasley at 00:31:45: Yeah. I've heard some really crazy stories about that, and it's never fun. It's never fun for people.

Paul Ashe at 00:31:54: Yeah. You know, some of our discussions have been really interesting. I think more often, we get brought in on the back end. Whether a company has made an exchange or not or have had negotiations, we tend to get brought in on the side of either recovery or helping us build a multilayer security profile.

Joel Beasley at 00:32:16: Nice. Nice. So that's where you specialize.

Paul Ashe at 00:32:19: Yeah. Yeah. We specialize in the assessment and building the security profiles.

Joel Beasley at 00:32:23: Perfect. So if people want to check that out, it's securanceconsulting.com?

Paul Ashe at 00:32:29: That's right. Securanceconsulting.com. Snapshot of all of our services, and certainly, we encourage you to flip a contact us form, and we'll get back to you right away and start the discussions—free of charge discussions—to do some high-level evaluations.

Joel Beasley at 00:32:45: Yep. And it's better now than when the fire is burning.

Paul Ashe at 00:32:49: Absolutely better now than when you're attacked.

Joel Beasley at 00:32:54: Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.